← All cheat sheets

SHODAN

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Google Dork Builder

Search engine for internet-connected devices. Indexes banners,
services, ports, and metadata across the entire IPv4 space.

ACCOUNT & API#

# API key (required for most features)
# Free account: limited searches, 1 query credit/month
# Membership ($49 one-time): unlimited searches, 100 credits/month
# API key location: https://account.shodan.io

# API info
curl "https://api.shodan.io/api-info?key=YOUR_API_KEY"

CLI INSTALLATION#

pip install shodan
shodan init YOUR_API_KEY

CLI COMMANDS#

shodan search "apache"                      # Basic search
shodan search "apache" --fields ip_str,port,org  # Specific fields
shodan count "apache country:US"            # Count results
shodan host 1.2.3.4                         # Host info
shodan stats --facets country "apache"      # Faceted stats
shodan download results "apache country:DE" # Download results
shodan parse results.json.gz               # Parse downloaded data
shodan scan submit 1.2.3.4                 # On-demand scan (credits)
shodan scan submit --filename targets.txt  # Scan from file
shodan myip                                # Your public IP
shodan domain example.com                  # Domain info
shodan info                                # Account info/credits
shodan honeyscore 1.2.3.4                  # Honeypot probability
shodan alert create "My Network" 1.2.3.0/24  # Create monitor alert
shodan alert list                           # List alerts
shodan alert triggers                       # Available triggers
shodan alert enable ALERT_ID trigger_name   # Enable trigger
shodan stream                               # Real-time stream (firehose)
shodan radar                                # Real-time map in terminal

BASIC SEARCH FILTERS#

# By service/product
product:"Apache httpd"
product:"nginx"
product:"Microsoft IIS"
product:"OpenSSH"
product:"MySQL"

# By port
port:22                                     # SSH
port:80                                     # HTTP
port:443                                    # HTTPS
port:3389                                   # RDP
port:21                                     # FTP
port:3306                                   # MySQL
port:5432                                   # PostgreSQL
port:27017                                  # MongoDB
port:6379                                   # Redis
port:9200                                   # Elasticsearch
port:5900                                   # VNC
port:1883                                   # MQTT
port:502                                    # Modbus (ICS)
port:47808                                  # BACnet (ICS)
port:2404                                   # IEC 60870-5-104 (ICS)
port:20000                                  # DNP3 (ICS)

# By country/city/region
country:"US"
country:"DE"
city:"Berlin"
state:"California"
geo:"48.8566,2.3522,100"                    # Lat,Lon,Radius(km)

# By organization/ISP/ASN
org:"Google"
org:"Amazon"
isp:"Comcast"
asn:"AS15169"

# By hostname/domain
hostname:"example.com"
hostname:".gov"
hostname:".edu"

# By operating system
os:"Windows Server 2019"
os:"Linux"
os:"Ubuntu"

# By version
version:"7.4"

# By network
net:"192.168.0.0/16"
net:"10.0.0.0/8"

# By SSL/TLS
ssl:"example.com"                           # SSL cert matches
ssl.cert.subject.cn:"example.com"           # Common name
ssl.cert.issuer.o:"Let's Encrypt"           # Issuer org
ssl.cert.expired:true                       # Expired certs
ssl.cert.serial:1234567890                  # Serial number
ssl.version:"sslv3"                         # Insecure version
ssl.version:"tlsv1"                         # TLS 1.0
has_ssl:true                                # Has SSL/TLS

# By HTTP
http.title:"Dashboard"
http.title:"login"
http.status:200
http.status:401
http.component:"WordPress"
http.component:"jQuery"
http.html:"password"
http.favicon.hash:116323821                 # Favicon hash

# By vulnerability
vuln:"CVE-2021-44228"                       # Log4Shell
vuln:"CVE-2019-0708"                        # BlueKeep
vuln:"CVE-2017-0144"                        # EternalBlue
has_vuln:true                               # Any known vuln

# By screenshot
has_screenshot:true
screenshot.label:"login"

# Before/after date
before:"01/01/2024"
after:"01/06/2024"

COMBINING FILTERS#

# AND (space-separated, implicit)
apache country:"US" port:80

# Negative filter (exclude)
apache -country:"US"
port:22 -product:"OpenSSH"

# OR is NOT supported in Shodan syntax
# Use multiple queries or the API instead

COMMON SEARCH QUERIES#

# Exposed databases
product:"MongoDB" -authentication
product:"Redis" -authentication
product:"Elasticsearch" port:9200
product:"CouchDB" port:5984
port:5432 "PostgreSQL" "no password"

# Default credentials / admin panels
http.title:"Dashboard" http.status:200
http.title:"admin" http.status:200
http.title:"phpMyAdmin"
http.title:"Kibana"
http.title:"Grafana"
http.title:"Jenkins"
"default password" port:80

# Webcams / IoT
has_screenshot:true port:554                # RTSP cameras
http.title:"webcamXP"
http.title:"IP Camera"
product:"Hikvision"
"Server: yawcam"
"Server: webcam"

# Industrial Control Systems (ICS/SCADA)
tag:"ics"
port:502 "Modbus"
port:47808 "BACnet"
port:20000 "DNP3"
port:44818 "EtherNet/IP"
"Siemens" port:102
"Schneider Electric"
"Rockwell Automation"

# Network infrastructure
product:"Cisco IOS"
product:"MikroTik"
"Server: Netgear"
http.title:"RouterOS"
"Fortinet" port:443
"SonicWall" port:443
"pfSense"
"Ubiquiti" port:443

# VPN / Remote access
product:"OpenVPN"
"Citrix" http.title:"NetScaler"
http.title:"Pulse Secure"
http.title:"GlobalProtect"
product:"Fortinet SSL VPN"

# Email servers
product:"Microsoft Exchange"
"X-OWA-Version"
product:"Postfix"
product:"Dovecot"

# Vulnerable services
vuln:"CVE-2021-44228" product:"Apache"      # Log4Shell
vuln:"CVE-2021-34473"                       # ProxyShell
vuln:"CVE-2023-34362"                       # MOVEit
ssl.version:"sslv3"                         # POODLE vulnerable
ssl.version:"tlsv1"                         # TLS 1.0 (deprecated)
"X-Powered-By: PHP/5"                       # Old PHP

# Cloud / misconfig
org:"Amazon" port:9200                      # AWS Elasticsearch
org:"Microsoft Azure" port:3389             # Azure RDP
org:"Google Cloud" port:22                  # GCP SSH
http.title:"Index of /"                     # Directory listing

PYTHON API#

import shodan

api = shodan.Shodan('YOUR_API_KEY')

# Search
results = api.search('apache country:US')
for result in results['matches']:
    print(f"{result['ip_str']}:{result['port']}")
    print(result['data'])

# Host info
host = api.host('1.2.3.4')
print(host['os'])
print(host['ports'])
for item in host['data']:
    print(f"Port: {item['port']}, Banner: {item['data'][:100]}")

# Count
count = api.count('apache')
print(f"Total: {count['total']}")

# Search with facets
results = api.search('apache', facets=[('country', 10)])
for facet in results['facets']['country']:
    print(f"{facet['value']}: {facet['count']}")

# Network alerts
alert = api.create_alert('My Alert', '1.2.3.0/24')
triggers = api.alert_triggers()

# Scan
scan = api.scan(['1.2.3.4'])

# DNS lookup
dns = api.dns.resolve(['google.com', 'example.com'])
reverse = api.dns.reverse(['8.8.8.8'])

# Exploits API
exploits = api.exploits.search('apache')
# Calculate favicon hash for finding specific web apps
import mmh3, requests, codecs
response = requests.get('https://target.com/favicon.ico')
favicon = codecs.encode(response.content, 'base64')
hash = mmh3.hash(favicon)
print(f"http.favicon.hash:{hash}")

# Common favicon hashes
http.favicon.hash:116323821                 # Cobalt Strike (default)
http.favicon.hash:-1137190734               # Spring Boot
http.favicon.hash:81586312                  # Jenkins
http.favicon.hash:1485257654               # Laravel

SHODAN MONITOR#

# Real-time monitoring of your assets
shodan alert create "Corp Network" 10.0.0.0/8
shodan alert enable ALERT_ID new_service
shodan alert enable ALERT_ID open_database
shodan alert enable ALERT_ID vulnerable
shodan alert enable ALERT_ID ssl_expired
shodan alert enable ALERT_ID internet_scanner

# Notification integrations: email, Slack, webhook, PagerDuty

SHODAN MAPS & IMAGES#

# Shodan Maps: https://maps.shodan.io
# Visual search with geographic display
# Shodan Images: https://images.shodan.io
# Browse screenshots of services (RDP, VNC, webcams)

TIPS#

  - Use quotes for exact multi-word matches
  - Combine filters for precision (product + country + port)
  - Favicon hash is powerful for finding specific applications
  - has_screenshot:true reveals visual services (RDP, VNC, web)
  - Monitor your own org with alerts for exposure detection
  - Free tier is limited; membership unlocks full search
  - vuln: filter requires membership or higher
  - Use download + parse for bulk analysis
  - SSL cert searches find related infrastructure
  - Check ssl.cert.expired:true for low-hanging fruit