Port · CVE · Product exposure intelligence via Shodan
GHOST DEFENSE
Tool 49 · Defend Always
How this works
Enter a port number to find hosts exposing that port, using Shodan's existing scan data through the Ghost Worker. This is passive — no packets are sent to any host; it reports what Shodan already observed: the service banner, product/version, org, location, and any known CVEs. Inverse of Tool 21 (which takes a host and lists its ports). Scope with an optional country / ASN / CIDR to keep results relevant and bounded.
SearchSourced · Shodan
By Port
By CVE (vuln:)
By Product / Version
By Banner Text
3389 RDP
445 SMB
23 Telnet
21 FTP
22 SSH
3306 MySQL
5432 PostgreSQL
6379 Redis
27017 MongoDB
9200 Elasticsearch
161 SNMP
502 Modbus
47808 BACnet
1900 SSDP
⚠ Banner-detection only. Shodan's vuln: flags a host when its banner reveals an affected version. This is reliable for banner-exposed vulns (RDP, network services, device firmware — e.g. BlueKeep) but near-blind to library/app-layer vulns (Log4Shell, Spring4Shell) that don't appear in banners. A low or zero count does not mean you're safe — it may mean Shodan can't see it. These are Shodan-inferred, not confirmed exploitable.
For library/app vulns vuln: can't see. Searches product: and shows the running version from each banner. Enter the affected version to highlight in-range hosts (highlighting is a banner-string match, advisory-grade — confirm the exact build on hosts you own).
Sends your term as a raw free-text query — Shodan searches the whole banner rather than the fingerprinted product: field. Use this when By Product returns 0 for software Shodan doesn't fingerprint (AnyDesk, TeamViewer and similar remote-access tools show up only as banner strings like Server: anydesk). Broader and noisier than product: — it also matches hosts that merely mention or redirect to the vendor, so treat hits as candidates to confirm, not an inventory.
Sector isn't a native Shodan field — it matches the organization name via org:"keyword", so it catches orgs whose name contains the word, not a formal sector taxonomy. Combine filters to narrow.
query →port:
Requires the Ghost Worker with SHODAN_API_KEY set and a Shodan plan with the Search API. Broad queries return huge counts — add scope filters.
ResultsSourced · Shodan scan data
IP
Port
Service / Product
Banner (sysDescr)
Org / Location
Signals
DEFEND ALWAYS · Passive discovery — no packets sent to any host · Banners, products and CVEs are Shodan-sourced scan observations, not live probes · Exposure ≠ exploitability; verify before acting · Broad, unauthenticated services (RDP, SMB, Telnet, exposed databases) flagged as risky · Data via Shodan Search API through the Ghost Worker (SHODAN_API_KEY server-side) · Inverse of Tool 21.