ivre/ivre
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc. observed · 2026-08-28
Health v2 · maintenance only
66/100
- Activity 96
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 4373
- days_rel: 707
- days_push: 28
- n_releases_24m: 1
Adoption not part of the score
4119 stars · 698 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
IVRE is an open-source network recon framework written in Python that collects, stores, and analyzes network intelligence from active scanning tools (Nmap, Masscan, ZGrab2, ZDNS, ProjectDiscovery tools) and passive sensors (Zeek, Argus, p0f, Nfdump). It provides CLI tools, a Python API, and a Web UI backed by MongoDB, PostgreSQL, or Elasticsearch, enabling self-hosted alternatives to Shodan, Censys, and GreyNoise.
Use cases
- build a self-hosted Shodan or Censys alternative
- run a passive DNS service from network traffic captures
- analyze and browse large Nmap or Masscan scan results
- build a custom external attack surface management (EASM) tool
- perform network flow analysis from Zeek or Argus data
- scan and map internet-exposed services across countries or ASNs
- search scan results for vulnerable service versions
When to choose
- you need full control over network scan data instead of relying on commercial search engines like Shodan or Censys
- you want to aggregate and query results from Nmap, Masscan, Zeek, and other recon tools in one place
- you need to analyze very large scans more efficiently than Zenmap allows
- you are building EASM or passive DNS capabilities on your own infrastructure
When to avoid
- you need a turnkey hosted service with no infrastructure to manage
- your focus is web application vulnerability scanning rather than network/service discovery
- you lack the resources to run and maintain a database backend like MongoDB or Elasticsearch
- you only need a one-off quick port scan without storage or analysis
Facets
framework · maturity active
security search-engine web-scraping analytics parser cli web-framework data-visualization security networking osint penetration-testing developer-tools python self-hosted cli network-recon nmap masscan zeek easm passive-dns attack-surface-management shodan-alternative network-intelligence osint linux macos docker web-server
3 sources
- readme: https://github.com/ivre/ivre · fetched 2026-08-28 · 05559c236e7f
- homepage: https://ivre.rocks/ · fetched 2026-08-29 · 43df940f8bdb
- registry_pypi: https://pypi.org/pypi/ivre/json · fetched 2026-08-29 · f35a5997109d
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| ivre/ivre | main | 66 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem