Where does nuclei fit into your pipeline/use cases? #2540
Replies: 34 comments 9 replies
-
Hello Nuclei Maintainers. Hope you all are doing well. First of all I would like to thank you for making such great tool. I love to use Nuclei so much. I use it on almost daily basis. |
Beta Was this translation helpful? Give feedback.
-
YAML format makes it easy to create customizable templates and modify them on the run in case of changes in the infrastructure. Integrating those scans in the development cycle gives us the possibility to quickly run them at different stages in the development phase, even multiple times. The possibility to create tailored templates works wonders against false positives, differently from other scanners. |
Beta Was this translation helpful? Give feedback.
-
For recon and also to first scanning the target for its security postures and findings accordingly. |
Beta Was this translation helpful? Give feedback.
-
Always start automation while do manual testing |
Beta Was this translation helpful? Give feedback.
-
Currently learning to use yaml, so being able to use the custom yaml format is extremely useful! |
Beta Was this translation helpful? Give feedback.
-
I think nuclei need s YouTube channel to guide newbie to make their own templates, Except that nuclei is 💯 |
Beta Was this translation helpful? Give feedback.
-
1st smoke test, if something comes up then functionality may be affected if plugged so no point to test further. Saves a lot of time |
Beta Was this translation helpful? Give feedback.
-
I love nuclei that's amazing feature. It's very easy and powerful tool.for every bug hunter and Red Teamer. |
Beta Was this translation helpful? Give feedback.
-
Currently new to this, exploring it. |
Beta Was this translation helpful? Give feedback.
-
Easy To find Hanging Fruits ........... good for Enumeration too At last it's the hurt of Hunters ..... :) |
Beta Was this translation helpful? Give feedback.
-
CVE pentesting. |
Beta Was this translation helpful? Give feedback.
-
Just after subdomain enumeration |
Beta Was this translation helpful? Give feedback.
-
We would integrating it in the DAST Process or Test , Deploy and maintain to regurlarly check for the ongoing vulnerabilities |
Beta Was this translation helpful? Give feedback.
-
My pipeline goes a little something like this: subfinder -> dnsx -> naabu -> httpx -> nuclei |
Beta Was this translation helpful? Give feedback.
-
Using nuclei for scanning is very optimal and very easy to use. Would love if the creators consider cloud security standpoint. |
Beta Was this translation helpful? Give feedback.
-
Is there a Splunk app for this, I can install the Splunk app on my deployment and use the dashboard. |
Beta Was this translation helpful? Give feedback.
-
Well, Nuclei have a wide range of rules written, and easy to create one. If possible can we have something on UI like https://editor.cilium.io/ , a whole interactive UI easy to understand and create rules. |
Beta Was this translation helpful? Give feedback.
-
I just started using it yesterday. So I am still trying to find the perfect fit on how I can use it to enhance my workflow. Iguess recon will be a good starting point. |
Beta Was this translation helpful? Give feedback.
-
I use nuclei as one of my main tools when conducting web application security assessments. It allows me to quickly and easily scan for a variety of vulnerabilities, which saves me a lot of time and makes my job easier. I would highly recommend nuclei to anyone looking for a fast and reliable vulnerability scanner. Additionally , the fact that it is based on a simple YAML-based DSL makes it very easy to use and customize. Overall, I believe nuclei is an excellent tool that can be extremely useful for web application security assessments. |
Beta Was this translation helpful? Give feedback.
-
Nuclei is integrated into reNgine that I use as all-in-one discovery platform installed on a VPS. I can throw a list of subdomain and have a general overview of the scope. |
Beta Was this translation helpful? Give feedback.
-
Always run nuclei while I'm doing some manual pentest. |
Beta Was this translation helpful? Give feedback.
-
Don't mind me .Here for a giveaway 😂 |
Beta Was this translation helpful? Give feedback.
-
Currently using default templates for vulnerability scanning. Still a lot to learn...😁 |
Beta Was this translation helpful? Give feedback.
-
For me, since I am new to using nuclei.. I just stick to finding the low hanging fruits as of now.. but I plan on learning to write templates.. |
Beta Was this translation helpful? Give feedback.
-
Tbh, Nuclei is like work as catalyst to my recon. |
Beta Was this translation helpful? Give feedback.
-
Awesome tool. Easy to understand YAML templates, and also pretty customizable. Tools like these are difficult to replace. |
Beta Was this translation helpful? Give feedback.
-
For "n" number of domains with "y" number of endpoints and "z" amount of payloads, it really increases the the complexity (nyz) and time to scan for certain issues. Thanks for the pd-nuclei for making this process reasonably simpler. I use it in my semi-automation scripts for appropriate notifications that saves me a ton of time as well with lesser false positives. |
Beta Was this translation helpful? Give feedback.
-
I integrated it into my scanner as a lib library reference, but there would be a memory leak problem, and finally I could only use binary. Can I access redis |
Beta Was this translation helpful? Give feedback.
-
I set up Nuclei for cloud-native, automated vulnerability scanning in my Kubernetes cluster. How it works in my setup is that I have a helper container that populates a target list using Kubernetes' internal DNS resolution (i.e.
The following configuration should work as-is with some requirements:
|
Beta Was this translation helpful? Give feedback.
-
Hello 👋🏻
We are keeping this “Show and Tell” discussion open, so anyone can describe how and where they are utilizing nuclei. By sharing, you not only help the community, but also enable us, maintainers, to better prioritize features in our backlogs.
Beta Was this translation helpful? Give feedback.
All reactions