category: Data Enrichment & Threat Intelligence provider: Shodan sectionorder: - Connect - Collect commonfields: id: Shodan_v2 version: -1 configuration: - name: credentials type: 9 displaypassword: API Key hiddenusername: true section: Connect required: false - display: API Key name: api_key type: 4 hidden: true section: Connect required: false - display: Base url to Shodan API name: api_url required: true type: 0 defaultvalue: https://api.shodan.io section: Connect - display: Trust any certificate (not secure) name: insecure type: 8 section: Connect advanced: true required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false - defaultvalue: A - Completely reliable name: integrationReliability display: 'Source Reliability' options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged type: 15 additionalinfo: Reliability of the source providing the intelligence data. section: Collect required: false - defaultvalue: 'indicatorType' name: feedExpirationPolicy display: '' type: 17 options: - never - interval - indicatorType - suddenDeath section: Collect advanced: true required: false - defaultvalue: '20160' name: feedExpirationInterval display: '' type: 1 section: Collect advanced: true required: false - display: The maximum number of events per fetch name: max_fetch defaultvalue: "50000" advanced: true type: 0 required: false section: Collect hidden: - xsoar supportedModules: - xsiam description: A search engine used for searching Internet-connected devices. display: Shodan v2 name: Shodan_v2 script: commands: - arguments: - default: true description: The query for searching the database of banners. The search query supports filtering using the "filter:value" format to narrow your search. For example, the query "apache country:DE" returns Apache web servers located in Germany. name: query required: true - description: A CSV list of properties on which to get summary information. The search query supports filtering using the "property:count" format to define the number of facets to return for a property. For example, the query "country:100" returns the top 100 countries. name: facets - defaultValue: '1' description: The page number of the fetched results. Each page contains a maximum of 100 results. name: page - name: return_json auto: PREDEFINED predefined: - Yes - No description: Whether to return a JSON file containing the full search results for further processing. defaultValue: No description: Searches Shodan using facets to get summary information on properties. name: search outputs: - contextPath: Shodan.Banner.Org description: The name of the organization to which the space of the IP address space for the searched device is assigned. type: String - contextPath: Shodan.Banner.Isp description: The Internet Service Provider that provides the organization with the IP address space for the searched device. type: String - contextPath: Shodan.Banner.Transport description: The IP address transport protocol used to fetch the summary information. Can be "UDP" or "TCP". type: String - contextPath: Shodan.Banner.Asn description: The Autonomous System Number. For example, "AS4837". type: String - contextPath: Shodan.Banner.IP description: The IP address of the host as a string. type: String - contextPath: Shodan.Banner.Port description: The port number on which the service is operating. type: Number - contextPath: Shodan.Banner.Ssl.versions description: The list of SSL versions that are supported by the server. Unsupported versions are prefixed with a "-". For example, ["TLSv1", "-SSLv2"] means that the server supports TLSv1, but does not support SSLv2. type: String - contextPath: Shodan.Banner.Hostnames description: An array of strings containing all of the host names that have been assigned to the IP address for the searched device. type: String - contextPath: Shodan.Banner.Location.City description: The city in which the searched device is located. type: String - contextPath: Shodan.Banner.Location.Longitude description: The longitude of the geolocation of the searched device. type: Number - contextPath: Shodan.Banner.Location.Latitude description: The latitude of the geolocation of the searched device. type: Number - contextPath: Shodan.Banner.Location.Country description: The country in which the searched device is located. type: String - contextPath: Shodan.Banner.Timestamp description: The timestamp in UTC format indicating when the banner was fetched from the searched device. type: Date - contextPath: Shodan.Banner.Domains description: An array of strings containing the top-level domains for the host names of the searched device. It is a utility property for filtering by a top-level domain instead of a subdomain. It supports handling global top-level domains that have several dots in the domain. For example, "co.uk". type: String - contextPath: Shodan.Banner.OS description: The operating system that powers the searched device. type: String - contextPath: Shodan.Banner.Product description: Name of the software that powers the service. type: String - contextPath: Shodan.Banner.Ntlm.OSBuild description: OS build reported by the service. type: String - contextPath: Shodan.Banner.Ntlm.DNSForestName description: DNS Forest Name reported by the service. type: String - contextPath: Shodan.Banner.Ntlm.Timestamp description: Timestamp. type: Number - contextPath: Shodan.Banner.Ntlm.FQDN description: FQDN. type: String - contextPath: Shodan.Banner.Ntlm.NetBIOSDomainName description: Netbios Domain Name. type: String - contextPath: Shodan.Banner.Ntlm.NetBIOSComputerName description: Netbios Computer Name. type: String - contextPath: Shodan.Banner.Ntlm.TargetRealm description: Target Realm. type: String - contextPath: Shodan.Banner.Ntlm.OS description: OS. type: Unknown - contextPath: Shodan.Banner.Ntlm.DNSDomainName description: DNS Domain Name. type: String - contextPath: Shodan.Banner.Hash description: Numeric hash of the "data" property which is helpful for finding other IPs with the exact same information. type: Number - contextPath: Shodan.Banner.Tags description: Tag applied by Shodan analysis. type: Unknown - contextPath: Shodan.Banner.SslCert.SigAlg description: Certificate Signature Algorithm. type: String - contextPath: Shodan.Banner.SslCert.Issued description: Timestamp of the beginning of certificate validity (Not Valid Before). type: Date - contextPath: Shodan.Banner.SslCert.Expires description: Timestamp of the end of certificate validity (Not Valid After). type: Date - contextPath: Shodan.Banner.SslCert.Version description: X.509 Certificate Version. type: Number - contextPath: Shodan.Banner.SslCert.Serial description: Serial Number assigned by the issuer. type: Number - contextPath: Shodan.Banner.SslCert.Subject.CN description: Subject Common Name. type: String - contextPath: Shodan.Banner.SslCert.Subject.O description: Subject Organization. type: String - contextPath: Shodan.Banner.SslCert.Subject.L description: Subject Locality or City. type: String - contextPath: Shodan.Banner.SslCert.Subject.ST description: Subject State or Province. type: String - contextPath: Shodan.Banner.SslCert.Subject.C description: Subject Country Name. type: String - contextPath: Shodan.Banner.SslCert.Expired description: Boolean indicating whether the certificate is expired. type: Boolean - contextPath: Shodan.Banner.SslCert.Issuer.CN description: Issuer Certificate Common Name. type: Unknown - contextPath: Shodan.Banner.SslCert.Issuer.O description: Issuer Organization. type: String - contextPath: Shodan.Banner.SslCert.Issuer.OU description: Issuer Organizational Unit. type: String - contextPath: Shodan.Banner.SslCert.Issuer.L description: Issuer Locality or City. type: String - contextPath: Shodan.Banner.SslCert.Issuer.ST description: Issuer State or Province. type: String - contextPath: Shodan.Banner.SslCert.Issuer.C description: Issuer Country Name. type: String - contextPath: Shodan.Banner.Data description: The raw data returned fro the service. type: String - contextPath: Shodan.Banner.CPE23 description: CPE information in the 2.3 format. type: Unknown - contextPath: Shodan.Banner.Device description: Device identified by Shodan. type: String - contextPath: Shodan.Banner.DeviceType description: The Device Type identified by Shodan. type: String - contextPath: Shodan.Banner.Info description: Additional information provided by Shodan. type: String - contextPath: Shodan.Banner.IPv6 description: The IPv6 address of the host as a string. type: String - contextPath: Shodan.Banner.Link description: The Link identified by Shodan. type: String - contextPath: Shodan.Banner.Platform description: The Platform identified by Shodan. type: String - contextPath: Shodan.Banner.Product description: The Product identified by Shodan. type: String - arguments: - default: true description: The IP addresses of the host. name: ip required: true isArray: true description: Returns all services that have been found on the IP address of the searched host. name: ip outputs: - contextPath: IP.ASN description: The Autonomous System Number. type: Unknown - contextPath: IP.Address description: The IP address. type: Unknown - contextPath: IP.Geo.Country description: The country of a given IP address. type: Unknown - contextPath: IP.Geo.Description description: The description of the location. type: Unknown - contextPath: IP.Geo.Location description: The latitude and longitude of an IP address. type: Unknown - contextPath: IP.Hostname description: The hostname of the IP address. type: Unknown - contextPath: IP.Relationships description: The relationships between the ip and it's CVEs. type: Unknown - contextPath: Shodan.IP.Tags description: The Shodan tags associated with the IP address. type: String - contextPath: Shodan.IP.Latitude description: The latitude of the geolocation of the searched device. type: Number - contextPath: Shodan.IP.Org description: The name of the organization to which the IP space for the searched device is assigned. type: String - contextPath: Shodan.IP.ASN description: The Autonomous System Number. For example, "AS4837". type: String - contextPath: Shodan.IP.ISP description: The Internet Service Provider that provides the organization with the IP space for the searched device. type: String - contextPath: Shodan.IP.Longitude description: The longitude of the geolocation of the searched device. type: Number - contextPath: Shodan.IP.LastUpdate description: The timestamp in UTC format indicating when the banner was fetched from the searched device. type: Date - contextPath: Shodan.IP.CountryName description: The country in which the searched device is located. type: String - contextPath: Shodan.IP.OS description: The operating system on which the searched device is running. type: String - contextPath: Shodan.IP.Port description: The port number on which the service is operating. type: Number - contextPath: Shodan.IP.Address description: The IP address of the host as a string. type: String - contextPath: Shodan.IP.Vulnerabilities description: A list of Vulnerabilities. type: Unknown - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - arguments: - description: The query for searching the database of banners. The search query supports filtering using the "filter:value" format to narrow your search. For example, the query "apache country:DE" returns Apache web servers located in Germany. name: query required: true description: Returns the total number of results that match only the specified query or facet settings. This command does not return host results. This command does not consume query credits. name: shodan-search-count outputs: - contextPath: Shodan.Search.ResultCount description: The number of results matched in the search query. type: Number - arguments: - description: A CSV list of IP addresses or netblocks for Shodan to crawl defined in CIDR notation. name: ips required: true description: Requests Shodan to crawl a network. name: shodan-scan-ip outputs: - contextPath: Shodan.Scan.ID description: The unique ID of the scan. type: String - contextPath: Shodan.Scan.Status description: The status of the scan. type: String - arguments: - description: The port for which Shodan crawls the Internet. name: port required: true - description: The name of the protocol used to interrogate the port. name: protocol required: true description: Requests for Shodan to perform a scan on the specified port and protocol. name: shodan-scan-internet outputs: - contextPath: Shodan.Scan.ID description: The ID of the initial scan. type: String - arguments: - description: The unique ID of the initial scan. name: scanID required: true description: Checks the progress of a previously submitted scan request on the specified port and protocol. name: shodan-scan-status outputs: - contextPath: Shodan.Scan.Id description: The unique ID of the scan request checked for progress. type: String - contextPath: Shodan.Scan.Status description: The status of the scan job checked for progress. type: String - arguments: - description: The name of the network alert. name: alertName required: true - description: A list of IP addresses or network ranges defined in CIDR notation. name: ip required: true - description: The number of seconds for the network alert to remain active. name: expires description: Creates a network alert for a defined IP address or netblock used for subscribing to changes or events that are discovered within the netblock's range. name: shodan-create-network-alert outputs: - contextPath: Shodan.Alert.ID description: The ID of the subscription of the specified network alert. type: String - contextPath: Shodan.Alert.Expires description: The number of seconds that the specified network alert remains active. type: String - arguments: - description: The ID of the network alert. name: alertID required: true description: Gets the details of a network alert. name: shodan-network-get-alert-by-id outputs: - contextPath: Shodan.Alert.ID description: The ID of the subscription of the network alert. type: String - contextPath: Shodan.Alert.Expires description: The number of seconds that the network alert remains active. type: String - description: Gets a list of all created network alerts. name: shodan-network-get-alerts outputs: - contextPath: Shodan.Alert.ID description: The IDs of the subscriptions of the network alerts. type: String - contextPath: Shodan.Alert.Expires description: The number of seconds that the network alerts remain active. type: String - arguments: - description: The ID of the network alert to remove. name: alertID required: true description: Removes the specified network alert. name: shodan-network-delete-alert - arguments: - description: The ID of the network alert for which to enable notifications. name: alertID required: true - description: The name of the trigger. name: Trigger required: true description: Enables receiving notifications for network alerts that are set off by the specified triggers. name: shodan-network-alert-set-trigger - arguments: - description: The ID of the network alert for which to disable notifications. name: alertID required: true - description: The name of the trigger. name: Trigger required: true description: Disables receiving notifications for network alerts that are set off by the specified triggers. name: shodan-network-alert-remove-trigger - arguments: - description: The ID of the network alert for which to ignore the specified services. name: alertID required: true - description: The name of the trigger. name: trigger required: true - description: The service specified in the "ip:port" format. For example, "1.1.1.1:80". name: service required: true description: Ignores the specified services for network alerts that are set off by the specified triggers. name: shodan-network-alert-whitelist-service - arguments: - description: The ID of the alert for which to resume the specified services. name: alertID required: true - description: The name of the trigger. name: trigger required: true - description: The service specified in the "ip:port" format. For example, "1.1.1.1:80". name: service required: true description: Resumes receiving notifications for network alerts that are set off by the specified triggers. name: shodan-network-alert-remove-service-from-whitelist - name: shodan-get-events description: Retrieves events from Shodan. arguments: - name: should_push_events description: If set to 'True', the command will create events; otherwise, it will only display them. defaultValue: 'False' auto: PREDEFINED isArray: false predefined: - 'True' - 'False' - name: max_fetch description: The maximum amount of events to return. defaultValue: 50000 dockerimage: demisto/python3:3.12.13.10116658 runonce: false script: '-' subtype: python3 type: python isfetchevents: true isfetchevents:xsoar: false tests: - Test-Shodan_v2 fromversion: 5.0.0