Threat intelligence · Censys
Censys
Internet-wide scanning platform that maps public-facing infrastructure for attack-surface management and adversary-infrastructure tracking.
Censys continuously scans and indexes internet-facing infrastructure, similar in principle to Shodan, and builds what it calls an authoritative map of global internet infrastructure from that data: hosts, certificates, and exposed services with rich metadata. On top of that raw index it sells Attack Surface Management, which automatically discovers and monitors all internet-facing assets tied to an organization, including unknown or shadow-IT exposures, and adversary-infrastructure investigation tooling for tracking threat-actor hosting and detecting compromises. A separate module focuses on critical-infrastructure and industrial-control-system exposure. Data reaches other tools through enrichment APIs built for SIEM and SOAR integration. Censys offers a free account with basic search visibility alongside named, published subscription tiers, Core, Adversary Investigation, and Security Operations, though the tier prices themselves are quote-only.
At a glance
| Vendor | Censys |
|---|---|
| Pricing model | Quote only |
| Free tier | Yes |
| Deployment | Cloud |
| Open source | No |
| Best for | Security teams that need attack-surface discovery plus adversary-infrastructure tracking from the same scan data. |
Pricing
Named self-serve tiers (Core, Adversary Investigation, Security Operations) are published with feature limits, but dollar prices require a sales quote; a free account with basic search is available.
| Plan | Price | Notes |
|---|---|---|
| Core | contact sales | 5+ users, 20K enrichment API calls/day base (unlimited add-on), 1+ month data history |
| Adversary Investigation | contact sales | 5+ users, fully searchable threat data, 3+ months data history |
| Security Operations | contact sales | Unlimited users and enrichment API calls, 12+ months data history |
Prices read from the vendor's own page on September 21, 2026. Vendors change prices; check the source before you budget.
Features
- Continuous internet-wide scanning and indexing
- Attack Surface Management for unknown/shadow-IT exposure
- Adversary infrastructure tracking and investigation
- Critical-infrastructure and ICS exposure monitoring
- Enrichment APIs for SIEM/SOAR integration
- Certificate and service metadata search
Profile last reviewed September 21, 2026