
nerva v1.42.9
Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian
Nerva
Nerva: Fast Service Fingerprinting CLI
Features • Installation • Quick Start • Usage • Protocols • Library • Use Cases • Troubleshooting
High-performance service fingerprinting written in Go. Identify 170+ network protocols across TCP, UDP, and SCTP transports with rich metadata extraction.
Nerva rapidly detects and identifies services running on open network ports. Use it alongside port scanners like Naabu to fingerprint discovered services, or integrate it into your security pipelines for automated reconnaissance.
Features
- 170+ Protocol Plugins — Databases, remote access, web services, messaging, industrial, and telecom protocols
- 76 HTTP Fingerprinters — Detect web technologies including firewalls, databases, AI/LLM servers, and more
- Security Misconfiguration Detection — Identify common security issues like unauthenticated APIs and cleartext protocols (
--misconfigs) - Multi-Transport Support — TCP (default), UDP (
--udp), and SCTP (--sctp, Linux only) - Proxy Support — Route scanning traffic transparently through SOCKS5 or HTTP proxies with configurable DNS resolution
- Rich Metadata — Extract versions, configurations, and security-relevant details from each service
- Fast Mode — Scan only default ports for rapid reconnaissance (
--fast) - Flexible Output — JSON, CSV, or human-readable formats
- Pipeline Friendly — Pipe from Naabu, Nmap, or any tool that outputs
host:port - Go Library — Import directly into your Go applications
Installation
Releases
Download a prebuilt binary from the Releases page.
From GitHub
go install github.com/praetorian-inc/nerva/cmd/nerva@latest
From Source
git clone https://github.com/praetorian-inc/nerva.git
cd nerva
go build ./cmd/nerva
./nerva -h
Docker
git clone https://github.com/praetorian-inc/nerva.git
cd nerva
docker build -t nerva .
docker run --rm nerva -h
docker run --rm nerva -t example.com:80 --json
Quick Start
Fingerprint a single target:
nerva -t example.com:22
# ssh://example.com:22
Get detailed JSON metadata:
nerva -t example.com:22 --json
# {"host":"example.com","ip":"93.184.216.34","port":22,"protocol":"ssh","transport":"tcp","metadata":{...}}
Pipe from a port scanner:
naabu -host example.com -silent | nerva
# http://example.com:80
# ssh://example.com:22
# https://example.com:443
The full reference — every subcommand, alias and flag, including the ones hidden from --help — is generated into docs/CLI.md.
Usage
nerva [flags]
TARGET SPECIFICATION:
Requires host:port or ip:port format. Assumes ports are open.
EXAMPLES:
nerva -t example.com:80
nerva -t example.com:80,example.com:443
nerva -l targets.txt
nerva --json -t example.com:80
cat targets.txt | nerva
Examples
Multiple targets:
nerva -t example.com:22,example.com:80,example.com:443
From file:
nerva -l targets.txt --json -o results.json
UDP scanning (may require root):
sudo nerva -t example.com:53 -U
# dns://example.com:53
SCTP scanning (Linux only):
nerva -t telecom-server:3868 -S
# diameter://telecom-server:3868
Fast mode (default ports only):
nerva -l large-target-list.txt --fast --json
Proxy routing with remote DNS resolution:
nerva -t target.internal:80 --proxy socks5://127.0.0.1:1080 --dns-order p
Security Misconfiguration Detection
Nerva can identify common security misconfigurations when enabled with --misconfigs:
nerva -t example.com:2375 --misconfigs --json
Detected misconfigurations:
| Finding ID | Severity | Description |
|---|---|---|
docker-unauth-api | Critical | Docker API accessible without authentication |
x11-unauth-access | Critical | X11 server allows unauthenticated connections |
smb-signing-not-required | Medium | SMB signing not required (relay attack risk) |
telnet-cleartext | Medium | Telnet transmits credentials in cleartext |
vnc-detected | Medium | VNC detected (often weak authentication) |
ssh-password-auth | Medium | Server allows password authentication |
ssh-weak-cipher | Low | Server offers weak ciphers (RC4, 3DES, Blowfish) |
ssh-weak-kex | Low | Server offers weak key exchange algorithms |
ssh-weak-mac | Low | Server offers weak MAC algorithms |
ftp-cleartext | Low | FTP transmits credentials in cleartext |
Example output with misconfigs:
{
"host": "example.com",
"port": 2375,
"protocol": "docker",
"anonymous_access": true,
"security_findings": [
{
"id": "docker-unauth-api",
"severity": "critical",
"description": "Docker API accessible without authentication",
"evidence": "Successfully queried /version endpoint without credentials"
}
]
}
Proxy Support
Nerva supports routing scanning traffic through SOCKS5 and HTTP proxies with configurable DNS resolution.
Supported proxy schemes:
socks5://- SOCKS5 proxy with local DNS resolutionsocks5h://- SOCKS5 proxy with proxy-side DNS resolution (always)http://- HTTP CONNECT proxyhttps://- HTTPS CONNECT proxy
Proxy authentication:
# Inline authentication (URL format)
nerva -t example.com:80 --proxy socks5://username:[email protected]:1080
# Separate authentication flag
nerva -t example.com:80 --proxy socks5://127.0.0.1:1080 --proxy-auth username:password
DNS resolution strategies (--dns-order):
| Option | Strategy | Use Case |
|---|---|---|
l | Local only | Standard local DNS (default) |
p | Proxy only | Force proxy-side DNS resolution |
lp | Local, fallback to proxy | Try local first, use proxy on failure |
pl | Proxy, fallback to local | Try proxy first, use local on failure |
Note: socks5h:// scheme automatically forces proxy-side DNS (equivalent to --dns-order p)
Tor scanning example:
# Scan .onion services through Tor (SOCKS5 proxy on port 9050)
nerva -t http://example.onion:80 --proxy socks5h://127.0.0.1:9050
UDP through proxy: