GDE-011 |
Exposed infrastructure discovery | |||||||
Digital infrastructure | ||||||||
July 2026 | ||||||||
01
What it is
Shodan OSINT is the use of Shodan's pre-built index of internet-connected devices and services to find exposed servers and infrastructure tied to a domain or IP range, by querying data Shodan has already collected rather than scanning the target directly.
Step 05 of the Email OSINT guide covers domain infrastructure analysis using MXToolbox and WHOIS lookups, cross-referenced against the DIG-001 WHOIS card. That step establishes the registrant, DNS records, and hosting provider for a domain. Shodan extends that step: once a domain's IP address or hosting range is known, Shodan reveals what services are actually running there, what ports are open, and whether any exposed software is outdated enough to carry a known vulnerability.
Shodan is a search engine, not a scanner an investigator runs live. It continuously crawls the internet on its own schedule and indexes what it finds; searching Shodan queries that existing index rather than sending any request to the target. That distinction matters for both the legal analysis and for understanding how current the results are.
|
When to use this guide
|
02
How to search Shodan for domain-linked infrastructure
A five-step workflow from anchoring on an IP range through cross-referencing exposed services against known vulnerabilities.
The following tools are used across the steps below. All are free unless noted.
Shodan: Search engine indexing service banners, open ports, and software versions across internet-connected devices worldwide. Free accounts return a limited number of results per query; a paid membership (roughly $49 lifetime) unlocks full search filters, higher result counts, and API access. Sign-up required for the free tier.
crt.sh: Free, no-registration certificate transparency log search. Useful for finding subdomains and hosts tied to a domain before pivoting into Shodan by IP or hostname. Already referenced in DIG-001; reused here for the pivot into Shodan.
|
Before you begin Stop at the login. Shodan searches return only data Shodan has already collected through its own scanning; running a search sends no request to the target infrastructure. Do not use a Shodan result as authorisation to connect to, log into, or test any exposed service it surfaces. Legal considerations. Searching Shodan's index is lawful in most jurisdictions, since the query is against Shodan's own database rather than the target. Connecting to, authenticating against, or testing any device found through Shodan without authorisation may violate computer misuse law in most jurisdictions. |
Use the domain's A record, from the WHOIS and DNS workflow covered in DIG-001, to identify the IP address or hosting range associated with the domain. Where the domain uses subdomains, run crt.sh first to surface additional hostnames worth checking. Note the autonomous system (AS) and hosting provider, since Shodan's org and net filters query on these values directly.
Search Shodan using the hostname filter or the IP address directly. Free-tier accounts return a limited number of results but still surface open ports, service banners, and detected software versions. Record every open port and the service and version identified, since an outdated software version is a specific, checkable claim rather than a vague exposure assessment.
Use Shodan's org and net filters with the hosting provider or IP range identified in step 01 to find other hosts on the same infrastructure. A cluster of unrelated-looking domains sharing hosting infrastructure, especially outside a well-known shared-hosting provider, is a pattern worth investigating rather than a finding to conclude from directly.
For any service running a specific, identifiable software version, check whether that version has known CVEs using a public vulnerability database. Paid Shodan plans surface some CVE matches directly; free-tier users can cross-reference the recorded version number manually. Document the version and the CVE reference rather than asserting a vulnerability exists without a specific citation.
Screenshot or export the Shodan search results with the query used and the date visible. Shodan's index reflects the last scan date for each host, which can be days or weeks old; note the scan date shown in the results alongside your own query date, since these are two different timestamps with different evidentiary meaning.
03
What to watch for when using Shodan for domain investigations
Data staleness, shared-hosting false positives, and legal boundaries specific to internet-wide scan data.
Scan staleness: Shodan's data reflects the last time its crawler scanned a given IP, which can be days, weeks, or in some cases months old; a service shown as exposed may have already been patched or taken offline. Verifying check: Note the scan date shown in the Shodan result alongside the query date, and treat findings older than a few weeks as requiring independent confirmation before publication.
Shared hosting false attribution: Many unrelated domains and services sit on the same shared hosting infrastructure or CDN, so appearing in the same org or net search as a target does not establish any relationship between them. Verifying check: Confirm a genuine infrastructure link, a shared registrant, an unusual shared configuration, or direct DNS pointing, before treating a shared-hosting result as a meaningful connection.
CVE presence without exploitation: A service running a version with a known CVE is a documented risk, not evidence the vulnerability has been exploited or that the service is currently compromised. Verifying check: Report only what the version and CVE reference show; do not characterise an exposed service as hacked or compromised without independent evidence of exploitation.
Chain of custody: Shodan's index changes as its crawler re-scans the internet, so a result visible today may not be reproducible next week.
Screenshot or export Shodan search results with the exact query, scan date, and access timestamp visible.
Record the AS number, organisation name, and IP range identified for the target infrastructure.
If a CVE is cited, record the CVE identifier and the source of the version data that produced the match.
Log every query run and its parameters in the case file, since Shodan filter syntax is precise and small variations change results.
04
Go deeper
Reference cards and the parent workflow this deep-dive extends.
Reference cards
DIG-001 WHOIS investigation: domain name to attribution chain
Related guides
GDE-005 Email OSINT: trace an address to accounts and infrastructure
Evidentiary standard
Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.
About Signal & Shadow
Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.

