AcademyWorkflowsOperations

Weekly Shodan Query: reports unexpected open ports

Security and IT operations teams that want a weekly check that public-facing hosts expose only the expected ports.

  • Recommendedour rating
  • 5,359views on n8n
Open on n8n.io ↗

Paste it straight onto an n8n canvas with Ctrl+V or Cmd+V.

weekly-shodan-query-report-accidents.json

Loading the file...

What it does

An n8n workflow that runs every Monday at 5:00 AM and checks a list of watched IP addresses against Shodan. It compares the ports Shodan reports with the ports you expect, and each unexpected port is collected with its service details. The findings are formatted as a table and raised as a medium-severity alert in TheHive.

Use cases

  1. 01Flagging a port opened on a server by mistake
  2. 02Creating a TheHive alert for each unexpected service
  3. 03Sharing a weekly table of exposed services with IT

Connects

HTTP Request · TheHive · HTML

Questions about
Weekly Shodan Query: reports unexpected open ports.

What is Weekly Shodan Query: reports unexpected open ports used for?

Security and IT operations teams that want a weekly check that public-facing hosts expose only the expected ports. An n8n workflow that runs every Monday at 5:00 AM and checks a list of watched IP addresses against Shodan. It compares the ports Shodan reports with the ports you expect, and each unexpected port is collected with its service details. The findings are formatted as a table and raised as a medium-severity alert in TheHive.

How do I import Weekly Shodan Query: reports unexpected open ports into n8n?

Copy the workflow JSON from this page and paste it onto the n8n canvas with Ctrl+V or Cmd+V. Then connect your credentials in each node.

Is Weekly Shodan Query: reports unexpected open ports safe to use?

It passed our automatic scan for credential theft, hidden instructions and risky install commands. Third party open source software. Sabemos AI does not maintain it. Check the code and permissions before you connect it to company data.