shodan Web
Search engine for internet-connected devices
How to use it
Search by IP, port, product or org (e.g., org:"Target" port:3389). Create a free account; filters like country:, ssl:, http.title: narrow results to exposed services.
Map the internet's infrastructure: find every subdomain, exposed service, certificate, IP and technology stack belonging to a target domain or organization.
Search engine for internet-connected devices
Search by IP, port, product or org (e.g., org:"Target" port:3389). Create a free account; filters like country:, ssl:, http.title: narrow results to exposed services.
Internet asset & certificate search
Query hosts and TLS certificates (e.g., parsed.names: example.com) to enumerate subdomains and services.
IP & domain risk search
Look up IPs and domains for open ports, vulnerabilities and abuse history.
Attack-surface data platform
Search their internet-scan data for exposed services, or use the API for continuous monitoring.
Internet asset search
Query by domain, IP, certificate field or response content; generous free tier.
Cyber-defense search engine
Search internet-scan, threat and passive-DNS data by IP or domain.
Exposed-service & leak search
Find services leaking data (open databases, git repos) by domain or keyword.
Internet noise intelligence
Check whether an IP is a known scanner or benign service before treating alerts as attacks.
URL sandbox scanner
Submit a URL to screenshot it, record all requests, and see contacted IPs/domains — safely inspect phishing links.
Multi-engine malware scanner
Upload a file or paste a URL/hash to get verdicts from 70+ antivirus engines plus behavior reports. Don't upload confidential files — uploads are shared.
DNS & domain intelligence
Enter a domain for full DNS history, subdomains and neighboring IPs.
Tech-stack profiler
Enter any site to see the technologies, analytics and frameworks it runs.
Technology detection
Use the browser extension or lookup to identify a site's CMS, frameworks and servers.
Free DNS recon
Enter a domain for a map of subdomains and DNS records from passive sources.
Certificate Transparency search
Search %.example.com to list every certificate ever issued — the classic free subdomain enumerator.
BGP & network intelligence
Look up any IP or ASN to see prefixes, peers and ownership — map an organization's entire netblock.
Hurricane Electric BGP toolkit
Check ASN announcements, peers and IPv4/IPv6 prefixes.
WHOIS lookup
Enter a domain to see registrar, dates and (unredacted where legal) registrant info.
Swiss-army DNS tools
Reverse IP, WHOIS history, DNS record lookups and more from one page.
Global DNS propagation checker
Check a record from dozens of worldwide resolvers to verify propagation.
Network utility suite
WHOIS, traceroute, email dossier and domain dossier tools.
Email/DNS health checker
Diagnose MX, SPF, DKIM, blacklist status for a domain — standard for email deliverability and spoofing checks.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Open-source code repository
Open the repo page, read the README for install instructions (usually a git clone or pip install command), then run it in a terminal. Check the 'Issues' and 'Releases' tabs for updates.
Most entries here are GitHub projects — clone the repository and follow the README's install steps (pip, npm, go or cargo). A Kali Linux VM gives you many of them pre-installed.
Public-record lookups and defensive/research use are generally lawful, but rules vary by country and tool. Only test systems you own or have written authorization to test, respect each site's terms of service, and never use personal data unlawfully.
Start with the web-based tools at the top of the list — they need no setup. Read each card's “How to use it” panel, run one real query, and only then move to installable tools.