Who an address is assigned to, which network it sits in, what it exposes. Facts taken from independent registries, each with its source.
It consumes no slots and has no usage limits: it is included in C.E.R.T.O. Desktop and available to anyone with an account.
The result is sealed in a bundle with an Ed25519 signature and an RFC 3161 timestamp, with a report in text and PDF.
A paid service answers with a judgement: “VPN: yes, risk 75 out of 100”. Useful, but it is a third party's opinion, and whoever reads the bundle cannot check it. This check returns facts, each with the source it came from, and anyone can repeat them.
The sources are independent of one another: a fact confirmed by two different routes is worth far more than the same fact repeated. Measured on 22 September 2026 on a real address: a paid service reported operator and network number as “not available”, while RDAP and Team Cymru both returned them.
Only what the program actually does: every item matches a finding that exists in the code.
The competent regional registry, queried directly: who the range is assigned to, since when, with which published contacts and which abuse-report references.
Autonomous system number and operator name, confirmed by a second source independent of the registry.
The name the address declares for itself and its geographic location. ⚠️ Three countries come back, from three sources, and they are not merged into one: if they disagree, the report shows it instead of choosing.
What Shodan found open at its latest scan, with the recognised services and the vulnerabilities it infers. Free and key-less.
A stated limit is worth more than a claim of completeness — and it goes into the report too, not just onto this page.
Shodan does not say when it looked. Its response carries no date: the listed ports are those of the latest scan, which may be yesterday's or months old. So the report never writes “on day X this address had port 22 open”, but “Shodan, at its latest scan of unknown date, found port 22”. In a report that difference is everything.
Vulnerabilities are inferred, not verified. They come from matching the service banner against a list of known vulnerabilities for that version. If the operator applied a fix without changing the banner, they still show up.
Only one check touches the target, and it is declared. All the others query registries and resolvers, and the examined system never notices. Reading the TLS certificate instead opens a connection, which therefore lands in its logs: it can be switched off, and the report always states which of the two actually happened.
The questions we are asked most often about this check.
All inside C.E.R.T.O. Desktop's OSINT section, all with their own sealed bundle.
Register and download C.E.R.T.O. Desktop for Windows and macOS from your client area.