Self-search your org weekly. Find shadow IT before attackers do. The favicon-hash trick reveals corporate apps exposed on unexpected IPs.
Legal Floor
Searching Shodan = legal. Accessing systems you find = not legal without authorization. Shodan tells you what exists; it does not authorize you to use it.
Defensive recipes
Plans
Inventory open ports Every IP block you own
CVE match by banner Detect outdated software at the edge
Cert transparency cross-ref Find subdomains via crt.sh + Shodan
Favicon-hash pivot Locate corporate apps on rogue IPs
Alert on changes Shodan Monitor
Free Limited searches, basic filters
Membership ($69 once) Most useful tier for one-time learners
Small Business + Continuous monitoring + vuln data