awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
projectdiscovery avatar

projectdiscovery/nuclei-templates

0
View on GitHub↗
12,518 stars·3,528 forks·JavaScript·MIT·16 viewsgithub.com/projectdiscovery/nuclei↗

Nuclei Templates

Nuclei-templates is a security automation framework and vulnerability scanning library designed for the continuous assessment of distributed infrastructure. It functions as a collection of structured configuration files that define how to identify security flaws and misconfigurations across web applications and network services.

The project utilizes a declarative domain-specific language to decouple detection logic from the underlying execution engine. This approach allows for the creation of modular, protocol-agnostic scanning rules that can be updated independently of the core software. By employing pattern matching and sequential validation pipelines, the templates enable precise identification of vulnerabilities while minimizing false positives.

The library supports the entire lifecycle of security testing, from the initial development and verification of custom detection rules to the execution of automated scans against production environments. Users can define complex request sequences and integrate runtime data to perform context-aware security analysis across diverse network protocols.

Features

  • Security Assessment Frameworks - Provides a modular framework for automated security testing and continuous vulnerability assessment of distributed infrastructure.
  • Vulnerability Scanners - Automates security checks across network services to identify known vulnerabilities and misconfigurations.
  • Infrastructure Security Scanners - Executes protocol-specific requests and validation logic to detect potential security flaws in target systems at scale.
  • Scanning Template Libraries - Provides a collection of structured YAML configurations for identifying security vulnerabilities and misconfigurations.
  • Configuration-Driven Scanning Engines - Uses declarative configuration files to define and execute multi-step automated security workflows.
  • Protocol Security Testers - Validates the security posture of various network protocols by crafting custom requests and verification logic.
  • Vulnerability Check Definitions - Enables the definition of structured network requests and validation logic to identify security flaws.
  • Exploit Proofs of Concept - Collection of vulnerability scanning templates.
  • Infrastructure Scanners - Community-driven library of vulnerability detection templates for infrastructure scanning.
  • Vulnerability Scanners - Community-curated templates for vulnerability scanning.
  • Protocol Abstraction Layers - Decouples transport and protocol modules to enable modular security scanning across diverse network services.
  • Security Detection Logic - Provides frameworks for creating and maintaining structured detection logic to standardize security flaw identification.
  • Security Monitoring - Runs automated security assessments against production environments to detect emerging threats and ensure compliance.
  • Declarative Configuration Languages - Provides a domain-specific language for defining complex network request sequences and validation logic.
  • Security Automation Templates - Supports the creation of custom scanning logic and protocol-specific request sequences via declarative configuration files.
  • Template Validators - Verifies scanning configurations in real-time to ensure high accuracy before production deployment.
  • Validation Pipelines - Executes sequences of security checks and validation steps to ensure accuracy and minimize false positives during automated analysis.
  • Runtime Variable Injections - Populates scanning templates with runtime data and target-specific parameters to enable flexible and context-aware security testing.
  • Regex Pattern Matchers - Analyzes server responses using regular expression patterns to identify vulnerabilities with high precision.

Star history

Star history chart for projectdiscovery/nuclei-templatesStar history chart for projectdiscovery/nuclei-templates

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Nuclei Templates

Similar open-source projects, ranked by how many features they share with Nuclei Templates.
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Goattack-surfacecve-scannerdast
    View on GitHub↗29,189
  • projectdiscovery/subfinderprojectdiscovery avatar

    projectdiscovery/subfinder

    13,105View on GitHub↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Gobugbountyhackinghacktoberfest
    View on GitHub↗13,105
  • chaitin/xraychaitin avatar

    chaitin/xray

    11,612View on GitHub↗

    Xray is a security assessment tool focused on web vulnerability scanning, attack surface mapping, and technology fingerprinting. It identifies common security flaws through automated scanning and semantic analysis, while verifying findings via a custom proof-of-concept execution engine. The system distinguishes itself with a containerized vulnerability testbed used to deploy pre-configured vulnerable applications. This environment allows for the simulation of specific vulnerabilities and edge-case scenarios to validate scanner accuracy and eliminate false positives. The platform covers a bro

    Vuepassive-vulnerability-scannerpocsecurity
    View on GitHub↗11,612
  • sullo/niktosullo avatar

    sullo/nikto

    10,104View on GitHub↗

    Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a reconnaissance engine designed to identify insecure server options, outdated software, and common vulnerabilities by analyzing HTTP responses. The project differentiates itself through capabilities for intrusion detection evasion and web server fingerprinting. It uses request-level encoding and timing spacers to bypass security filters and employs signature-based identification to determine specific server software versions and misconfigurations. The scanner covers broad capability are

    Perl
    View on GitHub↗10,104
See all 30 alternatives to Nuclei Templates→

Frequently asked questions

What does projectdiscovery/nuclei-templates do?

Nuclei-templates is a security automation framework and vulnerability scanning library designed for the continuous assessment of distributed infrastructure. It functions as a collection of structured configuration files that define how to identify security flaws and misconfigurations across web applications and network services.

What are the main features of projectdiscovery/nuclei-templates?

The main features of projectdiscovery/nuclei-templates are: Security Assessment Frameworks, Vulnerability Scanners, Infrastructure Security Scanners, Scanning Template Libraries, Configuration-Driven Scanning Engines, Protocol Security Testers, Vulnerability Check Definitions, Exploit Proofs of Concept.

What are some open-source alternatives to projectdiscovery/nuclei-templates?

Open-source alternatives to projectdiscovery/nuclei-templates include: projectdiscovery/nuclei — Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure… projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… chaitin/xray — Xray is a security assessment tool focused on web vulnerability scanning, attack surface mapping, and technology… sullo/nikto — Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a… projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… shadow1ng/fscan — Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability…