OSINT · Commercial (freemium); paid membership and API tiers

Shodan

Shodan is a search engine for internet-connected devices. Instead of indexing web page content like Google, it continuously scans the internet and catalogues the service banners of devices it finds: web servers, databases, routers, industrial control systems, webcams and IoT gear. Users search by product, port, country, organisation or vulnerability to see what is exposed online. Security researchers, defenders and attackers alike use it to understand an organisation's internet-facing attack surface.

Last updated: 6 August 2026

What Shodan is actually used for

Shodan answers what of an organisation, or the whole internet, is reachable and what it is running. A defender searches their own IP ranges or domain to find forgotten servers, exposed databases or devices running outdated, vulnerable software before an attacker does. A researcher measures how many hosts worldwide expose a given service or are affected by a CVE. It provides banners, geolocation, open ports and detected vulnerabilities, plus filters, a CLI and an API for automation. It only reports what devices already publish publicly; it does not log in.

Platforms

Web · CLI · API (cross-platform)

Licence

Commercial (freemium); paid membership and API tiers

Commands worth knowing

product:nginx

Find hosts whose banners identify a specific product.

port:3389 country:IN

Locate exposed Remote Desktop (RDP) services in a given country.

org:"Example Ltd"

See internet-facing assets attributed to an organisation.

vuln:cve-2021-44228

Search for hosts flagged for a specific vulnerability (paid feature).

net:203.0.113.0/24

Enumerate exposed services within an IP range you are assessing.

shodan host 8.8.8.8

Use the CLI to pull all known information about one IP.

shodan search --fields ip_str,port,org apache

Query from the command line and output selected fields.

The legal line

Shodan itself only indexes banners that devices publicly expose, and searching that index is lawful. The line is what you do next: connecting to, logging into or probing a discovered device you do not own, even one left wide open, is unauthorised access under the IT Act 2000. Use Shodan for your own asset discovery or authorised research only.

What Shodan is bad at

Its data is a cached snapshot from periodic scans, so it can be out of date and misses hosts not yet scanned or behind firewalls. Free accounts have limited searches, filters and results, with vulnerability search and higher volumes behind paid tiers. Banners can be spoofed or generic, so exposure and vulnerability results still need verification.

Alternatives, and when to pick them

ToolPick it when
CensysYou want an alternative internet-wide scan dataset with strong certificate search.
ZoomEyeYou want another device search engine with its own crawl and coverage.
FOFAYou want extensive fingerprinting popular for asset discovery.
BinaryEdgeYou want internet exposure data geared toward attack-surface monitoring.
Your own Nmap/MasscanYou need live, current scans of a defined scope rather than cached index data.

Where we teach it

Ethical Hacking Course (6 months) — OSINT and attack surface module

We are not affiliated with, endorsed by, or a reseller for the vendors of any tool on this site.

Shodan — FAQs

Is it illegal to use Shodan?

No. Shodan only indexes information devices publicly broadcast, and searching it is legal. What can be illegal is acting on the results, such as logging into or probing an exposed device you do not own, without authorisation.

How is Shodan different from Google?

Google indexes the content of web pages. Shodan indexes the service banners of internet-connected devices, so it tells you what a host is running and what ports are open, rather than what a website says.

Is Shodan free?

There is a free tier with limited searches and filters, useful for learning. Advanced filters, vulnerability search, larger result sets and API access require a paid membership or subscription.

Shodan se apni company ka exposure kaise check karein?

Apni IP ranges (net: filter) ya organisation (org: filter) search karein taaki pata chale kaun se servers, databases ya devices internet par khule hain. Yeh defensive attack-surface review ka accha pehla kadam hai.

Learn Shodan properly, in a legal lab

Free counselling call. We will tell you honestly whether a full course is worth it for what you actually want to do.

Call +91 75175 72000