ivre
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f,
The IVRE MCP server connects AI agents to a comprehensive network reconnaissance database framework. It exposes network intelligence gathered from passive tools like Zeek, p0f, and Argus, plus active scanning tools including Nmap, Masscan, and Nuclei, enabling agents to query scan results, host information, and network topology. Developers can build self-hosted alternatives to commercial threat intelligence platforms like Shodan or Censys, run passive DNS services, or create custom EASM (External Attack Surface Management) solutions. The server supports extension through custom plugins and integrates with multiple AI clients including Claude Desktop, Cursor, and VS Code.
Key Features
Use Cases
- 01Building AI-powered threat intelligence queries against self-hosted reconnaissance databases
- 02Creating custom EASM tools that analyze external attack surfaces through conversational interfaces
- 03Querying passive DNS records and network sensor data using natural language
- 04Automating network security assessments by letting agents analyze Nmap and Masscan results
- 05Developing alternatives to commercial platforms like Shodan, ZoomEye, or GreyNoise with AI agent access
- 06Correlating multiple reconnaissance data sources through agent-driven investigation workflows
Related MCP Servers
View moremarkitdown
Python tool for converting files and office documents to Markdown.
firecrawl
The context API to search, scrape, and interact with the web at scale. 🔥
prompts.chat
f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
langflow
Langflow is a powerful tool for building and deploying AI-powered agents and workflows.
ivre — FAQ
What is the IVRE MCP server?+
The IVRE MCP server is a Model Context Protocol implementation that exposes IVRE's network reconnaissance database to AI agents. It allows LLMs to query scan results, host information, and network intelligence collected from passive and active reconnaissance tools.
How do I install the IVRE MCP server?+
Install IVRE with MCP support using 'pip install ivre[mcp]', then run 'ivre mcp-server' to start the server. You'll need to configure your AI client (Claude Desktop, Cursor, etc.) to connect to the running MCP server endpoint.
Which AI clients work with the IVRE MCP server?+
The IVRE MCP server supports Claude Code, Claude Desktop, Cursor, OpenCode, VS Code, Windsurf, and JetBrains IDEs. Configuration instructions for each client are provided in the documentation.
Does the IVRE MCP server require API keys?+
No external API keys are required since IVRE is self-hosted. You'll need to set up an IVRE database (MongoDB, Elasticsearch, or PostgreSQL) and populate it with scan data from tools like Nmap or Zeek.
Is the IVRE MCP server free to use?+
Yes, IVRE is free and open-source software licensed under GNU GPL v3. You can freely use, modify, and redistribute it for any purpose.
Can I extend the IVRE MCP server with custom tools?+
Yes, the MCP server supports plugins that add additional tools and capabilities. Documentation on developing custom plugins is available in the doc/dev/mcp-plugins.rst file.
How do I install ivre?+
Open the source repository on GitHub and follow its README. ivre is a mcp server — MCP Agents Market links you directly to the official repo.
Is ivre free?+
ivre is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.