All products
02Security & infrastructureThreat intelligence

IPAudit

Is that IP vulnerable or compromised?

IPAudit answers one question about an internet-facing IP address: is it vulnerable, or is it already compromised? It runs passive OSINT lookups, 30+ keyless threat feeds and NVD CVE correlation against a target, adds active probing behind a typed confirmation in the CLI, and returns an HTML or JSON report with an executive summary and severity-banded findings. A companion masscan-based scanner runs internet-wide sweeps on high-risk ports and feeds a searchable exposure database.

At a glance

Status
Live
Sector
Security & infrastructure
Best for
IT auditors and security teams running authorised assessments of internet-facing IP addresses, who need an exportable, evidence-backed record of exposure and reputation rather than a one-line score. "IP" here means Internet Protocol address, not intellectual property.
Built with
Python 3 · FastAPI + uvicorn · SQLite (aiosqlite) · masscan · Jinja2 + vanilla JS

Highlights

  • 17 scan modules across passive OSINT, threat intel, CVE correlation and active probing
  • 35 threat-feed sources that need no API key: 29 DNSBLs, four blocklists, the TOR exit list and URLhaus
  • HTML and JSON reports with an executive summary, a 0-100 risk score and a five-band risk label
  • Local NVD mirror refreshed every 24 hours for version-range CVE lookups

What IPAudit does

01

Passive OSINT and threat intel in one pass

Shodan, VirusTotal, GreyNoise, AbuseIPDB and Censys run on your own API keys and return open ports, service banners and malware detections. Alongside them, needing no key at all: 29 DNSBLs, the Emerging Threats, Feodo, Spamhaus DROP and CINS blocklists, the TOR exit node list, URLhaus, and ASN and geo data. Everything runs in parallel.

02

CVE correlation against NVD

Discovered service versions are mapped to NVD CVEs with CVSS scores, so a finding says what can actually be exploited. A local SQLite CVE mirror is populated from the NVD API 2.0 and refreshed on a 24-hour cycle for fast version-range lookups.

03

Active probing is opt-in

Port scanning, banner grabbing, TLS certificate and cipher analysis, HTTP security header inspection, SSH key-exchange review and SNMP checks. The CLI will not run any of them until you type I AUTHORIZE, and every module it skips is recorded in the report.

04

Exposure search

A masscan-based scanner sends SYN-only probes on nine high-risk ports; the database currently holds SSH (22) and RDP (3389) results. Query it with Shodan-style syntax — port:, country:, org:, ip: and severity: — at scanner.ipaudit.ai.

Start here

Have something to build, or something to keep running?

Whether you need a product shipped, a system kept healthy, or a hand with a hard integration — tell us what you're dealing with.