شرح nuclei بالعربي: أقوى أداة مسح للثغرات في Bug Bounty
4 أكتوبر 2026 · بواسطة Pentevo
nuclei هي أداة مسح للثغرات مبنية على قوالب (Templates) مجتمعية. بدلًا من Scanner ضخم يفعل كل شيء بكفاءة منخفضة، nuclei تُشغّل آلاف الفحوصات الدقيقة الموثّقة بسرعة فائقة.
التثبيت
# عبر Go
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
# تحديث القوالب (مهم — افعله دائمًا أولًا)
nuclei -update-templates
nuclei -update
# التحقق من الإصدار
nuclei -version
الاستخدام الأساسي
# فحص هدف واحد (كل القوالب)
nuclei -u https://example.com
# فحص مع حد الخطورة
nuclei -u https://example.com -severity critical,high
# فحص قائمة أهداف
cat targets.txt | nuclei -severity high,critical
# حفظ النتائج
nuclei -u https://example.com -o results.txt
nuclei -u https://example.com -o results.json -json
أهم فئات القوالب
# بنية مجلد القوالب
~/.local/nuclei-templates/
├── cves/ # ثغرات CVE الموثّقة
├── exposures/ # ملفات ومعلومات مكشوفة
├── misconfigurations/ # إعدادات خاطئة
├── technologies/ # كشف التقنيات
├── takeovers/ # Subdomain Takeover
├── default-logins/ # بيانات دخول افتراضية
├── panels/ # لوحات تحكم مكشوفة
└── vulnerabilities/ # ثغرات متنوعة
فحص بفئة محددة
# CVEs فقط
nuclei -u https://example.com -t cves/
# ملفات وبيانات مكشوفة
nuclei -u https://example.com -t exposures/
# Subdomain Takeover
nuclei -l subdomains.txt -t takeovers/
# لوحات تحكم مكشوفة (Jenkins، Grafana، etc.)
nuclei -l live_hosts.txt -t panels/
# بيانات دخول افتراضية
nuclei -l live_hosts.txt -t default-logins/
# إعدادات خاطئة
nuclei -u https://example.com -t misconfigurations/
Workflow المثالي لـ Bug Bounty
# الخطوة 1: فحص سريع للخطورة العالية فقط
nuclei -l live_hosts.txt \
-severity critical,high \
-o critical_high.txt \
-silent \
-stats
# الخطوة 2: فحص الـ Exposures (كثيرًا ما تُعطي نتائج قيّمة)
nuclei -l live_hosts.txt \
-t exposures/ \
-o exposures.txt \
-silent
# الخطوة 3: فحص Takeovers على كل النطاقات
nuclei -l all_subdomains.txt \
-t takeovers/ \
-o takeovers.txt
# الخطوة 4: CVEs للتقنيات المكتشفة
nuclei -l live_hosts.txt \
-t cves/ \
-severity medium,high,critical \
-o cves.txt
كتابة قالب nuclei مخصص
أقوى ميزة في nuclei. مثال على قالب للكشف عن ملف .env مكشوف:
id: exposed-env-file
info:
name: Exposed .env File
author: yourname
severity: high
description: Detects exposed .env files that may contain API keys and passwords
tags: exposure,config,env
http:
- method: GET
path:
- "{{BaseURL}}/.env"
- "{{BaseURL}}/.env.local"
- "{{BaseURL}}/.env.production"
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
words:
- "APP_KEY="
- "DB_PASSWORD="
- "SECRET_KEY="
- "API_KEY="
condition: or
part: body
extractors:
- type: regex
name: env-variables
regex:
- "[A-Z_]+=.+"
part: body
مثال: IDOR Detection
id: idor-user-profile
info:
name: Potential IDOR in User Profile API
author: yourname
severity: medium
description: Tests if user profile endpoint is vulnerable to IDOR
tags: idor,api
http:
- raw:
- |
GET /api/users/{{user_id}}/profile HTTP/1.1
Host: {{Hostname}}
Authorization: Bearer {{token}}
payloads:
user_id:
- "1"
- "2"
- "100"
- "999"
token:
- "YOUR_TEST_TOKEN_HERE"
matchers:
- type: status
status:
- 200
- type: word
words:
- "email"
- "phone"
- "address"
condition: and
part: body
تشغيل قالب مخصص
# تشغيل قالب محدد
nuclei -u https://example.com -t my-template.yaml
# تشغيل مجلد من القوالب المخصصة
nuclei -l targets.txt -t custom-templates/ -o results.txt
خيارات متقدمة
# تجاهل SSL
nuclei -u https://example.com -nc # no color
nuclei -u https://example.com -silent # بدون تفاصيل
# Rate limiting (مهم لـ Bug Bounty)
nuclei -l targets.txt -rl 50 -c 25 # 50 requests/sec، 25 concurrent
# Header مخصص (للمصادقة)
nuclei -u https://example.com \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Cookie: session=YOUR_SESSION"
# تجاهل قوالب بعينها
nuclei -u https://example.com -exclude-templates cves/
# فحص بـ Tags محددة
nuclei -u https://example.com -tags xss,sqli,ssrf
# Verbose output للـ debugging
nuclei -u https://example.com -v -debug
قراءة النتائج
# قراءة JSON output
cat results.json | jq '.[] | {url: .matched-at, template: .template-id, severity: .info.severity}'
# فلترة بالخطورة
cat results.json | jq '.[] | select(.info.severity == "critical")'
# عد النتائج
cat results.txt | grep "\[critical\]" | wc -l
الخلاصة
nuclei مع قوالبها الـ 8,000+ هي أسرع طريقة للعثور على ثغرات شائعة ومعروفة. شغّلها دائمًا على live_hosts.txt كجزء من workflow الـ Recon. والأهم: تعلّم كتابة قوالب مخصصة — كل ثغرة تجدها يدويًا يمكن تحويلها لقالب يُساعدك وتُشاركه مع المجتمع.
الأسئلة الشائعة
هل nuclei يُعطي false positives كثيرة؟
أقل من معظم الأدوات لأنها مبنية على قوالب موثّقة مجتمعيًا. لكن تحقق دائمًا يدويًا من كل نتيجة قبل الإرسال لبرنامج Bug Bounty.
هل nuclei مجاني؟
نعم، مفتوح المصدر بالكامل. القوالب المجتمعية مجانية. هناك نسخة مدفوعة (Nuclei Cloud) لمشاركة الفرق والـ CI/CD.
هل يمكنني إنشاء قوالب nuclei الخاصة؟
نعم وهو من أقوى ميزاته. القوالب مكتوبة بـ YAML وسهلة التعلم. يمكنك كتابة قالب لثغرة اكتشفتها وتوثيقها.
مقالات ذات صلة
أدوات Bug Bounty الأساسية التي يستخدمها المحترفون في 2026
قائمة شاملة بأفضل أدوات Bug Bounty: Burp Suite وffuf وnuclei وsubfinder وhttpx — مع شرح عملي لكيفية استخدام كل أداة.
toolsشرح ffuf بالعربي: الدليل الكامل لـ Fuzzing في Bug Bounty
تعلّم ffuf من الصفر: Directory Fuzzing وParameter Discovery وVHost Enumeration مع أمثلة عملية وأفضل الـ Wordlists لكل سيناريو.
toolsLinux للهاكرز: الأوامر الأساسية التي يجب أن يعرفها كل باحث أمني
دليل Linux المتخصص لاختبار الاختراق: أوامر الشبكة، إدارة الملفات، البرمجة النصية، وأدوات Kali Linux الأساسية التي تحتاجها يوميًا.
طبّق هذا عمليًا
أكاديمية Pentevo تحوّل هذه المفاهيم إلى دروس موجّهة وفيديوهات واختبارات — مجانًا.
ابدأ التعلّم مجانًا