Find Exposed Servers

by useosint06243a5620b0No licenseListed Oct 8, 2026Updated Oct 8, 2026

Find internet-exposed hosts, ports, services and devices using third-party internet-scan data instead of touching the target. Covers Shodan and Censys query syntax, service banners, favicon-hash and TLS-certificate pivots, origin-IP discovery behind Cloudflare or a CDN, and exposed databases, dashboards, cameras and ICS devices. Use when asked what a company has exposed to the internet, to check open ports on an IP or netblock, or to write a Shodan filter query. Applies to external attack-surface management, third-party and vendor security review, M&A technical diligence, and pre-engagement reconnaissance. Reference at useosint.com/skills/find-exposed-servers.

Instructions only

Add to a SourceWeft workspace

  1. Open the skill in your dashboard and add it to a workspace.
  2. Enable it for the chats that should use it.

This skill is instructions only: it ships no scripts to execute.

Add to SourceWeft

You will be asked to sign in first, then taken straight to this skill.

Ask your agent to install it

Paste this prompt into Claude Code, Codex, Cursor or another agent that can run commands — or into SourceWeft chat. The agent reads this skill's install guide, shows you its source, license and scripts, and installs it with the SourceWeft CLI once you agree.

Read https://sourceweft.com/skills/gh-useosint-skills-find-exposed-servers/install.md and install the skill it describes. Before installing, show me its source, license and whether it ships scripts, and wait for my OK. Ask me before changing anything else on my machine.

Read the install guide the agent follows

Install it yourself from a terminal

For Claude Code, Codex, Cursor and other local agents. The SourceWeft CLI fetches the skill from its source repository at the commit scanned here, and verifies every file against the hashes recorded when the skill was scanned. If anything differs, nothing is written.

npx @sourceweft/cli skills install gh-useosint-skills-find-exposed-servers

Add --agent claude-code, codex, cursor or universal to choose which agent gets it (Claude Code by default).

Upstream installer — not verified by SourceWeft

The open-source skills installer fetches the same pinned commit, but does not check the files against the hashes SourceWeft recorded.

npx skills add https://github.com/useosint/skills/tree/06243a5620b0c9c97502edd4ee9e31995a3bdccd/skills/find-exposed-servers

Source and attribution

Source:useosint/skillsinskills/find-exposed-serversat commit06243a5

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from useosint/skills

Write The Intel Brief

useosint

Turn findings into a defensible intelligence product — BLUF key judgements, standardised estimative probability language, per-claim sourcing with timestamps and archived copies, separated observation, inference and assessment, documented negative findings and gaps, chain of custody and hashing, and redaction of uninvolved parties. Use when writing an intelligence report, due-diligence memo, evidence pack or executive summary, or when asked to write up an investigation so it survives challenge. Applies to regulated compliance reporting, litigation and disclosure, board and investment committee reporting, and law-enforcement referral. Reference at useosint.com/skills/write-the-intel-brief.

Awaiting classificationOct 8, 2026

X Ray A Company

useosint

Corporate due-diligence workflow — resolve a brand or website to its registered legal entity, map group structure and beneficial ownership, profile officers and directors, enumerate the digital estate, and screen litigation, insolvency, procurement, sanctions, PEP and adverse media. Use when asked to check out, vet or research a company, verify a supplier or counterparty before signing or paying, or assess whether a business is real. Applies to vendor and third-party risk, KYC and KYB onboarding, M&A and investor diligence, procurement integrity, and shell-company assessment. Reference at useosint.com/skills/x-ray-a-company.

Awaiting classificationOct 8, 2026

Whose Number Is This

useosint

Investigates a phone number through E.164 normalisation, line-type and carrier checks, app registration and reverse-lookup sources.

Research & AnalysisOct 8, 2026

Who Owns This Domain

useosint

Establish who registered and who operates a domain using WHOIS, RDAP and DNS. Use when running a whois lookup, querying RDAP, digging A, AAAA, MX, NS, TXT, SOA or CAA records, reading SPF includes, DKIM selectors or DMARC rua addresses, finding the registrar, registrant or nameservers, doing reverse DNS, PTR, ASN or netblock lookups, or hunting historical WHOIS and passive DNS. Applies to phishing and brand-abuse takedown, domain-dispute and UDRP evidence, vendor verification before payment, and infrastructure attribution. Reference at useosint.com/skills/who-owns-this-domain.

Awaiting classificationOct 8, 2026

Who Really Owns It

useosint

Research companies, directors, shareholders and ultimate beneficial ownership in official corporate registries, filings and offshore datasets — OpenCorporates, UK Companies House and the PSC register, SEC EDGAR, US Secretary of State registries, EU business registers, GLEIF LEI records, OpenOwnership, OpenSanctions and the ICIJ Offshore Leaks database. Use when asked who owns or controls a company, to find a person's other directorships, or to unpick a group structure. Applies to KYB and UBO verification, AML and sanctions screening, nominee and shell-company detection, procurement integrity, and M&A diligence. Reference at useosint.com/skills/who-really-owns-it.

Awaiting classificationOct 8, 2026

Where Was This Taken

useosint

Verifies where and when a photo or video was taken and whether it is authentic, producing a graded location finding.

Research & AnalysisOct 8, 2026