All integrations
Shodan logo
// Data Integration · Attack Surface Management

Cracken + Shodan

Cracken writes Shodan dorks and host lookups mid-operation. It takes its next move from the banners, versions and CVEs that come back — without a packet reaching the target.

Get started
// 01

Connecting Shodan

Connect with

A Shodan API key

Cadence

Queried live during an operation

Requires

No prerequisites

// 02

What Cracken gets from Shodan

  • IPAddress nodes carrying org, isp, asn, country_name, city, os and last_update

  • DNSName nodes for every hostname Shodan lists on the IP

  • Service nodes per open port with port, transport, product and version

  • Port nodes for search hits, which carry a single port and transport but no service list

  • Vulnerability nodes, one per CVE in Shodan's vulns list

  • Host lookup also returns domains, the full ports array, and a banner truncated to 200 characters per service

  • Search returns items with ip, port, transport, hostnames, org, country_name, os, timestamp and vulns, plus a result total

  • DNS resolve returns hostname to IP; DNS reverse returns IP to hostnames

// 03

What Shodan does not do

Shodan is passive and read-only — every action is a lookup, a search, a count or a DNS resolution; nothing is scanned and nothing is written. Its results also do not sync into the Cybergraph on their own: nodes appear only when someone explicitly pushes selected items to the knowledge base, and there is no scheduler that touches Shodan at all.

// 04

How Cracken uses Shodan

  1. 01

    Connect Shodan with an API key

  2. 02

    Look the target up in Shodan

  3. 03

    Push the hosts that matter into the graph

  4. 04

    Confirm it connected

// 05

Frequently asked questions

Does looking a target up in Shodan send traffic to that target?

No; Shodan runs its own internet-wide crawlers and Cracken reads their stored results, so the lookup reaches Shodan, never the target.

How current is the data Shodan returns?

As current as Shodan's last crawl — days or months behind reality — so Cracken stamps each imported host with the date Shodan last observed it.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real Shodan context.

See how Cracken works what Shodan already knows into attack paths it proves end to end.