Censys api
Cyber Threat Intelligence Skills for each stage of the CTI Lifecycle.
npx -y skills add Liberty91LTD/cti-skills --skill censys-apiAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 8 stars8 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Censys API v2 reference. Host reconnaissance and certificate data.
SKILL.md
2.3 KB, as published. Nobody here has run it
Censys API v2
Base URL
https://search.censys.io/api/v2
Authentication
Basic Auth: $CENSYS_API_ID:$CENSYS_API_SECRET
curl -s "https://search.censys.io/api/v2/hosts/{ip}" \
-u "$CENSYS_API_ID:$CENSYS_API_SECRET"
Rate Limits
- Free: 250 queries/month, 5 results/query
- Paid: Higher limits based on plan
Important: Free tier is very limited. Use selectively — prioritise high-value lookups.
Key Endpoints
View Host
curl -s "https://search.censys.io/api/v2/hosts/{ip}" \
-u "$CENSYS_API_ID:$CENSYS_API_SECRET"
Useful fields:
result.services[]— port, service_name, transport_protocol, bannerresult.services[].tls.certificates— TLS certificate chainresult.autonomous_system— ASN inforesult.location— geographic locationresult.operating_system— OS detectionresult.last_updated_at— scan freshness
Search Hosts
curl -s "https://search.censys.io/api/v2/hosts/search?q={query}" \
-u "$CENSYS_API_ID:$CENSYS_API_SECRET"
Search syntax: services.port: 443 AND services.tls.certificates.leaf_data.subject.common_name: example.com
View Certificate
curl -s "https://search.censys.io/api/v2/certificates/{fingerprint}" \
-u "$CENSYS_API_ID:$CENSYS_API_SECRET"
Common Search Queries
ip: {ip}— specific hostservices.tls.certificates.leaf_data.subject.common_name: {domain}— hosts with cert for domainservices.http.response.body_hash: {hash}— hosts serving same contentservices.jarm.fingerprint: {jarm}— hosts with same JARM fingerprint (C2 detection)labels: {label}— Censys-labeled hosts
CTI Value
Censys excels at:
- Certificate transparency analysis (finding related infrastructure)
- JARM fingerprinting (identifying C2 frameworks)
- Service banner analysis
- Historical infrastructure changes
Response Summary Format
ip: <IP>
services:
- port: <port>
service: <name>
banner: <truncated>
certificates:
- subject_cn: <common name>
issuer: <issuer>
valid_from: <date>
valid_to: <date>
autonomous_system:
asn: <number>
name: <name>
location:
country: <country>
city: <city>
last_updated: <date>