Passive IoT / ICS / IIoT Reconnaissance Engine — Stage 1
Auxular is a passive reconnaissance engine that continuously discovers and catalogues internet-exposed IoT, ICS, and IIoT devices by querying multiple open-source and free-tier threat intelligence platforms simultaneously. It normalises results from eleven sources into a unified device dataset, fingerprints industrial control system protocols, and stores output in both CSV and JSON formats for downstream analysis.
It operates silently in the background as a daemon, accumulating a master intelligence dataset over time — and can also be triggered manually against any country or organisation on demand.
- 11 passive sources queried simultaneously — Shodan, Censys, ZoomEye, FOFA, GreyNoise, BinaryEdge, Onyphe, LeakIX, Criminal IP, Hunter.how, InternetDB
- Unified device model — 30+ fields per device including IP, port, protocol, geo, ASN, org, product, vendor, version, banner, CVEs, and ICS protocol
- ICS protocol fingerprinting — Modbus, DNP3, Siemens S7, EtherNet/IP, BACnet, OPC-UA, Niagara Fox, MQTT, OMRON FINS, IEC 60870-5-104, GE SRTP, and more
- Dual output formats — CSV and NDJSON written on every run
- Master vs manual separation — scheduled scans append to persistent master files; manual queries write to isolated timestamped files that never touch the master dataset
- Daemon mode — runs continuously on a configurable interval, designed to be registered as a systemd service
- Manual mode — query by country (ISO-2 code or full name), organisation name, or both
- Rate limiting — per-source rate limiters respect free tier quotas automatically
- Deduplication — cross-source deduplication by IP/port/source fingerprint, keeping the richest record on conflict
- Threaded execution — sources run in parallel for faster scan cycles
git clone https://github.com/Calvaryyy/auxular.git
cd auxular
sudo bash install.shThe install script:
- Installs Python dependencies system-wide
- Creates an executable wrapper at
/usr/local/bin/auxular - Makes
auxularcallable from any directory on the machine
Requirements: Python 3.8+, Linux (developed and tested on Kali)
On first run, Auxular creates a default config file at ~/.auxular/config.yaml.
auxular --configAdd your API keys under each source. Sources with no key set are automatically skipped at runtime with a warning.
A template showing the full config structure is available at config.example.yaml in this repository.
| Source | Free Tier | Link |
|---|---|---|
| Shodan | ✓ | https://account.shodan.io |
| Censys | 250 queries/month | https://search.censys.io/account |
| ZoomEye | 10,000 results/month | https://www.zoomeye.org/profile |
| FOFA | 10,000 results/month | https://en.fofa.info/accountInfo |
| GreyNoise | Community tier | https://viz.greynoise.io/account |
| BinaryEdge | 250 queries/month | https://app.binaryedge.io/account/api |
| Onyphe | 1,000 results/month | https://www.onyphe.io/login |
| LeakIX | No key required | https://leakix.net/settings |
| Criminal IP | 50 credits/day | https://www.criminalip.io/mypage/information |
| Hunter.how | 100 results/month | https://hunter.how/dashboard |
| InternetDB | No key required | — |
auxular --statusauxular --scanauxular --daemonauxular --country NG
auxular --country Nigeria
auxular --country "Saudi Arabia"auxular --org "FAAN"
auxular --org "Dangote Group"
auxular --org "MTN Nigeria"auxular --country NG --org "FAAN"auxular --country NG --sources shodan,censys,zoomeyeauxular --scan --verboseauxular --install-service~/auxular_output/master/
auxular_master_20260422.csv ← appended on each run
auxular_master_20260422.json ← NDJSON, one record per line
~/auxular_output/manual/
auxular_manual_20260422_143022_country_ng.csv
auxular_manual_20260422_143022_country_ng.json
auxular_manual_20260422_151100_org_faan.csv
auxular_manual_20260422_151100_org_faan.json
Manual files are completely isolated from master files and are never appended to across runs.
| Category | Description |
|---|---|
| iot | IP cameras, DVRs, NVRs, routers, printers, VoIP adapters, smart meters, UPS |
| ics | PLCs, HMIs, RTUs, DCS, SCADA systems |
| iiot | Industrial IoT gateways, factory automation nodes, edge devices |
| building_automation | BACnet, Niagara/Fox systems |
| smart_grid | Grid automation, smart meters |
| medical_device | Network-connected medical equipment |
| Protocol | Port(s) | Domain |
|---|---|---|
| Modbus | 502, 503 | Universal ICS |
| DNP3 | 20000 | Power and water utilities |
| Siemens S7comm | 102 | Siemens PLCs |
| EtherNet/IP | 44818, 2222 | Rockwell / Allen-Bradley |
| BACnet | 47808 | Building automation |
| OPC-UA | 4840 | Modern ICS |
| Niagara Fox | 1911, 4911 | Building automation |
| MQTT / MQTT TLS | 1883, 8883 | IoT messaging |
| CoAP | 5683 | Constrained IoT |
| OMRON FINS | 9600 | Omron PLCs |
| IEC 60870-5-104 | 2404 | Power utilities |
| GE SRTP | 18245, 18246 | GE PLCs |
auxular/
├── auxular.py ← CLI entry point
├── core/
│ ├── base_source.py ← abstract base class for all sources
│ ├── config.py ← YAML config manager
│ ├── daemon.py ← continuous scan loop
│ ├── device.py ← Device dataclass and deduplication
│ ├── engine.py ← orchestrates sources (threaded)
│ ├── output.py ← CSV and JSON writer
│ ├── service.py ← systemd installer
│ └── status.py ← --status display
├── sources/
│ ├── shodan_source.py ← Shodan
│ ├── censys_source.py ← Censys
│ └── other_sources.py ← ZoomEye, FOFA, GreyNoise, BinaryEdge,
│ Onyphe, LeakIX, Criminal IP,
│ InternetDB, Hunter.how
├── config.example.yaml ← config template (no secrets)
├── requirements.txt
├── install.sh
└── README.md
| Version | Focus |
|---|---|
| v1.0 | Passive source discovery and device indexing ✅ |
Auxular is built for authorised security research and intelligence operations. It queries only passive, publicly available data sources and does not probe, interact with, or send any traffic to discovered devices. Use responsibly and within the bounds of applicable law.