ips
(required): List of IP addresses to lookup (e.g., ['8.8.8.8', '1.1.1.1'])
How to use it
ips is exposed by the Shodan MCP Server MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the ips tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
FULL SHODAN MCP SERVER LISTINGOther tools in Shodan MCP Server (39)
(required): Network range in CIDR notation (e.g., 192.168.1.0/24)
(optional): Optional country code to limit search (e.g., 'US', 'DE')
(optional): CPE 2.3 string to search for (e.g., 'cpe:2.3:a:apache:log4j:\')
(required): CVE ID to look up (e.g., 'CVE-2021-44228')
(required): Type of IoT device to search for (e.g., 'webcam', 'router', 'smart tv')
Resolve hostnames to IP addresses using DNS lookup.
(required): Domain name to look up SSL certificates for (e.g., example.com)
(optional): End date for filtering CVEs (YYYY-MM-DD format)
(optional): List of facets to include in the search results (e.g., ['country', 'org'])
(optional): List of fields to include in the results (e.g., ['ipstr', 'ports', 'location.countryname'])
Get detailed information about a specific CVE.
Get comprehensive domain information including subdomains and DNS records.
Get the count of hosts matching a search query without consuming query credits.
Get detailed information about a specific IP address.
Get SSL certificate information for a domain.
(optional): Include historical DNS data (default: false)
(required): List of hostnames to resolve (e.g., ['google.com', 'facebook.com'])
(required): IP address to look up
(optional): Filter for Known Exploited Vulnerabilities only
(optional): Maximum number of results to return (default: 10)
List all ports that Shodan crawls on the Internet.
List all protocols that can be used when performing on-demand Internet scans.
List all available search facets that can be used with Shodan queries.
List all available search filters that can be used in Shodan queries.
(optional): Maximum number of items to include in arrays (default: 5)
(optional): Page number for results pagination (default: 1)
Parse a search query to understand which filters and parameters are being used.
(optional): Product name to search for vulnerabilities (e.g., 'apache', 'windows')
(required): Shodan search query (e.g., 'apache country:US')
Get hostnames for IP addresses using reverse DNS lookup.
Scan a network range (CIDR notation) for devices.
Search for vulnerabilities with various filters.
Search for specific types of IoT devices.
Search Shodan's database for devices and services.
(optional): Number of results to skip for pagination (default: 0)
(optional): Sort results by EPSS score (Exploit Prediction Scoring System)
(optional): Start date for filtering CVEs (YYYY-MM-DD format)
(optional): Whether to return a summary of the results instead of the full data (default: false)
(optional): DNS record type filter (A, AAAA, CNAME, NS, SOA, MX, TXT)