Nuclei
Purpose
Nuclei scans URL, host, and IP targets with vulnerability templates and emits vulnerability entities.
Plugin Information
Plugin ID: nuclei
Category: Vulnerability Discovery
Plugin Type: vulnerability_scan
Execution: active CLI vulnerability scan
Default State: enabled
Default Profiles:
defaultdeepvuln_scanweb_discovery
Input Scope
Accepted asset types:
webappdomainsubdomainip- Other scope values as a fallback when no URL or host targets are available.
Required metadata:
- None
Produces targets:
- WebApp assets are passed as URL targets.
- Domains, subdomains, and IPs are expanded to
https://andhttp://targets. - Targets are written to a temporary file passed with
-list.
Output
Creates assets:
- None directly.
Creates vulnerabilities:
- Vulnerability entities with
entity_typeset tovulnerability.
May enrich:
- Vulnerability records with template, severity, remediation, host, tags, matched URL, and evidence metadata.
Metadata:
template_id: Nuclei template ID.title: finding name.severity: finding severity.description: finding description.remediation: remediation text.matched_url: matched URL.host: affected host from Nuclei.tags: template tags.evidence: extracted results.
Graph Relations
The vulnerability persistence path associates findings with affected assets. The wrapper itself does not create asset graph edges directly.
Files / Artifacts
Produces:
- None
Dependencies
Required binary: nuclei
Required installer entry: tools.nuclei
Operational requirements:
- Nuclei templates must be available in the worker runtime.
Command model:
nuclei -jsonl -no-color -duc -c 10 -list <target-file> [-rate-limit <n>]
Example Flow
webapp
-> nuclei
vulnerability
Notes
The wrapper disables update checks with -duc and caps concurrency at 10 to avoid overwhelming small deployments.
The wrapper does not apply an hxEASM whole-process wall-clock deadline. Long Nuclei scans may continue while the scan remains active. Cancel Scan and worker shutdown cancel the process through the worker context. Nuclei's own per-request timeout and retry behavior remain scanner-native and are separate from total scan duration.
hxresearch Integration
The standard nuclei plugin uses the normal Nuclei template availability in the worker runtime. It does not read hxresearch/nuclei.
Use nuclei_custom_templates when a scan should run only project-maintained templates from hxresearch/nuclei. A future hybrid mode may combine ProjectDiscovery templates with hxresearch templates, but that behavior is not implemented.