Tenable-style finding lifecycle
Dedup, evidence-driven detection state (new, active, resurfaced, mitigated), and analyst dispositions: accept-risk, false-positive, recast.
Open source and free to run. Small security teams often do not have the budget for expensive vulnerability scanners and platforms. Nuclei Security Center lets you deploy a vulnerability scanner on battle-proven Nuclei. It gives you everything you need to triage findings and escalate them to the people who can fix them.

The scanner is disposable and credential-less. The backend is what a team actually operates: a finding lifecycle, fail-closed scope, OIDC, and an audit trail.
Dedup, evidence-driven detection state (new, active, resurfaced, mitigated), and analyst dispositions: accept-risk, false-positive, recast.
Every scan stays inside approved targets. The guardrail matches before dispatch and fails closed. No approved targets, no scan.
Access and refresh tokens stay on the server. The browser holds an httpOnly session cookie. RBAC is enforced on every mutating endpoint.
Define targets and template sets, run on demand or on a cron schedule, and use naabu for port discovery before Nuclei.
Findings as JSON, CSV, SARIF, or raw JSONL. Complete scans import/export as versioned scan bundles (JSON or zip).
Backend is the system of record. Scanner nodes run nuclei, serve results over HTTP, and are reachable only backend → node.
Traffic is strictly backend to scanner. Raw scanner output archives to S3-compatible object storage. Every mutating call is a structured audit event.
Browser
React SPA, session cookie, roles
Served by the backend at the site root. The SPA talks to the session-authenticated API.
Backend
System of record
Postgres, OIDC/BFF, dispatch, ingestion, audit log, scope guardrail.
Scanner node
Credential-less nuclei runner
Pinned nuclei + naabu on UBI 10 Micro. No database credentials.
Finding data is some of the most sensitive information a security team holds. Nuclei Security Center is built so that data stays in the system of record, not on a scanner, and so a small team can run it without giving up the controls they would expect from an expensive platform. The project is scanned and reviewed regularly. Report issues privately through GitHub.
Scanner nodes hold no database credentials and never call the backend. Traffic is backend to node only. On an untrusted segment you can require TLS and mutual TLS so a stolen node cannot impersonate the backend.
OIDC runs as a BFF. Access and refresh tokens never reach JavaScript. The browser holds an httpOnly session cookie, RBAC is enforced on every mutating call, and cookie-authenticated changes must match the application origin.
Scans are rejected unless the target is already approved. Every mutation is a structured audit event to stdout, off the application database, for the log aggregator you already run.
The project is scanned and reviewed regularly, and security fixes land on the latest main and the newest tagged release. Use GitHub private vulnerability reporting rather than a public issue.
Run it locally with Docker Compose, or pull the published backend and scanner images from GitHub Container Registry. Images are built for both amd64 and arm64, and every release tag publishes a matching pair.
Only scan systems you own or are explicitly authorised to test. Scanning other systems without permission can be a criminal offence, including in Germany under §§ 202a–202c StGB.