ATT&CK T1596 - Shodan API Query Detected

This rule detects HTTP requests made to the Shodan API (api.shodan.io). This activity is often associated with reconnaissance, where an attacker or security researcher uses Shodan to gather information about internet-connected devices and services. The rule specifically looks for the 'api.shodan.io' string within the HTTP host header, indicating an attempt to query the Shodan service.