Nuclei CLI Playbook
Official docs:
Canonical syntax:
nuclei [flags]
High-signal flags:
-u, -target <url> single target
-l, -list <file> targets file
-im, -input-mode <mode> list/burp/jsonl/yaml/openapi/swagger
-t, -templates <path|tag> explicit template path(s)
-tags <tag1,tag2> run by tag
-s, -severity <critical,high,...> severity filter
-as, -automatic-scan tech-mapped automatic scan
-ni, -no-interactsh disable OAST/interactsh requests
-rl, -rate-limit <n> global request rate cap
-c, -concurrency <n> template concurrency
-bs, -bulk-size <n> hosts in parallel per template
-timeout <seconds> request timeout
-retries <n> retries
-stats periodic scan stats output
-silent findings-only output
-j, -jsonl JSONL output
-o <file> output file
Agent-safe baseline for automation:
nuclei -l targets.txt -as -s critical,high -rl 50 -c 20 -bs 20 -timeout 10 -retries 1 -silent -j -o nuclei.jsonl
Common patterns:
- Focused severity scan:
nuclei -u https://target.tld -s critical,high -silent -o nuclei_high.txt
- List-driven controlled scan:
nuclei -l targets.txt -as -rl 50 -c 20 -bs 20 -timeout 10 -retries 1 -j -o nuclei.jsonl
- Tag-driven run:
nuclei -l targets.txt -tags cve,misconfig -s critical,high,medium -silent
- Explicit templates:
nuclei -l targets.txt -t http/cves/ -t dns/ -rl 30 -c 10 -bs 10 -j -o nuclei_templates.jsonl
- Deterministic non-OAST run:
nuclei -l targets.txt -as -s critical,high -ni -stats -rl 30 -c 10 -bs 10 -timeout 10 -retries 1 -j -o nuclei_no_oast.jsonl
Critical correctness rules:
- Provide a template selection method (
-as, -t, or -tags); avoid unscoped broad runs.
- Keep
-rl, -c, and -bs explicit for predictable resource use.
- Use
-ni when outbound interactsh/OAST traffic is not expected or not allowed.
- Use structured output (
-j -o <file>) for automation.
Usage rules:
- Start with severity/tags/templates filters to keep runs explainable.
- Keep retries conservative (
-retries 1) unless transport instability is proven.
- Do not use
-h/--help for routine operation unless absolutely necessary.
Failure recovery:
- If performance degrades, lower
-c/-bs before lowering -rl.
- If findings are unexpectedly empty, verify template selection (
-as vs explicit -t/-tags).
- If scan duration grows, reduce target set and enforce stricter template/severity filters.
If uncertain, query web_search with:
site:docs.projectdiscovery.io nuclei <flag> running
1---2name: strix-nuclei3description: Strix Nuclei 命令手册,覆盖模板选择、高吞吐执行与自动化边界控制;触发名:strix-nuclei4---56# Nuclei CLI Playbook78Official docs:9- https://docs.projectdiscovery.io/opensource/nuclei/running10- https://docs.projectdiscovery.io/opensource/nuclei/mass-scanning-cli11- https://github.com/projectdiscovery/nuclei1213Canonical syntax:14`nuclei [flags]`1516High-signal flags:17- `-u, -target <url>` single target18- `-l, -list <file>` targets file19- `-im, -input-mode <mode>` list/burp/jsonl/yaml/openapi/swagger20- `-t, -templates <path|tag>` explicit template path(s)21- `-tags <tag1,tag2>` run by tag22- `-s, -severity <critical,high,...>` severity filter23- `-as, -automatic-scan` tech-mapped automatic scan24- `-ni, -no-interactsh` disable OAST/interactsh requests25- `-rl, -rate-limit <n>` global request rate cap26- `-c, -concurrency <n>` template concurrency27- `-bs, -bulk-size <n>` hosts in parallel per template28- `-timeout <seconds>` request timeout29- `-retries <n>` retries30- `-stats` periodic scan stats output31- `-silent` findings-only output32- `-j, -jsonl` JSONL output33- `-o <file>` output file3435Agent-safe baseline for automation:36`nuclei -l targets.txt -as -s critical,high -rl 50 -c 20 -bs 20 -timeout 10 -retries 1 -silent -j -o nuclei.jsonl`3738Common patterns:39- Focused severity scan:40 `nuclei -u https://target.tld -s critical,high -silent -o nuclei_high.txt`41- List-driven controlled scan:42 `nuclei -l targets.txt -as -rl 50 -c 20 -bs 20 -timeout 10 -retries 1 -j -o nuclei.jsonl`43- Tag-driven run:44 `nuclei -l targets.txt -tags cve,misconfig -s critical,high,medium -silent`45- Explicit templates:46 `nuclei -l targets.txt -t http/cves/ -t dns/ -rl 30 -c 10 -bs 10 -j -o nuclei_templates.jsonl`47- Deterministic non-OAST run:48 `nuclei -l targets.txt -as -s critical,high -ni -stats -rl 30 -c 10 -bs 10 -timeout 10 -retries 1 -j -o nuclei_no_oast.jsonl`4950Critical correctness rules:51- Provide a template selection method (`-as`, `-t`, or `-tags`); avoid unscoped broad runs.52- Keep `-rl`, `-c`, and `-bs` explicit for predictable resource use.53- Use `-ni` when outbound interactsh/OAST traffic is not expected or not allowed.54- Use structured output (`-j -o <file>`) for automation.5556Usage rules:57- Start with severity/tags/templates filters to keep runs explainable.58- Keep retries conservative (`-retries 1`) unless transport instability is proven.59- Do not use `-h`/`--help` for routine operation unless absolutely necessary.6061Failure recovery:62- If performance degrades, lower `-c/-bs` before lowering `-rl`.63- If findings are unexpectedly empty, verify template selection (`-as` vs explicit `-t/-tags`).64- If scan duration grows, reduce target set and enforce stricter template/severity filters.6566If uncertain, query web_search with:67`site:docs.projectdiscovery.io nuclei <flag> running`