Enriching Data with Shodan

Shodan provides information on devices with internet connectivity—such as device manufacturer and type—and evaluates services based on its comprehensive search engine.

When activated, the Shodan enrichment enables you to leverage Shodan data on details pages of IP address observables in ThreatStream.

ThreatStream consumes and displays the following information from Shodan:

  • HoneyScore—score between zero and one quantifying the likelihood that the observable is a honeypot.
  • Ports—ports used by the IP address.
  • Vulnerabilities—Vulnerabilities (if any) associated with the IP address.
  • Services—information on services hosted by the IP address such as ports, protocols, modules, products, and service content.
  • Geo Information— information about the IP address such as country, organization, ISP, last update, hostnames, and ASNs.

A View on Shodan link is also available, enabling you to view raw enrichment data from the Shodan user interface.

Prerequisites for the Shodan Enrichment Activation

Before activating the Shodan enrichment, ensure you have the following:

  • An active Shodan Enterprise license

  • An API Key from Shodan

If you do not have a Shodan account, use these steps to register and obtain your API key:

  1. Visit the Shodan registration page, enter the required information, and click Register. After completing this step, Shodan sends you an activation email.
  2. Locate the AbuseIPDB activation email in your inbox and click the enclosed link to activate your account. You are redirected to the Shodan login page.
  3. After logging in to Shodan, the Account Overview page is displayed. Your API key is listed at the top of the page.

To activate the Shodan enrichment:

  1. Navigate to ThreatStream > APP STORE > APP Store.
  2. Click Get Access on the Shodan tile.
  3. Click I have credentials on the wizard page that opens.
  4. On the next wizard page, click Credentials and then enter your Shodan API Key.
  5. Click Activate.

The Shodan enrichment is now active.

Notes:
  • To learn more about the Shodan public API, visit https://developer.shodan.io/api

  • The Shodan public API limits requests from individual users to 100 query credits per month.