โ† All cheat sheets

CENSYS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Internet-wide scanning platform that indexes hosts, certificates,
and services. Complement to Shodan with stronger certificate and
TLS analysis capabilities.

ACCOUNT & ACCESS#

# Free account: 250 queries/month, basic search
# Researcher: apply for academic/research access
# Enterprise: full API, historical data, bulk exports
# API credentials: https://search.censys.io/account/api

CLI INSTALLATION#

pip install censys
censys config                               # Configure API ID/Secret

# Environment variables
export CENSYS_API_ID=your_api_id
export CENSYS_API_SECRET=your_api_secret

SEARCH INTERFACES#

# Web UI: https://search.censys.io
# Search types: Hosts, Certificates
# API v2: https://search.censys.io/api

CLI COMMANDS#

# Host search
censys search "services.http.response.html_title: admin"
censys search "services.port: 22 AND location.country: Germany"

# View host details
censys view 1.2.3.4

# Certificates search
censys search --index-type certs "parsed.subject.common_name: example.com"

# Subdomains
censys subdomains example.com

HOST SEARCH QUERIES#

# By service/port
services.port: 22                           # SSH
services.port: 80                           # HTTP
services.port: 443                          # HTTPS
services.port: 3389                         # RDP
services.port: 3306                         # MySQL
services.port: 27017                        # MongoDB
services.port: 6379                         # Redis
services.port: 9200                         # Elasticsearch

# By service name
services.service_name: HTTP
services.service_name: SSH
services.service_name: FTP
services.service_name: MQTT
services.service_name: MODBUS

# By software/product
services.software.product: "Apache HTTPD"
services.software.product: "nginx"
services.software.product: "OpenSSH"
services.software.product: "Microsoft IIS"
services.software.vendor: "Apache"

# By version
services.software.version: "7.4"

# By banner content
services.banner: "MongoDB"
services.banner: "unauthorized"

# By HTTP title
services.http.response.html_title: "Dashboard"
services.http.response.html_title: "login"
services.http.response.html_title: "Index of"

# By HTTP headers
services.http.response.headers.server: "Apache"
services.http.response.headers.x_powered_by: "PHP"

# By HTTP status code
services.http.response.status_code: 200
services.http.response.status_code: 401
services.http.response.status_code: 403

# By HTTP body content
services.http.response.body: "password"
services.http.response.body: "admin"

# By location
location.country: "United States"
location.country_code: "US"
location.country_code: "DE"
location.city: "Berlin"
location.continent: "Europe"

# By AS / Organization
autonomous_system.name: "GOOGLE"
autonomous_system.asn: 15169
autonomous_system.description: "Amazon"

# By network
ip: 1.2.3.4
ip: 10.0.0.0/8

# By operating system
operating_system.product: "Windows"
operating_system.product: "Linux"
operating_system.vendor: "Microsoft"
operating_system.version: "10"

TLS/SSL & CERTIFICATE QUERIES#

# By certificate subject
services.tls.certificates.leaf.subject.common_name: "example.com"
services.tls.certificates.leaf.subject.organization: "Acme Corp"

# By certificate issuer
services.tls.certificates.leaf.issuer.organization: "Let's Encrypt"
services.tls.certificates.leaf.issuer.common_name: "DigiCert"

# By TLS version
services.tls.version_selected: "TLSv1.0"
services.tls.version_selected: "TLSv1.3"
services.tls.version_selected: "SSLv3"

# Self-signed certificates
services.tls.certificates.leaf.issuer.common_name: services.tls.certificates.leaf.subject.common_name

# Expired certificates
services.tls.certificates.leaf.validity.end: [* TO 2024-01-01]

# Certificate SAN (Subject Alt Names)
services.tls.certificates.leaf.names: "example.com"
services.tls.certificates.leaf.names: "*.example.com"

# JARM fingerprint (TLS server fingerprint)
services.jarm.fingerprint: "JARM_HASH_HERE"

# JA3S fingerprint
services.tls.ja3s: "JA3S_HASH_HERE"

CERTIFICATE SEARCH (Dedicated Index)#

# Search the certificate index directly
parsed.subject.common_name: "example.com"
parsed.issuer.organization: "Let's Encrypt"
parsed.names: "*.example.com"
fingerprint_sha256: "HASH"
parsed.validity.end: [* TO 2024-01-01]      # Expired
parsed.subject.organization: "Target Corp"

# Find related infrastructure via certs
# Same org cert on different IPs = related assets
# Wildcard cert reuse reveals hidden services

COMBINING QUERIES#

# AND (explicit)
services.port: 443 AND location.country_code: "US"

# OR
services.port: 80 OR services.port: 443

# NOT
NOT services.port: 22
services.port: 80 AND NOT location.country_code: "US"

# Grouping
(services.port: 80 OR services.port: 443) AND location.country_code: "DE"

# Wildcards
services.tls.certificates.leaf.subject.common_name: *.example.com

# Exists (field has any value)
services.http.response.html_title: *

COMMON SEARCH QUERIES#

# Exposed databases
services.port: 27017 AND services.banner: "MongoDB"
services.port: 6379 AND services.service_name: REDIS
services.port: 9200 AND services.http.response.body: "cluster_name"
services.port: 5984 AND services.http.response.body: "couchdb"

# Admin panels
services.http.response.html_title: "phpMyAdmin"
services.http.response.html_title: "Kibana"
services.http.response.html_title: "Grafana"
services.http.response.html_title: "Jenkins"
services.http.response.html_title: "Portainer"

# Industrial Control Systems
services.service_name: MODBUS
services.service_name: BACNET
services.service_name: DNP3
services.service_name: S7
services.port: 502
services.port: 47808

# Network devices
services.software.product: "Cisco IOS"
services.http.response.html_title: "RouterOS"
services.software.product: "MikroTik"
services.software.product: "Fortinet"

# Webcams / IoT
services.http.response.html_title: "webcam"
services.service_name: RTSP
services.port: 554

# Vulnerable TLS
services.tls.version_selected: "TLSv1.0"
services.tls.version_selected: "SSLv3"

PYTHON API#

from censys.search import CensysHosts, CensysCerts

# Host search
h = CensysHosts()

# Basic search
for host in h.search("services.port: 22 AND location.country_code: US",
                      per_page=25):
    print(host)

# View specific host
host = h.view("1.2.3.4")
print(host['services'])
print(host['location'])

# Aggregate (facets)
report = h.aggregate(
    "services.port: 443",
    field="services.software.product",
    num_buckets=10
)
for bucket in report:
    print(f"{bucket['key']}: {bucket['count']}")

# Certificate search
c = CensysCerts()
for cert in c.search("parsed.subject.common_name: example.com"):
    print(cert)

# Subdomains
from censys.search import CensysHosts
h = CensysHosts()
names = h.view_host_names("1.2.3.4")

# Bulk view
hosts = h.bulk_view(["1.2.3.4", "5.6.7.8"])

CENSYS VS SHODAN#

Feature          Censys              Shodan
-------          ------              ------
Cert search      Excellent           Good
TLS analysis     Deep (JARM/JA3S)    Basic
Query syntax     Structured fields   Flat filters
ICS/SCADA        Good                Excellent
Screenshots      Limited             Extensive
Free tier        250 queries/mo      Limited
Vuln tagging     Limited             vuln: filter
Historical       Enterprise          Membership
Real-time        No firehose         Stream API
Best for         Cert/TLS/infra      Banner/service

TIPS#

  - Certificate searches are Censys's strongest feature
  - Use cert subject/issuer to map org infrastructure
  - JARM fingerprints identify C2 frameworks and specific servers
  - Combine with Shodan for comprehensive coverage
  - Wildcard cert reuse often reveals shadow IT
  - services.tls.certificates.leaf.names finds all SANs
  - Use aggregate/facets for statistical analysis
  - Free tier is generous for research (250 queries/month)
  - Historical data (enterprise) shows infrastructure changes over time
  - Export results via API for large-scale analysis