nikto-nuclei-web-scanner-cheatsheets.md (35123B)
1 --- 2 title: "Nikto & Nuclei - Web Scanner Cheatsheets" 3 description: "sudo apt-get install nikto" 4 category: enumeration 5 tags: ["enumeration"] 6 tools: ["Nmap", "Nuclei", "Nikto", "Metasploit"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Enumeration/Nikto & Nuclei - Web Scanner Cheatsheets.md" 10 --- 11 # Nikto 12 13 --- 14 15 ## Install & Update 16 17 ```bash 18 # Kali / Debian / Ubuntu 19 sudo apt-get install nikto 20 21 # Git clone — latest code (v2.5.0+) 22 git clone https://github.com/sullo/nikto 23 cd nikto/program && perl nikto.pl -Help 24 25 # Docker — no local Perl required 26 docker pull sullo/nikto 27 docker run --rm sullo/nikto -h <target> 28 29 # Update plugin/signature database 30 nikto -update 31 32 # Verify installation and check DB integrity 33 nikto -Version 34 nikto -dbcheck 35 ``` 36 37 > [!info]+ Command Breakdown 38 > 1. **apt-get install nikto** — installs the packaged version; may lag behind upstream releases 39 > 2. **git clone** — always pulls the latest v2.5.0+ code; preferred for up-to-date signatures 40 > 3. **docker pull/run** — fully self-contained; no Perl dependency on the host 41 > 4. **-update** — syncs the vulnerability plugin and signature database; run before every engagement 42 > 5. **-dbcheck** — syntax-validates DB files; run after updates to confirm integrity 43 44 --- 45 46 ## Basic Web Scan 47 48 ```bash 49 # Standard HTTP scan 50 nikto -h http://192.168.1.10 51 52 # Specify port 53 nikto -h <host> -p <port> 54 55 # Force HTTPS 56 nikto -h <host> -ssl 57 58 # Multiple ports 59 nikto -h <host> -p 80,443,8080 60 61 # Bulk scan from file (one host per line) 62 nikto -h hosts.txt 63 64 # HTTPS on non-standard port 65 nikto -h 192.168.1.10 -p 8443 -ssl 66 67 # Authenticated scan with virtual host override 68 nikto -h http://192.168.1.10 -id admin:admin -vhost internal.corp.local 69 70 # Scan host list with 2s delay, abort after 10 min 71 nikto -h hosts.txt -Pause 2 -maxtime 600s 72 73 # Route all traffic through Burp Suite 74 nikto -h http://10.10.10.10 -useproxy http://127.0.0.1:8080 75 76 # Spoof User-Agent 77 nikto -h http://10.10.10.10 -useragent "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" 78 ``` 79 80 > [!info]+ Key Flags Reference 81 82 | Flag | Description | Default | 83 |---|---|---| 84 | `-h` | Target host / IP / URL | — | 85 | `-p` | Port(s), comma-sep or range | 80 | 86 | `-ssl` | Force HTTPS | off | 87 | `-nossl` | Force HTTP | off | 88 | `-id user:pass[:realm]` | HTTP Basic / NTLM auth | — | 89 | `-vhost HOSTNAME` | Override `Host:` header | — | 90 | `-useproxy http://IP:PORT` | Route via HTTP proxy | off | 91 | `-useragent "STRING"` | Spoof User-Agent | Nikto/version | 92 | `-root /path/` | Prepend path to all requests | — | 93 | `-timeout N` | Per-request timeout (seconds) | 10 | 94 | `-Pause N` | Delay between tests (seconds) | 0 | 95 | `-maxtime Ns` | Abort entire scan after N seconds | none | 96 | `-no404` | Disable 404 page guessing | off | 97 | `-nointeractive` | Suppress interactive prompts | off | 98 | `-nolookup` | Skip DNS lookups | off | 99 | `-Plugins "all"` | Run all plugins | ALL | 100 | `-list-plugins` | List available plugins | — | 101 | `-update` | Update plugins/signatures | — | 102 | `-dbcheck` | Syntax-check DB files | — | 103 104 > [!info]+ Output Interpretation 105 > 1. **`+ OSVDB-XXXX`** — known vulnerability reference; always verify before reporting 106 > 2. **`+ Server: Apache/2.2.x`** — outdated version detected; cross-check [NVD](https://nvd.nist.gov/)/CVE 107 > 3. **`+ /admin/` returning 200** — exposed panel; investigate access controls 108 > 4. **`+ OPTIONS: PUT, DELETE`** — dangerous HTTP methods enabled; test for write access 109 > 5. **`+ X-Frame-Options header not set`** — potential [clickjacking](https://owasp.org/www-community/attacks/Clickjacking); note for report 110 111 > [!warning]+ OPSEC / Detection Notes 112 > 6. Default UA `Mozilla/5.00 (Nikto/2.x.x)` is trivially flagged by any WAF — always spoof with `-useragent` 113 > 7. Even with UA spoofing, the sequential probe pattern (`/.git`, `/admin`, `/cgi-bin` etc.) is a strong fingerprint 114 > 8. Every request appears in `access.log` and `error.log`; WAF rules will trigger 115 > 9. `-Pause` adds delay but does **not** randomise order — rate-based detection still fires 116 > 10. **No stealth mode exists** — treat all Nikto scans as loud/noisy 117 > 11. Use `-Tuning b` (software ID only) for the lowest-footprint option 118 119 > [!failure]+ Common Errors 120 121 | Error | Fix | 122 |---|---| 123 | `ERROR: Cannot open db_tests` | Re-clone repo or run as root; run `-update` | 124 | SSL handshake failure | Explicitly add `-ssl` or `-nossl` | 125 | Scan completes with 0 findings | Target unreachable; verify with `curl` first | 126 | `No plugin found` | Run `nikto -list-plugins` to confirm name | 127 | Perl module missing | `cpan install Net::SSLeay` for SSL support | 128 | IPv6 target not resolving | Add `-ipv6` flag explicitly | 129 130 --- 131 132 ## Tuning & Targeted Checks 133 134 > [!faq]+ What is Tuning? 135 > Tuning narrows scans to specific vulnerability classes — reduces noise, cuts scan time, and lowers detection surface. Combine multiple codes in a single string (e.g. `-Tuning 49` = XSS + SQLi). 136 137 > [!info]+ Tuning Code Reference 138 139 | Code | Check Type | 140 |---|---| 141 | `0` | File upload | 142 | `1` | Interesting files / seen in logs | 143 | `2` | Misconfiguration / default files | 144 | `3` | Information disclosure | 145 | `4` | Injection (XSS / Script / HTML) | 146 | `5` | Remote file retrieval (inside web root) | 147 | `6` | Denial of service ⚠️ may break services | 148 | `7` | Remote file retrieval (server-wide) | 149 | `8` | Command execution / remote shell | 150 | `9` | SQL injection | 151 | `a` | Authentication bypass | 152 | `b` | Software identification | 153 | `c` | Remote source inclusion | 154 | `x` | Reverse — run ALL except listed codes | 155 156 ```bash 157 # XSS + SQLi only 158 nikto -h http://10.10.10.10 -Tuning 49 159 160 # Info disclosure + misconfiguration 161 nikto -h http://10.10.10.10 -Tuning 23 162 163 # Auth bypass + command execution 164 nikto -h http://10.10.10.10 -Tuning a8 165 166 # All checks EXCEPT denial of service 167 nikto -h http://10.10.10.10 -Tuning x6 168 169 # Software ID only — lowest footprint 170 nikto -h http://10.10.10.10 -Tuning b 171 172 # Full sweep minus DoS, save as JSON 173 nikto -h http://10.10.10.10 -Tuning x6 -o results.json -Format json 174 ``` 175 176 > [!info]+ Command Breakdown 177 > 1. **Tuning codes are combined as a string** — `-Tuning 49` runs codes `4` AND `9` simultaneously 178 > 2. **`x` reversal prefix** — `-Tuning x6` runs everything *except* DoS; safest full-scan option 179 > 3. **`b` alone** — software identification only; quietest possible scan; good for initial fingerprinting 180 > 4. *Combining `-Tuning` with `-o` and `-Format json` captures structured results for later analysis* 181 182 > [!danger]+ Tuning Code 6 — Denial of Service 183 > Code `6` can cause **service disruption** on the target. Exclude with `-Tuning x6` unless DoS testing is explicitly authorised in your scope agreement. 184 185 > [!warning]+ OPSEC Note 186 > Multiple tuning codes still execute many sequential requests — the pattern remains recognisable to IDS/WAF regardless of which codes are selected. 187 188 --- 189 190 ## Evasion Techniques 191 192 > [!warning]+ Effectiveness Warning 193 > Nikto evasion codes provide **very limited bypass** against modern WAFs (Cloudflare, ModSecurity v3). Request volume is unchanged — rate/volume-based detection still fires. Best combined with `-Pause`, narrow `-Tuning`, and UA spoofing. 194 195 > [!info]+ Evasion Code Reference 196 197 | Code | Technique | 198 |---|---| 199 | `1` | Random URI encoding (non-UTF8) | 200 | `2` | Directory self-reference `/./` | 201 | `3` | Premature URL ending | 202 | `4` | Prepend long random string | 203 | `5` | Fake URL parameter | 204 | `6` | TAB as request spacer | 205 | `7` | Change case of URL | 206 | `8` | Windows path separator `\` | 207 | `A` | Carriage return as request spacer | 208 | `B` | Binary value `0x0b` as request spacer | 209 210 ```bash 211 # Random URI encoding 212 nikto -h http://10.10.10.10 -evasion 1 213 214 # URI encoding + case change combined 215 nikto -h http://10.10.10.10 -evasion 17 216 217 # Targeted scan + evasion combo + slow down 218 nikto -h http://10.10.10.10 -Tuning 49 -evasion 12 -Pause 1 219 ``` 220 221 > [!info]+ Command Breakdown 222 > 1. **Evasion codes combine as a string** — `-evasion 17` applies codes `1` AND `7` simultaneously 223 > 2. **`-evasion 12 -Pause 1`** — encoding + directory self-reference with 1s delay; reduces scan velocity 224 > 3. *Pairing narrow `-Tuning` with evasion codes and UA spoofing is the closest Nikto gets to low-noise operation* 225 226 --- 227 228 ## Output Formats & Nmap Integration 229 230 > [!info]+ Supported Output Formats (`-Format`) 231 232 | Code | Type | Notes | 233 |---|---|---| 234 | `txt` | Plain text | Default if no extension match | 235 | `csv` | Comma-separated | Good for spreadsheet / Splunk import | 236 | `json` | JSON | v2.5.0+ native; best for pipelines | 237 | `xml` | XML | Vuln management tool import | 238 | `htm` | HTML | Human-readable client report | 239 | `nbe` | Nessus NBE | Import into Nessus / legacy tools | 240 | `msf+` | Metasploit log | Direct log to Metasploit DB | 241 242 ```bash 243 # JSON output 244 nikto -h http://10.10.10.10 -o scan.json -Format json 245 246 # HTML report for client delivery 247 nikto -h http://10.10.10.10 -p 443 -ssl -o report.htm -Format htm 248 249 # XML for vulnerability management import 250 nikto -h http://10.10.10.10 -o nikto_out.xml -Format xml 251 252 # Multiple formats from one scan (comma-separated) 253 nikto -h http://10.10.10.10 -o results.csv -Format csv,xml 254 255 # nmap greppable output piped directly to Nikto 256 # (discovers HTTP ports then scans each automatically) 257 nmap -p80,443,8080,8443 192.168.1.0/24 -oG - | nikto -h - 258 259 # nmap XML output fed to Nikto directly 260 nmap -sV -p80,443 192.168.1.0/24 -oX nmap_out.xml 261 nikto -h nmap_out.xml -o nikto_results.xml -Format xml 262 263 # Live output to stdout AND file simultaneously 264 nikto -h http://10.10.10.10 -Display P | tee nikto_live.txt 265 ``` 266 267 > [!info]+ Command Breakdown 268 > 1. **`-Format json`** requires v2.5.0+; older apt packages may not support it — use git clone if missing 269 > 2. **`-oG - | nikto -h -`** — nmap pipes greppable output directly; Nikto reads host list from stdin; efficient for subnet sweeps 270 > 3. **`-h nmap_out.xml`** — Nikto natively parses nmap XML; automatically extracts hosts and ports 271 > 4. **`-Display P | tee`** — streams live findings to terminal and writes to file simultaneously 272 > 5. **`msf+` / `nbe`** formats require additional DB configuration in `nikto.conf` 273 > 6. *Format is auto-detected from file extension if `-Format` is omitted* 274 275 --- 276 --- 277 278 # Nuclei 279 280 --- 281 282 ## Install & Template Management 283 284 ```bash 285 # Option 1 — Go install (always latest) 286 go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest 287 288 # Option 2 — Pre-built binary (Linux x64) 289 wget https://github.com/projectdiscovery/nuclei/releases/latest/download/nuclei_linux_amd64.zip 290 unzip nuclei_linux_amd64.zip && mv nuclei /usr/local/bin/ 291 292 # Option 3 — Docker 293 docker pull projectdiscovery/nuclei:latest 294 docker run --rm projectdiscovery/nuclei -u https://example.com 295 296 # Option 4 — Kali apt (may lag upstream; prefer binary) 297 sudo apt-get install nuclei 298 299 # Verify installation 300 nuclei -version 301 nuclei -health-check 302 ``` 303 304 > [!info]+ Template Management Commands 305 ```bash 306 # First run auto-downloads templates to ~/.local/nuclei-templates/ 307 nuclei -u example.com 308 309 # Update templates to latest release 310 nuclei -ut 311 312 # Update nuclei engine binary 313 nuclei -up 314 315 # Use custom template directory 316 nuclei -ud /opt/nuclei-templates -ut 317 318 # Show installed template version 319 nuclei -tv 320 321 # List all available templates 322 nuclei -tl 323 324 # List all available tags 325 nuclei -tgl 326 327 # Validate a template before use 328 nuclei -t /path/to/template.yaml -validate 329 330 # Disable auto-update check (OPSEC — suppresses outbound to GitHub on start) 331 nuclei -u example.com -duc 332 ``` 333 334 > [!info]+ Template Source Reference 335 336 | Source | URL | Notes | 337 |---|---|---| 338 | Official | [nuclei-templates](https://github.com/projectdiscovery/nuclei-templates) | 10,000+ templates; primary source | 339 | Official Labs | [nuclei-templates-labs](https://github.com/projectdiscovery/nuclei-templates-labs) | PoC / learning templates | 340 | Official Fuzzing | [fuzzing-templates](https://github.com/projectdiscovery/fuzzing-templates) | DAST fuzzing templates | 341 | Community collection | [Nuclei-Templates-Collection](https://github.com/emadshanab/Nuclei-Templates-Collection) | Curated community set | 342 | Aggregator (600+ repos) | [nucleihub-templates](https://github.com/rix4uni/nucleihub-templates) | Auto-synced every 6 hours | 343 | Browse all | [GitHub topic](https://github.com/topics/nuclei-templates) | All public template repos | 344 345 > [!info]+ Official Template Directory Layout 346 ``` 347 nuclei-templates/ 348 ├── http/cves/ # CVE-specific (1,400+) 349 ├── http/exposures/ # Info disclosure (275+) 350 ├── http/misconfiguration/ # Misconfigs (237+) 351 ├── http/exposed-panels/ # Admin panels (662+) 352 ├── http/default-logins/ # Default credentials (103+) 353 ├── http/technologies/ # Tech fingerprint (282+) 354 ├── http/vulnerabilities/ # General vulns (509+) 355 ├── workflows/ # Multi-step chains (189+) 356 ├── ssl/ # TLS/cert checks 357 ├── dns/ # DNS checks 358 ├── network/ # TCP/UDP checks 359 └── file/ # Local file checks 360 ``` 361 362 --- 363 364 ## Basic Vulnerability Scan 365 366 ```bash 367 # All templates, single target 368 nuclei -u https://example.com 369 370 # Scan from target list 371 nuclei -l targets.txt 372 373 # Specific template or directory 374 nuclei -u https://example.com -t http/cves/ 375 376 # Multiple template directories 377 nuclei -u https://example.com -t http/cves/ -t ssl -t http/exposures/ 378 379 # High/critical severity only 380 nuclei -l targets.txt -s high,critical 381 382 # Tag-based — WordPress checks 383 nuclei -u https://example.com -tags wordpress 384 385 # Exclude info noise 386 nuclei -u https://example.com -es info 387 388 # Auto-scan — tech detection drives template selection 389 nuclei -u https://example.com -as 390 391 # New templates only (latest release delta) 392 nuclei -u https://example.com -nt 393 394 # Specific CVE by template ID 395 nuclei -u https://example.com -id CVE-2021-44228 396 397 # Load template directly from URL 398 nuclei -u https://example.com -turl https://raw.githubusercontent.com/.../template.yaml 399 ``` 400 401 > [!info]+ Key Flags — Target 402 403 | Flag | Description | Default | 404 |---|---|---| 405 | `-u` | Single URL/host | — | 406 | `-l` | File of targets (one per line) | — | 407 | `-eh` | Exclude hosts (IP/CIDR/hostname) | — | 408 | `-resume` | Resume from `resume.cfg` | off | 409 | `-sa` | Scan all IPs for a hostname | off | 410 | `-iv` | IP version (4 or 6) | 4 | 411 412 > [!info]+ Key Flags — Templates & Filtering 413 414 | Flag | Description | Default | 415 |---|---|---| 416 | `-t` | Template file or directory | all | 417 | `-turl` | Load template from URL | — | 418 | `-w` | Workflow file or directory | — | 419 | `-nt` | New templates in latest release only | off | 420 | `-as` | Auto-scan via Wappalyzer tag mapping | off | 421 | `-tags` | Filter by tag(s), comma-separated | — | 422 | `-etags` | Exclude tags | — | 423 | `-id` | Filter by template ID(s) | — | 424 | `-eid` | Exclude template ID(s) | — | 425 | `-s` | Severity: `info,low,medium,high,critical` | all | 426 | `-es` | Exclude severity levels | — | 427 | `-pt` | Protocol type: `dns,http,ssl,tcp,file,headless...` | all | 428 | `-a` | Filter by template author | — | 429 | `-tl` | List all installed templates | — | 430 | `-tgl` | List all available tags | — | 431 | `-validate` | Validate template syntax | — | 432 | `-code` | Enable code-protocol templates (explicit opt-in) | off | 433 | `-dut` | Block unsigned/mismatched templates | off | 434 435 > [!info]+ Common Tags Reference 436 437 | Tag | Coverage | 438 |---|---| 439 | `cve` | All CVE templates | 440 | `exposure` | Info/credential disclosure | 441 | `misconfiguration` | Server/app misconfigs | 442 | `default-login` | Default credentials | 443 | `exposed-panel` | Admin/management panels | 444 | `rce` | Remote code execution | 445 | `sqli` | SQL injection | 446 | `xss` | Cross-site scripting | 447 | `ssrf` | Server-side request forgery | 448 | `lfi` | Local file inclusion | 449 | `wp-plugin` | WordPress plugin vulns | 450 | `tech` | Technology detection | 451 | `ssl` | TLS / certificate issues | 452 | `dns` | DNS misconfigs | 453 | `login` | Auth-related | 454 455 > [!info]+ Output Interpretation 456 > 1. **`[INF]`** — Tech/version detected; low operational priority 457 > 2. **`[LOW]` / `[MED]`** — Misconfigs, disclosures; assess contextual risk 458 > 3. **`[HIGH]` / `[CRIT]`** — Confirmed or likely exploitable; investigate immediately 459 > 4. **Template ID shown inline** (e.g. `CVE-2021-44228`) — map to [NVD](https://nvd.nist.gov/) for full CVSS score 460 > 5. **`[matcher-status]` lines with `-ms`** — shows failed matches; useful for false-positive tuning 461 462 > [!failure]+ Common Errors 463 464 | Error | Fix | 465 |---|---| 466 | `No templates found` | Run `nuclei -ut`; check `~/.local/nuclei-templates/` exists | 467 | Template parse error | Run `nuclei -t template.yaml -validate` | 468 | OAST interaction timeout | Add `-ni` or use `-iserver` with self-hosted Interactsh | 469 | OOM / high memory on large scans | Reduce `-c 10 -bs 10`; lower `-timeout 5` | 470 | `host skipped (max errors)` | Target unstable; raise `-mhe` or check connectivity | 471 | Templates not updating | Check outbound HTTPS; try `nuclei -ut -v` | 472 | Unsigned template blocked | Sign template or remove `-dut` restriction (not recommended) | 473 474 --- 475 476 ## Output Formats & Reporting 477 478 > [!info]+ Output Flag Reference 479 480 | Flag | Format | Best Use | 481 |---|---|---| 482 | `-o <file>` | Plain text | Quick review | 483 | `-j` / `-jsonl` | JSONL to stdout | Pipeline / `jq` | 484 | `-json-export <file>` | JSON array | Structured import | 485 | `-jsonl-export <file>` | JSONL file | Splunk / ELK ingestion | 486 | `-markdown-export <dir>` | Markdown per template | Client-ready report | 487 | `-sarif-export <file>` | SARIF | GitHub / Azure DevOps CI gate | 488 | `-rdb <file>` | SQLite DB | Persistent multi-run reporting | 489 | `-silent` | Suppress banner | Findings-only stdout | 490 | `-nm` | No metadata | Cleaner pipe output | 491 | `-ts` | Add timestamps | Audit log | 492 | `-or` | Omit raw req/resp | Smaller output files | 493 | `-store-resp` | Store all req/resp | Full traffic archive | 494 | `-nc` | No ANSI colour | Log files / CI output | 495 496 ```bash 497 # JSONL with timestamps, no raw payloads 498 nuclei -l targets.txt -s high,critical -jsonl-export findings.jsonl -ts -or 499 500 # Markdown report — full req/resp included 501 nuclei -u https://example.com -markdown-export ./report/ 502 503 # SARIF for GitHub Actions CI gate 504 nuclei -u https://example.com -sarif-export nuclei.sarif 505 506 # Filter JSONL with jq — critical findings only 507 nuclei -u https://example.com -json-export out.json 508 cat out.json | jq '.[] | select(.info.severity=="critical")' 509 510 # Silent mode — print findings only, no banner 511 nuclei -l targets.txt -s high,critical -silent -o findings.txt 512 513 # Persistent report database across multiple scans 514 nuclei -l targets.txt -rdb nuclei_results.db 515 516 # Store every request/response as evidence 517 nuclei -u https://example.com -store-resp -srd ./traffic_archive/ 518 ``` 519 520 > [!info]+ Command Breakdown 521 > 1. **`-ts -or`** — timestamps every finding and omits raw payloads; keeps files compact for audit logs 522 > 2. **`-markdown-export`** — generates one Markdown file per template match; ideal for client deliverables 523 > 3. **`-sarif-export`** — SARIF format integrates with GitHub Security tab and Azure DevOps pipeline gates 524 > 4. **`jq '.[] | select(.info.severity=="critical")'`** — filters JSON export to critical findings only; powerful for triage 525 > 5. **`-rdb`** — SQLite database accumulates results across multiple scan runs; enables trend tracking 526 > 6. **`-store-resp -srd`** — archives every raw HTTP request/response for evidence and replay 527 528 --- 529 530 ## Rate Limiting & OPSEC 531 532 > [!info]+ Rate / Concurrency Flags 533 534 | Flag | Description | Default | 535 |---|---|---| 536 | `-rl` | Max requests per second | 150 | 537 | `-c` | Templates executed in parallel | 25 | 538 | `-bs` | Hosts per template in parallel | 25 | 539 | `-timeout` | Request timeout (seconds) | 10 | 540 | `-retries` | Retries per failed request | 1 | 541 | `-mhe` | Max errors before host is skipped | 30 | 542 | `-project` | Deduplicate requests across runs | off | 543 544 > [!info]+ OPSEC Flags 545 546 | Flag | Effect | 547 |---|---| 548 | `-ni` | Disable Interactsh / OAST callbacks entirely | 549 | `-iserver` | Use self-hosted Interactsh (no PD infrastructure) | 550 | `-p` | Proxy all traffic (http/socks5) | 551 | `-H` | Inject custom headers (e.g. UA spoof) | 552 | `-tlsi` | Randomise TLS JA3 fingerprint (experimental) | 553 | `-passive` | Process existing responses only; zero active requests | 554 | `-duc` | Disable auto-update check; no outbound to GitHub on start | 555 | `-config` | Load settings from file; avoids CLI exposure in process list | 556 557 ```bash 558 # Low-and-slow stealth scan — high/critical only 559 nuclei -l targets.txt -rl 5 -c 5 -bs 5 -timeout 15 -s high,critical 560 561 # No OAST, proxied, spoofed UA, throttled 562 nuclei -u https://example.com \ 563 -ni \ 564 -p http://127.0.0.1:8080 \ 565 -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)" \ 566 -rl 10 -c 5 567 568 # Passive mode — zero active requests (feed Burp export) 569 nuclei -l burp_responses.txt -im jsonl -passive 570 571 # TLS fingerprint randomisation 572 nuclei -u https://example.com -tlsi 573 574 # Resume a large interrupted scan 575 nuclei -l targets.txt -resume resume.cfg 576 577 # Disable update telemetry entirely 578 nuclei -u https://example.com -duc -ni 579 ``` 580 581 > [!info]+ Command Breakdown 582 > 1. **`-rl 5 -c 5 -bs 5`** — throttles to 5 req/s, 5 parallel templates, 5 hosts at once; drastically reduces noise 583 > 2. **`-ni`** — the single most important OPSEC flag; stops DNS/HTTP callbacks to `oast.pro`, `oast.live`, `oast.me` which are **externally observable** 584 > 3. **`-passive -im jsonl`** — feeds pre-captured responses (e.g. Burp export); zero new requests sent to target 585 > 4. **`-tlsi`** — randomises TLS JA3 fingerprint; experimental but reduces tool-specific TLS detection 586 > 5. **`-duc`** — prevents version-check HTTP request to GitHub on every invocation; relevant in air-gapped or monitored environments 587 588 > [!warning]+ OPSEC / Detection Notes 589 > 6. **`-ni` is the single most important OPSEC flag** — OAST callbacks to `oast.pro`/`oast.live`/`oast.me` are externally observable and will expose the scan 590 > 7. Default 150 req/s across 25 parallel templates is very loud; reduce to ≤10 req/s for stealth operations 591 > 8. All requests still appear in web server `access.log` — no flag prevents server-side logging 592 > 9. **`-duc`** prevents a version-check HTTP request to GitHub on every invocation 593 > 10. Self-host [Interactsh](https://github.com/projectdiscovery/interactsh) for OOB testing with zero external callbacks 594 > 11. Prefer narrow template sets (`-t http/cves/ -s high,critical`) over all-templates runs — cuts request count by 90%+ 595 > 12. **`-as`** auto-scan fires a Wappalyzer fingerprint probe first — adds one visible pre-scan request 596 597 --- 598 599 ## DAST / Fuzzing 600 601 > [!danger]+ Authorisation Warning 602 > DAST mode sends **modified/injected payloads** — highly detectable by WAF/IDS. Only use on explicitly authorised scope. Combine with `-rl 5 -ni -p http://127.0.0.1:8080` for proxied, throttled fuzzing. 603 604 ```bash 605 # Clone fuzzing templates 606 git clone https://github.com/projectdiscovery/fuzzing-templates 607 608 # Enable DAST mode — all fuzzing templates 609 nuclei -list endpoints.txt -dast 610 611 # Fuzz query parameters only 612 nuclei -list endpoints.txt -dast -tags fuzzing-req-query 613 614 # Fuzz request body only 615 nuclei -list endpoints.txt -dast -tags fuzzing-req-body 616 617 # Fuzz cookies 618 nuclei -list endpoints.txt -dast -tags fuzzing-req-cookie 619 620 # Fuzz request headers 621 nuclei -list endpoints.txt -dast -tags fuzzing-req-header 622 623 # Fuzz URL path segments 624 nuclei -list endpoints.txt -dast -tags fuzzing-req-path 625 626 # Skip header + cookie fuzzing to reduce noise 627 nuclei -list endpoints.txt -dast -etags fuzzing-req-header,fuzzing-req-cookie 628 629 # Katana crawl → Nuclei DAST pipeline 630 katana -u https://example.com -jc -aff -o endpoints.txt 631 nuclei -list endpoints.txt -dast -s high,critical -rl 10 632 633 # Feed Katana JSONL output directly 634 nuclei -l katana.jsonl -im jsonl -dast 635 ``` 636 637 > [!info]+ DAST Fuzzing Flags 638 639 | Flag | Description | Default | 640 |---|---|---| 641 | `-dast` | Enable DAST / fuzzing templates | off | 642 | `-ft` | Override fuzzing type: `replace,prefix,postfix,infix` | template default | 643 | `-fm` | Override fuzzing mode: `multiple,single` | template default | 644 | `-fa` | Aggression level: `low,medium,high` | `low` | 645 | `-fuzz-param-frequency` | Skip param after N uninteresting hits | 10 | 646 647 > [!info]+ Command Breakdown 648 > 1. **`-dast`** — activates DAST engine; requires fuzzing-templates to be present 649 > 2. **`-tags fuzzing-req-query`** — restricts fuzzing to URL query parameters; lowest-noise DAST option 650 > 3. **`-etags fuzzing-req-header,fuzzing-req-cookie`** — excludes header and cookie fuzzing; reduces detection surface 651 > 4. **`katana -jc -aff`** — JavaScript crawling with form filling; produces comprehensive endpoint list for DAST input 652 > 5. **`-im jsonl`** — tells Nuclei the input file is JSONL format (Katana's native output format) 653 654 --- 655 656 ## Workflows & Chaining 657 658 > [!faq]+ What are Workflows? 659 > Workflows run multi-step conditional scans — detect technology first, then automatically select and run relevant templates. Defined in YAML; avoids running irrelevant templates against every target. 660 661 ```bash 662 # Run a specific workflow 663 nuclei -u https://example.com -w workflows/cms-detect.yaml 664 665 # Run all workflows in a directory 666 nuclei -u <target> -w workflows/ 667 668 # Run all official workflows 669 nuclei -u https://example.com -w ~/.local/nuclei-templates/workflows/ 670 671 # Combine workflow + structured output 672 nuclei -u https://example.com -w workflows/cms-detect.yaml \ 673 -markdown-export ./report/ -s medium,high,critical 674 ``` 675 676 > [!example]+ CMS Detection Workflow YAML 677 ```yaml 678 id: example-workflow 679 info: 680 name: CMS Detection + Targeted Scan 681 author: operator 682 severity: info 683 workflows: 684 - template: http/technologies/cms-detection.yaml 685 matchers: 686 - name: wordpress 687 subtemplates: 688 - tags: wp-plugin,wp-theme 689 - template: http/cves/2021/ # WordPress CVEs 690 - name: drupal 691 subtemplates: 692 - tags: drupal 693 - name: joomla 694 subtemplates: 695 - tags: joomla 696 ``` 697 698 > [!example]+ Auth Bypass Workflow YAML 699 ```yaml 700 id: auth-bypass-workflow 701 info: 702 name: Auth Bypass Assessment 703 author: operator 704 severity: critical 705 workflows: 706 - template: http/technologies/tech-detect.yaml 707 - template: http/default-logins/ 708 matchers: 709 - name: login-successful 710 subtemplates: 711 - template: http/exposures/ 712 - tags: exposure,rce 713 ``` 714 715 > [!info]+ Workflow Structure Breakdown 716 > 1. **`id`** — unique identifier used in output and reporting 717 > 2. **`workflows > template`** — first template to execute (detection step) 718 > 3. **`matchers > name`** — matches a specific result from the detection template 719 > 4. **`subtemplates`** — templates/tags to run **only if** the matcher fires; conditional chaining 720 > 5. *Workflows eliminate wasted requests — e.g. WordPress CVEs only run if WordPress is confirmed* 721 722 --- 723 724 ## Recon Pipeline Integration 725 726 > [!important]+ Install the Full ProjectDiscovery Stack 727 ```bash 728 go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest 729 go install github.com/projectdiscovery/httpx/cmd/httpx@latest 730 go install github.com/projectdiscovery/katana/cmd/katana@latest 731 go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest 732 ``` 733 734 ```bash 735 # Subdomain → live hosts → Nuclei (high/critical CVEs) 736 subfinder -d example.com -silent | \ 737 httpx -silent | \ 738 nuclei -s high,critical -t http/cves/ -ni -rl 20 739 740 # Full pipeline: subdomains → live hosts → Nuclei with exclusions 741 subfinder -d example.com -silent | \ 742 httpx -silent | \ 743 tee alive.txt | \ 744 nuclei -l alive.txt -es info -ept ssl -s medium,high,critical \ 745 -ni -rl 15 -o findings.txt 746 747 # Crawl endpoints then DAST fuzz 748 katana -u https://example.com -jc -aff -silent -o endpoints.txt 749 nuclei -list endpoints.txt -dast -tags fuzzing-req-query,fuzzing-req-body \ 750 -s high,critical -rl 5 -ni 751 752 # Full automated recon pipeline (single command) 753 subfinder -d example.com -all -silent | \ 754 httpx -silent | \ 755 katana -list - -silent -nc -jc -aff -ef woff,css,png,svg,jpg -aff | \ 756 nuclei -im jsonl -es info,unknown -ept ssl -ss template-spray \ 757 -ni -rl 10 -o nuclei_out.txt 758 759 # Scan from nmap XML output 760 nmap -sV -p80,443,8080,8443 192.168.1.0/24 -oG - | \ 761 grep "open" | awk '{print $2}' | \ 762 httpx -silent | \ 763 nuclei -s high,critical -ni -rl 10 764 ``` 765 766 > [!info]+ Key httpx Pipeline Flags 767 768 | Flag | Effect | 769 |---|---| 770 | `-silent` | Output URLs only | 771 | `-status-code` | Include HTTP status in output | 772 | `-title` | Include page title in output | 773 | `-tech-detect` | Detect technologies | 774 | `-mc 200,301,302` | Filter by status codes | 775 776 > [!info]+ Command Breakdown 777 > 1. **`subfinder -silent | httpx -silent`** — passive subdomain enumeration feeds into live host probing; httpx filters unreachable hosts 778 > 2. **`tee alive.txt`** — splits the pipe; writes live hosts to file AND continues the pipeline simultaneously 779 > 3. **`-ept ssl`** — excludes SSL protocol templates; avoids noisy cert-expiry findings in mixed pipelines 780 > 4. **`-ss template-spray`** — sprays one template across ALL hosts before moving to the next; spreads load and avoids per-host detection thresholds 781 > 5. **`-ef woff,css,png,svg,jpg`** — Katana excludes static asset extensions; keeps endpoint list clean for Nuclei 782 > 6. **`-im jsonl`** — instructs Nuclei to parse input as JSONL (Katana's native output); preserves full request context 783 784 > [!warning]+ OPSEC / Detection Notes 785 > 1. Always include **`-ni`** in automated pipelines — prevents uncontrolled OAST callbacks 786 > 2. Use **`-ss template-spray`** to spread load and avoid per-host detection thresholds 787 > 3. `subfinder` performs **passive enumeration only**; `katana` and `nuclei` are **active** — scope accordingly 788 > 4. Add **`-duc`** to suppress update checks in CI/CD pipelines 789 790 --- 791 792 ## Writing Custom Templates 793 794 > [!faq]+ When to Write a Custom Template 795 > Write custom templates when: a specific behaviour has no existing template; you need to detect a proprietary application's endpoints; you want to check for a custom misconfiguration; or you are adapting a PoC exploit for templated scanning. 796 797 > [!example]+ Minimal HTTP Template Skeleton 798 ```yaml 799 id: custom-template-id # unique; used in output 800 801 info: 802 name: Example Exposed Debug Page 803 author: operator 804 severity: medium # info / low / medium / high / critical 805 description: Detects exposed debug endpoint 806 tags: exposure,custom 807 808 http: 809 - method: GET 810 path: 811 - "{{BaseURL}}/debug" # {{BaseURL}} = scheme://host:port 812 813 matchers-condition: and # and / or 814 matchers: 815 - type: word # word / regex / status / size / binary / dsl 816 part: body # body / header / all / interactsh_protocol 817 words: 818 - "debug mode" 819 - "stack trace" 820 condition: or # or / and 821 822 - type: status 823 status: 824 - 200 825 ``` 826 827 > [!example]+ Template with Extractor + Multiple Paths 828 ```yaml 829 id: version-disclosure 830 831 info: 832 name: App Version Disclosure 833 author: operator 834 severity: info 835 tags: tech,exposure 836 837 http: 838 - method: GET 839 path: 840 - "{{BaseURL}}/version" 841 - "{{BaseURL}}/api/version" 842 - "{{BaseURL}}/status" 843 844 matchers: 845 - type: regex 846 part: body 847 regex: 848 - '([0-9]+\.[0-9]+\.[0-9]+)' 849 850 extractors: 851 - type: regex 852 part: body 853 regex: 854 - '([0-9]+\.[0-9]+\.[0-9]+)' 855 ``` 856 857 > [!example]+ OOB / OAST Template (requires Interactsh) 858 ```yaml 859 id: ssrf-oob-check 860 861 info: 862 name: SSRF OOB Detection 863 author: operator 864 severity: high 865 tags: ssrf 866 867 http: 868 - method: GET 869 path: 870 - "{{BaseURL}}/?url={{interactsh-url}}" 871 872 matchers: 873 - type: word 874 part: interactsh_protocol 875 words: 876 - "http" 877 ``` 878 879 ```bash 880 # Validate template syntax 881 nuclei -t custom-template.yaml -validate 882 883 # Test against single target with debug output 884 nuclei -u https://example.com -t custom-template.yaml -debug 885 886 # Run with verbose output 887 nuclei -u https://example.com -t custom-template.yaml -v 888 889 # Run against target list 890 nuclei -l targets.txt -t ./custom-templates/ -s medium,high -ni 891 ``` 892 893 > [!info]+ Command Breakdown 894 > 1. **`-validate`** — parses YAML and checks template syntax before running; always validate before deploying 895 > 2. **`-debug`** — prints full raw HTTP request and response for every template probe; essential for development 896 > 3. **`{{BaseURL}}`** — Nuclei variable automatically populated with `scheme://host:port` from the target 897 > 4. **`{{interactsh-url}}`** — automatically generates an OOB callback URL; match fires when the callback is received 898 > 5. **`matchers-condition: and`** — ALL matchers must fire for a finding to be reported; reduces false positives 899 900 > [!info]+ Matcher Types Reference 901 902 | Type | Matches On | 903 |---|---| 904 | `word` | Exact string presence | 905 | `regex` | Regular expression | 906 | `status` | HTTP status code | 907 | `size` | Response body size | 908 | `binary` | Binary content | 909 | `dsl` | DSL expression (flexible boolean logic) | 910 | `xpath` | XPath on HTML/XML body | 911 912 --- 913 914 ## References 915 916 1. [Nikto — GitHub](https://github.com/sullo/nikto) 917 2. [Nikto — Official Site](https://cirt.net/nikto2) 918 3. [Nikto — Official Documentation](https://cirt.net/nikto2-docs/) 919 4. [Nikto — Usage Documentation](https://www.cirt.net/nikto2-docs/usage.html) 920 5. [Nikto — Arch Linux Man Page](https://man.archlinux.org/man/extra/nikto/nikto.1.en) 921 6. [Nikto — HighOn.Coffee Cheat Sheet](https://highon.coffee/blog/nikto-cheat-sheet/) 922 7. [Nikto — Terminal Guide](https://www.terminal.guide/linux/security-tools/nikto/) 923 8. [Nuclei — GitHub](https://github.com/projectdiscovery/nuclei) 924 9. [Nuclei — Install Docs](https://docs.projectdiscovery.io/opensource/nuclei/install) 925 10. [Nuclei — Running Docs](https://docs.projectdiscovery.io/opensource/nuclei/running) 926 11. [Nuclei — Template Structure Docs](https://docs.projectdiscovery.io/templates/structure) 927 12. [Nuclei — README](https://github.com/projectdiscovery/nuclei/blob/main/README.md) 928 13. [Nuclei — Workflows Documentation](https://www.mintlify.com/projectdiscovery/nuclei/concepts/workflows) 929 14. [Nuclei — kb.offsec.nl Reference](https://kb.offsec.nl/tools/framework/projectdiscovery/nuclei/) 930 15. [Nuclei — Mass Scale Usage](https://ott3rly.com/using-nuclei-at-mass-scale/) 931 16. [Nuclei — Beginner's Guide (Bugcrowd)](https://www.bugcrowd.com/blog/the-ultimate-beginners-guide-to-nuclei/) 932 17. [Nuclei Templates — Official](https://github.com/projectdiscovery/nuclei-templates) 933 18. [Nuclei Templates — Fuzzing](https://github.com/projectdiscovery/fuzzing-templates) 934 19. [Nuclei Templates — DAST Templates](https://github.com/reewardius/nuclei-dast-templates) 935 20. [Nuclei Templates — Template Guide](https://github.com/rootklt/nuclei-template-guide/blob/main/template-guide.md) 936 21. [Interactsh — Self-hosted OOB](https://github.com/projectdiscovery/interactsh) 937 22. [Pipeline One-Liners — 0xPugal](https://github.com/0xPugal/One-Liners) 938 23. [ProjectDiscovery Blog](https://projectdiscovery.io/blog/uncover) 939 940 --- 941 942 #WebScan #Nikto #Nuclei #DAST #Fuzzing #ReconPipeline #WebAppTesting #VulnerabilityScanning #OPSEC #ProjectDiscovery