Censys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the internet.


The best open source alternative to Shodan is Censys. If that doesn't suit you, our users have ranked more than 25 alternatives to Shodan and eight of them is open source so hopefully you can find a suitable replacement. Other interesting open source alternatives to Shodan are IVRE, LeakIX, wapiti and Natlas.
Censys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the internet.


LeakIX is a search engine indexing open hosts on the internet. It focuses on listing the databases and table names and keeps a history of every successful connection.
Wapiti allows you to audit the security of your web applications. Wapiti is a command line tool.
Natlas is an open source project designed to provide scalable network scanning and an interface to search through the results. For more information, visit github.com/natlas/natlas




A fully automated, active web application security reconnaissance tool. Key features: High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint - easily achieving 2000 requests per second with responsive targets.


Vega is a free and open source scanner and testing platform to test the security of web applications. Vega can help you find and validate SQL Injection, Cross-Site Scripting (XSS), inadvertently disclosed sensitive information, and other vulnerabilities.



Grabber is a web application scanner. Basically it detects some kind of vulnerabilities in your website.
no limit on number of searches, lots of filters