GDE-061 |
Censys OSINT | |||||||
Internet-wide host and certificate search | ||||||||
September 2026 | ||||||||
01
What it is
Censys is an internet-wide search engine that continuously scans public IP space and indexes hosts, open ports, services and TLS certificates, letting an investigator search for exposed infrastructure by attribute, such as a specific software banner, certificate field or organisation name, rather than knowing an IP address in advance.
Censys continuously scans the public internet and indexes what it finds: open ports, running services, software versions, TLS certificate details and the organisations those certificates name. A free account gives a limited number of monthly searches through the web interface; paid tiers unlock higher query volumes and full API access.
Its certificate search is one of its most distinctive features: since a TLS certificate often names the organisation it was issued to, searching by certificate attributes such as organisation name or issuer can surface infrastructure belonging to a target that would be difficult to find by IP address alone.
| When to use this guide
|
02
How do you search with Censys?
Six steps from a first certificate search through to corroborating and documenting a finding.
The following resources are used across the steps below.
Censys Search: Free tier with limited monthly searches, paid tiers for API access and higher volume. The core search engine covered in this guide.
Shodan: Free tier available. A companion internet-scanning search engine for cross-verification (see this publication's separate Shodan guide).
| Before you begin Stop at the login. Censys's free tier allows a limited number of searches per month without payment, though creating a free account is required to search at all. Higher query volumes and API access require a paid account. Nothing in this workflow requires logging into a target's system. Legal considerations. Censys only indexes what its own scanners can observe from the public internet; it does not access anything behind a login or firewall. Running further, active checks against a host identified through Censys, such as a manual connection or vulnerability probe, requires the same authorisation any direct interaction with someone else's system would, regardless of how the host was found. |
Use a query such as services.tls.certificates.leaf_data.subject.organization: "Target Org" to find hosts presenting a certificate naming that organisation.
Query for a specific software banner or version to find hosts running it across the internet, useful when investigating exposure tied to a known vulnerable version.
Open the full host record for a match to see every open port and service Censys observed, since the field that matched the search is rarely the only relevant detail.
Censys results include a last-observed timestamp; a host's configuration can change between scans, so treat older results as historical rather than necessarily current.
Search the same IP or organisation through Shodan, since the two platforms scan on different schedules and can each surface hosts or services the other misses.
Save the precise query syntax used and the date searched, since Censys's index continues to update and a later search may return a different result set.
|
03
What are the pitfalls of using Censys?
A scan snapshot, a shared certificate or a coincidental banner match can each be misread as something they are not.
A scan snapshot mistaken for the host's current state: Censys results reflect the last time its scanners observed the host, which may not be recent. Verifying check: check the last-observed timestamp before treating a result as the host's present configuration.
A shared or wildcard certificate mistaken for exclusive infrastructure: some certificates cover multiple unrelated hosts, such as a shared hosting provider's wildcard certificate. Verifying check: confirm a certificate is genuinely specific to the target rather than shared infrastructure before attributing the host to them.
A software banner match mistaken for confirmed identity: many unrelated organisations run the same common software and version. Verifying check: corroborate a banner match with a second, more specific attribute, such as certificate organisation or hostname, before attributing a host to a particular target.
Chain of custody: a Censys result is a point-in-time observation of a system Censys, not you, actively scanned.
Record the exact search query used, including syntax.
Note the last-observed timestamp on any host record cited as a finding.
Screenshot the relevant host record, since the underlying index continues to update.
Log any cross-reference against Shodan or another source alongside the Censys finding.
04
Go deeper
The wider infrastructure-reconnaissance cluster Censys sits alongside.
GUIDE · GDE-008
Free OSINT tools and frameworks: 2026 toolkit guide
The wider free toolkit Censys sits alongside.
GUIDE · GDE-054
Osiris: deploying an open-source live intelligence dashboard
A live intelligence dashboard whose built-in RECON toolkit overlaps with Censys's scanning use case.
Evidentiary standard
Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.
About Signal & Shadow
Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.




