Track what opens on the ranges you own — baseline diffs plus Shodan alert management
Your netblocksLocal · you supply
Only list ranges you are authorized to monitor. A block announced under your ASN may be sub-leased to a partner or tenant — Shodan attributes by registration and cannot see that. Confirm ownership against your IPAM and any delegation agreements before acting on what shows up here.
What changedSourced · Shodan
Change
IP
Port
Service
Org
First seen
Compares what Shodan sees on your ranges and hosts now against the last baseline you accepted, stored in this browser. A single IP is looked up directly, returning every port Shodan has recorded for that host; a CIDR is searched across the range. New means a service Shodan did not previously report — the port may have been open earlier and only just been scanned. Detection follows Shodan’s rescan cadence, so this is change awareness, not intrusion detection. Passive: no packets are sent from this tool.
Shodan alertsWrites to your account
These controls change your Shodan account, not just this page. Alerts persist server-side and count against your plan limits. Shodan delivers alert events to the notifiers you attach below — this page manages the definitions but cannot receive the events. Use “What changed” above for in-browser detection.
Notifier endpointsWrites to your account
Create new notifier
Creating a notifier registers a delivery endpoint on your Shodan account. Delivery only starts once you attach it to an alert (button on each alert above). Nothing is sent yet — test the receiver first, then attach. Webhook URLs and tokens live on Shodan servers; treat them as credentials.
GHOST — Grounded Handling Of Sourced Threat-intel · DEFEND ALWAYS
Exposure observed by Shodan is not confirmation of current state or of exploitability. Ownership of an address is yours to verify. Confirm before you act.