[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQA9oJMcW6a0pITQm7v2ESm-TP-3-kjtNddaDralX3-o":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},913,"How can I search for devices using the Shodan command-line interface?","First initialize your API key with `shodan init YOUR_API_KEY`. Then use `shodan search --fields ip_str,port,org,hostnames \u003Cquery>` to search and display specific fields. For example, `shodan search --fields ip_str,port,org,hostnames apache` returns IP, port, organization, and hostnames for Apache servers. You can also count results with `shodan count \u003Cquery>` or download them with `shodan download \u003Cfilename> \u003Cquery>`, then parse the downloaded file using `shodan parse`.","\u003Cp>First initialize your API key with `shodan init YOUR_API_KEY`. Then use `shodan search --fields ip_str,port,org,hostnames &lt;query&gt;` to search and display specific fields. For example, `shodan search --fields ip_str,port,org,hostnames apache` returns IP, port, organization, and hostnames for Apache servers. You can also count results with `shodan count &lt;query&gt;` or download them with `shodan download &lt;filename&gt; &lt;query&gt;`, then parse the downloaded file using `shodan parse`.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fshodan-api-usage-guide\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-search-for-devices-using-the-shodan-command-line-interface-1777481313441","Shodan CLI, command-line interface, shodan search, shodan count, shodan download, shodan parse",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},222,"Shodan API Usage Guide","shodan-api-usage-guide","Learn to use Shodan API with Python for network device searches, understand credit types, and automate data extraction for cybersecurity analysis.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Shodan is a search engine for network devices. Using the Shodan API for searches not only provides richer data but also enables automated analysis by integrating with your own programs.\u003C\u002Fp>\u003Cp>This article will introduce considerations when using the Shodan API, share usage insights, and script development techniques.\u003C\u002Fp>\u003Ch2>0x01 This article will cover the following topics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Basic usage of the Shodan API\u003C\u002Fli>\u003Cli>Using Python to call the Shodan API to obtain search results\u003C\u002Fli>\u003Cli>Further processing of search results\u003C\u002Fli>\u003Cli>Differences between the three types of credits\u003C\u002Fli>\u003Cli>Exporting search results from the Shodan website and further processing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic usage of the Shodan API\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Register an account and obtain an API Key\u003C\u002Fh3>\u003Cp>Test API Key is: SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\u003C\u002Fp>\u003Ch3>2. Install Python package\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pip install shodan\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Obtain search results via Shodan CLI\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcli.shodan.io\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Only 100 search results are available without payment\u003C\u002Fp>\u003Cp>CLI stands for command-line interface, which is Shodan's command-line mode\u003C\u002Fp>\u003Cp>On Windows systems, using pip install generates the file Shodan.exe in the same directory\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017287204_0_d56de95fe7.jpeg\">\u003C\u002Fp>\u003Ch4>(1) Initialization\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan init \u003Capi key=\"\">\u003C\u002Fapi>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The actual command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan init SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017317898_1_bf5b42f364.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Search for the quantity of specified content (apache)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan count apache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017361790_2_b803958c87.jpeg\">\u003C\u002Fp>\u003Cp>Obtain result 23803090\u003C\u002Fp>\u003Ch4>(3) Search for information on specified content (apache)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan search --fields ip_str,port,org,hostnames apache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Search keyword: apache\u003C\u002Fp>\u003Cp>Output: ip_str,port,org,hostnames\u003C\u002Fp>\u003Ch4>(4) Download search results for specified content (apache)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan download result apache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Search keyword: apache\u003C\u002Fp>\u003Cp>Save file name: result.json.gz\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017390678_3_03e0073351.jpeg\">\u003C\u002Fp>\u003Ch4>(5) Parse the file to obtain search results\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan parse --fields ip_str,port,org --separator , result.json.gz\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017417011_4_f32559dd90.jpeg\">\u003C\u002Fp>\u003Ch4>(6) Search for information on a specified IP\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan host 189.201.128.250\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017461939_5_97b7a30e8e.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Differences between the three types of credits\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Shodan has three types of credits:\u003C\u002Fp>\u003Cul>\u003Cli>Export credits\u003C\u002Fli>\u003Cli>Query credits\u003C\u002Fli>\u003Cli>Scan credits\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fhelp.shodan.io\u002Fthe-basics\u002Fcredit-types-explained\u003C\u002Fp>\u003Cp>Simple explanation:\u003C\u002Fp>\u003Ch3>Export Credits\u003C\u002Fh3>\u003Cp>Used when downloading data from the Shodan official website\u003C\u002Fp>\u003Cp>1 export credit = 10,000 results\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Exporting results consumes one credit per export, regardless of the number of results obtained, up to a maximum of 10,000 results\u003C\u002Fp>\u003Cp>Does not renew at the beginning of the month\u003C\u002Fp>\u003Ch3>Query Credits\u003C\u002Fh3>\u003Cp>Used when calling the Shodan API\u003C\u002Fp>\u003Cp>1 query credit = 100 results\u003C\u002Fp>\u003Cp>Renews at the beginning of the month, meaning if you only purchase a one-month membership, it will reset to zero the following month\u003C\u002Fp>\u003Ch3>Scan Credits\u003C\u002Fh3>\u003Cp>Used when calling the Shodan API\u003C\u002Fp>\u003Cp>1 scan credit = 1 IP\u003C\u002Fp>\u003Cp>Updated at the beginning of the month\u003C\u002Fp>\u003Ch2>0x04 Obtaining search results by calling the Shodan API via Python\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Without payment, not only are search filters unavailable, but only 100 search results can be obtained\u003C\u002Fp>\u003Ch3>(1) Search for information on specified content (Apache)\u003C\u002Fh3>\u003Cp>Python code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import shodan\u003Cbr>SHODAN_API_KEY = \"SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\"\u003Cbr>api = shodan.Shodan(SHODAN_API_KEY)\u003Cbr>try:\u003Cbr>    results = api.search('Apache')\u003Cbr>    print 'Results found: %s' % results['total']\u003Cbr>    for result in results['matches']:         \u003Cbr>            print (\"%s:%s|%s|%s\"%(result['ip_str'],result['port'],result['location']['country_name'],result['hostnames']))\u003Cbr>except shodan.APIError, e:\u003Cbr>    print 'Error: %s' % e\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017477888_6_5fa2be2c8b.jpeg\">\u003C\u002Fp>\u003Cp>If not paid, search filters cannot be used, such as Apache country:\"US\"\u003C\u002Fp>\u003Ch3>(2) Search for specified content and write the obtained IPs to a file\u003C\u002Fh3>\u003Cp>Python code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import shodan\u003Cbr>SHODAN_API_KEY = \"SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\"\u003Cbr>api = shodan.Shodan(SHODAN_API_KEY)\u003Cbr>file_object = open('ip.txt', 'w')\u003Cbr>try:\u003Cbr>    results = api.search('Apache')\u003Cbr>    print 'Results found: %s' % results['total']\u003Cbr>    for result in results['matches']:         \u003Cbr>#            print result['ip_str']\u003Cbr>            file_object.writelines(result['ip_str']+'\\n')\u003Cbr>except shodan.APIError, e:\u003Cbr>    print 'Error: %s' % e\u003Cbr>file_object.close()  \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(3) Specify search criteria via command line arguments and write the found IPs to a file\u003C\u002Fh3>\u003Cp>Python code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import shodan\u003Cbr>import sys\u003Cbr>SHODAN_API_KEY = \"SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\"\u003Cbr>api = shodan.Shodan(SHODAN_API_KEY)\u003Cbr>if len(sys.argv)&lt;2:\u003Cbr>    print '[!]Wrong parameter'\u003Cbr>    sys.exit(0)\u003Cbr>print '[*]Search string: %s' % sys.argv[1]\u003Cbr>    \u003Cbr>file_object = open('ip.txt', 'w')\u003Cbr>try:\u003Cbr>    results = api.search(sys.argv[1])\u003Cbr>    print '[+]Results found: %s' % results['total']\u003Cbr>    for result in results['matches']:         \u003Cbr>#            print result['ip_str']\u003Cbr>            file_object.writelines(result['ip_str']+'\\n')\u003Cbr>except shodan.APIError, e:\u003Cbr>    print 'Error: %s' % e\u003Cbr>file_object.close() \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command line parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>search.py apache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If searching for multiple keywords, enclose the search criteria in quotes, for example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>search.py \"apache country:US\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(4) Read IP list from file and reverse lookup IP information\u003C\u002Fh3>\u003Cp>Python code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import shodan\u003Cbr>import sys\u003Cbr>reload(sys)\u003Cbr>sys.setdefaultencoding('utf8')\u003Cbr>SHODAN_API_KEY = \"SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\"\u003Cbr>api = shodan.Shodan(SHODAN_API_KEY)\u003Cbr>def searchip(str):\u003Cbr>    try:\u003Cbr>        host = api.host(str)\u003Cbr>    except shodan.exception.APIError:\u003Cbr>        print \"[!]No information available\"\u003Cbr>        print \"---------------------------------------------\"\u003Cbr>        return\u003Cbr>    else:\u003Cbr>        # Print general info\u003Cbr>        try:\u003Cbr>            print \"IP: %s\\r\\nOrganization: %s\\r\\nOperating System: %s\" % (host['ip_str'], host.get('org', 'n\u002Fa'), host.get('os', 'n\u002Fa'))\u003Cbr>        except UnicodeEncodeError:\u003Cbr>            print \"[!]UnicodeEncode Error\\r\\n\"\u003Cbr>        else:\u003Cbr>            # Print all banners\u003Cbr>            for item in host['data']:\u003Cbr>                print \"Port: %s\\r\\nBanner: %s\" % (item['port'], item['data'])\u003Cbr>        print \"---------------------------------------------\"\u003Cbr>        return\u003Cbr>file_object = open('ip.txt', 'r')\u003Cbr>for line in file_object:\u003Cbr>    searchip(line)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Download search results via Shodan official website\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Export credits are used when downloading data via the Shodan official website, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017487412_7_1e88436c83.jpeg\">\u003C\u002Fp>\u003Cp>Each query consumes one export credit, regardless of the number of results, with a maximum of 10,000\u003C\u002Fp>\u003Cp>Select json as the export format\u003C\u002Fp>\u003Ch3>(1) Extract IPs from the downloaded json result file\u003C\u002Fh3>\u003Cp>Python code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import json\u003Cbr>file_object = open(\"shodan_data.json\", 'r')\u003Cbr>for line in file_object:\u003Cbr>    data = json.loads(line)\u003Cbr>    print (data[\"ip_str\"])  \u003Cbr>file_object.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) Extract IP and port of specified country from downloaded json result file\u003C\u002Fh3>\u003Cp>Country code is in secondary element, corresponding structure: data[\"location\"][\"country_code\"]\u003C\u002Fp>\u003Cp>Python code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import json\u003Cbr>import sys\u003Cbr>import re\u003Cbr>def search(country):\u003Cbr>    file_object = open(\"shodan_data.json\", 'r')\u003Cbr>    file_object2 = open(country+\".txt\", 'w')\u003Cbr>    for line in file_object:\u003Cbr>        data = json.loads(line)  \u003Cbr>        if re.search(data[\"location\"][\"country_code\"], country, re.IGNORECASE):\u003Cbr>            str1 = \"%s:%s\" % (data[\"ip_str\"],data[\"port\"])\u003Cbr>            print str1\u003Cbr>            file_object2.writelines(str1+'\\n')\u003Cbr>    file_object.close()\u003Cbr>    file_object2.close()\u003Cbr>if __name__ == \"__main__\":\u003Cbr>    if len(sys.argv)&lt;2:\u003Cbr>    \tprint ('[!]Wrong parameter')\u003Cbr>        sys.exit(0)\u003Cbr>    else:\u003Cbr>        print ('[*]Search country code: %s' % sys.argv[1])\u003Cbr>        search(sys.argv[1])\u003Cbr>        print (\"[+]Done\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command line arguments:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>search.py US\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate file US.txt, save IP and corresponding ports\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the usage of the Shodan API, sharing insights and Python script development techniques. When opting for a paid purchase, remember to distinguish between the three types of credits (credits).\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Shodan is a search engine for network devices. Using the Shodan API for searches not only provides richer data but also enables automated analysis by integrating with your own programs.\u003C\u002Fp>\u003Cp>This article will introduce considerations when using the Shodan API, share usage insights, and script development techniques.\u003C\u002Fp>\u003Ch2>0x01 This article will cover the following topics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Basic usage of the Shodan API\u003C\u002Fli>\u003Cli>Using Python to call the Shodan API to obtain search results\u003C\u002Fli>\u003Cli>Further processing of search results\u003C\u002Fli>\u003Cli>Differences between the three types of credits\u003C\u002Fli>\u003Cli>Exporting search results from the Shodan website and further processing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic usage of the Shodan API\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Register an account and obtain an API Key\u003C\u002Fh3>\u003Cp>Test API Key is: SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\u003C\u002Fp>\u003Ch3>2. Install Python package\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pip install shodan\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Obtain search results via Shodan CLI\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcli.shodan.io\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Only 100 search results are available without payment\u003C\u002Fp>\u003Cp>CLI stands for command-line interface, which is Shodan's command-line mode\u003C\u002Fp>\u003Cp>On Windows systems, using pip install generates the file Shodan.exe in the same directory\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017287204_0_d56de95fe7-1.jpeg\">\u003C\u002Fp>\u003Ch4>(1) Initialization\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan init \u003Capi key=\"\">\u003C\u002Fapi>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The actual command is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan init SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017317898_1_bf5b42f364-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Search for the quantity of specified content (apache)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan count apache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017361790_2_b803958c87-1.jpeg\">\u003C\u002Fp>\u003Cp>Obtain result 23803090\u003C\u002Fp>\u003Ch4>(3) Search for information on specified content (apache)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan search --fields ip_str,port,org,hostnames apache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Search keyword: apache\u003C\u002Fp>\u003Cp>Output: ip_str,port,org,hostnames\u003C\u002Fp>\u003Ch4>(4) Download search results for specified content (apache)\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan download result apache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Search keyword: apache\u003C\u002Fp>\u003Cp>Save file name: result.json.gz\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017390678_3_03e0073351-1.jpeg\">\u003C\u002Fp>\u003Ch4>(5) Parse the file to obtain search results\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan parse --fields ip_str,port,org --separator , result.json.gz\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017417011_4_f32559dd90-1.jpeg\">\u003C\u002Fp>\u003Ch4>(6) Search for information on a specified IP\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shodan host 189.201.128.250\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017461939_5_97b7a30e8e-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Differences between the three types of credits\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Shodan has three types of credits:\u003C\u002Fp>\u003Cul>\u003Cli>Export credits\u003C\u002Fli>\u003Cli>Query credits\u003C\u002Fli>\u003Cli>Scan credits\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fhelp.shodan.io\u002Fthe-basics\u002Fcredit-types-explained\u003C\u002Fp>\u003Cp>Simple explanation:\u003C\u002Fp>\u003Ch3>Export Credits\u003C\u002Fh3>\u003Cp>Used when downloading data from the Shodan official website\u003C\u002Fp>\u003Cp>1 export credit = 10,000 results\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Exporting results consumes one credit per export, regardless of the number of results obtained, up to a maximum of 10,000 results\u003C\u002Fp>\u003Cp>Does not renew at the beginning of the month\u003C\u002Fp>\u003Ch3>Query Credits\u003C\u002Fh3>\u003Cp>Used when calling the Shodan API\u003C\u002Fp>\u003Cp>1 query credit = 100 results\u003C\u002Fp>\u003Cp>Renews at the beginning of the month, meaning if you only purchase a one-month membership, it will reset to zero the following month\u003C\u002Fp>\u003Ch3>Scan Credits\u003C\u002Fh3>\u003Cp>Used when calling the Shodan API\u003C\u002Fp>\u003Cp>1 scan credit = 1 IP\u003C\u002Fp>\u003Cp>Updated at the beginning of the month\u003C\u002Fp>\u003Ch2>0x04 Obtaining search results by calling the Shodan API via Python\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Without payment, not only are search filters unavailable, but only 100 search results can be obtained\u003C\u002Fp>\u003Ch3>(1) Search for information on specified content (Apache)\u003C\u002Fh3>\u003Cp>Python code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import shodan\u003Cbr>SHODAN_API_KEY = \"SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\"\u003Cbr>api = shodan.Shodan(SHODAN_API_KEY)\u003Cbr>try:\u003Cbr>    results = api.search('Apache')\u003Cbr>    print 'Results found: %s' % results['total']\u003Cbr>    for result in results['matches']:         \u003Cbr>            print (\"%s:%s|%s|%s\"%(result['ip_str'],result['port'],result['location']['country_name'],result['hostnames']))\u003Cbr>except shodan.APIError, e:\u003Cbr>    print 'Error: %s' % e\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017477888_6_5fa2be2c8b-1.jpeg\">\u003C\u002Fp>\u003Cp>If not paid, search filters cannot be used, such as Apache country:\"US\"\u003C\u002Fp>\u003Ch3>(2) Search for specified content and write the obtained IPs to a file\u003C\u002Fh3>\u003Cp>Python code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import shodan\u003Cbr>SHODAN_API_KEY = \"SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\"\u003Cbr>api = shodan.Shodan(SHODAN_API_KEY)\u003Cbr>file_object = open('ip.txt', 'w')\u003Cbr>try:\u003Cbr>    results = api.search('Apache')\u003Cbr>    print 'Results found: %s' % results['total']\u003Cbr>    for result in results['matches']:         \u003Cbr>#            print result['ip_str']\u003Cbr>            file_object.writelines(result['ip_str']+'\\n')\u003Cbr>except shodan.APIError, e:\u003Cbr>    print 'Error: %s' % e\u003Cbr>file_object.close()  \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(3) Specify search criteria via command line arguments and write the found IPs to a file\u003C\u002Fh3>\u003Cp>Python code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import shodan\u003Cbr>import sys\u003Cbr>SHODAN_API_KEY = \"SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\"\u003Cbr>api = shodan.Shodan(SHODAN_API_KEY)\u003Cbr>if len(sys.argv)&lt;2:\u003Cbr>    print '[!]Wrong parameter'\u003Cbr>    sys.exit(0)\u003Cbr>print '[*]Search string: %s' % sys.argv[1]\u003Cbr>    \u003Cbr>file_object = open('ip.txt', 'w')\u003Cbr>try:\u003Cbr>    results = api.search(sys.argv[1])\u003Cbr>    print '[+]Results found: %s' % results['total']\u003Cbr>    for result in results['matches']:         \u003Cbr>#            print result['ip_str']\u003Cbr>            file_object.writelines(result['ip_str']+'\\n')\u003Cbr>except shodan.APIError, e:\u003Cbr>    print 'Error: %s' % e\u003Cbr>file_object.close() \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command line parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>search.py apache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If searching for multiple keywords, enclose the search criteria in quotes, for example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>search.py \"apache country:US\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(4) Read IP list from file and reverse lookup IP information\u003C\u002Fh3>\u003Cp>Python code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import shodan\u003Cbr>import sys\u003Cbr>reload(sys)\u003Cbr>sys.setdefaultencoding('utf8')\u003Cbr>SHODAN_API_KEY = \"SkVS0RAbiTQpzzEsahqnq2Hv6SwjUfs3\"\u003Cbr>api = shodan.Shodan(SHODAN_API_KEY)\u003Cbr>def searchip(str):\u003Cbr>    try:\u003Cbr>        host = api.host(str)\u003Cbr>    except shodan.exception.APIError:\u003Cbr>        print \"[!]No information available\"\u003Cbr>        print \"---------------------------------------------\"\u003Cbr>        return\u003Cbr>    else:\u003Cbr>        # Print general info\u003Cbr>        try:\u003Cbr>            print \"IP: %s\\r\\nOrganization: %s\\r\\nOperating System: %s\" % (host['ip_str'], host.get('org', 'n\u002Fa'), host.get('os', 'n\u002Fa'))\u003Cbr>        except UnicodeEncodeError:\u003Cbr>            print \"[!]UnicodeEncode Error\\r\\n\"\u003Cbr>        else:\u003Cbr>            # Print all banners\u003Cbr>            for item in host['data']:\u003Cbr>                print \"Port: %s\\r\\nBanner: %s\" % (item['port'], item['data'])\u003Cbr>        print \"---------------------------------------------\"\u003Cbr>        return\u003Cbr>file_object = open('ip.txt', 'r')\u003Cbr>for line in file_object:\u003Cbr>    searchip(line)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Download search results via Shodan official website\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Export credits are used when downloading data via the Shodan official website, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017487412_7_1e88436c83-1.jpeg\">\u003C\u002Fp>\u003Cp>Each query consumes one export credit, regardless of the number of results, with a maximum of 10,000\u003C\u002Fp>\u003Cp>Select json as the export format\u003C\u002Fp>\u003Ch3>(1) Extract IPs from the downloaded json result file\u003C\u002Fh3>\u003Cp>Python code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import json\u003Cbr>file_object = open(\"shodan_data.json\", 'r')\u003Cbr>for line in file_object:\u003Cbr>    data = json.loads(line)\u003Cbr>    print (data[\"ip_str\"])  \u003Cbr>file_object.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) Extract IP and port of specified country from downloaded json result file\u003C\u002Fh3>\u003Cp>Country code is in secondary element, corresponding structure: data[\"location\"][\"country_code\"]\u003C\u002Fp>\u003Cp>Python code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import json\u003Cbr>import sys\u003Cbr>import re\u003Cbr>def search(country):\u003Cbr>    file_object = open(\"shodan_data.json\", 'r')\u003Cbr>    file_object2 = open(country+\".txt\", 'w')\u003Cbr>    for line in file_object:\u003Cbr>        data = json.loads(line)  \u003Cbr>        if re.search(data[\"location\"][\"country_code\"], country, re.IGNORECASE):\u003Cbr>            str1 = \"%s:%s\" % (data[\"ip_str\"],data[\"port\"])\u003Cbr>            print str1\u003Cbr>            file_object2.writelines(str1+'\\n')\u003Cbr>    file_object.close()\u003Cbr>    file_object2.close()\u003Cbr>if __name__ == \"__main__\":\u003Cbr>    if len(sys.argv)&lt;2:\u003Cbr>    \tprint ('[!]Wrong parameter')\u003Cbr>        sys.exit(0)\u003Cbr>    else:\u003Cbr>        print ('[*]Search country code: %s' % sys.argv[1])\u003Cbr>        search(sys.argv[1])\u003Cbr>        print (\"[+]Done\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command line arguments:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>search.py US\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate file US.txt, save IP and corresponding ports\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the usage of the Shodan API, sharing insights and Python script development techniques. When opting for a paid purchase, remember to distinguish between the three types of credits (credits).\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",644,"Onedaysec",5,"published","2026-02-02T07:38:21.176Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Shodan API Guide: Python Usage, Credits, and Search Tips","Shodan API, Python, network device search, API key, search results, credits, automation, cybersecurity",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],916,915,914,912,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.844Z","2026-07-23T16:02:15.791Z","draft","2026-07-23T16:15:30.039Z"]