MCPVault

ip

MCP tool from Shodan MCP Server by Cyreslab-AI

(required): IP address to look up

How to use it

ip is exposed by the Shodan MCP Server MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the ip tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.

FULL SHODAN MCP SERVER LISTING

Other tools in Shodan MCP Server (39)

cidr

(required): Network range in CIDR notation (e.g., 192.168.1.0/24)

country

(optional): Optional country code to limit search (e.g., 'US', 'DE')

cpe23

(optional): CPE 2.3 string to search for (e.g., 'cpe:2.3:a:apache:log4j:\')

cve_id

(required): CVE ID to look up (e.g., 'CVE-2021-44228')

device_type

(required): Type of IoT device to search for (e.g., 'webcam', 'router', 'smart tv')

dns_lookup

Resolve hostnames to IP addresses using DNS lookup.

domain

(required): Domain name to look up SSL certificates for (e.g., example.com)

end_date

(optional): End date for filtering CVEs (YYYY-MM-DD format)

facets

(optional): List of facets to include in the search results (e.g., ['country', 'org'])

fields

(optional): List of fields to include in the results (e.g., ['ipstr', 'ports', 'location.countryname'])

get_cve_info

Get detailed information about a specific CVE.

get_domain_info

Get comprehensive domain information including subdomains and DNS records.

get_host_count

Get the count of hosts matching a search query without consuming query credits.

get_host_info

Get detailed information about a specific IP address.

get_ssl_info

Get SSL certificate information for a domain.

history

(optional): Include historical DNS data (default: false)

hostnames

(required): List of hostnames to resolve (e.g., ['google.com', 'facebook.com'])

ips

(required): List of IP addresses to lookup (e.g., ['8.8.8.8', '1.1.1.1'])

is_kev

(optional): Filter for Known Exploited Vulnerabilities only

limit

(optional): Maximum number of results to return (default: 10)

list_ports

List all ports that Shodan crawls on the Internet.

list_protocols

List all protocols that can be used when performing on-demand Internet scans.

list_search_facets

List all available search facets that can be used with Shodan queries.

list_search_filters

List all available search filters that can be used in Shodan queries.

max_items

(optional): Maximum number of items to include in arrays (default: 5)

page

(optional): Page number for results pagination (default: 1)

parse_search_tokens

Parse a search query to understand which filters and parameters are being used.

product

(optional): Product name to search for vulnerabilities (e.g., 'apache', 'windows')

query

(required): Shodan search query (e.g., 'apache country:US')

reverse_dns_lookup

Get hostnames for IP addresses using reverse DNS lookup.

scan_network_range

Scan a network range (CIDR notation) for devices.

search_cves

Search for vulnerabilities with various filters.

search_iot_devices

Search for specific types of IoT devices.

search_shodan

Search Shodan's database for devices and services.

skip

(optional): Number of results to skip for pagination (default: 0)

sort_by_epss

(optional): Sort results by EPSS score (Exploit Prediction Scoring System)

start_date

(optional): Start date for filtering CVEs (YYYY-MM-DD format)

summarize

(optional): Whether to return a summary of the results instead of the full data (default: false)

type

(optional): DNS record type filter (A, AAAA, CNAME, NS, SOA, MX, TXT)