Skip to content
@projectdiscovery

ProjectDiscovery

Monitor your infrastructure. Real vulnerabilities. Zero noise.

ProjectDiscovery

ProjectDiscovery

Our mission is to Democratize Security.

ProjectDiscovery is an open source powered security company. We specialize in detecting new, exploitable vulnerabilities and misconfigurations so you can remediate them before hackers exploit them.

Getting Started

  • ProjectDiscovery Cloud Platform (PDCP) helps you find and quickly detect vulnerabiltiies for your most critcal assets. Get started for free and upgrade if needed to enable cloud scanning and other features.
  • Documentation where you can learn all about ProjectDiscovery and our tools
  • Run a Nuclei scan now with just a few steps
  • Learn more about templates, the cornerstone of the Nuclei scanning engine. Nuclei templates enable precise and rapid scanning across various protocols like TCP, DNS, HTTP, and more.
  • Need help? We're available on GitHub and Discord - feel free to reach out and join our community!

PD Open Source Tools

ProjectDiscovery produces a suite of open source tools tailored for offensive security: security engineers, bug bounty hunters, and red teamers. Our toolkit is structured around three distinct layers to optimize your security assessment and penetration testing processes. We also provide utilities and libraries as building blocks for an offensive security or bug bounty hunting program.

To learn about all of the tools, see our tools documentation or check out this video. You can also find the tools in our various GitHub repositories. A few of our most popular projects include:

  • nuclei: A fast and customizable vulnerability scanner based on simple YAML based DSL.
  • nuclei-templates: Community curated list of templates for the nuclei engine to find security vulnerabilities.
  • subfinder: A fast passive subdomain enumeration tool leveraging dozens of APIs.
  • httpx: A fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
  • cvemap: A CLI to Navigate the CVE jungle with ease.
  • katana: A next-generation crawling and spidering framework.
  • naabu: A fast port scanner written in go with a focus on reliability and simplicity.

Community

Our community is a dedicated space for security engineers and developers to collaborate, share knowledge, and learn how to manage vulnerability workflows more efficiently and effectively. By participating, you gain access to a wealth of resources, including tutorials, best practices, and the collective expertise of industry professionals, all aimed at enhancing your skills and improving your ability to handle security challenges.

Join Discord Follow Twitter

Contributing

Work with us

Love our mission and work? If you decide to contribute to any of our projects, we would be delighted to collaborate with you and refine your pull requests to near perfection. If you like the experience and think you might want to do this full-time, we are always hiring 🙌

Other Questions

Write us to hello@projectdiscovery.io for any other questions you might have.

Pinned Loading

  1. nuclei nuclei Public

    Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …

    Go 25.2k 2.9k

  2. nuclei-templates nuclei-templates Public

    Community curated list of templates for the nuclei engine to find security vulnerabilities.

    JavaScript 11.1k 3.1k

  3. subfinder subfinder Public

    Fast passive subdomain enumeration tool.

    Go 12.4k 1.5k

  4. httpx httpx Public

    httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

    Go 9.1k 978

  5. naabu naabu Public

    A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests

    Go 5.5k 627

  6. cvemap cvemap Public

    Modern CLI for exploring vulnerability data with powerful search, filtering, and analysis capabilities.

    Go 2.2k 157

Repositories

Showing 10 of 116 repositories
  • nuclei Public

    Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

    projectdiscovery/nuclei’s past year of commit activity
    Go 25,202 MIT 2,922 196 (1 issue needs help) 24 Updated Oct 27, 2025
  • httpx Public

    httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

    projectdiscovery/httpx’s past year of commit activity
    Go 9,121 MIT 978 18 4 Updated Oct 27, 2025
  • nuclei-templates Public

    Community curated list of templates for the nuclei engine to find security vulnerabilities.

    projectdiscovery/nuclei-templates’s past year of commit activity
    JavaScript 11,081 MIT 3,099 93 (6 issues need help) 99 Updated Oct 27, 2025
  • public-bugbounty-programs Public

    Community curated list of public bug bounty and responsible disclosure programs.

    projectdiscovery/public-bugbounty-programs’s past year of commit activity
    Go 1,236 MIT 381 3 (2 issues need help) 6 Updated Oct 27, 2025
  • cloudlist Public

    Cloudlist is a tool for listing Assets from multiple Cloud Providers.

    projectdiscovery/cloudlist’s past year of commit activity
    Go 981 MIT 121 2 3 Updated Oct 27, 2025
  • urlfinder Public

    A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.

    projectdiscovery/urlfinder’s past year of commit activity
    Go 737 MIT 59 2 0 Updated Oct 27, 2025
  • dnsx Public

    dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.

    projectdiscovery/dnsx’s past year of commit activity
    Go 2,529 MIT 271 9 4 Updated Oct 27, 2025
  • interactsh Public

    An OOB interaction gathering server and client library

    projectdiscovery/interactsh’s past year of commit activity
    Go 4,007 MIT 420 8 4 Updated Oct 27, 2025
  • fastdialer Public

    Dialer with DNS Cache + Dial History

    projectdiscovery/fastdialer’s past year of commit activity
    Go 66 MIT 25 3 1 Updated Oct 27, 2025
  • wappalyzergo Public

    A high performance go implementation of Wappalyzer Technology Detection Library

    projectdiscovery/wappalyzergo’s past year of commit activity
    Go 913 MIT 150 2 4 Updated Oct 26, 2025