Core use cases
Vulnerability assessment
Continuous scanning for known CVEs and vulnerabilities
Security audits
Comprehensive security configuration reviews
Penetration testing
Automated reconnaissance and vulnerability identification
Bug bounty hunting
Rapid scanning across large scopes
Enterprise security
Continuous vulnerability scanning
Nuclei excels at continuous monitoring of infrastructure for newly disclosed vulnerabilities.Why it matters
Why it matters
Modern attackers exploit new CVEs within days of disclosure. Traditional scanners take weeks to update. Nuclei’s community-driven template library is updated within hours of new CVE disclosures.
-nt flag runs only newly added templates from the latest release.
Asset discovery and inventory
Use Nuclei with technology detection to maintain an accurate asset inventory.Compliance and configuration auditing
Verify security configurations across your infrastructure:- SSL/TLS configuration compliance
- Security header validation
- Default credential detection
- Exposed administrative interfaces
DevSecOps and CI/CD
Shift-left security testing
Integrate Nuclei into your development pipeline to catch vulnerabilities early.Pre-deployment security gates
Prevent vulnerable code from reaching production:Regression testing
Ensure previously fixed vulnerabilities don’t reappear:Penetration testing
Reconnaissance and enumeration
Nuclei automates the initial reconnaissance phase:Vulnerability validation
Quickly validate potential vulnerabilities identified through other means:Multi-step exploitation workflows
Use Nuclei workflows for complex attack chains:Bug bounty hunting
Rapid scope scanning
Scan large bug bounty scopes efficiently:Template customization
Create custom templates for unique vulnerabilities:Integration with recon tools
Combine Nuclei with subdomain enumeration tools:Cloud security
Multi-cloud scanning
Nuclei supports scanning across AWS, GCP, Azure, and other cloud platforms.AWS security scanning
AWS security scanning
- Open S3 buckets
- Exposed ELB endpoints
- Public RDS instances
- Misconfigured IAM policies
Azure security scanning
Azure security scanning
- Subdomain takeover vulnerabilities
- Exposed storage accounts
- Misconfigured App Services
GCP security scanning
GCP security scanning
- Open Cloud Storage buckets
- Exposed BigQuery datasets
- Misconfigured Firebase instances
Kubernetes security
Scan Kubernetes clusters and services:Application security testing
Web application scanning
OWASP Top 10 testing
OWASP Top 10 testing
Nuclei templates cover all OWASP Top 10 vulnerabilities:
- Broken Access Control: Authorization bypass templates
- Cryptographic Failures: SSL/TLS misconfiguration detection
- Injection: SQL injection, XSS, command injection templates
- Insecure Design: Business logic vulnerability templates
- Security Misconfiguration: Default credentials, exposed configs
- Vulnerable Components: CVE detection for libraries/frameworks
- Authentication Failures: Weak authentication mechanism detection
- Data Integrity Failures: Deserialization vulnerability templates
- Security Logging Failures: Detection of missing security controls
- SSRF: Server-Side Request Forgery templates
API security testing
Test REST and GraphQL APIs:DAST (Dynamic Application Security Testing)
Use Nuclei’s fuzzing capabilities for dynamic testing:Network security
Port and service scanning
Scan network services for vulnerabilities:Protocol-specific testing
Nuclei supports multiple protocols:- HTTP/HTTPS: Web application testing
- DNS: DNS enumeration and validation
- TCP/TLS: Network service testing
- SSL: Certificate and configuration auditing
- WebSocket: WebSocket endpoint testing
- WHOIS: Domain registration information
Research and threat intelligence
CVE validation
Researchers use Nuclei to create proof-of-concept templates for new CVEs:Threat hunting
Proactively search for indicators of compromise:Team collaboration
Shared template libraries
Organizations can maintain private template libraries:Results aggregation
Centralize results across security teams:Integration scenarios
SIEM integration
Export findings to Splunk, Elastic, or other SIEM platforms
Issue tracking
Automatic ticket creation in Jira, GitHub, GitLab
Webhook notifications
Real-time alerts via Slack, Discord, Teams
Custom workflows
Build custom security automation workflows
Performance at scale
Nuclei is designed for large-scale scanning:- 50x faster scans with ProjectDiscovery Cloud
- Template clustering to reduce redundant requests
- Connection pooling for optimal performance
- Rate limiting to respect target resources
Learn more
Examples
See real-world command examples
Template library
Explore the template library
Running Nuclei
Learn how to run Nuclei
Pro & Enterprise
Explore enterprise features