awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
ivre avatar

ivre/ivre

0
View on GitHub↗
4,065 stars·694 forks·Python·GPL-3.0·27 viewsivre.rocks↗

Ivre

This project is a network reconnaissance framework and internet metadata database used for collecting, storing, and analyzing data from active scanners and passive traffic captures. It functions as a threat intelligence aggregator and passive traffic analysis tool, merging scan results from multiple tools into a unified dataset for security investigation.

The system distinguishes itself through its ability to visualize network assets using heatmaps and geographic charts to correlate autonomous systems and domain names. It provides external attack surface management by aggregating metadata to monitor the security posture of public internet assets and mapping connections between nodes to track communication patterns.

The platform covers a broad range of capabilities including active asset scanning, firewall log ingestion, and the archiving of network certificates and keys. It includes a search service for indexing devices across private or public internet ranges and integrates third-party network tools via a plugin-based system. Access to the data is managed through a web interface using key-based authentication and external headers.

Features

  • Internet Metadata Databases - Provides a searchable repository for indexing network assets, certificates, and service information.
  • Network Reconnaissance - Provides a complete system for collecting, storing, and analyzing data from active scanners and passive traffic captures.
  • Network Scanning - Identifies open ports and common products across an address space using active scanning and heatmaps.
  • Network Asset Indexes - Provides a searchable index of network devices across private or public internet ranges.
  • Network Discovery - Identifies open ports and active services across large address spaces to map the available attack surface.
  • Attack Surface Management - Aggregates scan results and metadata to visualize and monitor the security posture of public internet assets.
  • Passive Analysis Pipelines - Extracts host and service intelligence from captured network packets without initiating active connections.
  • Network Intelligence Extraction - Provides passive traffic analysis to extract host and service intelligence from network captures and firewall logs.
  • Passive Intelligence Gathering - Collects and indexes network reconnaissance data to build searchable directories of devices and communication patterns.
  • Reconnaissance Result Aggregators - Merges scan results from multiple active reconnaissance tools into a single unified dataset for security investigation.
  • Threat Intelligence Aggregation - Functions as a central hub for merging scan results from multiple tools into a unified dataset.
  • Network Reconnaissance Visualizations - Generates charts and maps to correlate autonomous systems, domain names, and geographic locations.
  • Address Space Heatmaps - Maps address space occupancy and port status onto a coordinate-based grid to identify network patterns.
  • Relational Database Persistence - Uses a relational schema to store structured network metadata and scan results for historical analysis.
  • Scan Result Visualizers - Visualizes port scan results and autonomous system mappings through heatmaps and geographic charts.
  • IP Range Indexers - Creates an optimized index of scanned network devices for fast retrieval across large IP ranges.
  • Network Flow Visualizers - Maps connections between nodes and autonomous systems to analyze data flows and geographic distributions.
  • Standardized Output Wrappers - Integrates diverse third-party network tools by wrapping their binary outputs into a standardized internal format.
  • Traffic Flow Aggregators - Maps connections between network nodes to track communication patterns and detailed flow data.
  • Reconnaissance and Discovery - Network recon framework to build alternatives to Shodan/ZoomEye/Censys.
  • Data Visualization - A framework for network reconnaissance and self-hosted security analysis.

Star history

Star history chart for ivre/ivreStar history chart for ivre/ivre

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does ivre/ivre do?

This project is a network reconnaissance framework and internet metadata database used for collecting, storing, and analyzing data from active scanners and passive traffic captures. It functions as a threat intelligence aggregator and passive traffic analysis tool, merging scan results from multiple tools into a unified dataset for security investigation.

What are the main features of ivre/ivre?

The main features of ivre/ivre are: Internet Metadata Databases, Network Reconnaissance, Network Scanning, Network Asset Indexes, Network Discovery, Attack Surface Management, Passive Analysis Pipelines, Network Intelligence Extraction.

What are some open-source alternatives to ivre/ivre?

Open-source alternatives to ivre/ivre include: six2dez/reconftw — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the… findomain/findomain — Findomain is a subdomain discovery tool and DNS resolver used for mapping an organization's external attack surface.… projectdiscovery/nuclei — Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure… smicallef/spiderfoot — SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the… lanmaster53/recon-ng — recon-ng is an open source intelligence reconnaissance framework designed to automate the collection and aggregation… owasp-amass/amass — Amass is an attack surface management tool designed to identify, map, and inventory an organization's internet-facing…

Open-source alternatives to Ivre

Similar open-source projects, ranked by how many features they share with Ivre.
  • six2dez/reconftwsix2dez avatar

    six2dez/reconftw

    7,226View on GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    View on GitHub↗7,226
  • findomain/findomainFindomain avatar

    Findomain/Findomain

    3,684View on GitHub↗

    Findomain is a subdomain discovery tool and DNS resolver used for mapping an organization's external attack surface. It functions as a DNS infrastructure analyzer that searches for registered subdomains associated with a root domain to uncover undocumented infrastructure and services. The project includes an attack surface monitor that tracks changes to subdomains over time, using differential state monitoring to identify newly created or deleted assets. It provides real-time alerting via webhooks when changes in the monitored domain surface are detected. The system performs high-speed DNS r

    Rustbugbountydnsosint
    View on GitHub↗3,684
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Goattack-surfacecve-scannerdast
    View on GitHub↗29,189
  • smicallef/spiderfootsmicallef avatar

    smicallef/spiderfoot

    18,189View on GitHub↗

    SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati

    Pythonattacksurfacecticybersecurity
    View on GitHub↗18,189
See all 30 alternatives to Ivre→