find-exposed-servers
Find internet-exposed hosts, ports, services and devices using third-party internet-scan data instead of touching the target. Covers Shodan and Censys query syntax, service banners, favicon-hash and TLS-certificate pivots, origin-IP discovery behind Cloudflare or a CDN, and exposed databases, dashboards, cameras and ICS devices. Use when asked what a company has exposed to the internet, to check open ports on an IP…
- installs 8w
- 1,870
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
An agent skill (SKILL.md) that teaches querying third-party internet-scan data — Shodan and Censys — to find exposed hosts, ports, services and devices without touching the target. It bundles a query cookbook, banner-interpretation reference, and ETHICS.md, covering pivots like favicon hashes, TLS certificates, and origin-IP discovery behind CDNs.
Reach for it when you need passive reconnaissance of a company's internet exposure, since querying scan platforms sends no packets to the target and leaves no logs there.
Use it to
- Map what a company exposes to the internet
- Check open ports on an IP or netblock
- Write a Shodan or Censys filter query
- Find origin IPs hidden behind Cloudflare or a CDN
- Review third-party or vendor exposure before engagement
For Security teams, OSINT researchers, and pentesters doing passive reconnaissance
- Host repository
- UseOSINT/Skills
- Installs, lifetime
- 1,900
- Installs, 8 weeks
- 1,870
- Host stars
- 37
- Host language
- Shell