Find Exposed Servers

Find internet-exposed hosts, ports, services and devices using third-party internet-scan data instead of touching the target. Covers Shodan and Censys query syntax, service banners, favicon-hash and TLS-certificate pivots, origin-IP discovery behind Cloudflare or a CDN, and exposed databases, dashboards, cameras and ICS devices. Use when asked what a company has exposed to the internet, to check open ports on an IP or netblock, or to write a Shodan filter query. Applies to external attack-surface management, third-party and vendor security review, M&A technical diligence, and pre-engagement reconnaissance. Reference at useosint.com/skills/find-exposed-servers.

useosint ecfa3f4 3 files · 28.9 KB Updated

File contents

useosint/skills/tree/main/skills/find-exposed-servers commit ecfa3f4a2b

Frequently asked questions

npx skillmds add useosint/find-exposed-servers