awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
projectdiscovery avatar

projectdiscovery/nuclei

0
View on GitHub↗
29,189 stars·3,492 forks·Go·MIT·17 viewsdocs.projectdiscovery.io/tools/nuclei↗

Nuclei

Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets.

The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integrates advanced reconnaissance capabilities, including cloud infrastructure assessment, subdomain discovery, and technology fingerprinting, into a unified workflow that can be orchestrated via a command-line interface or programmatic API.

Beyond core scanning, the project provides a comprehensive suite of tools for external attack surface management, including asset inventorying, visual evidence capture, and automated ticketing integration. It supports collaborative security operations through team workspaces, centralized template management, and real-time alerting, ensuring that vulnerability findings can be tracked, verified, and remediated within a single environment.

The platform is distributed as a command-line utility and supports containerized execution, enabling integration into existing CI/CD pipelines and automated security workflows.

Features

  • Configuration-Driven Scanning Engines - Executes modular security checks by interpreting YAML-based definitions to perform automated vulnerability detection.
  • Vulnerability Scanners - Provides an automated engine that executes security checks across diverse network protocols to identify vulnerabilities and misconfigurations.
  • Automated Security Scanners - Provides a high-performance engine for identifying security weaknesses and misconfigurations across large-scale network environments.
  • Vulnerability Assessment Frameworks - Provides a modular framework for automating vulnerability detection and infrastructure reconnaissance using customizable templates.
  • Vulnerability Scanning - Executes automated security checks against web applications and network infrastructure to identify vulnerabilities.
  • Distributed Scanning Agents - Orchestrates parallel security assessments across multiple nodes for large-scale discovery.
  • Scan Orchestration - Executes, schedules, and configures automated vulnerability assessments while managing import and export workflows for scan data.
  • Attack Surface Management - Maps and monitors internet-facing assets, subdomains, and cloud infrastructure to maintain a comprehensive view of organizational exposure.
  • Digital Footprint Mappers - Identifies internet-facing infrastructure by analyzing DNS records, security certificates, and third-party data sources to visualize an organization's complete online presence.
  • Subdomain Enumeration Tools - Identifies subdomains by testing combinations of domain names and wordlists against target infrastructure.
  • Vulnerability Ticketing Integrators - Creates and updates tickets in external management platforms based on detected vulnerabilities to streamline the remediation process.
  • Cloud Infrastructure Management - Connects to cloud providers to continuously track assets, identify exposed services, and detect risky configurations.
  • Asset Discovery Tools - Orchestrates multi-step discovery workflows including DNS resolution, port scanning, and endpoint crawling to map attack surfaces.
  • Security Automation Templates - Fetches security scanning templates from remote repositories to automate vulnerability detection.
  • AI Template Generators - Uses artificial intelligence to convert vulnerability proof-of-concept data into structured scanning templates for automated security testing.
  • Security Orchestration - Centralizes the management of automated vulnerability assessments, team collaboration, and integration with external ticketing workflows.
  • Out-of-Band Interaction Monitoring - Captures asynchronous network callbacks to identify blind vulnerabilities that do not produce immediate responses.
  • Template Synchronization - Integrates community-contributed detection templates to provide real-time coverage against emerging vulnerabilities and trending exploits.
  • Out-of-Band Testing - Detects blind vulnerabilities by capturing asynchronous network interactions triggered by security probes.
  • Interaction Monitoring - Captures asynchronous network callbacks from targets to identify blind vulnerabilities that do not produce immediate HTTP responses.
  • Headless Browser Orchestrators - Uses headless browser automation to render dynamic web content and discover endpoints.
  • Reconnaissance and Discovery - Fast vulnerability scanner based on simple YAML templates.
  • Vulnerability Scanners - Configurable targeted scanning based on templates.
  • Vulnerability Scanning - Template-based scanner for finding known vulnerabilities.
  • Web Application Scanners - Template-based scanner for fast, targeted vulnerability discovery.
  • Dynamic Analysis - Template-based security scanning for web applications.
  • Exploitation Tools - Fast, template-based vulnerability scanner for web targets.
  • Infrastructure Scanners - Fast, template-based vulnerability scanner for infrastructure and web services.
  • Network Reconnaissance - Executes customizable vulnerability scans using YAML-based templates.
  • Security and Auditing - Vulnerability scanner using YAML templates.
  • Security Testing - Automated scanner for identifying common site vulnerabilities.
  • Vulnerability Assessment - Template-based vulnerability scanning for web and infrastructure.
  • Vulnerability Auditing - Fast, template-based targeted scanning for security issues.
  • Vulnerability Exploitation Tools - Fast, template-based vulnerability scanner.
  • Vulnerability Scanners - Fast, customizable vulnerability scanner using YAML-based templates.
  • Cloud Infrastructure - Evaluates cloud environments for misconfigured resources, overly permissive access settings, and exposed assets across major cloud providers.
  • Cloud Synchronizers - Imports and maintains an up-to-date inventory of assets by connecting directly to cloud provider accounts for automated discovery.
  • Relationship Visualizers - Maps connections between domains, IP ranges, and cloud services to identify complex attack paths.
  • Private Template Managers - Uploads custom security scanning definitions to a remote platform to organize and store vulnerability detection logic for private use.
  • Vulnerability Databases - Provides comprehensive vulnerability details including severity and remediation steps.
  • Exploitability Validation - Simulates real-world attacks at runtime to confirm that identified vulnerabilities are actually exploitable, reducing false positives.
  • Interaction Capturers - Intercepts and logs network interactions across subdomains for comprehensive security monitoring.
  • Profile Categorizers - Analyzes raw infrastructure data using technology fingerprinting and visual snapshots to create detailed records for discovered network assets.
  • Scan Data Importers - Consolidates vulnerability findings by importing scan data from external sources.
  • Automation Triggers - Triggers security assessments via REST API for integration into CI/CD pipelines and automated workflows.
  • DNS Reconnaissance - Retrieves comprehensive internet-wide DNS datasets to assist in asset discovery and reconnaissance.
  • Domain Filtering Engines - Filters false-positive subdomains by detecting wildcard patterns and tracking resolution frequency.
  • Inbound Connection Managers - Hosts network protocols to capture and log inbound connection attempts for security analysis.
  • Port Scanners - Identifies active ports on target hosts or networks using SYN, CONNECT, or UDP probes to determine service availability.
  • Credential Rotators - Generates a new authentication key for the user account and invalidates the previous one to maintain secure access.
  • API Key Authentication - Creates unique API keys for user accounts to enable programmatic access to platform services.
  • AI Generation - Creates custom vulnerability detection templates by processing natural language descriptions through an integrated artificial intelligence engine.
  • Integrated Editors - Provides an integrated development environment for writing, modifying, and validating security detection logic with syntax highlighting and linting tools.
  • Brute Force Tools - Systematically tests potential hostnames against target domains to discover subdomains.
  • Web Asset Probing - Identifies and inspects web services across specified ports and protocols by performing automated HTTP and HTTPS connectivity checks.
  • Web Path Bruteforcing - Probes specific URL paths across multiple targets to discover hidden endpoints, unsecured files, or administrative interfaces.
  • Event-Driven Architectures - Processes scan results through non-blocking queues for real-time alerting and integration.
  • Headless Browsers - Uses headless browser engines to render dynamic web content and extract data during reconnaissance.
  • Web Crawling - Navigates and discovers web application endpoints by following links and parsing content.
  • Team Collaboration Management - Organizes users into teams with defined roles to control access to security resources.
  • Asset Inventory Management - Categorizes infrastructure using automated tagging or custom labels to streamline management and risk prioritization.
  • External Tool Integrations - Wraps third-party security tools to extend protocol coverage and interaction monitoring.
  • Template Management Systems - Manages the lifecycle of security templates, including removal from storage.
  • Containerized Execution - Supports running security scans within isolated container environments to ensure consistent execution.
  • Domain Correlation - Identifies related organizational assets by correlating certificate transparency logs and registration records.
  • Scan Result Exporters - Provides a centralized interface to filter, export, and manage vulnerability findings, including retesting capabilities to verify fixes.
  • Template Management - Stores and synchronizes security detection logic in a centralized cloud repository for consistent access and team collaboration.
  • Programmatic Managers - Automates the addition and organization of monitored targets by interacting with a REST API for integration into existing workflows.
  • Network Protocols - Performs DNS resolution, TLS inspection, and service probing to analyze network endpoint configurations.
  • DNS Resolution - Queries DNS records like A, CNAME, and PTR to verify connectivity and gather infrastructure metadata.
  • Network and Server Infrastructure - Analyzes TLS configurations, ASN affiliations, and favicon hashes to categorize and map the underlying technology stack of target web servers.
  • Authentication Security Policies - Enforces password-based authentication and multi-factor verification requirements to protect user account access.
  • Credential Monitoring Services - Tracks and alerts on exposed sensitive information and compromised credentials to identify potential security breaches.
  • Credential Retrieval Tools - Fetches unique security keys for authenticated users to authorize requests and manage remote scanning operations.
  • Credential Revocation - Invalidates existing authentication keys to prevent further access to platform services.
  • Origin Exposure Detection - Identifies when proxied DNS or CDN records inadvertently reveal the underlying origin IP address of a protected service.
  • Security Monitoring - Detects and tracks exposed sensitive information to identify potential security breaches.
  • Web Technology Detection - Extracts page titles, status codes, and technology signatures from web responses to profile the software and frameworks running on target endpoints.
  • Download Throughput Controls - Controls the speed and intensity of requests using concurrency, parallelism, and rate-limiting settings to avoid triggering security blocks.
  • Automated Fix Verifiers - Verifies security fixes through automated retesting to ensure vulnerabilities are resolved.
  • Plugin-Based Architectures - Wraps various network protocols and third-party tools into a unified interface to extend scanning capabilities.
  • Screenshot Capture - Renders target web pages using a headless browser to generate screenshots and extract the DOM for visual analysis.

Star history

Star history chart for projectdiscovery/nucleiStar history chart for projectdiscovery/nuclei

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does projectdiscovery/nuclei do?

Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets.

What are the main features of projectdiscovery/nuclei?

The main features of projectdiscovery/nuclei are: Configuration-Driven Scanning Engines, Vulnerability Scanners, Automated Security Scanners, Vulnerability Assessment Frameworks, Vulnerability Scanning, Distributed Scanning Agents, Scan Orchestration, Attack Surface Management.

What are some open-source alternatives to projectdiscovery/nuclei?

Open-source alternatives to projectdiscovery/nuclei include: projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… six2dez/reconftw — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the… zan8in/afrog — afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… projectdiscovery/nuclei-templates — Nuclei-templates is a security automation framework and vulnerability scanning library designed for the continuous…

Open-source alternatives to Nuclei

Similar open-source projects, ranked by how many features they share with Nuclei.
  • projectdiscovery/subfinderprojectdiscovery avatar

    projectdiscovery/subfinder

    13,105View on GitHub↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Gobugbountyhackinghacktoberfest
    View on GitHub↗13,105
  • projectdiscovery/naabuprojectdiscovery avatar

    projectdiscovery/naabu

    5,766View on GitHub↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Gocdn-exclusionhacktoberfestnmap
    View on GitHub↗5,766
  • six2dez/reconftwsix2dez avatar

    six2dez/reconftw

    7,226View on GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    View on GitHub↗7,226
  • zan8in/afrogzan8in avatar

    zan8in/afrog

    4,182View on GitHub↗

    afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points. The project provides a framework for out-of-band security testing, detecting blind vulnerabilities by triggering and verifying external DNS or HTTP callbacks. Beyond web traffic, it includes a protocol fuzzer capable of executing multi-step read and write sequences over raw TCP and SSL sockets to identify

    Goafrogbug-bountypenetration-testing
    View on GitHub↗4,182
See all 30 alternatives to Nuclei→