Shodan
Shodan is an integrated data source (a Module) in UserSearch. It maintains an internet-wide index of hosts and connected assets, letting you look up what a given piece of infrastructure exposes to the public internet rather than what a person or account looks like. In UserSearch, Shodan is the data source behind the Cyber search type.
Official site: shodan.io
What Shodan is
Section titled “What Shodan is”Shodan continuously scans the public internet and catalogues the services it finds. Instead of indexing web pages, it indexes hosts: the ports they leave open, the banners those services return, the certificates they present, and the devices sitting behind them. That makes it the reference source when your starting point is an infrastructure identifier — an IP address, a hostname or domain, or a TLS certificate — and you want to know what is exposed there.
What it returns
Section titled “What it returns”When you run a Cyber search, Shodan supplies host- and asset-level detail such as:
- Open ports and the services listening on them
- Service banners and detected technologies
- TLS/SSL certificates presented by a host
- Known vulnerabilities (CVEs) associated with the detected services
- Exposed devices — cameras, industrial control systems, databases, IoT and more
Which UserSearch search types use it
Section titled “Which UserSearch search types use it”Shodan powers the Cyber search type end to end. At v2.0.20, every one of the 12 Cyber Modules runs against Shodan, so you are always querying the same underlying scan data through a different lens:
| Cyber Module | What you look up |
|---|---|
| IP Host Lookup | Full host profile for a single IPv4/IPv6 address |
| Find Hosts by Hostname / Domain | Hosts matching a hostname or domain |
| Custom Asset Search | A custom Shodan query over exposed assets |
| Internet-Exposed Cameras | Internet-facing cameras |
| SSL/TLS Certificate Search | TLS/SSL certificate records |
| Industrial Control Systems | ICS / SCADA systems |
| Exposed Databases | Publicly exposed databases |
| Cryptocurrency Infrastructure | Crypto infrastructure hosts |
| VPN, Proxy & Anonymisation | VPN, proxy and anonymisation infrastructure |
| IoT & Smart Devices | IoT and smart devices |
| Open File Shares & Storage | Open file shares and storage |
| Email & Mail Servers | Email and mail servers |
Because a single data source backs the whole search type, switching Modules changes the query shape and the input field — not the source.
How to access Shodan in UserSearch
Section titled “How to access Shodan in UserSearch”- Select the Cyber search type.
- Leave the default IP Host Lookup Module selected, or pick the Module that matches your starting identifier.
- Enter your target (for IP Host Lookup, an IPv4 or IPv6 address).
- Confirm the Cost per search shown on screen before you run.
- Select Search Now.
- Review the returned host profile. Any matches are marked Found, and the Data Source column shows Shodan.
Reliability note
Section titled “Reliability note”Verified against UserSearch v2.0.20