Shodan and VirusTotal keys belong beside AWS
Security-intelligence APIs are high-privilege and usually invisible to credential governance. That's backwards.
The blind spot
Most credential inventories start with cloud — AWS, GCP, Azure — and maybe AI, once someone notices the OpenAI bill. Security-intelligence and OSINT tools almost never make the list: Shodan, VirusTotal, SecurityTrails, Censys, Hunter, and two dozen others usually aren’t tracked anywhere at all.
Not because anyone decided they don’t matter. Because of who adds them and how. A cloud key gets provisioned through infrastructure-as-code, with a ticket and an owner. A Shodan key gets pasted into a .env file by whoever’s doing recon work that afternoon, because the pentest engagement needed it by Thursday. Nobody files a ticket for that. Nobody thinks of it as infrastructure.
Why that’s backwards
These keys are high-privilege in a specific way that’s easy to miss: they can pull attack-surface data about your own organization — exposed hosts, leaked buckets, DNS history, certificate chains, whatever the tool indexes. Handed to someone who shouldn’t have it, a Shodan or Censys key is a reconnaissance shortcut against you, not a convenience someone forgot to delete.
They’re also forgotten faster than cloud keys, for the same reason they were never tracked in the first place. The engagement ends, the analyst moves on, and the key sits there with query credits ticking down while nobody’s watching. It’s the same “unused” problem an AWS key has — just with nobody around to notice, because it was never in the register that would have flagged it.
What “in the register” actually means here
Worth being precise about the limits, since it’s tempting to oversell this. SubScope doesn’t analyze what a Shodan key could be used to find about your org — that’s not a real feature, here or anywhere on this site. What’s real and concrete: the credential gets an owner at creation, the same staleness rules apply as any other vendor (a Shodan key unused 30+ days gets flagged exactly like an idle AWS key would), and where the vendor exposes it, you get quota visibility — 21 of the 27 vendors in this category return real usage/quota data; the other 7 only confirm the key still works, because the vendor itself doesn’t expose more.
The value isn’t “SubScope understands your OSINT tooling’s risk profile.” It’s smaller and more honest than that: this key exists, someone owns it, and if it’s been sitting idle for 93 days, you’ll know — instead of finding out during the next audit that nobody remembers what it was for.
The actual list
This is the largest category in SubScope’s register by a wide margin — 27 vendors, more than cloud, AI and DevTools combined. Shodan, VirusTotal, SecurityTrails, Censys, Hunter, ZoomEye, WhoisXML API, and twenty more, most of them OSINT and threat-intel APIs that don’t show up in any other credential inventory we’ve seen. The full list is on /integrations.