IVRE
IVRE is a Python network reconnaissance framework that collects and analyzes scan and passive data, for building self-hosted alternatives to Shodan or Censys.
- GitHub stars
- 4.2k
- Last commit
- yesterday
- Latest release
- v0.9.21
- Licence
- GPL-3.0
- Self-hosted
- Yes

IVRE, a French acronym also read as Dynamic Recon of UNKnown networks, is a network reconnaissance framework with tools for both passive and active recon. It lets security teams build their own, fully controlled alternatives to services like Shodan, ZoomEye, Censys and GreyNoise.
It ingests data from passive sources such as Zeek, Argus, Nfdump, p0f and airodump-ng, and from active tools including Nmap, Masscan, ZGrab2, ZDNS, Nuclei, httpx, dnsx, tlsx and Dismap. Uses listed by the project include running a passive DNS service, assembling a tailor-made external attack surface management tool, and collecting and analyzing network intelligence from your own sensors. Topics reference Nmap result analysis and OSINT.
IVRE is written in Python and licensed under GPL-3.0, and runs on your own infrastructure. It suits security researchers and defenders who work on networks they are authorized to scan. As with any scanning tool, use it only where you have permission.
Key features
- Passive recon from Zeek and p0f data
- Active scanning with Nmap and Masscan
- Integration with Nuclei and httpx
- Passive DNS service capability
- External attack surface management
- Searchable network intelligence database
Pricing: Free and open source under GPL-3.0.