Community template-powered scanning: thousands of one-click CVE and misconfiguration checks, from a CLI that scales from one target to ten thousand.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Templates auto-update โ run -update-templates regularly.
Focused folders = less noise, easier learning.
Pipes beautifully with subfinder + httpx in recon pipelines.
Triage view for sanity during big runs.
Custom templates = turn any 'huh' moment into reusable detection.
| -u / -l | single / list targets |
| -t path | choose templates |
| -tags x | filter by tag |
| -s sev | severity gate |
| -update-templates | fresh checks |
| -o file | save findings |
Template monthly churn is huge: -update-templates weekly.
Bug bounty workflows: subfinder | httpx | nuclei is the classic pipe.
Read 5 templates; YAML format is learnable in an afternoon.
Low false-positives beats high volume โ severity/tag filtering is your friend.
Use Nuclei only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.