Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Configure and enable Shodan integration

Before you use Shodan integration, you must download it from the ServiceNow Store.

Before you begin

Role required: sn_sec_tisc.admin

Important: The Threat Intelligence Security Center and Whois Observable Enrichment plugins must be installed and active.

Download the Whois integration from the ServiceNow Store and verify you have a valid Whois account before use. For more information see, Download the integration from the ServiceNow Store.

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center > Integrations > Enrichment Integrations > All Integrations > Observable Enrichment.

  2. In the Shodan card, select Configure New Enrichment to configure the integration.

  3. Complete the Configure New Enrichment form.

FieldDescription
NameName for the new enrichment integration. For example, Shodan.
Vendor NameName of the vendor.The details of the selected vendor are auto-populated and by default this field will be read only. For example, Shodan.
Integration TypeType of integration that you selected. For example, Observable Enrichment.
DescriptionDescription for the new enrichment integration.For example, the description for Shodan integration is, Shodan helps you to analyze banner information from connected devices all around the globe.
  1. Navigate to the Integration Configuration section.

  2. Enter (or paste) the API Key you acquired from the Shodan portal.

  3. Select Save to apply the changes.

    The integration details are validated, and by default the status is inactive.

  4. Select Enable to enable the integration.

Result

After configuration, Shodan can be selected for performing enrichment on observables in Threat Intelligence Security Center.

Parent Topic:Shodan integration

Related topics

Configure Observable Enrichment