Back to updates
New releaseJul 22, 2026

nerva v1.42.9

Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian

Share
Nerva - Fast service fingerprinting CLI for network reconnaissance supporting 170+ protocols

Nerva
Nerva: Fast Service Fingerprinting CLI

Release Build Status Go Report Card License Stars

Features • Installation • Quick Start • Usage • Protocols • Library • Use Cases • Troubleshooting

High-performance service fingerprinting written in Go. Identify 170+ network protocols across TCP, UDP, and SCTP transports with rich metadata extraction.

Nerva rapidly detects and identifies services running on open network ports. Use it alongside port scanners like Naabu to fingerprint discovered services, or integrate it into your security pipelines for automated reconnaissance.

Features

  • 170+ Protocol Plugins — Databases, remote access, web services, messaging, industrial, and telecom protocols
  • 76 HTTP Fingerprinters — Detect web technologies including firewalls, databases, AI/LLM servers, and more
  • Security Misconfiguration Detection — Identify common security issues like unauthenticated APIs and cleartext protocols (--misconfigs)
  • Multi-Transport Support — TCP (default), UDP (--udp), and SCTP (--sctp, Linux only)
  • Proxy Support — Route scanning traffic transparently through SOCKS5 or HTTP proxies with configurable DNS resolution
  • Rich Metadata — Extract versions, configurations, and security-relevant details from each service
  • Fast Mode — Scan only default ports for rapid reconnaissance (--fast)
  • Flexible Output — JSON, CSV, or human-readable formats
  • Pipeline Friendly — Pipe from Naabu, Nmap, or any tool that outputs host:port
  • Go Library — Import directly into your Go applications

Installation

Releases

Download a prebuilt binary from the Releases page.

From GitHub

go install github.com/praetorian-inc/nerva/cmd/nerva@latest

From Source

git clone https://github.com/praetorian-inc/nerva.git
cd nerva
go build ./cmd/nerva
./nerva -h

Docker

git clone https://github.com/praetorian-inc/nerva.git
cd nerva
docker build -t nerva .
docker run --rm nerva -h
docker run --rm nerva -t example.com:80 --json

Quick Start

Fingerprint a single target:

nerva -t example.com:22
# ssh://example.com:22

Get detailed JSON metadata:

nerva -t example.com:22 --json
# {"host":"example.com","ip":"93.184.216.34","port":22,"protocol":"ssh","transport":"tcp","metadata":{...}}

Pipe from a port scanner:

naabu -host example.com -silent | nerva
# http://example.com:80
# ssh://example.com:22
# https://example.com:443

The full reference — every subcommand, alias and flag, including the ones hidden from --help — is generated into docs/CLI.md.

Usage

nerva [flags]

TARGET SPECIFICATION:
  Requires host:port or ip:port format. Assumes ports are open.

EXAMPLES:
  nerva -t example.com:80
  nerva -t example.com:80,example.com:443
  nerva -l targets.txt
  nerva --json -t example.com:80
  cat targets.txt | nerva

Examples

Multiple targets:

nerva -t example.com:22,example.com:80,example.com:443

From file:

nerva -l targets.txt --json -o results.json

UDP scanning (may require root):

sudo nerva -t example.com:53 -U
# dns://example.com:53

SCTP scanning (Linux only):

nerva -t telecom-server:3868 -S
# diameter://telecom-server:3868

Fast mode (default ports only):

nerva -l large-target-list.txt --fast --json

Proxy routing with remote DNS resolution:

nerva -t target.internal:80 --proxy socks5://127.0.0.1:1080 --dns-order p

Security Misconfiguration Detection

Nerva can identify common security misconfigurations when enabled with --misconfigs:

nerva -t example.com:2375 --misconfigs --json

Detected misconfigurations:

Finding IDSeverityDescription
docker-unauth-apiCriticalDocker API accessible without authentication
x11-unauth-accessCriticalX11 server allows unauthenticated connections
smb-signing-not-requiredMediumSMB signing not required (relay attack risk)
telnet-cleartextMediumTelnet transmits credentials in cleartext
vnc-detectedMediumVNC detected (often weak authentication)
ssh-password-authMediumServer allows password authentication
ssh-weak-cipherLowServer offers weak ciphers (RC4, 3DES, Blowfish)
ssh-weak-kexLowServer offers weak key exchange algorithms
ssh-weak-macLowServer offers weak MAC algorithms
ftp-cleartextLowFTP transmits credentials in cleartext

Example output with misconfigs:

{
  "host": "example.com",
  "port": 2375,
  "protocol": "docker",
  "anonymous_access": true,
  "security_findings": [
    {
      "id": "docker-unauth-api",
      "severity": "critical",
      "description": "Docker API accessible without authentication",
      "evidence": "Successfully queried /version endpoint without credentials"
    }
  ]
}

Proxy Support

Nerva supports routing scanning traffic through SOCKS5 and HTTP proxies with configurable DNS resolution.

Supported proxy schemes:

  • socks5:// - SOCKS5 proxy with local DNS resolution
  • socks5h:// - SOCKS5 proxy with proxy-side DNS resolution (always)
  • http:// - HTTP CONNECT proxy
  • https:// - HTTPS CONNECT proxy

Proxy authentication:

# Inline authentication (URL format)
nerva -t example.com:80 --proxy socks5://username:[email protected]:1080

# Separate authentication flag
nerva -t example.com:80 --proxy socks5://127.0.0.1:1080 --proxy-auth username:password

DNS resolution strategies (--dns-order):

OptionStrategyUse Case
lLocal onlyStandard local DNS (default)
pProxy onlyForce proxy-side DNS resolution
lpLocal, fallback to proxyTry local first, use proxy on failure
plProxy, fallback to localTry proxy first, use local on failure

Note: socks5h:// scheme automatically forces proxy-side DNS (equivalent to --dns-order p)

Tor scanning example:

# Scan .onion services through Tor (SOCKS5 proxy on port 9050)
nerva -t http://example.onion:80 --proxy socks5h://127.0.0.1:9050

UDP through proxy:

Categories