高速なYAMLベースの脆弱性スキャナーで、テンプレート駆動型の検出エンジンを備え、Webアプリ、API、ネットワーク、DNS、クラウドインフラストラクチャにわたる自動セキュリティテストを実現します。

Nuclei は、シンプルな YAML ベースのテンプレートを活用する、モダンで高性能な脆弱性スキャナーです。実環境の条件を再現したカスタム脆弱性検出シナリオを設計でき、誤検知をゼロにします。
お使いのマシンに Nuclei をインストールしてください。こちらのインストールガイドに従って始めることができます。さらに、毎月の無料利用枠が豊富な無料クラウドプランも提供しています:
[!Important]
このプロジェクトは活発に開発中です。リリースごとに破壊的変更が発生する可能性があります。アップデート前にリリース ChangeLog を確認してください。 このプロジェクトは主にスタンドアロンの CLI ツールとして使用するように構築されています。nuclei をサービスとして実行すると、セキュリティ上のリスクが生じる可能性があります。 注意して使用し、追加のセキュリティ対策を講じることをお勧めします。
セキュリティチームや企業向けに、Nuclei OSS の上に構築されたクラウドホスティングサービスを提供しています。チームや既存のワークフローを使って、大規模に継続的な脆弱性スキャンを実行できるよう最適化されています:
追加しています!大規模な組織で複雑な要件をお持ちの場合は、Pro にサインアップするか、当社チームにご相談ください。
Nuclei の完全なドキュメントはこちらからご覧いただけます。Nuclei が初めての方は、基礎的な YouTube シリーズもぜひご覧ください。
nuclei のインストールには go >= 1.24.2 が必要です。以下のコマンドを実行してリポジトリを取得してください:
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
nuclei のインストールについて詳しくは https://docs.projectdiscovery.io/tools/nuclei/install を参照してください。
ツールの全フラグを表示するには:
nuclei -h
Nuclei is a fast, template based vulnerability scanner focusing
on extensive configurability, massive extensibility and ease of use.
Usage:
./nuclei [flags]
Flags:
TARGET:
-u, -target string[] target URLs/hosts to scan
-l, -list string path to file containing a list of target URLs/hosts to scan (one per line)
-eh, -exclude-hosts string[] hosts to exclude to scan from the input list (ip, cidr, hostname)
-resume string resume scan from and save to specified file (clustering will be disabled)
-sa, -scan-all-ips scan all the IP's associated with dns record
-iv, -ip-version string[] IP version to scan of hostname (4,6) - (default 4)
TARGET-FORMAT:
-im, -input-mode string mode of input file (list, burp, jsonl, yaml, openapi, swagger) (default "list")
-ro, -required-only use only required fields in input format when generating requests
-sfv, -skip-format-validation skip format validation (like missing vars) when parsing input file