BigHugger
sk Skill · UseOSINT

find-exposed-servers

Find internet-exposed hosts, ports, services and devices using third-party internet-scan data instead of touching the target. Covers Shodan and Censys query syntax, service banners, favicon-hash and TLS-certificate pivots, origin-IP discovery behind Cloudflare or a CDN, and exposed databases, dashboards, cameras and ICS devices. Use when asked what a company has exposed to the internet, to check open ports on an IP…

installs 8w
1,870
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashShell

An agent skill (SKILL.md) that teaches querying third-party internet-scan data — Shodan and Censys — to find exposed hosts, ports, services and devices without touching the target. It bundles a query cookbook, banner-interpretation reference, and ETHICS.md, covering pivots like favicon hashes, TLS certificates, and origin-IP discovery behind CDNs.

Reach for it when you need passive reconnaissance of a company's internet exposure, since querying scan platforms sends no packets to the target and leaves no logs there.

Use it to

  • Map what a company exposes to the internet
  • Check open ports on an IP or netblock
  • Write a Shodan or Censys filter query
  • Find origin IPs hidden behind Cloudflare or a CDN
  • Review third-party or vendor exposure before engagement

For Security teams, OSINT researchers, and pentesters doing passive reconnaissance

Host repository
UseOSINT/Skills
Installs, lifetime
1,900
Installs, 8 weeks
1,870
Host stars
37
Host language
Shell
topicsosintshodancensysattack-surfacereconnaissanceagent-skill