Last active
February 25, 2021 11:19
-
-
Save n0x08/0f793b26ce922ae0865fd7d02fe5682f to your computer and use it in GitHub Desktop.
Lookup IP address against greynoise.io and shodan
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# !/usr/bin/env python | |
# shoGrey_ip.py | |
# | |
# Stupid simple IP lookup against Greynoise.io | |
# Also looks up against Shodan and returns ports, tags, vulns | |
# requires json, requests, shodan | |
# | |
# Also requires Shodan API key | |
# | |
# Example: python3 shoGrey_ip.py 1.2.3.4 | |
# | |
import sys | |
import json | |
import requests | |
import shodan | |
headers = {'key': '[INSERT GREYNOISE API KEY HERE]'} | |
SHODAN_API_KEY = "[INSERT SHODAN API HERE]" | |
api = shodan.Shodan(SHODAN_API_KEY) | |
bots = {} | |
ip = sys.argv[1] | |
gnr = requests.get('https://enterprise.api.greynoise.io/v2/noise/context/' + ip, headers = headers) #V2 IP API lookup | |
data = gnr.json() | |
try: | |
host = api.host(ip) | |
tags = host['tags'] | |
vulns = host['vulns'] | |
ports = host['ports'] | |
data['shodan_tags'] = tags | |
data['vulns'] = vulns | |
data['open_ports'] = ports | |
# Compare open Shodan ports against GN scan ports to find bots | |
for i in data['raw_data'].get('scan'): | |
if i['port'] in host['ports']: | |
key = i['port'] | |
bots[key] = 'True' | |
data['bots'] = bots | |
except: | |
pass | |
json_str = json.dumps(data, indent=4, sort_keys=False) | |
print(json_str) |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment