> For the complete documentation index, see [llms.txt](https://breachtrace.gitbook.io/vulnkeeper/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://breachtrace.gitbook.io/vulnkeeper/chapter-f/16-16-exposure-internet-facing-asset-and-threat-telemetry.md).

# 16. Exposure, internet-facing asset & threat telemetry

## 16.1 Internet exposure search engines

<table><thead><tr><th width="90.56640625" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>Censys Search</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://search.censys.io/">search.censys.io</a><br><br><strong><code>Access / Cost</code>:</strong> Free tier / paid plans</td><td><strong><code>Relevance</code>:</strong> Internet exposure search engine.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for determining if vulnerable services are internet-facing.</td></tr><tr><td align="right">2</td><td><strong>Censys API</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://search.censys.io/api">search.censys.io/api</a><br><br><strong><code>Access / Cost</code>:</strong> Free tier / paid plans; API key required</td><td><strong><code>Relevance</code>:</strong> Programmatic Censys access.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> API terms &#x26; quotas may apply.</td></tr><tr><td align="right">3</td><td><strong>Shodan</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.shodan.io/">www.shodan.io</a><br><br><strong><code>Access / Cost</code>:</strong> Free limited access / paid plans</td><td><strong><code>Relevance</code>:</strong> Internet-connected device search.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for exposure discovery &#x26; banner-based matching.</td></tr><tr><td align="right">4</td><td><strong>Shodan developer API</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://developer.shodan.io/">developer.shodan.io</a><br><br><strong><code>Access / Cost</code>:</strong> Paid/API credit model may apply; account required</td><td><strong><code>Relevance</code>:</strong> Shodan API documentation.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for automation.</td></tr><tr><td align="right">5</td><td>ZoomEye</td><td><a href="https://www.zoomeye.org/">www.zoomeye.org</a></td></tr><tr><td align="right">6</td><td>FOFA</td><td><a href="https://fofa.info/">fofa.info</a></td></tr><tr><td align="right">7</td><td>BinaryEdge</td><td><a href="https://www.binaryedge.io/">www.binaryedge.io</a></td></tr><tr><td align="right">8</td><td>Onyphe</td><td><a href="https://www.onyphe.io/">www.onyphe.io</a></td></tr><tr><td align="right">9</td><td>SecurityTrails</td><td><a href="https://securitytrails.com/">securitytrails.com</a></td></tr><tr><td align="right">10</td><td>InternetDB by Shodan</td><td><a href="https://internetdb.shodan.io/">internetdb.shodan.io</a></td></tr></tbody></table>

## 16.2 Scan/exploitation telemetry

<table><thead><tr><th width="88.37109375" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>GreyNoise Visualizer</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://viz.greynoise.io/">viz.greynoise.io</a><br><br><strong><code>Access / Cost</code>:</strong> Free tier / paid plans</td><td><strong><code>Relevance</code>:</strong> Internet scanning/exploitation telemetry.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Helps separate background scanning from targeted activity.</td></tr><tr><td align="right">2</td><td><strong>GreyNoise API docs</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://docs.greynoise.io/">docs.greynoise.io</a><br><br><strong><code>Access / Cost</code>:</strong> Free tier / paid plans; API key required</td><td><strong><code>Relevance</code>:</strong> API docs for GreyNoise enrichment.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for automated telemetry enrichment.</td></tr><tr><td align="right">3</td><td><strong>Shadowserver</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.shadowserver.org/">www.shadowserver.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free for eligible organizations; registration may be required</td><td><strong><code>Relevance</code>:</strong> Internet-scale exposure &#x26; threat telemetry.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Good for population-level exposure signals.</td></tr><tr><td align="right">4</td><td><strong>Shadowserver reports</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://dashboard.shadowserver.org/">dashboard.shadowserver.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free for eligible organizations; login/registration may be required</td><td><strong><code>Relevance</code>:</strong> Shadowserver reporting dashboard.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Access/eligibility may vary.</td></tr><tr><td align="right">5</td><td><strong>SANS Internet Storm Center</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://isc.sans.edu/">isc.sans.edu</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Internet threat telemetry &#x26; diary reports.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for emergent exploitation context.</td></tr><tr><td align="right">6</td><td><strong>Honeynet Project</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.honeynet.org/">www.honeynet.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free public / open research</td><td><strong><code>Relevance</code>:</strong> Honeypot &#x26; threat research.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for attacker behavior insight.</td></tr><tr><td align="right">7</td><td><strong>DShield</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.dshield.org/">www.dshield.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free public / community</td><td><strong><code>Relevance</code>:</strong> Distributed intrusion detection &#x26; telemetry.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for broad scanning trend analysis.</td></tr><tr><td align="right">8</td><td><strong>LeakIX</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://leakix.net/">leakix.net</a><br><br><strong><code>Access / Cost</code>:</strong> Free limited access / paid plans</td><td><strong><code>Relevance</code>:</strong> Exposed service &#x26; leak search.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for exposure assessment.</td></tr><tr><td align="right">9</td><td><strong>urlscan.io</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://urlscan.io/">urlscan.io</a><br><br><strong><code>Access / Cost</code>:</strong> Free tier / paid plans</td><td><strong><code>Relevance</code>:</strong> URL scanning &#x26; web telemetry.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for phishing, web exposure, &#x26; IOC enrichment.</td></tr><tr><td align="right">10</td><td><strong>VirusTotal</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.virustotal.com/">www.virustotal.com</a><br><br><strong><code>Access / Cost</code>:</strong> Free community access / paid enterprise plans</td><td><strong><code>Relevance</code>:</strong> File, URL, domain, &#x26; IP reputation.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for malware/IOC enrichment; licensing constraints apply.</td></tr><tr><td align="right">11</td><td><strong>VirusTotal API</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://docs.virustotal.com/reference/overview">docs.virustotal.com/reference/overview</a><br><br><strong><code>Access / Cost</code>:</strong> Free community API / paid enterprise API</td><td><strong><code>Relevance</code>:</strong> VirusTotal API documentation.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> API quota &#x26; data-sharing policies matter.</td></tr></tbody></table>

## 16.3 Attack surface management context

<table><thead><tr><th width="89.91796875" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>Amass</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/owasp-amass/amass">github.com/owasp-amass/amass</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Attack surface mapping &#x26; DNS enumeration.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for external asset discovery.</td></tr><tr><td align="right">2</td><td><strong>ProjectDiscovery Subfinder</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/projectdiscovery/subfinder">github.com/projectdiscovery/subfinder</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Subdomain discovery.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for asset inventory enrichment.</td></tr><tr><td align="right">3</td><td><strong>httpx</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/projectdiscovery/httpx">github.com/projectdiscovery/httpx</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> HTTP probing toolkit.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for validating exposed services.</td></tr><tr><td align="right">4</td><td><strong>Naabu</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/projectdiscovery/naabu">github.com/projectdiscovery/naabu</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Port scanner.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for fast exposure discovery.</td></tr><tr><td align="right">5</td><td><strong>Nmap</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://nmap.org/">nmap.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source</td><td><strong><code>Relevance</code>:</strong> Network discovery &#x26; security auditing.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Mature scanner for service detection &#x26; scripts.</td></tr><tr><td align="right">6</td><td><strong>Masscan</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/robertdavidgraham/masscan">github.com/robertdavidgraham/masscan</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> High-speed port scanner.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Use carefully; scan authorization &#x26; network impact matter.</td></tr></tbody></table>

## Discussion

This chapter section keeps the latest table structure, source titles, access/cost fields, relevance notes, & operational notes from the source inventory. Review the table entries as ingestion candidates, then validate source freshness, licensing, authentication requirements, & link-check behavior before production use.

***

#### [Back to Index](/vulnkeeper/index.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://breachtrace.gitbook.io/vulnkeeper/chapter-f/16-16-exposure-internet-facing-asset-and-threat-telemetry.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
