{"id":14638203,"url":"https://github.com/0xKayala/NucleiFuzzer","last_synced_at":"2025-09-07T06:32:56.028Z","repository":{"id":168627633,"uuid":"644016278","full_name":"0xKayala/NucleiFuzzer","owner":"0xKayala","description":"NucleiFuzzer is a robust automation tool that efficiently detects web application vulnerabilities, including XSS, SQLi, SSRF, and Open Redirects, leveraging advanced scanning and URL enumeration techniques","archived":false,"fork":false,"pushed_at":"2025-07-17T17:26:18.000Z","size":157,"stargazers_count":1649,"open_issues_count":1,"forks_count":250,"subscribers_count":17,"default_branch":"main","last_synced_at":"2025-07-17T17:43:59.377Z","etag":null,"topics":["fuzzing-templates","gauplus","hakrawler","katana","nuclei","nuclei-templates","nucleifuzzer","paramspider","uro","waybackurls"],"latest_commit_sha":null,"homepage":"https://github.com/0xKayala/NucleiFuzzer","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/0xKayala.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null},"funding":{"github":null,"patreon":null,"open_collective":null,"ko_fi":null,"tidelift":null,"community_bridge":null,"liberapay":null,"issuehunt":null,"otechie":null,"lfx_crowdfunding":null,"custom":["https://www.paypal.me/ksatyaprakash","https://www.buymeacoffee.com/0xkayala"]}},"created_at":"2023-05-22T16:21:15.000Z","updated_at":"2025-07-17T17:26:21.000Z","dependencies_parsed_at":null,"dependency_job_id":"3d2bfbd0-0034-4bd1-a996-d2df61946260","html_url":"https://github.com/0xKayala/NucleiFuzzer","commit_stats":null,"previous_names":["0xkayala/nucleifuzzer"],"tags_count":6,"template":false,"template_full_name":null,"purl":"pkg:github/0xKayala/NucleiFuzzer","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xKayala%2FNucleiFuzzer","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xKayala%2FNucleiFuzzer/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xKayala%2FNucleiFuzzer/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xKayala%2FNucleiFuzzer/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/0xKayala","download_url":"https://codeload.github.com/0xKayala/NucleiFuzzer/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0xKayala%2FNucleiFuzzer/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":274005342,"owners_count":25205934,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-09-07T02:00:09.463Z","response_time":67,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["fuzzing-templates","gauplus","hakrawler","katana","nuclei","nuclei-templates","nucleifuzzer","paramspider","uro","waybackurls"],"created_at":"2024-09-10T02:01:56.188Z","updated_at":"2025-09-07T06:32:56.000Z","avatar_url":"https://github.com/0xKayala.png","language":"Shell","funding_links":["https://www.paypal.me/ksatyaprakash","https://www.buymeacoffee.com/0xkayala","https://www.buymeacoffee.com/0xKayala"],"categories":["Shell","Python"],"sub_categories":[],"readme":"\u003ch1 align=\"center\"\u003e \n  NucleiFuzzer = Nuclei + Paramspider + waybackurls + gauplus + hakrawler + katana + Fuzzing Templates\n  \u003cbr\u003e\n\u003c/h1\u003e\n\n\u003cp align=\"center\"\u003e\n\u003ca href=\"https://github.com/0xKayala/NucleiFuzzer/issues\"\u003e\u003cimg src=\"https://img.shields.io/badge/contributions-welcome-brightgreen.svg?style=flat\"\u003e\u003c/a\u003e\n\u003ca href=\"https://github.com/0xKayala/NucleiFuzzer/releases\"\u003e\u003cimg src=\"https://img.shields.io/github/v/release/0xkayala/NucleiFuzzer.svg\"\u003e\u003c/a\u003e\n\u003ca href=\"https://twitter.com/0xKayala\"\u003e\u003cimg src=\"https://img.shields.io/twitter/follow/0xKayala.svg?logo=twitter\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n## Overview\n`NucleiFuzzer` is an advanced automation tool designed to streamline and optimize web application security testing by integrating a suite of powerful URL discovery and vulnerability scanning tools. It combines `ParamSpider`, `Waybackurls`, `Katana`, `Gauplus`, and `Hakrawler` to comprehensively gather and enumerate potential entry points for web applications. Leveraging the power of `Nuclei`, it scans these endpoints using `fuzzing-templates` to effectively uncover a wide range of vulnerabilities.\n\nThe enhanced `NucleiFuzzer` is built for speed and accuracy, utilizing advanced URL validation, deduplication with `uro`, and precise HTTP filtering using `httpx`. This tool provides `security professionals`, `bug bounty hunters`, and `web developers` with a seamless workflow to detect and address security risks, ensuring robust web application protection.\n\n## Key Features:\n1. Comprehensive URL Discovery: Integrates multiple tools (`ParamSpider`, `Waybackurls`, `Katana`, `Gauplus`, and `Hakrawler`) to ensure exhaustive coverage of URLs and parameters.\n2. Enhanced Vulnerability Scanning: Uses `Nuclei` with `fuzzing-templates` to identify critical security issues with precision.\n3. Advanced Filtering and Validation: Removes duplicates and irrelevant results using `uro` and `httpx` for cleaner and more focused scanning.\n4. Rate Limiting for Efficiency: Allows customizable request rates for optimal performance during scans.\n5. Customizable and User-Friendly: Easy-to-configure options for domains, files, and output directories, catering to both individual and batch scans.\n\nTake advantage of `NucleiFuzzer` to safeguard your web applications against vulnerabilities and attacks with an enhanced, efficient, and reliable security testing solution!\n\n**Note:** `Nuclei` + `Paramspider` + `waybackurls` + `gauplus` + `hakrawler` + `katana` + `Fuzzing Templates` = `NucleiFuzzer` \u003cbr\u003e\u003cbr\u003e\n**Important:** Make sure the tools `Nuclei`, `Paramspider`, `waybackurls`, `gauplus`, `hakrawler`, `katana`, `httpx` \u0026 `uro` are installed on your machine and executing correctly to use the `NucleiFuzzer` without any issues.\n\n### Tools included:\n- [Nuclei](https://github.com/projectdiscovery/nuclei) `git clone https://github.com/projectdiscovery/nuclei.git`\u003cbr\u003e\n- [ParamSpider](https://github.com/0xKayala/ParamSpider) `git clone https://github.com/0xKayala/ParamSpider.git`\u003cbr\u003e\n- [waybackurls](https://github.com/tomnomnom/waybackurls) `git clone https://github.com/tomnomnom/waybackurls.git`\u003cbr\u003e\n- [gauplus](https://github.com/bp0lr/gauplus) `git clone https://github.com/bp0lr/gauplus.git`\u003cbr\u003e\n- [hakrawler](https://github.com/hakluke/hakrawler) `git clone https://github.com/hakluke/hakrawler.git`\u003cbr\u003e\n- [katana](https://github.com/projectdiscovery/katana) `git clone https://github.com/projectdiscovery/katana.git`\u003cbr\u003e\n- [httpx](https://github.com/projectdiscovery/httpx) `git clone https://github.com/projectdiscovery/httpx.git`\u003cbr\u003e\n- [uro](https://github.com/s0md3v/uro) `https://github.com/s0md3v/uro.git`\u003cbr\u003e\n\n\n### Templates:\n[Fuzzing Templates](https://github.com/projectdiscovery/nuclei-templates) `git clone https://github.com/projectdiscovery/nuclei-templates.git`\n\n## Screenshot\n\u003cimg width=\"1067\" height=\"559\" alt=\"image\" src=\"https://github.com/user-attachments/assets/3938d952-a3fd-4916-9d8e-89a1477b7065\" /\u003e\n\n\n## Output\n\u003cimg width=\"1733\" height=\"901\" alt=\"image\" src=\"https://github.com/user-attachments/assets/7fe78908-4f3f-4d8d-82cc-6eb406a7cf3c\" /\u003e\n\n\n## Usage\n\n```sh\nnf -h\n```\n\nThis will display help for the tool. Here are the options it supports.\n\n```console\nNucleiFuzzer: A Powerful Automation Tool for Web Vulnerability Scanning\n\nUsage: /usr/bin/nf [options]\n\nOptions:\n  -h, --help              Display help information\n  -d, --domain \u003cdomain\u003e   Single domain to scan for vulnerabilities\n  -f, --file \u003cfilename\u003e   File containing multiple domains/URLs to scan\n  -o, --output \u003cfolder\u003e   Specify output folder for scan results (default: ./output)\n```  \n\n## Installation:\n\nTo install `NucleiFuzzer`, follow these steps:\n\n```\ngit clone https://github.com/0xKayala/NucleiFuzzer.git \u0026\u0026 cd NucleiFuzzer \u0026\u0026 sudo chmod +x install.sh \u0026\u0026 ./install.sh \u0026\u0026 (command -v nf \u0026\u003e /dev/null \u0026\u0026 nf -h || echo \"Installation failed: Command 'nf' not found. Please check for errors during installation.\") \u0026\u0026 cd .. || echo \"Failed to clone or navigate to NucleiFuzzer repository. Please check your setup.\"\n```\n\n## Examples:\n\nHere are a few examples of how to use NucleiFuzzer:\n\n- Run `NucleiFuzzer` on a single domain:\n\n  ```sh\n  nf -d example.com\n  ```\n\n- Run `NucleiFuzzer` on multiple domains from a file:\n\n  ```sh\n  nf -f file.txt\n  ```\n\n## Practical Demonstration:\n\nFor a Practical Demonstration of the NucleiFuzzer tool see the below video 👇 \u003cbr\u003e\n\n[\u003cimg src=\"https://img.youtube.com/vi/2K2gTCHt6kg/hqdefault.jpg\" width=\"600\" height=\"300\"/\u003e](https://www.youtube.com/embed/2K2gTCHt6kg)\n\n## Star History\n\n\u003ca href=\"https://star-history.com/#0xKayala/NucleiFuzzer\u0026Date\"\u003e\n \u003cpicture\u003e\n   \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://api.star-history.com/svg?repos=0xKayala/NucleiFuzzer\u0026type=Date\u0026theme=dark\" /\u003e\n   \u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://api.star-history.com/svg?repos=0xKayala/NucleiFuzzer\u0026type=Date\" /\u003e\n   \u003cimg alt=\"Star History Chart\" src=\"https://api.star-history.com/svg?repos=0xKayala/NucleiFuzzer\u0026type=Date\" /\u003e\n \u003c/picture\u003e\n\u003c/a\u003e\n\n## Contributing\n\nContributions are welcome! If you'd like to contribute to `NucleiFuzzer`, please follow these steps:\n\n1. Fork the repository.\n2. Create a new branch.\n3. Make your changes and commit them.\n4. Submit a pull request.\n\nMade by\n`Satya Prakash` | `0xKayala` \\\n\nA `Security Researcher` and `Bug Hunter` \\\n\n## Connect with me:\n\u003cp align=\"left\"\u003e\n\u003ca href=\"https://twitter.com/0xkayala\" target=\"blank\"\u003e\u003cimg align=\"center\" src=\"https://raw.githubusercontent.com/rahuldkjain/github-profile-readme-generator/master/src/images/icons/Social/twitter.svg\" alt=\"0xkayala\" height=\"30\" width=\"40\" /\u003e\u003c/a\u003e\n\u003ca href=\"https://linkedin.com/in/0xkayala\" target=\"blank\"\u003e\u003cimg align=\"center\" src=\"https://raw.githubusercontent.com/rahuldkjain/github-profile-readme-generator/master/src/images/icons/Social/linked-in-alt.svg\" alt=\"0xkayala\" height=\"30\" width=\"40\" /\u003e\u003c/a\u003e\n\u003ca href=\"https://instagram.com/0xkayala\" target=\"blank\"\u003e\u003cimg align=\"center\" src=\"https://raw.githubusercontent.com/rahuldkjain/github-profile-readme-generator/master/src/images/icons/Social/instagram.svg\" alt=\"0xkayala\" height=\"30\" width=\"40\" /\u003e\u003c/a\u003e\n\u003ca href=\"https://medium.com/@0xkayala\" target=\"blank\"\u003e\u003cimg align=\"center\" src=\"https://raw.githubusercontent.com/rahuldkjain/github-profile-readme-generator/master/src/images/icons/Social/medium.svg\" alt=\"@0xkayala\" height=\"30\" width=\"40\" /\u003e\u003c/a\u003e\n\u003ca href=\"https://www.youtube.com/@0xkayala\" target=\"blank\"\u003e\u003cimg align=\"center\" src=\"https://raw.githubusercontent.com/rahuldkjain/github-profile-readme-generator/master/src/images/icons/Social/youtube.svg\" alt=\"0xkayala\" height=\"30\" width=\"40\" /\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n## Support me:\n\u003cp\u003e\u003ca href=\"https://www.buymeacoffee.com/0xKayala\"\u003e \u003cimg align=\"left\" src=\"https://cdn.buymeacoffee.com/buttons/v2/default-yellow.png\" height=\"50\" width=\"210\" alt=\"0xKayala\" /\u003e\u003c/a\u003e\u003c/p\u003e\u003cbr\u003e\u003cbr\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2F0xKayala%2FNucleiFuzzer","html_url":"https://awesome.ecosyste.ms/projects/github.com%2F0xKayala%2FNucleiFuzzer","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2F0xKayala%2FNucleiFuzzer/lists"}