All integrations
Shodan logo

Shodan

Compliance & SecurityMonitoring

Search Shodan, the search engine for Internet-connected devices: see what runs on an IP address, search and count exposed services by product, port, country or vulnerability, list a domain's subdomains and DNS records, request scans and manage Shodan Monitor network alerts. Eight actions are free and need no API key: InternetDB IP lookups, CVEDB vulnerability searches, subdomains and certificates from Certificate Transparency logs, and ping and DNS checks from around the world.

25 actions

Actions

Steps your workflow can run in Shodan.

Look up IP addressFree, no API key needed. See what Shodan's weekly scan found at an IP address, from its InternetDB: open ports, host names, the software running (as CPE names), tags like cloud or vpn, and CVE IDs of known vulnerabilities. An address Shodan saw nothing at comes back with found false, not an error. Free for non-commercial use.
Get vulnerabilityFree, no API key needed. Get a vulnerability from Shodan's CVEDB by CVE or EUVD ID: its summary, CVSS scores, EPSS exploit prediction, whether CISA lists it as exploited in the wild, references and the affected software versions. An ID CVEDB doesn't have comes back with found false. Free for non-commercial use.
Search vulnerabilitiesFree, no API key needed. Find vulnerabilities in Shodan's CVEDB by product (like log4j) or exact version (a CPE name), or the newest in anything. Narrow to ones known to be exploited, or to a publication date range, and sort by newest or by likelihood of exploitation (EPSS). Free for non-commercial use.
Find product CPEsFree, no API key needed. List the CPE names Shodan's CVEDB knows for a product, one per version, like cpe:2.3:a:apache:log4j:2.14.1. Pass one to Search vulnerabilities to check that exact version. Free for non-commercial use.
Find hostnames in certificate logsFree, no API key needed. Find every host name under a domain that a publicly logged TLS certificate covers, from Shodan's mirror of the Certificate Transparency logs: a quick way to map a domain's subdomains.
List domain certificatesFree, no API key needed. List the TLS certificates issued for a domain, newest first, from Shodan's mirror of the Certificate Transparency logs: who issued each, when it expires and the names it covers. Use it to spot a certificate you didn't request, or one about to expire.
Ping from around the worldFree, no API key needed. Ping an IP address or host name from Shodan's Geonet servers in several cities around the world, to see whether it is up everywhere and how fast it answers from each place.
Look up DNS from around the worldFree, no API key needed. Look up a host name's DNS records from Shodan's Geonet servers in several cities around the world and compare the answers, to check that a DNS change has spread or that a site is served differently by region.
Get host detailsGet everything Shodan knows about an IP address: who owns it, where it is, its open ports, and each service it runs with its software, TLS certificate, web page title and vulnerabilities. An address Shodan knows nothing about comes back with found false. Needs an API key with a Membership or a paid plan, and uses no query credits.
Search hostsSearch Shodan for Internet-facing services, 100 a page, using the same queries as shodan.io: by product, port, country, organization, network or vulnerability. Optionally break the results down by country, port or another property. Needs an API key. A query with filters, or a page after the first, costs 1 query credit and needs a Membership.
Count hostsCount how many services match a Shodan search query, with an optional breakdown by country, organization, port or another property, without returning the results. Needs an API key; uses no query credits.
Get domain infoGet the subdomains and DNS records Shodan has seen for a domain, 100 records a page, optionally of one record type. Needs an API key with a Membership or a paid plan. Each page costs 1 query credit.
Resolve hostnamesLook up the IP address of up to 100 host names at once. A name that doesn't resolve comes back with no address rather than stopping the rest. Needs an API key.
Reverse DNS lookupLook up the host names of up to 100 IP addresses at once. An address with none comes back with an empty list rather than stopping the rest. Needs an API key.
Request a scanAsk Shodan to scan public IP addresses or networks now, rather than waiting for its regular crawl, for example after closing a port. Each IP address costs 1 scan credit. Needs an API key with a Membership or a paid plan. Check progress with Get scan status, then read the results with Get host details.
Get scan statusCheck how far a scan has got: SUBMITTING, QUEUE, PROCESSING or DONE. Needs an API key.
List scansList the scans this account has requested, with each one's status, 100 a page. Needs an API key.
Create network alertStart monitoring IP addresses or networks with Shodan Monitor, and turn on the triggers to be notified about, like a newly opened port or a vulnerable service. Notifications go to the Shodan account's email. Needs an API key with a Membership (16 IP addresses) or a paid plan.
List network alertsList the account's network alerts, with what each monitors and which triggers are on. Needs an API key.
Get network alertGet one network alert: what it monitors, which triggers are on and when it expires. Needs an API key.
Update alert networksReplace the IP addresses and networks a network alert monitors with a new list. Its triggers stay as they are. Needs an API key.
Enable alert triggersTurn on triggers for a network alert, to be notified when Shodan finds, for example, a new open port or a vulnerable service. Turning on one that is already on changes nothing. Needs an API key.
Disable alert triggersTurn off triggers for a network alert, to stop those notifications. The alert keeps monitoring. Needs an API key.
Delete network alertDelete a network alert, which stops monitoring its IP addresses and frees them for another alert. Needs an API key.
Get API plan and creditsGet the Shodan account's plan and what it has left this month: query credits, scan credits and monitored IP addresses. Needs an API key; works on every plan.

Connect in a few clicks

Authenticate once and every action and trigger for the app is ready to drop into a workflow. No glue code, no maintenance.

Automate across your stack

Chain apps together with triggers, actions, and logic that move data between your tools automatically, so work happens without you.

Secure by default

Credentials are encrypted and scoped per workspace. Connect the tools your team already trusts with confidence.

Automate Shodan with Lodol.

Connect Shodan and build your first workflow in minutes. No credit card required.

Free plan available · No credit card required