Shodan is a search engine for internet-connected devices. Instead of indexing web page content like Google, it continuously scans the internet and catalogues the service banners of devices it finds: web servers, databases, routers, industrial control systems, webcams and IoT gear. Users search by product, port, country, organisation or vulnerability to see what is exposed online. Security researchers, defenders and attackers alike use it to understand an organisation's internet-facing attack surface.
Last updated: 6 August 2026
Shodan answers what of an organisation, or the whole internet, is reachable and what it is running. A defender searches their own IP ranges or domain to find forgotten servers, exposed databases or devices running outdated, vulnerable software before an attacker does. A researcher measures how many hosts worldwide expose a given service or are affected by a CVE. It provides banners, geolocation, open ports and detected vulnerabilities, plus filters, a CLI and an API for automation. It only reports what devices already publish publicly; it does not log in.
Web · CLI · API (cross-platform)
Commercial (freemium); paid membership and API tiers
product:nginxFind hosts whose banners identify a specific product.
port:3389 country:INLocate exposed Remote Desktop (RDP) services in a given country.
org:"Example Ltd"See internet-facing assets attributed to an organisation.
vuln:cve-2021-44228Search for hosts flagged for a specific vulnerability (paid feature).
net:203.0.113.0/24Enumerate exposed services within an IP range you are assessing.
shodan host 8.8.8.8Use the CLI to pull all known information about one IP.
shodan search --fields ip_str,port,org apacheQuery from the command line and output selected fields.
Shodan itself only indexes banners that devices publicly expose, and searching that index is lawful. The line is what you do next: connecting to, logging into or probing a discovered device you do not own, even one left wide open, is unauthorised access under the IT Act 2000. Use Shodan for your own asset discovery or authorised research only.
Its data is a cached snapshot from periodic scans, so it can be out of date and misses hosts not yet scanned or behind firewalls. Free accounts have limited searches, filters and results, with vulnerability search and higher volumes behind paid tiers. Banners can be spoofed or generic, so exposure and vulnerability results still need verification.
| Tool | Pick it when |
|---|---|
| Censys | You want an alternative internet-wide scan dataset with strong certificate search. |
| ZoomEye | You want another device search engine with its own crawl and coverage. |
| FOFA | You want extensive fingerprinting popular for asset discovery. |
| BinaryEdge | You want internet exposure data geared toward attack-surface monitoring. |
| Your own Nmap/Masscan | You need live, current scans of a defined scope rather than cached index data. |
Ethical Hacking Course (6 months) — OSINT and attack surface module
We are not affiliated with, endorsed by, or a reseller for the vendors of any tool on this site.
Free counselling call. We will tell you honestly whether a full course is worth it for what you actually want to do.
Call +91 75175 72000