Censys
Search and discovery for internet-facing assets: certificates, hosts, services, and vulnerabilities across the entire internet.
Open the official app on search.censys.io
This tool is hosted by its maintainers. Click below to open search.censys.io in a new tab — it's their official demo.
Browse network tools →What's next with Censys?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Censys?
Censys is an open-source platform designed to help information security professionals discover, monitor, and analyze internet-exposed devices. By systematically scanning public IP addresses and popular domain names, it collects data on networked systems and enriches it with contextual insights. The platform provides an interactive search engine and APIs to query this data, enabling users to assess risks and vulnerabilities. Enterprises leverage Censys to map their attack surfaces, while CERTs and researchers use it to identify emerging threats and evaluate their global impact. It addresses the challenge of understanding an organization's exposure to cyber risks by offering real-time visibility into internet-facing assets and their associated security postures.
How it works
Censys operates by continuously probing public IP addresses and domains to gather data on connected devices. This data is curated and structured to provide actionable insights for security teams. Its primary purpose is to bridge the gap between raw network data and meaningful security intelligence, enabling users to prioritize threats and respond to vulnerabilities proactively. Censys offers scalable scanning of internet-facing assets, with APIs for programmatic access to results. Its search engine allows filtering by criteria like operating system, service versions, and vulnerabilities.
How to use it
- 1Register for a Censys account to obtain API credentials. 2. Install the censys-python SDK via pip. 3. Authenticate using your API key to access search and scan functionalities. 4. Query the API to retrieve data on specific assets or vulnerabilities. Practical tips: Use the new API documentation for advanced queries, and leverage the SDK's lightweight design for integrating Censys into existing workflows.
What it can do
- internet asset search
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/Censys/censys-python
- license: Open source
- privacy: Opens an external demo
Limitations
- Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
- Deprecation of legacy Search v1/v2 APIs requires migration to the new platform
- Limited coverage of private IP addresses and non-public domains
- Dependency on public internet connectivity for scanning operations
- Potential for false positives in automated vulnerability assessments
Understanding the result
Search and discovery for internet-facing assets: certificates, hosts, services, and vulnerabilities across the entire internet.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (Censys/censys-python)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with Censys/censys-python. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
Frequently asked
What is Censys and how does it differ from traditional network scanning tools?
Censys is a cloud-based platform that systematically scans all public IP addresses and domains, providing a comprehensive view of internet-exposed assets. Unlike traditional tools that focus on internal networks, Censys offers global visibility into external threats. Its unique value lies in continuous data collection and enrichment, combining raw scan results with contextual risk analysis.
How does Censys' scanning process work technically?
Censys employs distributed scanning infrastructure to probe public IPs and domains. It uses a combination of TCP/IP protocols to detect open ports and services, then aggregates data from multiple sources including vulnerability databases. The collected data is indexed and enriched with metadata like geolocation and service-specific indicators, enabling complex search queries through its RESTful API.
How can I programmatically query Censys for devices running outdated software?
First, install the censys-python SDK and authenticate with your API key. Then, use the search API with filters like 'service.software.name' and 'service.software.version' to target specific software. For example: censys.search('service.software.name: Apache AND service.software.version: 2.2*'). Process results to identify vulnerable Apache servers and their associated IP ranges.
How does Censys compare to alternatives like Shodan or Cisco Talos?
Censys differs from Shodan by providing curated, enriched data rather than raw scan results. Compared to Cisco Talos, it offers more granular API access for custom threat analysis. While Shodan focuses on device discovery, Censys emphasizes risk scoring and integration with security operations. Each tool serves distinct needs: Censys for comprehensive asset analysis, Shodan for quick device lookups, and Talos for threat intelligence feeds.
What should I do if I receive an 'API key invalid' error?
Verify your API key was generated from the Censys dashboard and matches the scope of your request. Check for typos in the key and ensure it's correctly formatted. If the issue persists, regenerate the key in the dashboard and update it in your SDK configuration. Also, confirm your account has active subscription access to the requested API endpoints.