pielco11/fav-up
IP lookup by favicon using Shodan observed · 2026-08-28
Health v2 · maintenance only
25/100
- Activity 5
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2532
- days_rel: n/a
- days_push: 574
- n_releases_24m: 0
Adoption not part of the score
1199 stars · 148 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Fav-up is a Python CLI tool and library that finds the real IP address behind services like Cloudflare by hashing a website's favicon and searching for it via the Shodan API. It supports lookups from local favicon files, favicon URLs, or domain names, and can export results to CSV or JSON.
Use cases
- find the real IP behind a Cloudflare-protected site
- look up which servers use a given favicon
- identify phishing infrastructure hosting sites
- search Shodan by favicon hash
- deanonymize websites hiding their origin IP
- bulk lookup of favicons from a list of domains
When to choose
- you have a paid Shodan API key and need to map favicons to IPs
- you're doing OSINT or threat intelligence on websites behind CDNs
- you want a Python module you can integrate into recon workflows
When to avoid
- you only have a free Shodan account
- the target site has no favicon or a commonly shared one
- you need general-purpose IP geolocation rather than origin discovery
Facets
cli-tool · maturity active
osint search-engine cli developer-tools security osint networking python cli cross-platform shodan favicon-lookup cloudflare-bypass ip-lookup murmur3 osint-tool
1 source
- readme: https://github.com/pielco11/fav-up · fetched 2026-08-28 · ab6f057d5c3d
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| pielco11/fav-up | main | 25 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem