CENSYS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Internet-wide scanning platform that indexes hosts, certificates, and services. Complement to Shodan with stronger certificate and TLS analysis capabilities.
ACCOUNT & ACCESS#
# Free account: 250 queries/month, basic search # Researcher: apply for academic/research access # Enterprise: full API, historical data, bulk exports # API credentials: https://search.censys.io/account/api
CLI INSTALLATION#
pip install censys censys config # Configure API ID/Secret # Environment variables export CENSYS_API_ID=your_api_id export CENSYS_API_SECRET=your_api_secret
SEARCH INTERFACES#
# Web UI: https://search.censys.io # Search types: Hosts, Certificates # API v2: https://search.censys.io/api
CLI COMMANDS#
# Host search censys search "services.http.response.html_title: admin" censys search "services.port: 22 AND location.country: Germany" # View host details censys view 1.2.3.4 # Certificates search censys search --index-type certs "parsed.subject.common_name: example.com" # Subdomains censys subdomains example.com
HOST SEARCH QUERIES#
# By service/port services.port: 22 # SSH services.port: 80 # HTTP services.port: 443 # HTTPS services.port: 3389 # RDP services.port: 3306 # MySQL services.port: 27017 # MongoDB services.port: 6379 # Redis services.port: 9200 # Elasticsearch # By service name services.service_name: HTTP services.service_name: SSH services.service_name: FTP services.service_name: MQTT services.service_name: MODBUS # By software/product services.software.product: "Apache HTTPD" services.software.product: "nginx" services.software.product: "OpenSSH" services.software.product: "Microsoft IIS" services.software.vendor: "Apache" # By version services.software.version: "7.4" # By banner content services.banner: "MongoDB" services.banner: "unauthorized" # By HTTP title services.http.response.html_title: "Dashboard" services.http.response.html_title: "login" services.http.response.html_title: "Index of" # By HTTP headers services.http.response.headers.server: "Apache" services.http.response.headers.x_powered_by: "PHP" # By HTTP status code services.http.response.status_code: 200 services.http.response.status_code: 401 services.http.response.status_code: 403 # By HTTP body content services.http.response.body: "password" services.http.response.body: "admin" # By location location.country: "United States" location.country_code: "US" location.country_code: "DE" location.city: "Berlin" location.continent: "Europe" # By AS / Organization autonomous_system.name: "GOOGLE" autonomous_system.asn: 15169 autonomous_system.description: "Amazon" # By network ip: 1.2.3.4 ip: 10.0.0.0/8 # By operating system operating_system.product: "Windows" operating_system.product: "Linux" operating_system.vendor: "Microsoft" operating_system.version: "10"
TLS/SSL & CERTIFICATE QUERIES#
# By certificate subject services.tls.certificates.leaf.subject.common_name: "example.com" services.tls.certificates.leaf.subject.organization: "Acme Corp" # By certificate issuer services.tls.certificates.leaf.issuer.organization: "Let's Encrypt" services.tls.certificates.leaf.issuer.common_name: "DigiCert" # By TLS version services.tls.version_selected: "TLSv1.0" services.tls.version_selected: "TLSv1.3" services.tls.version_selected: "SSLv3" # Self-signed certificates services.tls.certificates.leaf.issuer.common_name: services.tls.certificates.leaf.subject.common_name # Expired certificates services.tls.certificates.leaf.validity.end: [* TO 2024-01-01] # Certificate SAN (Subject Alt Names) services.tls.certificates.leaf.names: "example.com" services.tls.certificates.leaf.names: "*.example.com" # JARM fingerprint (TLS server fingerprint) services.jarm.fingerprint: "JARM_HASH_HERE" # JA3S fingerprint services.tls.ja3s: "JA3S_HASH_HERE"
CERTIFICATE SEARCH (Dedicated Index)#
# Search the certificate index directly parsed.subject.common_name: "example.com" parsed.issuer.organization: "Let's Encrypt" parsed.names: "*.example.com" fingerprint_sha256: "HASH" parsed.validity.end: [* TO 2024-01-01] # Expired parsed.subject.organization: "Target Corp" # Find related infrastructure via certs # Same org cert on different IPs = related assets # Wildcard cert reuse reveals hidden services
COMBINING QUERIES#
# AND (explicit) services.port: 443 AND location.country_code: "US" # OR services.port: 80 OR services.port: 443 # NOT NOT services.port: 22 services.port: 80 AND NOT location.country_code: "US" # Grouping (services.port: 80 OR services.port: 443) AND location.country_code: "DE" # Wildcards services.tls.certificates.leaf.subject.common_name: *.example.com # Exists (field has any value) services.http.response.html_title: *
COMMON SEARCH QUERIES#
# Exposed databases services.port: 27017 AND services.banner: "MongoDB" services.port: 6379 AND services.service_name: REDIS services.port: 9200 AND services.http.response.body: "cluster_name" services.port: 5984 AND services.http.response.body: "couchdb" # Admin panels services.http.response.html_title: "phpMyAdmin" services.http.response.html_title: "Kibana" services.http.response.html_title: "Grafana" services.http.response.html_title: "Jenkins" services.http.response.html_title: "Portainer" # Industrial Control Systems services.service_name: MODBUS services.service_name: BACNET services.service_name: DNP3 services.service_name: S7 services.port: 502 services.port: 47808 # Network devices services.software.product: "Cisco IOS" services.http.response.html_title: "RouterOS" services.software.product: "MikroTik" services.software.product: "Fortinet" # Webcams / IoT services.http.response.html_title: "webcam" services.service_name: RTSP services.port: 554 # Vulnerable TLS services.tls.version_selected: "TLSv1.0" services.tls.version_selected: "SSLv3"
PYTHON API#
from censys.search import CensysHosts, CensysCerts
# Host search
h = CensysHosts()
# Basic search
for host in h.search("services.port: 22 AND location.country_code: US",
per_page=25):
print(host)
# View specific host
host = h.view("1.2.3.4")
print(host['services'])
print(host['location'])
# Aggregate (facets)
report = h.aggregate(
"services.port: 443",
field="services.software.product",
num_buckets=10
)
for bucket in report:
print(f"{bucket['key']}: {bucket['count']}")
# Certificate search
c = CensysCerts()
for cert in c.search("parsed.subject.common_name: example.com"):
print(cert)
# Subdomains
from censys.search import CensysHosts
h = CensysHosts()
names = h.view_host_names("1.2.3.4")
# Bulk view
hosts = h.bulk_view(["1.2.3.4", "5.6.7.8"])
CENSYS VS SHODAN#
Feature Censys Shodan ------- ------ ------ Cert search Excellent Good TLS analysis Deep (JARM/JA3S) Basic Query syntax Structured fields Flat filters ICS/SCADA Good Excellent Screenshots Limited Extensive Free tier 250 queries/mo Limited Vuln tagging Limited vuln: filter Historical Enterprise Membership Real-time No firehose Stream API Best for Cert/TLS/infra Banner/service
TIPS#
- Certificate searches are Censys's strongest feature - Use cert subject/issuer to map org infrastructure - JARM fingerprints identify C2 frameworks and specific servers - Combine with Shodan for comprehensive coverage - Wildcard cert reuse often reveals shadow IT - services.tls.certificates.leaf.names finds all SANs - Use aggregate/facets for statistical analysis - Free tier is generous for research (250 queries/month) - Historical data (enterprise) shows infrastructure changes over time - Export results via API for large-scale analysis