基于 YAML 的快速漏洞扫描器,采用模板驱动的检测引擎,可对 Web 应用、API、网络、DNS 和云基础设施进行自动化安全测试。

Nuclei 是一款现代化的高性能漏洞扫描器,基于简单的 YAML 模板。它让您能够设计模拟真实场景的自定义漏洞检测方案,从而实现零误报。
在您的机器上安装 Nuclei。请按照此处的安装指南开始使用。此外,我们还提供免费的云服务套餐,并附带慷慨的每月免费额度:
[!Important]
本项目正在积极开发中。每个版本都可能带来破坏性变更。更新前请阅读发布说明。 本项目主要用作独立的 CLI 工具。将 nuclei 作为服务运行可能会带来安全风险。 建议谨慎使用并采取额外的安全防护措施。
针对安全团队和企业,我们提供了构建在 Nuclei OSS 之上的云托管服务,专门优化以帮助您的团队按现有工作流程持续、大规模地运行漏洞扫描:
增加新功能!如果您所在的组织规模较大或需求较复杂,请注册 Pro或与我们的团队联系。
请浏览 Nuclei 的完整文档。如果您刚接触 Nuclei,可以观看我们的基础 YouTube 系列教程。
nuclei 需要 go >= 1.24.2 才能成功安装。运行以下命令获取仓库:
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
要了解更多关于安装 nuclei 的信息,请参阅 https://docs.projectdiscovery.io/tools/nuclei/install。
显示该工具所有的参数:
nuclei -h
Nuclei is a fast, template based vulnerability scanner focusing
on extensive configurability, massive extensibility and ease of use.
Usage:
./nuclei [flags]
Flags:
TARGET:
-u, -target string[] target URLs/hosts to scan
-l, -list string path to file containing a list of target URLs/hosts to scan (one per line)
-eh, -exclude-hosts string[] hosts to exclude to scan from the input list (ip, cidr, hostname)
-resume string resume scan from and save to specified file (clustering will be disabled)
-sa, -scan-all-ips scan all the IP's associated with dns record
-iv, -ip-version string[] IP version to scan of hostname (4,6) - (default 4)
TARGET-FORMAT:
-im, -input-mode string mode of input file (list, burp, jsonl, yaml, openapi, swagger) (default "list")
-ro, -required-only use only required fields in input format when generating requests
-sfv, -skip-format-validation skip format validation (like missing vars) when parsing input file