daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

nikto-nuclei-web-scanner-cheatsheets.md (35123B)


      1 ---
      2 title: "Nikto & Nuclei - Web Scanner Cheatsheets"
      3 description: "sudo apt-get install nikto"
      4 category: enumeration
      5 tags: ["enumeration"]
      6 tools: ["Nmap", "Nuclei", "Nikto", "Metasploit"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Enumeration/Nikto & Nuclei - Web Scanner Cheatsheets.md"
     10 ---
     11 # Nikto
     12 
     13 ---
     14 
     15 ## Install & Update
     16 
     17 ```bash
     18 # Kali / Debian / Ubuntu
     19 sudo apt-get install nikto
     20 
     21 # Git clone — latest code (v2.5.0+)
     22 git clone https://github.com/sullo/nikto
     23 cd nikto/program && perl nikto.pl -Help
     24 
     25 # Docker — no local Perl required
     26 docker pull sullo/nikto
     27 docker run --rm sullo/nikto -h <target>
     28 
     29 # Update plugin/signature database
     30 nikto -update
     31 
     32 # Verify installation and check DB integrity
     33 nikto -Version
     34 nikto -dbcheck
     35 ```
     36 
     37 > [!info]+ Command Breakdown
     38 > 1. **apt-get install nikto** — installs the packaged version; may lag behind upstream releases
     39 > 2. **git clone** — always pulls the latest v2.5.0+ code; preferred for up-to-date signatures
     40 > 3. **docker pull/run** — fully self-contained; no Perl dependency on the host
     41 > 4. **-update** — syncs the vulnerability plugin and signature database; run before every engagement
     42 > 5. **-dbcheck** — syntax-validates DB files; run after updates to confirm integrity
     43 
     44 ---
     45 
     46 ## Basic Web Scan
     47 
     48 ```bash
     49 # Standard HTTP scan
     50 nikto -h http://192.168.1.10
     51 
     52 # Specify port
     53 nikto -h <host> -p <port>
     54 
     55 # Force HTTPS
     56 nikto -h <host> -ssl
     57 
     58 # Multiple ports
     59 nikto -h <host> -p 80,443,8080
     60 
     61 # Bulk scan from file (one host per line)
     62 nikto -h hosts.txt
     63 
     64 # HTTPS on non-standard port
     65 nikto -h 192.168.1.10 -p 8443 -ssl
     66 
     67 # Authenticated scan with virtual host override
     68 nikto -h http://192.168.1.10 -id admin:admin -vhost internal.corp.local
     69 
     70 # Scan host list with 2s delay, abort after 10 min
     71 nikto -h hosts.txt -Pause 2 -maxtime 600s
     72 
     73 # Route all traffic through Burp Suite
     74 nikto -h http://10.10.10.10 -useproxy http://127.0.0.1:8080
     75 
     76 # Spoof User-Agent
     77 nikto -h http://10.10.10.10 -useragent "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
     78 ```
     79 
     80 > [!info]+ Key Flags Reference
     81 
     82 | Flag | Description | Default |
     83 |---|---|---|
     84 | `-h` | Target host / IP / URL | — |
     85 | `-p` | Port(s), comma-sep or range | 80 |
     86 | `-ssl` | Force HTTPS | off |
     87 | `-nossl` | Force HTTP | off |
     88 | `-id user:pass[:realm]` | HTTP Basic / NTLM auth | — |
     89 | `-vhost HOSTNAME` | Override `Host:` header | — |
     90 | `-useproxy http://IP:PORT` | Route via HTTP proxy | off |
     91 | `-useragent "STRING"` | Spoof User-Agent | Nikto/version |
     92 | `-root /path/` | Prepend path to all requests | — |
     93 | `-timeout N` | Per-request timeout (seconds) | 10 |
     94 | `-Pause N` | Delay between tests (seconds) | 0 |
     95 | `-maxtime Ns` | Abort entire scan after N seconds | none |
     96 | `-no404` | Disable 404 page guessing | off |
     97 | `-nointeractive` | Suppress interactive prompts | off |
     98 | `-nolookup` | Skip DNS lookups | off |
     99 | `-Plugins "all"` | Run all plugins | ALL |
    100 | `-list-plugins` | List available plugins | — |
    101 | `-update` | Update plugins/signatures | — |
    102 | `-dbcheck` | Syntax-check DB files | — |
    103 
    104 > [!info]+ Output Interpretation
    105 > 1. **`+ OSVDB-XXXX`** — known vulnerability reference; always verify before reporting
    106 > 2. **`+ Server: Apache/2.2.x`** — outdated version detected; cross-check [NVD](https://nvd.nist.gov/)/CVE
    107 > 3. **`+ /admin/` returning 200** — exposed panel; investigate access controls
    108 > 4. **`+ OPTIONS: PUT, DELETE`** — dangerous HTTP methods enabled; test for write access
    109 > 5. **`+ X-Frame-Options header not set`** — potential [clickjacking](https://owasp.org/www-community/attacks/Clickjacking); note for report
    110 
    111 > [!warning]+ OPSEC / Detection Notes
    112 > 6. Default UA `Mozilla/5.00 (Nikto/2.x.x)` is trivially flagged by any WAF — always spoof with `-useragent`
    113 > 7. Even with UA spoofing, the sequential probe pattern (`/.git`, `/admin`, `/cgi-bin` etc.) is a strong fingerprint
    114 > 8. Every request appears in `access.log` and `error.log`; WAF rules will trigger
    115 > 9. `-Pause` adds delay but does **not** randomise order — rate-based detection still fires
    116 > 10. **No stealth mode exists** — treat all Nikto scans as loud/noisy
    117 > 11. Use `-Tuning b` (software ID only) for the lowest-footprint option
    118 
    119 > [!failure]+ Common Errors
    120 
    121 | Error | Fix |
    122 |---|---|
    123 | `ERROR: Cannot open db_tests` | Re-clone repo or run as root; run `-update` |
    124 | SSL handshake failure | Explicitly add `-ssl` or `-nossl` |
    125 | Scan completes with 0 findings | Target unreachable; verify with `curl` first |
    126 | `No plugin found` | Run `nikto -list-plugins` to confirm name |
    127 | Perl module missing | `cpan install Net::SSLeay` for SSL support |
    128 | IPv6 target not resolving | Add `-ipv6` flag explicitly |
    129 
    130 ---
    131 
    132 ## Tuning & Targeted Checks
    133 
    134 > [!faq]+ What is Tuning?
    135 > Tuning narrows scans to specific vulnerability classes — reduces noise, cuts scan time, and lowers detection surface. Combine multiple codes in a single string (e.g. `-Tuning 49` = XSS + SQLi).
    136 
    137 > [!info]+ Tuning Code Reference
    138 
    139 | Code | Check Type |
    140 |---|---|
    141 | `0` | File upload |
    142 | `1` | Interesting files / seen in logs |
    143 | `2` | Misconfiguration / default files |
    144 | `3` | Information disclosure |
    145 | `4` | Injection (XSS / Script / HTML) |
    146 | `5` | Remote file retrieval (inside web root) |
    147 | `6` | Denial of service ⚠️ may break services |
    148 | `7` | Remote file retrieval (server-wide) |
    149 | `8` | Command execution / remote shell |
    150 | `9` | SQL injection |
    151 | `a` | Authentication bypass |
    152 | `b` | Software identification |
    153 | `c` | Remote source inclusion |
    154 | `x` | Reverse — run ALL except listed codes |
    155 
    156 ```bash
    157 # XSS + SQLi only
    158 nikto -h http://10.10.10.10 -Tuning 49
    159 
    160 # Info disclosure + misconfiguration
    161 nikto -h http://10.10.10.10 -Tuning 23
    162 
    163 # Auth bypass + command execution
    164 nikto -h http://10.10.10.10 -Tuning a8
    165 
    166 # All checks EXCEPT denial of service
    167 nikto -h http://10.10.10.10 -Tuning x6
    168 
    169 # Software ID only — lowest footprint
    170 nikto -h http://10.10.10.10 -Tuning b
    171 
    172 # Full sweep minus DoS, save as JSON
    173 nikto -h http://10.10.10.10 -Tuning x6 -o results.json -Format json
    174 ```
    175 
    176 > [!info]+ Command Breakdown
    177 > 1. **Tuning codes are combined as a string** — `-Tuning 49` runs codes `4` AND `9` simultaneously
    178 > 2. **`x` reversal prefix** — `-Tuning x6` runs everything *except* DoS; safest full-scan option
    179 > 3. **`b` alone** — software identification only; quietest possible scan; good for initial fingerprinting
    180 > 4. *Combining `-Tuning` with `-o` and `-Format json` captures structured results for later analysis*
    181 
    182 > [!danger]+ Tuning Code 6 — Denial of Service
    183 > Code `6` can cause **service disruption** on the target. Exclude with `-Tuning x6` unless DoS testing is explicitly authorised in your scope agreement.
    184 
    185 > [!warning]+ OPSEC Note
    186 > Multiple tuning codes still execute many sequential requests — the pattern remains recognisable to IDS/WAF regardless of which codes are selected.
    187 
    188 ---
    189 
    190 ## Evasion Techniques
    191 
    192 > [!warning]+ Effectiveness Warning
    193 > Nikto evasion codes provide **very limited bypass** against modern WAFs (Cloudflare, ModSecurity v3). Request volume is unchanged — rate/volume-based detection still fires. Best combined with `-Pause`, narrow `-Tuning`, and UA spoofing.
    194 
    195 > [!info]+ Evasion Code Reference
    196 
    197 | Code | Technique |
    198 |---|---|
    199 | `1` | Random URI encoding (non-UTF8) |
    200 | `2` | Directory self-reference `/./` |
    201 | `3` | Premature URL ending |
    202 | `4` | Prepend long random string |
    203 | `5` | Fake URL parameter |
    204 | `6` | TAB as request spacer |
    205 | `7` | Change case of URL |
    206 | `8` | Windows path separator `\` |
    207 | `A` | Carriage return as request spacer |
    208 | `B` | Binary value `0x0b` as request spacer |
    209 
    210 ```bash
    211 # Random URI encoding
    212 nikto -h http://10.10.10.10 -evasion 1
    213 
    214 # URI encoding + case change combined
    215 nikto -h http://10.10.10.10 -evasion 17
    216 
    217 # Targeted scan + evasion combo + slow down
    218 nikto -h http://10.10.10.10 -Tuning 49 -evasion 12 -Pause 1
    219 ```
    220 
    221 > [!info]+ Command Breakdown
    222 > 1. **Evasion codes combine as a string** — `-evasion 17` applies codes `1` AND `7` simultaneously
    223 > 2. **`-evasion 12 -Pause 1`** — encoding + directory self-reference with 1s delay; reduces scan velocity
    224 > 3. *Pairing narrow `-Tuning` with evasion codes and UA spoofing is the closest Nikto gets to low-noise operation*
    225 
    226 ---
    227 
    228 ## Output Formats & Nmap Integration
    229 
    230 > [!info]+ Supported Output Formats (`-Format`)
    231 
    232 | Code | Type | Notes |
    233 |---|---|---|
    234 | `txt` | Plain text | Default if no extension match |
    235 | `csv` | Comma-separated | Good for spreadsheet / Splunk import |
    236 | `json` | JSON | v2.5.0+ native; best for pipelines |
    237 | `xml` | XML | Vuln management tool import |
    238 | `htm` | HTML | Human-readable client report |
    239 | `nbe` | Nessus NBE | Import into Nessus / legacy tools |
    240 | `msf+` | Metasploit log | Direct log to Metasploit DB |
    241 
    242 ```bash
    243 # JSON output
    244 nikto -h http://10.10.10.10 -o scan.json -Format json
    245 
    246 # HTML report for client delivery
    247 nikto -h http://10.10.10.10 -p 443 -ssl -o report.htm -Format htm
    248 
    249 # XML for vulnerability management import
    250 nikto -h http://10.10.10.10 -o nikto_out.xml -Format xml
    251 
    252 # Multiple formats from one scan (comma-separated)
    253 nikto -h http://10.10.10.10 -o results.csv -Format csv,xml
    254 
    255 # nmap greppable output piped directly to Nikto
    256 # (discovers HTTP ports then scans each automatically)
    257 nmap -p80,443,8080,8443 192.168.1.0/24 -oG - | nikto -h -
    258 
    259 # nmap XML output fed to Nikto directly
    260 nmap -sV -p80,443 192.168.1.0/24 -oX nmap_out.xml
    261 nikto -h nmap_out.xml -o nikto_results.xml -Format xml
    262 
    263 # Live output to stdout AND file simultaneously
    264 nikto -h http://10.10.10.10 -Display P | tee nikto_live.txt
    265 ```
    266 
    267 > [!info]+ Command Breakdown
    268 > 1. **`-Format json`** requires v2.5.0+; older apt packages may not support it — use git clone if missing
    269 > 2. **`-oG - | nikto -h -`** — nmap pipes greppable output directly; Nikto reads host list from stdin; efficient for subnet sweeps
    270 > 3. **`-h nmap_out.xml`** — Nikto natively parses nmap XML; automatically extracts hosts and ports
    271 > 4. **`-Display P | tee`** — streams live findings to terminal and writes to file simultaneously
    272 > 5. **`msf+` / `nbe`** formats require additional DB configuration in `nikto.conf`
    273 > 6. *Format is auto-detected from file extension if `-Format` is omitted*
    274 
    275 ---
    276 ---
    277 
    278 # Nuclei
    279 
    280 ---
    281 
    282 ## Install & Template Management
    283 
    284 ```bash
    285 # Option 1 — Go install (always latest)
    286 go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
    287 
    288 # Option 2 — Pre-built binary (Linux x64)
    289 wget https://github.com/projectdiscovery/nuclei/releases/latest/download/nuclei_linux_amd64.zip
    290 unzip nuclei_linux_amd64.zip && mv nuclei /usr/local/bin/
    291 
    292 # Option 3 — Docker
    293 docker pull projectdiscovery/nuclei:latest
    294 docker run --rm projectdiscovery/nuclei -u https://example.com
    295 
    296 # Option 4 — Kali apt (may lag upstream; prefer binary)
    297 sudo apt-get install nuclei
    298 
    299 # Verify installation
    300 nuclei -version
    301 nuclei -health-check
    302 ```
    303 
    304 > [!info]+ Template Management Commands
    305 ```bash
    306 # First run auto-downloads templates to ~/.local/nuclei-templates/
    307 nuclei -u example.com
    308 
    309 # Update templates to latest release
    310 nuclei -ut
    311 
    312 # Update nuclei engine binary
    313 nuclei -up
    314 
    315 # Use custom template directory
    316 nuclei -ud /opt/nuclei-templates -ut
    317 
    318 # Show installed template version
    319 nuclei -tv
    320 
    321 # List all available templates
    322 nuclei -tl
    323 
    324 # List all available tags
    325 nuclei -tgl
    326 
    327 # Validate a template before use
    328 nuclei -t /path/to/template.yaml -validate
    329 
    330 # Disable auto-update check (OPSEC — suppresses outbound to GitHub on start)
    331 nuclei -u example.com -duc
    332 ```
    333 
    334 > [!info]+ Template Source Reference
    335 
    336 | Source | URL | Notes |
    337 |---|---|---|
    338 | Official | [nuclei-templates](https://github.com/projectdiscovery/nuclei-templates) | 10,000+ templates; primary source |
    339 | Official Labs | [nuclei-templates-labs](https://github.com/projectdiscovery/nuclei-templates-labs) | PoC / learning templates |
    340 | Official Fuzzing | [fuzzing-templates](https://github.com/projectdiscovery/fuzzing-templates) | DAST fuzzing templates |
    341 | Community collection | [Nuclei-Templates-Collection](https://github.com/emadshanab/Nuclei-Templates-Collection) | Curated community set |
    342 | Aggregator (600+ repos) | [nucleihub-templates](https://github.com/rix4uni/nucleihub-templates) | Auto-synced every 6 hours |
    343 | Browse all | [GitHub topic](https://github.com/topics/nuclei-templates) | All public template repos |
    344 
    345 > [!info]+ Official Template Directory Layout
    346 ```
    347 nuclei-templates/
    348 ├── http/cves/              # CVE-specific (1,400+)
    349 ├── http/exposures/         # Info disclosure (275+)
    350 ├── http/misconfiguration/  # Misconfigs (237+)
    351 ├── http/exposed-panels/    # Admin panels (662+)
    352 ├── http/default-logins/    # Default credentials (103+)
    353 ├── http/technologies/      # Tech fingerprint (282+)
    354 ├── http/vulnerabilities/   # General vulns (509+)
    355 ├── workflows/              # Multi-step chains (189+)
    356 ├── ssl/                    # TLS/cert checks
    357 ├── dns/                    # DNS checks
    358 ├── network/                # TCP/UDP checks
    359 └── file/                   # Local file checks
    360 ```
    361 
    362 ---
    363 
    364 ## Basic Vulnerability Scan
    365 
    366 ```bash
    367 # All templates, single target
    368 nuclei -u https://example.com
    369 
    370 # Scan from target list
    371 nuclei -l targets.txt
    372 
    373 # Specific template or directory
    374 nuclei -u https://example.com -t http/cves/
    375 
    376 # Multiple template directories
    377 nuclei -u https://example.com -t http/cves/ -t ssl -t http/exposures/
    378 
    379 # High/critical severity only
    380 nuclei -l targets.txt -s high,critical
    381 
    382 # Tag-based — WordPress checks
    383 nuclei -u https://example.com -tags wordpress
    384 
    385 # Exclude info noise
    386 nuclei -u https://example.com -es info
    387 
    388 # Auto-scan — tech detection drives template selection
    389 nuclei -u https://example.com -as
    390 
    391 # New templates only (latest release delta)
    392 nuclei -u https://example.com -nt
    393 
    394 # Specific CVE by template ID
    395 nuclei -u https://example.com -id CVE-2021-44228
    396 
    397 # Load template directly from URL
    398 nuclei -u https://example.com -turl https://raw.githubusercontent.com/.../template.yaml
    399 ```
    400 
    401 > [!info]+ Key Flags — Target
    402 
    403 | Flag | Description | Default |
    404 |---|---|---|
    405 | `-u` | Single URL/host | — |
    406 | `-l` | File of targets (one per line) | — |
    407 | `-eh` | Exclude hosts (IP/CIDR/hostname) | — |
    408 | `-resume` | Resume from `resume.cfg` | off |
    409 | `-sa` | Scan all IPs for a hostname | off |
    410 | `-iv` | IP version (4 or 6) | 4 |
    411 
    412 > [!info]+ Key Flags — Templates & Filtering
    413 
    414 | Flag | Description | Default |
    415 |---|---|---|
    416 | `-t` | Template file or directory | all |
    417 | `-turl` | Load template from URL | — |
    418 | `-w` | Workflow file or directory | — |
    419 | `-nt` | New templates in latest release only | off |
    420 | `-as` | Auto-scan via Wappalyzer tag mapping | off |
    421 | `-tags` | Filter by tag(s), comma-separated | — |
    422 | `-etags` | Exclude tags | — |
    423 | `-id` | Filter by template ID(s) | — |
    424 | `-eid` | Exclude template ID(s) | — |
    425 | `-s` | Severity: `info,low,medium,high,critical` | all |
    426 | `-es` | Exclude severity levels | — |
    427 | `-pt` | Protocol type: `dns,http,ssl,tcp,file,headless...` | all |
    428 | `-a` | Filter by template author | — |
    429 | `-tl` | List all installed templates | — |
    430 | `-tgl` | List all available tags | — |
    431 | `-validate` | Validate template syntax | — |
    432 | `-code` | Enable code-protocol templates (explicit opt-in) | off |
    433 | `-dut` | Block unsigned/mismatched templates | off |
    434 
    435 > [!info]+ Common Tags Reference
    436 
    437 | Tag | Coverage |
    438 |---|---|
    439 | `cve` | All CVE templates |
    440 | `exposure` | Info/credential disclosure |
    441 | `misconfiguration` | Server/app misconfigs |
    442 | `default-login` | Default credentials |
    443 | `exposed-panel` | Admin/management panels |
    444 | `rce` | Remote code execution |
    445 | `sqli` | SQL injection |
    446 | `xss` | Cross-site scripting |
    447 | `ssrf` | Server-side request forgery |
    448 | `lfi` | Local file inclusion |
    449 | `wp-plugin` | WordPress plugin vulns |
    450 | `tech` | Technology detection |
    451 | `ssl` | TLS / certificate issues |
    452 | `dns` | DNS misconfigs |
    453 | `login` | Auth-related |
    454 
    455 > [!info]+ Output Interpretation
    456 > 1. **`[INF]`** — Tech/version detected; low operational priority
    457 > 2. **`[LOW]` / `[MED]`** — Misconfigs, disclosures; assess contextual risk
    458 > 3. **`[HIGH]` / `[CRIT]`** — Confirmed or likely exploitable; investigate immediately
    459 > 4. **Template ID shown inline** (e.g. `CVE-2021-44228`) — map to [NVD](https://nvd.nist.gov/) for full CVSS score
    460 > 5. **`[matcher-status]` lines with `-ms`** — shows failed matches; useful for false-positive tuning
    461 
    462 > [!failure]+ Common Errors
    463 
    464 | Error | Fix |
    465 |---|---|
    466 | `No templates found` | Run `nuclei -ut`; check `~/.local/nuclei-templates/` exists |
    467 | Template parse error | Run `nuclei -t template.yaml -validate` |
    468 | OAST interaction timeout | Add `-ni` or use `-iserver` with self-hosted Interactsh |
    469 | OOM / high memory on large scans | Reduce `-c 10 -bs 10`; lower `-timeout 5` |
    470 | `host skipped (max errors)` | Target unstable; raise `-mhe` or check connectivity |
    471 | Templates not updating | Check outbound HTTPS; try `nuclei -ut -v` |
    472 | Unsigned template blocked | Sign template or remove `-dut` restriction (not recommended) |
    473 
    474 ---
    475 
    476 ## Output Formats & Reporting
    477 
    478 > [!info]+ Output Flag Reference
    479 
    480 | Flag | Format | Best Use |
    481 |---|---|---|
    482 | `-o <file>` | Plain text | Quick review |
    483 | `-j` / `-jsonl` | JSONL to stdout | Pipeline / `jq` |
    484 | `-json-export <file>` | JSON array | Structured import |
    485 | `-jsonl-export <file>` | JSONL file | Splunk / ELK ingestion |
    486 | `-markdown-export <dir>` | Markdown per template | Client-ready report |
    487 | `-sarif-export <file>` | SARIF | GitHub / Azure DevOps CI gate |
    488 | `-rdb <file>` | SQLite DB | Persistent multi-run reporting |
    489 | `-silent` | Suppress banner | Findings-only stdout |
    490 | `-nm` | No metadata | Cleaner pipe output |
    491 | `-ts` | Add timestamps | Audit log |
    492 | `-or` | Omit raw req/resp | Smaller output files |
    493 | `-store-resp` | Store all req/resp | Full traffic archive |
    494 | `-nc` | No ANSI colour | Log files / CI output |
    495 
    496 ```bash
    497 # JSONL with timestamps, no raw payloads
    498 nuclei -l targets.txt -s high,critical -jsonl-export findings.jsonl -ts -or
    499 
    500 # Markdown report — full req/resp included
    501 nuclei -u https://example.com -markdown-export ./report/
    502 
    503 # SARIF for GitHub Actions CI gate
    504 nuclei -u https://example.com -sarif-export nuclei.sarif
    505 
    506 # Filter JSONL with jq — critical findings only
    507 nuclei -u https://example.com -json-export out.json
    508 cat out.json | jq '.[] | select(.info.severity=="critical")'
    509 
    510 # Silent mode — print findings only, no banner
    511 nuclei -l targets.txt -s high,critical -silent -o findings.txt
    512 
    513 # Persistent report database across multiple scans
    514 nuclei -l targets.txt -rdb nuclei_results.db
    515 
    516 # Store every request/response as evidence
    517 nuclei -u https://example.com -store-resp -srd ./traffic_archive/
    518 ```
    519 
    520 > [!info]+ Command Breakdown
    521 > 1. **`-ts -or`** — timestamps every finding and omits raw payloads; keeps files compact for audit logs
    522 > 2. **`-markdown-export`** — generates one Markdown file per template match; ideal for client deliverables
    523 > 3. **`-sarif-export`** — SARIF format integrates with GitHub Security tab and Azure DevOps pipeline gates
    524 > 4. **`jq '.[] | select(.info.severity=="critical")'`** — filters JSON export to critical findings only; powerful for triage
    525 > 5. **`-rdb`** — SQLite database accumulates results across multiple scan runs; enables trend tracking
    526 > 6. **`-store-resp -srd`** — archives every raw HTTP request/response for evidence and replay
    527 
    528 ---
    529 
    530 ## Rate Limiting & OPSEC
    531 
    532 > [!info]+ Rate / Concurrency Flags
    533 
    534 | Flag | Description | Default |
    535 |---|---|---|
    536 | `-rl` | Max requests per second | 150 |
    537 | `-c` | Templates executed in parallel | 25 |
    538 | `-bs` | Hosts per template in parallel | 25 |
    539 | `-timeout` | Request timeout (seconds) | 10 |
    540 | `-retries` | Retries per failed request | 1 |
    541 | `-mhe` | Max errors before host is skipped | 30 |
    542 | `-project` | Deduplicate requests across runs | off |
    543 
    544 > [!info]+ OPSEC Flags
    545 
    546 | Flag | Effect |
    547 |---|---|
    548 | `-ni` | Disable Interactsh / OAST callbacks entirely |
    549 | `-iserver` | Use self-hosted Interactsh (no PD infrastructure) |
    550 | `-p` | Proxy all traffic (http/socks5) |
    551 | `-H` | Inject custom headers (e.g. UA spoof) |
    552 | `-tlsi` | Randomise TLS JA3 fingerprint (experimental) |
    553 | `-passive` | Process existing responses only; zero active requests |
    554 | `-duc` | Disable auto-update check; no outbound to GitHub on start |
    555 | `-config` | Load settings from file; avoids CLI exposure in process list |
    556 
    557 ```bash
    558 # Low-and-slow stealth scan — high/critical only
    559 nuclei -l targets.txt -rl 5 -c 5 -bs 5 -timeout 15 -s high,critical
    560 
    561 # No OAST, proxied, spoofed UA, throttled
    562 nuclei -u https://example.com \
    563   -ni \
    564   -p http://127.0.0.1:8080 \
    565   -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)" \
    566   -rl 10 -c 5
    567 
    568 # Passive mode — zero active requests (feed Burp export)
    569 nuclei -l burp_responses.txt -im jsonl -passive
    570 
    571 # TLS fingerprint randomisation
    572 nuclei -u https://example.com -tlsi
    573 
    574 # Resume a large interrupted scan
    575 nuclei -l targets.txt -resume resume.cfg
    576 
    577 # Disable update telemetry entirely
    578 nuclei -u https://example.com -duc -ni
    579 ```
    580 
    581 > [!info]+ Command Breakdown
    582 > 1. **`-rl 5 -c 5 -bs 5`** — throttles to 5 req/s, 5 parallel templates, 5 hosts at once; drastically reduces noise
    583 > 2. **`-ni`** — the single most important OPSEC flag; stops DNS/HTTP callbacks to `oast.pro`, `oast.live`, `oast.me` which are **externally observable**
    584 > 3. **`-passive -im jsonl`** — feeds pre-captured responses (e.g. Burp export); zero new requests sent to target
    585 > 4. **`-tlsi`** — randomises TLS JA3 fingerprint; experimental but reduces tool-specific TLS detection
    586 > 5. **`-duc`** — prevents version-check HTTP request to GitHub on every invocation; relevant in air-gapped or monitored environments
    587 
    588 > [!warning]+ OPSEC / Detection Notes
    589 > 6. **`-ni` is the single most important OPSEC flag** — OAST callbacks to `oast.pro`/`oast.live`/`oast.me` are externally observable and will expose the scan
    590 > 7. Default 150 req/s across 25 parallel templates is very loud; reduce to ≤10 req/s for stealth operations
    591 > 8. All requests still appear in web server `access.log` — no flag prevents server-side logging
    592 > 9. **`-duc`** prevents a version-check HTTP request to GitHub on every invocation
    593 > 10. Self-host [Interactsh](https://github.com/projectdiscovery/interactsh) for OOB testing with zero external callbacks
    594 > 11. Prefer narrow template sets (`-t http/cves/ -s high,critical`) over all-templates runs — cuts request count by 90%+
    595 > 12. **`-as`** auto-scan fires a Wappalyzer fingerprint probe first — adds one visible pre-scan request
    596 
    597 ---
    598 
    599 ## DAST / Fuzzing
    600 
    601 > [!danger]+ Authorisation Warning
    602 > DAST mode sends **modified/injected payloads** — highly detectable by WAF/IDS. Only use on explicitly authorised scope. Combine with `-rl 5 -ni -p http://127.0.0.1:8080` for proxied, throttled fuzzing.
    603 
    604 ```bash
    605 # Clone fuzzing templates
    606 git clone https://github.com/projectdiscovery/fuzzing-templates
    607 
    608 # Enable DAST mode — all fuzzing templates
    609 nuclei -list endpoints.txt -dast
    610 
    611 # Fuzz query parameters only
    612 nuclei -list endpoints.txt -dast -tags fuzzing-req-query
    613 
    614 # Fuzz request body only
    615 nuclei -list endpoints.txt -dast -tags fuzzing-req-body
    616 
    617 # Fuzz cookies
    618 nuclei -list endpoints.txt -dast -tags fuzzing-req-cookie
    619 
    620 # Fuzz request headers
    621 nuclei -list endpoints.txt -dast -tags fuzzing-req-header
    622 
    623 # Fuzz URL path segments
    624 nuclei -list endpoints.txt -dast -tags fuzzing-req-path
    625 
    626 # Skip header + cookie fuzzing to reduce noise
    627 nuclei -list endpoints.txt -dast -etags fuzzing-req-header,fuzzing-req-cookie
    628 
    629 # Katana crawl → Nuclei DAST pipeline
    630 katana -u https://example.com -jc -aff -o endpoints.txt
    631 nuclei -list endpoints.txt -dast -s high,critical -rl 10
    632 
    633 # Feed Katana JSONL output directly
    634 nuclei -l katana.jsonl -im jsonl -dast
    635 ```
    636 
    637 > [!info]+ DAST Fuzzing Flags
    638 
    639 | Flag | Description | Default |
    640 |---|---|---|
    641 | `-dast` | Enable DAST / fuzzing templates | off |
    642 | `-ft` | Override fuzzing type: `replace,prefix,postfix,infix` | template default |
    643 | `-fm` | Override fuzzing mode: `multiple,single` | template default |
    644 | `-fa` | Aggression level: `low,medium,high` | `low` |
    645 | `-fuzz-param-frequency` | Skip param after N uninteresting hits | 10 |
    646 
    647 > [!info]+ Command Breakdown
    648 > 1. **`-dast`** — activates DAST engine; requires fuzzing-templates to be present
    649 > 2. **`-tags fuzzing-req-query`** — restricts fuzzing to URL query parameters; lowest-noise DAST option
    650 > 3. **`-etags fuzzing-req-header,fuzzing-req-cookie`** — excludes header and cookie fuzzing; reduces detection surface
    651 > 4. **`katana -jc -aff`** — JavaScript crawling with form filling; produces comprehensive endpoint list for DAST input
    652 > 5. **`-im jsonl`** — tells Nuclei the input file is JSONL format (Katana's native output format)
    653 
    654 ---
    655 
    656 ## Workflows & Chaining
    657 
    658 > [!faq]+ What are Workflows?
    659 > Workflows run multi-step conditional scans — detect technology first, then automatically select and run relevant templates. Defined in YAML; avoids running irrelevant templates against every target.
    660 
    661 ```bash
    662 # Run a specific workflow
    663 nuclei -u https://example.com -w workflows/cms-detect.yaml
    664 
    665 # Run all workflows in a directory
    666 nuclei -u <target> -w workflows/
    667 
    668 # Run all official workflows
    669 nuclei -u https://example.com -w ~/.local/nuclei-templates/workflows/
    670 
    671 # Combine workflow + structured output
    672 nuclei -u https://example.com -w workflows/cms-detect.yaml \
    673   -markdown-export ./report/ -s medium,high,critical
    674 ```
    675 
    676 > [!example]+ CMS Detection Workflow YAML
    677 ```yaml
    678 id: example-workflow
    679 info:
    680   name: CMS Detection + Targeted Scan
    681   author: operator
    682   severity: info
    683 workflows:
    684   - template: http/technologies/cms-detection.yaml
    685     matchers:
    686       - name: wordpress
    687         subtemplates:
    688           - tags: wp-plugin,wp-theme
    689           - template: http/cves/2021/    # WordPress CVEs
    690       - name: drupal
    691         subtemplates:
    692           - tags: drupal
    693       - name: joomla
    694         subtemplates:
    695           - tags: joomla
    696 ```
    697 
    698 > [!example]+ Auth Bypass Workflow YAML
    699 ```yaml
    700 id: auth-bypass-workflow
    701 info:
    702   name: Auth Bypass Assessment
    703   author: operator
    704   severity: critical
    705 workflows:
    706   - template: http/technologies/tech-detect.yaml
    707   - template: http/default-logins/
    708     matchers:
    709       - name: login-successful
    710         subtemplates:
    711           - template: http/exposures/
    712           - tags: exposure,rce
    713 ```
    714 
    715 > [!info]+ Workflow Structure Breakdown
    716 > 1. **`id`** — unique identifier used in output and reporting
    717 > 2. **`workflows > template`** — first template to execute (detection step)
    718 > 3. **`matchers > name`** — matches a specific result from the detection template
    719 > 4. **`subtemplates`** — templates/tags to run **only if** the matcher fires; conditional chaining
    720 > 5. *Workflows eliminate wasted requests — e.g. WordPress CVEs only run if WordPress is confirmed*
    721 
    722 ---
    723 
    724 ## Recon Pipeline Integration
    725 
    726 > [!important]+ Install the Full ProjectDiscovery Stack
    727 ```bash
    728 go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
    729 go install github.com/projectdiscovery/httpx/cmd/httpx@latest
    730 go install github.com/projectdiscovery/katana/cmd/katana@latest
    731 go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
    732 ```
    733 
    734 ```bash
    735 # Subdomain → live hosts → Nuclei (high/critical CVEs)
    736 subfinder -d example.com -silent | \
    737   httpx -silent | \
    738   nuclei -s high,critical -t http/cves/ -ni -rl 20
    739 
    740 # Full pipeline: subdomains → live hosts → Nuclei with exclusions
    741 subfinder -d example.com -silent | \
    742   httpx -silent | \
    743   tee alive.txt | \
    744   nuclei -l alive.txt -es info -ept ssl -s medium,high,critical \
    745     -ni -rl 15 -o findings.txt
    746 
    747 # Crawl endpoints then DAST fuzz
    748 katana -u https://example.com -jc -aff -silent -o endpoints.txt
    749 nuclei -list endpoints.txt -dast -tags fuzzing-req-query,fuzzing-req-body \
    750   -s high,critical -rl 5 -ni
    751 
    752 # Full automated recon pipeline (single command)
    753 subfinder -d example.com -all -silent | \
    754   httpx -silent | \
    755   katana -list - -silent -nc -jc -aff -ef woff,css,png,svg,jpg -aff | \
    756   nuclei -im jsonl -es info,unknown -ept ssl -ss template-spray \
    757     -ni -rl 10 -o nuclei_out.txt
    758 
    759 # Scan from nmap XML output
    760 nmap -sV -p80,443,8080,8443 192.168.1.0/24 -oG - | \
    761   grep "open" | awk '{print $2}' | \
    762   httpx -silent | \
    763   nuclei -s high,critical -ni -rl 10
    764 ```
    765 
    766 > [!info]+ Key httpx Pipeline Flags
    767 
    768 | Flag | Effect |
    769 |---|---|
    770 | `-silent` | Output URLs only |
    771 | `-status-code` | Include HTTP status in output |
    772 | `-title` | Include page title in output |
    773 | `-tech-detect` | Detect technologies |
    774 | `-mc 200,301,302` | Filter by status codes |
    775 
    776 > [!info]+ Command Breakdown
    777 > 1. **`subfinder -silent | httpx -silent`** — passive subdomain enumeration feeds into live host probing; httpx filters unreachable hosts
    778 > 2. **`tee alive.txt`** — splits the pipe; writes live hosts to file AND continues the pipeline simultaneously
    779 > 3. **`-ept ssl`** — excludes SSL protocol templates; avoids noisy cert-expiry findings in mixed pipelines
    780 > 4. **`-ss template-spray`** — sprays one template across ALL hosts before moving to the next; spreads load and avoids per-host detection thresholds
    781 > 5. **`-ef woff,css,png,svg,jpg`** — Katana excludes static asset extensions; keeps endpoint list clean for Nuclei
    782 > 6. **`-im jsonl`** — instructs Nuclei to parse input as JSONL (Katana's native output); preserves full request context
    783 
    784 > [!warning]+ OPSEC / Detection Notes
    785 > 1. Always include **`-ni`** in automated pipelines — prevents uncontrolled OAST callbacks
    786 > 2. Use **`-ss template-spray`** to spread load and avoid per-host detection thresholds
    787 > 3. `subfinder` performs **passive enumeration only**; `katana` and `nuclei` are **active** — scope accordingly
    788 > 4. Add **`-duc`** to suppress update checks in CI/CD pipelines
    789 
    790 ---
    791 
    792 ## Writing Custom Templates
    793 
    794 > [!faq]+ When to Write a Custom Template
    795 > Write custom templates when: a specific behaviour has no existing template; you need to detect a proprietary application's endpoints; you want to check for a custom misconfiguration; or you are adapting a PoC exploit for templated scanning.
    796 
    797 > [!example]+ Minimal HTTP Template Skeleton
    798 ```yaml
    799 id: custom-template-id               # unique; used in output
    800 
    801 info:
    802   name: Example Exposed Debug Page
    803   author: operator
    804   severity: medium                   # info / low / medium / high / critical
    805   description: Detects exposed debug endpoint
    806   tags: exposure,custom
    807 
    808 http:
    809   - method: GET
    810     path:
    811       - "{{BaseURL}}/debug"          # {{BaseURL}} = scheme://host:port
    812 
    813     matchers-condition: and          # and / or
    814     matchers:
    815       - type: word                   # word / regex / status / size / binary / dsl
    816         part: body                   # body / header / all / interactsh_protocol
    817         words:
    818           - "debug mode"
    819           - "stack trace"
    820         condition: or                # or / and
    821 
    822       - type: status
    823         status:
    824           - 200
    825 ```
    826 
    827 > [!example]+ Template with Extractor + Multiple Paths
    828 ```yaml
    829 id: version-disclosure
    830 
    831 info:
    832   name: App Version Disclosure
    833   author: operator
    834   severity: info
    835   tags: tech,exposure
    836 
    837 http:
    838   - method: GET
    839     path:
    840       - "{{BaseURL}}/version"
    841       - "{{BaseURL}}/api/version"
    842       - "{{BaseURL}}/status"
    843 
    844     matchers:
    845       - type: regex
    846         part: body
    847         regex:
    848           - '([0-9]+\.[0-9]+\.[0-9]+)'
    849 
    850     extractors:
    851       - type: regex
    852         part: body
    853         regex:
    854           - '([0-9]+\.[0-9]+\.[0-9]+)'
    855 ```
    856 
    857 > [!example]+ OOB / OAST Template (requires Interactsh)
    858 ```yaml
    859 id: ssrf-oob-check
    860 
    861 info:
    862   name: SSRF OOB Detection
    863   author: operator
    864   severity: high
    865   tags: ssrf
    866 
    867 http:
    868   - method: GET
    869     path:
    870       - "{{BaseURL}}/?url={{interactsh-url}}"
    871 
    872     matchers:
    873       - type: word
    874         part: interactsh_protocol
    875         words:
    876           - "http"
    877 ```
    878 
    879 ```bash
    880 # Validate template syntax
    881 nuclei -t custom-template.yaml -validate
    882 
    883 # Test against single target with debug output
    884 nuclei -u https://example.com -t custom-template.yaml -debug
    885 
    886 # Run with verbose output
    887 nuclei -u https://example.com -t custom-template.yaml -v
    888 
    889 # Run against target list
    890 nuclei -l targets.txt -t ./custom-templates/ -s medium,high -ni
    891 ```
    892 
    893 > [!info]+ Command Breakdown
    894 > 1. **`-validate`** — parses YAML and checks template syntax before running; always validate before deploying
    895 > 2. **`-debug`** — prints full raw HTTP request and response for every template probe; essential for development
    896 > 3. **`{{BaseURL}}`** — Nuclei variable automatically populated with `scheme://host:port` from the target
    897 > 4. **`{{interactsh-url}}`** — automatically generates an OOB callback URL; match fires when the callback is received
    898 > 5. **`matchers-condition: and`** — ALL matchers must fire for a finding to be reported; reduces false positives
    899 
    900 > [!info]+ Matcher Types Reference
    901 
    902 | Type | Matches On |
    903 |---|---|
    904 | `word` | Exact string presence |
    905 | `regex` | Regular expression |
    906 | `status` | HTTP status code |
    907 | `size` | Response body size |
    908 | `binary` | Binary content |
    909 | `dsl` | DSL expression (flexible boolean logic) |
    910 | `xpath` | XPath on HTML/XML body |
    911 
    912 ---
    913 
    914 ## References
    915 
    916 1. [Nikto — GitHub](https://github.com/sullo/nikto)
    917 2. [Nikto — Official Site](https://cirt.net/nikto2)
    918 3. [Nikto — Official Documentation](https://cirt.net/nikto2-docs/)
    919 4. [Nikto — Usage Documentation](https://www.cirt.net/nikto2-docs/usage.html)
    920 5. [Nikto — Arch Linux Man Page](https://man.archlinux.org/man/extra/nikto/nikto.1.en)
    921 6. [Nikto — HighOn.Coffee Cheat Sheet](https://highon.coffee/blog/nikto-cheat-sheet/)
    922 7. [Nikto — Terminal Guide](https://www.terminal.guide/linux/security-tools/nikto/)
    923 8. [Nuclei — GitHub](https://github.com/projectdiscovery/nuclei)
    924 9. [Nuclei — Install Docs](https://docs.projectdiscovery.io/opensource/nuclei/install)
    925 10. [Nuclei — Running Docs](https://docs.projectdiscovery.io/opensource/nuclei/running)
    926 11. [Nuclei — Template Structure Docs](https://docs.projectdiscovery.io/templates/structure)
    927 12. [Nuclei — README](https://github.com/projectdiscovery/nuclei/blob/main/README.md)
    928 13. [Nuclei — Workflows Documentation](https://www.mintlify.com/projectdiscovery/nuclei/concepts/workflows)
    929 14. [Nuclei — kb.offsec.nl Reference](https://kb.offsec.nl/tools/framework/projectdiscovery/nuclei/)
    930 15. [Nuclei — Mass Scale Usage](https://ott3rly.com/using-nuclei-at-mass-scale/)
    931 16. [Nuclei — Beginner's Guide (Bugcrowd)](https://www.bugcrowd.com/blog/the-ultimate-beginners-guide-to-nuclei/)
    932 17. [Nuclei Templates — Official](https://github.com/projectdiscovery/nuclei-templates)
    933 18. [Nuclei Templates — Fuzzing](https://github.com/projectdiscovery/fuzzing-templates)
    934 19. [Nuclei Templates — DAST Templates](https://github.com/reewardius/nuclei-dast-templates)
    935 20. [Nuclei Templates — Template Guide](https://github.com/rootklt/nuclei-template-guide/blob/main/template-guide.md)
    936 21. [Interactsh — Self-hosted OOB](https://github.com/projectdiscovery/interactsh)
    937 22. [Pipeline One-Liners — 0xPugal](https://github.com/0xPugal/One-Liners)
    938 23. [ProjectDiscovery Blog](https://projectdiscovery.io/blog/uncover)
    939 
    940 ---
    941 
    942 #WebScan #Nikto #Nuclei #DAST #Fuzzing #ReconPipeline #WebAppTesting #VulnerabilityScanning #OPSEC #ProjectDiscovery