
Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian
Features • Installation • Quick Start • Usage • Protocols • Library • Use Cases • Troubleshooting
High-performance service fingerprinting written in Go. Identify 170+ network protocols across TCP, UDP, and SCTP transports with rich metadata extraction.
Nerva rapidly detects and identifies services running on open network ports. Use it alongside port scanners like Naabu to fingerprint discovered services, or integrate it into your security pipelines for automated reconnaissance.
--misconfigs)--udp), and SCTP (--sctp, Linux only)--fast)host:portDownload a prebuilt binary from the Releases page.
go install github.com/praetorian-inc/nerva/cmd/nerva@latest
git clone https://github.com/praetorian-inc/nerva.git
cd nerva
go build ./cmd/nerva
./nerva -h
git clone https://github.com/praetorian-inc/nerva.git
cd nerva
docker build -t nerva .
docker run --rm nerva -h
docker run --rm nerva -t example.com:80 --json
Fingerprint a single target:
nerva -t example.com:22
# ssh://example.com:22
Get detailed JSON metadata:
nerva -t example.com:22 --json
# {"host":"example.com","ip":"93.184.216.34","port":22,"protocol":"ssh","transport":"tcp","metadata":{...}}
Pipe from a port scanner:
naabu -host example.com -silent | nerva
# http://example.com:80
# ssh://example.com:22
# https://example.com:443
The full reference — every subcommand, alias and flag, including the ones hidden from --help — is generated into docs/CLI.md.
nerva [flags]
TARGET SPECIFICATION:
Requires host:port or ip:port format. Assumes ports are open.
EXAMPLES:
nerva -t example.com:80
nerva -t example.com:80,example.com:443
nerva -l targets.txt
nerva --json -t example.com:80
cat targets.txt | nerva
Multiple targets:
nerva -t example.com:22,example.com:80,example.com:443
From file:
nerva -l targets.txt --json -o results.json
UDP scanning (may require root):
sudo nerva -t example.com:53 -U
# dns://example.com:53
SCTP scanning (Linux only):
nerva -t telecom-server:3868 -S
# diameter://telecom-server:3868
Fast mode (default ports only):
nerva -l large-target-list.txt --fast --json
Proxy routing with remote DNS resolution:
nerva -t target.internal:80 --proxy socks5://127.0.0.1:1080 --dns-order p
Nerva can identify common security misconfigurations when enabled with --misconfigs:
nerva -t example.com:2375 --misconfigs --json
Detected misconfigurations:
| Finding ID | Severity | Description |
|---|---|---|
docker-unauth-api | Critical | Docker API accessible without authentication |
x11-unauth-access | Critical | X11 server allows unauthenticated connections |
smb-signing-not-required | Medium | SMB signing not required (relay attack risk) |
telnet-cleartext | Medium | Telnet transmits credentials in cleartext |
vnc-detected | Medium | VNC detected (often weak authentication) |
ssh-password-auth | Medium | Server allows password authentication |
ssh-weak-cipher | Low | Server offers weak ciphers (RC4, 3DES, Blowfish) |
ssh-weak-kex | Low | Server offers weak key exchange algorithms |
ssh-weak-mac | Low | Server offers weak MAC algorithms |
ftp-cleartext | Low | FTP transmits credentials in cleartext |
Example output with misconfigs:
{
"host": "example.com",
"port": 2375,
"protocol": "docker",
"anonymous_access": true,
"security_findings": [
{
"id": "docker-unauth-api",
"severity": "critical",
"description": "Docker API accessible without authentication",
"evidence": "Successfully queried /version endpoint without credentials"
}
]
}
Nerva supports routing scanning traffic through SOCKS5 and HTTP proxies with configurable DNS resolution.
Supported proxy schemes:
socks5:// - SOCKS5 proxy with local DNS resolutionsocks5h:// - SOCKS5 proxy with proxy-side DNS resolution (always)http:// - HTTP CONNECT proxyhttps:// - HTTPS CONNECT proxyProxy authentication:
# Inline authentication (URL format)
nerva -t example.com:80 --proxy socks5://username:[email protected]:1080
# Separate authentication flag
nerva -t example.com:80 --proxy socks5://127.0.0.1:1080 --proxy-auth username:password
DNS resolution strategies (--dns-order):
| Option | Strategy | Use Case |
|---|---|---|
l | Local only | Standard local DNS (default) |
p | Proxy only | Force proxy-side DNS resolution |
lp | Local, fallback to proxy | Try local first, use proxy on failure |
pl | Proxy, fallback to local | Try proxy first, use local on failure |
Note: socks5h:// scheme automatically forces proxy-side DNS (equivalent to --dns-order p)
Tor scanning example:
# Scan .onion services through Tor (SOCKS5 proxy on port 9050)
nerva -t http://example.onion:80 --proxy socks5h://127.0.0.1:9050
UDP through proxy: