
Jun 21, 2023
1.0.2
ThreatQ versions >= 5.6.0
Shodan Action
Overview
The Shodan action for ThreatQ submits a data collection of IP Address objects to the Shodan API. The Shodan API queries the submitted IPs for any services running and returns related threat intelligence to be ingested into the ThreatQ library.
The action provides the following functions:
The action provides the following functions:
- Shodan - submits an IP Address to the Shodan API to enrich the indicator with all services found by Shodan on the host.
The action is compatible with the IP Address type indicators and returns enriched indicators.
Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.