Sector-level OT/ICS exposure from control-protocol fingerprints, weighted by KEV — plus a watchlist for assets you already know are exposed
ConnectionLocal · you supply
checking…
Stored in localStorage.ghost2210_exploit_proxy, shared with every Ghost tool on this origin. Your Shodan key stays in the Worker — it is never held by this page.
Survey scopeFree · no query credits
Enumeration returns the actual addresses: 1 credit per page of 100 hosts, per protocol. It needs a real scope — enumerating a global port filter burns credits on the open internet. Set country:, asn:, org: or net: above first. Results land in the findings table at the bottom.
wide marks a port-only filter that will also catch unrelated services on the same port — 502, 102 and 20000 especially. fp marks a filter that depends on Shodan's product: fingerprint, which returns a legitimate zero for anything Shodan does not catalog. Tighten both against your own scope before trusting a number either way.
The /shodan/host/count endpoint returns totals and facets without consuming query credits, so this survey is free to re-run. Spend credits only on the watchlist below, once the counts show something worth enumerating.
Sector annunciatorSourced · Shodan facets
Tiles count only endpoints Shodan named an organization for and that the keyword classifier matched. Shodan returns at most 100 organization facet values per query, so on a broad scope that is a small fraction of the total — everything else lands in UNCLASS, which is the honest answer, not a gap to be filled by guessing. If UNCLASS dwarfs the named sectors, narrow the scope with country:, asn: or net: until the facet actually covers your population. The coverage table below tells you when it does.
Query auditLocal · verbatim
Every query string sent to Shodan, verbatim, with the result count it returned. Any figure this tool reports can be reproduced by pasting one of these into Shodan directly. If a query does not say what you meant it to say, it is visible here.
OrganizationsFree · org facet
These are the organizations Shodan attributes by netblock registration. Registration is not operation — a range registered to a carrier or hosting provider may be operated by a tenant, and Shodan cannot see the delegation. Treat a name here as a lead to verify, never as an asset owner of record.
Hardware observedFree · product facet
Only the hosts Shodan actually fingerprinted appear here, so these counts will not sum to the protocol totals — the coverage column shows how much of each protocol was identified. Shodan's product: taxonomy is vendor and service names, not hardware model designators: expect "Siemens S7" or "Schneider Electric", never a part number like 6ES7-315. Model attribution has to come from your IPAM, not from here.
Identified assetsSourced · Shodan
This stage spends credits: 1 per single IP, and 1 per 100 hosts for a CIDR. Only list ranges you are authorized to assess — a block registered to your ASN may be sub-leased to a tenant, and Shodan attributes by registration and cannot see delegation.
Exposed HMI screensSourced · Shodan screenshots
This survey renders only within a defined scope — a country plus at least one of asn:, org: or net: in the filter box at the top, or a country on its own. It will not display screenshots for the open internet: a wall of other operators' live control panels is a reconnaissance product, not an audit. Set your scope above first.
Query: has_screenshot:true RFB port:5900 joined to your scope (RFB = the VNC banner marker Shodan indexes screenshots under). Cost: 1 credit for the search, plus 1 per host that needs its image pulled directly — Shodan trims the image bytes off bulk search results, so panels without an inline image are fetched per-host to retrieve the actual screenshot. Every survey is a fresh live pull, never cached, and the timestamp on each result confirms it. Read-only against Shodan's stored index — this never connects to an HMI, opens no VNC session, and touches nothing on the device.
GHOST — Grounded Handling Of Sourced Threat-intel · DEFEND ALWAYS
Exposure observed by Shodan is not confirmation of current state or of exploitability. CVEs shown are Shodan's banner-version inference and are candidate findings requiring validation, not confirmed vulnerabilities. Sector attribution is inferred from organization and hostname text. Confirm before you act.