A fast, open-source recon-oriented tech stack fingerprinting CLI.
Identify the technologies exposed by a target website or service, straight from the terminal.
Inoue is designed to identify the technologies exposed by a target website or service, with a broad signature catalog that covers servers, runtimes, CMS platforms, ecommerce stacks, frameworks, JavaScript libraries, analytics tools, payment providers, admin panels, cloud/self-hosted management surfaces, VPN portals, and IoT/admin devices.
It is useful for recon, CTF/HTB, bug bounty, internal network review, and general surface analysis.
Maintained by Alham Rizvi.
A major recon and security-posture release, still fully read-only:
- ~21,000-signature fingerprint catalog with aggressive version detection
(every version carries a
version_sourceso a precisely-parsed value is never confused with a best-effort guess) - technology end-of-life detection against a verified EOL table
- JS bundle intelligence: fetches same-origin scripts and re-runs them through the full catalog, closing the client-rendered/SPA detection gap, plus redacted secret-pattern findings and endpoint extraction
- WAF/CDN detection, security header grading, CORS misconfiguration detection, cookie/CSP/redirect-chain/HTTP-method posture checks
- SPF/DMARC/DKIM/MTA-STS email security analysis
- subdomain takeover fingerprinting and API surface discovery (OpenAPI/ Swagger detection, GraphQL introspection status)
- a triage risk score combining every signal above into one ordered view
- scope guardrails (
--scope): domain wildcard + CIDR matching, so recon modules that fan out to discovered subdomains refuse to touch anything outside a declared scope - optional orchestration of subfinder, naabu, nmap, nuclei, gau, waybackurls, katana, and gowitness when installed, with graceful degradation when they aren't
- append-only scan history with timeline diffing
- an MCP server (7 read-only tools, dual SDK support, stdio/SSE/ streamable-HTTP transports) and a FastAPI backend at parity with the CLI
- the Chrome/Firefox extension, now with a proper toolbar icon
See CHANGELOG.md for the full list, including three
real bugs found via live testing and fixed at the root: a catalog-wide
confidence-inflation issue affecting 96.5% of signatures, a crash in
--full-recon's DNS display, and a DNS-timeout-reported-as-absence issue
in the email security module.
The bundled offline CVE dataset is included in published wheels.
Also in the box:
- Parallel scanning — multiple targets at once with configurable worker count
- Structured JSON output — for automation and reporting, optionally saved to file
- Rate limiting & caching —
--rate-limitand an opt-in local SQLite cache with configurable TTL - Nuclei export — write technology-tagged target groups as JSON for downstream nuclei workflows
- Configurable terminal presentation — layout and colors via
.inoue.tomlor~/.config/inoue/config.toml - Extensible signature engine — add new detections by editing a single Python dict
- And more — see COMMANDS.md for the full reference
python -m pip install inoue==1.1.2
inoue --helpInstall the optional API dependencies with:
python -m pip install "inoue[api]==1.1.2"Install optional MCP support with:
python -m pip install "inoue[mcp]"
inoue-mcpOr from source:
git clone https://github.com/alham-rizvi/Inoue.git
cd Inoue
pip install -r requirements.txtThe browser extension is built from the same repository for both Chrome and Firefox. Start the API, then package it with:
python -m uvicorn api.main:app --host 127.0.0.1 --port 8000
python scripts/build_extension.pyLoad the generated ZIP or the extension/ directory as an unpacked extension.
# Basic scan
python inoue.py alhamrizvi.in
# Verbose scan with SSL, DNS, headers, and security inspection
python inoue.py -v alhamrizvi.in
# Show the evidence behind each detection
python inoue.py -e https://alhamrizvi.in
# Full recon-style scan
python inoue.py -v -e https://alhamrizvi.in
# Scan multiple targets concurrently
python inoue.py site1.com site2.com site3.com
# Read targets from a file or stdin pipeline
python inoue.py --list targets.txt
cat targets.txt | python inoue.py --json
# Rate-limit and cache repeat scans
python inoue.py --rate-limit 1 --cache alhamrizvi.in
# Correlate detected versions with the local CVE dataset
python inoue.py --cve alhamrizvi.in
python inoue.py --cve --cve-min-severity high alhamrizvi.in
python inoue.py --cve --fail-on-cve alhamrizvi.in
# Refresh the local CVE dataset explicitly
python inoue.py update-cve
# Export technology-tagged URLs for downstream nuclei workflows
python inoue.py --nuclei-out nuclei-targets.json alhamrizvi.in
# JSON output
python inoue.py --json alhamrizvi.in
python inoue.py --json -o results.json alhamrizvi.in
python inoue.py -o report.html alhamrizvi.in
# Fast HTB/CTF style scan without DNS
python inoue.py --no-dns -t 5 10.10.11.55
# Skip SSL checks for HTTP-only or self-signed targets
python inoue.py --no-ssl https://alhamrizvi.in
# Pull the latest catalog and scanner updates from the repository
python inoue.py updateFor a full command reference, see COMMANDS.md.
For deeper implementation notes and backend context, see the project guides in guides/README.md. For installation, MCP, terminal themes, Docker, verification, and release publishing, see the repository wiki guide.
Operational defaults can be stored in project .inoue.toml or user ~/.config/inoue/config.toml; CLI flags always take precedence.
Terminal presentation can be customized in the same TOML file:
[terminal]
text_style = "bright_white"
layout = "wide" # compact, standard, or wide
[terminal.colors]
"Web Server" = "bright_cyan"
"Application Server" = "green"
"Other" = "grey70"| Flag | Description |
|---|---|
-v, --verbose |
Show SSL info, DNS records, security headers, and response headers |
-e, --evidence |
Show the evidence that triggered each detection |
--no-dns |
Skip DNS enumeration |
--no-ssl |
Skip SSL/TLS inspection |
--service |
Run service/technology fingerprint detection only |
--headers |
Enable header-based detection |
--dns |
Enable DNS enumeration |
--ssl |
Enable SSL inspection |
--whois |
Enable whois lookup |
--subdomains |
Enable subdomain enumeration |
--mail |
Enable mail record lookup |
--ports |
Enable common port scanning |
--extra |
Enable extra reconnaissance intelligence |
--fast |
Fast scan preset (headers + tech) |
--full-recon |
Full recon preset |
--all |
Enable all recon modules |
-t, --timeout |
HTTP timeout in seconds (default: 10) |
-w, --workers |
Concurrent scan threads (default: 5) |
-l, --list |
Read one target per line from a file |
--rate-limit |
Maximum requests per second per host |
--cache |
Enable the opt-in local SQLite cache |
--cache-path |
Override the SQLite cache path |
--cache-ttl |
Cache lifetime in seconds |
--cve |
Match detected versions against the local CVE dataset |
--nuclei-out |
Write technology-tagged target groups as JSON |
--plugin-dir |
Load result plugins from an additional directory |
--json |
Output results as JSON |
-o, --output |
Save JSON to a file |
--no-banner |
Suppress the ASCII banner |
--api-key |
Optional API key for enrichment services |
Inoue is built around a large signature catalog and can surface technologies across categories such as:
- Web servers: Apache, Nginx, IIS, LiteSpeed, Caddy, Tomcat, OpenResty
- Languages and runtimes: PHP, ASP.NET, Node.js, Python, Ruby on Rails, Java, Go
- Frameworks: Laravel, Django, Flask, Express.js, Spring, Symfony, FastAPI, Next.js, React, Vue, Angular
- CMS and ecommerce: WordPress, Drupal, Joomla, Magento, Shopify, PrestaShop, OpenCart, Ghost
- Analytics and marketing: Google Analytics, Tag Manager, Hotjar, Matomo, Plausible, Segment, Mixpanel
- Payments: Stripe, PayPal, Braintree, Authorize.Net, Square, Adyen, Paddle
- CDNs and security: Cloudflare, CloudFront, Fastly, Akamai, Varnish, WAF products
- Admin and management panels: phpMyAdmin, Adminer, pgAdmin, Webmin, Portainer, Jenkins, GitLab, Jira, Confluence, and more
- Cloud and self-hosted infrastructure: OpenStack, OpenShift, Proxmox, oVirt, CloudStack, Rancher, Harbor, Nextcloud, OwnCloud
- VPN and remote access: OpenVPN, WireGuard, Tailscale, pfSense, OPNsense, FortiGate, UniFi, MikroTik
- IoT and appliance surfaces: Home Assistant, OpenHAB, Synology DSM, QNAP QTS, TrueNAS, routers, cameras, and printer web consoles
The scanner evaluates several signal sources in order:
- HTTP response headers
- Cookies
- HTML body content
- Script tags and referenced assets
- Meta tags
- URL paths and common login/admin routes
Each detection is enriched with a confidence level, version hint when available, and evidence from the matched signal.
Edit fingerprints/signatures.py. Each entry follows this schema:
"TechName": {
"category": "Framework",
"headers": {"Header-Name": r"regex(with optional (version) group)"},
"cookies": [r"cookie_name_pattern"],
"html": [r"pattern in response body"],
"scripts": [r"pattern in <script src=...>"],
"meta": {"generator": r"pattern"},
"paths": [r"/common/admin/path"],
},Normalize a reviewed Wappalyzer catalog without changing scans:
python scripts/import_wappalyzer.py wappalyzer.json
python scripts/import_wappalyzer.py wappalyzer.json --write --output imported.json[
{
"url": "https://target.com",
"ip": "1.2.3.4",
"status_code": 200,
"response_time_ms": 142.3,
"server": "nginx",
"technologies": [
{"name": "Nginx", "category": "Web Server", "version": "1.24.0", "evidence": "Server: nginx/1.24.0"},
{"name": "WordPress", "category": "CMS", "version": "6.5", "evidence": "Meta generator: WordPress 6.5"}
],
"ssl": {"protocol": "TLSv1.3", "cipher": "TLS_AES_256_GCM_SHA384"},
"dns": {"A": ["1.2.3.4"], "MX": ["mail.target.com"]}
}
]Planned improvements include:
- more signature coverage for modern web stacks
- broader version heuristics and enrichment sources
- deeper TLS and header analysis
- better structured reports for recon workflows
- Issues & Feature Requests: Open an issue
- Discussions: Join the conversation on GitHub Discussions
- Contributing: See CONTRIBUTING.md for setup and PR guidance
- Catalog expansion: A full walkthrough for extending the fingerprint catalog, adding version detection heuristics, and keeping the tool current is available in GUIDE.md
- Security: See SECURITY.md to report vulnerabilities
- Show Support: Star this repo to follow along with development
Want to contribute or run locally? See CONTRIBUTING.md.
Inoue is free and open source under the MIT License.



