---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Understanding the Shodan Exploit Integration

# Understanding the Shodan Exploit Integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Understanding the Shodan Exploit Integration

The ServiceNow® Shodan Exploit Integration application utilizes data from the Shodan search engine to assess the impact and priority of potential malicious exploits.
This integration is designed to enhance the ServiceNow® Vulnerability Response application by mapping exploits to third-party vulnerabilities, thereby enriching the data available within your instance.
Show full answer Show less  

## Key Features

* **Data Integration:** The Shodan API provides access to a database of exploit data, seamlessly integrating with the ServiceNow AI Platform®.
* **Scheduled Jobs:** Daily scheduled jobs automatically synchronize the instance with other vulnerability management systems, simplifying the remediation lifecycle.
* **User Roles:** Specific roles (admin, user, read) are defined for managing access and permissions within the Shodan Exploit Integration.
* **Default Configurations:** Integrations, including Shodan ExploitDB and Shodan Metasploit, are active by default with scheduled runs at specified times.

## Key Outcomes

By utilizing the Shodan Exploit Integration, ServiceNow customers can effectively prioritize vulnerability remediation efforts based on enriched exploit data. The automatic integration and scheduled jobs facilitate a streamlined process for managing vulnerabilities, allowing teams to respond more efficiently to potential threats.  
The ServiceNow®
Shodan Exploit Integration
application uses data imported from the Shodan search engine to help you
determine the impact and priority of potentially malicious exploits.

## Request apps on the Store {#shodan-exploit-vuln-integration__section_wlq_1kz_thb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#shodan-exploit-vuln-integration__inline-send-to-store}

## Shodan Exploit Integration {#shodan-exploit-vuln-integration__section_l13_1kz_thb}

The Shodan search engine collects exploit data and the Shodan API makes that
database available to the ServiceNow AI Platform®. It easily integrates with the
ServiceNow®
Vulnerability Response application to map exploits to third-party vulnerabilities
enriching the exploit data in your instance.

There is a configured run-as user for each integration record. The default value for this
user is VR.System. Do not change this value.

Every day, scheduled jobs invoke the integrations automatically in the order they are
listed. You can also execute individual scheduled jobs manually. Scheduled jobs simplify the
vulnerability remediation life cycle by keeping the instance synchronized with other
vulnerability management systems.

## Available versions {#shodan-exploit-vuln-integration__section_gkd_vpw_zhb}

{#shodan-exploit-vuln-integration__table_tqh_wpw_zht__entry__2}

| Release version for Australia | Release Notes |
|-|-|
| Shodan Exploit Integration v10.6, 10.7 | For compatibility information, see [KB0856498 Vulnerability Response Compatibility Matrix and Release Schema Changes](https://support.servicenow.com/kb_view.do?sysparm_article=KB0856498) |
[ ]

{#shodan-exploit-vuln-integration__table_tqh_wpw_zht}

## Roles {#shodan-exploit-vuln-integration__section_pxk_vtn_pgb}

Shodan Exploit Integration tasks involve the following roles.

* sn_vul_shodan.admin: Users with this role can read, write, and delete records.
* sn_vul_shodan.user: Users with this role can read and write records.
* sn_vul_shodan.read: Users with this role can read records.
{#shodan-exploit-vuln-integration__ul_vgz_3qj_v1b}

Persona and granular roles are available to help you manage what users and groups can see and do in the Vulnerability Response application. For an initial assignment of the persona roles in Setup Assistant, see [Assign the Vulnerability Response persona roles using Setup Assistant](https://servicenow-prod.fluidtopics.net/msi8kaFkGNjyRib_XBHEzQ "Assign the Vulnerability Response persona roles to groups or users with Setup Assistant."). For more information about managing granular roles, see [Manage persona and granular roles for Vulnerability Response](https://servicenow-prod.fluidtopics.net/WeKNf9YHNMJmJIA6yCsRvA "After you complete your initial assignment of persona roles using Setup Assistant, manage additional granular role assignments to users or groups from the User Administration module in your instance.").

## Shodan exploit integrations {#shodan-exploit-vuln-integration__section_ift_yxh_x1b}

To view the Shodan exploit integrations, navigate to AllShodan Exploit IntegrationIntegrations.

The following integrations are included in the base system. These integrations are active
by default.  
{#shodan-exploit-vuln-integration__table_sbn_qtp_dt__entry__2}

| Integration | Description |
|-|-|
| Shodan ExploitDB Integration | Retrieves ExploitDB data from Shodan and enriches your third-party vulnerability data. This integration is set to run daily at 03:15:00. |
| Shodan Metasploit Integration | Retrieves Metasploit information from Shodan and enriches your third-party vulnerability data. This integration is set to run daily at 01:15:00. |
[Table 1. Shodan exploit integrations]

{#shodan-exploit-vuln-integration__table_sbn_qtp_dt}

To change the default start time for the scheduled integration imports, see [Set Shodan Exploit Integration import time](https://servicenow-prod.fluidtopics.net/631rvjRm6sBrUMcGb3OZIw "For your convenience, you can reset the start time for the Shodan exploit integrations.").

To view exploit data in third-party vulnerabilities, see [View Vulnerability Response vulnerability libraries](https://servicenow-prod.fluidtopics.net/JMOl4iNRK0~b7PHhzDFl1w "You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.").

Changing other Shodan Exploit Integration settings requires advanced ServiceNow and Vulnerability Response expertise and is beyond the
scope of the product documentation.

*[\>]: and then


