ProjectDiscovery

Detect infrastructure vulnerabilities in real time with customizable templates and low false‑positive rates across multiple protocols.

ProjectDiscovery screenshot 1

ProjectDiscovery Nuclei is an open-source vulnerability scanner that identifies exploitable vulnerabilities by using a template-based approach to simulate real-world attack conditions. The software is primarily deployed as a standalone command-line interface tool, though it can be integrated into broader security workflows to monitor infrastructure for flaws.

Users employ the tool to conduct comprehensive vulnerability assessments, detect subdomain takeovers, and perform dynamic application security testing. It is designed to be integrated into CI/CD pipelines for continuous vulnerability detection and regression testing, ensuring that new deployments do not introduce known security regressions. The tool supports a wide range of input formats for target lists, including standard text files, Burp Suite exports, JSONL, and OpenAPI specifications.

Key features

  • YAML-based templates for creating and customizing vulnerability detection scenarios
  • Support for multiple protocols including TCP, DNS, HTTP, SSL, WHOIS, and JavaScript
  • Parallel scan processing and request clustering for high-speed execution
  • Integration capabilities with Jira, GitHub, Elastic, and GitLab
  • Ability to run templates based on severity, author, or specific tags
  • Automatic web scanning using Wappalyzer technology for tag mapping
  • Support for custom workflows to chain multiple templates together
  • Validation tools to verify template syntax and signatures

The architecture relies on a community-driven template library, where thousands of security professionals contribute YAML files to track trending vulnerabilities. This allows the scanner to adapt quickly to new CVEs without requiring core software updates. The engine is designed to reduce false positives by simulating the exact steps required to verify a vulnerability in a live environment. It is built specifically for pentesters, security teams, and enterprises who need to map their attack surface and verify the presence of specific flaws across large sets of targets.

ProjectDiscovery is a high-performance tool for security automation and vulnerability management.

Last Modified
Software TypeWeb App / Server
Platform
Last Activity14 days ago
Repository Age6 years
LicenseMIT
Open Source Alternative to
Open Source Software.io

Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.