โ† Read the full guide
All infographics

Shodan: The Search Engine for Connected Devices

Every public IP. Every open port. Every banner. What's exposed about you โ€” and the entire internet.


All
Public IPv4 / IPv6
24/7
Continuous Scanning
Free
Tier Available
Banners
+ Tech Fingerprints
What Shodan indexes
CORE
Open ports + services
Every responding port. Service banners. Software versions.
TLS certificates
Cert details. Helps find hostnames + related infrastructure.
HTTP titles + bodies
Page titles, headers, response codes, HTML samples.
Tech fingerprints
Framework, CMS, web server, DB version inferred from banners.
Useful search filters
org:"Your Company Inc" โ€” everything attributed to your org
net:198.51.100.0/24 โ€” IP CIDR range
hostname:example.com โ€” by reverse-DNS
port:5432 country:US โ€” open Postgres in the US (don't!)
product:"nginx" โ€” by software
http.favicon.hash:-123456789 โ€” find every host with same favicon
vuln:CVE-2024-XXXX โ€” vulnerable hosts (paid tier)
Defender Use
Self-search your org weekly. Find shadow IT before attackers do. The favicon-hash trick reveals corporate apps exposed on unexpected IPs.
Legal Floor
Searching Shodan = legal. Accessing systems you find = not legal without authorization. Shodan tells you what exists; it does not authorize you to use it.
Defensive recipes
Plans
  1. Inventory open ports
    Every IP block you own
  2. CVE match by banner
    Detect outdated software at the edge
  3. Cert transparency cross-ref
    Find subdomains via crt.sh + Shodan
  4. Favicon-hash pivot
    Locate corporate apps on rogue IPs
  5. Alert on changes
    Shodan Monitor
  1. Free
    Limited searches, basic filters
  2. Membership ($69 once)
    Most useful tier for one-time learners
  3. Small Business +
    Continuous monitoring + vuln data