27 lines
1.3 KiB
Markdown
27 lines
1.3 KiB
Markdown
- Shodan is a tool that continuously spiders infrastructure on the internet. It is much more verbose than regular spiders. It captures response data, cert data, stack profiling data, and more. It requires registration.
|
|
- [Example Search](https://www.shodan.io/search?query=twitch.tv)
|
|
- Official Shodan documentation:
|
|
- Data reference: https://datapedia.shodan.io/
|
|
- List of search filters: https://www.shodan.io/search/filters
|
|
- Query syntax: https://help.shodan.io/the-basics/search-query-fundamentals
|
|
- Official Examples: https://www.shodan.io/search/examples
|
|
- Shodan Pentesting Guide
|
|
- https://community.turgensec.com/shodan-pentesting-guide/
|
|
- Shodan and Cert.sh Recon w/ GodfatherOrwa
|
|
- https://www.youtube.com/watch?v=YoXM4m1VEM0
|
|
- Shodan filters and hacks
|
|
- https://www.youtube.com/watch?v=GyZFM5IaH2Y
|
|
- 100 Shodan Queries for Discovery
|
|
- https://www.osintme.com/index.php/2021/01/16/ultimate-osint-with-shodan-100-great-shodan-queries/
|
|
- Org filter dorks for technologies and services:
|
|
- https://mr-koanti.github.io/shodan#
|
|
- Other interesting queries:
|
|
- https://github.com/jakejarvis/awesome-shodan-queries
|
|
|
|
![[ShodanCheatSheet.png]]
|
|
- Automated tooling:
|
|
- [Karma v2](https://github.com/Dheerajmadhukar/karma_v2)
|
|
- [WTFIS](https://github.com/pirxthepilot/wtfis)
|
|
-
|
|
|