The search engine of internet-connected devices: open cameras, exposed databases, forgotten ICS gear โ found without sending a single packet yourself.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Shodan crawls the whole internet continuously.
Operators: port, org, net, product, vuln, country, sslโฆ
Self-footprinting = the responsible use #1.
Paid tiers expose vuln data; even free shows exposed surface.
The CLI + API turn it into an automation engine.
| port:N | service port filter |
| org: | by organization |
| country:/city: | geo filters |
| product:/os: | tech filters |
| vuln:CVE | affected hosts |
| net: | cidr range |
Banners lie. Shodan = leads, not verdicts โ verify responsibly.
Free account unlocks more results; monitor your IPs with alerts.
Censys is the excellent free complement with deeper cert history.
Found something exposed that isn't yours? Report, don't touch.
Use Shodan only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.