Shodan

Updated 2 weeks ago by TruSTAR

This document explains how to set up the Shodan premium intelligence source in the TruSTAR platform.

Shodan is a "freemium" search engine that helps you find specific types of computers connected to the internet. TruSTAR’s integration with Shodan queries for IP addresses and URLs found in the submission enclave and reports findings to the Shodan enclave.

  • Source Type: Premium Intel
  • Update Type: Query-based
  • Update Frequency: 15 minutes
  • Parser: Yes
  • Time to install: 10 minutes

Observables Supported

  • IP Address
  • URL (via DNS lookup)

Requirements

  • A Freemium or paid subscription to Shodan
  • Shodan API Key
TruSTAR Admin rights are required to activate this Premium Intelligence feed.

Getting Started

  1. Login into the TruSTAR Web App.
  2. Click the Marketplace icon on the Navigation Bar.
  3. Choose Premium Intel.
  4. Click Subscribe to Shodan
  5. In the Source Subscription dialog box, enter your Shodan API Key and the TruSTAR Enclave ID (not the Enclave Name) where you will submit Reports or Indicators.
    Example of Enclave ID: 0092174d-25c0-4d9e-ae7e-7d5031643df0
  6. Click Save Credentials & Request Subscription.

TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.

TruSTAR Report Mapping

The information retrieved from this intelligence source is stored in the Shodan Enclave using this format.

Field

Explanation

Report Title

Shodan: Indicator-Type + Indicator -Value

External ID

Shodan UUID taken from indicator

Report Body

 ASN: <Value>

Geo Location: City, Country Code, Location, Longitude, Latitude

Host Names:

Value Strings:

ISP:

ORG:

Port:

Services: Port: Transport

Tags

 

Deeplink

None

Client Type

Python SDK

Client MetaTag

TruSTASH

Known Issues

The Shodan Source can only provide data for IP addresses and URLs found by its search engine. There are no corresponding reports when Shodan does not have any information on the observables that were searched.

Please contact support@trustar.co if you have issues with this integration.


How Did We Do?