GHOST DEFENSE
Tool 57 · Defend Always

ICS Exposure Map

Sector-level OT/ICS exposure from control-protocol fingerprints, weighted by KEV — plus a watchlist for assets you already know are exposed
ConnectionLocal · you supply
checking…
Stored in localStorage.ghost2210_exploit_proxy, shared with every Ghost tool on this origin. Your Shodan key stays in the Worker — it is never held by this page.
Survey scopeFree · no query credits
Enumeration returns the actual addresses: 1 credit per page of 100 hosts, per protocol. It needs a real scope — enumerating a global port filter burns credits on the open internet. Set country:, asn:, org: or net: above first. Results land in the findings table at the bottom.
wide marks a port-only filter that will also catch unrelated services on the same port — 502, 102 and 20000 especially. fp marks a filter that depends on Shodan's product: fingerprint, which returns a legitimate zero for anything Shodan does not catalog. Tighten both against your own scope before trusting a number either way.
The /shodan/host/count endpoint returns totals and facets without consuming query credits, so this survey is free to re-run. Spend credits only on the watchlist below, once the counts show something worth enumerating.
Identified assetsSourced · Shodan
This stage spends credits: 1 per single IP, and 1 per 100 hosts for a CIDR. Only list ranges you are authorized to assess — a block registered to your ASN may be sub-leased to a tenant, and Shodan attributes by registration and cannot see delegation.
Exposed HMI screensSourced · Shodan screenshots
This survey renders only within a defined scope — a country plus at least one of asn:, org: or net: in the filter box at the top, or a country on its own. It will not display screenshots for the open internet: a wall of other operators' live control panels is a reconnaissance product, not an audit. Set your scope above first.
Query: has_screenshot:true RFB port:5900 joined to your scope (RFB = the VNC banner marker Shodan indexes screenshots under). Cost: 1 credit for the search, plus 1 per host that needs its image pulled directly — Shodan trims the image bytes off bulk search results, so panels without an inline image are fetched per-host to retrieve the actual screenshot. Every survey is a fresh live pull, never cached, and the timestamp on each result confirms it. Read-only against Shodan's stored index — this never connects to an HMI, opens no VNC session, and touches nothing on the device.
GHOST — Grounded Handling Of Sourced Threat-intel · DEFEND ALWAYS
Exposure observed by Shodan is not confirmation of current state or of exploitability. CVEs shown are Shodan's banner-version inference and are candidate findings requiring validation, not confirmed vulnerabilities. Sector attribution is inferred from organization and hostname text. Confirm before you act.