找到
3
篇与
渗透测试
相关的结果
-
白帽黑客工具箱:routersploit 篇 推荐一个实用的开源工具——routersploit。项目由threat9开发维护,GitHub上获得了 13240 个Star。简单来说,它是一款嵌入式设备的利用框架,对于站长和开发者来说是个不错的工具。 工具功能介绍 Community Join community on Embedded Exploitation Discord. Description The RouterSploit Framework is an open-source exploitation framework dedicated to embedded devices.asciicast图片It consists of various modules that aid penetration testing operations:* exploits - modules that take advantage of identified vulnerabilities creds - modules designed to test credentials against network services scanners - modules that check if a target is vulnerable to any exploit payloads - modules that are responsible for generating payloads for various architectures and injection points generic - modules that perform generic attacks Installation Requirements Required: requests paramiko pysnmp pycryptoOptional: bluepy - Bluetooth low energy Installation on Kali Linux apt-get install python3-pip git clone https://www.github.com/threat9/routersploit cd routersploit python3 -m pip install -r requirements.txt python3 rsf.py Bluetooth Low Energy support: apt-get install libglib2.0-dev python3 -m pip install bluepy python3 rsf.py Installation on Ubuntu 20.04 sudo apt-get install git python3-pip git clone https://github.com/threat9/routersploit cd routersploit python3 -m pip install -r requirements.txt python3 rsf.py Bluetooth Low Energy support: sudo apt-get install libglib2.0-dev python3 -m pip install bluepy python3 rsf.py Installation on Ubuntu 18.04 & 17.10 sudo add-apt-repository universe sudo apt-get install git python3-pip git clone https://www.github.com/threat9/routersploit cd routersploit python3 -m pip install setuptools python3 -m pip install -r requirements.txt python3 rsf.py Bluetooth Low Energy support: apt-get install libglib2.0-dev python3 -m pip install bluepy python3 rsf.py Installation on OSX git clone https://www.github.com/threat9/routersploit cd routersploit sudo python3 -m pip install -r requirements.txt python3 rsf.py Running on Docker git clone https://www.github.com/threat9/routersploit cd routersploit docker compose up --build -d docker attach routersploit To run again without rebuild docker start routersploit docker attach routersploit Update Update RouterSploit Framework often. The project is under heavy development and new modules are shipped almost every day. cd routersploit git pull Build your own To our surprise, people started to fork routersploit not because they were interested in the security of embedded devices but simply because they want to leverage our interactive shell logic and build their tools using similar concept. All these years they must have said: "There must be a better way!" and they were completely right, the better way is called Riposte.Riposte allows you to easily wrap your application inside a tailored interactive shell. Common chores regarding building REPLs was factored out and being taken care of so you can focus on specific domain logic of your application. License The RouterSploit Framework is under a BSD license. Please see LICENSE for more details. Acknowledgments riposte {card-default label="📦 工具信息"} 🔗 项目地址:https://github.com/threat9/routersploit ⭐ Star数:13240 💻 开发语言:Python 📝 项目描述:嵌入式设备的利用框架 {/card-default} 总的来说,routersploit是一个功能比较实用的开源工具,适合日常工作和学习使用。如果你正在寻找一款相关工具,不妨下载试试。使用前建议仔细阅读项目文档。 本文介绍的工具来源于GitHub开源社区,仅供学习交流使用,请遵守原项目开源协议。 -
strix - 一款实用的开源工具 推荐一个实用的开源工具——strix。项目由usestrix开发维护,GitHub上获得了 61007 个Star。简单来说,它是一款开源人工智能渗透测试工具,用于查找和修复应用程序的漏洞。,对于站长和开发者来说是个不错的工具。 工具功能介绍 The open-source AI pentesting tool. Autonomous AI hackers that find and fix your app’s vulnerabilities. [!TIP] New! Strix integrates seamlessly with GitHub Actions and CI/CD pipelines. Automatically scan for vulnerabilities on every pull request and block insecure code before it reaches production - Get started with no setup required.---Strix OverviewStrix are autonomous AI penetration testing agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proofs-of-concept. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools.Key Capabilities:- Full pentesting toolkit - reconnaissance, exploitation, and validation out of the box Multi-agent orchestration - teams of AI pentesters that collaborate and scale Real exploit validation - working PoCs, not false positives like legacy vulnerability scanners Developer‑first CLI - actionable findings with remediation guidance Auto‑fix & reporting - generate patches and compliance-ready pentest reports Use Cases- Application Security Testing - Detect and validate critical vulnerabilities in your applications Rapid Penetration Testing - Get penetration tests done in hours, not weeks, with compliance reports Bug Bounty Automation - Automate bug bounty research and generate PoCs for faster reporting CI/CD Integration - Run tests in CI/CD to block vulnerabilities before reaching production 🚀 Quick StartPrerequisites: Docker (running) An LLM API key from any supported provider (OpenAI, Anthropic, Google, etc.) Installation & First Scan bash # Install Strix curl -sSL https://strix.ai/install | bash # Configure your AI provider export STRIX_LLM="openrouter/z-ai/glm-5.3" export LLM_API_KEY="your-api-key" # Run your first security assessment strix --target ./app-directory [!NOTE] First run automatically pulls the sandbox Docker image. Results are saved to strix_runs/---Ways to Run Strix- Open Source - free, runs locally with Docker and your own LLM key. Quick Start Strix Cloud - no setup, validated findings, one-click autofix, and PR reviews. Run a pentest → Enterprise - SSO, compliance-ready reports, VPC or self-hosted deployment. Try Strix Enterprise →--- ☁️ Strix CloudTry the Strix full-stack penetration testing platform at app.strix.ai - sign up for free, connect your repos and domains, and launch a pentest in minutes.- Validated findings with PoCs - every vulnerability includes a working proof-of-concept exploit and reproduction steps One-click autofix - AI-generated security patches as ready-to-merge pull requests Continuous pentesting - always-on vulnerability scanning that keeps pace with your deployments DevSecOps integrations - GitHub, GitLab, Bitbucket, Slack, Jira, Linear, and CI/CD pipelines Continuous learning - AI that builds on past findings, adapts to your codebase, and reduces false positives over timeRun a pentest → 🏢 EnterpriseGet the same Strix experience with enterprise-grade controls: SSO (SAML/OIDC), custom compliance-ready penetration testing reports (SOC 2, ISO 27001, PCI DSS), dedicated support and SLA, custom deployment options (VPC or self-hosted), BYOK model support, and tailored AI pentesting agents optimized for your environment.Try Strix Enterprise →--- 🤖 Use Strix from Your Coding AgentStrix is agent-ready. Give Claude Code, Cursor, Codex, or any SKILL.md-compatible agent the ability to run pentests, fix findings, and set up CI scanning: bash npx skills add usestrix/strix This installs nine skills for running pentests, fixing findings, and CI scanning, against code, web apps, APIs, and the OWASP Top 10. Agents can use the local CLI or the managed cloud with the same engine.See AGENTS.md for the quick reference, docs.strix.ai/llms.txt for the CLI, and docs.app.strix.ai for the API.--- ✨ Features Agentic Pentesting ToolsStrix agents come equipped with a comprehensive offensive security toolkit - the same tools used by professional penetration testers and ethical hackers:- HTTP Interception Proxy - Full request/response manipulation and analysis with Caido Browser Exploitation - Automated browser for testing XSS, CSRF, clickjacking, and auth bypass flows Shell & Command Execution - Interactive terminal for exploit development and post-exploitation Custom Exploit Runtime - Python sandbox for writing and validating proof-of-concept exploits Reconnaissance & OSINT - Automated attack surface mapping, subdomain enumeration, and fingerprinting Static & Dynamic Code Analysis - SAST + DAST capabilities for comprehensive application security testing Vulnerability Knowledge Base - Structured findings with CVSS scoring and OWASP classification Comprehensive Vulnerability ScannerStrix identifies, validates, and exploits a wide range of security vulnerabilities across the OWASP Top 10 and beyond:- Broken Access Control - IDOR, privilege escalation, auth bypass Injection Attacks - SQL injection, NoSQL injection, OS command injection, SSTI Server-Side Vulnerabilities - SSRF, XXE, insecure deserialization, RCE Client-Side Attacks - XSS (stored/reflected/DOM), prototype pollution, CSRF Business Logic Flaws - Race conditions, payment manipulation, workflow bypass Authentication & Session - JWT attacks, session fixation, credential stuffing vectors Infrastructure & Cloud - Misconfigurations, exposed services, cloud security issues API Security - Broken authentication, mass assignment, rate limiting bypass Graph of Agents (Multi-Agent Pentesting)Advanced multi-agent orchestration for comprehensive automated penetration testing:- Distributed Pentesting - Specialized AI agents for recon, exploitation, and post-exploitation Scalable Security Testing - Parallel execution across multiple targets for fast, comprehensive coverage Dynamic Coordination - Agents share discoveries, chain vulnerabilities, and collaborate like a red team--- 🖥️ Local Web ViewerEvery scan writes its results to disk as it runs. Bring them up in a local dashboard with a single command: bash # Open the most recent run strix view # ...or open a specific run by name strix view my-run-name # Expose the viewer on all IPv4 interfaces at a fixed port strix view --host 0.0.0.0 --port 8080 --no-open The dashboard shows the findings, a live map of the agent team, and past runs. Nothing leaves your machine, and the UI ships prebuilt. strix view binds to 127.0.0.1 and prints a tokened link that grants access to the run, so share it carefully.See the viewer documentation for the options and for reaching the viewer from another machine.--- Usage Examples Basic Usage bash # Scan a local codebase strix --target ./app-directory # Security review of a GitHub repository strix --target https://github.com/org/repo # Black-box web application assessment strix --target https://your-app.com API Testing (OpenAPI / Swagger / Postman)Point Strix at an API contract and it tests every declared endpoint instead of having to discover them by crawling. Pair the spec with the live base URL so the agent knows where to send traffic: bash # OpenAPI / Swagger file, Postman export, or a live collection by id strix --target ./openapi.yaml --target https://api.your-app.com strix --target postman:// --target https://api.your-app.com Advanced Testing Scenarios bash # Grey-box authenticated testing strix --target https://your-app.com --instruction "Perform authenticated testing using credentials: user:pass" # Multi-target testing (source code + deployed app) strix -t https://github.com/org/app -t https://your-app.com # Targets from a file, one target per non-empty, non-comment line strix --target-list ./targets.txt See the CLI reference for every option, including scan modes, diff scope, instruction files, and budgets. Headless ModeRun Strix programmatically without interactive UI using the -n/--non-interactive flag - perfect for servers and automated jobs. The CLI prints real-time vulnerability findings and the final report before exiting. Exits with non-zero code when vulnerabilities are found. bash strix -n --target https://your-app.com CI/CD (GitHub Actions)Strix can be added to your pipeline to run a security test on pull requests with a lightweight GitHub Actions workflow: yaml name: strix-penetration-teston: pull_request:jobs: security-scan: runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 with: fetch-depth: 0- name: Install Strix run: curl -sSL https://strix.ai/install | bash- name: Run Strix env: STRIX_LLM: ${{ secrets.STRIX_LLM }} LLM_API_KEY: ${{ secrets.LLM_API_KEY }}run: strix -n -t ./ --scan-mode quick [!TIP] In CI pull request runs, Strix automatically scopes quick reviews to changed files, which is why the checkout above fetches full history. See the CI/CD documentation for the details.Configuration bash export STRIX_LLM="openrouter/z-ai/glm-5.3" export LLM_API_KEY="your-api-key" # Optional export LLM_API_BASE="your-api-base-url" # if using a local model, e.g. Ollama, LMStudio [!NOTE] Strix automatically saves your configuration to ~/.strix/cli-config.json, so you don't have to re-enter it on every run. See the configuration reference for every environment variable.Sign in with a ChatGPT subscriptionInstead of a metered API key, you can run Strix on your ChatGPT Plus/Pro subscription: bash strix auth login chatgpt # sign in with your ChatGPT account export STRIX_LLM="chatgpt/gpt-5.4" # chatgpt/ runs on the subscription strix auth status # show the active sign-in, or logout to forget it Use the managed platform: strix cloudRun scans on app.strix.ai from the terminal, without Docker or an LLM key: bash strix cloud login # browser sign-in, one credential per install strix cloud scans start --source . --yes --wait # scan local code, approving the upload strix cloud scans start --engagement-type live_test --domain-ids --wait strix cloud vulns list --severity critical Every REST API operation has a matching strix cloud command. Run strix cloud to list the resources, and add help to a resource to list its verbs. Output is JSON when stdout is not a terminal or when you pass --json. Binary downloads are the exception: redirect the raw bytes, or combine --output FILE --json for download metadata.See the cloud CLI documentation for scopes, workspaces, billing, and source-upload options. Connect your own MCP serversStrix can connect to Model Context Protocol (MCP) servers you list and expose their tools to the agent during a run. Create ~/.strix/mcp-servers.json with a JSON list of local stdio servers or remote http servers: json [ { "name": "github", "transport": "http", "url": "https://api.githubcopilot.com/mcp/", "auth": { "kind": "bearer", "token": "your-token" }, "allowed_tools": ["list_issues"] } ] Each server's tools are namespaced by name, for example github_list_issues. See the MCP documentation for the full schema, tool filtering, and stdio servers.Recommended models for best results:- Z.ai GLM-5.3 on OpenRouter - openrouter/z-ai/glm-5.3 (the default pick) OpenAI GPT-5.4 - openai/gpt-5.4 Anthropic Claude Sonnet 4.6 - anthropic/claude-sonnet-4-6 Google Gemini 3 Pro Preview - vertex_ai/gemini-3-pro-preview DeepSeek V4 Pro - deepseek/deepseek-v4-pro Moonshot Kimi K3 - moonshot/kimi-k3See the LLM Providers documentation for all supported providers including Vertex AI, Bedrock, Azure, and local models. Documentation Full documentation is available at docs.strix.ai - including detailed guides for usage, CI/CD integrations, skills, and advanced configuration. Contributing We welcome contributions of code, docs, and new skills - check out our Contributing Guide to get started or open a pull request/issue. Join Our CommunityHave questions? Found a bug? Want to contribute? Join our Discord! Support the ProjectLove Strix? Give us a ⭐ on GitHub! Acknowledgements Strix builds on the incredible work of open-source projects like LiteLLM, Caido, Nuclei, Playwright, and Bubble Tea. Huge thanks to their maintainers!> [!WARNING] Authorized use only. Strix actively tests the targets you point it at, so only run it against systems you own or have explicit, written permission to test, and stay within the agreed scope. Unauthorized testing is illegal in most jurisdictions. You alone are responsible for obtaining authorization and complying with the law. Strix is provided "as is" with no warranty or liability for misuse.{card-default label="📦 工具信息"} 🔗 项目地址:https://github.com/usestrix/strix ⭐ Star数:61007 💻 开发语言:Python 📝 项目描述:开源人工智能渗透测试工具,用于查找和修复应用程序的漏洞。 {/card-default} 总的来说,strix是一个功能比较实用的开源工具,适合日常工作和学习使用。如果你正在寻找一款相关工具,不妨下载试试。使用前建议仔细阅读项目文档。 本文介绍的工具来源于GitHub开源社区,仅供学习交流使用,请遵守原项目开源协议。 -
开源安全工具 nuclei 推荐 推荐一个实用的开源工具——nuclei。项目由projectdiscovery开发维护,GitHub上获得了 31053 个Star。简单来说,它是一款Nuclei是一款快速、可定制的漏洞扫描器,由全球安全社区提供支持,构建在一个简单的基于YAML的DSL之上,使协作能够解决互联网上的流行漏洞。它可帮助您查找应用程序、API、网络、DNS和云配置中的漏洞。,对于站长和开发者来说是个不错的工具。 工具功能介绍 nuclei图片 Nuclei is a modern, high-performance vulnerability scanner that leverages simple YAML-based templates. It empowers you to design custom vulnerability detection scenarios that mimic real-world conditions, leading to zero false positives.- Simple YAML format for creating and customizing vulnerability templates. Contributed by thousands of security professionals to tackle trending vulnerabilities. Reduce false positives by simulating real-world steps to verify a vulnerability. Ultra-fast parallel scan processing and request clustering. Integrate into CI/CD pipelines for vulnerability detection and regression testing. Supports multiple protocols like TCP, DNS, HTTP, SSL, WHOIS, JavaScript, Code and more. Integrate with Jira, Splunk, GitHub, Elastic, GitLab. Get Started 1. Nuclei CLI 2. Pro and Enterprise Editions Documentation Command Line Flags Single target scan Scanning multiple targets Network scan Scanning with your custom template Connect Nuclei to ProjectDiscovery_ Nuclei Templates, Community and Rewards 💎 Our Mission Contributors ❤ License Get Started 1. Nuclei CLI_Install Nuclei on your machine. Get started by following the installation guide here. Additionally, we provide a free cloud tier that comes with generous monthly free limits:_- Store and visualize your vulnerability findings Write and manage your Nuclei templates Access the latest Nuclei templates Discover and store your targets> [!Important] This project is in active development. Expect breaking changes with releases. Review the release changelog before updating.This project is primarily built to be used as a standalone CLI tool. Running nuclei as a service may pose security risks. It's recommended to use with caution and additional security measures. 2. Pro and Enterprise Editions_For security teams and enterprises, we provide a cloud-hosted service built on top of Nuclei OSS, fine-tuned to help you continuously run vulnerability scans at scale with your team and existing workflows:_- 50x faster scans Large scale scanning with high accuracy Integrations with cloud services (AWS, GCP, Azure, Cloudflare, Fastly, Terraform, Kubernetes) Jira, Slack, Linear, APIs and Webhooks Executive and compliance reporting Plus: Real-time scanning, SAML SSO, SOC 2 compliant platform (with EU and US hosting options), shared team workspaces, and more We're constantly adding new features! Ideal for: Pentesters, security teams, and enterprisesSign up to Pro or Talk to our team if you have a large organization and complex requirements. Documentation Browse the full Nuclei documentation here. If you’re new to Nuclei, check out our foundational YouTube series. Installationnuclei requires go >= 1.24.2 to install successfully. Run the following command to get the repo: sh go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest To learn more about installing nuclei, see https://docs.projectdiscovery.io/tools/nuclei/install. Command Line FlagsTo display all the flags for the tool: sh nuclei -h Expand full help flags yaml Nuclei is a fast, template based vulnerability scanner focusing on extensive configurability, massive extensibility and ease of use.Usage: ./nuclei [flags]Flags: TARGET: -u, -target string[] target URLs/hosts to scan -l, -list string path to file containing a list of target URLs/hosts to scan (one per line) -targets-inline string inline multiline target list (for use in template profiles) -eh, -exclude-hosts string[] hosts to exclude to scan from the input list (ip, cidr, hostname) -resume string resume scan from and save to specified file (clustering will be disabled) -sa, -scan-all-ips scan all the IP's associated with dns record -iv, -ip-version string[] IP version to scan of hostname (4,6) - (default 4)TARGET-FORMAT: -im, -input-mode string mode of input file (list, burp, jsonl, yaml, openapi, swagger, http) (default "list") -ro, -required-only use only required fields in input format when generating requests -sfv, -skip-format-validation skip format validation (like missing vars) when parsing input file -vtt, -vars-text-templating enable text templating for vars in input file (only for yaml input mode) -vfp, -var-file-paths string[] list of yaml file contained vars to inject into yaml inputTEMPLATES: -nt, -new-templates run only new templates added in latest nuclei-templates release -ntv, -new-templates-version string[] run new templates added in specific version -as, -automatic-scan automatic web scan using wappalyzer technology detection to tags mapping -t, -templates string[] list of template or template directory to run (comma-separated, file) -turl, -template-url string[] template url or list containing template urls to run (comma-separated, file) -ai, -prompt string generate and run template using ai prompt -w, -workflows string[] list of workflow or workflow directory to run (comma-separated, file) -wurl, -workflow-url string[] workflow url or list containing workflow urls to run (comma-separated, file) -validate validate the passed templates to nuclei -nss, -no-strict-syntax disable strict syntax check on templates -td, -template-display displays the templates content -tl list all templates matching current filters -tgl list all available tags -sign signs the templates with the private key defined in NUCLEI_SIGNATURE_PRIVATE_KEY env variable -code enable loading code protocol-based templates -dut, -disable-unsigned-templates disable running unsigned templates or templates with mismatched signature -esc, -enable-self-contained enable loading self-contained templates -egm, -enable-global-matchers enable loading global matchers templates -file enable loading file templatesFILTERING: -a, -author string[] templates to run based on authors (comma-separated, file) -tags string[] templates to run based on tags (comma-separated, file) -etags, -exclude-tags string[] templates to exclude based on tags (comma-separated, file) -itags, -include-tags string[] tags to be executed even if they are excluded either by default or configuration -id, -template-id string[] templates to run based on template ids (comma-separated, file, allow-wildcard) -eid, -exclude-id string[] templates to exclude based on template ids (comma-separated, file) -it, -include-templates string[] path to template file or directory to be executed even if they are excluded either by default or configuration -et, -exclude-templates string[] path to template file or directory to exclude (comma-separated, file) -em, -exclude-matchers string[] template matchers to exclude in result -s, -severity value[] templates to run based on severity. Possible values: info, low, medium, high, critical, unknown -es, -exclude-severity value[] templates to exclude based on severity. Possible values: info, low, medium, high, critical, unknown -pt, -type value[] templates to run based on protocol type. Possible values: dns, file, http, headless, tcp, workflow, ssl, websocket, whois, code, javascript -ept, -exclude-type value[] templates to exclude based on protocol type. Possible values: dns, file, http, headless, tcp, workflow, ssl, websocket, whois, code, javascript -tc, -template-condition string[] templates to run based on expression conditionOUTPUT: -o, -output string output file to write found issues/vulnerabilities -sresp, -store-resp store all request/response passed through nuclei to output directory -srd, -store-resp-dir string store all request/response passed through nuclei to custom directory (default "output") -silent display findings only -nc, -no-color disable output content coloring (ANSI escape codes) -j, -jsonl write output in JSONL(ines) format -irr, -include-rr -omit-raw include request/response pairs in the JSON, JSONL, and Markdown outputs (for findings only) [DEPRECATED use -omit-raw] (default true) -or, -omit-raw omit request/response pairs in the JSON, JSONL, and Markdown outputs (for findings only) -ot, -omit-template omit encoded template in the JSON, JSONL output -nm, -no-meta disable printing result metadata in cli output -ts, -timestamp enables printing timestamp in cli output -rdb, -report-db string nuclei reporting database (always use this to persist report data) -ms, -matcher-status display match failure status -me, -markdown-export string directory to export results in markdown format -se, -sarif-export string file to export results in SARIF format -je, -json-export string file to export results in JSON format -jle, -jsonl-export string file to export results in JSONL(ine) format -pe, -pdf-export string file to export results in PDF format -rd, -redact string[] redact given list of keys from query parameter, request header and bodyCONFIGURATIONS: -config string path to the nuclei configuration file -tp, -profile string template profile config file to run -tpl, -profile-list list community template profiles -fr, -follow-redirects enable following redirects for http templates -fhr, -follow-host-redirects follow redirects on the same host -mr, -max-redirects int max number of redirects to follow for http templates (default 10) -dr, -disable-redirects disable redirects for http templates -rc, -report-config string nuclei reporting module configuration file -H, -header string[] custom header/cookie to include in all http request in header:value format (cli, file) -V, -var value custom vars in key=value format -r, -resolvers string file containing resolver list for nuclei -sr, -system-resolvers use system DNS resolving as error fallback -dc, -disable-clustering disable clustering of requests -passive enable passive HTTP response processing mode -fh2, -force-http2 force http2 connection on requests -ev, -env-vars enable environment variables to be used in template -cc, -client-cert string client certificate file (PEM-encoded) used for authenticating against scanned hosts -ck, -client-key string client key file (PEM-encoded) used for authenticating against scanned hosts -ca, -client-ca string client certificate authority file (PEM-encoded) used for authenticating against scanned hosts -sml, -show-match-line show match lines for file templates, works with extractors only -ztls use ztls library with autofallback to standard one for tls13 [Deprecated] autofallback to ztls is enabled by default -sni string tls sni hostname to use (default: input domain name) -dka, -dialer-keep-alive value keep-alive duration for network requests. -lfa, -allow-local-file-access allows file (payload) access anywhere on the system -lna, -restrict-local-network-access blocks connections to the local / private network -i, -interface string network interface to use for network scan -at, -attack-type string type of payload combinations to perform (batteringram,pitchfork,clusterbomb) -sip, -source-ip string source ip address to use for network scan -rsr, -response-size-read int max response size to read in bytes -rss, -response-size-save int max response size to read in bytes (default 1048576) -reset reset removes all nuclei configuration and data files (including nuclei-templates) -tlsi, -tls-impersonate enable experimental client hello (ja3) tls randomization -hae, -http-api-endpoint string experimental http api endpointINTERACTSH: -iserver, -interactsh-server string interactsh server url for self-hosted instance (default: oast.pro,oast.live,oast.site,oast.online,oast.fun,oast.me) -itoken, -interactsh-token string authentication token for self-hosted interactsh server -interactions-cache-size int number of requests to keep in the interactions cache (default 5000) -interactions-eviction int number of seconds to wait before evicting requests from cache (default 60) -interactions-poll-duration int number of seconds to wait before each interaction poll request (default 5) -interactions-cooldown-period int extra time for interaction polling before exiting (default 5) -ni, -no-interactsh disable interactsh server for OAST testing, exclude OAST based templatesFUZZING: -ft, -fuzzing-type string overrides fuzzing type set in template (replace, prefix, postfix, infix) -fm, -fuzzing-mode string overrides fuzzing mode set in template (multiple, single) -fuzz enable loading fuzzing templates (Deprecated: use -dast instead) -dast enable / run dast (fuzz) nuclei templates -dts, -dast-server enable dast server mode (live fuzzing) -dtr, -dast... {card-default label="📦 工具信息"} 🔗 项目地址:[https://github.com/projectdiscovery/nuclei](https://github.com/projectdiscovery/nuclei) ⭐ Star数:31053 💻 开发语言:Go 📝 项目描述:Nuclei是一款快速、可定制的漏洞扫描器,由全球安全社区提供支持,构建在一个简单的基于YAML的DSL之上,使协作能够解决互联网上的流行漏洞。它可帮助您查找应用程序、API、网络、DNS和云配置中的漏洞。 {/card-default} 总的来说,**nuclei**是一个功能比较实用的开源工具,适合日常工作和学习使用。如果你正在寻找一款相关工具,不妨下载试试。使用前建议仔细阅读项目文档。