Shodan Integration
Shodan is a search engine that lets the user find specific types of computers (webcams, routers, servers, etc.) connected to the internet using a variety of filters. Some have also described it as a search engine of service banners, which are metadata that the server sends back to the client. This can be information about the server software, what options the service supports, a welcome message or anything else that the client can find out before interacting with the server. Shodan data and infrastructure povide your organization with real-time information about the entire Internet.
Security Beyond the Perimeter: The Shodan platform helps you monitor not just your own network but also the entire Internet. Detect data leaks to the cloud, phishing websites, compromised databases and more. The Enterprise Data License gives you the tools to monitor all connected devices on the Internet.
Market Intelligence for the Connected World: Use the Shodan platform to see which products are popular on the Internet and how the markets are shifting over time. Which areas have the most home automation systems? How popular are the latest smart TVs? Purchase the Enterprise Data License to understand the modern connected world.
New Age of Fraud Prevention: When was the last time you saw a refrigerator buy a computer? Use Shodan to detect whether the purchase is being made from an IoT device, compromised database, VPN, Tor or any type of unusual device.
Platform Components:
-
Bulk DataFeed: Download all of the data that Shodan collects to build your own database of Internet-connected devices.
-
On-DemandScanning: Use Shodan's global infrastructure to scan networks ranging from individual IPs up to the entire Internet.
-
UnlimitedAccess: The Enterprise Data License provides unlimited access to Shodan for all employees of the organization.

-
In the Cisco XDR navigation menu, choose Administration > Integrations.
-
On the Integrations page, click the Third-Party tab and navigate to the Shodan integration.
-
Click the plus sign (+) in the lower-right corner of the card. The Shodan integration page is displayed.
-
Expand the Integration Guide area and follow the instructions on how to add the Shodan integration in Cisco XDR.

You can perform the following tasks after you integrate Shodan with Cisco XDR:
-
Investigations - Start a new investigation by searching on suspicious indicators of compromise to extract observables for enrichment. To verify that this integration is working, and to see what kind of data is returned, investigate one of more observables about which you know Shodan has recent information. For details, see Investigate.
-
Pivot Menu - Use the Pivot menu to access actions in Shodan. Available actions include searching for an IP address and browsing IP addresses in Shodan.