Claude
Chat app · Skill upload
In Claude, open Customize → Skills and use Create skill to upload the ZIP. Skill availability depends on your plan and workspace settings.
Official Claude setup →Community skill · Free instruction package
This skill should be used when the user asks to "search for exposed devices on the internet," "perform Shodan reconnaissance," "find vulnerable services using Shodan," "scan IP ranges with Shodan," or "discover IoT devices and open ports." It provides comprehensive guidance for using Shodan's search engine, CLI, and API for penetration testing reconnaissance.
Community instruction package. Read the full workflow below, then choose your app in the setup guide. Package instructions and compatibility claims have not been individually verified; check dependencies and license before use.
CHOOSE YOUR AI APP
Choose your app below for setup instructions. Keep the complete downloaded folder together. Each package may need tools, dependencies or permissions that your app does not provide.
Chat app · Skill upload
In Claude, open Customize → Skills and use Create skill to upload the ZIP. Skill availability depends on your plan and workspace settings.
Official Claude setup →Chat app · Access varies
Where Skills is available, open Plugins → Skills → Create → Upload from your computer. Otherwise, copy the instructions into a chat and add your brief; this does not install a skill or include its supporting files.
Official ChatGPT setup →Agent · Project skills
Extract the complete skill folder into your project’s .agents/skills directory. Ask the agent to use the skill for your task.
.agents/skills/shodan-reconnaissance/SKILL.mdOfficial Google Antigravity setup →Code editor · Project skills
Extract the complete folder into .cursor/skills. Check the editor’s skill settings and ask the agent to use it.
.cursor/skills/shodan-reconnaissance/SKILL.mdOfficial Cursor setup →Coding agent · Project skills
Extract the complete folder into .claude/skills. Ask Claude to use the named skill, or use its slash command when available.
.claude/skills/shodan-reconnaissance/SKILL.mdOfficial Claude Code setup →For text-only workflows, you can also paste the instructions into an AI conversation. Copying text does not enable scripts, connect accounts or grant tool access. App subscriptions may cost extra. Logos identify the products; KuchhBhi is independent and is not endorsed by these companies.
Provide systematic methodologies for leveraging Shodan as a reconnaissance tool during penetration testing engagements. This skill covers the Shodan web interface, command-line interface (CLI), REST API, search filters, on-demand scanning, and network monitoring capabilities for discovering exposed services, vulnerable systems, and IoT devices.
# Using pip
pip install shodan
# Or easy_install
easy_install shodan
# On BlackArch/Arch Linux
sudo pacman -S python-shodan
# Set your API key
shodan init YOUR_API_KEY
# Verify setup
shodan info
# Output: Query credits available: 100
# Scan credits available: 100
# View credits and plan info
shodan info
# Check your external IP
shodan myip
# Check CLI version
shodan version
# Get all information about an IP
shodan host 1.1.1.1
# Example output:
# 1.1.1.1
# Hostnames: one.one.one.one
# Country: Australia
# Organization: Mountain View Communications
# Number of open ports: 3
# Ports:
# 53/udp
# 80/tcp
# 443/tcp
# Get honeypot probability score
shodan honeyscore 192.168.1.100
# Output: Not a honeypot
# Score: 0.3
# Simple keyword search (no credits consumed)
shodan search apache
# Specify output fields
shodan search --fields ip_str,port,os smb
# Product-specific search
shodan search product:mongodb
# Search with multiple filters
shodan search product:nginx country:US city:"New York"
# Get result count without consuming credits
shodan count openssh
# Output: 23128
shodan count openssh 7
# Output: 219
# Download 1000 results (default)
shodan download results.json.gz "apache country:US"
# Download specific number of results
shodan download --limit 5000 results.json.gz "nginx"
# Download all available results
shodan download --limit -1 all_results.json.gz "query"
# Extract specific fields from downloaded data
shodan parse --fields ip_str,port,hostnames results.json.gz
# Filter by specific criteria
shodan parse --fields location.country_code3,ip_str -f port:22 results.json.gz
# Export to CSV format
shodan parse --fields ip_str,port,org --separator , results.json.gz > results.csv
ip:1.2.3.4 # Specific IP address
net:192.168.0.0/24 # Network range (CIDR)
hostname:example.com # Hostname contains
port:22 # Specific port
asn:AS15169 # Autonomous System Number
country:US # Two-letter country code
country:"United States" # Full country name
city:"San Francisco" # City name
state:CA # State/region
postal:94102 # Postal/ZIP code
geo:37.7,-122.4 # Lat/long coordinates
org:"Google" # Organization name
isp:"Comcast" # ISP name
product:nginx # Software product
version:1.14.0 # Software version
os:"Windows Server 2019" # Operating system
http.title:"Dashboard" # HTTP page title
http.html:"login" # HTML content
http.status:200 # HTTP status code
ssl.cert.subject.cn:*.example.com # SSL certificate
ssl:true # Has SSL enabled
vuln:CVE-2019-0708 # Specific CVE
has_vuln:true # Has any vulnerability
has_screenshot:true # Has screenshot available
screenshot.label:webcam # Screenshot type
# Scan single IP (1 credit per IP)
shodan scan submit 192.168.1.100
# Scan with verbose output (shows scan ID)
shodan scan submit --verbose 192.168.1.100
# Scan and save results
shodan scan submit --filename scan_results.json.gz 192.168.1.100
# List recent scans
shodan scan list
# Check specific scan status
shodan scan status SCAN_ID
# Download scan results later
shodan download --limit -1 results.json.gz scan:SCAN_ID
# List available protocols/modules
shodan scan protocols
# Default statistics (top 10 countries, orgs)
shodan stats nginx
# Custom facets
shodan stats --facets domain,port,asn --limit 5 nginx
# Save to CSV
shodan stats --facets country,org -O stats.csv apache
1. Navigate to Monitor Dashboard
2. Add IP, range, or domain to monitor
3. Configure notification service (email, Slack, webhook)
4. Select trigger events (new service, vulnerability, etc.)
5. View dashboard for exposed services
# Get API info
curl -s "https://api.shodan.io/api-info?key=YOUR_KEY" | jq
# Host lookup
curl -s "https://api.shodan.io/shodan/host/1.1.1.1?key=YOUR_KEY" | jq
# Search query
curl -s "https://api.shodan.io/shodan/host/search?key=YOUR_KEY&query=apache" | jq
import shodan
api = shodan.Shodan('YOUR_API_KEY')
# Search
results = api.search('apache')
print(f'Results found: {results["total"]}')
for result in results['matches']:
print(f'IP: {result["ip_str"]}')
# Host lookup
host = api.host('1.1.1.1')
print(f'IP: {host["ip_str"]}')
print(f'Organization: {host.get("org", "n/a")}')
for item in host['data']:
print(f'Port: {item["port"]}')
| Command | Description | Credits |
|---------|-------------|---------|
| shodan init KEY | Initialize API key | 0 |
| shodan info | Show account info | 0 |
| shodan myip | Show your IP | 0 |
| shodan host IP | Host details | 0 |
| shodan count QUERY | Result count | 0 |
| shodan search QUERY | Basic search | 0* |
| shodan download FILE QUERY | Save results | 1/100 results |
| shodan parse FILE | Extract data | 0 |
| shodan stats QUERY | Statistics | 1 |
| shodan scan submit IP | On-demand scan | 1/IP |
| shodan honeyscore IP | Honeypot check | 0 |
*Filters consume 1 credit per query
| Purpose | Query |
|---------|-------|
| Find webcams | webcam has_screenshot:true |
| MongoDB databases | product:mongodb |
| Redis servers | product:redis |
| Elasticsearch | product:elastic port:9200 |
| Default passwords | "default password" |
| Vulnerable RDP | port:3389 vuln:CVE-2019-0708 |
| Industrial systems | port:502 modbus |
| Cisco devices | product:cisco |
| Open VNC | port:5900 authentication disabled |
| Exposed FTP | port:21 anonymous |
| WordPress sites | http.component:wordpress |
| Printers | "HP-ChaiSOE" port:80 |
| Cameras (RTSP) | port:554 has_screenshot:true |
| Jenkins servers | X-Jenkins port:8080 |
| Docker APIs | port:2375 product:docker |
| Scenario | Query |
|---------|-------|
| Target org recon | org:"Company Name" |
| Domain enumeration | hostname:example.com |
| Network range scan | net:192.168.0.0/24 |
| SSL cert search | ssl.cert.subject.cn:*.target.com |
| Vulnerable servers | vuln:CVE-2021-44228 country:US |
| Exposed admin panels | http.title:"admin" port:443 |
| Database exposure | port:3306,5432,27017,6379 |
| Action | Credit Type | Cost | |--------|-------------|------| | Basic search | Query | 0 (no filters) | | Filtered search | Query | 1 | | Download 100 results | Query | 1 | | Generate report | Query | 1 | | Scan 1 IP | Scan | 1 | | Network monitoring | Monitored IPs | Depends on plan |
# Find all hosts belonging to target organization
shodan search 'org:"Target Company"'
# Get statistics on their infrastructure
shodan stats --facets port,product,country 'org:"Target Company"'
# Download detailed data
shodan download target_data.json.gz 'org:"Target Company"'
# Parse for specific info
shodan parse --fields ip_str,port,product target_data.json.gz
# Find hosts vulnerable to BlueKeep (RDP CVE)
shodan search 'vuln:CVE-2019-0708 country:US'
# Find exposed Elasticsearch with no auth
shodan search 'product:elastic port:9200 -authentication'
# Find Log4j vulnerable systems
shodan search 'vuln:CVE-2021-44228'
# Find exposed webcams
shodan search 'webcam has_screenshot:true country:US'
# Find industrial control systems
shodan search 'port:502 product:modbus'
# Find exposed printers
shodan search '"HP-ChaiSOE" port:80'
# Find smart home devices
shodan search 'product:nest'
# Find hosts with specific SSL cert
shodan search 'ssl.cert.subject.cn:*.example.com'
# Find expired certificates
shodan search 'ssl.cert.expired:true org:"Company"'
# Find self-signed certificates
shodan search 'ssl.cert.issuer.cn:self-signed'
#!/usr/bin/env python3
import shodan
import json
API_KEY = 'YOUR_API_KEY'
api = shodan.Shodan(API_KEY)
def recon_organization(org_name):
"""Perform reconnaissance on an organization"""
try:
# Search for organization
query = f'org:"{org_name}"'
results = api.search(query)
print(f"[*] Found {results['total']} hosts for {org_name}")
# Collect unique IPs and ports
hosts = {}
for result in results['matches']:
ip = result['ip_str']
port = result['port']
product = result.get('product', 'unknown')
if ip not in hosts:
hosts[ip] = []
hosts[ip].append({'port': port, 'product': product})
# Output findings
for ip, services in hosts.items():
print(f"\n[+] {ip}")
for svc in services:
print(f" - {svc['port']}/tcp ({svc['product']})")
return hosts
except shodan.APIError as e:
print(f"Error: {e}")
return None
if __name__ == '__main__':
recon_organization("Target Company")
# Scan a /24 network range
shodan search 'net:192.168.1.0/24'
# Get port distribution
shodan stats --facets port 'net:192.168.1.0/24'
# Find specific vulnerabilities in range
shodan search 'net:192.168.1.0/24 vuln:CVE-2021-44228'
# Export all data for range
shodan download network_scan.json.gz 'net:192.168.1.0/24'
| Issue | Cause | Solution |
|-------|-------|----------|
| No API Key Configured | Key not initialized | Run shodan init YOUR_API_KEY then verify with shodan info |
| Query Credits Exhausted | Monthly credits consumed | Use credit-free queries (no filters), wait for reset, or upgrade |
| Host Recently Crawled | Cannot re-scan IP within 24h | Use shodan host IP for existing data, or wait 24 hours |
| Rate Limit Exceeded | >1 request/second | Add time.sleep(1) between API requests |
| Empty Search Results | Too specific or syntax error | Use quotes for phrases: 'org:"Company Name"'; broaden criteria |
| Downloaded File Won't Parse | Corrupted or wrong format | Verify with gunzip -t file.gz, re-download with --limit |
The instruction package is free to download. Your AI app, model usage, connected services and third-party assets may have separate costs.
It is a set of instructions for a compatible AI assistant. It does not run by itself, connect accounts or install an MCP server.
Check that the named folder contains SKILL.md directly, not a second nested ZIP folder. Confirm that your editor supports skills and that its current settings allow this location. See the official documentation below.