shodan-reconnaissance

Enrich BBOT reconnaissance results with Shodan host intelligence and CVE correlation.

11|1|Updated May 4, 2026
One-click install
npx skills add https://github.com/dreadnode/capabilities --skill shodan-reconnaissance
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: shodan-reconnaissance
Source: https://github.com/dreadnode/capabilities/tree/main/capabilities/attack-surface-management/skills/shodan-reconnaissance
Command: npx skills add https://github.com/dreadnode/capabilities --skill shodan-reconnaissance

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Active reconnaissance tools like BBOT often miss passive internet-wide host data, historical service records, and banner intelligence, leading to incomplete attack surface visibility during security assessments.

Core Features & Use Cases

  • Asset Discovery & Enrichment: Complement BBOT active scans with Shodan's passive host data to find exposed services, missed assets, and org-wide infrastructure.
  • Vulnerability Correlation: Link discovered hosts to known CVEs, outdated software, and misconfigurations using Shodan's vulnerability and banner analysis.
  • Attack Surface Mapping: Aggregate service distribution, geographic data, and technology fingerprints to build a complete profile of a target's internet-facing assets. Use case: For a red team engagement, use this skill to enrich BBOT's discovered IPs with Shodan data, identify exposed databases and remote desktop services, and correlate any found CVEs with available exploits.

Quick Start

Use the shodan-reconnaissance skill to enrich all IPs discovered by BBOT with Shodan host intelligence and correlate any associated CVEs with available exploits.

Frequently Asked Questions about shodan-reconnaissance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enrich active reconnaissance results with Shodan passive host intelligence?

Enrich active reconnaissance results by correlating discovered IPs with Shodan's passive internet-wide host intelligence to close gaps in attack surface visibility and identify exposed services. This skill provides structured query patterns to map internet-facing infrastructure.

What is the best way to map an organization's attack surface and discover exposed assets?

Map attack surfaces by aggregating service distribution, geographic data, and technology fingerprints from Shodan to build a complete profile of a target's internet-facing assets. This approach supports red teaming and attack surface management workflows involving asset discovery.

How can I correlate discovered hosts with known CVEs and outdated software?

Correlate discovered hosts with known CVEs, outdated software, and misconfigurations using Shodan's vulnerability and banner analysis. This workflow links passive host data to security risks, identifying exposed databases and remote desktop services for further exploitation.

Can I use Shodan reconnaissance to complement active scanning tools like BBOT?

You can complement BBOT active scans with Shodan's passive host data to find exposed services, missed assets, and org-wide infrastructure. This integration enriches discovered IPs with internet-wide host intelligence and correlates associated CVEs with available exploits.

Does Shodan reconnaissance support credit-optimized workflows for large-scale asset discovery?

Shodan reconnaissance provides credit-optimized workflows and facet analysis tools to efficiently map internet-facing infrastructure during large-scale asset discovery. These structured query patterns identify security risks while managing API resource consumption.

Why does active reconnaissance miss passive internet-wide host data and historical service records?

Active reconnaissance tools often miss passive internet-wide host data and historical service records because they only capture real-time responses, leading to incomplete attack surface visibility. Shodan's banner intelligence closes these gaps during security assessments.