Incomplete Lab - Shodan Search

Objectives

In this lab, you will use the Shodan search engine to understand why security should be the focus of any IIoT implementation.

  • Part 1: Obtain Access to Shodan’s Free Features
  • Part 2: Investigate Connected IoT Devices

Background / Scenario

Warning: Do not attempt to login to any device you find on the Shodan search engine. Doing so violates your ethical hacking agreement.

In this lab, you will use the Shodan search engine to gain an understanding of why security should be the focus of any IoT implementation.

Shodan has servers located around the world that continually scan the internet for connected devices, including those used in industrial environments. It can detect specific device types such as PLCs, SCADA systems, building automation controllers, and other IIoT components. This information is indexed and made searchable, allowing users to explore systems based on protocols, ports, vendors, or locations. Common industrial-focused searches include terms like "Modbus," "Siemens S7," "HMI," or "BACnet", which can reveal how and where critical infrastructure systems are exposed online.

Shodan is a favorite tool used by researchers, security professionals, large enterprises, and computer emergency response teams (CERTs).

  • Researchers can use Shodan to data mine information about what devices are connected, where they are connected, and what services are exposed.
  • Security professionals can use Shodan as part of a penetration testing plan to discover devices that need to be hardened to prevent potential attacks.
  • Large enterprises employ security professionals who should be aware of tools like Shodan for determining the current risk profile of the enterprise’s connected devices.
  • CERTs can use Shodan to quickly generate reports about an emerging attack on connected devices.

Shodan is also a tool used by nefarious individuals and groups commonly referred to as threat actors. Shodan can accelerate a threat actor’s reconnaissance of Internet connected devices. Like all the tools in this course, you must use it responsibly according to your organization’s ethical hacking policies.

Required Resources

Instructions

Part 1: Obtain Access to Shodan’s Free Features

In this part of the lab, you will navigate to the Shodan search engine and sign up for an account and explore the Shodan features.

Step 1: Create free Shodan account.

  1. Open a web browser and navigate to the Shodan website at https://www.shodan.io/.
  2. Log in or register to create an account.
  3. After successfully logging in, you will see your account page, as shown below. Click the Shodan link to return to the homepage.
Screenshot of Shondan web site's top navigation bar.

Now that you’ve created your Shodan account, you’ll begin using its powerful tools to investigate internet-connected devices. In the part of the lab, you will first use the Search feature to perform targeted queries for industrial systems. Then, you'll use the Explore page to discover popular device categories and real-world examples of exposed technologies.

Step 2: Get to know the Shodan interface and how it works.

In this step, you will explore the “Getting Started” area of the Shodan website to learn about its basic features and search capabilities.

  1. From the Shodan Dashboard, scroll down to locate the “Getting Started” panel.
  2. Review the introductory materials, including how Shodan gathers data, what banner information is, and how to use search filters and operators.
  3. Click on any linked tutorials or “Search Examples” to view sample queries and explore how real devices and services appear in Shodan.
  4. Tip: Pay attention to how Shodan uses filters like port, country, or product -you’ll use these in upcoming steps to find IIoT and ICS systems.

Briefly summarize one new thing you learned about how Shodan works or how it identifies devices.
Answer Area
Answers will vary. For example, Shodan is a search engine for Internet-connected devices, and the bulk of the data is taken from the banners. The banner may be welcome messages or provide information to the client before interacting with the server.

Part 2: Investigate Connected IIoT Devices

Step 1: Use the Shodan search engine to find Internet-connected IIoT devices.

In this part, you will gain familiarity with using Shodan to search for Internet-connected IIoT devices.

Legal reminder: Shodan only shows publicly accessible data, but you must not interact with devices unless you own or have permission to do so. Remember, passive observation is allowed; active probing is not.

Shodan is a specialized search engine designed to find Internet-connected devices, not websites. It’s often described as the "Google for IoT and IIoT" because it indexes devices like:

  • Webcams, routers, and printers
  • Industrial control systems (ICS)
  • Building automation systems
  • Smart TVs, home assistants, and more
  • Instead of indexing web content like Google, Shodan scans the internet to collect banner information from devices and services listening on open ports. These banners may include:

  • Device type and vendor (e.g., Siemens, Rockwell)
  • Open ports and services (e.g., Modbus TCP on port 502)
  • Operating system or firmware versions
  • Location and hosting provider
  • Shodan organizes this data so users can search for devices by keyword, service, IP range, country, or vulnerability.

  1. In the Shodan search box type title:"HMI" country:US.
  2. This search will result in industrial Human-Machine Interfaces—the graphical control panels operators use to monitor and control PLCs, SCADA systems, and automated machinery – located in the United States.

Look on the top left of the results page. How many results did you get for your search?
Answer Area
At the time of testing this lab, this search returned more than 500 results.
  1. Look at other information on the left side of the web page. The results are broken down into various categories.
What are the top three cities listed?
Answer Area
At the time of writing, Ashburn, Atlanta, and Richardson.
What are the top three ports listed?
Answer Area
At the time of writing, 80, 443, and 8080.
What are the top three organizations listed?
Answer Area
At the time of writing, Linode, Verizon Business, and AT&T Enterprises LLC.
What are the top three products listed?
Answer Area
At the time of writing, Automation Direct, nginx, Apache httpd.
What are the top three operating systems listed?
Answer Area
At the time of writing, Windows, Linux, Ubuntu.
  1. Each entry in a category is a clickable link that will refine your search. Click on 443 under TOP PORTS on the left.
  2. The results in the right side of the Shodan window show HMI systems in the U.S. that are exposed to the public internet and that are using HTTPS (port 443). These devices often include industrial control dashboards for SCADA systems or remote interfaces for automation. Seeing them on port 443 means they are running a web interface secured by SSL/TLS encryption. However, many of these could still be insecure due to weak or self-signed certificates, misconfigured servers, or lack of authentication or access control. This exposure is significant because HMI systems are meant to control or monitor industrial processes and having them publicly reachable poses serious cybersecurity risks.

  3. Select one of the devices in the list of results and click on it to view more details. Shodan now displays key information about the device, including its IP address, domain, geographic location (city), owning organization, internet service provider (ISP), autonomous system number (ASN), web technologies in use, open ports, and any known vulnerabilities. This information helps to assess the device’s exposure and risk profile. Review the results to answer the following:
What is the IP Address?
Answer Area
Answers will vary.

What is the domain?
Answer Area
Answers will vary.
What is the country and city?
Answer Area
Answers will vary.
What is the Organization?
Answer Area
Answers will vary.
What is the ISP?
Answer Area
Answers will vary.
What is the ASN?
Answer Area
Answers will vary.
What is the ISP?
Answer Area
Answers will vary.
What are the Web Technologies?
Answer Area
Answers will vary.
What are the open ports, and the services associated?
Answer Area
Answers will vary.
What are the vulnerabilities listed?
Answer Area
Answers will vary.

This is all very valuable information to a threat actor. By analyzing exposed IP addresses, open ports, software versions, and even geographic or organizational data, they can:

  • Pinpoint vulnerable industrial or IoT devices (e.g., PLCs, HMIs)
  • Target outdated software versions or services with known vulnerabilities (CVEs)
  • Use the organization name and location to craft phishing or social engineering campaigns
  • Exploit insecure services (e.g., unencrypted protocols, default credentials)
  • Map exposed systems across entire industries or geographic regions

This kind of passive reconnaissance is typically the first step in a more targeted cyberattack.

Step 2: Use the Shodan Explore page.

In the previous step you used the Shodan search feature to perform a targeted query which is useful for finding specific internet-connected devices or services and is ideal for focused investigations, such as identifying publicly exposed PLCs or HMI systems. In contrast, the Shodan Explore page highlights popular and pre-defined categories (e.g., Industrial Control Systems, Webcams, or Databases), making it easier for beginners to browse interesting or high-risk devices without needing advanced search syntax.

  1. In the Shodan webpage menu click Explore.
  2. The Explore page showcases popular categories, research tools, and community-driven search topics that help users better understand real-world exposure.

    At the top, you’ll find clickable categories like:

  • Industrial Control Systems – Devices used in manufacturing, energy, and critical infrastructure.
  • Databases – Exposed data systems like MongoDB, MySQL, or Elasticsearch.
  • Network Infrastructure – Routers, firewalls, load balancers, etc.
  • Video Games – Game servers and multiplayer platforms found online.
  1. Clicking one of these will bring up pre-made searches related to that category, helping you quickly explore how exposed certain systems are across the internet.
  2. On the left side, you’ll find special research tools:

  • Shodan 2000 – A fun, retro-styled interface for exploring Shodan results.
  • Internet Observatory – A high-level dashboard that shows trends in device exposure by country and the most common vulnerabilities.
  • The middle and right sections show community-created search queries you can browse:

  • Popular Tags – Keywords like door, default password, or modbus help you explore specific technologies or risks.
  • Example Queries – Like the Job Board (websites that accidentally reveal jobs in HTTP headers) or Ethereum Miners (devices mining cryptocurrency).
  • These are public searches shared by other Shodan users, which can be used as a learning tool to analyze exposure and misconfiguration across device types.

  1. Select the Industrial Control Systems category and review the page contents. Read the descriptions of the various ICS protocols listed on the page.
  2. Click EXPLORE MODBUS and view the results.
How many devices are exposing Modbus to the public internet?
Answer Area
At the time this lab was written more than 800,000. This is alarmingly high, considering Modbus lacks encryption, authentication, or built-in security.
Which country alone accounts for more than half of all exposed Modbus devices?
Answer Area
At time of writing: United States.
Which organization accounts for most of the exposed Modbus devices?
Answer Area
At time of writing: Google.
Note: These may not be actual Modbus devices but rather honeypots, scanning proxies, or systems relaying industrial traffic from VPNs or edge gateways.
What are the top two operating systems?
Answer Area
At time of writing: Windows and Linux.
Note: Many SCADA HMIs run on Windows; these are vulnerable if unpatched. Common on IIoT gateways and edge devices run on Linux. Legacy control systems run on Unix. These systems date back to the 1980s and 1990s and are still in use today due to their reliability, specialized function, and resistance to change in operational environments. As for IOS and ASUSWRT operating systems, these are usually not industrial control systems (ICS). Instead, they're often misclassified, misconfigured, or acting as gateways or proxies for IIoT or ICS traffic.
  1. Look at the right side of the screen. This shows a list of Modbus devices exposing port 502.
  2. These entries represent IP addresses with an open TCP port 502, which is the default port for Modbus TCP.

  3. Click on an entry of your choice.
  4. Remember: Passive observation using Shodan is legal, but only if it remains strictly observational. You are allowed to view banner information, metadata such as IP addresses and open ports, and analyze publicly reported vulnerabilities that Shodan already displays. However, it is illegal and unethical to interact with the device in any way. This includes attempting to log in, send commands, run scans, or authenticate—even with default credentials. As a rule of thumb: if you are not explicitly authorized by the device owner, any interaction beyond viewing is off-limits and may be considered unlawful.

  5. Review the information shown to answer the following:
What is the IP Address?
Answer Area
Answers will vary.
What is the domain?
Answer Area
Answers will vary.
What is the country and city?
Answer Area
Answers will vary.
What is the Organization?
Answer Area
Answers will vary.
What is the ISP?
Answer Area
Answers will vary.
What is the ASN?
Answer Area
Answers will vary.
What is the ISP?
Answer Area
Answers will vary.
What are the Web Technologies?
Answer Area
Answers will vary.
What are the open ports, and the services associated?
Answer Area
Answers will vary.
What are the vulnerabilities listed?
Answer Area
Answers will vary.

Step 3: Explore other ICS systems.

  1. Return to the Industrial Control Systems page.
  2. Select other ICS protocols such as SIEMENS S7, DNP, or EtherNet/IP and explore the results.

Reflection Question

After using Shodan's Search and Explore features to investigate internet-exposed ICS (Industrial Control Systems) devices and protocols, what surprised you most about the types of systems that are publicly accessible? How might this visibility pose a risk to critical infrastructure, and what steps should organizations take to reduce this exposure?

Answer Area

Answers will vary but may include noticing the large number of publicly accessible ICS devices, such as PLCs and HMIs, many of which appear outdated, misconfigured, or linked to critical infrastructure like energy and water systems. Students may be surprised that these systems are reachable without authentication or are revealing technical details in their banners.

Students may explain that such visibility creates serious cybersecurity risks, including unauthorized access, data manipulation, and potential physical damage to systems. Protocols like Modbus and DNP3 lack basic security, making exposed devices easy targets for attackers conducting reconnaissance or launching direct attacks.

Mitigation strategies students might mention include network segmentation, using firewalls and VPNs, closing unnecessary ports, enforcing strong authentication, applying regular updates, and auditing public exposure using tools like Shodan.


© 2018 - 2025 Cisco and/or its affiliates. All rights reserved. Cisco Public