# ivre/ivre

Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.

Repository: https://github.com/ivre/ivre
Canonical: https://ross.abutalabs.com/products/ivre
Homepage: https://ivre.rocks/
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: bro, scans, nmap, network, network-discovery, scan-ports, security, network-security, nmap-results-analyse, nmap-parser, nmap-scripts, zeek, masscan, osint, hacktoberfest, easm, external-attack-surface-management, network-recon, network-reconnaissance, projectdiscovery
Last push: 2026-08-05T03:17:41+00:00

## Health v2 (maintenance only)
Score: 66/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 96, release rhythm 8, longevity 100
- inputs: {"age_days": 4373, "days_push": 28, "days_rel": 707, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4119, forks 698 (observed 2026-08-28T04:08:35.903456+00:00)

## What it is
IVRE is an open-source network recon framework written in Python that collects, stores, and analyzes network intelligence from active scanning tools (Nmap, Masscan, ZGrab2, ZDNS, ProjectDiscovery tools) and passive sensors (Zeek, Argus, p0f, Nfdump). It provides CLI tools, a Python API, and a Web UI backed by MongoDB, PostgreSQL, or Elasticsearch, enabling self-hosted alternatives to Shodan, Censys, and GreyNoise.

## Use cases
- build a self-hosted Shodan or Censys alternative
- run a passive DNS service from network traffic captures
- analyze and browse large Nmap or Masscan scan results
- build a custom external attack surface management (EASM) tool
- perform network flow analysis from Zeek or Argus data
- scan and map internet-exposed services across countries or ASNs
- search scan results for vulnerable service versions

## When to choose
- you need full control over network scan data instead of relying on commercial search engines like Shodan or Censys
- you want to aggregate and query results from Nmap, Masscan, Zeek, and other recon tools in one place
- you need to analyze very large scans more efficiently than Zenmap allows
- you are building EASM or passive DNS capabilities on your own infrastructure

## When to avoid
- you need a turnkey hosted service with no infrastructure to manage
- your focus is web application vulnerability scanning rather than network/service discovery
- you lack the resources to run and maintain a database backend like MongoDB or Elasticsearch
- you only need a one-off quick port scan without storage or analysis

## Facets
- artifact type: framework
- maturity: active
- function: security, search-engine, web-scraping, analytics, parser, cli, web-framework, data-visualization
- domain: security, networking, osint, penetration-testing, developer-tools
- platform: python, self-hosted, cli
- tags: network-recon, nmap, masscan, zeek, easm, passive-dns, attack-surface-management, shodan-alternative, network-intelligence, osint, linux, macos, docker, web-server

## Member repositories
- ivre/ivre (main) score 66

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:35.903456+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:23:07.728792+00:00, confidence not recorded.
  - readme: https://github.com/ivre/ivre (fetched 2026-08-28T04:08:35.903456+00:00, sha 05559c236e7f)
  - homepage: https://ivre.rocks/ (fetched 2026-08-29T09:15:31.240124+00:00, sha 43df940f8bdb)
  - registry_pypi: https://pypi.org/pypi/ivre/json (fetched 2026-08-29T09:15:31.253302+00:00, sha f35a5997109d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
