Skip to content

Shodan & Censys

Shodan and Censys are powerful OSINT tools designed for network discovery, enabling red teams to identify exposed devices, services, and potential vulnerabilities in target networks. This section demonstrates their practical use in authorized testing scenarios, focusing on querying public-facing infrastructure and extracting actionable intelligence.


Shodan for Network Discovery

Shodan is a search engine for internet-connected devices, indexing services like SSH, HTTP, FTP, and more. It allows querying by port, service, IP range, or vulnerability.

Basic Querying

Use the Shodan CLI (shodan) or API to search for exposed assets. For example:

shodan search "port:22"  # Find SSH servers
shodan search "http.title:Apache"  # Find Apache web servers
shodan search "vuln:unauthenticated"  # Filter by known vulnerabilities
Example Output:
{
  "ip": "192.0.2.1",
  "port": 22,
  "product": "OpenSSH 8.2",
  "banner": "SSH-2.0-OpenSSH_8.2",
  "org": "Example Corp"
}
Shodan’s --vuln flag can highlight vulnerabilities:
shodan search "port:80" --vuln

Advanced Filters

Combine filters for precision:

shodan search "country:US city:New York" "http.title:WordPress"  # Target specific regions
shodan search "ip:192.0.2.0/24" "ssl.version:TLS 1.0"  # Check for outdated TLS


Censys for TLS and Service Discovery

Censys specializes in TLS/SSL certificate data and network services, making it ideal for analyzing encrypted traffic and identifying misconfigured servers.

Querying TLS Data

Use the Censys CLI (censys) to search for TLS configurations:

censys search "tls.cipher:suite:TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"  # Find specific ciphers
censys search "http.title:nginx"  # Find Nginx servers
Example Output:
{
  "ip": "192.0.2.2",
  "tls": {
    "server_name": "example.com",
    "protocols": ["TLSv1.2", "TLSv1.3"],
    "certificates": [
      {
        "subject": "CN=example.com",
        "issuer": "CN=Let's Encrypt"
      }
    ]
  }
}

Filtering by IP/Port

Target specific ranges or ports:

censys search "ip:192.0.2.0/24" "port:443"  # Check HTTPS servers in a range
censys search "service:http" "http.server:Apache"  # Find Apache HTTP servers


Combining Shodan and Censys

For comprehensive network discovery, pair both tools:
1. Use Shodan to identify devices and services.
2. Use Censys to analyze TLS configurations or deeper service details.

Example Workflow:

# Find a server via Shodan
shodan search "title:MySQL" --output json > mysql_servers.json

# Use Censys to check TLS on those IPs
censys search "ip:192.0.2.1" "tls.version:TLS 1.0"  # Check for weak TLS


Key takeaways

  • Shodan excels at general network discovery, exposing devices and services.
  • Censys specializes in TLS/SSL data, making it ideal for analyzing encrypted traffic.
  • Combine both tools for a holistic view of target infrastructure.
  • Always operate within authorized boundaries and respect legal/ethical guidelines.