Shodan CLI
shodan search <query>
Command-line interface for the internet-connected device search engine, Shodan.
To discover exposed hosts, services, and devices of a target without directly interacting with its network. Ideal for finding forgotten infrastructure (e.g., development servers, cameras, routers, printers) that have open ports. In the OSINT phase, it's the first tool I use to see if the client has things hanging on the internet that shouldn't be.
If you don't have an API key (limited free plan) or if the target uses Cloudflare/CDN that hides real IPs. Also, if the client is small and doesn't have much internet presence, the search may yield no results.