Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Auxular

Passive IoT / ICS / IIoT Reconnaissance Engine — Stage 1

Auxular is a passive reconnaissance engine that continuously discovers and catalogues internet-exposed IoT, ICS, and IIoT devices by querying multiple open-source and free-tier threat intelligence platforms simultaneously. It normalises results from eleven sources into a unified device dataset, fingerprints industrial control system protocols, and stores output in both CSV and JSON formats for downstream analysis.

It operates silently in the background as a daemon, accumulating a master intelligence dataset over time — and can also be triggered manually against any country or organisation on demand.

Features

  • 11 passive sources queried simultaneously — Shodan, Censys, ZoomEye, FOFA, GreyNoise, BinaryEdge, Onyphe, LeakIX, Criminal IP, Hunter.how, InternetDB
  • Unified device model — 30+ fields per device including IP, port, protocol, geo, ASN, org, product, vendor, version, banner, CVEs, and ICS protocol
  • ICS protocol fingerprinting — Modbus, DNP3, Siemens S7, EtherNet/IP, BACnet, OPC-UA, Niagara Fox, MQTT, OMRON FINS, IEC 60870-5-104, GE SRTP, and more
  • Dual output formats — CSV and NDJSON written on every run
  • Master vs manual separation — scheduled scans append to persistent master files; manual queries write to isolated timestamped files that never touch the master dataset
  • Daemon mode — runs continuously on a configurable interval, designed to be registered as a systemd service
  • Manual mode — query by country (ISO-2 code or full name), organisation name, or both
  • Rate limiting — per-source rate limiters respect free tier quotas automatically
  • Deduplication — cross-source deduplication by IP/port/source fingerprint, keeping the richest record on conflict
  • Threaded execution — sources run in parallel for faster scan cycles

Installation

git clone https://github.com/Calvaryyy/auxular.git
cd auxular
sudo bash install.sh

The install script:

  • Installs Python dependencies system-wide
  • Creates an executable wrapper at /usr/local/bin/auxular
  • Makes auxular callable from any directory on the machine

Requirements: Python 3.8+, Linux (developed and tested on Kali)

Configuration

On first run, Auxular creates a default config file at ~/.auxular/config.yaml.

auxular --config

Add your API keys under each source. Sources with no key set are automatically skipped at runtime with a warning.

A template showing the full config structure is available at config.example.yaml in this repository.

Where to get API keys

Source Free Tier Link
Shodan ✓ https://account.shodan.io
Censys 250 queries/month https://search.censys.io/account
ZoomEye 10,000 results/month https://www.zoomeye.org/profile
FOFA 10,000 results/month https://en.fofa.info/accountInfo
GreyNoise Community tier https://viz.greynoise.io/account
BinaryEdge 250 queries/month https://app.binaryedge.io/account/api
Onyphe 1,000 results/month https://www.onyphe.io/login
LeakIX No key required https://leakix.net/settings
Criminal IP 50 credits/day https://www.criminalip.io/mypage/information
Hunter.how 100 results/month https://hunter.how/dashboard
InternetDB No key required —

Usage

Check source status and API key configuration

auxular --status

Run a single scheduled scan cycle

auxular --scan

Start in daemon mode (continuous, runs every 6 hours by default)

auxular --daemon

Manual query by country

auxular --country NG
auxular --country Nigeria
auxular --country "Saudi Arabia"

Manual query by organisation

auxular --org "FAAN"
auxular --org "Dangote Group"
auxular --org "MTN Nigeria"

Manual query combining country and organisation

auxular --country NG --org "FAAN"

Restrict to specific sources

auxular --country NG --sources shodan,censys,zoomeye

Verbose output

auxular --scan --verbose

Register as a systemd service (runs on startup)

auxular --install-service

Output

Master files (daemon / scheduled runs)

~/auxular_output/master/
  auxular_master_20260422.csv       ← appended on each run
  auxular_master_20260422.json      ← NDJSON, one record per line

Manual files (--country / --org runs)

~/auxular_output/manual/
  auxular_manual_20260422_143022_country_ng.csv
  auxular_manual_20260422_143022_country_ng.json
  auxular_manual_20260422_151100_org_faan.csv
  auxular_manual_20260422_151100_org_faan.json

Manual files are completely isolated from master files and are never appended to across runs.

Device Categories

Category Description
iot IP cameras, DVRs, NVRs, routers, printers, VoIP adapters, smart meters, UPS
ics PLCs, HMIs, RTUs, DCS, SCADA systems
iiot Industrial IoT gateways, factory automation nodes, edge devices
building_automation BACnet, Niagara/Fox systems
smart_grid Grid automation, smart meters
medical_device Network-connected medical equipment

ICS Protocols Fingerprinted

Protocol Port(s) Domain
Modbus 502, 503 Universal ICS
DNP3 20000 Power and water utilities
Siemens S7comm 102 Siemens PLCs
EtherNet/IP 44818, 2222 Rockwell / Allen-Bradley
BACnet 47808 Building automation
OPC-UA 4840 Modern ICS
Niagara Fox 1911, 4911 Building automation
MQTT / MQTT TLS 1883, 8883 IoT messaging
CoAP 5683 Constrained IoT
OMRON FINS 9600 Omron PLCs
IEC 60870-5-104 2404 Power utilities
GE SRTP 18245, 18246 GE PLCs

Project Structure

auxular/
├── auxular.py              ← CLI entry point
├── core/
│   ├── base_source.py      ← abstract base class for all sources
│   ├── config.py           ← YAML config manager
│   ├── daemon.py           ← continuous scan loop
│   ├── device.py           ← Device dataclass and deduplication
│   ├── engine.py           ← orchestrates sources (threaded)
│   ├── output.py           ← CSV and JSON writer
│   ├── service.py          ← systemd installer
│   └── status.py           ← --status display
├── sources/
│   ├── shodan_source.py    ← Shodan
│   ├── censys_source.py    ← Censys
│   └── other_sources.py    ← ZoomEye, FOFA, GreyNoise, BinaryEdge,
│                              Onyphe, LeakIX, Criminal IP,
│                              InternetDB, Hunter.how
├── config.example.yaml     ← config template (no secrets)
├── requirements.txt
├── install.sh
└── README.md

Roadmap

Version Focus
v1.0 Passive source discovery and device indexing ✅

Disclaimer

Auxular is built for authorised security research and intelligence operations. It queries only passive, publicly available data sources and does not probe, interact with, or send any traffic to discovered devices. Use responsibly and within the bounds of applicable law.

About

Passive IoT / ICS / IIoT Reconnaissance Engine

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages