Skip to content

Nuclei

Template-driven vulnerability checker

VerifiedPentesting· Vulnerability AssessmentIntermediateMITOpen sourceEntry revised 6 Jan 2026
  • Linux
  • macOS
  • Windows
  • Kali
  • Parrot
  • Docker
  • Source

Overview

5 commands documented

Nuclei executes YAML templates that describe a request and a match condition, so a check is a readable file rather than a binary blob. The templates are the product: they document what is being looked for and can be reviewed before they ever touch a target.

Because the same engine can be pointed at many hosts, discipline is required: run it against assets you own or are authorized to test, prefer low-severity informational templates for sweeps, and verify every hit manually.

Supported platforms

7

Documented install or usage guidance

Learning curve

intermediate

Difficulty of becoming productive, not of the underlying theory

Tags

templates, scanner, http, dast, automation

Dataset entry

nuclei.ts

Reviewed 2026-01-06

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

RecommendedHomebrew
brew install nuclei

Package availability follows your distribution and enabled repositories. Entry revised 6 Jan 2026 — confirm the current release on the project's own download page.

Commands

5 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Check one target with the default template set

bash

Downloads the template repository on first run, then matches each enabled request against the target.

nuclei -u https://app.internal -severity low,info -o findings.txt
  • Some templates send requests that change state. Keep `http/miscellaneous`-style and `cve` templates away from production systems.

Notes

  • `-severity low,info` is the polite default for a first sweep.

02Update the template library

bash

Template coverage changes constantly, so an old library produces old answers.

nuclei -ut

Notes

  • `-nt` creates a new template stub — useful when you need a project-specific check and want to read it before running it.

03Sweep a list with a rate limit

bash

Bounds requests per second so a shared or monitored environment stays usable.

nuclei -l assets.txt -rl 50 -c 25 -timeout 5 -o sweep.txt

Notes

  • `-rl` requests/second, `-c` concurrent hosts, `-bulk` groups paths per request.

04Chain checks with a workflow

bash

Workflows run one template and feed its output into the next, e.g. technology detection then focused checks.

nuclei -u https://app.internal -w workflows/ -id

Notes

  • `-id` prints template IDs, which is what your notes should quote.

05Resume an interrupted run

bash

Keeps a resume directory so a long sweep survives a disconnect.

nuclei -l assets.txt -resume -id

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

No results although the same issue was found manuallyCause 1/3

Possible causes

  • Templates are version-specific; the check may not cover the variant, or requires `-severity` widening.

Usual fix

Read the template you expected to fire (`-t path/to.yaml`) and run it with `-debug` and `-vv` to see whether the matcher condition was met.

Massive false-positive listCause 2/3

Possible causes

  • Informational templates matching generic banners, or an intercepting proxy answering instead of the target.

Usual fix

Verify each match in a browser or with curl, and demote unverified items out of the report. Nuclei output is a queue of hypotheses, not findings.

Rate limiting, 429s or an IPS alertCause 3/3

Possible causes

  • Concurrency far above the environment's tolerance.

Usual fix

Lower `-c` and `-rl`, restrict to `-severity info`, and tell the Blue Team before the run: they should see the traffic.

Tips

  • Point `-dashboard` or `-sr` at your reporting endpoint instead of re-parsing stdout.
  • Write a project-specific template for anything recurring — that turns one-off knowledge into an automated control.
  • Archive the exact template directory with the results; 'found by nuclei' is not reproducible without it.

Alternatives & comparisons

Not documented yet: nuclei is template-driven; nikto and general scanners overlap only partially. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Pentesting