October 9, 2026
Shodan —The Search Engine for Internet-Connected Devices (With a Walkthrough using x.com)
Shodan is basically the search engine for internet-connected devices. It scans the internet and records the banners (the metadata a service…
By Aremu Mercy
3 min read
Shodan is basically the search engine for internet-connected devices. It scans the internet and records the banners (the metadata a service returns when you connect to it) from things like web servers, routers, webcams, databases, industrial control systems, medical devices, and IoT gear. It is used by security professionals use to; see what an organization exposes to the internet, find systems running outdated or vulnerable software, spot exposed databases with no authentication and research the scale of a problem, such as how many devices of a certain type are reachable online.
In this post, I'll cover what Shodan is, how its search filters work, and a hands-on, passive walkthrough using x.com as an example target.
What Shodan Does
Instead of returning web pages, it returns hosts: an IP address plus everything Shodan learned about it, such as:
- Open ports and the services running on them
- Software names and versions (for example, nginx or Apache)
- The organization and internet provider that owns the IP
- Location (country and city)
- SSL certificate details
- Sometimes known vulnerabilities (CVEs) tied to the software it detects
Shodan web set-up
Shodan works entirely in the browser at shodan.io. A command-line tool and a Python library exist, but they're optional extras for automation. To get started:
- Go to shodan.io and create a free account.
- Log in.
- Use the search bar at the top.
Shodan Queries and how they work
Searches are built from filters in the form filter:value. You can combine them.
Walkthrough: Looking Up x.com on Shodan
Step 1: Start with the hostname
In the search bar, enter: hostname:x.com
Step 2: Read the results page
Each result shows an IP address, the organization, the country, and a snippet of the banner. Also on the left sidebar, shodan's facets break the results down by:
- Top countries
- Top ports
- Top organizations
- Top products
Step 3: Try the certificate search
Many hosts can be found through the SSL certificate names they present: ssl.cert.subject.cn:x.com
When the results are compared with the hostname search result. Differences can show exactly how an organization's certificates are deployed across its infrastructure.
Step 4: Try searching by organization
org:XServer
Step 5: Open a single host page
Click any result to open its host page. Here you can review, without interacting with the server itself:
- Open ports and the services behind them
- The software and version banners Shodan recorded
- Certificate details
- The date Shodan last scanned the host
- Any vulnerabilities Shodan associates with the detected software
Step 6: Narrow search with combined filters
Here, I combined what I have learned, for example: hostname:x.com port:22
Take home as a beginner in Application Security Testing.
As a beginner in AppSec, Shodan has changed how I think through this exercise about the internet: not as a collection of websites, but as a huge, searchable map of devices and services. Learning to read that map is a valuable foundation for me as I move into security, from attack surface management to vulnerability research. My own x.com search showed me that the map needs careful reading: it returned unrelated domains, so I must always confirm who owns a result before drawing conclusions.
Conclusion
Before this project, I thought of the internet as a collection of websites. Shodan showed me it's also a huge, searchable map of servers, devices, and services that anyone can look up. Searching for x.com taught me the most: I expected to see x.com's servers, but the results came from unrelated organizations in Japan, the US, and Ukraine, because Shodan matches text patterns. That showed the need to check the organization, certificate, and hostname on every result before drawing conclusions.
I also saw how much a network can reveal from the outside, including open ports, software banners, and remote access services. That's the same view an attacker gets during reconnaissance, which is why defenders use Shodan to find and fix weak spots first. Throughout, I stuck to passive lookups. As I build my skills in application security, Shodan has given me a practical starting point for understanding attack surfaces. My next step is to practice on my own assets and in lab environments, and to keep learning how to read the map accurately.