Skip to main content
The Nucleus integration lets you send security findings to Nucleus for vulnerability management.
Available on NetSec, WebNetSec, and Pentest Suite plans.

What is Nucleus?

Nucleus is a vulnerability management platform that aggregates findings from multiple security tools into a single view. It handles deduplication across tools, remediation workflows, and reporting.

Setting up Nucleus

1

Get API credentials

In Nucleus, obtain your API key.
2

Configure credentials

In Pentest-Tools.com, go to Settings > Integrations > Nucleus and enter your subdomain and API key.
3

Add projects

Add Nucleus projects to send findings to.
4

Start sending

Send findings manually from the findings list, or set up a notification to push findings to Nucleus when a scan completes.

Sending findings

You can send findings to Nucleus from the findings list in two ways: Single finding: open a finding and click Send to Nucleus, or use the row action menu. Multiple findings at once: select findings from the list, then click Send to Nucleus in the toolbar. Choose the target Nucleus project and the findings are queued for upload. You get a notification when the upload completes.

Automatic sync via notifications

You can also configure notifications to send scan results to Nucleus automatically when scans complete:
  1. Create a notification
  2. Select a Nucleus project as the destination
  3. Findings are sent when scans finish

Nucleus projects

Add multiple Nucleus projects to organize findings:
Create different projects for different environments (production, staging) or teams.

What gets sent

Severity mapping

Tracking sent findings

After sending findings to Nucleus:
  • Findings show a Nucleus indicator
  • You can track which findings have been sent
  • Avoid duplicate submissions

Troubleshooting

  • Verify API credentials are correct
  • Check the project ID exists in Nucleus
  • Review the subdomain configuration
  • Regenerate your API key in Nucleus
  • Update the credentials in Pentest-Tools.com
  • Check Nucleus deduplication rules
  • Verify you haven’t already sent the findings