This document explains how to set up the Shodan premium intelligence source in the TruSTAR platform.
Shodan is a "freemium" search engine that helps you find specific types of computers connected to the internet. TruSTAR’s integration with Shodan queries for IP addresses and URLs found in the submission enclave and reports findings to the Shodan enclave.
- Source Type: Premium Intel
- Update Type: Query-based
- Update Frequency: 15 minutes
- Parser: Yes
- Time to install: 10 minutes
- IP Address
- URL (via DNS lookup)
- A Freemium or paid subscription to Shodan
- Shodan API Key
- Login into the TruSTAR Web App.
- Click the Marketplace icon on the Navigation Bar.
- Choose Premium Intel.
- Click Subscribe to Shodan
- In the Source Subscription dialog box, enter your Shodan API Key and the TruSTAR Enclave ID (not the Enclave Name) where you will submit Reports or Indicators.
Example of Enclave ID: 0092174d-25c0-4d9e-ae7e-7d5031643df0
- Click Save Credentials & Request Subscription.
TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.
TruSTAR Report Mapping
The information retrieved from this intelligence source is stored in the Shodan Enclave using this format.
Shodan: Indicator-Type + Indicator -Value
Shodan UUID taken from indicator
Geo Location: City, Country Code, Location, Longitude, Latitude
Services: Port: Transport
The Shodan Source can only provide data for IP addresses and URLs found by its search engine. There are no corresponding reports when Shodan does not have any information on the observables that were searched.