The Art of the Passive Check: Inside rxerium-templates

How a boutique collection of Nuclei scripts uses metadata forensics and Base64 decoding to hunt zero-day vulnerabilities without firing a single exploit.

6 min read • View on GitHub • More from rxerium

A person in a suit uses a jeweler's loupe to inspect a tiny serial number on the hinge of a heavy iron safe. This illustrates the concept of passive vulnerability checking, where metadata is inspected instead of attacking the system.
Passive checks rely on quiet observation rather than forced entry.
Key Takeaways

The Zero-Day Detection Gap

When a new vulnerability hits the CISA Known Exploited Vulnerabilities catalog, the clock starts. Security teams need to scan their infrastructure immediately. However, commercial vulnerability scanners often require days or weeks to push reliable detection signatures.

This lag creates a dangerous window of exposure. rxerium-templates steps into this gap as a hyper-fast, boutique feed of Nuclei templates. It provides detection capabilities for emerging threats almost as soon as the CVE drops, beating enterprise tools to the punch.

Forensics Over Force

The traditional approach to vulnerability scanning is inherently noisy and often destructive. Scanners hurl buffer overflows or SQL injections at a target, waiting to see if the server crashes or leaks data. This active scanning risks downtime and triggers Web Application Firewalls.

A split scene comparing a battering ram smashing a door to a gloved hand taking a wax impression of a keyhole. This contrasts active, destructive exploit scanning with passive, observational fingerprinting.
Active scanning attempts to break the system. Passive scanning merely asks the system to identify itself.

By contrast, rxerium-templates employs a strict "Passive-Active" philosophy. Instead of kicking the door down, it reads the manufacturer's serial number on the lock. By focusing on version fingerprinting and metadata analysis, these templates can conclusively identify a vulnerable system without firing a single malicious payload.

Unmasking Obfuscated Versions

The most elegant technical feat in the repository is how it handles targets that actively hide their version numbers. Take the template for the n8n vulnerability. The version string is not sitting in plain text. It is buried inside a Base64-encoded Sentry configuration block.

The in-memory Base64 extraction pipeline built using Nuclei's DSL.

The template extracts the Base64 string via regex, decodes it entirely in memory using Nuclei's DSL, and then isolates the true version number. It is a masterclass in extracting maximum signal from minimal, non-destructive noise.

The Favicon Fallback

What happens when a target completely scrubs its version numbers from the DOM? The templates fall back to environmental metadata. This is a calculated design choice that prioritizes coverage over absolute certainty, which is exactly what a rapid zero-day response requires.

A close-up of a standard ink fingerprint where the ridges and whorls are constructed entirely of tiny geometric shapes resembling website favicons. This illustrates how small, seemingly insignificant image files can be hashed to uniquely identify a server.
When explicit versioning is absent, the environment itself becomes the fingerprint.

For example, the Citrix NetScaler templates cross-reference the Last-Modified HTTP header, converting it to a Unix timestamp. They then combine this with an MMH3 hash of the site's favicon to verify the target's identity.

A Self-Documenting Threat Feed

The repository is more than just a folder of clever scripts. It is a self-maintaining threat intelligence dashboard. A lone Python script, update_readme_stats.py, serves as the engine for this automation.

import yaml

with open(filepath, 'r') as f:
    template = yaml.safe_load(f)
    cvss = template.get('info', {}).get('cvss-score')

Triggered by GitHub Actions, this script parses every YAML file, extracts CVSS scores and CISA KEV statuses, and dynamically injects the aggregated statistics into the README. It transforms a boutique collection of templates into a trusted, automated feed.