Ross ROSS = Recommend OSS · open-source software intelligence for agents

ivre/ivre

Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc. observed · 2026-08-28

github.com/ivre/ivre · homepage · Python · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

66/100

  • Activity 96
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4373
  • days_rel: 707
  • days_push: 28
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

4119 stars · 698 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

IVRE is an open-source network recon framework written in Python that collects, stores, and analyzes network intelligence from active scanning tools (Nmap, Masscan, ZGrab2, ZDNS, ProjectDiscovery tools) and passive sensors (Zeek, Argus, p0f, Nfdump). It provides CLI tools, a Python API, and a Web UI backed by MongoDB, PostgreSQL, or Elasticsearch, enabling self-hosted alternatives to Shodan, Censys, and GreyNoise.

Use cases

  • build a self-hosted Shodan or Censys alternative
  • run a passive DNS service from network traffic captures
  • analyze and browse large Nmap or Masscan scan results
  • build a custom external attack surface management (EASM) tool
  • perform network flow analysis from Zeek or Argus data
  • scan and map internet-exposed services across countries or ASNs
  • search scan results for vulnerable service versions

When to choose

  • you need full control over network scan data instead of relying on commercial search engines like Shodan or Censys
  • you want to aggregate and query results from Nmap, Masscan, Zeek, and other recon tools in one place
  • you need to analyze very large scans more efficiently than Zenmap allows
  • you are building EASM or passive DNS capabilities on your own infrastructure

When to avoid

  • you need a turnkey hosted service with no infrastructure to manage
  • your focus is web application vulnerability scanning rather than network/service discovery
  • you lack the resources to run and maintain a database backend like MongoDB or Elasticsearch
  • you only need a one-off quick port scan without storage or analysis

Facets

framework · maturity active

security search-engine web-scraping analytics parser cli web-framework data-visualization security networking osint penetration-testing developer-tools python self-hosted cli network-recon nmap masscan zeek easm passive-dns attack-surface-management shodan-alternative network-intelligence osint linux macos docker web-server

3 sources

Member repositories

RepositoryRoleHealth v2
ivre/ivremain66

For agents

markdown · JSON · MCP: product_card(name="ivre/ivre")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem