Homebrew
RecommendedHomebrewbrew install nuclei
Template-driven vulnerability checker
Nuclei executes YAML templates that describe a request and a match condition, so a check is a readable file rather than a binary blob. The templates are the product: they document what is being looked for and can be reviewed before they ever touch a target.
Because the same engine can be pointed at many hosts, discipline is required: run it against assets you own or are authorized to test, prefer low-severity informational templates for sweeps, and verify every hit manually.
Supported platforms
7
Documented install or usage guidance
Learning curve
intermediate
Difficulty of becoming productive, not of the underlying theory
Tags
templates, scanner, http, dast, automation
Dataset entry
nuclei.ts
Reviewed 2026-01-06
Grouped by platform. Elevation requirements are marked per method.
brew install nuclei
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
ProjectDiscovery publish an installer; read it before piping to a shell, as with any remote script.
Open official sourcedocker pull projectdiscovery/nuclei:latest
Package availability follows your distribution and enabled repositories. Entry revised 6 Jan 2026 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
Downloads the template repository on first run, then matches each enabled request against the target.
nuclei -u https://app.internal -severity low,info -o findings.txt
Notes
Template coverage changes constantly, so an old library produces old answers.
nuclei -ut
Notes
Bounds requests per second so a shared or monitored environment stays usable.
nuclei -l assets.txt -rl 50 -c 25 -timeout 5 -o sweep.txt
Notes
Workflows run one template and feed its output into the next, e.g. technology detection then focused checks.
nuclei -u https://app.internal -w workflows/ -id
Notes
Keeps a resume directory so a long sweep survives a disconnect.
nuclei -l assets.txt -resume -id
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Read the template you expected to fire (`-t path/to.yaml`) and run it with `-debug` and `-vv` to see whether the matcher condition was met.
Possible causes
Usual fix
Verify each match in a browser or with curl, and demote unverified items out of the report. Nuclei output is a queue of hypotheses, not findings.
Possible causes
Usual fix
Lower `-c` and `-rl`, restrict to `-severity info`, and tell the Blue Team before the run: they should see the traffic.
Not documented yet: nuclei is template-driven; nikto and general scanners overlap only partially. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.