\documentclass[10pt,a4paper]{article} % Packages \usepackage{fancyhdr} % For header and footer \usepackage{multicol} % Allows multicols in tables \usepackage{tabularx} % Intelligent column widths \usepackage{tabulary} % Used in header and footer \usepackage{hhline} % Border under tables \usepackage{graphicx} % For images \usepackage{xcolor} % For hex colours %\usepackage[utf8x]{inputenc} % For unicode character support \usepackage[T1]{fontenc} % Without this we get weird character replacements \usepackage{colortbl} % For coloured tables \usepackage{setspace} % For line height \usepackage{lastpage} % Needed for total page number \usepackage{seqsplit} % Splits long words. %\usepackage{opensans} % Can't make this work so far. Shame. Would be lovely. \usepackage[normalem]{ulem} % For underlining links % Most of the following are not required for the majority % of cheat sheets but are needed for some symbol support. \usepackage{amsmath} % Symbols \usepackage{MnSymbol} % Symbols \usepackage{wasysym} % Symbols %\usepackage[english,german,french,spanish,italian]{babel} % Languages % Document Info \author{himajedi} \pdfinfo{ /Title (censys-search.pdf) /Creator (Cheatography) /Author (himajedi) /Subject (Censys Search Cheat Sheet) } % Lengths and widths \addtolength{\textwidth}{6cm} \addtolength{\textheight}{-1cm} \addtolength{\hoffset}{-3cm} \addtolength{\voffset}{-2cm} \setlength{\tabcolsep}{0.2cm} % Space between columns \setlength{\headsep}{-12pt} % Reduce space between header and content \setlength{\headheight}{85pt} % If less, LaTeX automatically increases it \renewcommand{\footrulewidth}{0pt} % Remove footer line \renewcommand{\headrulewidth}{0pt} % Remove header line \renewcommand{\seqinsert}{\ifmmode\allowbreak\else\-\fi} % Hyphens in seqsplit % This two commands together give roughly % the right line height in the tables \renewcommand{\arraystretch}{1.3} \onehalfspacing % Commands \newcommand{\SetRowColor}[1]{\noalign{\gdef\RowColorName{#1}}\rowcolor{\RowColorName}} % Shortcut for row colour \newcommand{\mymulticolumn}[3]{\multicolumn{#1}{>{\columncolor{\RowColorName}}#2}{#3}} % For coloured multi-cols \newcolumntype{x}[1]{>{\raggedright}p{#1}} % New column types for ragged-right paragraph columns \newcommand{\tn}{\tabularnewline} % Required as custom column type in use % Font and Colours \definecolor{HeadBackground}{HTML}{333333} \definecolor{FootBackground}{HTML}{666666} \definecolor{TextColor}{HTML}{333333} \definecolor{DarkBackground}{HTML}{FF5200} \definecolor{LightBackground}{HTML}{FFF4EF} \renewcommand{\familydefault}{\sfdefault} \color{TextColor} % Header and Footer \pagestyle{fancy} \fancyhead{} % Set header to blank \fancyfoot{} % Set footer to blank \fancyhead[L]{ \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{C} \SetRowColor{DarkBackground} \vspace{-7pt} {\parbox{\dimexpr\textwidth-2\fboxsep\relax}{\noindent \hspace*{-6pt}\includegraphics[width=5.8cm]{/web/www.cheatography.com/public/images/cheatography_logo.pdf}} } \end{tabulary} \columnbreak \begin{tabulary}{11cm}{L} \vspace{-2pt}\large{\bf{\textcolor{DarkBackground}{\textrm{Censys Search Cheat Sheet}}}} \\ \normalsize{by \textcolor{DarkBackground}{himajedi} via \textcolor{DarkBackground}{\uline{cheatography.com/196419/cs/41272/}}} \end{tabulary} \end{multicols}} \fancyfoot[L]{ \footnotesize \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{LL} \SetRowColor{FootBackground} \mymulticolumn{2}{p{5.377cm}}{\bf\textcolor{white}{Cheatographer}} \\ \vspace{-2pt}himajedi \\ \uline{cheatography.com/himajedi} \\ \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Cheat Sheet}} \\ \vspace{-2pt}Published 14th November, 2023.\\ Updated 29th April, 2024.\\ Page {\thepage} of \pageref{LastPage}. \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Sponsor}} \\ \SetRowColor{white} \vspace{-5pt} %\includegraphics[width=48px,height=48px]{dave.jpeg} Measure your website readability!\\ www.readability-score.com \end{tabulary} \end{multicols}} \begin{document} \raggedright \raggedcolumns % Set font size to small. Switch to any value % from this page to resize cheat sheet text: % www.emerson.emory.edu/services/latex/latex_169.html \footnotesize % Small font. \begin{multicols*}{2} \begin{tabularx}{8.4cm}{x{3.76 cm} x{4.24 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{IP Addresses and Subnets}} \tn % Row 0 \SetRowColor{LightBackground} Single IP ({\emph{supports IPv4 and IPv6}}) & 8.8.8.8 or \{\{nl\}\} ip:8.8.8.8 \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} Subnet by CIDR & ip: "23.0.0.0/8" \tn % Row Count 3 (+ 1) % Row 2 \SetRowColor{LightBackground} Subnet by IP Range & ip: {[}1.12.0.0 to 1.15.255.255{]} \tn % Row Count 5 (+ 2) % Row 3 \SetRowColor{white} Hostname & dns.names:"*.zip" \tn % Row Count 6 (+ 1) % Row 4 \SetRowColor{LightBackground} Autonomous System \# (ASN) & \seqsplit{autonomous\_system.asn:16509} \tn % Row Count 8 (+ 2) % Row 5 \SetRowColor{white} Autonomous System Name & \seqsplit{autonomous\_system.name:"AMAZON-02"} \{\{nl\}\} \tn % Row Count 10 (+ 2) % Row 6 \SetRowColor{LightBackground} IPv6 hosts & ip: "2001::/3" or \{\{nl\}\} labels:ipv6 \tn % Row Count 12 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{3.6 cm} x{4.4 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Ports, Protocols, and Software}} \tn % Row 0 \SetRowColor{LightBackground} Port & services.port:22 \{\{nl\}\} services.port:\{20,21,22\} \tn % Row Count 3 (+ 3) % Row 1 \SetRowColor{white} Service / Protocol & \seqsplit{services.service\_name:SSH} \tn % Row Count 5 (+ 2) % Row 2 \SetRowColor{LightBackground} Transport protocol & \seqsplit{services.transport\_protocol:TCP} \tn % Row Count 7 (+ 2) % Row 3 \SetRowColor{white} Software by product and/or vendor & services: \seqsplit{(software.vendor:"Apache"} AND \seqsplit{software.product:"HTTPD")} \tn % Row Count 10 (+ 3) % Row 4 \SetRowColor{LightBackground} Software by URI / CPE & services.software.cpe =\textbackslash{}`cpe:2.3:o:mikrotik:routeros:{\emph{:}}:{\emph{:}}:{\emph{:}}:{\emph{:}}\textbackslash{}` \tn % Row Count 14 (+ 4) % Row 5 \SetRowColor{white} Banner grab & \seqsplit{services.banner:"HTTP/"} \tn % Row Count 16 (+ 2) % Row 6 \SetRowColor{LightBackground} Device type & services.software: (other.key:"Device" and other.value:"Router") \tn % Row Count 19 (+ 3) % Row 7 \SetRowColor{white} Number of open ports on host & service\_count: {[}1 to 20{]} \tn % Row Count 21 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{2.16 cm} x{5.84 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Geography}} \tn % Row 0 \SetRowColor{LightBackground} Country & location.country:"United States" \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} City & location.city:"Ann Arbor" \tn % Row Count 3 (+ 1) % Row 2 \SetRowColor{LightBackground} State & \seqsplit{location.province:"Michigan"} \tn % Row Count 4 (+ 1) % Row 3 \SetRowColor{white} GPS \seqsplit{Coordinates} & \seqsplit{(location.coordinates.latitude=41.85003} AND \seqsplit{location.coordinates.longitude=-87.65005)} \tn % Row Count 7 (+ 3) \hhline{>{\arrayrulecolor{DarkBackground}}--} \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{{\bf{Pro tip:}} Use \{\{link="https://workshop.censys.io/map-to-censys/"\}\}Map To Censys\{\{/link\}\} to draw a box over the geographic area of interest and click "Open in Search" to see hosts in the area} \tn \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{3.36 cm} x{4.64 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Labels}} \tn % Row 0 \SetRowColor{LightBackground} search by label & labels:`\textless{}label-name\textgreater{}` \tn % Row Count 1 (+ 1) \hhline{>{\arrayrulecolor{DarkBackground}}--} \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Labels provide broad context about a host or service. {\bf{Some useful host labels:}} c2, login-page, open-dir, ics, network.device, cryptocurrency, managed-file-transfer, ipv6, tarpit, honeypot.} \tn \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{2.64 cm} x{5.36 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Handy Censys Search CLI JQ filters}} \tn % Row 0 \SetRowColor{LightBackground} List of IP addresses & '.{[}{]}.ip' \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} Banners & '.{[}{]} | .ip as \$ip | .services{[}{]} | {[} \$ip, .transport\_protocol, .port, .service\_name, .banner {]}' \tn % Row Count 6 (+ 4) \hhline{>{\arrayrulecolor{DarkBackground}}--} \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Usage: `censys search \textless{}query\textgreater{} | jq \textless{}filter\textgreater{}`} \tn \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{4 cm} x{4 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Web Entities (HTTP/S)}} \tn % Row 0 \SetRowColor{LightBackground} HTML Title & \seqsplit{services.http.response.html\_title:"dashboard"} \tn % Row Count 3 (+ 3) % Row 1 \SetRowColor{white} Response Body - plaintext or hash & \seqsplit{services.http.response.body:"login"} or \seqsplit{services.http.response.body\_hashes:*} \tn % Row Count 7 (+ 4) % Row 2 \SetRowColor{LightBackground} Status code & \seqsplit{services.http.response.status\_code=200} \tn % Row Count 9 (+ 2) % Row 3 \SetRowColor{white} Server header & \seqsplit{services.http.response.headers:} (key: `Server` and value.headers: `nginx`) \tn % Row Count 13 (+ 4) % Row 4 \SetRowColor{LightBackground} Certificate Issuer & \seqsplit{services.tls.certificates.leaf\_data.issuer.organization:"Let's} Encrypt" \tn % Row Count 17 (+ 4) % Row 5 \SetRowColor{white} Certificate Subject Common Name & \seqsplit{services.tls.certificates.leaf\_data.subject.common\_name:`*.herokuapp.com`} \tn % Row Count 21 (+ 4) % Row 6 \SetRowColor{LightBackground} TLS version \{\{nl\}\} ({\emph{Highest negotiated version}}) & \seqsplit{services.tls.version\_selected:"TLSv1\_1"} \tn % Row Count 24 (+ 3) % Row 7 \SetRowColor{white} Favicon MD5 Hash & \seqsplit{services.http.response.favicons.md5\_hash:*} \tn % Row Count 27 (+ 3) % Row 8 \SetRowColor{LightBackground} Favicon Shodan Hash (mmh3) & \seqsplit{services.http.response.favicons.shodan\_hash:*} \tn % Row Count 30 (+ 3) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{4 cm} x{4 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Use Case Examples}} \tn % Row 0 \SetRowColor{LightBackground} Hacked web servers & services: \seqsplit{(service\_name:"HTTP"} and \seqsplit{http.response.html\_title:"hacked} by") \tn % Row Count 4 (+ 4) % Row 1 \SetRowColor{white} Hosts serving login pages with port 22 open & services.port:22 and labels:`login-page` \tn % Row Count 7 (+ 3) % Row 2 \SetRowColor{LightBackground} Servers in Russia running remote access protocols & \seqsplit{location.country:"Russia"} and \seqsplit{labels:`remote-access`} \tn % Row Count 10 (+ 3) % Row 3 \SetRowColor{white} Filter out hosts with 100+ ports open & services.truncated: false \tn % Row Count 12 (+ 2) % Row 4 \SetRowColor{LightBackground} Compromised MikroTik routers & \seqsplit{services.service\_name:} MIKROTIK\_BW and "HACKED" \tn % Row Count 15 (+ 3) % Row 5 \SetRowColor{white} Filter out honeypots and noisy hosts & not labels:\{'honeypot', 'tarpit', 'truncated'\} \tn % Row Count 18 (+ 3) % Row 6 \SetRowColor{LightBackground} RDP running on nonstandard ports & services: \seqsplit{(service\_name="RDP"} and NOT port=3389) \tn % Row Count 21 (+ 3) \hhline{>{\arrayrulecolor{DarkBackground}}--} \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{{\bf{Pro tip}}: Get more results by including virtual hosts -{}- click the gear icon and toggle {\bf{Virtual Hosts: `INCLUDE`}}} \tn \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{4 cm} x{4 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Certificates}} \tn % Row 0 \SetRowColor{LightBackground} Unexpired certificates for a specific domain & labels=`unexpired` and names: censys.io \tn % Row Count 3 (+ 3) % Row 1 \SetRowColor{white} Self-signed certificates observed in Censys host scans & \seqsplit{ever\_seen\_in\_scan:} true and labels: "self-signed" \tn % Row Count 6 (+ 3) % Row 2 \SetRowColor{LightBackground} Trusted certs from a specific CA expiring on specific day & \seqsplit{parsed.issuer.organization:} "Let's Encrypt" and labels: "trusted" and \seqsplit{parsed.validity\_period.not\_after:} 2023-10-13 \tn % Row Count 12 (+ 6) \hhline{>{\arrayrulecolor{DarkBackground}}--} \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Learn more about the data collected in our certificates dataset: \seqsplit{https://search.censys.io/search/definitions?resource=certificates}} \tn \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} % That's all folks \end{multicols*} \end{document}