Skip to content
Back to skills

Censys

ASecurity

Censys search engine for internet-connected hosts, TLS certificates, and web properties. Use when: certificate transparency monitoring, finding hosts by certificate fingerprint, alternative to Shodan for TLS/SSL analysis, discovering hosts running specific services, or tracking infrastructure changes via cert issuance.

  • 142 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added May 27, 2026
devopspythongobashgitapisecurity

Works with

  • cursor
  • terminal
  • cli
  • api

Security analysis

A96/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 2 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add TerminalSkills/skills --skill censys --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Censys?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Censys
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/terminalskills-censys/badge)](https://www.skillsdirectory.com/skills/terminalskills-censys)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: censys
description: >-
  Censys search engine for internet-connected hosts, TLS certificates, and web properties. Use when:
  certificate transparency monitoring, finding hosts by certificate fingerprint, alternative to
  Shodan for TLS/SSL analysis, discovering hosts running specific services, or tracking infrastructure
  changes via cert issuance.
license: Apache-2.0
compatibility: "Python 3.9+"
metadata:
  author: terminal-skills
  version: "1.1.0"
  category: research
  tags: [censys, certificates, tls, attack-surface, recon]
  repository: https://github.com/censys/censys-sdk-python
  use-cases:
    - "Find all IP addresses serving a TLS certificate for a target domain"
    - "Monitor certificate transparency logs for newly issued certs for a domain"
    - "Discover hosts running a specific service version across the internet"
    - "Find shadow IT infrastructure using TLS certificate common names"
  agents: [claude-code, openai-codex, gemini-cli, cursor]
---

# Censys

## Overview

Censys continuously scans the entire internet and indexes every reachable host, certificate, and web property with details about open ports, TLS/SSL certificates, service banners, and configurations. Censys is particularly strong for certificate-based discovery — it indexes certificate transparency logs and lets you pivot from certificate subject names to IP addresses and vice versa, which is excellent for finding unknown infrastructure tied to a target organization.

Censys retired its old Search v1/v2 API and the `censys` PyPI package in favor of the unified **Censys Platform**, queried with **CenQL** (Censys Query Language) through the `censys-platform` SDK or the `censys search` CLI. Authenticate with a Personal Access Token, not the old API ID/secret pair.

**Requires:** a Censys account and a Personal Access Token (create one from the Platform console under your user menu → API Access). Free accounts get a limited monthly search-credit allowance that Censys adjusts over time — check the current limits on your account's billing page rather than assuming a fixed number.

## Instructions

### Step 1: Install and authenticate

```bash
pip install censys-platform
```

```bash
export CENSYS_API_KEY="your-personal-access-token"
export CENSYS_ORGANIZATION_ID="your-organization-id"      # shown on the Personal Access Tokens page
```

```python
import os
from censys_platform import SDK

sdk = SDK(
    organization_id=os.environ["CENSYS_ORGANIZATION_ID"],
    personal_access_token=os.environ["CENSYS_API_KEY"],
)
```

`SDK` is also a context manager (`with SDK(...) as sdk:`), which closes the underlying HTTP session for you. Every method has an `_async` counterpart (`sdk.global_data.search_async(...)`) for use inside `asyncio` code.

### Step 2: Search with CenQL

CenQL queries start with a dataset prefix — `host.`, `cert.`, or `webproperty.` — and use `=` for an exact, case-sensitive match or `:` for a case-insensitive tokenized match.

```python
def search_hosts(query, page_size=50, fields=None):
    """Search the Censys Platform for hosts matching a CenQL query."""
    if fields is None:
        fields = [
            "host.ip",
            "host.services.port",
            "host.services.protocol",
            "host.autonomous_system.name",
            "host.location.country",
        ]

    res = sdk.global_data.search(search_query_input_body={
        "query": query,
        "fields": fields,
        "page_size": page_size,
    })

    for hit in res.result.hits:
        print(hit)
    return res

# Hosts serving a TLS cert naming a domain (any SAN)
search_hosts('host.services.cert.names = "beacontowersecurity.com"')

# Exposed Redis instances outside an internal range
search_hosts('host.services: (protocol = "REDIS") and not host.ip: "10.0.0.0/8"')

# Hosts in a specific organization's ASN, on port 443
search_hosts('host.autonomous_system.organization = "Beacon Tower Security" and host.services.port = 443')
```

### Step 3: Look up a specific host or certificate

```python
host = sdk.global_data.get_host(host="203.0.113.42")
print(host.result.ip, host.result.autonomous_system, host.result.location)

cert = sdk.global_data.get_certificate(fingerprint="a1b2c3d4e5f6...")
print(cert.result.names, cert.result.issuer)
```

### Step 4: Certificate-based discovery

```python
def find_hosts_by_domain_cert(domain):
    """Find hosts serving a TLS certificate that names this domain (any SAN)."""
    res = sdk.global_data.search(search_query_input_body={
        "query": f'host.services.cert.names = "{domain}"',
        "fields": ["host.ip", "host.services.port", "host.services.cert.names",
                   "host.autonomous_system.name", "host.location.country"],
        "page_size": 100,
    })
    for hit in res.result.hits:
        print(hit)
    return res

find_hosts_by_domain_cert("beacontowersecurity.com")
```

### Step 5: Aggregate and export

```python
# Distribution of countries for hosts running nginx
agg = sdk.global_data.aggregate(
    aggregation_input_body={
        "query": 'host.services.endpoints.http.headers: (key = "Server" and value = "nginx")',
        "field": "host.location.country",
        "num_buckets": 15,
    }
)
for bucket in agg.result.buckets:
    print(bucket.key, bucket.count)
```

```bash
# The Platform CLI (cencli) mirrors the SDK for one-off lookups and scripting.
# It ships as a standalone binary, not a pip package.
brew install censys/tap/cencli
censys auth login
censys search 'host.services.cert.names = "beacontowersecurity.com"'
```

## Examples

### Example 1: "Find every IP serving a TLS cert for beacontowersecurity.com, including subdomains"

```python
find_hosts_by_domain_cert("beacontowersecurity.com")
```

Result: prints each matching host's IP, open port, the certificate's subject/SAN names, issuer, ASN, and country — including boxes the security team never registered in DNS but that still present a valid cert for the domain (shadow IT).

### Example 2: "See which countries host the most nginx servers in our ASN before a security review"

```python
agg = sdk.global_data.aggregate(
    aggregation_input_body={
        "query": 'host.services.endpoints.http.headers: (key = "Server" and value = "nginx") '
                 'and host.autonomous_system.asn = 16509',
        "field": "host.location.country",
        "num_buckets": 10,
    }
)
for bucket in agg.result.buckets:
    print(bucket.key, bucket.count)
```

Result: a ranked list of countries by nginx host count within ASN 16509, letting the reviewer spot an unexpected region before pulling the full per-host detail.

## CenQL Reference

| Query | Description |
|-------|-------------|
| `host.services.port = 443` | Hosts with port 443 open |
| `host.services: (protocol = "HTTP")` | Hosts running HTTP |
| `host.services.cert.names = "beacontowersecurity.com"` | Any TLS cert naming the domain |
| `cert.names: "beacontowersecurity.com"` | Certificate records (not hosts) naming the domain |
| `host.autonomous_system.name = "AMAZON-02"` | Hosts in a named ASN |
| `host.autonomous_system.asn = 16509` | Hosts in ASN 16509 |
| `host.location.country = "Germany"` | Hosts in Germany |
| `host.ip: "198.51.100.0/24"` | Hosts in a CIDR range |
| `webproperty.services.http.response.html_title: "Kibana"` | Exposed Kibana instances |

## Guidelines

- **Certificate pivoting**: pivoting from a known domain → certificate → IPs → more domains is the most powerful Censys use case; it often reveals shadow IT and forgotten assets.
- **Credits, not a fixed quota**: Platform usage is metered in search credits that vary by plan; preview counts with an aggregation query before pulling full result pages.
- **Combine with Shodan**: Censys and Shodan index different things. Censys is stronger on TLS/certificate data; Shodan is stronger on IoT and raw service banners.
- **Legacy SDK is retired**: code using `from censys.search import CensysHosts` or the old `services.*:` query syntax targets the discontinued Search v1/v2 API — migrate it to `censys-platform` and CenQL.
- **SDK vs REST**: the SDK handles auth headers, pagination, and retries; prefer it over hand-built REST calls against the Platform API.

Files in this skill

  • SKILL.md10.4 KB
  • _scores.json1.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…