Cyber Search Engines
Cyber search engines are specialized tools that continuously scan and index internet-connected devices, services, and assets. Unlike traditional search engines that index web content, these platforms focus on technical infrastructure, vulnerabilities, and security-related metadata. They are essential tools for security professionals conducting reconnaissance, threat hunting, asset discovery, and vulnerability management.
Shodan
Shodan is often called the "Search Engine for the Internet of Everything" or "Hacker's Search Engine". Unlike traditional search engines, Shodan continuously scans the entire internet for connected devices and services, cataloging their open ports, running services, and associated metadata. It supports advanced search operators (similar to Google dorks) that enable precise queries for specific technologies, vulnerabilities, or configurations. Shodan's flexible API allows integration with security tools and automated workflows.
Key Resources:
Shodan CLI Documentation - Command-line interface for Shodan queries and automation
Shodan Search Filters - Complete list of available search filters and operators
Shodan training has been moved to the Training section.
Shodan Dorking (Search Query Collections)
Shodan "dorks" are specialized search queries designed to find specific types of devices, vulnerabilities, or configurations. These collections provide ready-to-use queries for security research and reconnaissance.
Awesome Shodan Queries - Curated collection of useful Shodan search queries
Bug Bounty Shodan Dorks - Queries focused on bug bounty reconnaissance
Pentesting Bible - Shodan Queries - Comprehensive pentesting query collection
Shodan-Dorks by humblelad - General purpose Shodan dork repository
ICS/IoT Shodan Dorks - Specialized queries for Industrial Control Systems and IoT devices
Shodan Dorks by lothos612 - Additional query collection
IFLinfosec Shodan Dorks - InfoSec-focused search queries
Ultimate OSINT with Shodan - 100 practical Shodan queries for OSINT
Additional Cyber Search Tools
Asset search engines are powerful platforms that continuously scan the internet, cataloging every detectable entity and their characteristics. Using distributed networks of sensors and scanners, these tools collect comprehensive data including domain registration information, open ports, running services, SSL certificates, vulnerabilities, and network traffic patterns. This data is invaluable for attack surface management, threat intelligence, and security research.
Internet Asset Search Engines
FullHunt - Attack surface database covering the entire internet with focus on exposures, misconfigurations, and vulnerabilities.
Maltiverse - Specialized search engine for threat-based indicators (IPs, domains, hashes, URLs). Provides multiple threat intelligence feeds that can be integrated into security platforms for real-time alerting.
Onyphe - Cyber defense search engine aggregating open-source and threat intelligence data from multiple sources including internet background noise, active scanning of connected devices, and web crawling. Excels at correlating diverse data sources for comprehensive analysis.
Onyphe Dorkpedia - Search query documentation and examples
IntelligenceX - Advanced search engine supporting specialized selectors including email addresses, domains, URLs, IPs, CIDRs, Bitcoin addresses, and IPFS hashes. Searches across darknet sources, document sharing platforms, WHOIS data, and public data breaches. Maintains historical archives similar to the Wayback Machine for tracking changes over time.
Synapsint - Unified OSINT research platform that aggregates data from multiple sources, allowing comprehensive searches across various indicators and data types.
Natlas - Self-hostable network scanning platform designed for scaling and managing large-scale reconnaissance operations.
Netlas.io - Internet asset discovery and monitoring platform for tracking online infrastructure and detecting changes in attack surface.
Pulsedive - Threat intelligence platform that balances raw technical data with enriched context and community-driven insights. Excellent for both manual analysis and automated lookups.
ThreatMiner - Threat intelligence portal aggregating data from multiple sources into a single analyst interface. Featured in the SANS FOR578 Cyber Threat Intelligence course as a training tool.
OPSWAT MetaDefender - Multi-engine malware scanning and threat intelligence platform providing contextual analysis of indicators, vulnerabilities, and files.
ShadowServer - Free threat intelligence service aggregating data from honeypots, malware collection systems, and internet-wide scanning infrastructure. Valuable for tracking botnet activity and vulnerable systems.
Trend Micro Threat Encyclopedia - Comprehensive intelligence repository covering malware families, vulnerabilities (CVEs), and threat actor profiles.
ThreatView.io - Curated directory of threat intelligence feeds and resources organized by use case and data type.
BinaryEdge - Internet scanning platform specializing in discovering exposed services, databases, webcams, and Industrial Control Systems (ICS). Strong capabilities for identifying indicators of compromise.
Censys - Internet-wide asset discovery platform focused on certificate transparency, scanning data, and continuous monitoring. Excellent for attack surface management and alerting on infrastructure changes.
LeakIX - Search engine focused on finding publicly exposed databases, API keys, configuration files, and misconfigurations. Provides real-time scanning data and leak detection across the internet.
Favicon Analysis Tools
Favicon hashes can be used as unique fingerprints to identify web applications and infrastructure across the internet. These tools leverage favicon analysis for reconnaissance and asset discovery.
FavFreak - Tool for weaponizing favicon.ico files in bug bounty reconnaissance and OSINT investigations. Generates favicon hashes for searching across platforms like Shodan.
Weaponizing favicon.ico Article - Detailed guide on favicon-based reconnaissance techniques
fav-up - Performs IP address lookups using favicon hashes via Shodan. Particularly useful for discovering real IP addresses of servers hidden behind CDNs like Cloudflare.
Cloud Hunting Article - Methodology for finding servers behind cloud protection
## Additional Specialized Search Engines
Alternative Internet Scanning Platforms
These platforms offer similar capabilities to Shodan but with unique features, data sources, or regional coverage:
ZoomEye - Chinese cyberspace mapping platform that scans and indexes internet-connected devices. Offers both web-based search and API access with strong coverage of Asian networks.
Fofa - Chinese cyber asset search engine with extensive device fingerprinting capabilities and advanced search syntax. Popular for discovering exposed services and devices globally.
Criminal IP - Comprehensive cyber threat intelligence search engine providing real-time vulnerability detection, malicious IP tracking, and exposed asset discovery. Features user-friendly interface and detailed risk scoring.
Wigle - Wireless network mapping database. The world's largest database of wireless networks and cell towers, collected through wardriving and crowdsourcing.
Search Techniques and Dorking
Google Dorking - The original advanced search technique using specialized operators to find specific information indexed by Google. While not specific to cybersecurity, it remains a fundamental OSINT skill for discovering exposed files, directories, vulnerable systems, and sensitive information. See the search engines section for detailed Google dork resources.
Shodan Dorking - Similar concept applied to Shodan's search syntax (see Shodan section above).
Deprecated and Discontinued Services
These tools are no longer actively maintained or have shut down their services. They are listed here for historical reference:
Spyse (spyse.com) - Internet asset search engine acquired by SOCRadar in 2023. The original Spyse.com service was shut down and integrated into SOCRadar's commercial platform. Free public search capabilities are no longer available. Consider alternatives like FullHunt, Censys, or Netlas.io.
Riddler.io - Historical internet scanning data and DNS records search engine. Service shut down in 2022. Consider alternatives like Censys or SecurityTrails for historical DNS data.
BestIcon (besticon.herokuapp.com) - Web service for extracting favicon files. The Heroku-hosted public instance became unreliable after Heroku ended free tier hosting in 2022. The open-source project can still be self-hosted.
Guardicore Threat Intelligence - Free public threat intelligence portal. Discontinued after Akamai's acquisition of Guardicore in 2021. The platform was integrated into Akamai's commercial offerings.
Last updated