Shodan
Shodan is an internet-connected device search engine that helps users discover and analyze devices across the globe.
Shodan is a search engine for Internet-connected devices, providing insights into the online presence of various assets. This connector allows users to interact with Shodan's extensive database to monitor network alerts, perform IP lookups, and initiate scans. By integrating Shodan with Swimlane Turbine, users can automate the detection and analysis of network vulnerabilities, enhancing their security posture with real-time intelligence and streamlined workflows.
This Connector integrates Shodan with Swimlane Turbine.
Prerequisites
Before you can use the Shodan connector for Turbine, you'll need access to the Shodan API. This requires the following:
- An API key authentication using the following parameter:
- API Key: A unique key provided by Shodan to authenticate API requests.
Capabilities
This Connector provides the following capabilities:
- Get Network Alert by ID
- Get Network Alerts
- Get Scan Request Status
- Lookup IP Address
- Network Alert Create
- Network Alert Delete by ID
- Network Alert Disable Trigger
- Network Alert Enable Trigger
- Network Alert Remove Service from Whitelist
- Network Alert Whitelist Service
- Scan Internet
- Scan IP
- Search
- Search Count
- Search Facets
Notes
API Documentation : https://developer.shodan.io/api
Configurations
API Key Authentication
Shodan API turbine connector
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Optional |
key | API Key for authentication. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Get Network Alert by ID
Retrieve information about a specific network alert in Shodan using the alert ID as a path parameter.
Endpoint
- URL: shodan/alert/{{id}}/info
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Network Alert by ID action |
Input Example
{"path_parameters":{"id":"6VORHMNXOMBEAQAY"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
name | string | Name of the resource |
created | string | Output field: created |
triggers | object | Output field: triggers |
has_triggers | boolean | Output field: has_triggers |
expires | number | Output field: expires |
expiration | object | Output field: expiration |
filters | object | Output field: filters |
filters.ip | array | Output field: filters.ip |
notifiers | array | Output field: notifiers |
notifiers.file_name | string | Name of the resource |
notifiers.file | string | Output field: notifiers.file |
id | string | Unique identifier |
size | number | Output field: size |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 10:09:42 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"6","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","CF-Cache-Status":"DYNAMIC","permissions-policy":"interest-...
Get Network Alerts
Returns a listing of all the network alerts that are currently active on the Shodan account.
Endpoint
- URL: shodan/alert/info
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 10:14:13 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"5","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","CF-Cache-Status":"DYNAMIC","permissions-policy":"interest-...
Get Scan Request Status
Check the progress of a previously submitted scan request in Shodan using the scan ID as a path parameter.
Endpoint
- URL: shodan/scan/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Scan Request Status action |
Input Example
{"path_parameters":{"id":"Mo8W7itcWumiy9Ay"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
count | number | Count value |
status | string | Status value |
id | string | Unique identifier |
created | string | Output field: created |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 07:42:33 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"3","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","Last-Modified":"Sat, 29 Jul 2023 07:42:33 GMT","CF-Cache-S...
Lookup IP Address
Returns all services found on the specified host IP in Shodan. Requires the IP address as a path parameter.
Endpoint
- URL: shodan/host/{{ip}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip | string | Required | Parameters for the Lookup IP Address action |
parameters.history | boolean | Optional | Parameters for the Lookup IP Address action |
parameters.minify | boolean | Optional | Parameters for the Lookup IP Address action |
Input Example
{"parameters":{"history":false,"minify":false},"path_parameters":{"ip":"8.8.8.8"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
city | string | Output field: city |
region_code | string | Output field: region_code |
os | object | Output field: os |
tags | array | Output field: tags |
tags.file_name | string | Name of the resource |
tags.file | string | Output field: tags.file |
ip | number | Output field: ip |
isp | string | Output field: isp |
area_code | object | Output field: area_code |
longitude | number | Output field: longitude |
last_update | string | Date value |
ports | array | Output field: ports |
latitude | number | Output field: latitude |
hostnames | array | Name of the resource |
country_code | string | Output field: country_code |
country_name | string | Name of the resource |
domains | array | Output field: domains |
org | string | Output field: org |
data | array | Response data |
data.hash | number | Response data |
data.opts | object | Response data |
data.opts.vulns | array | Response data |
data.opts.vulns.file_name | string | Response data |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 07:42:33 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"3","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","Last-Modified":"Sat, 29 Jul 2023 07:42:33 GMT","CF-Cache-S...
Network Alert Create
Create an alert in Shodan to monitor a specified network range using filters and name as inputs.
Endpoint
- URL: shodan/alert
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
name | string | Optional | Name of the resource |
filters | object | Optional | Parameter for Network Alert Create |
filters.ip | array | Required | Parameter for Network Alert Create |
expires | number | Optional | Parameter for Network Alert Create |
Input Example
{"json_body":{"name":"DNS Alert","filters":{"ip":["8.8.8.8","1.1.1.1"]},"expires":0}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
name | string | Name of the resource |
created | string | Output field: created |
triggers | object | Output field: triggers |
has_triggers | boolean | Output field: has_triggers |
expires | number | Output field: expires |
expiration | object | Output field: expiration |
filters | object | Output field: filters |
filters.ip | array | Output field: filters.ip |
id | string | Unique identifier |
size | number | Output field: size |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 10:05:08 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"5","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","CF-Cache-Status":"DYNAMIC","permissions-policy":"interest-...
Network Alert Delete by ID
Remove a specified network alert in Shodan using the alert ID as a path parameter.
Endpoint
- URL: shodan/alert/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Network Alert Delete by ID action |
Input Example
{"path_parameters":{"id":"6VORHMNXOMBEAQAY"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 10:24:10 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"6","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","CF-Cache-Status":"DYNAMIC","permissions-policy":"interest-...
Network Alert Disable Trigger
Stop receiving notifications for a specified trigger in Shodan by providing the trigger ID and type as path parameters.
Endpoint
- URL: shodan/alert/{{id}}/trigger/{{trigger}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Network Alert Disable Trigger action |
path_parameters.trigger | string | Required | Parameters for the Network Alert Disable Trigger action |
Input Example
{"path_parameters":{"id":"OYPRB8IR9Z35AZPR","trigger":"new_service,vulnerable"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 10:24:10 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"6","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","CF-Cache-Status":"DYNAMIC","permissions-policy":"interest-...
Network Alert Enable Trigger
Get notifications from Shodan when a specified network alert trigger is met. Requires path parameters: ID and trigger.
Endpoint
- URL: shodan/alert/{{id}}/trigger/{{trigger}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Network Alert Enable Trigger action |
path_parameters.trigger | string | Required | Parameters for the Network Alert Enable Trigger action |
Input Example
{"path_parameters":{"id":"OYPRB8IR9Z35AZPR","trigger":"new_service,vulnerable"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 10:24:10 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"6","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","CF-Cache-Status":"DYNAMIC","permissions-policy":"interest-...
Network Alert Remove Service from Whitelist
Start receiving notifications again for a specified trigger in Shodan by removing the service from the whitelist. Requires path parameters: id, trigger, and service.
Endpoint
- URL: shodan/alert/{{id}}/trigger/{{trigger}}/ignore/{{service}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Network Alert Remove Service from Whitelist action |
path_parameters.trigger | string | Required | Parameters for the Network Alert Remove Service from Whitelist action |
path_parameters.service | string | Required | Parameters for the Network Alert Remove Service from Whitelist action |
Input Example
{"path_parameters":{"id":"OYPRB8IR9Z35AZPR","trigger":"new_service","service":"1.1.1.1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 10:24:10 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"6","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","CF-Cache-Status":"DYNAMIC","permissions-policy":"interest-...
Network Alert Whitelist Service
Ignore the specified service in Shodan when it matches the trigger. Requires path parameters: id, trigger, and service.
Endpoint
- URL: shodan/alert/{{id}}/trigger/{{trigger}}/ignore/{{service}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Network Alert Whitelist Service action |
path_parameters.trigger | string | Required | Parameters for the Network Alert Whitelist Service action |
path_parameters.service | string | Required | Parameters for the Network Alert Whitelist Service action |
Input Example
{"path_parameters":{"id":"OYPRB8IR9Z35AZPR","trigger":"new_service","service":"1.1.1.1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
success | boolean | Whether the operation was successful |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 10:24:10 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"6","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","CF-Cache-Status":"DYNAMIC","permissions-policy":"interest-...
Scan Internet
Request Shodan to crawl the Internet for a specific port using the provided data body.
Endpoint
- URL: shodan/scan/internet
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
headers | object | Optional | HTTP headers for the request |
headers.Content-Type | string | Required | HTTP headers for the request |
data_body | object | Required | Response data |
data_body.port | number | Required | Response data |
data_body.protocol | string | Required | Response data |
Input Example
{"headers":{"Content-Type":"application/x-www-form-urlencoded"},"data_body":{"port":443,"protocol":"https"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 07:59:01 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"6","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","CF-Cache-Status":"DYNAMIC","permissions-policy":"interest-...
Scan IP
Request Shodan to crawl a specified network by providing the IPs in the JSON body.
Endpoint
- URL: shodan/scan
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
ips | object | Optional | Parameter for Scan IP |
Input Example
{"json_body":{"ips":{}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
count | number | Count value |
id | string | Unique identifier |
credits_left | number | Output field: credits_left |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 07:59:01 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"6","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","CF-Cache-Status":"DYNAMIC","permissions-policy":"interest-...
Search
Search Shodan using query syntax and retrieve summary information for various properties. Requires a query parameter.
Endpoint
- URL: shodan/host/search
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.query | string | Required | Parameters for the Search action |
parameters.facets | string | Optional | Parameters for the Search action |
parameters.page | number | Optional | Parameters for the Search action |
parameters.minify | boolean | Optional | Parameters for the Search action |
Input Example
{"parameters":{"query":"product:nginx","facets":"country","page":10,"minify":false}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | string | HTTP status code of the response |
reason | string | Response reason phrase |
matches | string | Output field: matches |
facets | string | Output field: facets |
total | string | Output field: total |
Output Example
{"matches":"string","facets":"string","total":"string"}
Search Count
Return the number of results that match the specified query in Shodan. This action requires a query parameter.
Endpoint
- URL: shodan/host/count
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.query | string | Required | Parameters for the Search Count action |
parameters.facets | string | Optional | Parameters for the Search Count action |
Input Example
{"parameters":{"query":"port:22","facets":"org,os"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
matches | array | Output field: matches |
matches.file_name | string | Name of the resource |
matches.file | string | Output field: matches.file |
facets | object | Output field: facets |
facets.org | array | Output field: facets.org |
facets.org.count | number | Count value |
facets.org.value | string | Value for the parameter |
facets.os | array | Output field: facets.os |
facets.os.count | number | Count value |
facets.os.value | string | Value for the parameter |
total | number | Output field: total |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 07:44:37 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"6","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","Last-Modified":"Sat, 29 Jul 2023 07:44:37 GMT","CF-Cache-S...
Search Facets
Returns a list of facets to obtain a breakdown of top values for a property in Shodan.
Endpoint
- URL: shodan/host/search/facets
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Date":"Sat, 29 Jul 2023 07:46:33 GMT","Content-Type":"application/json; charset=UTF-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Vary":"Accept-Encoding","Access-Control-Allow-Origin":"*","X-CID":"6","X-Frame-Options":"DENY","X-Content-Type-Options":"nosniff","X-XSS-Protection":"1; mode=block","Strict-Transport-Security":"max-age=63072000; includeSubDomains","Content-Encoding":"gzip","Last-Modified":"Fri, 28 Jul 2023 19:08:20 GMT","CF-Cache-S...
Response Headers
Header | Description | Example |
|---|---|---|
Access-Control-Allow-Origin | HTTP response header: Access-Control-Allow-Origin | * |
alt-svc | HTTP response header: alt-svc | h3=":443"; ma=86400 |
Cache-Control | Directives for caching mechanisms | public, max-age=28800 |
CF-Cache-Status | HTTP response header: CF-Cache-Status | DYNAMIC |
CF-RAY | HTTP response header: CF-RAY | 7ee48aaded182e11-BOM |
Connection | HTTP response header: Connection | keep-alive |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
Content-Type | The media type of the resource | application/json; charset=UTF-8 |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |
Expires | The date/time after which the response is considered stale | Sat, 29 Jul 2023 15:42:33 GMT |
Last-Modified | The date and time at which the origin server believes the resource was last modified | Sat, 29 Jul 2023 07:44:37 GMT |
permissions-policy | HTTP response header: permissions-policy | interest-cohort=() |
Server | Information about the software used by the origin server | cloudflare |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=63072000; includeSubDomains |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Vary | HTTP response header: Vary | Accept-Encoding |
X-CID | HTTP response header: X-CID | 6 |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
X-Frame-Options | HTTP response header: X-Frame-Options | DENY |
X-XSS-Protection | HTTP response header: X-XSS-Protection | 1; mode=block |