find-exposed-servers

Installation
SKILL.md

Find exposed servers

Internet-wide scanners already scanned your target. Querying their results is passive — you never send a packet to the target, so nothing appears in their logs and nothing is attributable to you. The cost is that every result is a claim about a moment in the past, and the beginner's mistake is reading a banner as the current state of a live host.

Which platform first

You hold Reach for Why
An IP Shodan host lookup, or the free InternetDB endpoint One request gives ports, hostnames, and CPEs
A netblock or ASN Shodan net:/asn: with port faceting Shows the shape of the estate before you look at individual hosts
A hostname behind a CDN Censys certificate-to-host joins Censys links certs to observed hosts, which is how you find origins
A cert or a distinctive page Favicon hash and cert subject/serial searches Finds sibling infrastructure the DNS never links
An org name org: on Shodan, autonomous_system on Censys Both are attribution by network registration, so both inherit its errors
Coverage doubt A second platform with different sensors The platforms disagree constantly; disagreement is signal
Installs
832
GitHub Stars
3
First Seen
1 day ago
find-exposed-servers — useosint/osint-skills