Skip to content

Latest commit

 

History

128 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Green Black Professional Minimal Fashion Brand Logo Inoue

GitHub stars PyPI version License: MIT Python 3.12

A fast, open-source recon-oriented tech stack fingerprinting CLI.
Identify the technologies exposed by a target website or service, straight from the terminal.

e (2)

Inoue is designed to identify the technologies exposed by a target website or service, with a broad signature catalog that covers servers, runtimes, CMS platforms, ecommerce stacks, frameworks, JavaScript libraries, analytics tools, payment providers, admin panels, cloud/self-hosted management surfaces, VPN portals, and IoT/admin devices.

It is useful for recon, CTF/HTB, bug bounty, internal network review, and general surface analysis.

Maintained by Alham Rizvi.

Version 2.0.0

A major recon and security-posture release, still fully read-only:

  • ~21,000-signature fingerprint catalog with aggressive version detection (every version carries a version_source so a precisely-parsed value is never confused with a best-effort guess)
  • technology end-of-life detection against a verified EOL table
  • JS bundle intelligence: fetches same-origin scripts and re-runs them through the full catalog, closing the client-rendered/SPA detection gap, plus redacted secret-pattern findings and endpoint extraction
  • WAF/CDN detection, security header grading, CORS misconfiguration detection, cookie/CSP/redirect-chain/HTTP-method posture checks
  • SPF/DMARC/DKIM/MTA-STS email security analysis
  • subdomain takeover fingerprinting and API surface discovery (OpenAPI/ Swagger detection, GraphQL introspection status)
  • a triage risk score combining every signal above into one ordered view
  • scope guardrails (--scope): domain wildcard + CIDR matching, so recon modules that fan out to discovered subdomains refuse to touch anything outside a declared scope
  • optional orchestration of subfinder, naabu, nmap, nuclei, gau, waybackurls, katana, and gowitness when installed, with graceful degradation when they aren't
  • append-only scan history with timeline diffing
  • an MCP server (7 read-only tools, dual SDK support, stdio/SSE/ streamable-HTTP transports) and a FastAPI backend at parity with the CLI
  • the Chrome/Firefox extension, now with a proper toolbar icon

See CHANGELOG.md for the full list, including three real bugs found via live testing and fixed at the root: a catalog-wide confidence-inflation issue affecting 96.5% of signatures, a crash in --full-recon's DNS display, and a DNS-timeout-reported-as-absence issue in the email security module.

The bundled offline CVE dataset is included in published wheels.

Features

Broad Signature Catalog

600+ services covering web servers, languages, frameworks, CMS, ecommerce, JS libraries, analytics, payments, CDNs, WAFs, cloud portals, ICS/SCADA surfaces, admin panels, and network appliances.

Inoue scan output

Multi-Signal Detection

Detects technologies from HTTP headers, cookies, HTML body content, script tags, meta tags, and common login/admin URL paths — each match enriched with confidence, version hint, and evidence.

Docs →

Inoue evidence detection

SSL, DNS & Security Auditing

SSL/TLS inspection with certificate metadata and handshake details, DNS intelligence across A, AAAA, MX, NS, TXT, and CNAME records, and security header auditing for HSTS, CSP, X-Frame-Options, and related protections.

Inoue SSL and DNS output

CVE Correlation

Correlate detected versions against a local, offline CVE dataset with optional EPSS scores. Refreshed explicitly, never silently, so scans stay reproducible.

Docs →

Inoue CVE correlation

Watch Mode & Webhooks

Run repeated watch scans with structured technology, CVE, port, and certificate diffs, delivered over generic, Slack, or Discord webhook payloads with verified HTTPS delivery.

Inoue watch mode

API, MCP & Browser Extension

Optional FastAPI endpoints for health, signature, single-target, and batch scans; an MCP server over stdio for catalog search and read-only scans; and a shared Chrome/Firefox extension for detecting the active tab's stack.

Docs →

Inoue API and MCP

Also in the box:

  • Parallel scanning — multiple targets at once with configurable worker count
  • Structured JSON output — for automation and reporting, optionally saved to file
  • Rate limiting & caching — --rate-limit and an opt-in local SQLite cache with configurable TTL
  • Nuclei export — write technology-tagged target groups as JSON for downstream nuclei workflows
  • Configurable terminal presentation — layout and colors via .inoue.toml or ~/.config/inoue/config.toml
  • Extensible signature engine — add new detections by editing a single Python dict
  • And more — see COMMANDS.md for the full reference

Install

python -m pip install inoue==1.1.2
inoue --help

Install the optional API dependencies with:

python -m pip install "inoue[api]==1.1.2"

Install optional MCP support with:

python -m pip install "inoue[mcp]"
inoue-mcp

Or from source:

git clone https://github.com/alham-rizvi/Inoue.git
cd Inoue
pip install -r requirements.txt

The browser extension is built from the same repository for both Chrome and Firefox. Start the API, then package it with:

python -m uvicorn api.main:app --host 127.0.0.1 --port 8000
python scripts/build_extension.py

Load the generated ZIP or the extension/ directory as an unpacked extension.

Usage

# Basic scan
python inoue.py alhamrizvi.in

# Verbose scan with SSL, DNS, headers, and security inspection
python inoue.py -v alhamrizvi.in

# Show the evidence behind each detection
python inoue.py -e https://alhamrizvi.in

# Full recon-style scan
python inoue.py -v -e https://alhamrizvi.in

# Scan multiple targets concurrently
python inoue.py site1.com site2.com site3.com

# Read targets from a file or stdin pipeline
python inoue.py --list targets.txt
cat targets.txt | python inoue.py --json

# Rate-limit and cache repeat scans
python inoue.py --rate-limit 1 --cache alhamrizvi.in

# Correlate detected versions with the local CVE dataset
python inoue.py --cve alhamrizvi.in
python inoue.py --cve --cve-min-severity high alhamrizvi.in
python inoue.py --cve --fail-on-cve alhamrizvi.in

# Refresh the local CVE dataset explicitly
python inoue.py update-cve

# Export technology-tagged URLs for downstream nuclei workflows
python inoue.py --nuclei-out nuclei-targets.json alhamrizvi.in

# JSON output
python inoue.py --json alhamrizvi.in
python inoue.py --json -o results.json alhamrizvi.in
python inoue.py -o report.html alhamrizvi.in

# Fast HTB/CTF style scan without DNS
python inoue.py --no-dns -t 5 10.10.11.55

# Skip SSL checks for HTTP-only or self-signed targets
python inoue.py --no-ssl https://alhamrizvi.in

# Pull the latest catalog and scanner updates from the repository
python inoue.py update

For a full command reference, see COMMANDS.md.

For deeper implementation notes and backend context, see the project guides in guides/README.md. For installation, MCP, terminal themes, Docker, verification, and release publishing, see the repository wiki guide.

Operational defaults can be stored in project .inoue.toml or user ~/.config/inoue/config.toml; CLI flags always take precedence.

Terminal presentation can be customized in the same TOML file:

[terminal]
text_style = "bright_white"
layout = "wide" # compact, standard, or wide

[terminal.colors]
"Web Server" = "bright_cyan"
"Application Server" = "green"
"Other" = "grey70"

Options

Flag Description
-v, --verbose Show SSL info, DNS records, security headers, and response headers
-e, --evidence Show the evidence that triggered each detection
--no-dns Skip DNS enumeration
--no-ssl Skip SSL/TLS inspection
--service Run service/technology fingerprint detection only
--headers Enable header-based detection
--dns Enable DNS enumeration
--ssl Enable SSL inspection
--whois Enable whois lookup
--subdomains Enable subdomain enumeration
--mail Enable mail record lookup
--ports Enable common port scanning
--extra Enable extra reconnaissance intelligence
--fast Fast scan preset (headers + tech)
--full-recon Full recon preset
--all Enable all recon modules
-t, --timeout HTTP timeout in seconds (default: 10)
-w, --workers Concurrent scan threads (default: 5)
-l, --list Read one target per line from a file
--rate-limit Maximum requests per second per host
--cache Enable the opt-in local SQLite cache
--cache-path Override the SQLite cache path
--cache-ttl Cache lifetime in seconds
--cve Match detected versions against the local CVE dataset
--nuclei-out Write technology-tagged target groups as JSON
--plugin-dir Load result plugins from an additional directory
--json Output results as JSON
-o, --output Save JSON to a file
--no-banner Suppress the ASCII banner
--api-key Optional API key for enrichment services

What it can identify

Inoue is built around a large signature catalog and can surface technologies across categories such as:

  • Web servers: Apache, Nginx, IIS, LiteSpeed, Caddy, Tomcat, OpenResty
  • Languages and runtimes: PHP, ASP.NET, Node.js, Python, Ruby on Rails, Java, Go
  • Frameworks: Laravel, Django, Flask, Express.js, Spring, Symfony, FastAPI, Next.js, React, Vue, Angular
  • CMS and ecommerce: WordPress, Drupal, Joomla, Magento, Shopify, PrestaShop, OpenCart, Ghost
  • Analytics and marketing: Google Analytics, Tag Manager, Hotjar, Matomo, Plausible, Segment, Mixpanel
  • Payments: Stripe, PayPal, Braintree, Authorize.Net, Square, Adyen, Paddle
  • CDNs and security: Cloudflare, CloudFront, Fastly, Akamai, Varnish, WAF products
  • Admin and management panels: phpMyAdmin, Adminer, pgAdmin, Webmin, Portainer, Jenkins, GitLab, Jira, Confluence, and more
  • Cloud and self-hosted infrastructure: OpenStack, OpenShift, Proxmox, oVirt, CloudStack, Rancher, Harbor, Nextcloud, OwnCloud
  • VPN and remote access: OpenVPN, WireGuard, Tailscale, pfSense, OPNsense, FortiGate, UniFi, MikroTik
  • IoT and appliance surfaces: Home Assistant, OpenHAB, Synology DSM, QNAP QTS, TrueNAS, routers, cameras, and printer web consoles

How detection works

The scanner evaluates several signal sources in order:

  • HTTP response headers
  • Cookies
  • HTML body content
  • Script tags and referenced assets
  • Meta tags
  • URL paths and common login/admin routes

Each detection is enriched with a confidence level, version hint when available, and evidence from the matched signal.

Adding signatures

Edit fingerprints/signatures.py. Each entry follows this schema:

"TechName": {
    "category": "Framework",
    "headers": {"Header-Name": r"regex(with optional (version) group)"},
    "cookies": [r"cookie_name_pattern"],
    "html": [r"pattern in response body"],
    "scripts": [r"pattern in <script src=...>"],
    "meta": {"generator": r"pattern"},
    "paths": [r"/common/admin/path"],
},

Normalize a reviewed Wappalyzer catalog without changing scans:

python scripts/import_wappalyzer.py wappalyzer.json
python scripts/import_wappalyzer.py wappalyzer.json --write --output imported.json

Example JSON output

[
  {
    "url": "https://target.com",
    "ip": "1.2.3.4",
    "status_code": 200,
    "response_time_ms": 142.3,
    "server": "nginx",
    "technologies": [
      {"name": "Nginx", "category": "Web Server", "version": "1.24.0", "evidence": "Server: nginx/1.24.0"},
      {"name": "WordPress", "category": "CMS", "version": "6.5", "evidence": "Meta generator: WordPress 6.5"}
    ],
    "ssl": {"protocol": "TLSv1.3", "cipher": "TLS_AES_256_GCM_SHA384"},
    "dns": {"A": ["1.2.3.4"], "MX": ["mail.target.com"]}
  }
]

Roadmap

Planned improvements include:

  • more signature coverage for modern web stacks
  • broader version heuristics and enrichment sources
  • deeper TLS and header analysis
  • better structured reports for recon workflows

Community & Support

  • Issues & Feature Requests: Open an issue
  • Discussions: Join the conversation on GitHub Discussions
  • Contributing: See CONTRIBUTING.md for setup and PR guidance
  • Catalog expansion: A full walkthrough for extending the fingerprint catalog, adding version detection heuristics, and keeping the tool current is available in GUIDE.md
  • Security: See SECURITY.md to report vulnerabilities
  • Show Support: Star this repo to follow along with development

Developing

Want to contribute or run locally? See CONTRIBUTING.md.

License

Inoue is free and open source under the MIT License.

About

Web Tech-stack Fingerprinting Tool

Resources

Contributing

Security policy

Stars

17 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages