GD
GHOST DEFENSE
Tool 52 · Defend Always

Sector Peer Exposure

One Shodan query, fanned across critical-infrastructure sectors. Your sector highlighted. Briefing-ready output: are we in the hit population, and where do we rank?
QueryLocal · you supply
Runs ONE Shodan query with facets=org:100 — retrieves the top 100 organizations in your query's result set, then buckets each into a sector CLIENT-SIDE using regex name matching. Total cost: 1 query credit (+1 more if you provide a custom sector override, which is measured by direct intersection instead of facet-bucketing). Sectors ordered specific-to-general so an ambiguous org attributes to the more-specific bucket ("City of X Fire Department" → Emergency Services, not Government). Long-tail orgs beyond top-100 are lost — accepted; briefing-scale doesn't need the tail. The "Other / Unclassified" row is the honest measure of what didn't fit any rule.
GHOST — Grounded Handling Of Sourced Threat-intel · DEFEND ALWAYS
Sector definitions are query approximations, not authoritative sector attribution. Shodan reflects its last crawl of open-internet-reachable services and undercounts (a) hosts behind IPs the crawler cannot reach, (b) services with no fingerprintable banner, and (c) recent CVEs before the fingerprint deploys and the rescan completes. Treat the ranking as directional and the counts as provisional.