{
  "info": {
    "_postman_id": "b2941a5c-ce2b-5602-bbf9-926bb87f0cf8",
    "name": "Deepinfo Postman",
    "description": "Requests only: the saved example responses are not part of this download. Every endpoint's page on https://docs.deepinfo.com shows them.\n\nThe **Deepinfo API** gives you programmatic access to Deep Search & Insights (**DSI**), Deepinfo's internet-wide domain, DNS, WHOIS, SSL and vulnerability data, and to your Deepinfo Platform modules: External Attack Surface Management (**EASM**), Cyber Threat Intelligence (**CTI**), Brand Risk Protection (**BRP**) and **Platform** (notifications and reports).\n\nThis collection is the reference for every public endpoint. Each request comes with a description, its parameters and saved example responses (success and errors). You can read it like documentation or send the requests directly from Postman.\n\nEvery request carries its full API name, a description, documented parameters, the request body schema, the response fields, and saved examples: a successful response plus the errors that endpoint can return.\n\n## Quick start\n\n1. **Import** the collection and the *Deepinfo - Production* environment.\n2. Select the environment (top right) and paste your API key into the `api_key` variable. Put it in **Current value** so it stays on your machine.\n3. Open **Lookup → Domain WHOIS** and click **Send**.\n\nNo API key yet? Contact [support@deepinfo.com](mailto:support@deepinfo.com).\n\n## Variables\n\n| Variable | Value | Description |\n|---|---|---|\n| `api_base_url` | `https://api.deepinfo.com` | API host |\n| `api_version` | `v1` | API version, the first path segment of every endpoint |\n| `api_key` | *your key* | Sent in the `apikey` header of every request |\n\n## Modules\n\n| Folder | What it covers |\n|---|---|\n| **Getting Started** | Authentication, rate limits, pagination, errors |\n| **Lookup** | Real-time and historical lookups for a single domain, IP, host or website: WHOIS, DNS, IP WHOIS, SSL, port scan, technologies, screenshots, web data |\n| **Discovery** | Search Deepinfo's domain dataset: subdomains, associated domains, reverse WHOIS/NS/IP/MX, TLDs |\n| **Darkweb** | Search dark web sources |\n| **Vulnerability** | Vulnerability (CVE) search, details and insights |\n| **Domain Intelligence** | Domain registration statistics |\n| **Feeds** | Download domain and subdomain data feeds |\n| **EASM** | Your assets, discovery, issues, vulnerabilities and technologies |\n| **CTI** | Email breaches, compromised credentials and devices, threat actors, security news |\n| **BRP** | Fraudulent and suspicious domains, detection rules |\n| **Platform** | Notification rules, reports and scheduled reports |\n\nWhich endpoints you can call depends on your plan.\n\n## Support\n\nWhen you contact [support@deepinfo.com](mailto:support@deepinfo.com) about a request, include the value of the `deepinfo-request-id` response header.\n",
    "schema": "https://schema.getpostman.com/json/collection/v2.1.0/collection.json"
  },
  "auth": {
    "type": "apikey",
    "apikey": [
      {
        "key": "key",
        "value": "apikey",
        "type": "string"
      },
      {
        "key": "value",
        "value": "{{api_key}}",
        "type": "string"
      },
      {
        "key": "in",
        "value": "header",
        "type": "string"
      }
    ]
  },
  "variable": [
    {
      "key": "api_base_url",
      "value": "https://api.deepinfo.com",
      "type": "string",
      "description": "API host. Override it in an environment if you use another one."
    },
    {
      "key": "api_version",
      "value": "v1",
      "type": "string",
      "description": "API version (first path segment)."
    },
    {
      "key": "api_key",
      "value": "",
      "type": "string",
      "description": "Your Deepinfo API key. Keep it in the environment's **Current value**, not here."
    }
  ],
  "event": [
    {
      "listen": "test",
      "script": {
        "type": "text/javascript",
        "exec": [
          "// Runs after every request in this collection.",
          "const id = pm.response.headers.get('deepinfo-request-id');",
          "if (id) { pm.collectionVariables.set('last_request_id', id); }",
          "",
          "pm.test('No server error', function () {",
          "    pm.expect(pm.response.code, 'status').to.be.below(500);",
          "});",
          "",
          "pm.test('Authenticated', function () {",
          "    if (pm.response.code === 401) {",
          "        throw new Error('401 - set the api_key variable in your environment.');",
          "    }",
          "});",
          "",
          "if (pm.response.code === 429) {",
          "    console.warn('Rate limited. Retry after ' + pm.response.headers.get('ratelimit-reset') + ' s.');",
          "}",
          "if (pm.response.code >= 400) {",
          "    const b = pm.response.json ? (function () { try { return pm.response.json(); } catch (e) { return {}; } })() : {};",
          "    console.log('Error', pm.response.code, b.message || b.code, 'request id:', id);",
          "}"
        ]
      }
    }
  ],
  "item": [
    {
      "name": "Getting Started",
      "id": "f4450b72-bf96-579f-8367-11775ed078c2",
      "description": "Start here: authentication, environments, rate limits, pagination and errors.",
      "item": [
        {
          "name": "Errors",
          "id": "70f1afcf-d9f8-54b1-a97f-5c4bacda2282",
          "description": "The API uses standard HTTP status codes. Errors come in two formats, depending on where the request stopped.\n\n### 1. Gateway errors\n\nThese are returned before the request reaches the API service: authentication, plan access, rate limiting and unknown URLs.\n\n```json\n{\n  \"message\": \"Unauthorized\",\n  \"request_id\": \"9b1f3c5d7e9a1b3c5d7e9f1a3b5c7d9e\"\n}\n```\n\n| Status | `message` | Cause |\n|---|---|---|\n| 401 | `No API key found in request` | The `apikey` header is missing |\n| 401 | `Unauthorized` | The API key is not valid |\n| 403 | `You cannot consume this service` | The endpoint is not included in your plan |\n| 404 | `no Route matched with those values` | The URL does not exist (check the path and version) |\n| 429 | `API rate limit exceeded` | Rate limit exceeded (see **Rate Limits**) |\n\n### 2. Application errors\n\nThese are returned by the API service itself: invalid input, missing resources and unexpected errors.\n\n```json\n{\n  \"code\": 10400,\n  \"details\": [],\n  \"parameters\": [\n    {\n      \"param\": \"domain\",\n      \"subcode\": 10001,\n      \"details\": [\"Domain extension is not given in the input.\"]\n    }\n  ],\n  \"solution\": \"https://docs.deepinfo.com/reference/\"\n}\n```\n\n| Field | Description |\n|---|---|\n| `code` | Error code (see below) |\n| `details` | Human-readable messages about the error as a whole |\n| `parameters` | Per-parameter validation errors: `param` (name), `subcode`, `path`, `details` |\n| `solution` | Link to documentation that helps resolve the error |\n\n| Status | Example `code` | Meaning |\n|---|---|---|\n| 400 | `10400` | Invalid or missing parameters or body. See `parameters` for the field-level reason |\n| 404 | e.g. `30003` | The requested resource does not exist |\n| 400 | `30004` | The requested state change is not allowed for the record's current state |\n| 500 | `-1` | Unexpected error. Retry later. If it persists, contact support with the `deepinfo-request-id` |\n\nThe requests in this folder reproduce each error. Open a request and check its saved examples.\n",
          "item": [
            {
              "name": "401 · Missing API Key",
              "id": "46ae75fe-edc5-5c40-b432-cdeb539c5bae",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/lookup/whois?domain=deepinfo.com",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "lookup",
                    "whois"
                  ],
                  "query": [
                    {
                      "key": "domain",
                      "value": "deepinfo.com",
                      "description": "Domain name"
                    }
                  ]
                },
                "description": "Sends a request **without** the `apikey` header. The gateway rejects it with **401**.",
                "auth": {
                  "type": "noauth"
                }
              },
              "response": []
            },
            {
              "name": "401 · Invalid API Key",
              "id": "1675050b-43e3-56d8-a914-4e966c3f402a",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/lookup/whois?domain=deepinfo.com",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "lookup",
                    "whois"
                  ],
                  "query": [
                    {
                      "key": "domain",
                      "value": "deepinfo.com",
                      "description": "Domain name"
                    }
                  ]
                },
                "description": "Sends an **invalid** API key. The gateway rejects it with **401**.",
                "auth": {
                  "type": "apikey",
                  "apikey": [
                    {
                      "key": "key",
                      "value": "apikey",
                      "type": "string"
                    },
                    {
                      "key": "value",
                      "value": "invalid-api-key",
                      "type": "string"
                    },
                    {
                      "key": "in",
                      "value": "header",
                      "type": "string"
                    }
                  ]
                }
              },
              "response": []
            },
            {
              "name": "403 · Endpoint Not in Plan",
              "id": "6f5943b2-a03e-5182-abf5-1545fdd7301a",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/discovery/vulnerability-finder?url=https://deepinfo.com",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "discovery",
                    "vulnerability-finder"
                  ],
                  "query": [
                    {
                      "key": "url",
                      "value": "https://deepinfo.com",
                      "description": "URL to check"
                    }
                  ]
                },
                "description": "Returned when your API key is valid but the endpoint is **not included in your plan**. Whether you see it depends on your plan; the saved example shows the response."
              },
              "response": []
            },
            {
              "name": "404 · Unknown URL",
              "id": "f0889cf8-ae38-5fe9-802f-d2c9949ff397",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/lookup/does-not-exist",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "lookup",
                    "does-not-exist"
                  ]
                },
                "description": "Calls a URL that does not exist. The gateway returns **404**."
              },
              "response": []
            },
            {
              "name": "429 · Rate Limit Exceeded",
              "id": "abf58fc9-119a-5d9b-ab66-3b231adce528",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/lookup/ip-whois?ip=8.8.8.8",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "lookup",
                    "ip-whois"
                  ],
                  "query": [
                    {
                      "key": "ip",
                      "value": "8.8.8.8",
                      "description": "IPv4 or IPv6 address"
                    }
                  ]
                },
                "description": "Returned when you exceed your rate limit. Send this request several times within one second to reproduce it. See **Rate Limits**."
              },
              "response": []
            },
            {
              "name": "400 · Validation Error",
              "id": "deaa2d2b-3032-5feb-9daa-c9e4ff6c0208",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/lookup/whois?domain=not_a_domain",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "lookup",
                    "whois"
                  ],
                  "query": [
                    {
                      "key": "domain",
                      "value": "not_a_domain",
                      "description": "An invalid domain name"
                    }
                  ]
                },
                "description": "Sends an invalid `domain`. The API returns **400** with a field-level reason in `parameters`."
              },
              "response": []
            },
            {
              "name": "404 · Resource Not Found",
              "id": "74963d29-f5f0-548e-8c9a-597a1f473f7e",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/00000000-0000-0000-0000-000000000000",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "00000000-0000-0000-0000-000000000000"
                  ]
                },
                "description": "Requests an EASM asset that does not exist. The API returns **404** with an application error code. Requires EASM access."
              },
              "response": []
            },
            {
              "name": "500 · Unexpected Error",
              "id": "e7ca3190-bf15-58d2-ab83-6758e371d990",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/lookup/whois?domain=deepinfo.com",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "lookup",
                    "whois"
                  ],
                  "query": [
                    {
                      "key": "domain",
                      "value": "deepinfo.com",
                      "description": "Domain name"
                    }
                  ]
                },
                "description": "Shape of an unexpected server error (**500**). This request normally succeeds; the saved example only shows what a 500 looks like. Retry later. If it persists, contact support with the `deepinfo-request-id` header value."
              },
              "response": []
            }
          ]
        }
      ]
    },
    {
      "name": "Lookup",
      "id": "0848691a-1d66-5bd7-a273-878b1c1a9d6d",
      "description": "Look up a **single** domain, host, IP address or website, either in real time or from Deepinfo's history.\n\n| Request | Returns |\n|---|---|\n| **Domain WHOIS** | Current registration record of a domain |\n| **DNS** | Current DNS records (up to 5 types per call) |\n| **IP WHOIS** | Current registration details of an IP address |\n| **SSL** | The certificate served by a host |\n| **Port Scan** | Open ports and services of a host |\n| **Technology** | Technologies a website runs on |\n| **Screenshot** | A screenshot of a web page, with options in the query string |\n| **Screenshot (POST)** | The same, with options in a JSON body |\n| **Web Data** | Content, metadata, links, trackers, headers and cookies of a web page, optionally with a screenshot |\n| **DNS History** | Every DNS value observed for a domain over time |\n| **WHOIS History** | Every WHOIS record observed for a domain over time |\n\nEach request uses one quota unit on your plan.\n",
      "item": [
        {
          "name": "Domain WHOIS",
          "id": "278d1459-82f2-5d58-b61a-23165518f3dc",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/lookup/whois?domain=deepinfo.com",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "lookup",
                "whois"
              ],
              "query": [
                {
                  "key": "domain",
                  "value": "deepinfo.com",
                  "description": "**Required.** Domain name, e.g. `deepinfo.com`. Subdomains are accepted (`www.deepinfo.com`); IP addresses are not."
                }
              ]
            },
            "description": "**Deepinfo Lookup Domain WHOIS API**\n\nReturns the **current** WHOIS registration record of a domain: registrar, registrant, creation, update and expiry dates, name servers and status codes. The record is queried in real time. The response includes both the raw WHOIS text and a parsed version.\n\n### Response\n\n| Field | Description |\n|---|---|\n| `domain_name` | The queried domain |\n| `raw` | Raw WHOIS text as returned by the WHOIS server |\n| `parsed` | Parsed record, with the `parsed.*` fields below. `null` if the record could not be parsed |\n| `parsed.create_date` | Registration date |\n| `parsed.update_date` | Date of the last update |\n| `parsed.expiry_date` | Expiry date |\n| `parsed.registrar` | Registrar |\n| `parsed.registrant.name` | Registrant name |\n| `parsed.registrant.organization` | Registrant organization |\n| `parsed.registrant.street` | Registrant street address |\n| `parsed.registrant.city` | Registrant city |\n| `parsed.registrant.state` | Registrant state or province |\n| `parsed.registrant.postal_code` | Registrant postal code |\n| `parsed.registrant.country` | Registrant country |\n| `parsed.registrant.phone` | Registrant phone number |\n| `parsed.registrant.email` | Registrant e-mail address |\n| `parsed.name_servers` | Name servers |\n| `parsed.domain_status` | Domain status codes |\n| `parsed.whois_server` | WHOIS server |\n| `check_date` | When the lookup was performed (UTC) |\n| `parse_code` | Parser status code; `null` when parsing succeeded |\n\n### Errors\n\n`400` if `domain` is missing or not a valid domain. See **Getting Started → Errors**."
          },
          "response": []
        },
        {
          "name": "DNS",
          "id": "f5cbedc0-4d9e-56b0-b3ec-d5770fd96166",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/lookup/dns?domain=deepinfo.com&type=A,MX",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "lookup",
                "dns"
              ],
              "query": [
                {
                  "key": "domain",
                  "value": "deepinfo.com",
                  "description": "**Required.** Fully qualified domain name, e.g. `deepinfo.com` or `www.deepinfo.com`. IP addresses are not accepted."
                },
                {
                  "key": "type",
                  "value": "A,MX",
                  "description": "**Required.** DNS record type names, comma-separated, for example `A,MX`. Up to **5** types per request."
                }
              ]
            },
            "description": "**Deepinfo Lookup DNS API**\n\nResolves the **current** DNS records of a domain or hostname in real time. Request up to five record types in one call. Each request uses **one quota unit**, whether you ask for one type or five.\n\n### Response\n\n| Field | Description |\n|---|---|\n| `fqdn` | The queried name |\n| `requested_types` | Record types that were requested |\n| `responses[]` | One entry per requested type |\n| `responses[].type` | Record type |\n| `responses[].conn_status` | `success` or `timeout` |\n| `responses[].rcode` | DNS response code, for example `NOERROR` or `NXDOMAIN` |\n| `responses[].values` | Parsed record values |\n| `responses[].raw` | The answer in zone-file format |\n| `responses[].server` | Resolver used |\n| `servers` | Resolvers used for the lookup |\n| `check_date` | When the lookup was performed (UTC) |\n\n### Errors\n\n`400` if `domain` is not a valid FQDN or `type` is missing."
          },
          "response": []
        },
        {
          "name": "IP WHOIS",
          "id": "40c581ef-dfef-54ea-9ef5-eb8c137f24a7",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/lookup/ip-whois?ip=8.8.8.8",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "lookup",
                "ip-whois"
              ],
              "query": [
                {
                  "key": "ip",
                  "value": "8.8.8.8",
                  "description": "**Required.** IPv4 or IPv6 address."
                }
              ]
            },
            "description": "**Deepinfo Lookup IP WHOIS API**\n\nReturns the **current** registration details of an IP address from the regional internet registries (RDAP/WHOIS): the owning network and its range, the ASN, the registry, and contact entities.\n\n### Response\n\n| Field | Description |\n|---|---|\n| `ip` | The queried IP address |\n| `ipwhois.asn` | Number of the autonomous system (AS) that announces the IP |\n| `ipwhois.asn_cidr` | The announced IP range that contains the IP |\n| `ipwhois.asn_description` | Name of the AS |\n| `ipwhois.asn_country_code` | Country code of the AS |\n| `ipwhois.asn_registry` | Regional internet registry of the AS |\n| `ipwhois.asn_date` | Allocation date of the AS |\n| `ipwhois.network` | The registered network that contains the IP, with the `ipwhois.network.*` fields below |\n| `ipwhois.network.cidr` | Network range in CIDR notation |\n| `ipwhois.network.name` | Network name |\n| `ipwhois.network.country` | Country of the network |\n| `ipwhois.network.start_address` | First address of the range |\n| `ipwhois.network.end_address` | Last address of the range |\n| `ipwhois.network.ip_version` | IP version, e.g. `v4` |\n| `ipwhois.network.handle` | Registry handle of the network |\n| `ipwhois.network.parent_handle` | Handle of the parent network |\n| `ipwhois.network.type` | Allocation type |\n| `ipwhois.network.status` | Registration status |\n| `ipwhois.network.events[]` | Registration events of the network |\n| `ipwhois.network.events[].action` | What happened, e.g. `registration` |\n| `ipwhois.network.events[].actor` | Who did it, when the registry says |\n| `ipwhois.network.events[].timestamp` | When it happened (UTC) |\n| `ipwhois.network.notices[]` | Registry notices |\n| `ipwhois.network.notices[].title` | Notice title |\n| `ipwhois.network.notices[].description` | Notice text |\n| `ipwhois.network.notices[].links` | Links given with the notice |\n| `ipwhois.network.remarks[]` | Registry remarks |\n| `ipwhois.network.remarks[].title` | Remark title |\n| `ipwhois.network.remarks[].description` | Remark text |\n| `ipwhois.network.remarks[].links` | Links given with the remark |\n| `ipwhois.network.links` | RDAP and WHOIS links for the network |\n| `ipwhois.network.raw` | Raw registry answer for the network, when available |\n| `ipwhois.entities` | Handles of related entities (organizations, contacts) |\n| `ipwhois.objects` | Details for each entity handle, keyed by the handle: contact details, roles and registration events |\n| `ipwhois.nir` | National Internet Registry data, where applicable |\n| `check_date` | When the lookup was performed (UTC) |\n\n### Errors\n\n`400` if `ip` is not a valid IP address."
          },
          "response": []
        },
        {
          "name": "SSL",
          "id": "5771177f-77b8-523c-b7aa-a2f45b44244c",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/lookup/ssl?target=deepinfo.com",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "lookup",
                "ssl"
              ],
              "query": [
                {
                  "key": "target",
                  "value": "deepinfo.com",
                  "description": "**Required.** Domain name or IP address to connect to."
                },
                {
                  "key": "port",
                  "value": "443",
                  "description": "Port to connect to. Default `443`.",
                  "disabled": true
                },
                {
                  "key": "proxy",
                  "value": "",
                  "description": "Optional proxy to connect through, in the form `scheme://user:password@host:port`.",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Lookup SSL API**\n\nConnects to a host in real time and returns the SSL/TLS certificate it serves: subject, issuer, validity, fingerprints, extensions (including all DNS names in the Subject Alternative Name) and whether the signature and chain are valid.\n\n### Response\n\n| Field | Description |\n|---|---|\n| `target` | The host that was checked |\n| `port` | The port that was checked |\n| `connection_status` | `success`, `timeout`, `refused`, `reset`, `ssl_error`, `not_resolved` or `proxy_connection_error` |\n| `parsed` | Parsed certificate, with the `parsed.*` fields below. `null` if no certificate was retrieved |\n| `parsed.version.name` | Certificate version, e.g. `v3` |\n| `parsed.version.value` | The version number as encoded in the certificate (`2` for v3) |\n| `parsed.subject.dn` | Subject distinguished name |\n| `parsed.subject.common_name` | Subject common name (CN) |\n| `parsed.subject.organization` | Subject organization (O) |\n| `parsed.subject.organizational_unit` | Subject organizational unit (OU) |\n| `parsed.subject.locality` | Subject locality (L) |\n| `parsed.subject.state` | Subject state or province (ST) |\n| `parsed.subject.country_name` | Subject country (C) |\n| `parsed.issuer.dn` | Issuer distinguished name |\n| `parsed.issuer.common_name` | Issuer common name (CN) |\n| `parsed.issuer.organization` | Issuer organization (O) |\n| `parsed.issuer.organizational_unit` | Issuer organizational unit (OU) |\n| `parsed.issuer.locality` | Issuer locality (L) |\n| `parsed.issuer.state` | Issuer state or province (ST) |\n| `parsed.issuer.country_name` | Issuer country (C) |\n| `parsed.validity.start` | Start of the validity period |\n| `parsed.validity.end` | End of the validity period |\n| `parsed.validity.length` | Length of the validity period, in seconds |\n| `parsed.signature.valid` | Whether the signature is valid |\n| `parsed.signature.valid_chain` | Whether the certificate chain is valid |\n| `parsed.signature.self_signed` | Whether the certificate is self-signed |\n| `parsed.signature.invalid_reason` | Why the signature or the chain is not valid; `null` when both are valid |\n| `parsed.signature.value` | The signature, base64-encoded |\n| `parsed.signature.signature_algorithm.oid` | OID of the signature algorithm |\n| `parsed.signature.signature_algorithm.name` | Name of the signature algorithm, e.g. `sha256` |\n| `parsed.fingerprint_sha1` | SHA-1 fingerprint of the certificate |\n| `parsed.fingerprint_sha256` | SHA-256 fingerprint of the certificate |\n| `parsed.fingerprint_md5` | MD5 fingerprint of the certificate |\n| `parsed.tbs_fingerprint` | Fingerprint of the signed part of the certificate (TBS certificate) |\n| `parsed.serial_number` | Serial number |\n| `parsed.subject_key_info` | The certificate's public key: its algorithm, fingerprint and key parameters |\n| `parsed.extensions` | X.509 extensions. `parsed.extensions.subject_alt_name.dns_names` holds every DNS name in the Subject Alternative Name |\n| `parsed.has_expired` | Whether the certificate has expired |\n| `parsed.fqdn_list` | Host names the certificate is valid for |\n| `certificate` | The certificate in base64 (DER) |\n| `parse_errors` | Problems found while parsing the certificate |\n| `check_date` | When the check was performed (UTC) |\n\n### Errors\n\n`400` if `target` is missing or invalid. Connection problems are **not** errors: they return `200` with the reason in `connection_status`."
          },
          "response": []
        },
        {
          "name": "Port Scan",
          "id": "ad1e7863-3684-5abb-aa43-3ac05c3f5055",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/lookup/port-scan?target=deepinfo.com",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "lookup",
                "port-scan"
              ],
              "query": [
                {
                  "key": "target",
                  "value": "deepinfo.com",
                  "description": "**Required.** Domain name or IP address to scan."
                },
                {
                  "key": "timeout",
                  "value": "85",
                  "description": "Scan timeout in seconds. Maximum and default: `85`.",
                  "disabled": true
                },
                {
                  "key": "proxy",
                  "value": "",
                  "description": "Optional proxy to scan through, in the form `scheme://user:password@host:port`.",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Lookup Port Scan API**\n\nScans a host in real time and returns its open TCP/UDP ports and the services running on them. Optionally detects service versions and the operating system.\n\n> Only scan hosts you own or are authorized to test.\n\n### Request body\n\n| Field | Type | Description |\n|---|---|---|\n| `tcp_ports` | string | TCP ports to scan: a list (`\"80,443\"`), a range (`\"440-445\"`) or both. Omit to scan the default port set of `mode` |\n| `udp_ports` | string | UDP ports to scan |\n| `mode` | `light` \\| `full` | Scan depth. Default `light` |\n| `version` | boolean | Detect service versions. Default `false` |\n| `os` | boolean | Detect the operating system. Default `false` |\n| `scripts` | boolean | Run service detection scripts. Default `false` |\n\n### Response\n\n| Field | Description |\n|---|---|\n| `status` | `success`, or `host_down` if the host did not respond |\n| `target` | The scanned host |\n| `target_ip` | The IP address the host resolved to |\n| `port_data.tcp[]` | One entry per TCP port in the result |\n| `port_data.tcp[].port_number` | Port number |\n| `port_data.tcp[].state` | Port state, e.g. `open` |\n| `port_data.tcp[].service_name` | Name of the service, e.g. `https` |\n| `port_data.tcp[].service_product` | Product that runs the service |\n| `port_data.tcp[].service_version` | Version of that product |\n| `port_data.tcp[].extra_data` | Additional data about the service |\n| `port_data.udp[]` | One entry per UDP port in the result |\n| `port_data.udp[].port_number` | Port number |\n| `port_data.udp[].state` | Port state, e.g. `open` |\n| `port_data.udp[].service_name` | Name of the service, e.g. `https` |\n| `port_data.udp[].service_product` | Product that runs the service |\n| `port_data.udp[].service_version` | Version of that product |\n| `port_data.udp[].extra_data` | Additional data about the service |\n| `os` | Operating system matches, when `os` is `true` |\n| `check_date` | When the scan was performed (UTC) |\n\n### Errors\n\n`400` if `target` is missing or the body is invalid.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"tcp_ports\": \"80,443\",\n  \"mode\": \"light\",\n  \"version\": true\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        },
        {
          "name": "Technology",
          "id": "ef8caa5c-a9e8-5b9c-a67c-bf0c71e03eea",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/lookup/technology?url=https://www.deepinfo.com",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "lookup",
                "technology"
              ],
              "query": [
                {
                  "key": "url",
                  "value": "https://www.deepinfo.com",
                  "description": "**Required.** Website to analyze, e.g. `https://www.deepinfo.com`."
                },
                {
                  "key": "proxy",
                  "value": "",
                  "description": "Proxy to connect through, in the form `http://user:password@host:port`.",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Lookup Technology API**\n\nLoads a website in real time and detects the technologies it runs on: CMS, web frameworks, JavaScript libraries, CDN, analytics, chat widgets and more. Each technology comes with its categories, the detected version (when the site reveals it) and a CPE name.\n\nUse it to fingerprint a single site. The CPE name lets you match the result against vulnerability data (see **Vulnerability**). If you also need the page's HTML, links, headers and cookies, **Web Data** returns the same technologies together with them in one call.\n\nThe site is loaded live, so a request takes a few seconds (about 5 s in our tests).\n\n### Response\n\n| Field | Description |\n|---|---|\n| `urls` | Every URL that was loaded, with the HTTP `status` it returned, e.g. `{\"https://www.deepinfo.com/\": {\"status\": 200}}`. `null` if nothing could be loaded |\n| `technologies[]` | One entry per detected technology |\n| `technologies[].slug` | Identifier of the technology |\n| `technologies[].name` | Name of the technology |\n| `technologies[].description` | What the technology is |\n| `technologies[].categories` | Categories it belongs to |\n| `technologies[].confidence` | Detection confidence (0–100) |\n| `technologies[].version` | Detected version; empty when the site does not reveal it |\n| `technologies[].clean_version` | The version as a number, or `null` |\n| `technologies[].cpe` | CPE name |\n| `technologies[].alternative_cpe_names` | Other CPE names of the technology |\n| `technologies[].website` | The vendor's website |\n| `technologies[].icon` | Icon file name |\n| `connection_status` | `success` when the site was reached |\n| `version` | Version of the result format (currently `1`) |\n| `check_date` | When the lookup was performed (UTC) |\n\n### Errors\n\n`400` (`10400`) if `url` is missing or not a valid URL. The validation error currently names the parameter `domain`, although the request parameter is `url` (see the example). `500` for an unexpected error. `503` means the analyzer is busy and `504` that it timed out: retry after a short wait. See **Getting Started → Errors**."
          },
          "response": []
        },
        {
          "name": "Screenshot",
          "id": "06f2b46f-fbd1-5dee-80d1-7e9479b817d2",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/lookup/screenshot?url=https://www.deepinfo.com",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "lookup",
                "screenshot"
              ],
              "query": [
                {
                  "key": "url",
                  "value": "https://www.deepinfo.com",
                  "description": "**Required.** Web page to capture, e.g. `https://www.deepinfo.com`. It can be left out only when `custom_html` is sent."
                },
                {
                  "key": "width",
                  "value": "1366",
                  "description": "Browser viewport width, in pixels. Range `100`–`3000`. Default `1366`.",
                  "disabled": true
                },
                {
                  "key": "height",
                  "value": "768",
                  "description": "Browser viewport height, in pixels. Range `100`–`3000`. Default `768`.",
                  "disabled": true
                },
                {
                  "key": "full_page",
                  "value": "false",
                  "description": "Capture the whole page, not only the visible viewport. Default `false`.",
                  "disabled": true
                },
                {
                  "key": "mobile",
                  "value": "false",
                  "description": "Emulate a mobile device. The viewport then defaults to 360 × 740. Default `false`.",
                  "disabled": true
                },
                {
                  "key": "landscape",
                  "value": "false",
                  "description": "Emulate landscape orientation. Default `false`.",
                  "disabled": true
                },
                {
                  "key": "touchscreen",
                  "value": "false",
                  "description": "Emulate a touch screen. Default `false`.",
                  "disabled": true
                },
                {
                  "key": "retina",
                  "value": "false",
                  "description": "Render at twice the pixel density for a sharper image. Ignored when `scale` is set. Default `false`.",
                  "disabled": true
                },
                {
                  "key": "scale",
                  "value": "",
                  "description": "Device pixel ratio: how many screen pixels draw one CSS pixel. Range `0.5`–`4`.",
                  "disabled": true
                },
                {
                  "key": "image_output",
                  "value": "jpeg",
                  "description": "Image format. One of `jpeg`, `png`. Default `jpeg`.",
                  "disabled": true
                },
                {
                  "key": "quality",
                  "value": "",
                  "description": "JPEG quality. Used only when `image_output` is `jpeg`. Range `0`–`100`.",
                  "disabled": true
                },
                {
                  "key": "thumbnail_width",
                  "value": "",
                  "description": "Resize the image to this width, keeping the aspect ratio. Must not be larger than the screenshot width. Minimum `50`.",
                  "disabled": true
                },
                {
                  "key": "mode",
                  "value": "fast",
                  "description": "`fast` captures as soon as the HTML document has loaded (`domcontentloaded`); `slow` waits until network activity stops. One of `fast`, `slow`. Default `fast`.",
                  "disabled": true
                },
                {
                  "key": "timeout",
                  "value": "30000",
                  "description": "Maximum time to wait for the page to load, in milliseconds. Range `0`–`90000`. Default `30000`.",
                  "disabled": true
                },
                {
                  "key": "delay",
                  "value": "0",
                  "description": "Extra wait after the page has loaded, in milliseconds, before the screenshot is taken. Maximum `30000`. Default `0`.",
                  "disabled": true
                },
                {
                  "key": "lazy_load",
                  "value": "false",
                  "description": "Scroll through the whole page first, so that lazy-loaded images are rendered. Default `false`.",
                  "disabled": true
                },
                {
                  "key": "block_ads",
                  "value": "false",
                  "description": "Block advertisements. Default `false`.",
                  "disabled": true
                },
                {
                  "key": "no_cookie_banners",
                  "value": "false",
                  "description": "Hide cookie consent banners. Default `false`.",
                  "disabled": true
                },
                {
                  "key": "no_js",
                  "value": "false",
                  "description": "Disable JavaScript on the page. Default `false`.",
                  "disabled": true
                },
                {
                  "key": "selector",
                  "value": "",
                  "description": "CSS selector of one element, e.g. `body > .container > .logo`. When it matches, only that element is captured.",
                  "disabled": true
                },
                {
                  "key": "scroll_to_element",
                  "value": "",
                  "description": "CSS selector of an element to scroll to before the screenshot, e.g. `body > .footer`.",
                  "disabled": true
                },
                {
                  "key": "accept_languages",
                  "value": "en-US",
                  "description": "Browser `Accept-Language` value. Default `en-US`.",
                  "disabled": true
                },
                {
                  "key": "latitude",
                  "value": "",
                  "description": "Latitude reported by the browser's Geolocation API. Requires `longitude`. Range `-80`–`80`.",
                  "disabled": true
                },
                {
                  "key": "longitude",
                  "value": "",
                  "description": "Longitude reported by the browser's Geolocation API. Requires `latitude`. Range `-180`–`180`.",
                  "disabled": true
                },
                {
                  "key": "user_agent",
                  "value": "",
                  "description": "Browser user agent string.",
                  "disabled": true
                },
                {
                  "key": "cookies",
                  "value": "",
                  "description": "Cookies to set in the browser, e.g. `name1=value1; name2=value2`.",
                  "disabled": true
                },
                {
                  "key": "headers",
                  "value": "",
                  "description": "Extra request headers, e.g. `Header-1:value1; Header-2:value2`.",
                  "disabled": true
                },
                {
                  "key": "css",
                  "value": "",
                  "description": "CSS code to inject into the page, e.g. `h1 { color: red }`.",
                  "disabled": true
                },
                {
                  "key": "css_url",
                  "value": "",
                  "description": "URL of a stylesheet to inject into the page.",
                  "disabled": true
                },
                {
                  "key": "custom_html",
                  "value": "",
                  "description": "HTML to render instead of loading `url`. For long HTML, use **Screenshot (POST)**.",
                  "disabled": true
                },
                {
                  "key": "proxy",
                  "value": "",
                  "description": "Proxy to load the page through, in the form `user:password@host:port`.",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Lookup Screenshot API**\n\nOpens a web page in a real browser and returns a link to a screenshot of it. Options control the viewport, full-page capture, mobile emulation, image format and how long to wait for the page.\n\nUse it to see what a site shows right now, for example to review a suspicious or look-alike domain without visiting it yourself. A request takes a few seconds (about 5 s in our tests).\n\nAll options are query parameters; the defaults give a 1366 × 768 JPEG of the visible part of the page. To send the options as a JSON body instead (for long values such as `custom_html`), use **Screenshot (POST)**.\n\n### Response\n\n| Field | Description |\n|---|---|\n| `url` | The requested URL |\n| `redirected_url` | The URL the browser ended up on after redirects |\n| `screenshot_url` | Link to the image (JPEG, or PNG with `image_output=png`). It is a **signed link that expires after 7 days**: download the image if you need to keep it |\n| `connection_status` | `success` when the page was loaded |\n| `check_date` | When the screenshot was taken (UTC) |\n\n### Errors\n\n`400` (`10400`) if `url` is missing or invalid (and no `custom_html` is sent), or an option is out of range. The validation error currently names the parameter `domain`, although the request parameter is `url` (see the example). `500` for an unexpected error. `503` means the service is busy or out of memory: retry shortly. See **Getting Started → Errors**."
          },
          "response": []
        },
        {
          "name": "Screenshot (POST)",
          "id": "549a2b71-fcfa-53b4-b071-fc6343c5d607",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/lookup/screenshot",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "lookup",
                "screenshot"
              ]
            },
            "description": "**Deepinfo Lookup Screenshot API (POST)**\n\nSame as **Screenshot**, with the options in a JSON body instead of the query string. Use it when a value is too long for a URL, such as `custom_html`. The response is the same.\n\n### Request body\n\n| Field | Type | Description |\n|---|---|---|\n| `url` | string | **Required.** Web page to capture, e.g. `https://www.deepinfo.com`. It can be left out only when `custom_html` is sent. |\n| `width` | integer | Browser viewport width, in pixels. Range `100`–`3000`. Default `1366`. |\n| `height` | integer | Browser viewport height, in pixels. Range `100`–`3000`. Default `768`. |\n| `full_page` | boolean | Capture the whole page, not only the visible viewport. Default `false`. |\n| `mobile` | boolean | Emulate a mobile device. The viewport then defaults to 360 × 740. Default `false`. |\n| `landscape` | boolean | Emulate landscape orientation. Default `false`. |\n| `touchscreen` | boolean | Emulate a touch screen. Default `false`. |\n| `retina` | boolean | Render at twice the pixel density for a sharper image. Ignored when `scale` is set. Default `false`. |\n| `scale` | number | Device pixel ratio: how many screen pixels draw one CSS pixel. Range `0.5`–`4`. |\n| `image_output` | `jpeg` \\| `png` | Image format. Default `jpeg`. |\n| `quality` | integer | JPEG quality. Used only when `image_output` is `jpeg`. Range `0`–`100`. |\n| `thumbnail_width` | integer | Resize the image to this width, keeping the aspect ratio. Must not be larger than the screenshot width. Minimum `50`. |\n| `mode` | `fast` \\| `slow` | `fast` captures as soon as the HTML document has loaded (`domcontentloaded`); `slow` waits until network activity stops. Default `fast`. |\n| `timeout` | integer | Maximum time to wait for the page to load, in milliseconds. Range `0`–`90000`. Default `30000`. |\n| `delay` | integer | Extra wait after the page has loaded, in milliseconds, before the screenshot is taken. Maximum `30000`. Default `0`. |\n| `lazy_load` | boolean | Scroll through the whole page first, so that lazy-loaded images are rendered. Default `false`. |\n| `block_ads` | boolean | Block advertisements. Default `false`. |\n| `no_cookie_banners` | boolean | Hide cookie consent banners. Default `false`. |\n| `no_js` | boolean | Disable JavaScript on the page. Default `false`. |\n| `selector` | string | CSS selector of one element, e.g. `body > .container > .logo`. When it matches, only that element is captured. |\n| `scroll_to_element` | string | CSS selector of an element to scroll to before the screenshot, e.g. `body > .footer`. |\n| `accept_languages` | string | Browser `Accept-Language` value. Default `en-US`. |\n| `latitude` | number | Latitude reported by the browser's Geolocation API. Requires `longitude`. Range `-80`–`80`. |\n| `longitude` | number | Longitude reported by the browser's Geolocation API. Requires `latitude`. Range `-180`–`180`. |\n| `user_agent` | string | Browser user agent string. |\n| `cookies` | string | Cookies to set in the browser, e.g. `name1=value1; name2=value2`. |\n| `headers` | string | Extra request headers, e.g. `Header-1:value1; Header-2:value2`. |\n| `css` | string | CSS code to inject into the page, e.g. `h1 { color: red }`. |\n| `css_url` | string | URL of a stylesheet to inject into the page. |\n| `custom_html` | string | HTML to render instead of loading `url`. |\n| `proxy` | string | Proxy to load the page through, in the form `user:password@host:port`. |\n\n### Response\n\n| Field | Description |\n|---|---|\n| `url` | The requested URL |\n| `redirected_url` | The URL the browser ended up on after redirects |\n| `screenshot_url` | Link to the image (JPEG, or PNG with `image_output=png`). It is a **signed link that expires after 7 days**: download the image if you need to keep it |\n| `connection_status` | `success` when the page was loaded |\n| `check_date` | When the screenshot was taken (UTC) |\n\n### Errors\n\n`400` (`10400`) if `url` is missing or invalid (and no `custom_html` is sent), or an option is out of range. The validation error currently names the parameter `domain`, although the request parameter is `url` (see the example). `500` for an unexpected error. `503` means the service is busy or out of memory: retry shortly. See **Getting Started → Errors**.",
            "body": {
              "mode": "raw",
              "raw": "{\n  \"url\": \"https://www.deepinfo.com\",\n  \"width\": 1366,\n  \"height\": 768,\n  \"full_page\": false\n}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        },
        {
          "name": "Web Data",
          "id": "9ff15c6a-c710-5094-8781-c91f292c087b",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/lookup/webdata?url=https://www.deepinfo.com",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "lookup",
                "webdata"
              ],
              "query": [
                {
                  "key": "url",
                  "value": "https://www.deepinfo.com",
                  "description": "**Required.** Web page to analyze, e.g. `https://www.deepinfo.com`."
                },
                {
                  "key": "screenshot",
                  "value": "true",
                  "description": "Also capture a JPEG screenshot of the rendered page. The response then includes a `screenshot` object. Default `false`.",
                  "disabled": true
                },
                {
                  "key": "wait_until",
                  "value": "networkidle2,load,domcontentloaded",
                  "description": "Page load events to wait for before the page is parsed, comma-separated. Ignored when `screenshot` is `true`: the page is then always parsed after `load`. One or more of `load`, `domcontentloaded`, `networkidle0`, `networkidle2`. Default `networkidle2,load,domcontentloaded`.",
                  "disabled": true
                },
                {
                  "key": "max_file_size",
                  "value": "8388608",
                  "description": "Maximum size of `html.source_code`, in bytes. For a larger page, `source_code` holds a placeholder message instead of the HTML. Range `1`–`33554432`. Default `8388608`.",
                  "disabled": true
                },
                {
                  "key": "proxy",
                  "value": "",
                  "description": "Proxy to load the page through, as a URL with an explicit port, e.g. `http://user:password@host:8080`. The proxy host must be a public IP address or an allowed domain.",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Lookup Web Data API**\n\nLoads a web page in a real browser and returns everything Deepinfo extracts from it, in one call: detected technologies, page metadata (title, description, Open Graph tags, JSON-LD), the HTML source and visible text, links, scripts, trackers (Google Analytics, AdSense and Tag Manager IDs), e-mail addresses, favicons, `robots.txt`, and the HTTP response headers, cookies and redirects. Add `screenshot=true` to capture a screenshot as well.\n\nUse it to profile a website in depth, for example to compare a look-alike domain's page with your own or to find the analytics IDs it shares with other sites. For technologies only, **Technology** is lighter; for an image only, use **Screenshot**.\n\nA request takes several seconds (about 10 s in our tests).\n\n### Response\n\n| Field | Description |\n|---|---|\n| `url` | The requested URL |\n| `technology.stacks[]` | One entry per detected technology |\n| `technology.stacks[].slug` | Identifier of the technology |\n| `technology.stacks[].name` | Name of the technology |\n| `technology.stacks[].description` | What the technology is |\n| `technology.stacks[].categories` | Categories it belongs to |\n| `technology.stacks[].confidence` | Detection confidence (0–100) |\n| `technology.stacks[].version` | Detected version; empty when the site does not reveal it |\n| `technology.stacks[].clean_version` | The version as a number, or `null` |\n| `technology.stacks[].cpe` | CPE name |\n| `technology.stacks[].alternative_cpe_names` | Other CPE names of the technology |\n| `technology.stacks[].website` | The vendor's website |\n| `technology.stacks[].icon` | Icon file name |\n| `html.meta.title` | Page title |\n| `html.meta.name` | Site name given in the page metadata |\n| `html.meta.description` | Meta description |\n| `html.meta.keywords` | Meta keywords |\n| `html.meta.language` | Language of the page |\n| `html.meta.language_alternatives` | Other language versions the page declares |\n| `html.meta.encoding` | Character encoding |\n| `html.meta.noindex_status` | Whether the page asks search engines not to index it |\n| `html.meta.canonical_url` | Canonical URL |\n| `html.meta.og[]` | Open Graph and Twitter card tags, one entry per tag |\n| `html.meta.og[].name` | Tag name |\n| `html.meta.og[].value` | Tag value |\n| `html.meta.json_ld` | Structured data blocks, in expanded JSON-LD form |\n| `html.source_code` | The page HTML. For a page larger than `max_file_size`, a placeholder message instead of the HTML |\n| `html.source_code_hash` | SHA-256 hash of `html.source_code` |\n| `html.content` | The visible text of the page |\n| `html.content_hash` | SHA-256 hash of `html.content` |\n| `html.content_keywords` | The most frequent words of `html.content` |\n| `html.internal_links_fqdns` | Host names on the site's own domain that the page links to |\n| `html.external_links` | Links to other sites |\n| `html.external_links_fqdns` | Host names of those links |\n| `html.external_links_domains` | Registered domains of those links |\n| `html.script_links` | Scripts the page loads |\n| `html.iframe_links` | Iframes the page loads |\n| `html.favicon_links` | Icons the page links to |\n| `html.trackers[]` | Tracking IDs found in the page, one entry per tracker (e.g. Google Analytics) |\n| `html.trackers[].name` | Tracker name |\n| `html.trackers[].values` | IDs found for that tracker |\n| `html.emails` | E-mail addresses found in the page |\n| `html.emails_internal` | E-mail addresses found in the page that are on the site's own domain |\n| `html.inspect_disabled` | Whether the page tries to block inspection of its content |\n| `favicon[]` | One entry per icon |\n| `favicon[].url` | Icon URL |\n| `favicon[].hash` | Hash of the icon |\n| `robots_txt.content` | Content of the site's `robots.txt` |\n| `robots_txt.hash` | Hash of `robots_txt.content` |\n| `robots_txt.disallowed_links` | The `Disallow` paths |\n| `http.headers[]` | HTTP response headers, one entry per header |\n| `http.headers[].name` | Header name |\n| `http.headers[].value` | Header value |\n| `http.cookies[]` | Cookies the page set, one entry per cookie |\n| `http.cookies[].name` | Cookie name |\n| `http.cookies[].value` | Cookie value |\n| `http.cookies[].domain` | Domain the cookie applies to |\n| `http.cookies[].path` | Path the cookie applies to |\n| `http.cookies[].expires` | Expiry time |\n| `http.cookies[].secure` | Whether the cookie is sent over HTTPS only |\n| `http.cookies[].http_only` | Whether the cookie is hidden from JavaScript |\n| `http.cookies[].same_site` | The cookie's `SameSite` attribute |\n| `http.cookies[].same_party` | The cookie's `SameParty` attribute |\n| `http.cookies[].priority` | The cookie's `Priority` attribute |\n| `http.cookies[].size` | Size of the cookie, in bytes |\n| `http.cookies[].session` | Whether it is a session cookie |\n| `http.redirection_history[]` | Each URL on the way to the final page |\n| `http.redirection_history[].url` | The URL |\n| `http.redirection_history[].status_code` | The HTTP status it returned |\n| `screenshot` | Only with `screenshot=true`: the capture, with the `screenshot.*` fields below |\n| `screenshot.url` | The requested URL |\n| `screenshot.redirected_url` | The URL the browser ended up on after redirects |\n| `screenshot.screenshot_url` | Link to the JPEG image: a signed link that expires after 7 days. `null` if the capture was skipped |\n| `screenshot.connection_status` | `success` when the page was loaded |\n| `screenshot.check_date` | When the screenshot was taken (UTC) |\n| `connection_status` | `success` when the page was loaded |\n| `version` | Version of the result format (currently `1`) |\n| `check_date` | When the lookup was performed (UTC) |\n\n### Errors\n\n`400` (`10400`) if `url` is missing or invalid, or a parameter is out of range. The validation error currently names the parameter `domain`, although the request parameter is `url` (see the example). A `400` without `parameters` (only `details`, e.g. *\"Target is not allowed.\"*) means the target cannot be analyzed. `500` for an unexpected error. `503` means the service or its browser is busy: retry after the number of seconds in the `Retry-After` header. See **Getting Started → Errors**."
          },
          "response": []
        },
        {
          "name": "DNS History",
          "id": "22889cb1-8f67-5ba1-a91c-c8b46a4cf5f5",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/analyze/dns-history?domain=deepinfo.com&type=A",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "analyze",
                "dns-history"
              ],
              "query": [
                {
                  "key": "domain",
                  "value": "deepinfo.com",
                  "description": "**Required.** Domain name or FQDN, e.g. `deepinfo.com` or `www.deepinfo.com`. IP addresses are not accepted."
                },
                {
                  "key": "type",
                  "value": "A",
                  "description": "Record type to return, for example `A`. Omit to return every type."
                }
              ]
            },
            "description": "**Deepinfo Lookup DNS History API**\n\nReturns the **historical** DNS records Deepinfo has observed for a domain or FQDN, including values that have since changed or been removed (passive DNS). Use it to see how a domain's hosting, mail and name servers changed over time.\n\n### Response\n\n| Field | Description |\n|---|---|\n| `fqdn` | The queried name |\n| `dn` | Its registered domain |\n| `subdomain` | Subdomain part, or `null` |\n| `records[]` | One entry per record type |\n| `records[].type` | Record type, in lower case, for example `a` or `mx` |\n| `records[].values[]` | One entry per distinct value seen for that type |\n| `records[].values[].value` | The value |\n| `records[].values[].time` | Every time (UTC, newest first) that value was observed |\n\n### Errors\n\n`400` if `domain` is not a valid FQDN."
          },
          "response": []
        },
        {
          "name": "WHOIS History",
          "id": "2af5ed7f-eaf2-539b-a085-f484f33b1b9c",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/analyze/whois-history?domain=deepinfo.com",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "analyze",
                "whois-history"
              ],
              "query": [
                {
                  "key": "domain",
                  "value": "deepinfo.com",
                  "description": "**Required.** Domain name, e.g. `deepinfo.com`."
                }
              ]
            },
            "description": "**Deepinfo Lookup WHOIS History API**\n\nReturns the **historical** WHOIS records of a domain: every distinct registration record Deepinfo has observed, with the dates it was seen. Use it to track ownership, registrar and name server changes.\n\n### Response\n\nAn array. Each item is one distinct WHOIS record:\n\n| Field | Description |\n|---|---|\n| `whois` | The record, with the `whois.*` fields below |\n| `whois.check_date` | Check date of the record (UTC) |\n| `whois.create_date` | Registration date |\n| `whois.update_date` | Date of the last update |\n| `whois.expiry_date` | Expiry date |\n| `whois.registrar` | Registrar |\n| `whois.registrant.name` | Registrant name |\n| `whois.registrant.organization` | Registrant organization |\n| `whois.registrant.street` | Registrant street address |\n| `whois.registrant.city` | Registrant city |\n| `whois.registrant.state` | Registrant state or province |\n| `whois.registrant.postal_code` | Registrant postal code |\n| `whois.registrant.country` | Registrant country |\n| `whois.registrant.phone` | Registrant phone number |\n| `whois.registrant.email` | Registrant e-mail address |\n| `whois.name_servers` | Name servers |\n| `whois.domain_status` | Domain status codes |\n| `whois.whois_server` | WHOIS server |\n| `check_dates` | Every time (UTC) this exact record was observed |\n\n### Errors\n\n`400` if `domain` is not a valid domain."
          },
          "response": []
        }
      ]
    },
    {
      "name": "Discovery",
      "id": "7689caee-ea74-51be-a36d-9c9ea9a285be",
      "description": "Search Deepinfo's internet-wide domain dataset: find subdomains, associated domains, domains registered at the same time, and domains that share a WHOIS email, name server, IP or mail server.\n\nFinder endpoints support `export=true` to get a **download link** for the full result instead of a page (`export_format`: `json` or `csv`; `export_scope`: `basic`, `default` or `extended`).\n\nPagination: `page` ≤ 400, `page_size` 25–100. At most **10,000** results per query.",
      "item": [
        {
          "name": "Domain Search",
          "id": "7b1bd990-746b-5ba8-bd9c-7ec4121541e0",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/domain-search?page_size=25",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "domain-search"
              ],
              "query": [
                {
                  "key": "export",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "export_format",
                  "value": "",
                  "description": "One of: `json`, `csv`.",
                  "disabled": true
                },
                {
                  "key": "export_scope",
                  "value": "",
                  "description": "One of: `basic`, `default`, `extended`.",
                  "disabled": true
                },
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `400`. Default `1`.",
                  "disabled": true
                },
                {
                  "key": "page_size",
                  "value": "25",
                  "description": "Min `25`, max `100`. Default `100`."
                }
              ]
            },
            "description": "**Deepinfo Discovery Domain Search API**\n\nSearches Deepinfo's whole domain dataset with filters on WHOIS, DNS, SSL, web data and more. `result_count` is the true total; results page up to 10,000.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fqdn\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"punycode\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `wildcard`, `fuzzy`, `exists`** — 97 fields\n\n- `fqdn`: The full host name (FQDN) of the record in its ASCII (punycode) form, such as `www.example.com`. Search results return it as `punycode`.\n- `subdomain_last`: The leftmost label of the subdomain, compared in its ASCII (punycode) form: `a` in `a.b.example.com`, and `www` in `www.example.com`.\n- `subdomain_root`: The subdomain label directly in front of the registrable domain, compared in its ASCII (punycode) form: `b` in `a.b.example.com`, and `www` in `www.example.com`.\n- `domain`: The registrable domain the FQDN belongs to (`example.com` for `www.example.com`), compared in its ASCII (punycode) form. A filter on it matches the domain itself and all its subdomains.\n- `domain.name.language`: The language detected for the domain name, as a two-letter ISO 639-1 code such as `en`, `de` or `tr`. Search results return it as `domain.name.lang`.\n- `domain.name.keywords`: The words detected in the domain name, such as `deep` and `info` for `deepinfo`, so `cybersecurity` and `cyber-security` both contain the word `cyber`.\n- `domain.extension`: The extension of the registrable domain, everything after the name, such as `com`, `io` or `co.uk`, compared in its ASCII (punycode) form.\n- `domain.extension_root`: The top-level part of the extension, compared in its ASCII (punycode) form: `uk` for both `uk` and `co.uk`.\n- `domain.extension_sub`: The second-level part of a two-part extension, compared in its ASCII (punycode) form: `co` in `co.uk`. Single-part extensions such as `com` have none.\n- `domain.whois.registrar`: The registrar the domain is registered through, as named in its WHOIS record and stored in lower case, such as `godaddy.com, llc`.\n- `domain.whois.registrant.name`: The registrant's name (person or organization) from the domain's WHOIS record, stored in lower case.\n- `domain.whois.registrant.organization`: The registrant's organization from the domain's WHOIS record, stored in lower case, such as `cloudflare, inc.`.\n- `domain.whois.registrant.street`: The registrant's street address from the domain's WHOIS record, stored in lower case.\n- `domain.whois.registrant.city`: The registrant's city from the domain's WHOIS record, stored in lower case.\n- `domain.whois.registrant.state`: The registrant's state or region from the domain's WHOIS record, stored in lower case.\n- `domain.whois.registrant.postal_code`: The registrant's postal code from the domain's WHOIS record.\n- `domain.whois.registrant.country`: The registrant's country from the domain's WHOIS record, usually a two-letter ISO 3166-1 alpha-2 code in lower case, such as `de`.\n- `domain.whois.registrant.phone`: The registrant's phone number as written in the domain's WHOIS record.\n- `domain.whois.registrant.email`: The registrant's e-mail address from the domain's WHOIS record; it can be the relay address of a privacy service instead of the owner's own.\n- `domain.whois.name_servers`: The name servers listed in the domain's WHOIS record, as host names such as `ns1.example.com`.\n- `domain.whois.domain_status`: The status codes in the domain's WHOIS record, mostly EPP codes, in lower case without spaces, such as `clienttransferprohibited`, `clientdeleteprohibited`, `clientupdateprohibited`, `clientrenewprohibited`, `clienthold` or `ok`.\n- `domain.whois_normalized.registrant.organization`: The registrant's organization from WHOIS in normalized form: lower case with spaces and punctuation removed, so `cloudflare, inc.` becomes `cloudflareinc`. A pattern such as `*cloudflare*` finds it more reliably than an exact value.\n- `domain.whois_normalized.registrant.phone`: The registrant's phone number from WHOIS in normalized form: digits only, with `+`, dots and other separators removed.\n- `domain.whois_normalized.registrant.email`: The registrant's e-mail address as kept in `whois_normalized`; `email_fqdn_apex` and `email_domain_apex` hold its host and registrable domain.\n- `domain.whois_normalized.registrant.email_fqdn_apex`: The host part of the normalized registrant e-mail address, everything after the `@`: `mail.example.com` for `user@mail.example.com`.\n- `domain.whois_normalized.registrant.email_domain_apex`: The registrable domain of the normalized registrant e-mail address: `example.com` for `user@mail.example.com`.\n- `domain.whois_registrant_email_historical`: Every registrant e-mail address seen in the domain's WHOIS records over time.\n- `domain.dns.a.ip_addresses`: The IPv4 addresses in the A record of the registrable domain (`domain.dns`); `dns.a.ip_addresses` holds those of the FQDN itself.\n- `domain.ip_history`: Every IP address the registrable domain has resolved to over time, so it also finds domains that have since moved.\n- `dns.a.ip_addresses`: The IPv4 addresses in the FQDN's DNS A record.\n- `dns.aaaa.ip_addresses`: The IPv6 addresses in the FQDN's DNS AAAA record.\n- `dns.ns.name_servers`: The name servers in the FQDN's DNS NS record, as host names.\n- `dns.mx.mail_servers`: The mail server host names in the FQDN's DNS MX record, such as `aspmx.l.google.com` for Google Workspace.\n- `dns.soa.mnames`: The MNAME of the FQDN's SOA record: the primary name server of the zone.\n- `dns.soa.rnames`: The RNAME of the FQDN's SOA record, the zone's responsible mailbox in DNS form: `dns.example.com` stands for the mailbox `dns` at `example.com`.\n- `dns.soa.rname_emails`: The RNAME of the FQDN's SOA record written as an e-mail address, such as `user@example.com`.\n- `dns.txt.values`: The text of the FQDN's DNS TXT records, such as SPF policies and site-verification tokens, stored as quoted text (each value starts with `\"`).\n- `dns.cname.values`: The target of the FQDN's DNS CNAME record, stored as a fully qualified name with the final dot, such as `www.example.com.`.\n- `dns.others.type`: The type of a DNS record that has no field of its own (`dns.others`), in upper case; values seen include `DNSKEY`, `DS`, `SPF`, `HINFO`, `RRSIG`, `NSEC3`, `NSEC3PARAM`, `CAA`, `PTR` and `TYPE65`.\n- `dns.others.values`: The data of a record in `dns.others`, as text in zone-file notation, such as the flags, protocol, algorithm and key of a `DNSKEY` record.\n- `ip_history`: Every IP address the FQDN has resolved to over time, including addresses it no longer uses.\n- `ssl.fqdns`: The host names the FQDN's TLS certificate is valid for, in lower case; wildcard names appear without the leading `*.`.\n- `ssl.fingerprint.sha256`: The SHA-256 fingerprint of the FQDN's TLS certificate, as 64 lower-case hex characters; a fingerprint identifies one certificate, so it finds every host that serves it.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the FQDN's TLS certificate, as 40 lower-case hex characters.\n- `ssl.fingerprint.md5`: The MD5 fingerprint of the FQDN's TLS certificate, as 32 lower-case hex characters.\n- `ssl.signature.value`: The signature of the FQDN's TLS certificate, Base64-encoded.\n- `ssl.issuer_dn`: The distinguished name of the certificate issuer as one string, such as `CN=YR2,O=Let's Encrypt,C=US`, compared exactly as the response shows it.\n- `ssl.issuer.common_name`: The common name (CN) in the issuer's name, usually the name of the issuing CA certificate, such as `YR2`, `YR1` or `WE1`.\n- `ssl.issuer.country`: The country (C) in the issuer's name, as a two-letter code in the case the certificate uses, usually upper case such as `US` or `GB`.\n- `ssl.issuer.state`: The state or province (ST) in the issuer's name, as written in the certificate.\n- `ssl.issuer.locality`: The locality or city (L) in the issuer's name, as written in the certificate.\n- `ssl.issuer.organization`: The organization (O) in the issuer's name, as written in the certificate, such as `Let's Encrypt`, `Google Trust Services` or `DigiCert Inc`.\n- `ssl.issuer.organizational_unit`: The organizational unit (OU) in the issuer's name, as written in the certificate.\n- `ssl.subject_dn`: The distinguished name of the certificate subject as one string; a value that starts with `CN=*.` belongs to a wildcard certificate.\n- `ssl.subject.common_name`: The common name (CN) in the subject's name, usually the host name the certificate was issued for, such as `example.com`.\n- `ssl.subject.country`: The country (C) in the subject's name, as a two-letter code in the case the certificate uses, such as `DE`.\n- `ssl.subject.state`: The state or province (ST) in the subject's name, as written in the certificate.\n- `ssl.subject.locality`: The locality or city (L) in the subject's name, as written in the certificate.\n- `ssl.subject.organization`: The organization (O) in the subject's name, as written in the certificate: the company the certificate was issued to, when it names one.\n- `ssl.subject.organizational_unit`: The organizational unit (OU) in the subject's name, as written in the certificate.\n- `ssl.extensions.subject_alt_name.dns_names`: The DNS names in the certificate's Subject Alternative Name (SAN) extension, including wildcard names such as `*.example.com`.\n- `webdata.url`: The URL recorded for Deepinfo's web visit to the FQDN (`webdata` is what Deepinfo saw over HTTP(S)); it takes filters, but search results do not return it.\n- `webdata.connection_status`: The outcome of Deepinfo's web visit to the FQDN: `success`, `not_resolved`, `timeout`, `thread_timeout`, `reset`, `refused`, `connection_error`, `ssl_error` or `too_many_redirects`.\n- `webdata.html.source_code_hash`: The SHA-256 hash of the HTML source Deepinfo received on its web visit to the FQDN, as 64 lower-case hex characters, so identical pages share the same value.\n- `webdata.http.redirection_history.url`: The URL of one step of Deepinfo's web visit; `redirection_history` lists every URL requested, from the first one to the final page.\n- `webdata.http.final_url`: The URL Deepinfo's web visit ended on after all redirects, exactly as recorded, with or without a trailing `/`.\n- `webdata.http.final_fqdn`: The host name of the URL Deepinfo's web visit ended on after all redirects; an internationalized name is stored and compared in its readable (Unicode) form, not as punycode.\n- `webdata.http.final_domain`: The registrable domain of the host Deepinfo's web visit ended on after all redirects, such as `cloudflare.com`; an internationalized name is stored and compared in its readable (Unicode) form, not as punycode.\n- `webdata.http.headers.others.name`: The name of a response header that has no field of its own (`headers.others`), in lower case with dashes written as underscores: `cf-ray` becomes `cf_ray`.\n- `webdata.http.headers.others.value`: The value of a response header listed in `headers.others`, as text.\n- `webdata.http.headers.access_control_allow_headers`: The value of the `Access-Control-Allow-Headers` response header on Deepinfo's web visit to the FQDN: the request headers the site accepts in cross-origin (CORS) requests.\n- `webdata.http.headers.access_control_allow_methods`: The value of the `Access-Control-Allow-Methods` response header on Deepinfo's web visit to the FQDN: the HTTP methods the site allows in cross-origin (CORS) requests, such as `GET, POST, OPTIONS`.\n- `webdata.http.headers.access_control_allow_origin`: The value of the `Access-Control-Allow-Origin` response header on Deepinfo's web visit to the FQDN: the origins allowed to read the response in cross-origin (CORS) requests; `*` means any origin.\n- `webdata.http.headers.cache_control`: The value of the `Cache-Control` response header on Deepinfo's web visit to the FQDN: the caching rules, such as `no-store` or `max-age=0`.\n- `webdata.http.headers.clear_site_data`: The value of the `Clear-Site-Data` response header on Deepinfo's web visit to the FQDN: the browser data the site asks to clear, such as `cache`.\n- `webdata.http.headers.content_encoding`: The value of the `Content-Encoding` response header on Deepinfo's web visit to the FQDN: the compression used, such as `gzip`.\n- `webdata.http.headers.content_security_policy`: The value of the `Content-Security-Policy` response header on Deepinfo's web visit to the FQDN: the sources the page may load scripts and other content from.\n- `webdata.http.headers.content_type`: The value of the `Content-Type` response header on Deepinfo's web visit to the FQDN: the media type and character set, such as `text/html; charset=UTF-8`.\n- `webdata.http.headers.cross_origin_embedder_policy`: The value of the `Cross-Origin-Embedder-Policy` response header on Deepinfo's web visit to the FQDN, such as `require-corp` or `credentialless`.\n- `webdata.http.headers.cross_origin_opener_policy`: The value of the `Cross-Origin-Opener-Policy` response header on Deepinfo's web visit to the FQDN, such as `same-origin` or `unsafe-none`.\n- `webdata.http.headers.cross_origin_resource_policy`: The value of the `Cross-Origin-Resource-Policy` response header on Deepinfo's web visit to the FQDN, such as `same-origin` or `cross-origin`.\n- `webdata.http.headers.expect_ct`: The value of the `Expect-CT` response header on Deepinfo's web visit to the FQDN (Certificate Transparency enforcement), such as `max-age=86400, enforce`.\n- `webdata.http.headers.feature_policy`: The value of the `Feature-Policy` response header on Deepinfo's web visit to the FQDN: the older form of the policy that limits browser features such as camera or geolocation.\n- `webdata.http.headers.last_modified`: The value of the `Last-Modified` response header on Deepinfo's web visit to the FQDN, stored as the header text (an HTTP date such as `Tue, 20 Jan 2026 04:02:54 GMT`), so it takes text operators, not date ranges.\n- `webdata.http.headers.permission_policy`: The value of the `Permission-Policy` response header on Deepinfo's web visit to the FQDN (singular spelling). The standard `Permissions-Policy` header is listed in `webdata.http.headers.others` as `permissions_policy`.\n- `webdata.http.headers.referrer_policy`: The value of the `Referrer-Policy` response header on Deepinfo's web visit to the FQDN, such as `strict-origin-when-cross-origin` or `no-referrer`.\n- `webdata.http.headers.server`: The value of the `Server` response header on Deepinfo's web visit to the FQDN: the web server software the site reports, such as `nginx`, `Apache`, `LiteSpeed` or `cloudflare`.\n- `webdata.http.headers.set_cookie`: The value of the `Set-Cookie` response header on Deepinfo's web visit to the FQDN, as text starting with the cookie name, such as `PHPSESSID=`.\n- `webdata.http.headers.strict_transport_security`: The value of the `Strict-Transport-Security` response header on Deepinfo's web visit to the FQDN (HSTS), such as `max-age=31536000; includeSubDomains; preload`.\n- `webdata.http.headers.x_content_type_options`: The value of the `X-Content-Type-Options` response header on Deepinfo's web visit to the FQDN, usually `nosniff`.\n- `webdata.http.headers.x_download_options`: The value of the `X-Download-Options` response header on Deepinfo's web visit to the FQDN, usually `noopen`.\n- `webdata.http.headers.x_frame_options`: The value of the `X-Frame-Options` response header on Deepinfo's web visit to the FQDN: whether other sites may show the page in a frame, such as `SAMEORIGIN` or `DENY`, in the case the site sent.\n- `webdata.http.headers.x_permitted_cross_domain_policies`: The value of the `X-Permitted-Cross-Domain-Policies` response header on Deepinfo's web visit to the FQDN, such as `none`.\n- `webdata.http.headers.x_powered_by`: The value of the `X-Powered-By` response header on Deepinfo's web visit to the FQDN: the technology the site reports, such as `PHP/8.2.32`, `ASP.NET` or `Next.js`.\n- `webdata.http.headers.x_xss_protection`: The value of the `X-XSS-Protection` response header on Deepinfo's web visit to the FQDN, such as `1; mode=block` or `0`.\n- `webdata.http.cookies.name`: The name of a cookie the site set on Deepinfo's web visit, such as `PHPSESSID` or `__cf_bm`.\n- `webdata.http.cookies.value`: The value of a cookie the site set on Deepinfo's web visit, as text.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 34 fields\n\n- `type`: Whether the record is a registrable domain or a subdomain: `1` = domain (such as `example.com`), `2` = subdomain (such as `www.example.com`).\n- `subdomain.length`: The number of characters in the subdomain part (0 to 255), counted in its ASCII (punycode) form without the dots between labels: `6` for `api.dev.example.com`.\n- `subdomain_level_count`: The number of labels in front of the registrable domain: `0` for the domain itself, `1` for `www.example.com`, `2` for `a.b.example.com`.\n- `domain.name.length`: The number of characters in the domain name without its extension, counted in its ASCII (punycode) form (0 to 63).\n- `domain.name.keyword_count`: The number of words detected in the domain name (the length of `domain.name.keywords`).\n- `domain.extension_type`: The kind of extension: `1` = generic (gTLD, such as `.com`), `2` = country code (ccTLD, such as `.de` or `.co.uk`).\n- `domain.whois.create_date`: The date the registrable domain was created (registered), from its WHOIS record (UTC, ISO 8601).\n- `domain.whois.update_date`: The last-updated date that the domain's WHOIS record itself reports (UTC, ISO 8601); `domain.whois_last_change_date` is when Deepinfo saw the record change.\n- `domain.whois.expiry_date`: The date the domain's registration expires, from its WHOIS record (UTC, ISO 8601).\n- `domain.whois_create_date_historical`: Every creation date seen in the domain's WHOIS records over time (UTC, ISO 8601), so a domain that was registered again still matches on its earlier dates.\n- `domain.whois_last_change_date`: The last time Deepinfo saw the domain's WHOIS record change (UTC, ISO 8601).\n- `domain.dns.a.update_date`: The update date Deepinfo recorded for the registrable domain's A records (UTC, ISO 8601); it is set even when the domain has no A record.\n- `domain.dns_update_date`: A DNS update date of the registrable domain (UTC, ISO 8601) that takes date filters; search results do not return this field.\n- `domain.dns_last_change_date`: The last time Deepinfo saw the DNS records of the registrable domain change (UTC, ISO 8601).\n- `domain.ssl.validity.start_date`: The date the registrable domain's TLS certificate became valid, its not-before date (UTC, ISO 8601). `ssl.validity.start_date` holds the same for the FQDN's own certificate.\n- `domain.ssl.validity.end_date`: The date the registrable domain's TLS certificate expires, its not-after date (UTC, ISO 8601). `ssl.validity.end_date` holds the same for the FQDN's own certificate.\n- `domain.ssl_last_change_date`: The last time Deepinfo saw the registrable domain's TLS certificate change (UTC, ISO 8601).\n- `dns.a.update_date`: The update date Deepinfo recorded for the FQDN's A records (UTC, ISO 8601); it is set even when the FQDN has no A record.\n- `dns.aaaa.update_date`: The update date Deepinfo recorded for the FQDN's AAAA records (UTC, ISO 8601); it is set even when the FQDN has no AAAA record.\n- `dns.ns.update_date`: The update date Deepinfo recorded for the FQDN's NS records (UTC, ISO 8601); it is set even when the FQDN has no NS record.\n- `dns.mx.update_date`: The update date Deepinfo recorded for the FQDN's MX records (UTC, ISO 8601); it is set even when the FQDN has no MX record.\n- `dns.soa.update_date`: The update date Deepinfo recorded for the FQDN's SOA records (UTC, ISO 8601); it is set even when the FQDN has no SOA record.\n- `dns.txt.update_date`: The update date Deepinfo recorded for the FQDN's TXT records (UTC, ISO 8601); it is set even when the FQDN has no TXT record.\n- `dns.cname.update_date`: The update date Deepinfo recorded for the FQDN's CNAME records (UTC, ISO 8601); it is set even when the FQDN has no CNAME record.\n- `dns.others.update_date`: The update date Deepinfo recorded for a record in `dns.others` (UTC, ISO 8601).\n- `dns_update_date`: A DNS update date of the FQDN (UTC, ISO 8601) that takes date filters; search results do not return this field.\n- `dns_last_change_date`: The last time Deepinfo saw the DNS records of the FQDN change (UTC, ISO 8601).\n- `ssl.validity.start_date`: The date the FQDN's TLS certificate became valid, its not-before date (UTC, ISO 8601).\n- `ssl.validity.end_date`: The date the FQDN's TLS certificate expires, its not-after date (UTC, ISO 8601).\n- `ssl.validity.length`: The validity period of the FQDN's TLS certificate in seconds, from start date to end date: 7,776,000 seconds are 90 days.\n- `ssl_last_change_date`: The last time Deepinfo saw the FQDN's TLS certificate change (UTC, ISO 8601).\n- `webdata.http.status_code_first`: The HTTP status code of the first response on Deepinfo's web visit to the FQDN, such as `200`, or `301` for a permanent redirect.\n- `webdata.http.status_code_last`: The HTTP status code of the final response on Deepinfo's web visit, after all redirects, such as `200`, `403` or `404`.\n- `webdata.http.redirection_history.status_code`: The HTTP status code returned at one step of Deepinfo's web visit, such as `301` or `302` for a redirect and `200` for the final page.\n\n**`eq`, `in`, `exists`** — 15 fields\n\n- `is_idn`: `true` when the FQDN is an internationalized domain name (IDN) with non-ASCII characters; `punycode` then holds its ASCII form and `unicode` the readable one.\n- `subdomain.is_idn`: `true` when the subdomain part contains non-ASCII (internationalized) characters.\n- `subdomain.contains_letter`: `true` when the subdomain part contains at least one letter, checked on its readable (Unicode) form.\n- `subdomain.contains_number`: `true` when the subdomain part contains at least one digit, checked on its readable (Unicode) form, so the digits of an `xn--` punycode form do not count.\n- `subdomain.contains_hyphen`: `true` when the subdomain part contains at least one hyphen, checked on its readable (Unicode) form, so the `xn--` prefix of an IDN does not count.\n- `name.contains_confusable`: `true` when the FQDN's name (without its extension) contains confusable characters: letters that look like others, such as Cyrillic `а` and Latin `a`, a common trick in look-alike domains.\n- `domain.is_idn`: `true` when the registrable domain contains non-ASCII (internationalized) characters.\n- `domain.name.contains_letter`: `true` when the domain name (without its extension) contains at least one letter, checked on its readable (Unicode) form.\n- `domain.name.contains_number`: `true` when the domain name (without its extension) contains at least one digit, checked on its readable (Unicode) form, so the digits of an `xn--` punycode form do not count.\n- `domain.name.contains_hyphen`: `true` when the domain name (without its extension) contains at least one hyphen, checked on its readable (Unicode) form, so the `xn--` prefix of an IDN does not count.\n- `domain.extension.is_idn`: `true` when the extension contains non-ASCII (internationalized) characters, such as `.рф` (`xn--p1ai`).\n- `domain.whois_privacy_enabled`: `true` when the domain's WHOIS record hides the registrant's details, through a privacy service or redaction, `false` when it does not.\n- `ssl.signature.is_self_signed`: `true` when the FQDN's TLS certificate is self-signed, signed with its own key instead of by a certificate authority.\n- `ssl.signature.is_valid`: `true` when the signature of the FQDN's TLS certificate validates, `false` when it does not.\n- `webdata.http.external_redirection`: `true` when Deepinfo's web visit was redirected to a different registrable domain, `false` when it ended on the FQDN's own domain, for example on its `www.` host.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 2 fields\n\n- `subdomain`: The subdomain part of the FQDN, everything in front of the registrable domain (`mail` in `mail.example.com`), compared in its ASCII (punycode) form. It is `null` for a registrable domain.\n- `domain.name`: The name of the registrable domain without its extension, compared in its ASCII (punycode) form: `example` in `example.com`, and the same when the extension has two parts, such as `co.uk`.\n\n**`eq`, `in`, `startswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 1 field\n\n- `name.latinized`: Latin look-alike forms of the FQDN's name (the FQDN without its extension) when it has non-Latin or accented letters: each character becomes the Latin letter it resembles (Cyrillic `р` becomes `p`), so `istanbul` also finds names written with `İ`.\n\nSortable fields:\n\n- `punycode`: The FQDN in its ASCII (punycode) form, such as `www.example.com`; sorting on it lists results alphabetically. Filters use the same value under the name `fqdn`.\n- `domain.extension.punycode`: The extension of the registrable domain in its ASCII (punycode) form, such as `com` or `co.uk`; sorting on it lists results by extension.\n- `domain.whois.create_date`: The date the registrable domain was created (registered), from its WHOIS record (UTC, ISO 8601).\n- `domain.whois.expiry_date`: The date the domain's registration expires, from its WHOIS record (UTC, ISO 8601).\n- `domain.whois.update_date`: The last-updated date that the domain's WHOIS record itself reports (UTC, ISO 8601); `domain.whois_last_change_date` is when Deepinfo saw the record change.\n- `domain.whois_last_change_date`: The last time Deepinfo saw the domain's WHOIS record change (UTC, ISO 8601).\n- `dns_last_change_date`: The last time Deepinfo saw the DNS records of the FQDN change (UTC, ISO 8601).\n- `ssl_last_change_date`: The last time Deepinfo saw the FQDN's TLS certificate change (UTC, ISO 8601).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].punycode` | string |  |\n| `results[].unicode` | string |  |\n| `results[].is_idn` | boolean |  |\n| `results[].subdomain` | object |  |\n| `results[].subdomain_last` | object |  |\n| `results[].subdomain_root` | object |  |\n| `results[].name` | object |  |\n| `results[].domain` | object |  |\n| `results[].type` | integer |  |\n| `results[].subdomain_level_count` | integer |  |\n| `results[].dns` | object |  |\n| `results[].dns_last_change_date` | string | date-time |\n| `results[].ip_history` | array of string |  |\n| `results[].ssl` | object |  |\n| `results[].ssl_last_change_date` | string | date-time |\n| `results[].webdata` | object |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        },
        {
          "name": "Domain Detail",
          "id": "a8698ebf-3019-5eaa-a203-8452a23e83b7",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/domain-detail?domain=deepinfo.com",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "domain-detail"
              ],
              "query": [
                {
                  "key": "domain",
                  "value": "deepinfo.com",
                  "description": "**Required.**"
                }
              ]
            },
            "description": "**Deepinfo Discovery Domain Detail API**\n\nReturns everything Deepinfo has on one domain: WHOIS, DNS, SSL, web data and more.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `punycode` | string |  |\n| `unicode` | string |  |\n| `is_idn` | boolean |  |\n| `subdomain` | object |  |\n| `subdomain_last` | object |  |\n| `subdomain_root` | object |  |\n| `name` | object |  |\n| `domain` | object |  |\n| `type` | integer |  |\n| `subdomain_level_count` | integer |  |\n| `dns` | object |  |\n| `dns_last_change_date` | string | date-time |\n| `ip_history` | array of string |  |\n| `ssl` | object |  |\n| `ssl_last_change_date` | string | date-time |\n| `webdata` | object |  |"
          },
          "response": []
        },
        {
          "name": "All TLDs",
          "id": "e31d460e-c66a-5938-b521-dc2b0198d52b",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/all-tlds?domain=deepinfo.com&page_size=25",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "all-tlds"
              ],
              "query": [
                {
                  "key": "ordering",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "export",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "export_format",
                  "value": "",
                  "description": "One of: `json`, `csv`.",
                  "disabled": true
                },
                {
                  "key": "export_scope",
                  "value": "",
                  "description": "One of: `basic`, `default`, `extended`.",
                  "disabled": true
                },
                {
                  "key": "domain",
                  "value": "deepinfo.com",
                  "description": "**Required.**"
                },
                {
                  "key": "include_subdomains",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `400`. Default `1`.",
                  "disabled": true
                },
                {
                  "key": "page_size",
                  "value": "25",
                  "description": "Min `25`, max `100`. Default `100`."
                }
              ]
            },
            "description": "**Deepinfo Discovery All TLDs API**\n\nFinds the same name registered under other TLDs (e.g. `deepinfo.net`, `deepinfo.io`).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].punycode` | string |  |\n| `results[].unicode` | string |  |\n| `results[].is_idn` | boolean |  |\n| `results[].subdomain` | object |  |\n| `results[].subdomain_last` | object |  |\n| `results[].subdomain_root` | object |  |\n| `results[].name` | object |  |\n| `results[].domain` | object |  |\n| `results[].type` | integer |  |\n| `results[].subdomain_level_count` | integer |  |\n| `results[].dns` | object |  |\n| `results[].dns_last_change_date` | string | date-time |\n| `results[].ip_history` | array of string |  |\n| `results[].ssl` | object |  |\n| `results[].ssl_last_change_date` | string | date-time |\n| `results[].webdata` | object |  |\n\nPaginated. See **Getting Started → Pagination**."
          },
          "response": []
        },
        {
          "name": "Associated Domain Finder",
          "id": "a931b790-8101-5b55-b204-602f0b2a219d",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/associated-domain-finder?domain=deepinfo.com&page_size=25",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "associated-domain-finder"
              ],
              "query": [
                {
                  "key": "ordering",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "export",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "export_format",
                  "value": "",
                  "description": "One of: `json`, `csv`.",
                  "disabled": true
                },
                {
                  "key": "export_scope",
                  "value": "",
                  "description": "One of: `basic`, `default`, `extended`.",
                  "disabled": true
                },
                {
                  "key": "domain",
                  "value": "deepinfo.com",
                  "description": "**Required.**"
                },
                {
                  "key": "association",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "strict",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "include_subdomains",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `400`. Default `1`.",
                  "disabled": true
                },
                {
                  "key": "page_size",
                  "value": "25",
                  "description": "Min `25`, max `100`. Default `100`."
                }
              ]
            },
            "description": "**Deepinfo Discovery Associated Domain Finder API**\n\nFinds domains associated with a domain: same registrant email, organization or phone, same name servers, IP, mail servers or SSL organization. Choose the `association` type(s); `strict` requires every association to match.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `domain` | string |  |\n| `requested_association_parameters` | array of string |  |\n| `applied_association_parameters` | array of string |  |\n| `results[].punycode` | string |  |\n| `results[].unicode` | string |  |\n| `results[].is_idn` | boolean |  |\n| `results[].subdomain` | object |  |\n| `results[].subdomain_last` | object |  |\n| `results[].subdomain_root` | object |  |\n| `results[].name` | object |  |\n| `results[].domain` | object |  |\n| `results[].type` | integer |  |\n| `results[].subdomain_level_count` | integer |  |\n| `results[].dns` | object |  |\n| `results[].dns_last_change_date` | string | date-time |\n| `results[].ip_history` | array of string |  |\n| `results[].ssl` | object |  |\n| `results[].ssl_last_change_date` | string | date-time |\n| `results[].webdata` | object |  |\n\nPaginated. See **Getting Started → Pagination**."
          },
          "response": []
        },
        {
          "name": "Reverse IP",
          "id": "90c5dae7-82de-57b5-9262-cb06e2eca1e2",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/reverse-ip?ip=104.26.10.21&page_size=25",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "reverse-ip"
              ],
              "query": [
                {
                  "key": "ordering",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "export",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "export_format",
                  "value": "",
                  "description": "One of: `json`, `csv`.",
                  "disabled": true
                },
                {
                  "key": "export_scope",
                  "value": "",
                  "description": "One of: `basic`, `default`, `extended`.",
                  "disabled": true
                },
                {
                  "key": "ip",
                  "value": "104.26.10.21",
                  "description": "**Required.**"
                },
                {
                  "key": "mask",
                  "value": "",
                  "description": "One of: `8`, `16`, `24`, `32`.",
                  "disabled": true
                },
                {
                  "key": "include_subdomains",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `400`. Default `1`.",
                  "disabled": true
                },
                {
                  "key": "page_size",
                  "value": "25",
                  "description": "Min `25`, max `100`. Default `100`."
                }
              ]
            },
            "description": "**Deepinfo Discovery Reverse IP API**\n\nFinds domains that resolve to `ip`, or to its network when `mask` is 8, 16 or 24.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].punycode` | string |  |\n| `results[].unicode` | string |  |\n| `results[].is_idn` | boolean |  |\n| `results[].subdomain` | object |  |\n| `results[].subdomain_last` | object |  |\n| `results[].subdomain_root` | object |  |\n| `results[].name` | object |  |\n| `results[].domain` | object |  |\n| `results[].type` | integer |  |\n| `results[].subdomain_level_count` | integer |  |\n| `results[].dns` | object |  |\n| `results[].dns_last_change_date` | string | date-time |\n| `results[].ip_history` | array of string |  |\n| `results[].ssl` | object |  |\n| `results[].ssl_last_change_date` | string | date-time |\n| `results[].webdata` | object |  |\n\nPaginated. See **Getting Started → Pagination**."
          },
          "response": []
        },
        {
          "name": "Reverse MX",
          "id": "112c1791-7207-5429-b809-f97838a6472c",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/reverse-mx?mx=aspmx.l.google.com&page_size=25",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "reverse-mx"
              ],
              "query": [
                {
                  "key": "ordering",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "export",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "export_format",
                  "value": "",
                  "description": "One of: `json`, `csv`.",
                  "disabled": true
                },
                {
                  "key": "export_scope",
                  "value": "",
                  "description": "One of: `basic`, `default`, `extended`.",
                  "disabled": true
                },
                {
                  "key": "mx",
                  "value": "aspmx.l.google.com",
                  "description": "**Required.**"
                },
                {
                  "key": "apex",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "include_subdomains",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `400`. Default `1`.",
                  "disabled": true
                },
                {
                  "key": "page_size",
                  "value": "25",
                  "description": "Min `25`, max `100`. Default `100`."
                }
              ]
            },
            "description": "**Deepinfo Discovery Reverse MX API**\n\nFinds domains that use the mail server `mx`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].punycode` | string |  |\n| `results[].unicode` | string |  |\n| `results[].is_idn` | boolean |  |\n| `results[].subdomain` | object |  |\n| `results[].subdomain_last` | object |  |\n| `results[].subdomain_root` | object |  |\n| `results[].name` | object |  |\n| `results[].domain` | object |  |\n| `results[].type` | integer |  |\n| `results[].subdomain_level_count` | integer |  |\n| `results[].dns` | object |  |\n| `results[].dns_last_change_date` | string | date-time |\n| `results[].ip_history` | array of string |  |\n| `results[].ssl` | object |  |\n| `results[].ssl_last_change_date` | string | date-time |\n| `results[].webdata` | object |  |\n\nPaginated. See **Getting Started → Pagination**."
          },
          "response": []
        },
        {
          "name": "Reverse NS",
          "id": "312a99ec-d342-5690-b35a-59d0d00ebf0a",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/reverse-ns?ns=may.ns.cloudflare.com&page_size=25",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "reverse-ns"
              ],
              "query": [
                {
                  "key": "ordering",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "export",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "export_format",
                  "value": "",
                  "description": "One of: `json`, `csv`.",
                  "disabled": true
                },
                {
                  "key": "export_scope",
                  "value": "",
                  "description": "One of: `basic`, `default`, `extended`.",
                  "disabled": true
                },
                {
                  "key": "ns",
                  "value": "may.ns.cloudflare.com",
                  "description": "**Required.**"
                },
                {
                  "key": "apex",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "include_subdomains",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `400`. Default `1`.",
                  "disabled": true
                },
                {
                  "key": "page_size",
                  "value": "25",
                  "description": "Min `25`, max `100`. Default `100`."
                }
              ]
            },
            "description": "**Deepinfo Discovery Reverse NS API**\n\nFinds domains that use the name server `ns`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].punycode` | string |  |\n| `results[].unicode` | string |  |\n| `results[].is_idn` | boolean |  |\n| `results[].subdomain` | object |  |\n| `results[].subdomain_last` | object |  |\n| `results[].subdomain_root` | object |  |\n| `results[].name` | object |  |\n| `results[].domain` | object |  |\n| `results[].type` | integer |  |\n| `results[].subdomain_level_count` | integer |  |\n| `results[].dns` | object |  |\n| `results[].dns_last_change_date` | string | date-time |\n| `results[].ip_history` | array of string |  |\n| `results[].ssl` | object |  |\n| `results[].ssl_last_change_date` | string | date-time |\n| `results[].webdata` | object |  |\n\nPaginated. See **Getting Started → Pagination**."
          },
          "response": []
        },
        {
          "name": "Reverse WHOIS Email",
          "id": "b090f41c-d5d4-5872-a0c9-67d9a7e956e3",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/reverse-email?email=user@cloudflare.com&page_size=25",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "reverse-email"
              ],
              "query": [
                {
                  "key": "ordering",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "export",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "export_format",
                  "value": "",
                  "description": "One of: `json`, `csv`.",
                  "disabled": true
                },
                {
                  "key": "export_scope",
                  "value": "",
                  "description": "One of: `basic`, `default`, `extended`.",
                  "disabled": true
                },
                {
                  "key": "email",
                  "value": "user@cloudflare.com",
                  "description": "**Required.**"
                },
                {
                  "key": "apex",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "include_subdomains",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `400`. Default `1`.",
                  "disabled": true
                },
                {
                  "key": "page_size",
                  "value": "25",
                  "description": "Min `25`, max `100`. Default `100`."
                }
              ]
            },
            "description": "**Deepinfo Discovery Reverse WHOIS Email API**\n\nFinds domains whose WHOIS registrant email is `email`. `apex=true` matches the whole email domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].punycode` | string |  |\n| `results[].unicode` | string |  |\n| `results[].is_idn` | boolean |  |\n| `results[].subdomain` | object |  |\n| `results[].subdomain_last` | object |  |\n| `results[].subdomain_root` | object |  |\n| `results[].name` | object |  |\n| `results[].domain` | object |  |\n| `results[].type` | integer |  |\n| `results[].subdomain_level_count` | integer |  |\n| `results[].dns` | object |  |\n| `results[].dns_last_change_date` | string | date-time |\n| `results[].ip_history` | array of string |  |\n| `results[].ssl` | object |  |\n| `results[].ssl_last_change_date` | string | date-time |\n| `results[].webdata` | object |  |\n\nPaginated. See **Getting Started → Pagination**."
          },
          "response": []
        },
        {
          "name": "Same-Time Registered Domain Finder",
          "id": "64ae9090-6293-5d84-813f-447cc35f20df",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/sametime-domain-finder?domain=deepinfo.com&page_size=25",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "sametime-domain-finder"
              ],
              "query": [
                {
                  "key": "ordering",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "export",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "export_format",
                  "value": "",
                  "description": "One of: `json`, `csv`.",
                  "disabled": true
                },
                {
                  "key": "export_scope",
                  "value": "",
                  "description": "One of: `basic`, `default`, `extended`.",
                  "disabled": true
                },
                {
                  "key": "domain",
                  "value": "deepinfo.com",
                  "description": "**Required.**"
                },
                {
                  "key": "interval",
                  "value": "5",
                  "description": "Min `1`, max `60`. Default `5`.",
                  "disabled": true
                },
                {
                  "key": "include_subdomains",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `400`. Default `1`.",
                  "disabled": true
                },
                {
                  "key": "page_size",
                  "value": "25",
                  "description": "Min `25`, max `100`. Default `100`."
                }
              ]
            },
            "description": "**Deepinfo Discovery Same-Time Registered Domain Finder API**\n\nFinds domains registered by the same registrant within `interval` minutes (1–60, default 5) of the given domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].punycode` | string |  |\n| `results[].unicode` | string |  |\n| `results[].is_idn` | boolean |  |\n| `results[].subdomain` | object |  |\n| `results[].subdomain_last` | object |  |\n| `results[].subdomain_root` | object |  |\n| `results[].name` | object |  |\n| `results[].domain` | object |  |\n| `results[].type` | integer |  |\n| `results[].subdomain_level_count` | integer |  |\n| `results[].dns` | object |  |\n| `results[].dns_last_change_date` | string | date-time |\n| `results[].ip_history` | array of string |  |\n| `results[].ssl` | object |  |\n| `results[].ssl_last_change_date` | string | date-time |\n| `results[].webdata` | object |  |\n\nPaginated. See **Getting Started → Pagination**."
          },
          "response": []
        },
        {
          "name": "Subdomain Finder",
          "id": "d2d79b03-0114-5b6e-a4e7-b209b51ebfd3",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/subdomain-finder?export=true&export_format=csv&export_scope=basic&domain=deepinfo.com",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "subdomain-finder"
              ],
              "query": [
                {
                  "key": "ordering",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "export",
                  "value": "true",
                  "description": "Default `false`."
                },
                {
                  "key": "export_format",
                  "value": "csv",
                  "description": "One of: `json`, `csv`."
                },
                {
                  "key": "export_scope",
                  "value": "basic",
                  "description": "One of: `basic`, `default`, `extended`."
                },
                {
                  "key": "domain",
                  "value": "deepinfo.com",
                  "description": "**Required.**"
                },
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `400`. Default `1`.",
                  "disabled": true
                },
                {
                  "key": "page_size",
                  "value": "100",
                  "description": "Min `25`, max `100`. Default `100`.",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Discovery Subdomain Finder API**\n\nFinds all known subdomains of a domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].punycode` | string |  |\n| `results[].unicode` | string |  |\n| `results[].is_idn` | boolean |  |\n| `results[].subdomain` | object |  |\n| `results[].subdomain_last` | object |  |\n| `results[].subdomain_root` | object |  |\n| `results[].name` | object |  |\n| `results[].domain` | object |  |\n| `results[].type` | integer |  |\n| `results[].subdomain_level_count` | integer |  |\n| `results[].dns` | object |  |\n| `results[].dns_last_change_date` | string | date-time |\n| `results[].ip_history` | array of string |  |\n| `results[].ssl` | object |  |\n| `results[].ssl_last_change_date` | string | date-time |\n| `results[].webdata` | object |  |\n\nPaginated. See **Getting Started → Pagination**."
          },
          "response": []
        }
      ]
    },
    {
      "name": "Darkweb",
      "id": "bd85705c-b170-56bb-9c47-1484064be0dc",
      "description": "Search dark web sources (forums, markets, paste sites, chats, leaks). Results are paged **25 per page**, up to page **250**.",
      "item": [
        {
          "name": "Search",
          "id": "753df83e-4828-594e-95c0-f373f3f0e266",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/darkweb-search",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "darkweb-search"
              ],
              "query": [
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `250`. Default `1`.",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Darkweb Search API**\n\nSearches dark web content by free `text`, by indicators and by sources. At least one of them is required.\n\nIndicators:\n\n- `email`\n- `email_apex`\n- `ip_address`\n- `crypto_address`\n- `ccn`\n- `cve`\n- `ssn`\n- `website_mention`\n- `data_leak`\n\nSources:\n\n- `source_type`\n- `source_group`\n- `source_domain`\n\nNarrow the results with:\n\n- `language`\n- `crawl_date`\n- `post_date`\n- `hackishness` (0–1)\n\nSort with `sorting`.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `text` | string |  |  |\n| `include_similar` | boolean |  |  |\n| `language` | array |  |  |\n| `source_domain` | array |  |  |\n| `crawl_date` | object |  |  |\n| `post_date` | object |  |  |\n| `hackishness` | object |  |  |\n| `contains` | array |  |  |\n| `include_text_content` | boolean |  |  |\n| `ccn` | array |  |  |\n| `cve` | array |  |  |\n| `website_mention` | array |  |  |\n| `ssn` | array |  |  |\n| `email` | array |  |  |\n| `email_apex` | array |  |  |\n| `ip_address` | array |  |  |\n| `site_id` | string |  |  |\n| `crypto_address` | array |  |  |\n| `data_leak` | array |  |  |\n| `source_type` | array |  |  |\n| `source_group` | array |  |  |\n| `source_discord_channel` | array |  |  |\n| `source_telegram_channel` | array |  |  |\n| `sorting` | object |  |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].ref` | string |  |\n| `results[].body` | string |  |\n| `results[].hackishness` | number |  |\n| `results[].title` | string |  |\n| `results[].uri` | string |  |\n| `results[].url` | string |  |\n| `results[].location` | string |  |\n| `results[].crawl_date` | string |  |\n| `results[].file_size` | integer |  |\n| `results[].network` | string |  |\n| `results[].languages` | array of string |  |\n| `results[].domain` | string |  |\n| `results[].site_id` | string |  |\n| `results[].snippet` | string |  |\n| `results[].emails` | array of string |  |\n| `results[].ssns` | array of string |  |\n| `results[].ccns` | array of string |  |\n| `results[].cves` | array of string |  |\n| `results[].websites` | array of string |  |\n| `results[].ips` | array of string |  |\n| `results[].cryptos` | array of string |  |\n| `results[].headers` | array of string |  |\n| `results[].groups` | array of string |  |\n| `results[].paste` | object |  |\n| `results[].market` | object |  |\n| `results[].leak` | object |  |\n| `results[].chat` | object |  |\n| `results[].irc` | object |  |\n| `results[].forum` | object |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> No live example: the DEMO account has no data for this endpoint yet, or it returned an error during testing. The response shape is described above.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        }
      ]
    },
    {
      "name": "Vulnerability",
      "id": "20773b46-591e-50d7-ba5c-81b5cd036d59",
      "description": "Deepinfo's vulnerability (CVE) database: search, CVE details, EPSS history and global statistics.",
      "item": [
        {
          "name": "Search",
          "id": "8233beda-0799-56cc-9e6e-a2cf2b71fd2c",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/vulnerability-search?page_size=25",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "vulnerability-search"
              ],
              "query": [
                {
                  "key": "export",
                  "value": "",
                  "description": "Default `false`.",
                  "disabled": true
                },
                {
                  "key": "export_format",
                  "value": "",
                  "description": "One of: `json`, `csv`.",
                  "disabled": true
                },
                {
                  "key": "export_scope",
                  "value": "",
                  "description": "One of: `basic`, `default`, `extended`.",
                  "disabled": true
                },
                {
                  "key": "page",
                  "value": "1",
                  "description": "Min `1`, max `400`. Default `1`.",
                  "disabled": true
                },
                {
                  "key": "page_size",
                  "value": "25",
                  "description": "Min `25`, max `100`. Default `100`."
                }
              ]
            },
            "description": "**Deepinfo Vulnerability Search API**\n\nSearches Deepinfo's CVE database with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `startswith`, `wildcard`, `exists`** — 183 fields\n\n- `source_identifier`: The CVE's assigner, shown as Assigner in the platform: the organization that submitted the CVE record, identified by an email address or a UUID.\n- `status`: Analysis status of the CVE record. Values seen: `Received`, `Awaiting Analysis`, `Undergoing Analysis`, `Analyzed`, `Modified`, `Deferred`, `Rejected`.\n- `descriptions.lang`: Language of one of the CVE's descriptions, as a two-letter code (`en` and `es` seen).\n- `references.url`: URL of one of the CVE's references, such as a vendor advisory, a patch or an exploit.\n- `references.source`: Who added the reference to the CVE record, identified by an email address or a UUID.\n- `metrics.cvss_metric_v2.source`: Who provided a CVSS 2.0 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 2.0 assessment per source.\n- `metrics.cvss_metric_v2.type`: Role of a CVSS 2.0 assessment of the CVE. Values: `Primary`, `Secondary`.\n- `metrics.cvss_metric_v2.cvss_data.version`: CVSS version of the assessment; always `2.0` here.\n- `metrics.cvss_metric_v2.cvss_data.vector_string`: The full CVSS 2.0 vector of the assessment, for example `AV:N/AC:L/Au:N/C:C/I:C/A:C`; it encodes the individual metrics of the assessment.\n- `metrics.cvss_metric_v2.cvss_data.access_vector`: CVSS 2.0 Access Vector (AV): how an attacker reaches the vulnerable system. Values: `NETWORK`, `ADJACENT_NETWORK`, `LOCAL`.\n- `metrics.cvss_metric_v2.cvss_data.access_complexity`: CVSS 2.0 Access Complexity (AC): how difficult the attack is once the attacker has access to the target. Values: `HIGH`, `MEDIUM`, `LOW`.\n- `metrics.cvss_metric_v2.cvss_data.authentication`: CVSS 2.0 Authentication (Au): how many times an attacker must authenticate to exploit the vulnerability. Values: `MULTIPLE`, `SINGLE`, `NONE`.\n- `metrics.cvss_metric_v2.cvss_data.confidentiality_impact`: CVSS 2.0 Confidentiality Impact (C): how much a successful attack affects the confidentiality of data. Values: `NONE`, `PARTIAL`, `COMPLETE`.\n- `metrics.cvss_metric_v2.cvss_data.integrity_impact`: CVSS 2.0 Integrity Impact (I): how much a successful attack affects the integrity of data. Values: `NONE`, `PARTIAL`, `COMPLETE`.\n- `metrics.cvss_metric_v2.cvss_data.availability_impact`: CVSS 2.0 Availability Impact (A): how much a successful attack affects the availability of the affected system. Values: `NONE`, `PARTIAL`, `COMPLETE`.\n- `metrics.cvss_metric_v2.cvss_data.exploitability`: CVSS 2.0 Exploitability (E), a temporal metric: how mature the exploit code or technique is. Values: `UNPROVEN`, `PROOF_OF_CONCEPT`, `FUNCTIONAL`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v2.cvss_data.remediation_level`: CVSS 2.0 Remediation Level (RL), a temporal metric: what kind of fix is available. Values: `OFFICIAL_FIX`, `TEMPORARY_FIX`, `WORKAROUND`, `UNAVAILABLE`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v2.cvss_data.report_confidence`: CVSS 2.0 Report Confidence (RC), a temporal metric: how far the existence of the vulnerability is confirmed. Values: `UNCONFIRMED`, `UNCORROBORATED`, `CONFIRMED`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v2.cvss_data.collateral_damage_potential`: CVSS 2.0 Collateral Damage Potential (CDP), an environmental metric: the potential for loss of life, physical assets or revenue. Values: `NONE`, `LOW`, `LOW_MEDIUM`, `MEDIUM_HIGH`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v2.cvss_data.target_distribution`: CVSS 2.0 Target Distribution (TD), an environmental metric: the share of systems in an environment that are vulnerable. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v2.cvss_data.confidentiality_requirement`: CVSS 2.0 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v2.cvss_data.integrity_requirement`: CVSS 2.0 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v2.cvss_data.availability_requirement`: CVSS 2.0 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v2.base_severity`: Severity band of the CVSS 2.0 base score. Values: `LOW`, `MEDIUM`, `HIGH`.\n- `metrics.cvss_metric_v30.source`: Who provided a CVSS 3.0 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 3.0 assessment per source.\n- `metrics.cvss_metric_v30.type`: Role of a CVSS 3.0 assessment of the CVE. Values: `Primary`, `Secondary`.\n- `metrics.cvss_metric_v30.cvss_data.version`: CVSS version of the assessment; always `3.0` here.\n- `metrics.cvss_metric_v30.cvss_data.vector_string`: The full CVSS 3.0 vector of the assessment, for example `CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`; it encodes the individual metrics of the assessment.\n- `metrics.cvss_metric_v30.cvss_data.attack_vector`: CVSS 3.0 Attack Vector (AV): how an attacker reaches the vulnerable component. Values: `NETWORK`, `ADJACENT_NETWORK`, `LOCAL`, `PHYSICAL`.\n- `metrics.cvss_metric_v30.cvss_data.attack_complexity`: CVSS 3.0 Attack Complexity (AC): how difficult the attack is to carry out. Values: `LOW`, `HIGH`.\n- `metrics.cvss_metric_v30.cvss_data.privileges_required`: CVSS 3.0 Privileges Required (PR): the level of privileges an attacker needs before the attack. Values: `NONE`, `LOW`, `HIGH`.\n- `metrics.cvss_metric_v30.cvss_data.user_interaction`: CVSS 3.0 User Interaction (UI): whether a user other than the attacker must take part in the attack. Values: `NONE`, `REQUIRED`.\n- `metrics.cvss_metric_v30.cvss_data.scope`: CVSS 3.0 Scope (S): whether a successful attack can affect components beyond the vulnerable one. Values: `UNCHANGED`, `CHANGED`.\n- `metrics.cvss_metric_v30.cvss_data.confidentiality_impact`: CVSS 3.0 Confidentiality Impact (C): how much a successful attack affects the confidentiality of data. Values: `NONE`, `LOW`, `HIGH`.\n- `metrics.cvss_metric_v30.cvss_data.integrity_impact`: CVSS 3.0 Integrity Impact (I): how much a successful attack affects the integrity of data. Values: `NONE`, `LOW`, `HIGH`.\n- `metrics.cvss_metric_v30.cvss_data.availability_impact`: CVSS 3.0 Availability Impact (A): how much a successful attack affects the availability of the affected system. Values: `NONE`, `LOW`, `HIGH`.\n- `metrics.cvss_metric_v30.cvss_data.base_severity`: Severity band of the CVSS 3.0 base score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`.\n- `metrics.cvss_metric_v30.cvss_data.exploit_code_maturity`: CVSS 3.0 Exploit Code Maturity (E), a temporal metric: how mature the exploit code or technique is. Values: `UNPROVEN`, `PROOF_OF_CONCEPT`, `FUNCTIONAL`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.remediation_level`: CVSS 3.0 Remediation Level (RL), a temporal metric: what kind of fix is available. Values: `OFFICIAL_FIX`, `TEMPORARY_FIX`, `WORKAROUND`, `UNAVAILABLE`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.report_confidence`: CVSS 3.0 Report Confidence (RC), a temporal metric: how far the existence of the vulnerability is confirmed. Values: `UNKNOWN`, `REASONABLE`, `CONFIRMED`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.temporal_severity`: Severity band of the CVSS 3.0 temporal score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.confidentiality_requirement`: CVSS 3.0 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.integrity_requirement`: CVSS 3.0 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.availability_requirement`: CVSS 3.0 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.modified_attack_vector`: CVSS 3.0 Modified Attack Vector (MAV), an environmental metric that overrides Attack Vector for a specific environment. Values: `NETWORK`, `ADJACENT_NETWORK`, `LOCAL`, `PHYSICAL`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.modified_attack_complexity`: CVSS 3.0 Modified Attack Complexity (MAC), an environmental metric that overrides Attack Complexity for a specific environment. Values: `HIGH`, `LOW`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.modified_privileges_required`: CVSS 3.0 Modified Privileges Required (MPR), an environmental metric that overrides Privileges Required for a specific environment. Values: `HIGH`, `LOW`, `NONE`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.modified_user_interaction`: CVSS 3.0 Modified User Interaction (MUI), an environmental metric that overrides User Interaction for a specific environment. Values: `NONE`, `REQUIRED`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.modified_scope`: CVSS 3.0 Modified Scope (MS), an environmental metric that overrides Scope for a specific environment. Values: `UNCHANGED`, `CHANGED`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.modified_confidentiality_impact`: CVSS 3.0 Modified Confidentiality Impact (MC), an environmental metric that overrides Confidentiality Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.modified_integrity_impact`: CVSS 3.0 Modified Integrity Impact (MI), an environmental metric that overrides Integrity Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.modified_availability_impact`: CVSS 3.0 Modified Availability Impact (MA), an environmental metric that overrides Availability Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.environmental_severity`: Severity band of the CVSS 3.0 environmental score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.source`: Who provided a CVSS 3.1 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 3.1 assessment per source.\n- `metrics.cvss_metric_v31.type`: Role of a CVSS 3.1 assessment of the CVE. Values: `Primary`, `Secondary`.\n- `metrics.cvss_metric_v31.cvss_data.version`: CVSS version of the assessment; always `3.1` here.\n- `metrics.cvss_metric_v31.cvss_data.vector_string`: The full CVSS 3.1 vector of the assessment, for example `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`; it encodes the individual metrics of the assessment.\n- `metrics.cvss_metric_v31.cvss_data.attack_vector`: CVSS 3.1 Attack Vector (AV): how an attacker reaches the vulnerable component. Values: `NETWORK`, `ADJACENT_NETWORK`, `LOCAL`, `PHYSICAL`.\n- `metrics.cvss_metric_v31.cvss_data.attack_complexity`: CVSS 3.1 Attack Complexity (AC): how difficult the attack is to carry out. Values: `LOW`, `HIGH`.\n- `metrics.cvss_metric_v31.cvss_data.privileges_required`: CVSS 3.1 Privileges Required (PR): the level of privileges an attacker needs before the attack. Values: `NONE`, `LOW`, `HIGH`.\n- `metrics.cvss_metric_v31.cvss_data.user_interaction`: CVSS 3.1 User Interaction (UI): whether a user other than the attacker must take part in the attack. Values: `NONE`, `REQUIRED`.\n- `metrics.cvss_metric_v31.cvss_data.scope`: CVSS 3.1 Scope (S): whether a successful attack can affect components beyond the vulnerable one. Values: `UNCHANGED`, `CHANGED`.\n- `metrics.cvss_metric_v31.cvss_data.confidentiality_impact`: CVSS 3.1 Confidentiality Impact (C): how much a successful attack affects the confidentiality of data. Values: `NONE`, `LOW`, `HIGH`.\n- `metrics.cvss_metric_v31.cvss_data.integrity_impact`: CVSS 3.1 Integrity Impact (I): how much a successful attack affects the integrity of data. Values: `NONE`, `LOW`, `HIGH`.\n- `metrics.cvss_metric_v31.cvss_data.availability_impact`: CVSS 3.1 Availability Impact (A): how much a successful attack affects the availability of the affected system. Values: `NONE`, `LOW`, `HIGH`.\n- `metrics.cvss_metric_v31.cvss_data.base_severity`: Severity band of the CVSS 3.1 base score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`.\n- `metrics.cvss_metric_v31.cvss_data.exploit_code_maturity`: CVSS 3.1 Exploit Code Maturity (E), a temporal metric: how mature the exploit code or technique is. Values: `UNPROVEN`, `PROOF_OF_CONCEPT`, `FUNCTIONAL`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.remediation_level`: CVSS 3.1 Remediation Level (RL), a temporal metric: what kind of fix is available. Values: `OFFICIAL_FIX`, `TEMPORARY_FIX`, `WORKAROUND`, `UNAVAILABLE`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.report_confidence`: CVSS 3.1 Report Confidence (RC), a temporal metric: how far the existence of the vulnerability is confirmed. Values: `UNKNOWN`, `REASONABLE`, `CONFIRMED`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.temporal_severity`: Severity band of the CVSS 3.1 temporal score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.confidentiality_requirement`: CVSS 3.1 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.integrity_requirement`: CVSS 3.1 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.availability_requirement`: CVSS 3.1 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.modified_attack_vector`: CVSS 3.1 Modified Attack Vector (MAV), an environmental metric that overrides Attack Vector for a specific environment. Values: `NETWORK`, `ADJACENT_NETWORK`, `LOCAL`, `PHYSICAL`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.modified_attack_complexity`: CVSS 3.1 Modified Attack Complexity (MAC), an environmental metric that overrides Attack Complexity for a specific environment. Values: `HIGH`, `LOW`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.modified_privileges_required`: CVSS 3.1 Modified Privileges Required (MPR), an environmental metric that overrides Privileges Required for a specific environment. Values: `HIGH`, `LOW`, `NONE`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.modified_user_interaction`: CVSS 3.1 Modified User Interaction (MUI), an environmental metric that overrides User Interaction for a specific environment. Values: `NONE`, `REQUIRED`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.modified_scope`: CVSS 3.1 Modified Scope (MS), an environmental metric that overrides Scope for a specific environment. Values: `UNCHANGED`, `CHANGED`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.modified_confidentiality_impact`: CVSS 3.1 Modified Confidentiality Impact (MC), an environmental metric that overrides Confidentiality Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.modified_integrity_impact`: CVSS 3.1 Modified Integrity Impact (MI), an environmental metric that overrides Integrity Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.modified_availability_impact`: CVSS 3.1 Modified Availability Impact (MA), an environmental metric that overrides Availability Impact for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.environmental_severity`: Severity band of the CVSS 3.1 environmental score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`; not filled for any CVE in the current data.\n- `metrics.cvss_metric_v40.source`: Who provided a CVSS 4.0 assessment of the CVE, identified by an email address or a UUID. A CVE can carry one CVSS 4.0 assessment per source.\n- `metrics.cvss_metric_v40.type`: Role of a CVSS 4.0 assessment of the CVE. Values: `Primary`, `Secondary`.\n- `metrics.cvss_metric_v40.cvss_data.version`: CVSS version of the assessment; always `4.0` here.\n- `metrics.cvss_metric_v40.cvss_data.vector_string`: The full CVSS 4.0 vector of the assessment, for example `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H` followed by the threat, environmental and supplemental metrics (`X` when not defined).\n- `metrics.cvss_metric_v40.cvss_data.base_severity`: Severity band of the CVSS 4.0 base score. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL`.\n- `metrics.cvss_metric_v40.cvss_data.attack_vector`: CVSS 4.0 Attack Vector (AV): how an attacker reaches the vulnerable system. Values: `NETWORK`, `ADJACENT`, `LOCAL`, `PHYSICAL`.\n- `metrics.cvss_metric_v40.cvss_data.attack_complexity`: CVSS 4.0 Attack Complexity (AC): how difficult the attack is to carry out. Values: `LOW`, `HIGH`.\n- `metrics.cvss_metric_v40.cvss_data.attack_requirements`: CVSS 4.0 Attack Requirements (AT): whether the attack depends on conditions of the vulnerable system that the attacker does not control. Values: `NONE`, `PRESENT`.\n- `metrics.cvss_metric_v40.cvss_data.privileges_required`: CVSS 4.0 Privileges Required (PR): the level of privileges an attacker needs before the attack. Values: `NONE`, `LOW`, `HIGH`.\n- `metrics.cvss_metric_v40.cvss_data.user_interaction`: CVSS 4.0 User Interaction (UI): whether and how a user other than the attacker must take part in the attack. Values: `NONE`, `PASSIVE`, `ACTIVE`.\n- `metrics.cvss_metric_v40.cvss_data.vulnerable_system_confidentiality`: CVSS 4.0 Vulnerable System Confidentiality (VC): impact of a successful attack on the confidentiality of the vulnerable system. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `VC`).\n- `metrics.cvss_metric_v40.cvss_data.vulnerable_system_integrity`: CVSS 4.0 Vulnerable System Integrity (VI): impact of a successful attack on the integrity of the vulnerable system. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `VI`).\n- `metrics.cvss_metric_v40.cvss_data.vulnerable_system_availability`: CVSS 4.0 Vulnerable System Availability (VA): impact of a successful attack on the availability of the vulnerable system. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `VA`).\n- `metrics.cvss_metric_v40.cvss_data.subsequent_system_confidentiality`: CVSS 4.0 Subsequent System Confidentiality (SC): impact of a successful attack on the confidentiality of other systems beyond the vulnerable one. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `SC`).\n- `metrics.cvss_metric_v40.cvss_data.subsequent_system_integrity`: CVSS 4.0 Subsequent System Integrity (SI): impact of a successful attack on the integrity of other systems beyond the vulnerable one. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `SI`).\n- `metrics.cvss_metric_v40.cvss_data.subsequent_system_availability`: CVSS 4.0 Subsequent System Availability (SA): impact of a successful attack on the availability of other systems beyond the vulnerable one. Values: `NONE`, `LOW`, `HIGH`; rarely filled, and for most CVSS 4.0 assessments the value appears only in `vector_string` (as `SA`).\n- `metrics.cvss_metric_v40.cvss_data.exploit_maturity`: CVSS 4.0 Exploit Maturity (E), a threat metric: how likely the vulnerability is to be attacked, based on known exploits and attacks. Values: `UNREPORTED`, `PROOF_OF_CONCEPT`, `ATTACKED`, `NOT_DEFINED` (stored when the vector has `E:X`).\n- `metrics.cvss_metric_v40.cvss_data.confidentiality_requirements`: CVSS 4.0 Confidentiality Requirement (CR), an environmental metric: how important confidentiality of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; rarely filled.\n- `metrics.cvss_metric_v40.cvss_data.integrity_requirements`: CVSS 4.0 Integrity Requirement (IR), an environmental metric: how important integrity of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; rarely filled.\n- `metrics.cvss_metric_v40.cvss_data.availability_requirements`: CVSS 4.0 Availability Requirement (AR), an environmental metric: how important availability of the affected asset is to the organization. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`; rarely filled.\n- `metrics.cvss_metric_v40.cvss_data.modified_attack_vector`: CVSS 4.0 Modified Attack Vector (MAV), an environmental metric that overrides Attack Vector for a specific environment. Values: `NETWORK`, `ADJACENT`, `LOCAL`, `PHYSICAL`, `NOT_DEFINED`; usually `NOT_DEFINED` (`MAV:X` in the vector).\n- `metrics.cvss_metric_v40.cvss_data.modified_attack_complexity`: CVSS 4.0 Modified Attack Complexity (MAC), an environmental metric that overrides Attack Complexity for a specific environment. Values: `HIGH`, `LOW`, `NOT_DEFINED`; usually `NOT_DEFINED` (`MAC:X` in the vector).\n- `metrics.cvss_metric_v40.cvss_data.modified_attack_requirements`: CVSS 4.0 Modified Attack Requirements (MAT), an environmental metric that overrides Attack Requirements for a specific environment. Values: `NONE`, `PRESENT`, `NOT_DEFINED`; usually `NOT_DEFINED` (`MAT:X` in the vector).\n- `metrics.cvss_metric_v40.cvss_data.modified_privileges_required`: CVSS 4.0 Modified Privileges Required (MPR), an environmental metric that overrides Privileges Required for a specific environment. Values: `HIGH`, `LOW`, `NONE`, `NOT_DEFINED`; usually `NOT_DEFINED` (`MPR:X` in the vector).\n- `metrics.cvss_metric_v40.cvss_data.modified_user_interaction`: CVSS 4.0 Modified User Interaction (MUI), an environmental metric that overrides User Interaction for a specific environment. Values: `NONE`, `PASSIVE`, `ACTIVE`, `NOT_DEFINED`; usually `NOT_DEFINED` (`MUI:X` in the vector).\n- `metrics.cvss_metric_v40.cvss_data.modified_vulnerable_system_confidentiality`: CVSS 4.0 Modified Vulnerable System Confidentiality (MVC), an environmental metric that overrides Vulnerable System Confidentiality for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; rarely filled.\n- `metrics.cvss_metric_v40.cvss_data.modified_vulnerable_system_integrity`: CVSS 4.0 Modified Vulnerable System Integrity (MVI), an environmental metric that overrides Vulnerable System Integrity for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; rarely filled.\n- `metrics.cvss_metric_v40.cvss_data.modified_vulnerable_system_availability`: CVSS 4.0 Modified Vulnerable System Availability (MVA), an environmental metric that overrides Vulnerable System Availability for a specific environment. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`; rarely filled.\n- `metrics.cvss_metric_v40.cvss_data.modified_subsequent_system_confidentiality`: CVSS 4.0 Modified Subsequent System Confidentiality (MSC), an environmental metric that overrides Subsequent System Confidentiality for a specific environment. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `NOT_DEFINED`; rarely filled.\n- `metrics.cvss_metric_v40.cvss_data.modified_subsequent_system_integrity`: CVSS 4.0 Modified Subsequent System Integrity (MSI), an environmental metric that overrides Subsequent System Integrity for a specific environment. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `SAFETY`, `NOT_DEFINED`; rarely filled.\n- `metrics.cvss_metric_v40.cvss_data.modified_subsequent_system_availability`: CVSS 4.0 Modified Subsequent System Availability (MSA), an environmental metric that overrides Subsequent System Availability for a specific environment. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `SAFETY`, `NOT_DEFINED`; rarely filled.\n- `metrics.cvss_metric_v40.cvss_data.safety`: CVSS 4.0 Safety (S), a supplemental metric: whether exploitation can affect human safety. Values: `NEGLIGIBLE`, `PRESENT`, `NOT_DEFINED`; rarely filled, and `vector_string` usually has `S:X` (not defined).\n- `metrics.cvss_metric_v40.cvss_data.automatable`: CVSS 4.0 Automatable (AU), a supplemental metric: whether an attacker can automate exploitation across many targets. Values: `NO`, `YES`, `NOT_DEFINED`; rarely filled, and `vector_string` usually has `AU:X` (not defined).\n- `metrics.cvss_metric_v40.cvss_data.recovery`: CVSS 4.0 Recovery (R), a supplemental metric: how the system recovers after an attack. Values: `AUTOMATIC`, `USER`, `IRRECOVERABLE`, `NOT_DEFINED`; rarely filled, and `vector_string` usually has `R:X` (not defined).\n- `metrics.cvss_metric_v40.cvss_data.value_density`: CVSS 4.0 Value Density (V), a supplemental metric: whether the resources an attacker gains control of are diffuse or concentrated. Values: `DIFFUSE`, `CONCENTRATED`, `NOT_DEFINED`; usually `NOT_DEFINED` (`V:X` in the vector).\n- `metrics.cvss_metric_v40.cvss_data.vulnerability_response_effort`: CVSS 4.0 Vulnerability Response Effort (RE), a supplemental metric: how much effort it takes to respond to the vulnerability. Values: `LOW`, `MODERATE`, `HIGH`, `NOT_DEFINED`; usually `NOT_DEFINED` (`RE:X` in the vector).\n- `metrics.cvss_metric_v40.cvss_data.provider_urgency`: CVSS 4.0 Provider Urgency (U), a supplemental metric: the urgency the provider assigns to the vulnerability. Values: `CLEAR`, `GREEN`, `AMBER`, `RED`, `NOT_DEFINED`; usually `NOT_DEFINED` (`U:X` in the vector).\n- `weaknesses.source`: Who assigned a weakness (CWE) to the CVE, identified by an email address or a UUID.\n- `weaknesses.type`: Role of a weakness entry of the CVE. Values: `Primary`, `Secondary`.\n- `weaknesses.description.lang`: Language code of a weakness entry; `en` in all data seen.\n- `weaknesses.description.value`: The weakness itself: a CWE ID such as `CWE-94`, or `NVD-CWE-noinfo` (not enough information) or `NVD-CWE-Other` (no specific CWE fits).\n- `configurations.operator`: Operator that joins the nodes of one applicability configuration (a product combination the CVE applies to): `AND` or `OR`. Set only when the configuration has more than one node; `AND` in all data seen.\n- `configurations.nodes.operator`: Operator that joins the CPE matches inside a configuration node: `AND` or `OR`; `OR` in all data seen.\n- `configurations.nodes.cpe_match.criteria`: CPE 2.3 match string of a product in the configuration, for example `cpe:2.3:a:adobe:flash_player:*:*:*:*:*:*:*:*`.\n- `configurations.nodes.cpe_match.match_criteria_id`: Unique identifier (UUID) of the CPE match criterion.\n- `configurations.nodes.cpe_match.version_start_including`: Start of the affected version range of the CPE match, inclusive: this version and later ones are affected.\n- `configurations.nodes.cpe_match.version_start_excluding`: Start of the affected version range of the CPE match, exclusive: versions after this one are affected.\n- `configurations.nodes.cpe_match.version_end_including`: End of the affected version range of the CPE match, inclusive: this version and earlier ones are affected.\n- `configurations.nodes.cpe_match.version_end_excluding`: End of the affected version range of the CPE match, exclusive: versions before this one are affected.\n- `enrichment.cpe.criteria`: CPE 2.3 match string of a product the CVE applies to, in Deepinfo's product list for the CVE (built from the CPE matches in `configurations`).\n- `enrichment.cpe.vendor`: Vendor of a product the CVE applies to, as written in its CPE (lower case, for example `adobe` or `cisco`).\n- `enrichment.cpe.product`: Product the CVE applies to, as written in its CPE (lower case with underscores, for example `linux_kernel`).\n- `enrichment.cpe.product_type`: Kind of product, from the CPE part. Values: `a` (application), `h` (hardware), `o` (operating system).\n- `enrichment.cpe.version_start_including`: Start of the product's affected version range, inclusive: this version and later ones are affected.\n- `enrichment.cpe.version_start_excluding`: Start of the product's affected version range, exclusive: versions after this one are affected.\n- `enrichment.cpe.version_end_including`: End of the product's affected version range, inclusive: this version and earlier ones are affected.\n- `enrichment.cpe.version_end_excluding`: End of the product's affected version range, exclusive: versions before this one are affected.\n- `enrichment.cpe.affected_versions_first`: First affected version of the product; together with `affected_versions_last` it gives the version range the platform shows (for example v1.5.0 - v1.7.0).\n- `enrichment.cpe.affected_versions_last`: Last affected version of the product; together with `affected_versions_first` it gives the version range the platform shows (for example v1.5.0 - v1.7.0).\n- `enrichment.cpe.cpe_names.cpe_name`: A concrete CPE 2.3 name covered by the product's match string. You can filter on it, but only GET /discovery/vulnerability-detail returns it; search results leave it out.\n- `enrichment.cwe.owasptop10_2021`: OWASP Top 10 (2021) category of the weakness. Values: `A01 Broken Access Control`, `A02 Cryptographic Failures`, `A03 Injection`, `A04 Insecure Design`, `A05 Security Misconfiguration`, `A06 Vulnerable and Outdated Components`, `A07 Identification and Authentication Failures`, `A08 Software and Data Integrity Failures`, `A09 Security Logging and Monitoring Failures`, `A10 Server-Side Request Forgery (SSRF)`.\n- `enrichment.cisa_kev.vendor_project`: Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Microsoft`.\n- `enrichment.cisa_kev.product`: Product named in the CVE's CISA KEV entry, for example `Kernel` or `Multiple Products`.\n- `enrichment.cisa_kev.known_ransomware_campaign_use`: Whether the CVE is known to be used in ransomware campaigns, according to CISA KEV. Values: `Known`, `Unknown`.\n- `enrichment.vdeep_metric.source`: Source of the CVE's main CVSS assessment (copied from the highest CVSS version available), as an email address or a UUID; the platform shows it as CVE ORIGIN.\n- `enrichment.vdeep_metric.type`: Role of the CVE's main CVSS assessment: `Primary` or `Secondary`. When the highest CVSS version has both, the Primary one is used.\n- `enrichment.vdeep_metric.cvss_data.version`: CVSS version of the CVE's main CVSS assessment, the highest version available. Values: `2.0`, `3.0`, `3.1`, `4.0`.\n- `enrichment.vdeep_metric.cvss_data.vector_string`: CVSS vector of the CVE's main CVSS assessment, in the format of its version (for example `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`).\n- `enrichment.vdeep_metric.cvss_data.attack_vector`: Attack vector of the CVE's main CVSS assessment (Access Vector for CVSS 2.0). Values: `NETWORK`, `ADJACENT_NETWORK`, `ADJACENT`, `LOCAL`, `PHYSICAL`.\n- `enrichment.vdeep_metric.cvss_data.attack_complexity`: Attack complexity of the CVE's main CVSS assessment (Access Complexity for CVSS 2.0). Values: `LOW`, `MEDIUM`, `HIGH`.\n- `enrichment.vdeep_metric.cvss_data.attack_requirements`: Attack Requirements (AT) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0. Values: `NONE`, `PRESENT`.\n- `enrichment.vdeep_metric.cvss_data.privileges_required`: Privileges required by the CVE's main CVSS assessment; empty when it is CVSS 2.0. Values: `NONE`, `LOW`, `HIGH`.\n- `enrichment.vdeep_metric.cvss_data.user_interaction`: User interaction of the CVE's main CVSS assessment; empty when it is CVSS 2.0. Values: `NONE`, `REQUIRED` (CVSS 3.x) or `NONE`, `PASSIVE`, `ACTIVE` (CVSS 4.0).\n- `enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality`: Confidentiality impact of the CVE's main CVSS assessment: the Confidentiality Impact of a CVSS 2.0 or 3.x assessment (`NONE`, `PARTIAL`, `COMPLETE` or `NONE`, `LOW`, `HIGH`), or VC of a CVSS 4.0 one, which is rarely filled. The platform shows it in the C/I/A classification.\n- `enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`: Integrity impact of the CVE's main CVSS assessment: the Integrity Impact of a CVSS 2.0 or 3.x assessment (`NONE`, `PARTIAL`, `COMPLETE` or `NONE`, `LOW`, `HIGH`), or VI of a CVSS 4.0 one, which is rarely filled. The platform shows it in the C/I/A classification.\n- `enrichment.vdeep_metric.cvss_data.vulnerable_system_availability`: Availability impact of the CVE's main CVSS assessment: the Availability Impact of a CVSS 2.0 or 3.x assessment (`NONE`, `PARTIAL`, `COMPLETE` or `NONE`, `LOW`, `HIGH`), or VA of a CVSS 4.0 one, which is rarely filled. The platform shows it in the C/I/A classification.\n- `enrichment.vdeep_metric.cvss_data.subsequent_system_confidentiality`: Subsequent System Confidentiality (SC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`.\n- `enrichment.vdeep_metric.cvss_data.subsequent_system_integrity`: Subsequent System Integrity (SI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`.\n- `enrichment.vdeep_metric.cvss_data.subsequent_system_availability`: Subsequent System Availability (SA) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`.\n- `enrichment.vdeep_metric.cvss_data.exploit_maturity`: Exploit Maturity (E) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0. Values: `UNREPORTED`, `PROOF_OF_CONCEPT`, `ATTACKED`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.confidentiality_requirements`: Confidentiality Requirement (CR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.integrity_requirements`: Integrity Requirement (IR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.availability_requirements`: Availability Requirement (AR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `LOW`, `MEDIUM`, `HIGH`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_attack_vector`: Modified Attack Vector (MAV) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `NETWORK`, `ADJACENT`, `LOCAL`, `PHYSICAL`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_attack_complexity`: Modified Attack Complexity (MAC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `HIGH`, `LOW`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_attack_requirements`: Modified Attack Requirements (MAT) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `NONE`, `PRESENT`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_privileges_required`: Modified Privileges Required (MPR) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `HIGH`, `LOW`, `NONE`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_user_interaction`: Modified User Interaction (MUI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `NONE`, `PASSIVE`, `ACTIVE`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_vulnerable_system_confidentiality`: Modified Vulnerable System Confidentiality (MVC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_vulnerable_system_integrity`: Modified Vulnerable System Integrity (MVI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_vulnerable_system_availability`: Modified Vulnerable System Availability (MVA) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NONE`, `LOW`, `HIGH`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_subsequent_system_confidentiality`: Modified Subsequent System Confidentiality (MSC) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_subsequent_system_integrity`: Modified Subsequent System Integrity (MSI) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `SAFETY`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.modified_subsequent_system_availability`: Modified Subsequent System Availability (MSA) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NEGLIGIBLE`, `LOW`, `HIGH`, `SAFETY`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.safety`: Safety (S) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NEGLIGIBLE`, `PRESENT`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.automatable`: Automatable (AU) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `NO`, `YES`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.recovery`: Recovery (R) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, and rarely even then. Values: `AUTOMATIC`, `USER`, `IRRECOVERABLE`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.value_density`: Value Density (V) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `DIFFUSE`, `CONCENTRATED`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.vulnerability_response_effort`: Vulnerability Response Effort (RE) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `LOW`, `MODERATE`, `HIGH`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.provider_urgency`: Provider Urgency (U) of the CVE's main CVSS assessment; filled only when it is CVSS 4.0, usually `NOT_DEFINED`. Values: `CLEAR`, `GREEN`, `AMBER`, `RED`, `NOT_DEFINED`.\n- `enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL` (`LOW`, `MEDIUM`, `HIGH` for CVSS 2.0); the platform shows it as the CVE's severity.\n\n**`eq`, `gt`, `gte`, `lt`, `lte`, `exists`** — 28 fields\n\n- `published`: Date and time the CVE was first published, in ISO 8601 UTC (for example `2026-06-30T16:16:54Z`).\n- `last_modified`: Date and time the CVE record was last changed, in ISO 8601 UTC (for example `2026-08-26T16:35:20Z`).\n- `cisa_exploit_add`: Date the CVE was added to the CISA Known Exploited Vulnerabilities (KEV) catalog (YYYY-MM-DD), as given in the CVE record. `enrichment.cisa_kev.date_added` holds the same date and is filled for a few more CVEs.\n- `cisa_action_due`: Remediation due date from the CISA KEV catalog (YYYY-MM-DD), as given in the CVE record. `enrichment.cisa_kev.due_date` holds the same date and is filled for a few more CVEs.\n- `metrics.cvss_metric_v2.cvss_data.base_score`: CVSS 2.0 base score of the assessment, from 0 to 10.\n- `metrics.cvss_metric_v2.cvss_data.temporal_score`: CVSS 2.0 temporal score, from 0 to 10: the base score adjusted by the temporal metrics. Not filled for any CVE in the current data.\n- `metrics.cvss_metric_v2.cvss_data.environmental_score`: CVSS 2.0 environmental score, from 0 to 10: the score adjusted for a specific environment. Not filled for any CVE in the current data.\n- `metrics.cvss_metric_v2.exploitability_score`: CVSS 2.0 exploitability subscore, from 0 to 10: the part of the base score that comes from access vector, access complexity and authentication.\n- `metrics.cvss_metric_v2.impact_score`: CVSS 2.0 impact subscore, from 0 to 10: the part of the base score that comes from the confidentiality, integrity and availability impacts.\n- `metrics.cvss_metric_v30.cvss_data.base_score`: CVSS 3.0 base score of the assessment, from 0 to 10.\n- `metrics.cvss_metric_v30.cvss_data.temporal_score`: CVSS 3.0 temporal score, from 0 to 10: the base score adjusted by the temporal metrics. Not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.cvss_data.environmental_score`: CVSS 3.0 environmental score, from 0 to 10: the score adjusted for a specific environment. Not filled for any CVE in the current data.\n- `metrics.cvss_metric_v30.exploitability_score`: CVSS 3.0 exploitability subscore: the part of the base score that comes from attack vector, attack complexity, privileges required and user interaction (for example `3.9`).\n- `metrics.cvss_metric_v30.impact_score`: CVSS 3.0 impact subscore: the part of the base score that comes from the confidentiality, integrity and availability impacts (for example `5.9`).\n- `metrics.cvss_metric_v31.cvss_data.base_score`: CVSS 3.1 base score of the assessment, from 0 to 10.\n- `metrics.cvss_metric_v31.cvss_data.temporal_score`: CVSS 3.1 temporal score, from 0 to 10: the base score adjusted by the temporal metrics. Not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.cvss_data.environmental_score`: CVSS 3.1 environmental score, from 0 to 10: the score adjusted for a specific environment. Not filled for any CVE in the current data.\n- `metrics.cvss_metric_v31.exploitability_score`: CVSS 3.1 exploitability subscore: the part of the base score that comes from attack vector, attack complexity, privileges required and user interaction (for example `3.9`).\n- `metrics.cvss_metric_v31.impact_score`: CVSS 3.1 impact subscore: the part of the base score that comes from the confidentiality, integrity and availability impacts (for example `5.9`).\n- `metrics.cvss_metric_v40.cvss_data.base_score`: CVSS 4.0 base score of the assessment, from 0 to 10.\n- `vendor_comments.last_modified`: Date and time the vendor comment was last changed, in ISO 8601 UTC.\n- `enrichment.cwe.id`: Number of a CWE weakness linked to the CVE (for example `94` for CWE-94). `enrichment.cwe` adds CWE catalog details for each CWE listed in `weaknesses`.\n- `enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `enrichment.epss_score.percentile`: Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score).\n- `enrichment.epss_score.date`: Date of the EPSS score (YYYY-MM-DD); the platform shows it as ANALYSIS DATE.\n- `enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog (YYYY-MM-DD); empty for CVEs not in the catalog. The platform shows CISA KEV: YES when it is set.\n- `enrichment.cisa_kev.due_date`: Remediation due date in the CVE's CISA KEV entry (YYYY-MM-DD), shown as REMEDIATION DUE; the results table marks CVEs that have it as EXPLOITABLE.\n- `enrichment.vdeep_metric.cvss_data.base_score`: Base score, from 0 to 10, of the CVE's main CVSS assessment: the assessment of the highest CVSS version the CVE has. The platform shows it as the CVE's score.\n\n**`eq`, `startswith`, `wildcard`, `contains_any`, `contains_all`, `exists`** — 12 fields\n\n- `evaluator_comment`: Free-text comment from the CVE's evaluator, such as a link to the matching CWE entry or a note on how the score applies to particular platforms or versions. Filled for few CVEs.\n- `evaluator_solution`: Free-text note from the CVE's evaluator about the fix, often a link or a quote from an advisory. Filled for few CVEs.\n- `evaluator_impact`: Free-text note from the CVE's evaluator about the impact or the affected products, often quoting an advisory. Filled for few CVEs.\n- `cisa_required_action`: Action CISA requires for the CVE in the KEV catalog, as given in the CVE record, for example to apply updates per vendor instructions. Same text as `enrichment.cisa_kev.required_action`.\n- `cisa_vulnerability_name`: Name of the vulnerability in the CISA KEV catalog, as given in the CVE record. Same text as `enrichment.cisa_kev.vulnerability_name`.\n- `vendor_comments.organization`: Name of a vendor that commented on the CVE, for example `Red Hat` or `Oracle`.\n- `vendor_comments.comment`: Text of the vendor's statement about the CVE.\n- `enrichment.cwe.name`: Name of the CWE weakness, for example `Improper Access Control`.\n- `enrichment.cisa_kev.vulnerability_name`: Name of the vulnerability in the CVE's CISA KEV entry.\n- `enrichment.cisa_kev.short_description`: CISA's short description of the vulnerability in the KEV entry.\n- `enrichment.cisa_kev.required_action`: Action CISA requires in the KEV entry, for example to apply updates per vendor instructions.\n- `enrichment.cisa_kev.notes`: Notes in the CVE's CISA KEV entry, usually reference URLs separated by `;`.\n\n**`eq`, `exists`** — 10 fields\n\n- `metrics.cvss_metric_v2.ac_insuf_info`: Flag on a CVSS 2.0 assessment: `true` when there was not enough information to rate Access Complexity.\n- `metrics.cvss_metric_v2.obtain_all_privilege`: Flag on a CVSS 2.0 assessment: `true` when a successful attack gives the attacker all privileges on the affected system.\n- `metrics.cvss_metric_v2.obtain_user_privilege`: Flag on a CVSS 2.0 assessment: `true` when a successful attack gives the attacker user-level privileges on the affected system.\n- `metrics.cvss_metric_v2.obtain_other_privilege`: Flag on a CVSS 2.0 assessment: `true` when a successful attack gives the attacker other privileges on the affected system.\n- `metrics.cvss_metric_v2.user_interaction_required`: Flag on a CVSS 2.0 assessment: `true` when exploitation needs a user to take some action.\n- `configurations.negate`: When `true`, the configuration's condition is negated. Not filled for any CVE in the current data.\n- `configurations.nodes.negate`: When `true`, the node matches products that do not meet its CPE matches; `false` in all data seen.\n- `configurations.nodes.cpe_match.vulnerable`: `true` when the product in this CPE match is vulnerable; `false` when it is only part of the configuration, such as the hardware a vulnerable firmware runs on.\n- `enrichment.cpe.vulnerable`: `true` when the product is vulnerable; `false` when it is only part of an affected configuration, such as the hardware a vulnerable firmware runs on.\n- `enrichment.cpe.cpe_names.deprecated`: `true` when that CPE name is deprecated in the CPE dictionary. You can filter on it, but only GET /discovery/vulnerability-detail returns it; search results leave it out.\n\n**`eq`, `in`, `startswith`, `wildcard`, `exists`** — 6 fields\n\n- `references.tags`: Tags that classify a reference. Values: `Vendor Advisory`, `Third Party Advisory`, `Patch`, `Exploit`, `VDB Entry`, `Mailing List`, `US Government Resource`, `Issue Tracking`, `Release Notes`, `Broken Link`, `Permissions Required`, `Product`, `Mitigation`, `Technical Description`, `Not Applicable`, `Press/Media Coverage`, `Tool Signature`, `URL Repurposed`.\n- `enrichment.cpe.affected_versions`: All affected versions of the product. You can filter on it, but only GET /discovery/vulnerability-detail returns it; search results leave it out.\n- `enrichment.cwe.scope`: Security areas the weakness can affect, from the CWE entry. Values: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Accountability`, `Authentication`, `Authorization`, `Non-Repudiation`, `Other`.\n- `enrichment.cwe.impact`: Technical impacts the weakness can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Application Data` or `DoS: Crash, Exit, or Restart`.\n- `enrichment.cwe.detection_method`: Methods that can detect the weakness, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`.\n- `enrichment.vdeep_metric.available_versions`: CVSS versions the CVE has assessments for, highest first. Values: `2.0`, `3.0`, `3.1`, `4.0`.\n\n**`wildcard`, `contains_any`, `contains_all`, `exists`** — 2 fields\n\n- `descriptions.value`: Text of one of the CVE's descriptions, in the language given by `descriptions.lang`. For a rejected CVE it holds the rejection reason.\n- `enrichment.cwe.description`: The CWE catalog's description of the weakness.\n\n**`eq`, `in`, `gt`, `gte`, `lt`, `lte`, `exists`** — 1 field\n\n- `enrichment.cwe.capec_id`: IDs of CAPEC attack patterns related to the weakness, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES.\n\n**`eq`, `startswith`, `wildcard`, `gt`, `lt`, `exists`** — 1 field\n\n- `id`: The CVE identifier, in the form CVE-YYYY-NNNN with four to seven digits after the year (for example `CVE-2021-44228`).\n\nSortable fields:\n\n- `id`: The CVE identifier, in the form CVE-YYYY-NNNN with four to seven digits after the year (for example `CVE-2021-44228`).\n- `enrichment.cpe.vendor`: Vendor of a product the CVE applies to, as written in its CPE (lower case, for example `adobe` or `cisco`).\n- `enrichment.cpe.product`: Product the CVE applies to, as written in its CPE (lower case with underscores, for example `linux_kernel`).\n- `published`: Date and time the CVE was first published, in ISO 8601 UTC (for example `2026-06-30T16:16:54Z`).\n- `last_modified`: Date and time the CVE record was last changed, in ISO 8601 UTC (for example `2026-08-26T16:35:20Z`).\n- `enrichment.vdeep_metric.cvss_data.base_score`: Base score, from 0 to 10, of the CVE's main CVSS assessment: the assessment of the highest CVSS version the CVE has. The platform shows it as the CVE's score.\n- `enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment. Values: `NONE`, `LOW`, `MEDIUM`, `HIGH`, `CRITICAL` (`LOW`, `MEDIUM`, `HIGH` for CVSS 2.0); the platform shows it as the CVE's severity.\n- `enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog (YYYY-MM-DD); empty for CVEs not in the catalog. The platform shows CISA KEV: YES when it is set.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].source_identifier` | string |  |\n| `results[].published` | string | date-time |\n| `results[].last_modified` | string | date-time |\n| `results[].status` | string |  |\n| `results[].evaluator_comment` | string |  |\n| `results[].evaluator_solution` | string |  |\n| `results[].evaluator_impact` | string |  |\n| `results[].cisa_exploit_add` | string | date |\n| `results[].cisa_action_due` | string | date |\n| `results[].cisa_required_action` | string |  |\n| `results[].cisa_vulnerability_name` | string |  |\n| `results[].descriptions` | array of object |  |\n| `results[].references` | array of object |  |\n| `results[].metrics` | object |  |\n| `results[].weaknesses` | array of object |  |\n| `results[].configurations` | array of object |  |\n| `results[].vendor_comments` | array of object |  |\n| `results[].enrichment` | object |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · 50 of 243 filters** holds this body with 50 of the 243 filters (the first 10 of each operator group); the full list is above (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          },
          "response": []
        },
        {
          "name": "Detail",
          "id": "6c20ec0d-6af5-5ee1-8f16-7f0d19a57266",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/vulnerability-detail?cve=CVE-2021-44228",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "vulnerability-detail"
              ],
              "query": [
                {
                  "key": "cve",
                  "value": "CVE-2021-44228",
                  "description": "**Required.**"
                }
              ]
            },
            "description": "**Deepinfo Vulnerability Detail API**\n\nReturns full details of a CVE: description, CVSS, CWE, EPSS, KEV status, affected products (CPE) and references.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `source_identifier` | string |  |\n| `published` | string | date-time |\n| `last_modified` | string | date-time |\n| `status` | string |  |\n| `evaluator_comment` | string |  |\n| `evaluator_solution` | string |  |\n| `evaluator_impact` | string |  |\n| `cisa_exploit_add` | string | date |\n| `cisa_action_due` | string | date |\n| `cisa_required_action` | string |  |\n| `cisa_vulnerability_name` | string |  |\n| `descriptions` | array of object |  |\n| `references` | array of object |  |\n| `metrics` | object |  |\n| `weaknesses` | array of object |  |\n| `configurations` | array of object |  |\n| `vendor_comments` | array of object |  |\n| `enrichment` | object |  |"
          },
          "response": []
        },
        {
          "name": "EPSS History",
          "id": "8bb50f7f-a2ce-5f25-8129-74de6382e7a1",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explore/vulnerability-insight/epss-history/:cve",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explore",
                "vulnerability-insight",
                "epss-history",
                ":cve"
              ],
              "variable": [
                {
                  "key": "cve",
                  "value": "CVE-2021-44228",
                  "description": "**Required.**"
                }
              ]
            },
            "description": "**Deepinfo Vulnerability EPSS History API**\n\nReturns the EPSS (exploit prediction) score history of a CVE.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `cve` | string |  |\n| `records` | array of object |  |"
          },
          "response": []
        },
        {
          "name": "Finder",
          "id": "3fbf58ff-7200-5bc5-b552-e13d62e8e808",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/discovery/vulnerability-finder?url=",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "discovery",
                "vulnerability-finder"
              ],
              "query": [
                {
                  "key": "url",
                  "value": "",
                  "description": "**Required.** FQDN, IP or URL.",
                  "disabled": false
                }
              ]
            },
            "description": "**Deepinfo Vulnerability Finder API**\n\nFinds vulnerabilities that affect the technologies detected on a `url`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `check_date` | string | date-time |\n| `connection_status` | string |  |\n| `url` | string |  |\n| `redirection_history` | array of object |  |\n| `technologies` | array of object |  |\n| `vulnerability_stats` | object |  |\n\n> No live example: the DEMO account has no data for this endpoint yet, or it returned an error during testing. The response shape is described above."
          },
          "response": []
        },
        {
          "name": "Latest Added",
          "id": "d080ab78-971f-5a4a-a1d4-e403abb18c37",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explore/vulnerability-insight/latest-added-vulnerabilities-list?size=5",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explore",
                "vulnerability-insight",
                "latest-added-vulnerabilities-list"
              ],
              "query": [
                {
                  "key": "vendor",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "product",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "version",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "version__startswith",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "size",
                  "value": "5",
                  "description": "Min `1`, max `100`. Default `10`."
                },
                {
                  "key": "severity",
                  "value": "",
                  "description": "",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Vulnerability Latest Added API**\n\nLists the latest added CVEs.\n\nOptional filters:\n\n- `vendor`\n- `product`\n- `version`\n- `severity`\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `source_identifier` | string |  |\n| `published` | string | date-time |\n| `last_modified` | string | date-time |\n| `status` | string |  |\n| `evaluator_comment` | string |  |\n| `evaluator_solution` | string |  |\n| `evaluator_impact` | string |  |\n| `cisa_exploit_add` | string | date |\n| `cisa_action_due` | string | date |\n| `cisa_required_action` | string |  |\n| `cisa_vulnerability_name` | string |  |\n| `descriptions` | array of object |  |\n| `references` | array of object |  |\n| `metrics` | object |  |\n| `weaknesses` | array of object |  |\n| `configurations` | array of object |  |\n| `vendor_comments` | array of object |  |\n| `enrichment` | object |  |"
          },
          "response": []
        },
        {
          "name": "CISA KEV Stats",
          "id": "71a87eb7-e625-5ac2-ad60-5ffd7c7671ad",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explore/vulnerability-insight/cisa-kev-stats",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explore",
                "vulnerability-insight",
                "cisa-kev-stats"
              ]
            },
            "description": "**Deepinfo Vulnerability CISA KEV Stats API**\n\nStatistics on the CISA Known Exploited Vulnerabilities catalog.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `added_in_last_1_day` | integer |  |\n| `added_in_last_7_days` | integer |  |\n| `added_in_last_30_days` | integer |  |"
          },
          "response": []
        },
        {
          "name": "CVE Stats",
          "id": "982db867-ac78-57f8-ab18-e62af52b45dd",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explore/vulnerability-insight/cve-stats",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explore",
                "vulnerability-insight",
                "cve-stats"
              ]
            },
            "description": "**Deepinfo Vulnerability CVE Stats API**\n\nNumber of CVEs published in the last 1, 7, 30 and 365 days.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `published_in_last_1_day` | integer |  |\n| `published_in_last_7_days` | integer |  |\n| `published_in_last_30_days` | integer |  |\n| `modified_in_last_1_day` | integer |  |\n| `modified_in_last_7_days` | integer |  |\n| `modified_in_last_30_days` | integer |  |"
          },
          "response": []
        },
        {
          "name": "CVSS Score Stats",
          "id": "f7739fca-21e2-5606-b194-f44c83a75230",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explore/vulnerability-insight/vulnerability-stats-by-cvss-scores",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explore",
                "vulnerability-insight",
                "vulnerability-stats-by-cvss-scores"
              ],
              "query": [
                {
                  "key": "vendor",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "product",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "version",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "version__startswith",
                  "value": "",
                  "description": "",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Vulnerability CVSS Score Stats API**\n\nDistribution of CVEs by CVSS score.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `vendor` | string |  |\n| `product` | string |  |\n| `version` | string |  |\n| `cve_count` | integer |  |\n| `cve_count_by_score` | array of object |  |"
          },
          "response": []
        },
        {
          "name": "CWE Timeline",
          "id": "df93c8ef-0e5e-5ceb-b958-3d312d16692e",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explore/vulnerability-insight/cwe-timeline",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explore",
                "vulnerability-insight",
                "cwe-timeline"
              ]
            },
            "description": "**Deepinfo Vulnerability CWE Timeline API**\n\nTime series of CVEs per CWE (weakness type).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `year` | integer |  |\n| `cwe_stats` | array of object |  |"
          },
          "response": []
        },
        {
          "name": "Severity By Year Stats",
          "id": "187f4c0f-8a72-5372-a5f9-ca32c4263d19",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explore/vulnerability-insight/vulnerability-severity-stats-by-year",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explore",
                "vulnerability-insight",
                "vulnerability-severity-stats-by-year"
              ],
              "query": [
                {
                  "key": "vendor",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "product",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "version",
                  "value": "",
                  "description": "",
                  "disabled": true
                },
                {
                  "key": "version__startswith",
                  "value": "",
                  "description": "",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Vulnerability Severity By Year Stats API**\n\nCVE counts per severity and year.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `vendor` | string |  |\n| `product` | string |  |\n| `version` | string |  |\n| `cve_count` | integer |  |\n| `cve_count_by_year` | array of object |  |"
          },
          "response": []
        }
      ]
    },
    {
      "name": "Domain Intelligence",
      "id": "33a87cd5-088a-5e5f-9755-19c77a792bbf",
      "description": "Global domain registration statistics.",
      "item": [
        {
          "name": "Keyword Stats",
          "id": "e2e783e9-9678-53cc-bc73-ef1253f2e93e",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explorer/domain-intelligence/keyword-stats",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explorer",
                "domain-intelligence",
                "keyword-stats"
              ],
              "query": [
                {
                  "key": "interval",
                  "value": "",
                  "description": "One of: `1`, `7`, `30`, `365`.",
                  "disabled": true
                },
                {
                  "key": "size",
                  "value": "10",
                  "description": "One of: `10`, `100`, `1000`, `10000`. Default `10`.",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Domain Intelligence Keyword Stats API**\n\nTop keywords in newly registered domain names. Same parameters as TLD Stats. Can take several seconds.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `keyword` | string |  |\n| `count` | integer |  |"
          },
          "response": []
        },
        {
          "name": "Registration Stats",
          "id": "1c2bebe7-ca94-5a44-8dcd-f7c2e8bc5737",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explorer/domain-intelligence/registration-stats",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explorer",
                "domain-intelligence",
                "registration-stats"
              ]
            },
            "description": "**Deepinfo Domain Intelligence Registration Stats API**\n\nNumber of domains registered in the last 1, 7, 30 and 365 days.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `created_in_last_1_day` | integer |  |\n| `created_in_last_7_days` | integer |  |\n| `created_in_last_30_days` | integer |  |\n| `created_in_last_365_days` | integer |  |\n| `created_all_time` | integer |  |"
          },
          "response": []
        },
        {
          "name": "Registration Timeline",
          "id": "b06d45be-7f5f-59ed-8b83-04d862a46fd0",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explorer/domain-intelligence/registration-timeline",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explorer",
                "domain-intelligence",
                "registration-timeline"
              ],
              "query": [
                {
                  "key": "interval",
                  "value": "7",
                  "description": "Min `1`, max `30`. Default `7`.",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Domain Intelligence Registration Timeline API**\n\nDaily registration counts for the last `interval` days (1–30).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `count` | integer |  |"
          },
          "response": []
        },
        {
          "name": "TLD Stats",
          "id": "c6a7ec48-e587-5964-b07b-6575b92bd67f",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/explorer/domain-intelligence/tld-stats",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "explorer",
                "domain-intelligence",
                "tld-stats"
              ],
              "query": [
                {
                  "key": "interval",
                  "value": "",
                  "description": "One of: `1`, `7`, `30`, `365`.",
                  "disabled": true
                },
                {
                  "key": "size",
                  "value": "10",
                  "description": "One of: `10`, `100`, `1000`, `10000`. Default `10`.",
                  "disabled": true
                }
              ]
            },
            "description": "**Deepinfo Domain Intelligence TLD Stats API**\n\nTop TLDs by registrations. `interval` (days: 1, 7, 30, 365), `size` (10–10000).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `tld` | string |  |\n| `count` | integer |  |"
          },
          "response": []
        }
      ]
    },
    {
      "name": "Feeds",
      "id": "e0299cf1-9cc4-5998-861a-1d13eadc79aa",
      "description": "Download Deepinfo data feeds (all domains/subdomains, daily registered/updated/deleted domains, daily discovered subdomains).\n\nEach endpoint returns file metadata and a **pre-signed `download_url`**, valid for 1 hour. `file_format`: `json` (default) or `csv`.",
      "item": [
        {
          "name": "List",
          "id": "0b14bd55-274f-528f-b3ad-e303c4fa51b6",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/feeds/latest",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "feeds",
                "latest"
              ]
            },
            "description": "**Deepinfo Feeds List API**\n\nLists every feed with its files (format, size, line count, update time) and the API URL to get each.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `type` | string |  |\n| `files` | array of object |  |"
          },
          "response": []
        },
        {
          "name": "All Domains",
          "id": "dd53c405-8e45-5fe3-ad26-633c4fc3ac28",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/feeds/all-domains?file_format=json",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "feeds",
                "all-domains"
              ],
              "query": [
                {
                  "key": "file_format",
                  "value": "json",
                  "description": "One of: `csv`, `json`."
                }
              ]
            },
            "description": "**Deepinfo Feeds All Domains API**\n\nAll registered domains Deepinfo knows about.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `download_url` | string | uri |\n| `file_format` | string | One of `csv`, `json` |\n| `file_size` | integer |  |\n| `file_update_time` | string | date-time |\n| `line_count` | integer |  |"
          },
          "response": []
        },
        {
          "name": "All Subdomains",
          "id": "0030361a-d427-5681-a231-1ecfdddc645c",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/feeds/all-subdomains?file_format=json",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "feeds",
                "all-subdomains"
              ],
              "query": [
                {
                  "key": "file_format",
                  "value": "json",
                  "description": "One of: `csv`, `json`."
                }
              ]
            },
            "description": "**Deepinfo Feeds All Subdomains API**\n\nAll subdomains Deepinfo knows about.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `download_url` | string | uri |\n| `file_format` | string | One of `csv`, `json` |\n| `file_size` | integer |  |\n| `file_update_time` | string | date-time |\n| `line_count` | integer |  |"
          },
          "response": []
        },
        {
          "name": "Daily Deleted Domains",
          "id": "94548f07-134e-5a58-bb14-8c40b3cd9304",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/feeds/daily-deleted-domains?file_format=json",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "feeds",
                "daily-deleted-domains"
              ],
              "query": [
                {
                  "key": "file_format",
                  "value": "json",
                  "description": "One of: `csv`, `json`."
                }
              ]
            },
            "description": "**Deepinfo Feeds Daily Deleted Domains API**\n\nDomains deleted in the last day.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `download_url` | string | uri |\n| `file_format` | string | One of `csv`, `json` |\n| `file_size` | integer |  |\n| `file_update_time` | string | date-time |\n| `line_count` | integer |  |"
          },
          "response": []
        },
        {
          "name": "Daily Discovered Subdomains",
          "id": "8acd13e4-3ba3-52c8-9c2d-fa35131d7351",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/feeds/daily-discovered-subdomains?file_format=json",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "feeds",
                "daily-discovered-subdomains"
              ],
              "query": [
                {
                  "key": "file_format",
                  "value": "json",
                  "description": "One of: `csv`, `json`."
                }
              ]
            },
            "description": "**Deepinfo Feeds Daily Discovered Subdomains API**\n\nSubdomains discovered in the last day.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `download_url` | string | uri |\n| `file_format` | string | One of `csv`, `json` |\n| `file_size` | integer |  |\n| `file_update_time` | string | date-time |\n| `line_count` | integer |  |"
          },
          "response": []
        },
        {
          "name": "Daily Registered Domains",
          "id": "1b529669-682f-5b18-8271-e57b8b2927f3",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/feeds/daily-registered-domains?file_format=csv",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "feeds",
                "daily-registered-domains"
              ],
              "query": [
                {
                  "key": "file_format",
                  "value": "csv",
                  "description": "One of: `csv`, `json`."
                }
              ]
            },
            "description": "**Deepinfo Feeds Daily Registered Domains API**\n\nDomains registered in the last day.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `download_url` | string | uri |\n| `file_format` | string | One of `csv`, `json` |\n| `file_size` | integer |  |\n| `file_update_time` | string | date-time |\n| `line_count` | integer |  |"
          },
          "response": []
        },
        {
          "name": "Daily Updated Domains",
          "id": "a25c451a-1434-5a37-845e-69224b505117",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{api_base_url}}/{{api_version}}/feeds/daily-updated-domains?file_format=json",
              "host": [
                "{{api_base_url}}"
              ],
              "path": [
                "{{api_version}}",
                "feeds",
                "daily-updated-domains"
              ],
              "query": [
                {
                  "key": "file_format",
                  "value": "json",
                  "description": "One of: `csv`, `json`."
                }
              ]
            },
            "description": "**Deepinfo Feeds Daily Updated Domains API**\n\nDomains whose registration was updated in the last day.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `download_url` | string | uri |\n| `file_format` | string | One of `csv`, `json` |\n| `file_size` | integer |  |\n| `file_update_time` | string | date-time |\n| `line_count` | integer |  |"
          },
          "response": []
        }
      ]
    },
    {
      "name": "EASM",
      "id": "c5e73101-c27f-5a01-9183-691d5f6fe6ab",
      "description": "External Attack Surface Management: your monitored **assets** (domains, subdomains, IPs, websites), what Deepinfo **discovers** around them, and the **issues**, **vulnerabilities** and **technologies** found on them.",
      "item": [
        {
          "name": "Assets",
          "id": "bc41e377-634f-575d-8d93-2d21446571ec",
          "description": "Add, search, update, tag and delete the assets you monitor, and trigger an on-demand scan.",
          "item": [
            {
              "name": "Asset Search",
              "id": "d3c5783a-ee0c-5a50-acf4-44752d63ffc2",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Search API**\n\nSearches your monitored assets with filters and sorting. An empty body `{}` returns all assets. See **Getting Started → Search & Filters** for the filter syntax; `name` accepts every searchable asset field (see **Filtering**).\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 517 fields\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `tags`: Your own labels on the asset, such as a business unit or an environment; each tag is 3 to 100 characters long.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.name.unicode`: The host name without its extension, in Unicode: `acme` for `acme.example`, `www.acme` for `www.acme.example`.\n- `fqdn.name.latinized`: Latin-letter spellings of a name that has non-Latin or accented letters, so a search for `istanbul` also finds names written with `İ`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_sub.unicode`: The second-level part of a two-part extension, such as `co` in `co.uk`; empty for single-part extensions.\n- `website.path`: The URL path of a website asset, such as `/`.\n- `website.scheme`: The URL scheme of a website asset, such as `http`.\n- `website.parent_asset.id`: The ID of the domain or subdomain asset that a website asset belongs to.\n- `website.parent_asset.name`: The name of the domain or subdomain asset that a website asset belongs to.\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.name`: The registrant's name in WHOIS; often a privacy placeholder such as `redacted for privacy`.\n- `whois.registrant.country`: The registrant's country in WHOIS, as a two-letter code in lower case such as `us`.\n- `whois.registrant.state`: The registrant's state or province in WHOIS.\n- `whois.registrant.city`: The registrant's city in WHOIS.\n- `whois.registrant.street`: The registrant's street address in WHOIS.\n- `whois.registrant.postal_code`: The registrant's postal code in WHOIS.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `whois_registrant_email_historical`: Every registrant e-mail address seen for the domain over time, the current one included.\n- `whois_normalized.registrar`: The registrar reduced to a short normalized name, such as `godaddy` or `gandi`, so the same registrar matches across spellings.\n- `whois_normalized.registrant.email`: The registrant e-mail address after WHOIS normalization.\n- `whois_normalized.registrant.email_real`: Another normalized registrant e-mail field, set on fewer domains than `whois_normalized.registrant.email`; in the samples it is set only where `whois_privacy_enabled` is false, with the same address.\n- `whois_normalized.registrant.email_domain_apex`: The registrable domain of the registrant e-mail address: `acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.email_fqdn_apex`: The full host name after the `@` of the registrant e-mail address: `mail.acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.organization`: The registrant organization cleaned up across registrars: lower case, with spaces and punctuation removed, such as `domainsbyproxyllc`.\n- `whois_normalized.registrant.phone`: The registrant phone number reduced to its digits, such as `14805551234`.\n- `whois_last_change_data`: The WHOIS fields that changed in the last change seen, as field paths such as `whois.update_date` or `whois.domain_status`.\n- `dns.a.value`: The asset's current A records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.a.value_previous`: The asset's A records as they were before the last change, in the same text form as `dns.a.value`.\n- `dns.a.rcode`: The DNS response code returned for the asset's A lookup, such as `NOERROR`.\n- `dns.a.rcode_previous`: The DNS response code of the A lookup before it last changed.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.entities`: The handles of the registry contacts and organizations linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, when it is kept.\n- `dns.a.ip_addresses.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the A-record address.\n- `dns.a.ip_addresses.raw`: The raw IP WHOIS response for the A-record address, when it is kept; empty on every sampled asset.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.a.ip_addresses.network.start_address`: The first address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.end_address`: The last address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.handle`: The registry handle of the network that contains the A-record address, such as `NET-192-0-2-0-1`.\n- `dns.a.ip_addresses.network.ip_version`: The IP version of the network that contains the A-record address: `v4` or `v6`.\n- `dns.a.ip_addresses.network.links`: Links to the registry record of the network that contains the A-record address, such as its RDAP and WHOIS URLs.\n- `dns.a.ip_addresses.network.parent_handle`: The handle of the larger network block from which the network of the A-record address was allocated.\n- `dns.a.ip_addresses.network.raw`: The raw RDAP network object for the A-record address, when it is kept.\n- `dns.a.ip_addresses.network.status`: The registry status of the network that contains the A-record address, such as `active`.\n- `dns.a.ip_addresses.network.type`: The registry's allocation type for the network that contains the A-record address, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `dns.a.ip_addresses.network.notices.title`: The title of a notice the registry attached to the network record of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.network.notices.description`: The text of a notice the registry attached to the network record of the A-record address.\n- `dns.a.ip_addresses.network.notices.links`: Links given in a notice on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.title`: The title of a remark on the network record of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.network.remarks.description`: The text of a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.links`: Links given in a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.events.action`: An event in the history of the network record of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.network.events.actor`: Who performed an event on the network record of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the A-record address, such as `abuse`.\n- `dns.a.ip_addresses.objects.contact.email.value`: An e-mail address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.value`: A postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the A-record address, such as `voice` or `work`.\n- `dns.a.ip_addresses.objects.contact.phone.value`: A phone number of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.kind`: What kind of contact is linked to the network of the A-record address: `org`, `group` or `individual`.\n- `dns.a.ip_addresses.objects.contact.name`: The name of a contact or organization linked to the network of the A-record address, such as `Abuse` or a company name.\n- `dns.a.ip_addresses.objects.contact.role`: The role given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.title`: The title given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.entities`: Handles of further entities listed under a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.events.action`: An event in the history of a contact record linked to the network of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.objects.events.actor`: Who performed an event on a contact record linked to the network of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.events_actor`: Events in which a contact linked to the network of the A-record address is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `dns.a.ip_addresses.objects.handle`: The registry handle of a contact or organization linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.links`: Links to the registry record of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.title`: The title of a notice on a contact record linked to the network of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.objects.notices.description`: The text of a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.links`: Links given in a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.raw`: The raw RDAP object of a contact linked to the network of the A-record address, when it is kept.\n- `dns.a.ip_addresses.objects.remarks.title`: The title of a remark on a contact record linked to the network of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.objects.remarks.description`: The text of a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.roles`: The roles of a contact for the network of the A-record address, such as `registrant`, `abuse` or `technical`.\n- `dns.a.ip_addresses.objects.status`: The registry status of a contact linked to the network of the A-record address, such as `validated`.\n- `dns.a.ip_history`: Every IPv4 address seen in the asset's A records over time, the current ones included.\n- `dns.aaaa.value`: The asset's current AAAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.aaaa.value_previous`: The asset's AAAA records as they were before the last change, in the same text form as `dns.aaaa.value`.\n- `dns.aaaa.rcode`: The DNS response code returned for the asset's AAAA lookup, such as `NOERROR`.\n- `dns.aaaa.rcode_previous`: The DNS response code of the AAAA lookup before it last changed.\n- `dns.aaaa.ip_addresses`: The IPv6 addresses in the asset's AAAA records.\n- `dns.caa.value`: The asset's current CAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.caa.value_previous`: The asset's CAA records as they were before the last change, in the same text form as `dns.caa.value`.\n- `dns.caa.rcode`: The DNS response code returned for the asset's CAA lookup, such as `NOERROR`.\n- `dns.caa.rcode_previous`: The DNS response code of the CAA lookup before it last changed.\n- `dns.caa.issue_fqdns`: The certificate authorities allowed to issue certificates for the name, from the CAA `issue` tags, such as `fernhill.example` or `kestrel.example`.\n- `dns.caa.issuewild_fqdns`: The certificate authorities allowed to issue wildcard certificates for the name, from the CAA `issuewild` tags.\n- `dns.caa.iodef_emails`: The e-mail addresses from the CAA `iodef` tags, where certificate authorities report requests that break the CAA policy.\n- `dns.cname.value`: The asset's current CNAME records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.cname.value_previous`: The asset's CNAME records as they were before the last change, in the same text form as `dns.cname.value`.\n- `dns.cname.rcode`: The DNS response code returned for the asset's CNAME lookup, such as `NOERROR`.\n- `dns.cname.rcode_previous`: The DNS response code of the CNAME lookup before it last changed.\n- `dns.cname.canonical_fqdns`: The host names the asset's CNAME records point to (the alias targets).\n- `dns.dnskey.value`: The asset's current DNSKEY records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.dnskey.value_previous`: The asset's DNSKEY records as they were before the last change, in the same text form as `dns.dnskey.value`.\n- `dns.dnskey.rcode`: The DNS response code returned for the asset's DNSKEY lookup, such as `NOERROR`.\n- `dns.dnskey.rcode_previous`: The DNS response code of the DNSKEY lookup before it last changed.\n- `dns.dnskey.records.public_key`: The public key of a DNSKEY record, Base64-encoded and split into space-separated groups as in the zone-file text.\n- `dns.ds.value`: The asset's current DS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ds.value_previous`: The asset's DS records as they were before the last change, in the same text form as `dns.ds.value`.\n- `dns.ds.rcode`: The DNS response code returned for the asset's DS lookup, such as `NOERROR`.\n- `dns.ds.rcode_previous`: The DNS response code of the DS lookup before it last changed.\n- `dns.ds.records.digest`: The digest of a DS record, the hash of the DNSKEY it refers to.\n- `dns.mx.value`: The asset's current MX records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.mx.value_previous`: The asset's MX records as they were before the last change, in the same text form as `dns.mx.value`.\n- `dns.mx.rcode`: The DNS response code returned for the asset's MX lookup, such as `NOERROR`.\n- `dns.mx.rcode_previous`: The DNS response code of the MX lookup before it last changed.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns.mx.domains`: The registrable domains of the asset's mail servers, such as `acme.example`.\n- `dns.ns.value`: The asset's current NS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ns.value_previous`: The asset's NS records as they were before the last change, in the same text form as `dns.ns.value`.\n- `dns.ns.rcode`: The DNS response code returned for the asset's NS lookup, such as `NOERROR`.\n- `dns.ns.rcode_previous`: The DNS response code of the NS lookup before it last changed.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.ns.domains`: The registrable domains of the asset's name servers, such as `acme.example`.\n- `dns.nsec.value`: The asset's current NSEC records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec.value_previous`: The asset's NSEC records as they were before the last change, in the same text form as `dns.nsec.value`.\n- `dns.nsec.rcode`: The DNS response code returned for the asset's NSEC lookup, such as `NOERROR`.\n- `dns.nsec.rcode_previous`: The DNS response code of the NSEC lookup before it last changed.\n- `dns.nsec.records.next_domain`: The next name in the zone, from an NSEC record.\n- `dns.nsec.records.record_types`: The record types that exist at the name, from an NSEC record's type list, such as `A`, `NS` or `SOA`.\n- `dns.nsec3.value`: The asset's current NSEC3 records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec3.value_previous`: The asset's NSEC3 records as they were before the last change, in the same text form as `dns.nsec3.value`.\n- `dns.nsec3.rcode`: The DNS response code returned for the asset's NSEC3 lookup, such as `NOERROR`.\n- `dns.nsec3.rcode_previous`: The DNS response code of the NSEC3 lookup before it last changed.\n- `dns.nsec3.records.next_domain_hashed`: The hashed next name in the zone, from an NSEC3 record.\n- `dns.nsec3.records.record_types`: The record types that exist at the name, from an NSEC3 record's type list, such as `A` or `MX`.\n- `dns.rrsig.value`: The asset's current RRSIG records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.rrsig.value_previous`: The asset's RRSIG records as they were before the last change, in the same text form as `dns.rrsig.value`.\n- `dns.rrsig.rcode`: The DNS response code returned for the asset's RRSIG lookup, such as `NOERROR`.\n- `dns.rrsig.rcode_previous`: The DNS response code of the RRSIG lookup before it last changed.\n- `dns.rrsig.type_covered`: The record type that an RRSIG signature covers, such as `A` or `SOA`.\n- `dns.rrsig.signature`: The signature data of an RRSIG record, Base64-encoded.\n- `dns.soa.value`: The asset's current SOA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.soa.value_previous`: The asset's SOA records as they were before the last change, in the same text form as `dns.soa.value`.\n- `dns.soa.rcode`: The DNS response code returned for the asset's SOA lookup, such as `NOERROR`.\n- `dns.soa.rcode_previous`: The DNS response code of the SOA lookup before it last changed.\n- `dns.soa.mnames`: The MNAME of the SOA record: the primary name server of the zone, such as `ns1.acme.example`.\n- `dns.soa.rnames`: The RNAME of the SOA record, the zone administrator's mailbox in DNS form: `hostmaster.acme.example` stands for the mailbox `hostmaster` at `acme.example`.\n- `dns.soa.rname_emails`: The RNAME of the SOA record written as an e-mail address, such as `user@acme.example`.\n- `dns.srv.value`: The asset's current SRV records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.srv.value_previous`: The asset's SRV records as they were before the last change, in the same text form as `dns.srv.value`.\n- `dns.srv.rcode`: The DNS response code returned for the asset's SRV lookup, such as `NOERROR`.\n- `dns.srv.rcode_previous`: The DNS response code of the SRV lookup before it last changed.\n- `dns.srv.records.service`: The service named in an SRV record (the `_service` part of its name).\n- `dns.srv.records.protocol`: The protocol named in an SRV record (the `_proto` part of its name, such as TCP or UDP).\n- `dns.srv.records.target`: The host name an SRV record points to.\n- `dns.txt.value`: The asset's current TXT records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.txt.value_previous`: The asset's TXT records as they were before the last change, in the same text form as `dns.txt.value`.\n- `dns.txt.rcode`: The DNS response code returned for the asset's TXT lookup, such as `NOERROR`.\n- `dns.txt.rcode_previous`: The DNS response code of the TXT lookup before it last changed.\n- `dns.txt.values`: Each TXT record of the asset as its quoted text, such as `\"v=spf1 include:_spf.acme.example ~all\"`; the quotes are part of the value.\n- `dns.txt.spf_list.value`: The text of an SPF record (a TXT record that starts with `v=spf1`), quoted as in `dns.txt.values`.\n- `dns.txt.spf_list.allowed_domains`: The registrable domains that an SPF record refers to, such as `acme.example` for `include:_spf.acme.example`.\n- `dns.txt.spf_list.allowed_ips`: The IP addresses and ranges that an SPF record authorizes to send mail (its `ip4:` and `ip6:` entries).\n- `dns.txt.verifications.value`: The text of a site-verification TXT record, quoted as in `dns.txt.values`.\n- `dns.txt.verifications.domain`: The domain of the service a verification record is for, such as `acme.example`, `fernhill.example` or `kestrel.example`.\n- `dns.txt.verifications.name`: The name of a verification record, such as `site-verification` or `domain-verification`.\n- `dns_last_change_data`: The DNS fields that changed in the last change seen, as field paths such as `dns.soa.mnames`.\n- `ssl.target`: The host name that the asset's TLS certificate was collected from, normally the asset itself.\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.md5`: The MD5 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha256`: The SHA-256 fingerprint of the asset's TLS certificate, as lower-case hex; one fingerprint identifies one certificate.\n- `ssl.issuer.common_name`: The common name (CN) of the certificate authority that issued the asset's TLS certificate, such as `WE1` or `YE2`.\n- `ssl.issuer.country`: The country (C) of the certificate authority that issued the asset's TLS certificate, as a two-letter code such as `US`.\n- `ssl.issuer.state`: The state or province (ST) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.locality`: The locality or city (L) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.organization`: The organization (O) of the certificate authority that issued the asset's TLS certificate, such as `Let's Encrypt` or `Google Trust Services`.\n- `ssl.issuer.organizational_unit`: The organizational unit (OU) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer_dn`: The full distinguished name of the issuer of the asset's TLS certificate, as one string such as `CN=WE1,O=Google Trust Services,C=US`.\n- `ssl.subject.common_name`: The common name (CN) of the subject (holder) of the asset's TLS certificate, usually a host name such as `acme.example`.\n- `ssl.subject.country`: The country (C) of the subject (holder) of the asset's TLS certificate, as a two-letter code.\n- `ssl.subject.state`: The state or province (ST) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.locality`: The locality or city (L) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organizational_unit`: The organizational unit (OU) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject_dn`: The full distinguished name of the subject of the asset's TLS certificate, such as `CN=acme.example`; one that starts with `CN=*.` belongs to a wildcard certificate.\n- `ssl.signature.value`: The signature of the asset's TLS certificate, Base64-encoded.\n- `ssl.signature.invalid_reason`: Why certificate validation failed, such as a host name mismatch or `unable to get issuer certificate`.\n- `ssl.signature.algorithm.name`: The hash algorithm of the signature on the asset's TLS certificate, such as `sha256` or `sha384`.\n- `ssl.signature.algorithm.oid`: The object identifier (OID) of the signature algorithm, such as `1.2.840.113549.1.1.11` (SHA-256 with RSA) or `1.2.840.10045.4.3.2` (ECDSA with SHA-256).\n- `ssl.extensions.authority_key_id`: The Authority Key Identifier extension, which identifies the issuer's key, Base64-encoded.\n- `ssl.extensions.certificate_policies`: The policy OIDs in the Certificate Policies extension, such as `2.23.140.1.2.1` (domain validated).\n- `ssl.extensions.signed_certificate_timestamps.log_id`: The ID of the Certificate Transparency log that issued a signed certificate timestamp (SCT) for the certificate, Base64-encoded.\n- `ssl.extensions.signed_certificate_timestamps.signature`: The log's signature on a signed certificate timestamp, Base64-encoded.\n- `ssl.extensions.subject_alt_name.dns_names`: The host names in the certificate's Subject Alternative Name extension, including wildcard names such as `*.acme.example`.\n- `ssl.extensions.subject_key_id`: The Subject Key Identifier extension, which identifies the certificate's own key, Base64-encoded.\n- `ssl.subject_key_info.fingerprint.hash_algorithm`: The hash algorithm used for `ssl.subject_key_info.fingerprint.value`, such as `sha256` or `sha384`.\n- `ssl.subject_key_info.fingerprint.value`: A hex fingerprint recorded under the certificate's subject key information, made with the hash in `hash_algorithm`. In the samples it equals `ssl.fingerprint.sha256` when that hash is SHA-256.\n- `ssl.subject_key_info.key_algorithm.name`: The algorithm of the certificate's public key, such as `RSA` or `ECDSA`.\n- `ssl.version.name`: The X.509 version of the certificate, such as `v3`.\n- `ssl.version.value`: The X.509 version as encoded in the certificate, counted from zero: `2` means `v3`.\n- `ssl.tbs_fingerprint`: A SHA-256 fingerprint (hex) of the certificate's to-be-signed part, the certificate content without its signature.\n- `ssl.certificate`: The whole certificate, Base64-encoded (a PEM body without the header and footer lines).\n- `ssl.fqdn_list`: The host names the certificate covers, with the `*.` of wildcard names removed and duplicates merged, so `*.acme.example` and `acme.example` both give `acme.example`.\n- `ssl_last_change_data`: The certificate fields that changed in the last change seen, as field paths such as `ssl.validity.end_date`.\n- `http.requested_url`: The URL the HTTP check started from, such as `http://acme.example`.\n- `http.requested_domain`: The registrable domain of the URL the HTTP check started from.\n- `http.requested_fqdn`: The host name of the URL the HTTP check started from.\n- `http.final_url`: The URL the HTTP check ended on after following all redirects.\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.redirection_history.url`: A URL in the redirect chain of the HTTP check, listed in the order visited.\n- `http.headers.accept`: The `Accept` header, when it was returned in the HTTP check. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the HTTP check. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `http.headers.accept_language`: The `Accept-Language` header, when it was returned in the HTTP check. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the HTTP check; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the HTTP check; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the HTTP check; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the HTTP check; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the HTTP check; it lists the response headers that scripts from other origins may read (CORS).\n- `http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the HTTP check; it says how many seconds browsers may cache a CORS preflight result.\n- `http.headers.alt_svc`: The `Alt-Svc` header returned in the HTTP check; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `http.headers.authorization`: The `Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `http.headers.cache_control`: The `Cache-Control` header returned in the HTTP check; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the HTTP check; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `http.headers.content_disposition`: The `Content-Disposition` header returned in the HTTP check; it says whether the content is shown in the browser or downloaded as a file.\n- `http.headers.content_encoding`: The `Content-Encoding` header returned in the HTTP check; it names the compression applied to the response body, for example `gzip` or `br`.\n- `http.headers.content_language`: The `Content-Language` header returned in the HTTP check; it gives the language of the content, for example `en` or `tr`.\n- `http.headers.content_length`: The `Content-Length` header returned in the HTTP check; it gives the size of the response body in bytes.\n- `http.headers.content_range`: The `Content-Range` header returned in the HTTP check; it says which part of the full body a partial response holds.\n- `http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the HTTP check; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `http.headers.content_type`: The `Content-Type` header returned in the HTTP check; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `http.headers.cookie`: The `Cookie` header, when it was returned in the HTTP check. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the HTTP check; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the HTTP check; it controls whether the page shares its browsing context with cross-origin windows.\n- `http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the HTTP check; it controls which sites may load the resource.\n- `http.headers.date`: The `Date` header returned in the HTTP check; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `http.headers.early_data`: The `Early-Data` header, when it was returned in the HTTP check. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `http.headers.expect_ct`: The `Expect-CT` header returned in the HTTP check; it is a deprecated header about Certificate Transparency enforcement.\n- `http.headers.expires`: The `Expires` header returned in the HTTP check; it gives the date after which the response counts as stale, in HTTP date format.\n- `http.headers.feature_policy`: The `Feature-Policy` header returned in the HTTP check; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `http.headers.host`: The `Host` header, when it was returned in the HTTP check. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the HTTP check. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the HTTP check. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `http.headers.last_modified`: The `Last-Modified` header returned in the HTTP check; it gives the time the server says the resource last changed, in HTTP date format.\n- `http.headers.origin_isolation`: The `Origin-Isolation` header returned in the HTTP check; it is an experimental header that asks browsers to isolate the site's origin.\n- `http.headers.others.name`: The name of a header returned in the HTTP check that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `http.headers.others.value`: The value of a header listed in `headers.others` for the HTTP check.\n- `http.headers.permission_policy`: The `Permission-Policy` header returned in the HTTP check; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `http.headers.permissions_policy`: The `Permissions-Policy` header returned in the HTTP check; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `http.headers.pragma`: The `Pragma` header returned in the HTTP check; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the HTTP check; it tells a client how to authenticate to a proxy.\n- `http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the HTTP check; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `http.headers.range`: The `Range` header, when it was returned in the HTTP check. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `http.headers.referer`: The `Referer` header, when it was returned in the HTTP check. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `http.headers.referrer_policy`: The `Referrer-Policy` header returned in the HTTP check; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the HTTP check. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `http.headers.server`: The `Server` header returned in the HTTP check; it names the server software the site reports, for example `nginx` or `Apache`.\n- `http.headers.set_cookie`: The `Set-Cookie` header returned in the HTTP check; it sets cookies, with their attributes.\n- `http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the HTTP check; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `http.headers.te`: The `TE` header, when it was returned in the HTTP check. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the HTTP check; it says how the body is transferred, for example `chunked`.\n- `http.headers.upgrade`: The `Upgrade` header returned in the HTTP check; it offers or asks for a switch to another protocol.\n- `http.headers.user_agent`: The `User-Agent` header, when it was returned in the HTTP check. It is normally a request header (the client software), so it is rarely set.\n- `http.headers.vary`: The `Vary` header returned in the HTTP check; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the HTTP check; it tells a client how to authenticate, usually with a `401` response.\n- `http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the HTTP check; it stops browsers from guessing the content type when set to `nosniff`.\n- `http.headers.x_download_options`: The `X-Download-Options` header returned in the HTTP check; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `http.headers.x_frame_options`: The `X-Frame-Options` header returned in the HTTP check; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the HTTP check; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `http.headers.x_powered_by`: The `X-Powered-By` header returned in the HTTP check; it names the technology the server reports running on, for example `Express`.\n- `http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the HTTP check; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `http.cookies.name`: The name of a cookie set in the HTTP check.\n- `http.cookies.value`: The value of a cookie set in the HTTP check.\n- `http.html.source_code_hash`: A SHA-256 hash of the page source returned in the HTTP check; the same hash means the same source.\n- `http_last_change_data`: The HTTP check fields that changed in the last change seen, as field paths such as `http.html.source_code_hash`.\n- `webdata.requested_url`: The URL the web data scan started from, such as `http://acme.example`.\n- `webdata.requested_domain`: The registrable domain of the URL the web data scan started from.\n- `webdata.requested_fqdn`: The host name of the URL the web data scan started from.\n- `webdata.html.internal_links_fqdns`: The host names of links on the scanned page that stay within the site's own domain, such as other subdomains.\n- `webdata.html.external_links_domains`: The registrable domains of links on the scanned page that point to other domains, such as `kestrel.example`.\n- `webdata.html.external_links_fqdns`: The host names of links on the scanned page that point to other domains, such as `www.kestrel.example`.\n- `webdata.html.external_links`: The full URLs of links on the scanned page that point to other domains.\n- `webdata.html.script_links`: The URLs of the scripts the scanned page loads.\n- `webdata.html.iframe_links`: The URLs of the frames (iframes) embedded in the scanned page.\n- `webdata.html.trackers.name`: The name of an analytics or advertising tracker found on the scanned page, such as `google_adsense` or `google_tag_manager`.\n- `webdata.html.trackers.values`: The IDs found for a tracker, such as a Google Analytics ID that starts with `G-` or `UA-`.\n- `webdata.html.emails`: The e-mail addresses found on the scanned page.\n- `webdata.html.emails_internal`: The e-mail addresses found on the scanned page that belong to the site's own domain.\n- `webdata.html.source_code_hash`: A SHA-256 hash of the page source in the web data scan; the same hash means the same source.\n- `webdata.html.content_hash`: A SHA-256 hash of the page content in the web data scan, kept apart from `source_code_hash`, the hash of the raw source.\n- `webdata.html.content_top_keywords`: The most frequent words in the text of the scanned page.\n- `webdata.html.favicon_links`: The URLs of the icons the scanned page declares, such as its favicon and touch icons.\n- `webdata.html.html_meta.name`: The site or application name declared in the scanned page's metadata.\n- `webdata.html.html_meta.description`: The meta description of the scanned page.\n- `webdata.html.html_meta.language`: The language the scanned page declares, such as `en`, `tr` or `en-US`.\n- `webdata.html.html_meta.language_alternatives`: The languages of the alternative versions the scanned page links to, such as `en` or `ar`.\n- `webdata.html.html_meta.keywords`: The keywords listed in the keywords meta tag of the scanned page.\n- `webdata.html.html_meta.encoding`: The character encoding the scanned page declares, such as `utf-8`.\n- `webdata.html.html_meta.canonical_url`: The canonical URL the scanned page declares.\n- `webdata.html.html_meta.title`: The title of the scanned page.\n- `webdata.favicon.url`: The URL of a site icon (favicon) recorded by the web data scan.\n- `webdata.favicon.hash`: A SHA-256 hash of a site icon; the same hash means the same icon.\n- `webdata.http.final_url`: The URL the web data scan ended on after following all redirects.\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.redirection_history.url`: A URL in the redirect chain of the web data scan, listed in the order visited.\n- `webdata.http.redirection_history.method`: How a step of the web data scan's redirect chain was made; `http-header` (a redirect sent in the HTTP response) is the value in the samples.\n- `webdata.http.headers.accept`: The `Accept` header, when it was returned in the web data scan. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the web data scan. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_language`: The `Accept-Language` header, when it was returned in the web data scan. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `webdata.http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the web data scan; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `webdata.http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the web data scan; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `webdata.http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the web data scan; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `webdata.http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the web data scan; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `webdata.http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the web data scan; it lists the response headers that scripts from other origins may read (CORS).\n- `webdata.http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the web data scan; it says how many seconds browsers may cache a CORS preflight result.\n- `webdata.http.headers.alt_svc`: The `Alt-Svc` header returned in the web data scan; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `webdata.http.headers.authorization`: The `Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `webdata.http.headers.cache_control`: The `Cache-Control` header returned in the web data scan; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `webdata.http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the web data scan; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `webdata.http.headers.content_disposition`: The `Content-Disposition` header returned in the web data scan; it says whether the content is shown in the browser or downloaded as a file.\n- `webdata.http.headers.content_encoding`: The `Content-Encoding` header returned in the web data scan; it names the compression applied to the response body, for example `gzip` or `br`.\n- `webdata.http.headers.content_language`: The `Content-Language` header returned in the web data scan; it gives the language of the content, for example `en` or `tr`.\n- `webdata.http.headers.content_length`: The `Content-Length` header returned in the web data scan; it gives the size of the response body in bytes.\n- `webdata.http.headers.content_range`: The `Content-Range` header returned in the web data scan; it says which part of the full body a partial response holds.\n- `webdata.http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the web data scan; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `webdata.http.headers.content_type`: The `Content-Type` header returned in the web data scan; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `webdata.http.headers.cookie`: The `Cookie` header, when it was returned in the web data scan. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `webdata.http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the web data scan; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `webdata.http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the web data scan; it controls whether the page shares its browsing context with cross-origin windows.\n- `webdata.http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the web data scan; it controls which sites may load the resource.\n- `webdata.http.headers.date`: The `Date` header returned in the web data scan; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `webdata.http.headers.early_data`: The `Early-Data` header, when it was returned in the web data scan. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `webdata.http.headers.expect_ct`: The `Expect-CT` header returned in the web data scan; it is a deprecated header about Certificate Transparency enforcement.\n- `webdata.http.headers.expires`: The `Expires` header returned in the web data scan; it gives the date after which the response counts as stale, in HTTP date format.\n- `webdata.http.headers.feature_policy`: The `Feature-Policy` header returned in the web data scan; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `webdata.http.headers.host`: The `Host` header, when it was returned in the web data scan. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `webdata.http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the web data scan. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `webdata.http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the web data scan. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `webdata.http.headers.last_modified`: The `Last-Modified` header returned in the web data scan; it gives the time the server says the resource last changed, in HTTP date format.\n- `webdata.http.headers.origin_isolation`: The `Origin-Isolation` header returned in the web data scan; it is an experimental header that asks browsers to isolate the site's origin.\n- `webdata.http.headers.others.name`: The name of a header returned in the web data scan that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `webdata.http.headers.others.value`: The value of a header listed in `headers.others` for the web data scan.\n- `webdata.http.headers.permission_policy`: The `Permission-Policy` header returned in the web data scan; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `webdata.http.headers.permissions_policy`: The `Permissions-Policy` header returned in the web data scan; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `webdata.http.headers.pragma`: The `Pragma` header returned in the web data scan; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `webdata.http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the web data scan; it tells a client how to authenticate to a proxy.\n- `webdata.http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `webdata.http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the web data scan; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `webdata.http.headers.range`: The `Range` header, when it was returned in the web data scan. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `webdata.http.headers.referer`: The `Referer` header, when it was returned in the web data scan. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `webdata.http.headers.referrer_policy`: The `Referrer-Policy` header returned in the web data scan; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `webdata.http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `webdata.http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the web data scan. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `webdata.http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `webdata.http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the web data scan. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `webdata.http.headers.server`: The `Server` header returned in the web data scan; it names the server software the site reports, for example `nginx` or `Apache`.\n- `webdata.http.headers.set_cookie`: The `Set-Cookie` header returned in the web data scan; it sets cookies, with their attributes.\n- `webdata.http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the web data scan; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `webdata.http.headers.te`: The `TE` header, when it was returned in the web data scan. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `webdata.http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the web data scan; it says how the body is transferred, for example `chunked`.\n- `webdata.http.headers.upgrade`: The `Upgrade` header returned in the web data scan; it offers or asks for a switch to another protocol.\n- `webdata.http.headers.user_agent`: The `User-Agent` header, when it was returned in the web data scan. It is normally a request header (the client software), so it is rarely set.\n- `webdata.http.headers.vary`: The `Vary` header returned in the web data scan; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `webdata.http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the web data scan; it tells a client how to authenticate, usually with a `401` response.\n- `webdata.http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the web data scan; it stops browsers from guessing the content type when set to `nosniff`.\n- `webdata.http.headers.x_download_options`: The `X-Download-Options` header returned in the web data scan; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `webdata.http.headers.x_frame_options`: The `X-Frame-Options` header returned in the web data scan; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `webdata.http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the web data scan; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `webdata.http.headers.x_powered_by`: The `X-Powered-By` header returned in the web data scan; it names the technology the server reports running on, for example `Express`.\n- `webdata.http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the web data scan; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `webdata.http.cookies.name`: The name of a cookie set in the web data scan.\n- `webdata.http.cookies.value`: The value of a cookie set in the web data scan.\n- `webdata.http.cookies.domain`: The domain a cookie set in the web data scan applies to, such as `.acme.example`.\n- `webdata.http.cookies.path`: The path a cookie set in the web data scan applies to, such as `/`.\n- `webdata.http.cookies.same_party`: The SameParty attribute of a cookie set in the web data scan; in the samples it always holds the same value as `same_site`, such as `Lax` or `None`.\n- `webdata.http.cookies.priority`: The Priority attribute of a cookie set in the web data scan (`Low`, `Medium` or `High` in Chromium-based browsers).\n- `webdata.http.cookies.same_site`: The SameSite attribute of a cookie set in the web data scan, such as `Lax`, `Strict` or `None`.\n- `webdata.technology.stacks.slug`: A short identifier of a technology detected on the site, such as `iis` or `windows-server`.\n- `webdata.technology.stacks.name`: The name of a technology detected on the site, such as `IIS` or `Microsoft ASP.NET`.\n- `webdata.technology.stacks.icon`: The file name of a detected technology's icon, such as `acme.png`.\n- `webdata.technology.stacks.website`: The website of a detected technology's vendor or project.\n- `webdata.technology.stacks.cpe`: The CPE identifier of a detected technology, such as `cpe:/a:acme:acme-portal`, used to match it to known vulnerabilities.\n- `webdata.technology.stacks.version`: The detected version of a technology, such as `1.0`.\n- `webdata.technology.stacks.categories`: The categories of a detected technology, such as `Web servers` or `Operating systems`.\n- `webdata.technology.stacks.description`: A short description of a detected technology.\n- `webdata_last_change_data`: The web data fields that changed in the last change seen, as field paths under `webdata`.\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.entities`: The handles of the registry contacts and organizations linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, when it is kept.\n- `ipwhois.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the IP address asset.\n- `ipwhois.raw`: The raw IP WHOIS response for the IP address asset, when it is kept; empty on every sampled asset.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `ipwhois.network.start_address`: The first address of the registered network block that contains the IP address asset.\n- `ipwhois.network.end_address`: The last address of the registered network block that contains the IP address asset.\n- `ipwhois.network.handle`: The registry handle of the network that contains the IP address asset, such as `NET-192-0-2-0-1`.\n- `ipwhois.network.ip_version`: The IP version of the network that contains the IP address asset: `v4` or `v6`.\n- `ipwhois.network.links`: Links to the registry record of the network that contains the IP address asset, such as its RDAP and WHOIS URLs.\n- `ipwhois.network.parent_handle`: The handle of the larger network block from which the network of the IP address asset was allocated.\n- `ipwhois.network.raw`: The raw RDAP network object for the IP address asset, when it is kept.\n- `ipwhois.network.status`: The registry status of the network that contains the IP address asset, such as `active`.\n- `ipwhois.network.type`: The registry's allocation type for the network that contains the IP address asset, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `ipwhois.network.notices.title`: The title of a notice the registry attached to the network record of the IP address asset, such as `Terms of Service`.\n- `ipwhois.network.notices.description`: The text of a notice the registry attached to the network record of the IP address asset.\n- `ipwhois.network.notices.links`: Links given in a notice on the network record of the IP address asset.\n- `ipwhois.network.remarks.title`: The title of a remark on the network record of the IP address asset, such as `Registration Comments`.\n- `ipwhois.network.remarks.description`: The text of a remark on the network record of the IP address asset.\n- `ipwhois.network.remarks.links`: Links given in a remark on the network record of the IP address asset.\n- `ipwhois.network.events.action`: An event in the history of the network record of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.network.events.actor`: Who performed an event on the network record of the IP address asset, when the registry names one.\n- `ipwhois.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the IP address asset, such as `abuse`.\n- `ipwhois.objects.contact.email.value`: An e-mail address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.value`: A postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the IP address asset, such as `voice` or `work`.\n- `ipwhois.objects.contact.phone.value`: A phone number of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.kind`: What kind of contact is linked to the network of the IP address asset: `org`, `group` or `individual`.\n- `ipwhois.objects.contact.name`: The name of a contact or organization linked to the network of the IP address asset, such as `Abuse` or a company name.\n- `ipwhois.objects.contact.role`: The role given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.contact.title`: The title given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.entities`: Handles of further entities listed under a contact linked to the network of the IP address asset.\n- `ipwhois.objects.events.action`: An event in the history of a contact record linked to the network of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.objects.events.actor`: Who performed an event on a contact record linked to the network of the IP address asset, when the registry names one.\n- `ipwhois.objects.events_actor`: Events in which a contact linked to the network of the IP address asset is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `ipwhois.objects.handle`: The registry handle of a contact or organization linked to the network of the IP address asset.\n- `ipwhois.objects.links`: Links to the registry record of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.notices.title`: The title of a notice on a contact record linked to the network of the IP address asset, such as `Terms of Service`.\n- `ipwhois.objects.notices.description`: The text of a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.notices.links`: Links given in a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.raw`: The raw RDAP object of a contact linked to the network of the IP address asset, when it is kept.\n- `ipwhois.objects.remarks.title`: The title of a remark on a contact record linked to the network of the IP address asset, such as `Registration Comments`.\n- `ipwhois.objects.remarks.description`: The text of a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.roles`: The roles of a contact for the network of the IP address asset, such as `registrant`, `abuse` or `technical`.\n- `ipwhois.objects.status`: The registry status of a contact linked to the network of the IP address asset, such as `validated`.\n- `ipwhois_last_change_data`: The IP WHOIS fields that changed in the last change seen, as field paths under `ipwhois`.\n- `ipdns.ptr_records`: The PTR (reverse DNS) host names of an IP address asset.\n- `ipdns_last_change_data`: The reverse DNS fields that changed in the last change seen, as field paths under `ipdns`.\n- `issue_category_stats.name`: The name of an issue category in the per-category issue counts of the asset, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`.\n- `technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the asset, such as `Web servers` or `Analytics`.\n- `domain_snapshot.issue_category_stats.name`: The name of an issue category in the per-category issue counts of the domain and its subdomains together, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the domain and its subdomains together, such as `Web servers` or `Analytics`. Set on domain assets.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 179 fields\n\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.name.length`: The number of characters in the name without the extension: `4` for `acme.example`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois_create_date_historical`: Every creation date seen for the domain over time, so a domain that was deleted and registered again keeps its earlier dates too (UTC date-times).\n- `whois_check_date`: When the WHOIS record of the asset was last checked (UTC date-time).\n- `whois_last_change_date`: When a change in the WHOIS record of the asset was last seen (UTC date-time).\n- `dns.a.value_last_change_date`: When the A record text (`dns.a.value`) last changed (UTC date-time).\n- `dns.a.rcode_last_change_date`: When the response code of the A lookup (`dns.a.rcode`) last changed (UTC date-time).\n- `dns.a.last_change_date`: When the asset's A records last changed, in their text or their response code (UTC date-time).\n- `dns.a.ip_addresses.asn_date`: The registry allocation date that the ASN lookup reports for the A-record address, as a date at midnight UTC.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was created (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was last updated (UTC date-time).\n- `dns.a.ip_addresses.network.events.timestamp`: When an event on the network record of the A-record address happened (UTC date-time).\n- `dns.a.ip_addresses.objects.events.timestamp`: When an event on a contact record linked to the network of the A-record address happened (UTC date-time).\n- `dns.aaaa.value_last_change_date`: When the AAAA record text (`dns.aaaa.value`) last changed (UTC date-time).\n- `dns.aaaa.rcode_last_change_date`: When the response code of the AAAA lookup (`dns.aaaa.rcode`) last changed (UTC date-time).\n- `dns.aaaa.last_change_date`: When the asset's AAAA records last changed, in their text or their response code (UTC date-time).\n- `dns.caa.value_last_change_date`: When the CAA record text (`dns.caa.value`) last changed (UTC date-time).\n- `dns.caa.rcode_last_change_date`: When the response code of the CAA lookup (`dns.caa.rcode`) last changed (UTC date-time).\n- `dns.caa.last_change_date`: When the asset's CAA records last changed, in their text or their response code (UTC date-time).\n- `dns.cname.value_last_change_date`: When the CNAME record text (`dns.cname.value`) last changed (UTC date-time).\n- `dns.cname.rcode_last_change_date`: When the response code of the CNAME lookup (`dns.cname.rcode`) last changed (UTC date-time).\n- `dns.cname.last_change_date`: When the asset's CNAME records last changed, in their text or their response code (UTC date-time).\n- `dns.dnskey.value_last_change_date`: When the DNSKEY record text (`dns.dnskey.value`) last changed (UTC date-time).\n- `dns.dnskey.rcode_last_change_date`: When the response code of the DNSKEY lookup (`dns.dnskey.rcode`) last changed (UTC date-time).\n- `dns.dnskey.last_change_date`: When the asset's DNSKEY records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.value_last_change_date`: When the DS record text (`dns.ds.value`) last changed (UTC date-time).\n- `dns.ds.rcode_last_change_date`: When the response code of the DS lookup (`dns.ds.rcode`) last changed (UTC date-time).\n- `dns.ds.last_change_date`: When the asset's DS records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.records.key_tag`: The key tag (a number) of the DNSKEY that a DS record refers to.\n- `dns.mx.value_last_change_date`: When the MX record text (`dns.mx.value`) last changed (UTC date-time).\n- `dns.mx.rcode_last_change_date`: When the response code of the MX lookup (`dns.mx.rcode`) last changed (UTC date-time).\n- `dns.mx.last_change_date`: When the asset's MX records last changed, in their text or their response code (UTC date-time).\n- `dns.ns.value_last_change_date`: When the NS record text (`dns.ns.value`) last changed (UTC date-time).\n- `dns.ns.rcode_last_change_date`: When the response code of the NS lookup (`dns.ns.rcode`) last changed (UTC date-time).\n- `dns.ns.last_change_date`: When the asset's NS records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec.value_last_change_date`: When the NSEC record text (`dns.nsec.value`) last changed (UTC date-time).\n- `dns.nsec.rcode_last_change_date`: When the response code of the NSEC lookup (`dns.nsec.rcode`) last changed (UTC date-time).\n- `dns.nsec.last_change_date`: When the asset's NSEC records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec3.value_last_change_date`: When the NSEC3 record text (`dns.nsec3.value`) last changed (UTC date-time).\n- `dns.nsec3.rcode_last_change_date`: When the response code of the NSEC3 lookup (`dns.nsec3.rcode`) last changed (UTC date-time).\n- `dns.nsec3.last_change_date`: When the asset's NSEC3 records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.value_last_change_date`: When the RRSIG record text (`dns.rrsig.value`) last changed (UTC date-time).\n- `dns.rrsig.rcode_last_change_date`: When the response code of the RRSIG lookup (`dns.rrsig.rcode`) last changed (UTC date-time).\n- `dns.rrsig.last_change_date`: When the asset's RRSIG records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.signature_inception`: When an RRSIG signature becomes valid (UTC date-time).\n- `dns.rrsig.signature_expiration`: When an RRSIG signature expires (UTC date-time).\n- `dns.soa.value_last_change_date`: When the SOA record text (`dns.soa.value`) last changed (UTC date-time).\n- `dns.soa.rcode_last_change_date`: When the response code of the SOA lookup (`dns.soa.rcode`) last changed (UTC date-time).\n- `dns.soa.last_change_date`: When the asset's SOA records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.value_last_change_date`: When the SRV record text (`dns.srv.value`) last changed (UTC date-time).\n- `dns.srv.rcode_last_change_date`: When the response code of the SRV lookup (`dns.srv.rcode`) last changed (UTC date-time).\n- `dns.srv.last_change_date`: When the asset's SRV records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.records.port`: The port an SRV record points to.\n- `dns.txt.value_last_change_date`: When the TXT record text (`dns.txt.value`) last changed (UTC date-time).\n- `dns.txt.rcode_last_change_date`: When the response code of the TXT lookup (`dns.txt.rcode`) last changed (UTC date-time).\n- `dns.txt.last_change_date`: When the asset's TXT records last changed, in their text or their response code (UTC date-time).\n- `dns_check_date`: When the DNS records of the asset were last checked (UTC date-time).\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.port`: The port that the asset's TLS certificate was collected on, such as `443`.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl.validity.length`: The validity period of the certificate in seconds: 7,776,000 seconds are 90 days.\n- `ssl.extensions.signed_certificate_timestamps.timestamp`: When a Certificate Transparency log recorded the certificate, from a signed certificate timestamp (UTC date-time).\n- `ssl.extensions.signed_certificate_timestamps.version`: The version of a signed certificate timestamp; `0` stands for version 1.\n- `ssl_check_date`: When the TLS certificate of the asset was last checked (UTC date-time).\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the HTTP check, such as `301` or `200`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_check_date`: When the HTTP check of the asset last ran (UTC date-time).\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the web data scan, such as `301` or `200`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata.http.cookies.size`: The size of a cookie set in the web data scan, in bytes (name plus value).\n- `webdata.http.cookies.expires`: When a cookie set in the web data scan expires (UTC date-time); session cookies show `1969-12-31T23:59:59Z`.\n- `webdata.technology.stacks.confidence`: How certain the detection of a technology is, from 0 to 100; every sampled detection has `100`.\n- `webdata.technology.stacks.clean_version`: The major version of a detected technology as a whole number, such as `1` for version `1.0`.\n- `webdata_check_date`: When the web data scan of the asset, which collects the page content, headers and technologies, last ran (UTC date-time).\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn_date`: The registry allocation date that the ASN lookup reports for the IP address asset, as a date at midnight UTC.\n- `ipwhois.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was created (UTC date-time).\n- `ipwhois.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was last updated (UTC date-time).\n- `ipwhois.network.events.timestamp`: When an event on the network record of the IP address asset happened (UTC date-time).\n- `ipwhois.objects.events.timestamp`: When an event on a contact record linked to the network of the IP address asset happened (UTC date-time).\n- `ipwhois_check_date`: When the IP WHOIS record of an IP address asset was last checked (UTC date-time).\n- `ipwhois_last_change_date`: When a change in the IP WHOIS record of an IP address asset was last seen (UTC date-time).\n- `ipdns_check_date`: When the reverse DNS (PTR) records of an IP address asset were last checked (UTC date-time).\n- `ipdns_last_change_date`: When a change in the reverse DNS (PTR) records of an IP address asset was last seen (UTC date-time).\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `open_port_count`: The number of open ports found on the asset.\n- `open_ports`: The open port numbers found on the asset, such as `80`, `443` or `8080`.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_category_stats.count`: The number of active issues in that category on the asset.\n- `issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the asset.\n- `issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the asset.\n- `issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the asset.\n- `issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the asset.\n- `issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the asset.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `issue_count.active_by_severity.low`: The number of active issues of low severity on the asset.\n- `issue_count.active_by_severity.information`: The number of active issues of information severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `technology_count.by_category.count`: The number of technologies in that category on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity on the asset.\n- `vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity on the asset.\n- `vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity on the asset.\n- `vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) on the asset whose severity is `none`.\n- `vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) on the asset whose severity is `unknown`.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.count`: The number of active issues in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.count`: The number of distinct technologies in that category across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n**`eq`, `exists`** — 36 fields\n\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `fqdn.is_idn`: True when the host name is an internationalized domain name (IDN) with non-ASCII characters.\n- `fqdn.name.contains_confusable`: True when the name contains confusable characters that look like other letters, such as Cyrillic `а` for Latin `a`, a common trick in look-alike domains.\n- `fqdn.name.contains_hyphen`: True when the name (without the extension) contains a hyphen.\n- `fqdn.name.contains_letter`: True when the name (without the extension) contains a letter.\n- `fqdn.name.contains_number`: True when the name (without the extension) contains a digit.\n- `fqdn.domain.is_idn`: True when the registrable domain is an internationalized domain name (IDN) with non-ASCII characters.\n- `whois_privacy_enabled`: True when the platform flagged WHOIS privacy protection on the domain's registrant details; set on domain assets.\n- `ssl.signature.is_valid`: True when the asset's TLS certificate passed validation for the host; when false, `ssl.signature.invalid_reason` says why.\n- `ssl.signature.is_valid_chain`: A flag for whether the certificate chain of the asset's TLS certificate is valid. It was true on every sampled certificate, even one whose validation failed with `unable to get issuer certificate`.\n- `ssl.signature.is_self_signed`: True when the asset's TLS certificate is self-signed, that is signed by its own key rather than by a certificate authority.\n- `ssl.extensions.basic_constraints.is_ca`: True when the certificate is a certificate authority (CA) certificate, from its Basic Constraints extension.\n- `ssl.extensions.extended_key_usage.client_auth`: True when the Extended Key Usage extension allows TLS client authentication.\n- `ssl.extensions.extended_key_usage.server_auth`: True when the Extended Key Usage extension allows TLS server authentication, as website certificates need.\n- `ssl.extensions.key_usage.content_commitment`: True when the Key Usage extension allows the certificate's key to be used for content commitment (non-repudiation).\n- `ssl.extensions.key_usage.crl_sign`: True when the Key Usage extension allows the certificate's key to be used for signing certificate revocation lists (CRL sign).\n- `ssl.extensions.key_usage.data_encipherment`: True when the Key Usage extension allows the certificate's key to be used for data encipherment.\n- `ssl.extensions.key_usage.digital_signature`: True when the Key Usage extension allows the certificate's key to be used for digital signatures.\n- `ssl.extensions.key_usage.key_agreement`: True when the Key Usage extension allows the certificate's key to be used for key agreement.\n- `ssl.extensions.key_usage.key_cert_sign`: True when the Key Usage extension allows the certificate's key to be used for signing other certificates (certificate sign).\n- `ssl.extensions.key_usage.key_encipherment`: True when the Key Usage extension allows the certificate's key to be used for key encipherment.\n- `ssl.has_expired`: True when the asset's TLS certificate is past its end date.\n- `http.external_domain_redirection`: True when the HTTP check ended on a different registrable domain than it started on.\n- `http.external_fqdn_redirection`: True when the HTTP check ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.html.inspect_disabled`: A flag of the web data scan that marks pages whose inspection was disabled; it was `false` on every sampled asset.\n- `webdata.html.html_meta.no_index_status`: True when the scanned page asks search engines not to index it (a `noindex` robots directive).\n- `webdata.http.external_domain_redirection`: True when the web data scan ended on a different registrable domain than it started on.\n- `webdata.http.external_fqdn_redirection`: True when the web data scan ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.http.cookies.secure`: True when a cookie set in the web data scan is sent over HTTPS only (Secure attribute).\n- `webdata.http.cookies.http_only`: True when scripts on the page cannot read a cookie set in the web data scan (HttpOnly attribute).\n- `webdata.http.cookies.session`: True when a cookie set in the web data scan is a session cookie, deleted when the browser closes.\n- `is_parked`: True when the asset is parked; Inventory marks it with a P badge whose tooltip shows where it redirects.\n\n**`eq`, `in`, `exists`** — 8 fields\n\n- `asset_type`: The asset type: `domain`, `subdomain`, `ip` or `website`.\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `dns.dnskey.records.key_type`: The role of a DNSKEY: `ZSK` (zone-signing key), `KSK` (key-signing key) or `KSK_REVOKED` (revoked key-signing key).\n- `dns.dnskey.records.algorithm`: The DNSSEC algorithm of a DNSKEY, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.algorithm`: The DNSSEC algorithm of the key that a DS record refers to, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.digest_type`: The hash used for a DS record's digest: `SHA1`, `SHA256`, `SHA384`, `GOST` or `NULL`.\n- `dns.rrsig.algorithm`: The DNSSEC algorithm of an RRSIG signature, such as `ECDSAP256SHA256` or `RSASHA256`.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `website.parent_asset.type`: The asset type of the website's parent asset, such as `subdomain`.\n\nSortable fields:\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `website_count`: The number of website assets (`host:port`) in your inventory that belong to this asset.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `open_port_count`: The number of open ports found on the asset.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].asset` | string |  |\n| `results[].asset_type` | string | One of `domain`, `subdomain`, `ip`, `website` |\n| `results[].added_date` | string | date-time |\n| `results[].tags` | array of string |  |\n| `results[].creation_method` | string | One of `manually_added`, `manually_approved`, `auto_approved` |\n| `results[].favicon` | string |  |\n| `results[].screenshot` | string |  |\n| `results[].thumbnail` | string |  |\n| `results[].latest_scan_date` | string | date-time |\n| `results[].is_main_asset` | boolean |  |\n| `results[].seems_inactive` | boolean |  |\n| `results[].seems_inactive_first_seen` | string | date-time |\n| `results[].seems_inactive_last_seen` | string | date-time |\n| `results[].discovery_enabled` | boolean |  |\n| `results[].dns_wildcard_active` | boolean |  |\n| `results[].is_login_page` | boolean |  |\n| `results[].login_page_probability` | number |  |\n| `results[].fqdn` | object |  |\n| `results[].website` | object |  |\n| `results[].whois` | object |  |\n| `results[].whois_privacy_enabled` | boolean |  |\n| `results[].whois_registrant_email_historical` | array of string |  |\n| `results[].whois_create_date_historical` | array of string |  |\n| `results[].whois_normalized` | object |  |\n| `results[].whois_check_date` | string | date-time |\n| `results[].whois_last_change_date` | string | date-time |\n| `results[].whois_last_change_data` | array of string |  |\n| `results[].dns` | object |  |\n| `results[].dns_check_date` | string | date-time |\n| `results[].dns_last_change_date` | string | date-time |\n| `results[].dns_last_change_data` | array of string |  |\n| `results[].ssl` | object |  |\n| `results[].ssl_check_date` | string | date-time |\n| `results[].ssl_last_change_date` | string | date-time |\n| `results[].ssl_last_change_data` | array of string |  |\n| `results[].http` | object |  |\n| `results[].http_check_date` | string | date-time |\n| `results[].http_last_change_date` | string | date-time |\n| `results[].http_last_change_data` | array of string |  |\n| `results[].webdata` | object |  |\n| `results[].webdata_check_date` | string | date-time |\n| `results[].webdata_last_change_date` | string | date-time |\n| `results[].webdata_last_change_data` | array of string |  |\n| `results[].ipwhois` | object |  |\n| `results[].ipwhois_check_date` | string | date-time |\n| `results[].ipwhois_last_change_date` | string | date-time |\n| `results[].ipwhois_last_change_data` | array of string |  |\n| `results[].ipdns` | object |  |\n| `results[].ipdns_check_date` | string | date-time |\n| `results[].ipdns_last_change_date` | string | date-time |\n| `results[].ipdns_last_change_data` | array of string |  |\n| `results[].subdomain_count` | integer |  |\n| `results[].website_count` | integer |  |\n| `results[].pointed_fqdn_count` | integer |  |\n| `results[].redirected_domain_count` | integer |  |\n| `results[].redirected_asset_count` | integer |  |\n| `results[].average_issue_duration` | integer |  |\n| `results[].average_fix_duration` | integer |  |\n| `results[].is_parked` | boolean |  |\n| `results[].open_port_count` | integer |  |\n| `results[].open_ports` | array of integer |  |\n| `results[].issue_state_stats` | object |  |\n| `results[].issue_category_stats` | array of object |  |\n| `results[].issue_count` | object |  |\n| `results[].technology_count` | object |  |\n| `results[].vulnerability_count` | object |  |\n| `results[].security_score` | number |  |\n| `results[].weight` | integer |  |\n| `results[].user_weight` | integer |  |\n| `results[].system_weight` | integer |  |\n| `results[].domain_snapshot` | object |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · 38 of 740 filters** holds this body with 38 of the 740 filters (the first 10 of each operator group); the full list is above (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Asset Export",
              "id": "3af96a82-b61a-5565-9a67-a9ce4cb03162",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    },
                    {
                      "key": "scope",
                      "value": "",
                      "description": "One of: `basic`, `default`, `extended`.",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 517 fields\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `tags`: Your own labels on the asset, such as a business unit or an environment; each tag is 3 to 100 characters long.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.name.unicode`: The host name without its extension, in Unicode: `acme` for `acme.example`, `www.acme` for `www.acme.example`.\n- `fqdn.name.latinized`: Latin-letter spellings of a name that has non-Latin or accented letters, so a search for `istanbul` also finds names written with `İ`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_sub.unicode`: The second-level part of a two-part extension, such as `co` in `co.uk`; empty for single-part extensions.\n- `website.path`: The URL path of a website asset, such as `/`.\n- `website.scheme`: The URL scheme of a website asset, such as `http`.\n- `website.parent_asset.id`: The ID of the domain or subdomain asset that a website asset belongs to.\n- `website.parent_asset.name`: The name of the domain or subdomain asset that a website asset belongs to.\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.name`: The registrant's name in WHOIS; often a privacy placeholder such as `redacted for privacy`.\n- `whois.registrant.country`: The registrant's country in WHOIS, as a two-letter code in lower case such as `us`.\n- `whois.registrant.state`: The registrant's state or province in WHOIS.\n- `whois.registrant.city`: The registrant's city in WHOIS.\n- `whois.registrant.street`: The registrant's street address in WHOIS.\n- `whois.registrant.postal_code`: The registrant's postal code in WHOIS.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `whois_registrant_email_historical`: Every registrant e-mail address seen for the domain over time, the current one included.\n- `whois_normalized.registrar`: The registrar reduced to a short normalized name, such as `godaddy` or `gandi`, so the same registrar matches across spellings.\n- `whois_normalized.registrant.email`: The registrant e-mail address after WHOIS normalization.\n- `whois_normalized.registrant.email_real`: Another normalized registrant e-mail field, set on fewer domains than `whois_normalized.registrant.email`; in the samples it is set only where `whois_privacy_enabled` is false, with the same address.\n- `whois_normalized.registrant.email_domain_apex`: The registrable domain of the registrant e-mail address: `acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.email_fqdn_apex`: The full host name after the `@` of the registrant e-mail address: `mail.acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.organization`: The registrant organization cleaned up across registrars: lower case, with spaces and punctuation removed, such as `domainsbyproxyllc`.\n- `whois_normalized.registrant.phone`: The registrant phone number reduced to its digits, such as `14805551234`.\n- `whois_last_change_data`: The WHOIS fields that changed in the last change seen, as field paths such as `whois.update_date` or `whois.domain_status`.\n- `dns.a.value`: The asset's current A records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.a.value_previous`: The asset's A records as they were before the last change, in the same text form as `dns.a.value`.\n- `dns.a.rcode`: The DNS response code returned for the asset's A lookup, such as `NOERROR`.\n- `dns.a.rcode_previous`: The DNS response code of the A lookup before it last changed.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.entities`: The handles of the registry contacts and organizations linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, when it is kept.\n- `dns.a.ip_addresses.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the A-record address.\n- `dns.a.ip_addresses.raw`: The raw IP WHOIS response for the A-record address, when it is kept; empty on every sampled asset.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.a.ip_addresses.network.start_address`: The first address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.end_address`: The last address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.handle`: The registry handle of the network that contains the A-record address, such as `NET-192-0-2-0-1`.\n- `dns.a.ip_addresses.network.ip_version`: The IP version of the network that contains the A-record address: `v4` or `v6`.\n- `dns.a.ip_addresses.network.links`: Links to the registry record of the network that contains the A-record address, such as its RDAP and WHOIS URLs.\n- `dns.a.ip_addresses.network.parent_handle`: The handle of the larger network block from which the network of the A-record address was allocated.\n- `dns.a.ip_addresses.network.raw`: The raw RDAP network object for the A-record address, when it is kept.\n- `dns.a.ip_addresses.network.status`: The registry status of the network that contains the A-record address, such as `active`.\n- `dns.a.ip_addresses.network.type`: The registry's allocation type for the network that contains the A-record address, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `dns.a.ip_addresses.network.notices.title`: The title of a notice the registry attached to the network record of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.network.notices.description`: The text of a notice the registry attached to the network record of the A-record address.\n- `dns.a.ip_addresses.network.notices.links`: Links given in a notice on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.title`: The title of a remark on the network record of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.network.remarks.description`: The text of a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.links`: Links given in a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.events.action`: An event in the history of the network record of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.network.events.actor`: Who performed an event on the network record of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the A-record address, such as `abuse`.\n- `dns.a.ip_addresses.objects.contact.email.value`: An e-mail address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.value`: A postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the A-record address, such as `voice` or `work`.\n- `dns.a.ip_addresses.objects.contact.phone.value`: A phone number of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.kind`: What kind of contact is linked to the network of the A-record address: `org`, `group` or `individual`.\n- `dns.a.ip_addresses.objects.contact.name`: The name of a contact or organization linked to the network of the A-record address, such as `Abuse` or a company name.\n- `dns.a.ip_addresses.objects.contact.role`: The role given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.title`: The title given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.entities`: Handles of further entities listed under a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.events.action`: An event in the history of a contact record linked to the network of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.objects.events.actor`: Who performed an event on a contact record linked to the network of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.events_actor`: Events in which a contact linked to the network of the A-record address is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `dns.a.ip_addresses.objects.handle`: The registry handle of a contact or organization linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.links`: Links to the registry record of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.title`: The title of a notice on a contact record linked to the network of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.objects.notices.description`: The text of a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.links`: Links given in a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.raw`: The raw RDAP object of a contact linked to the network of the A-record address, when it is kept.\n- `dns.a.ip_addresses.objects.remarks.title`: The title of a remark on a contact record linked to the network of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.objects.remarks.description`: The text of a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.roles`: The roles of a contact for the network of the A-record address, such as `registrant`, `abuse` or `technical`.\n- `dns.a.ip_addresses.objects.status`: The registry status of a contact linked to the network of the A-record address, such as `validated`.\n- `dns.a.ip_history`: Every IPv4 address seen in the asset's A records over time, the current ones included.\n- `dns.aaaa.value`: The asset's current AAAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.aaaa.value_previous`: The asset's AAAA records as they were before the last change, in the same text form as `dns.aaaa.value`.\n- `dns.aaaa.rcode`: The DNS response code returned for the asset's AAAA lookup, such as `NOERROR`.\n- `dns.aaaa.rcode_previous`: The DNS response code of the AAAA lookup before it last changed.\n- `dns.aaaa.ip_addresses`: The IPv6 addresses in the asset's AAAA records.\n- `dns.caa.value`: The asset's current CAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.caa.value_previous`: The asset's CAA records as they were before the last change, in the same text form as `dns.caa.value`.\n- `dns.caa.rcode`: The DNS response code returned for the asset's CAA lookup, such as `NOERROR`.\n- `dns.caa.rcode_previous`: The DNS response code of the CAA lookup before it last changed.\n- `dns.caa.issue_fqdns`: The certificate authorities allowed to issue certificates for the name, from the CAA `issue` tags, such as `fernhill.example` or `kestrel.example`.\n- `dns.caa.issuewild_fqdns`: The certificate authorities allowed to issue wildcard certificates for the name, from the CAA `issuewild` tags.\n- `dns.caa.iodef_emails`: The e-mail addresses from the CAA `iodef` tags, where certificate authorities report requests that break the CAA policy.\n- `dns.cname.value`: The asset's current CNAME records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.cname.value_previous`: The asset's CNAME records as they were before the last change, in the same text form as `dns.cname.value`.\n- `dns.cname.rcode`: The DNS response code returned for the asset's CNAME lookup, such as `NOERROR`.\n- `dns.cname.rcode_previous`: The DNS response code of the CNAME lookup before it last changed.\n- `dns.cname.canonical_fqdns`: The host names the asset's CNAME records point to (the alias targets).\n- `dns.dnskey.value`: The asset's current DNSKEY records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.dnskey.value_previous`: The asset's DNSKEY records as they were before the last change, in the same text form as `dns.dnskey.value`.\n- `dns.dnskey.rcode`: The DNS response code returned for the asset's DNSKEY lookup, such as `NOERROR`.\n- `dns.dnskey.rcode_previous`: The DNS response code of the DNSKEY lookup before it last changed.\n- `dns.dnskey.records.public_key`: The public key of a DNSKEY record, Base64-encoded and split into space-separated groups as in the zone-file text.\n- `dns.ds.value`: The asset's current DS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ds.value_previous`: The asset's DS records as they were before the last change, in the same text form as `dns.ds.value`.\n- `dns.ds.rcode`: The DNS response code returned for the asset's DS lookup, such as `NOERROR`.\n- `dns.ds.rcode_previous`: The DNS response code of the DS lookup before it last changed.\n- `dns.ds.records.digest`: The digest of a DS record, the hash of the DNSKEY it refers to.\n- `dns.mx.value`: The asset's current MX records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.mx.value_previous`: The asset's MX records as they were before the last change, in the same text form as `dns.mx.value`.\n- `dns.mx.rcode`: The DNS response code returned for the asset's MX lookup, such as `NOERROR`.\n- `dns.mx.rcode_previous`: The DNS response code of the MX lookup before it last changed.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns.mx.domains`: The registrable domains of the asset's mail servers, such as `acme.example`.\n- `dns.ns.value`: The asset's current NS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ns.value_previous`: The asset's NS records as they were before the last change, in the same text form as `dns.ns.value`.\n- `dns.ns.rcode`: The DNS response code returned for the asset's NS lookup, such as `NOERROR`.\n- `dns.ns.rcode_previous`: The DNS response code of the NS lookup before it last changed.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.ns.domains`: The registrable domains of the asset's name servers, such as `acme.example`.\n- `dns.nsec.value`: The asset's current NSEC records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec.value_previous`: The asset's NSEC records as they were before the last change, in the same text form as `dns.nsec.value`.\n- `dns.nsec.rcode`: The DNS response code returned for the asset's NSEC lookup, such as `NOERROR`.\n- `dns.nsec.rcode_previous`: The DNS response code of the NSEC lookup before it last changed.\n- `dns.nsec.records.next_domain`: The next name in the zone, from an NSEC record.\n- `dns.nsec.records.record_types`: The record types that exist at the name, from an NSEC record's type list, such as `A`, `NS` or `SOA`.\n- `dns.nsec3.value`: The asset's current NSEC3 records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec3.value_previous`: The asset's NSEC3 records as they were before the last change, in the same text form as `dns.nsec3.value`.\n- `dns.nsec3.rcode`: The DNS response code returned for the asset's NSEC3 lookup, such as `NOERROR`.\n- `dns.nsec3.rcode_previous`: The DNS response code of the NSEC3 lookup before it last changed.\n- `dns.nsec3.records.next_domain_hashed`: The hashed next name in the zone, from an NSEC3 record.\n- `dns.nsec3.records.record_types`: The record types that exist at the name, from an NSEC3 record's type list, such as `A` or `MX`.\n- `dns.rrsig.value`: The asset's current RRSIG records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.rrsig.value_previous`: The asset's RRSIG records as they were before the last change, in the same text form as `dns.rrsig.value`.\n- `dns.rrsig.rcode`: The DNS response code returned for the asset's RRSIG lookup, such as `NOERROR`.\n- `dns.rrsig.rcode_previous`: The DNS response code of the RRSIG lookup before it last changed.\n- `dns.rrsig.type_covered`: The record type that an RRSIG signature covers, such as `A` or `SOA`.\n- `dns.rrsig.signature`: The signature data of an RRSIG record, Base64-encoded.\n- `dns.soa.value`: The asset's current SOA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.soa.value_previous`: The asset's SOA records as they were before the last change, in the same text form as `dns.soa.value`.\n- `dns.soa.rcode`: The DNS response code returned for the asset's SOA lookup, such as `NOERROR`.\n- `dns.soa.rcode_previous`: The DNS response code of the SOA lookup before it last changed.\n- `dns.soa.mnames`: The MNAME of the SOA record: the primary name server of the zone, such as `ns1.acme.example`.\n- `dns.soa.rnames`: The RNAME of the SOA record, the zone administrator's mailbox in DNS form: `hostmaster.acme.example` stands for the mailbox `hostmaster` at `acme.example`.\n- `dns.soa.rname_emails`: The RNAME of the SOA record written as an e-mail address, such as `user@acme.example`.\n- `dns.srv.value`: The asset's current SRV records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.srv.value_previous`: The asset's SRV records as they were before the last change, in the same text form as `dns.srv.value`.\n- `dns.srv.rcode`: The DNS response code returned for the asset's SRV lookup, such as `NOERROR`.\n- `dns.srv.rcode_previous`: The DNS response code of the SRV lookup before it last changed.\n- `dns.srv.records.service`: The service named in an SRV record (the `_service` part of its name).\n- `dns.srv.records.protocol`: The protocol named in an SRV record (the `_proto` part of its name, such as TCP or UDP).\n- `dns.srv.records.target`: The host name an SRV record points to.\n- `dns.txt.value`: The asset's current TXT records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.txt.value_previous`: The asset's TXT records as they were before the last change, in the same text form as `dns.txt.value`.\n- `dns.txt.rcode`: The DNS response code returned for the asset's TXT lookup, such as `NOERROR`.\n- `dns.txt.rcode_previous`: The DNS response code of the TXT lookup before it last changed.\n- `dns.txt.values`: Each TXT record of the asset as its quoted text, such as `\"v=spf1 include:_spf.acme.example ~all\"`; the quotes are part of the value.\n- `dns.txt.spf_list.value`: The text of an SPF record (a TXT record that starts with `v=spf1`), quoted as in `dns.txt.values`.\n- `dns.txt.spf_list.allowed_domains`: The registrable domains that an SPF record refers to, such as `acme.example` for `include:_spf.acme.example`.\n- `dns.txt.spf_list.allowed_ips`: The IP addresses and ranges that an SPF record authorizes to send mail (its `ip4:` and `ip6:` entries).\n- `dns.txt.verifications.value`: The text of a site-verification TXT record, quoted as in `dns.txt.values`.\n- `dns.txt.verifications.domain`: The domain of the service a verification record is for, such as `acme.example`, `fernhill.example` or `kestrel.example`.\n- `dns.txt.verifications.name`: The name of a verification record, such as `site-verification` or `domain-verification`.\n- `dns_last_change_data`: The DNS fields that changed in the last change seen, as field paths such as `dns.soa.mnames`.\n- `ssl.target`: The host name that the asset's TLS certificate was collected from, normally the asset itself.\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.md5`: The MD5 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha256`: The SHA-256 fingerprint of the asset's TLS certificate, as lower-case hex; one fingerprint identifies one certificate.\n- `ssl.issuer.common_name`: The common name (CN) of the certificate authority that issued the asset's TLS certificate, such as `WE1` or `YE2`.\n- `ssl.issuer.country`: The country (C) of the certificate authority that issued the asset's TLS certificate, as a two-letter code such as `US`.\n- `ssl.issuer.state`: The state or province (ST) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.locality`: The locality or city (L) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.organization`: The organization (O) of the certificate authority that issued the asset's TLS certificate, such as `Let's Encrypt` or `Google Trust Services`.\n- `ssl.issuer.organizational_unit`: The organizational unit (OU) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer_dn`: The full distinguished name of the issuer of the asset's TLS certificate, as one string such as `CN=WE1,O=Google Trust Services,C=US`.\n- `ssl.subject.common_name`: The common name (CN) of the subject (holder) of the asset's TLS certificate, usually a host name such as `acme.example`.\n- `ssl.subject.country`: The country (C) of the subject (holder) of the asset's TLS certificate, as a two-letter code.\n- `ssl.subject.state`: The state or province (ST) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.locality`: The locality or city (L) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organizational_unit`: The organizational unit (OU) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject_dn`: The full distinguished name of the subject of the asset's TLS certificate, such as `CN=acme.example`; one that starts with `CN=*.` belongs to a wildcard certificate.\n- `ssl.signature.value`: The signature of the asset's TLS certificate, Base64-encoded.\n- `ssl.signature.invalid_reason`: Why certificate validation failed, such as a host name mismatch or `unable to get issuer certificate`.\n- `ssl.signature.algorithm.name`: The hash algorithm of the signature on the asset's TLS certificate, such as `sha256` or `sha384`.\n- `ssl.signature.algorithm.oid`: The object identifier (OID) of the signature algorithm, such as `1.2.840.113549.1.1.11` (SHA-256 with RSA) or `1.2.840.10045.4.3.2` (ECDSA with SHA-256).\n- `ssl.extensions.authority_key_id`: The Authority Key Identifier extension, which identifies the issuer's key, Base64-encoded.\n- `ssl.extensions.certificate_policies`: The policy OIDs in the Certificate Policies extension, such as `2.23.140.1.2.1` (domain validated).\n- `ssl.extensions.signed_certificate_timestamps.log_id`: The ID of the Certificate Transparency log that issued a signed certificate timestamp (SCT) for the certificate, Base64-encoded.\n- `ssl.extensions.signed_certificate_timestamps.signature`: The log's signature on a signed certificate timestamp, Base64-encoded.\n- `ssl.extensions.subject_alt_name.dns_names`: The host names in the certificate's Subject Alternative Name extension, including wildcard names such as `*.acme.example`.\n- `ssl.extensions.subject_key_id`: The Subject Key Identifier extension, which identifies the certificate's own key, Base64-encoded.\n- `ssl.subject_key_info.fingerprint.hash_algorithm`: The hash algorithm used for `ssl.subject_key_info.fingerprint.value`, such as `sha256` or `sha384`.\n- `ssl.subject_key_info.fingerprint.value`: A hex fingerprint recorded under the certificate's subject key information, made with the hash in `hash_algorithm`. In the samples it equals `ssl.fingerprint.sha256` when that hash is SHA-256.\n- `ssl.subject_key_info.key_algorithm.name`: The algorithm of the certificate's public key, such as `RSA` or `ECDSA`.\n- `ssl.version.name`: The X.509 version of the certificate, such as `v3`.\n- `ssl.version.value`: The X.509 version as encoded in the certificate, counted from zero: `2` means `v3`.\n- `ssl.tbs_fingerprint`: A SHA-256 fingerprint (hex) of the certificate's to-be-signed part, the certificate content without its signature.\n- `ssl.certificate`: The whole certificate, Base64-encoded (a PEM body without the header and footer lines).\n- `ssl.fqdn_list`: The host names the certificate covers, with the `*.` of wildcard names removed and duplicates merged, so `*.acme.example` and `acme.example` both give `acme.example`.\n- `ssl_last_change_data`: The certificate fields that changed in the last change seen, as field paths such as `ssl.validity.end_date`.\n- `http.requested_url`: The URL the HTTP check started from, such as `http://acme.example`.\n- `http.requested_domain`: The registrable domain of the URL the HTTP check started from.\n- `http.requested_fqdn`: The host name of the URL the HTTP check started from.\n- `http.final_url`: The URL the HTTP check ended on after following all redirects.\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.redirection_history.url`: A URL in the redirect chain of the HTTP check, listed in the order visited.\n- `http.headers.accept`: The `Accept` header, when it was returned in the HTTP check. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the HTTP check. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `http.headers.accept_language`: The `Accept-Language` header, when it was returned in the HTTP check. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the HTTP check; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the HTTP check; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the HTTP check; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the HTTP check; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the HTTP check; it lists the response headers that scripts from other origins may read (CORS).\n- `http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the HTTP check; it says how many seconds browsers may cache a CORS preflight result.\n- `http.headers.alt_svc`: The `Alt-Svc` header returned in the HTTP check; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `http.headers.authorization`: The `Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `http.headers.cache_control`: The `Cache-Control` header returned in the HTTP check; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the HTTP check; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `http.headers.content_disposition`: The `Content-Disposition` header returned in the HTTP check; it says whether the content is shown in the browser or downloaded as a file.\n- `http.headers.content_encoding`: The `Content-Encoding` header returned in the HTTP check; it names the compression applied to the response body, for example `gzip` or `br`.\n- `http.headers.content_language`: The `Content-Language` header returned in the HTTP check; it gives the language of the content, for example `en` or `tr`.\n- `http.headers.content_length`: The `Content-Length` header returned in the HTTP check; it gives the size of the response body in bytes.\n- `http.headers.content_range`: The `Content-Range` header returned in the HTTP check; it says which part of the full body a partial response holds.\n- `http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the HTTP check; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `http.headers.content_type`: The `Content-Type` header returned in the HTTP check; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `http.headers.cookie`: The `Cookie` header, when it was returned in the HTTP check. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the HTTP check; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the HTTP check; it controls whether the page shares its browsing context with cross-origin windows.\n- `http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the HTTP check; it controls which sites may load the resource.\n- `http.headers.date`: The `Date` header returned in the HTTP check; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `http.headers.early_data`: The `Early-Data` header, when it was returned in the HTTP check. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `http.headers.expect_ct`: The `Expect-CT` header returned in the HTTP check; it is a deprecated header about Certificate Transparency enforcement.\n- `http.headers.expires`: The `Expires` header returned in the HTTP check; it gives the date after which the response counts as stale, in HTTP date format.\n- `http.headers.feature_policy`: The `Feature-Policy` header returned in the HTTP check; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `http.headers.host`: The `Host` header, when it was returned in the HTTP check. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the HTTP check. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the HTTP check. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `http.headers.last_modified`: The `Last-Modified` header returned in the HTTP check; it gives the time the server says the resource last changed, in HTTP date format.\n- `http.headers.origin_isolation`: The `Origin-Isolation` header returned in the HTTP check; it is an experimental header that asks browsers to isolate the site's origin.\n- `http.headers.others.name`: The name of a header returned in the HTTP check that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `http.headers.others.value`: The value of a header listed in `headers.others` for the HTTP check.\n- `http.headers.permission_policy`: The `Permission-Policy` header returned in the HTTP check; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `http.headers.permissions_policy`: The `Permissions-Policy` header returned in the HTTP check; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `http.headers.pragma`: The `Pragma` header returned in the HTTP check; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the HTTP check; it tells a client how to authenticate to a proxy.\n- `http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the HTTP check; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `http.headers.range`: The `Range` header, when it was returned in the HTTP check. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `http.headers.referer`: The `Referer` header, when it was returned in the HTTP check. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `http.headers.referrer_policy`: The `Referrer-Policy` header returned in the HTTP check; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the HTTP check. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `http.headers.server`: The `Server` header returned in the HTTP check; it names the server software the site reports, for example `nginx` or `Apache`.\n- `http.headers.set_cookie`: The `Set-Cookie` header returned in the HTTP check; it sets cookies, with their attributes.\n- `http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the HTTP check; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `http.headers.te`: The `TE` header, when it was returned in the HTTP check. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the HTTP check; it says how the body is transferred, for example `chunked`.\n- `http.headers.upgrade`: The `Upgrade` header returned in the HTTP check; it offers or asks for a switch to another protocol.\n- `http.headers.user_agent`: The `User-Agent` header, when it was returned in the HTTP check. It is normally a request header (the client software), so it is rarely set.\n- `http.headers.vary`: The `Vary` header returned in the HTTP check; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the HTTP check; it tells a client how to authenticate, usually with a `401` response.\n- `http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the HTTP check; it stops browsers from guessing the content type when set to `nosniff`.\n- `http.headers.x_download_options`: The `X-Download-Options` header returned in the HTTP check; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `http.headers.x_frame_options`: The `X-Frame-Options` header returned in the HTTP check; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the HTTP check; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `http.headers.x_powered_by`: The `X-Powered-By` header returned in the HTTP check; it names the technology the server reports running on, for example `Express`.\n- `http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the HTTP check; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `http.cookies.name`: The name of a cookie set in the HTTP check.\n- `http.cookies.value`: The value of a cookie set in the HTTP check.\n- `http.html.source_code_hash`: A SHA-256 hash of the page source returned in the HTTP check; the same hash means the same source.\n- `http_last_change_data`: The HTTP check fields that changed in the last change seen, as field paths such as `http.html.source_code_hash`.\n- `webdata.requested_url`: The URL the web data scan started from, such as `http://acme.example`.\n- `webdata.requested_domain`: The registrable domain of the URL the web data scan started from.\n- `webdata.requested_fqdn`: The host name of the URL the web data scan started from.\n- `webdata.html.internal_links_fqdns`: The host names of links on the scanned page that stay within the site's own domain, such as other subdomains.\n- `webdata.html.external_links_domains`: The registrable domains of links on the scanned page that point to other domains, such as `kestrel.example`.\n- `webdata.html.external_links_fqdns`: The host names of links on the scanned page that point to other domains, such as `www.kestrel.example`.\n- `webdata.html.external_links`: The full URLs of links on the scanned page that point to other domains.\n- `webdata.html.script_links`: The URLs of the scripts the scanned page loads.\n- `webdata.html.iframe_links`: The URLs of the frames (iframes) embedded in the scanned page.\n- `webdata.html.trackers.name`: The name of an analytics or advertising tracker found on the scanned page, such as `google_adsense` or `google_tag_manager`.\n- `webdata.html.trackers.values`: The IDs found for a tracker, such as a Google Analytics ID that starts with `G-` or `UA-`.\n- `webdata.html.emails`: The e-mail addresses found on the scanned page.\n- `webdata.html.emails_internal`: The e-mail addresses found on the scanned page that belong to the site's own domain.\n- `webdata.html.source_code_hash`: A SHA-256 hash of the page source in the web data scan; the same hash means the same source.\n- `webdata.html.content_hash`: A SHA-256 hash of the page content in the web data scan, kept apart from `source_code_hash`, the hash of the raw source.\n- `webdata.html.content_top_keywords`: The most frequent words in the text of the scanned page.\n- `webdata.html.favicon_links`: The URLs of the icons the scanned page declares, such as its favicon and touch icons.\n- `webdata.html.html_meta.name`: The site or application name declared in the scanned page's metadata.\n- `webdata.html.html_meta.description`: The meta description of the scanned page.\n- `webdata.html.html_meta.language`: The language the scanned page declares, such as `en`, `tr` or `en-US`.\n- `webdata.html.html_meta.language_alternatives`: The languages of the alternative versions the scanned page links to, such as `en` or `ar`.\n- `webdata.html.html_meta.keywords`: The keywords listed in the keywords meta tag of the scanned page.\n- `webdata.html.html_meta.encoding`: The character encoding the scanned page declares, such as `utf-8`.\n- `webdata.html.html_meta.canonical_url`: The canonical URL the scanned page declares.\n- `webdata.html.html_meta.title`: The title of the scanned page.\n- `webdata.favicon.url`: The URL of a site icon (favicon) recorded by the web data scan.\n- `webdata.favicon.hash`: A SHA-256 hash of a site icon; the same hash means the same icon.\n- `webdata.http.final_url`: The URL the web data scan ended on after following all redirects.\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.redirection_history.url`: A URL in the redirect chain of the web data scan, listed in the order visited.\n- `webdata.http.redirection_history.method`: How a step of the web data scan's redirect chain was made; `http-header` (a redirect sent in the HTTP response) is the value in the samples.\n- `webdata.http.headers.accept`: The `Accept` header, when it was returned in the web data scan. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the web data scan. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_language`: The `Accept-Language` header, when it was returned in the web data scan. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `webdata.http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the web data scan; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `webdata.http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the web data scan; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `webdata.http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the web data scan; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `webdata.http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the web data scan; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `webdata.http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the web data scan; it lists the response headers that scripts from other origins may read (CORS).\n- `webdata.http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the web data scan; it says how many seconds browsers may cache a CORS preflight result.\n- `webdata.http.headers.alt_svc`: The `Alt-Svc` header returned in the web data scan; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `webdata.http.headers.authorization`: The `Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `webdata.http.headers.cache_control`: The `Cache-Control` header returned in the web data scan; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `webdata.http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the web data scan; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `webdata.http.headers.content_disposition`: The `Content-Disposition` header returned in the web data scan; it says whether the content is shown in the browser or downloaded as a file.\n- `webdata.http.headers.content_encoding`: The `Content-Encoding` header returned in the web data scan; it names the compression applied to the response body, for example `gzip` or `br`.\n- `webdata.http.headers.content_language`: The `Content-Language` header returned in the web data scan; it gives the language of the content, for example `en` or `tr`.\n- `webdata.http.headers.content_length`: The `Content-Length` header returned in the web data scan; it gives the size of the response body in bytes.\n- `webdata.http.headers.content_range`: The `Content-Range` header returned in the web data scan; it says which part of the full body a partial response holds.\n- `webdata.http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the web data scan; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `webdata.http.headers.content_type`: The `Content-Type` header returned in the web data scan; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `webdata.http.headers.cookie`: The `Cookie` header, when it was returned in the web data scan. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `webdata.http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the web data scan; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `webdata.http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the web data scan; it controls whether the page shares its browsing context with cross-origin windows.\n- `webdata.http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the web data scan; it controls which sites may load the resource.\n- `webdata.http.headers.date`: The `Date` header returned in the web data scan; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `webdata.http.headers.early_data`: The `Early-Data` header, when it was returned in the web data scan. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `webdata.http.headers.expect_ct`: The `Expect-CT` header returned in the web data scan; it is a deprecated header about Certificate Transparency enforcement.\n- `webdata.http.headers.expires`: The `Expires` header returned in the web data scan; it gives the date after which the response counts as stale, in HTTP date format.\n- `webdata.http.headers.feature_policy`: The `Feature-Policy` header returned in the web data scan; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `webdata.http.headers.host`: The `Host` header, when it was returned in the web data scan. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `webdata.http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the web data scan. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `webdata.http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the web data scan. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `webdata.http.headers.last_modified`: The `Last-Modified` header returned in the web data scan; it gives the time the server says the resource last changed, in HTTP date format.\n- `webdata.http.headers.origin_isolation`: The `Origin-Isolation` header returned in the web data scan; it is an experimental header that asks browsers to isolate the site's origin.\n- `webdata.http.headers.others.name`: The name of a header returned in the web data scan that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `webdata.http.headers.others.value`: The value of a header listed in `headers.others` for the web data scan.\n- `webdata.http.headers.permission_policy`: The `Permission-Policy` header returned in the web data scan; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `webdata.http.headers.permissions_policy`: The `Permissions-Policy` header returned in the web data scan; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `webdata.http.headers.pragma`: The `Pragma` header returned in the web data scan; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `webdata.http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the web data scan; it tells a client how to authenticate to a proxy.\n- `webdata.http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `webdata.http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the web data scan; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `webdata.http.headers.range`: The `Range` header, when it was returned in the web data scan. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `webdata.http.headers.referer`: The `Referer` header, when it was returned in the web data scan. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `webdata.http.headers.referrer_policy`: The `Referrer-Policy` header returned in the web data scan; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `webdata.http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `webdata.http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the web data scan. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `webdata.http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `webdata.http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the web data scan. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `webdata.http.headers.server`: The `Server` header returned in the web data scan; it names the server software the site reports, for example `nginx` or `Apache`.\n- `webdata.http.headers.set_cookie`: The `Set-Cookie` header returned in the web data scan; it sets cookies, with their attributes.\n- `webdata.http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the web data scan; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `webdata.http.headers.te`: The `TE` header, when it was returned in the web data scan. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `webdata.http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the web data scan; it says how the body is transferred, for example `chunked`.\n- `webdata.http.headers.upgrade`: The `Upgrade` header returned in the web data scan; it offers or asks for a switch to another protocol.\n- `webdata.http.headers.user_agent`: The `User-Agent` header, when it was returned in the web data scan. It is normally a request header (the client software), so it is rarely set.\n- `webdata.http.headers.vary`: The `Vary` header returned in the web data scan; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `webdata.http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the web data scan; it tells a client how to authenticate, usually with a `401` response.\n- `webdata.http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the web data scan; it stops browsers from guessing the content type when set to `nosniff`.\n- `webdata.http.headers.x_download_options`: The `X-Download-Options` header returned in the web data scan; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `webdata.http.headers.x_frame_options`: The `X-Frame-Options` header returned in the web data scan; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `webdata.http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the web data scan; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `webdata.http.headers.x_powered_by`: The `X-Powered-By` header returned in the web data scan; it names the technology the server reports running on, for example `Express`.\n- `webdata.http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the web data scan; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `webdata.http.cookies.name`: The name of a cookie set in the web data scan.\n- `webdata.http.cookies.value`: The value of a cookie set in the web data scan.\n- `webdata.http.cookies.domain`: The domain a cookie set in the web data scan applies to, such as `.acme.example`.\n- `webdata.http.cookies.path`: The path a cookie set in the web data scan applies to, such as `/`.\n- `webdata.http.cookies.same_party`: The SameParty attribute of a cookie set in the web data scan; in the samples it always holds the same value as `same_site`, such as `Lax` or `None`.\n- `webdata.http.cookies.priority`: The Priority attribute of a cookie set in the web data scan (`Low`, `Medium` or `High` in Chromium-based browsers).\n- `webdata.http.cookies.same_site`: The SameSite attribute of a cookie set in the web data scan, such as `Lax`, `Strict` or `None`.\n- `webdata.technology.stacks.slug`: A short identifier of a technology detected on the site, such as `iis` or `windows-server`.\n- `webdata.technology.stacks.name`: The name of a technology detected on the site, such as `IIS` or `Microsoft ASP.NET`.\n- `webdata.technology.stacks.icon`: The file name of a detected technology's icon, such as `acme.png`.\n- `webdata.technology.stacks.website`: The website of a detected technology's vendor or project.\n- `webdata.technology.stacks.cpe`: The CPE identifier of a detected technology, such as `cpe:/a:acme:acme-portal`, used to match it to known vulnerabilities.\n- `webdata.technology.stacks.version`: The detected version of a technology, such as `1.0`.\n- `webdata.technology.stacks.categories`: The categories of a detected technology, such as `Web servers` or `Operating systems`.\n- `webdata.technology.stacks.description`: A short description of a detected technology.\n- `webdata_last_change_data`: The web data fields that changed in the last change seen, as field paths under `webdata`.\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.entities`: The handles of the registry contacts and organizations linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, when it is kept.\n- `ipwhois.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the IP address asset.\n- `ipwhois.raw`: The raw IP WHOIS response for the IP address asset, when it is kept; empty on every sampled asset.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `ipwhois.network.start_address`: The first address of the registered network block that contains the IP address asset.\n- `ipwhois.network.end_address`: The last address of the registered network block that contains the IP address asset.\n- `ipwhois.network.handle`: The registry handle of the network that contains the IP address asset, such as `NET-192-0-2-0-1`.\n- `ipwhois.network.ip_version`: The IP version of the network that contains the IP address asset: `v4` or `v6`.\n- `ipwhois.network.links`: Links to the registry record of the network that contains the IP address asset, such as its RDAP and WHOIS URLs.\n- `ipwhois.network.parent_handle`: The handle of the larger network block from which the network of the IP address asset was allocated.\n- `ipwhois.network.raw`: The raw RDAP network object for the IP address asset, when it is kept.\n- `ipwhois.network.status`: The registry status of the network that contains the IP address asset, such as `active`.\n- `ipwhois.network.type`: The registry's allocation type for the network that contains the IP address asset, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `ipwhois.network.notices.title`: The title of a notice the registry attached to the network record of the IP address asset, such as `Terms of Service`.\n- `ipwhois.network.notices.description`: The text of a notice the registry attached to the network record of the IP address asset.\n- `ipwhois.network.notices.links`: Links given in a notice on the network record of the IP address asset.\n- `ipwhois.network.remarks.title`: The title of a remark on the network record of the IP address asset, such as `Registration Comments`.\n- `ipwhois.network.remarks.description`: The text of a remark on the network record of the IP address asset.\n- `ipwhois.network.remarks.links`: Links given in a remark on the network record of the IP address asset.\n- `ipwhois.network.events.action`: An event in the history of the network record of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.network.events.actor`: Who performed an event on the network record of the IP address asset, when the registry names one.\n- `ipwhois.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the IP address asset, such as `abuse`.\n- `ipwhois.objects.contact.email.value`: An e-mail address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.value`: A postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the IP address asset, such as `voice` or `work`.\n- `ipwhois.objects.contact.phone.value`: A phone number of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.kind`: What kind of contact is linked to the network of the IP address asset: `org`, `group` or `individual`.\n- `ipwhois.objects.contact.name`: The name of a contact or organization linked to the network of the IP address asset, such as `Abuse` or a company name.\n- `ipwhois.objects.contact.role`: The role given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.contact.title`: The title given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.entities`: Handles of further entities listed under a contact linked to the network of the IP address asset.\n- `ipwhois.objects.events.action`: An event in the history of a contact record linked to the network of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.objects.events.actor`: Who performed an event on a contact record linked to the network of the IP address asset, when the registry names one.\n- `ipwhois.objects.events_actor`: Events in which a contact linked to the network of the IP address asset is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `ipwhois.objects.handle`: The registry handle of a contact or organization linked to the network of the IP address asset.\n- `ipwhois.objects.links`: Links to the registry record of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.notices.title`: The title of a notice on a contact record linked to the network of the IP address asset, such as `Terms of Service`.\n- `ipwhois.objects.notices.description`: The text of a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.notices.links`: Links given in a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.raw`: The raw RDAP object of a contact linked to the network of the IP address asset, when it is kept.\n- `ipwhois.objects.remarks.title`: The title of a remark on a contact record linked to the network of the IP address asset, such as `Registration Comments`.\n- `ipwhois.objects.remarks.description`: The text of a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.roles`: The roles of a contact for the network of the IP address asset, such as `registrant`, `abuse` or `technical`.\n- `ipwhois.objects.status`: The registry status of a contact linked to the network of the IP address asset, such as `validated`.\n- `ipwhois_last_change_data`: The IP WHOIS fields that changed in the last change seen, as field paths under `ipwhois`.\n- `ipdns.ptr_records`: The PTR (reverse DNS) host names of an IP address asset.\n- `ipdns_last_change_data`: The reverse DNS fields that changed in the last change seen, as field paths under `ipdns`.\n- `issue_category_stats.name`: The name of an issue category in the per-category issue counts of the asset, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`.\n- `technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the asset, such as `Web servers` or `Analytics`.\n- `domain_snapshot.issue_category_stats.name`: The name of an issue category in the per-category issue counts of the domain and its subdomains together, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the domain and its subdomains together, such as `Web servers` or `Analytics`. Set on domain assets.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 179 fields\n\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.name.length`: The number of characters in the name without the extension: `4` for `acme.example`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois_create_date_historical`: Every creation date seen for the domain over time, so a domain that was deleted and registered again keeps its earlier dates too (UTC date-times).\n- `whois_check_date`: When the WHOIS record of the asset was last checked (UTC date-time).\n- `whois_last_change_date`: When a change in the WHOIS record of the asset was last seen (UTC date-time).\n- `dns.a.value_last_change_date`: When the A record text (`dns.a.value`) last changed (UTC date-time).\n- `dns.a.rcode_last_change_date`: When the response code of the A lookup (`dns.a.rcode`) last changed (UTC date-time).\n- `dns.a.last_change_date`: When the asset's A records last changed, in their text or their response code (UTC date-time).\n- `dns.a.ip_addresses.asn_date`: The registry allocation date that the ASN lookup reports for the A-record address, as a date at midnight UTC.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was created (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was last updated (UTC date-time).\n- `dns.a.ip_addresses.network.events.timestamp`: When an event on the network record of the A-record address happened (UTC date-time).\n- `dns.a.ip_addresses.objects.events.timestamp`: When an event on a contact record linked to the network of the A-record address happened (UTC date-time).\n- `dns.aaaa.value_last_change_date`: When the AAAA record text (`dns.aaaa.value`) last changed (UTC date-time).\n- `dns.aaaa.rcode_last_change_date`: When the response code of the AAAA lookup (`dns.aaaa.rcode`) last changed (UTC date-time).\n- `dns.aaaa.last_change_date`: When the asset's AAAA records last changed, in their text or their response code (UTC date-time).\n- `dns.caa.value_last_change_date`: When the CAA record text (`dns.caa.value`) last changed (UTC date-time).\n- `dns.caa.rcode_last_change_date`: When the response code of the CAA lookup (`dns.caa.rcode`) last changed (UTC date-time).\n- `dns.caa.last_change_date`: When the asset's CAA records last changed, in their text or their response code (UTC date-time).\n- `dns.cname.value_last_change_date`: When the CNAME record text (`dns.cname.value`) last changed (UTC date-time).\n- `dns.cname.rcode_last_change_date`: When the response code of the CNAME lookup (`dns.cname.rcode`) last changed (UTC date-time).\n- `dns.cname.last_change_date`: When the asset's CNAME records last changed, in their text or their response code (UTC date-time).\n- `dns.dnskey.value_last_change_date`: When the DNSKEY record text (`dns.dnskey.value`) last changed (UTC date-time).\n- `dns.dnskey.rcode_last_change_date`: When the response code of the DNSKEY lookup (`dns.dnskey.rcode`) last changed (UTC date-time).\n- `dns.dnskey.last_change_date`: When the asset's DNSKEY records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.value_last_change_date`: When the DS record text (`dns.ds.value`) last changed (UTC date-time).\n- `dns.ds.rcode_last_change_date`: When the response code of the DS lookup (`dns.ds.rcode`) last changed (UTC date-time).\n- `dns.ds.last_change_date`: When the asset's DS records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.records.key_tag`: The key tag (a number) of the DNSKEY that a DS record refers to.\n- `dns.mx.value_last_change_date`: When the MX record text (`dns.mx.value`) last changed (UTC date-time).\n- `dns.mx.rcode_last_change_date`: When the response code of the MX lookup (`dns.mx.rcode`) last changed (UTC date-time).\n- `dns.mx.last_change_date`: When the asset's MX records last changed, in their text or their response code (UTC date-time).\n- `dns.ns.value_last_change_date`: When the NS record text (`dns.ns.value`) last changed (UTC date-time).\n- `dns.ns.rcode_last_change_date`: When the response code of the NS lookup (`dns.ns.rcode`) last changed (UTC date-time).\n- `dns.ns.last_change_date`: When the asset's NS records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec.value_last_change_date`: When the NSEC record text (`dns.nsec.value`) last changed (UTC date-time).\n- `dns.nsec.rcode_last_change_date`: When the response code of the NSEC lookup (`dns.nsec.rcode`) last changed (UTC date-time).\n- `dns.nsec.last_change_date`: When the asset's NSEC records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec3.value_last_change_date`: When the NSEC3 record text (`dns.nsec3.value`) last changed (UTC date-time).\n- `dns.nsec3.rcode_last_change_date`: When the response code of the NSEC3 lookup (`dns.nsec3.rcode`) last changed (UTC date-time).\n- `dns.nsec3.last_change_date`: When the asset's NSEC3 records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.value_last_change_date`: When the RRSIG record text (`dns.rrsig.value`) last changed (UTC date-time).\n- `dns.rrsig.rcode_last_change_date`: When the response code of the RRSIG lookup (`dns.rrsig.rcode`) last changed (UTC date-time).\n- `dns.rrsig.last_change_date`: When the asset's RRSIG records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.signature_inception`: When an RRSIG signature becomes valid (UTC date-time).\n- `dns.rrsig.signature_expiration`: When an RRSIG signature expires (UTC date-time).\n- `dns.soa.value_last_change_date`: When the SOA record text (`dns.soa.value`) last changed (UTC date-time).\n- `dns.soa.rcode_last_change_date`: When the response code of the SOA lookup (`dns.soa.rcode`) last changed (UTC date-time).\n- `dns.soa.last_change_date`: When the asset's SOA records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.value_last_change_date`: When the SRV record text (`dns.srv.value`) last changed (UTC date-time).\n- `dns.srv.rcode_last_change_date`: When the response code of the SRV lookup (`dns.srv.rcode`) last changed (UTC date-time).\n- `dns.srv.last_change_date`: When the asset's SRV records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.records.port`: The port an SRV record points to.\n- `dns.txt.value_last_change_date`: When the TXT record text (`dns.txt.value`) last changed (UTC date-time).\n- `dns.txt.rcode_last_change_date`: When the response code of the TXT lookup (`dns.txt.rcode`) last changed (UTC date-time).\n- `dns.txt.last_change_date`: When the asset's TXT records last changed, in their text or their response code (UTC date-time).\n- `dns_check_date`: When the DNS records of the asset were last checked (UTC date-time).\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.port`: The port that the asset's TLS certificate was collected on, such as `443`.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl.validity.length`: The validity period of the certificate in seconds: 7,776,000 seconds are 90 days.\n- `ssl.extensions.signed_certificate_timestamps.timestamp`: When a Certificate Transparency log recorded the certificate, from a signed certificate timestamp (UTC date-time).\n- `ssl.extensions.signed_certificate_timestamps.version`: The version of a signed certificate timestamp; `0` stands for version 1.\n- `ssl_check_date`: When the TLS certificate of the asset was last checked (UTC date-time).\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the HTTP check, such as `301` or `200`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_check_date`: When the HTTP check of the asset last ran (UTC date-time).\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the web data scan, such as `301` or `200`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata.http.cookies.size`: The size of a cookie set in the web data scan, in bytes (name plus value).\n- `webdata.http.cookies.expires`: When a cookie set in the web data scan expires (UTC date-time); session cookies show `1969-12-31T23:59:59Z`.\n- `webdata.technology.stacks.confidence`: How certain the detection of a technology is, from 0 to 100; every sampled detection has `100`.\n- `webdata.technology.stacks.clean_version`: The major version of a detected technology as a whole number, such as `1` for version `1.0`.\n- `webdata_check_date`: When the web data scan of the asset, which collects the page content, headers and technologies, last ran (UTC date-time).\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn_date`: The registry allocation date that the ASN lookup reports for the IP address asset, as a date at midnight UTC.\n- `ipwhois.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was created (UTC date-time).\n- `ipwhois.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was last updated (UTC date-time).\n- `ipwhois.network.events.timestamp`: When an event on the network record of the IP address asset happened (UTC date-time).\n- `ipwhois.objects.events.timestamp`: When an event on a contact record linked to the network of the IP address asset happened (UTC date-time).\n- `ipwhois_check_date`: When the IP WHOIS record of an IP address asset was last checked (UTC date-time).\n- `ipwhois_last_change_date`: When a change in the IP WHOIS record of an IP address asset was last seen (UTC date-time).\n- `ipdns_check_date`: When the reverse DNS (PTR) records of an IP address asset were last checked (UTC date-time).\n- `ipdns_last_change_date`: When a change in the reverse DNS (PTR) records of an IP address asset was last seen (UTC date-time).\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `open_port_count`: The number of open ports found on the asset.\n- `open_ports`: The open port numbers found on the asset, such as `80`, `443` or `8080`.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_category_stats.count`: The number of active issues in that category on the asset.\n- `issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the asset.\n- `issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the asset.\n- `issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the asset.\n- `issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the asset.\n- `issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the asset.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `issue_count.active_by_severity.low`: The number of active issues of low severity on the asset.\n- `issue_count.active_by_severity.information`: The number of active issues of information severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `technology_count.by_category.count`: The number of technologies in that category on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity on the asset.\n- `vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity on the asset.\n- `vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity on the asset.\n- `vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) on the asset whose severity is `none`.\n- `vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) on the asset whose severity is `unknown`.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.count`: The number of active issues in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.count`: The number of distinct technologies in that category across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n**`eq`, `exists`** — 36 fields\n\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `fqdn.is_idn`: True when the host name is an internationalized domain name (IDN) with non-ASCII characters.\n- `fqdn.name.contains_confusable`: True when the name contains confusable characters that look like other letters, such as Cyrillic `а` for Latin `a`, a common trick in look-alike domains.\n- `fqdn.name.contains_hyphen`: True when the name (without the extension) contains a hyphen.\n- `fqdn.name.contains_letter`: True when the name (without the extension) contains a letter.\n- `fqdn.name.contains_number`: True when the name (without the extension) contains a digit.\n- `fqdn.domain.is_idn`: True when the registrable domain is an internationalized domain name (IDN) with non-ASCII characters.\n- `whois_privacy_enabled`: True when the platform flagged WHOIS privacy protection on the domain's registrant details; set on domain assets.\n- `ssl.signature.is_valid`: True when the asset's TLS certificate passed validation for the host; when false, `ssl.signature.invalid_reason` says why.\n- `ssl.signature.is_valid_chain`: A flag for whether the certificate chain of the asset's TLS certificate is valid. It was true on every sampled certificate, even one whose validation failed with `unable to get issuer certificate`.\n- `ssl.signature.is_self_signed`: True when the asset's TLS certificate is self-signed, that is signed by its own key rather than by a certificate authority.\n- `ssl.extensions.basic_constraints.is_ca`: True when the certificate is a certificate authority (CA) certificate, from its Basic Constraints extension.\n- `ssl.extensions.extended_key_usage.client_auth`: True when the Extended Key Usage extension allows TLS client authentication.\n- `ssl.extensions.extended_key_usage.server_auth`: True when the Extended Key Usage extension allows TLS server authentication, as website certificates need.\n- `ssl.extensions.key_usage.content_commitment`: True when the Key Usage extension allows the certificate's key to be used for content commitment (non-repudiation).\n- `ssl.extensions.key_usage.crl_sign`: True when the Key Usage extension allows the certificate's key to be used for signing certificate revocation lists (CRL sign).\n- `ssl.extensions.key_usage.data_encipherment`: True when the Key Usage extension allows the certificate's key to be used for data encipherment.\n- `ssl.extensions.key_usage.digital_signature`: True when the Key Usage extension allows the certificate's key to be used for digital signatures.\n- `ssl.extensions.key_usage.key_agreement`: True when the Key Usage extension allows the certificate's key to be used for key agreement.\n- `ssl.extensions.key_usage.key_cert_sign`: True when the Key Usage extension allows the certificate's key to be used for signing other certificates (certificate sign).\n- `ssl.extensions.key_usage.key_encipherment`: True when the Key Usage extension allows the certificate's key to be used for key encipherment.\n- `ssl.has_expired`: True when the asset's TLS certificate is past its end date.\n- `http.external_domain_redirection`: True when the HTTP check ended on a different registrable domain than it started on.\n- `http.external_fqdn_redirection`: True when the HTTP check ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.html.inspect_disabled`: A flag of the web data scan that marks pages whose inspection was disabled; it was `false` on every sampled asset.\n- `webdata.html.html_meta.no_index_status`: True when the scanned page asks search engines not to index it (a `noindex` robots directive).\n- `webdata.http.external_domain_redirection`: True when the web data scan ended on a different registrable domain than it started on.\n- `webdata.http.external_fqdn_redirection`: True when the web data scan ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.http.cookies.secure`: True when a cookie set in the web data scan is sent over HTTPS only (Secure attribute).\n- `webdata.http.cookies.http_only`: True when scripts on the page cannot read a cookie set in the web data scan (HttpOnly attribute).\n- `webdata.http.cookies.session`: True when a cookie set in the web data scan is a session cookie, deleted when the browser closes.\n- `is_parked`: True when the asset is parked; Inventory marks it with a P badge whose tooltip shows where it redirects.\n\n**`eq`, `in`, `exists`** — 8 fields\n\n- `asset_type`: The asset type: `domain`, `subdomain`, `ip` or `website`.\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `dns.dnskey.records.key_type`: The role of a DNSKEY: `ZSK` (zone-signing key), `KSK` (key-signing key) or `KSK_REVOKED` (revoked key-signing key).\n- `dns.dnskey.records.algorithm`: The DNSSEC algorithm of a DNSKEY, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.algorithm`: The DNSSEC algorithm of the key that a DS record refers to, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.digest_type`: The hash used for a DS record's digest: `SHA1`, `SHA256`, `SHA384`, `GOST` or `NULL`.\n- `dns.rrsig.algorithm`: The DNSSEC algorithm of an RRSIG signature, such as `ECDSAP256SHA256` or `RSASHA256`.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `website.parent_asset.type`: The asset type of the website's parent asset, such as `subdomain`.\n\nSortable fields:\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `website_count`: The number of website assets (`host:port`) in your inventory that belong to this asset.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `open_port_count`: The number of open ports found on the asset.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n> The saved example **Request template · 38 of 740 filters** holds this body with 38 of the 740 filters (the first 10 of each operator group); the full list is above (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset_type\",\n        \"type\": \"eq\",\n        \"value\": \"domain\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Asset Detail",
              "id": "da3a1cf3-b626-56c1-8ad0-a8f4df10e1f9",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Detail API**\n\nReturns everything Deepinfo knows about one asset: latest WHOIS, DNS, SSL, HTTP and web data, open ports, technologies, issue and vulnerability counts, and security score.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `asset` | string |  |\n| `asset_type` | string | One of `domain`, `subdomain`, `ip`, `website` |\n| `added_date` | string | date-time |\n| `tags` | array of string |  |\n| `creation_method` | string | One of `manually_added`, `manually_approved`, `auto_approved` |\n| `favicon` | string |  |\n| `screenshot` | string |  |\n| `thumbnail` | string |  |\n| `latest_scan_date` | string | date-time |\n| `is_main_asset` | boolean |  |\n| `seems_inactive` | boolean |  |\n| `seems_inactive_first_seen` | string | date-time |\n| `seems_inactive_last_seen` | string | date-time |\n| `discovery_enabled` | boolean |  |\n| `dns_wildcard_active` | boolean |  |\n| `is_login_page` | boolean |  |\n| `login_page_probability` | number |  |\n| `fqdn` | object |  |\n| `website` | object |  |\n| `whois` | object |  |\n| `whois_privacy_enabled` | boolean |  |\n| `whois_registrant_email_historical` | array of string |  |\n| `whois_create_date_historical` | array of string |  |\n| `whois_normalized` | object |  |\n| `whois_check_date` | string | date-time |\n| `whois_last_change_date` | string | date-time |\n| `whois_last_change_data` | array of string |  |\n| `dns` | object |  |\n| `dns_check_date` | string | date-time |\n| `dns_last_change_date` | string | date-time |\n| `dns_last_change_data` | array of string |  |\n| `ssl` | object |  |\n| `ssl_check_date` | string | date-time |\n| `ssl_last_change_date` | string | date-time |\n| `ssl_last_change_data` | array of string |  |\n| `http` | object |  |\n| `http_check_date` | string | date-time |\n| `http_last_change_date` | string | date-time |\n| `http_last_change_data` | array of string |  |\n| `webdata` | object |  |\n| `webdata_check_date` | string | date-time |\n| `webdata_last_change_date` | string | date-time |\n| `webdata_last_change_data` | array of string |  |\n| `ipwhois` | object |  |\n| `ipwhois_check_date` | string | date-time |\n| `ipwhois_last_change_date` | string | date-time |\n| `ipwhois_last_change_data` | array of string |  |\n| `ipdns` | object |  |\n| `ipdns_check_date` | string | date-time |\n| `ipdns_last_change_date` | string | date-time |\n| `ipdns_last_change_data` | array of string |  |\n| `subdomain_count` | integer |  |\n| `website_count` | integer |  |\n| `pointed_fqdn_count` | integer |  |\n| `redirected_domain_count` | integer |  |\n| `redirected_asset_count` | integer |  |\n| `average_issue_duration` | integer |  |\n| `average_fix_duration` | integer |  |\n| `is_parked` | boolean |  |\n| `open_port_count` | integer |  |\n| `open_ports` | array of integer |  |\n| `issue_state_stats` | object |  |\n| `issue_category_stats` | array of object |  |\n| `issue_count` | object |  |\n| `technology_count` | object |  |\n| `vulnerability_count` | object |  |\n| `security_score` | number |  |\n| `weight` | integer |  |\n| `user_weight` | integer |  |\n| `system_weight` | integer |  |\n| `domain_snapshot` | object |  |\n| `domain_asset` | object |  |\n| `weight_last_update_date` | string | date-time |\n| `user_weight_last_update_date` | string | date-time |\n| `system_weight_last_update_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset Create",
              "id": "003f3f8b-d367-57df-9e55-b546531ee591",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets"
                  ]
                },
                "description": "**Deepinfo EASM Asset Create API**\n\nAdds assets to monitoring. Send up to 1,000 domains, subdomains, IPs or website URLs in `assets`. The response lists which were `created`, which `already_existed` and which were `invalid`. New assets are scanned automatically.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `assets` | array | yes | min items `1`; max items `1000` |\n| `description` | string |  |  |\n| `portfolio_id` | string |  |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `created` | array of string |  |\n| `already_existed` | array of string |  |\n| `invalid` | array of string |  |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"assets\": [\n    \"postman-docs-test.deepinfo.com\"\n  ],\n  \"description\": \"Postman documentation test asset\"\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Asset Delete",
              "id": "dc167d6a-2ed9-5d0d-a958-e077b6c456e2",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/search:delete",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "search:delete"
                  ]
                },
                "description": "**Deepinfo EASM Asset Delete API**\n\nRemoves every asset matching `filters` from monitoring. Deleted assets are listed under **Deleted Assets**.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 517 fields\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `tags`: Your own labels on the asset, such as a business unit or an environment; each tag is 3 to 100 characters long.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.name.unicode`: The host name without its extension, in Unicode: `acme` for `acme.example`, `www.acme` for `www.acme.example`.\n- `fqdn.name.latinized`: Latin-letter spellings of a name that has non-Latin or accented letters, so a search for `istanbul` also finds names written with `İ`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_sub.unicode`: The second-level part of a two-part extension, such as `co` in `co.uk`; empty for single-part extensions.\n- `website.path`: The URL path of a website asset, such as `/`.\n- `website.scheme`: The URL scheme of a website asset, such as `http`.\n- `website.parent_asset.id`: The ID of the domain or subdomain asset that a website asset belongs to.\n- `website.parent_asset.name`: The name of the domain or subdomain asset that a website asset belongs to.\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.name`: The registrant's name in WHOIS; often a privacy placeholder such as `redacted for privacy`.\n- `whois.registrant.country`: The registrant's country in WHOIS, as a two-letter code in lower case such as `us`.\n- `whois.registrant.state`: The registrant's state or province in WHOIS.\n- `whois.registrant.city`: The registrant's city in WHOIS.\n- `whois.registrant.street`: The registrant's street address in WHOIS.\n- `whois.registrant.postal_code`: The registrant's postal code in WHOIS.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `whois_registrant_email_historical`: Every registrant e-mail address seen for the domain over time, the current one included.\n- `whois_normalized.registrar`: The registrar reduced to a short normalized name, such as `godaddy` or `gandi`, so the same registrar matches across spellings.\n- `whois_normalized.registrant.email`: The registrant e-mail address after WHOIS normalization.\n- `whois_normalized.registrant.email_real`: Another normalized registrant e-mail field, set on fewer domains than `whois_normalized.registrant.email`; in the samples it is set only where `whois_privacy_enabled` is false, with the same address.\n- `whois_normalized.registrant.email_domain_apex`: The registrable domain of the registrant e-mail address: `acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.email_fqdn_apex`: The full host name after the `@` of the registrant e-mail address: `mail.acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.organization`: The registrant organization cleaned up across registrars: lower case, with spaces and punctuation removed, such as `domainsbyproxyllc`.\n- `whois_normalized.registrant.phone`: The registrant phone number reduced to its digits, such as `14805551234`.\n- `whois_last_change_data`: The WHOIS fields that changed in the last change seen, as field paths such as `whois.update_date` or `whois.domain_status`.\n- `dns.a.value`: The asset's current A records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.a.value_previous`: The asset's A records as they were before the last change, in the same text form as `dns.a.value`.\n- `dns.a.rcode`: The DNS response code returned for the asset's A lookup, such as `NOERROR`.\n- `dns.a.rcode_previous`: The DNS response code of the A lookup before it last changed.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.entities`: The handles of the registry contacts and organizations linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, when it is kept.\n- `dns.a.ip_addresses.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the A-record address.\n- `dns.a.ip_addresses.raw`: The raw IP WHOIS response for the A-record address, when it is kept; empty on every sampled asset.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.a.ip_addresses.network.start_address`: The first address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.end_address`: The last address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.handle`: The registry handle of the network that contains the A-record address, such as `NET-192-0-2-0-1`.\n- `dns.a.ip_addresses.network.ip_version`: The IP version of the network that contains the A-record address: `v4` or `v6`.\n- `dns.a.ip_addresses.network.links`: Links to the registry record of the network that contains the A-record address, such as its RDAP and WHOIS URLs.\n- `dns.a.ip_addresses.network.parent_handle`: The handle of the larger network block from which the network of the A-record address was allocated.\n- `dns.a.ip_addresses.network.raw`: The raw RDAP network object for the A-record address, when it is kept.\n- `dns.a.ip_addresses.network.status`: The registry status of the network that contains the A-record address, such as `active`.\n- `dns.a.ip_addresses.network.type`: The registry's allocation type for the network that contains the A-record address, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `dns.a.ip_addresses.network.notices.title`: The title of a notice the registry attached to the network record of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.network.notices.description`: The text of a notice the registry attached to the network record of the A-record address.\n- `dns.a.ip_addresses.network.notices.links`: Links given in a notice on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.title`: The title of a remark on the network record of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.network.remarks.description`: The text of a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.links`: Links given in a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.events.action`: An event in the history of the network record of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.network.events.actor`: Who performed an event on the network record of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the A-record address, such as `abuse`.\n- `dns.a.ip_addresses.objects.contact.email.value`: An e-mail address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.value`: A postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the A-record address, such as `voice` or `work`.\n- `dns.a.ip_addresses.objects.contact.phone.value`: A phone number of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.kind`: What kind of contact is linked to the network of the A-record address: `org`, `group` or `individual`.\n- `dns.a.ip_addresses.objects.contact.name`: The name of a contact or organization linked to the network of the A-record address, such as `Abuse` or a company name.\n- `dns.a.ip_addresses.objects.contact.role`: The role given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.title`: The title given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.entities`: Handles of further entities listed under a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.events.action`: An event in the history of a contact record linked to the network of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.objects.events.actor`: Who performed an event on a contact record linked to the network of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.events_actor`: Events in which a contact linked to the network of the A-record address is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `dns.a.ip_addresses.objects.handle`: The registry handle of a contact or organization linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.links`: Links to the registry record of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.title`: The title of a notice on a contact record linked to the network of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.objects.notices.description`: The text of a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.links`: Links given in a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.raw`: The raw RDAP object of a contact linked to the network of the A-record address, when it is kept.\n- `dns.a.ip_addresses.objects.remarks.title`: The title of a remark on a contact record linked to the network of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.objects.remarks.description`: The text of a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.roles`: The roles of a contact for the network of the A-record address, such as `registrant`, `abuse` or `technical`.\n- `dns.a.ip_addresses.objects.status`: The registry status of a contact linked to the network of the A-record address, such as `validated`.\n- `dns.a.ip_history`: Every IPv4 address seen in the asset's A records over time, the current ones included.\n- `dns.aaaa.value`: The asset's current AAAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.aaaa.value_previous`: The asset's AAAA records as they were before the last change, in the same text form as `dns.aaaa.value`.\n- `dns.aaaa.rcode`: The DNS response code returned for the asset's AAAA lookup, such as `NOERROR`.\n- `dns.aaaa.rcode_previous`: The DNS response code of the AAAA lookup before it last changed.\n- `dns.aaaa.ip_addresses`: The IPv6 addresses in the asset's AAAA records.\n- `dns.caa.value`: The asset's current CAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.caa.value_previous`: The asset's CAA records as they were before the last change, in the same text form as `dns.caa.value`.\n- `dns.caa.rcode`: The DNS response code returned for the asset's CAA lookup, such as `NOERROR`.\n- `dns.caa.rcode_previous`: The DNS response code of the CAA lookup before it last changed.\n- `dns.caa.issue_fqdns`: The certificate authorities allowed to issue certificates for the name, from the CAA `issue` tags, such as `fernhill.example` or `kestrel.example`.\n- `dns.caa.issuewild_fqdns`: The certificate authorities allowed to issue wildcard certificates for the name, from the CAA `issuewild` tags.\n- `dns.caa.iodef_emails`: The e-mail addresses from the CAA `iodef` tags, where certificate authorities report requests that break the CAA policy.\n- `dns.cname.value`: The asset's current CNAME records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.cname.value_previous`: The asset's CNAME records as they were before the last change, in the same text form as `dns.cname.value`.\n- `dns.cname.rcode`: The DNS response code returned for the asset's CNAME lookup, such as `NOERROR`.\n- `dns.cname.rcode_previous`: The DNS response code of the CNAME lookup before it last changed.\n- `dns.cname.canonical_fqdns`: The host names the asset's CNAME records point to (the alias targets).\n- `dns.dnskey.value`: The asset's current DNSKEY records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.dnskey.value_previous`: The asset's DNSKEY records as they were before the last change, in the same text form as `dns.dnskey.value`.\n- `dns.dnskey.rcode`: The DNS response code returned for the asset's DNSKEY lookup, such as `NOERROR`.\n- `dns.dnskey.rcode_previous`: The DNS response code of the DNSKEY lookup before it last changed.\n- `dns.dnskey.records.public_key`: The public key of a DNSKEY record, Base64-encoded and split into space-separated groups as in the zone-file text.\n- `dns.ds.value`: The asset's current DS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ds.value_previous`: The asset's DS records as they were before the last change, in the same text form as `dns.ds.value`.\n- `dns.ds.rcode`: The DNS response code returned for the asset's DS lookup, such as `NOERROR`.\n- `dns.ds.rcode_previous`: The DNS response code of the DS lookup before it last changed.\n- `dns.ds.records.digest`: The digest of a DS record, the hash of the DNSKEY it refers to.\n- `dns.mx.value`: The asset's current MX records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.mx.value_previous`: The asset's MX records as they were before the last change, in the same text form as `dns.mx.value`.\n- `dns.mx.rcode`: The DNS response code returned for the asset's MX lookup, such as `NOERROR`.\n- `dns.mx.rcode_previous`: The DNS response code of the MX lookup before it last changed.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns.mx.domains`: The registrable domains of the asset's mail servers, such as `acme.example`.\n- `dns.ns.value`: The asset's current NS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ns.value_previous`: The asset's NS records as they were before the last change, in the same text form as `dns.ns.value`.\n- `dns.ns.rcode`: The DNS response code returned for the asset's NS lookup, such as `NOERROR`.\n- `dns.ns.rcode_previous`: The DNS response code of the NS lookup before it last changed.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.ns.domains`: The registrable domains of the asset's name servers, such as `acme.example`.\n- `dns.nsec.value`: The asset's current NSEC records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec.value_previous`: The asset's NSEC records as they were before the last change, in the same text form as `dns.nsec.value`.\n- `dns.nsec.rcode`: The DNS response code returned for the asset's NSEC lookup, such as `NOERROR`.\n- `dns.nsec.rcode_previous`: The DNS response code of the NSEC lookup before it last changed.\n- `dns.nsec.records.next_domain`: The next name in the zone, from an NSEC record.\n- `dns.nsec.records.record_types`: The record types that exist at the name, from an NSEC record's type list, such as `A`, `NS` or `SOA`.\n- `dns.nsec3.value`: The asset's current NSEC3 records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec3.value_previous`: The asset's NSEC3 records as they were before the last change, in the same text form as `dns.nsec3.value`.\n- `dns.nsec3.rcode`: The DNS response code returned for the asset's NSEC3 lookup, such as `NOERROR`.\n- `dns.nsec3.rcode_previous`: The DNS response code of the NSEC3 lookup before it last changed.\n- `dns.nsec3.records.next_domain_hashed`: The hashed next name in the zone, from an NSEC3 record.\n- `dns.nsec3.records.record_types`: The record types that exist at the name, from an NSEC3 record's type list, such as `A` or `MX`.\n- `dns.rrsig.value`: The asset's current RRSIG records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.rrsig.value_previous`: The asset's RRSIG records as they were before the last change, in the same text form as `dns.rrsig.value`.\n- `dns.rrsig.rcode`: The DNS response code returned for the asset's RRSIG lookup, such as `NOERROR`.\n- `dns.rrsig.rcode_previous`: The DNS response code of the RRSIG lookup before it last changed.\n- `dns.rrsig.type_covered`: The record type that an RRSIG signature covers, such as `A` or `SOA`.\n- `dns.rrsig.signature`: The signature data of an RRSIG record, Base64-encoded.\n- `dns.soa.value`: The asset's current SOA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.soa.value_previous`: The asset's SOA records as they were before the last change, in the same text form as `dns.soa.value`.\n- `dns.soa.rcode`: The DNS response code returned for the asset's SOA lookup, such as `NOERROR`.\n- `dns.soa.rcode_previous`: The DNS response code of the SOA lookup before it last changed.\n- `dns.soa.mnames`: The MNAME of the SOA record: the primary name server of the zone, such as `ns1.acme.example`.\n- `dns.soa.rnames`: The RNAME of the SOA record, the zone administrator's mailbox in DNS form: `hostmaster.acme.example` stands for the mailbox `hostmaster` at `acme.example`.\n- `dns.soa.rname_emails`: The RNAME of the SOA record written as an e-mail address, such as `user@acme.example`.\n- `dns.srv.value`: The asset's current SRV records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.srv.value_previous`: The asset's SRV records as they were before the last change, in the same text form as `dns.srv.value`.\n- `dns.srv.rcode`: The DNS response code returned for the asset's SRV lookup, such as `NOERROR`.\n- `dns.srv.rcode_previous`: The DNS response code of the SRV lookup before it last changed.\n- `dns.srv.records.service`: The service named in an SRV record (the `_service` part of its name).\n- `dns.srv.records.protocol`: The protocol named in an SRV record (the `_proto` part of its name, such as TCP or UDP).\n- `dns.srv.records.target`: The host name an SRV record points to.\n- `dns.txt.value`: The asset's current TXT records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.txt.value_previous`: The asset's TXT records as they were before the last change, in the same text form as `dns.txt.value`.\n- `dns.txt.rcode`: The DNS response code returned for the asset's TXT lookup, such as `NOERROR`.\n- `dns.txt.rcode_previous`: The DNS response code of the TXT lookup before it last changed.\n- `dns.txt.values`: Each TXT record of the asset as its quoted text, such as `\"v=spf1 include:_spf.acme.example ~all\"`; the quotes are part of the value.\n- `dns.txt.spf_list.value`: The text of an SPF record (a TXT record that starts with `v=spf1`), quoted as in `dns.txt.values`.\n- `dns.txt.spf_list.allowed_domains`: The registrable domains that an SPF record refers to, such as `acme.example` for `include:_spf.acme.example`.\n- `dns.txt.spf_list.allowed_ips`: The IP addresses and ranges that an SPF record authorizes to send mail (its `ip4:` and `ip6:` entries).\n- `dns.txt.verifications.value`: The text of a site-verification TXT record, quoted as in `dns.txt.values`.\n- `dns.txt.verifications.domain`: The domain of the service a verification record is for, such as `acme.example`, `fernhill.example` or `kestrel.example`.\n- `dns.txt.verifications.name`: The name of a verification record, such as `site-verification` or `domain-verification`.\n- `dns_last_change_data`: The DNS fields that changed in the last change seen, as field paths such as `dns.soa.mnames`.\n- `ssl.target`: The host name that the asset's TLS certificate was collected from, normally the asset itself.\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.md5`: The MD5 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha256`: The SHA-256 fingerprint of the asset's TLS certificate, as lower-case hex; one fingerprint identifies one certificate.\n- `ssl.issuer.common_name`: The common name (CN) of the certificate authority that issued the asset's TLS certificate, such as `WE1` or `YE2`.\n- `ssl.issuer.country`: The country (C) of the certificate authority that issued the asset's TLS certificate, as a two-letter code such as `US`.\n- `ssl.issuer.state`: The state or province (ST) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.locality`: The locality or city (L) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.organization`: The organization (O) of the certificate authority that issued the asset's TLS certificate, such as `Let's Encrypt` or `Google Trust Services`.\n- `ssl.issuer.organizational_unit`: The organizational unit (OU) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer_dn`: The full distinguished name of the issuer of the asset's TLS certificate, as one string such as `CN=WE1,O=Google Trust Services,C=US`.\n- `ssl.subject.common_name`: The common name (CN) of the subject (holder) of the asset's TLS certificate, usually a host name such as `acme.example`.\n- `ssl.subject.country`: The country (C) of the subject (holder) of the asset's TLS certificate, as a two-letter code.\n- `ssl.subject.state`: The state or province (ST) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.locality`: The locality or city (L) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organizational_unit`: The organizational unit (OU) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject_dn`: The full distinguished name of the subject of the asset's TLS certificate, such as `CN=acme.example`; one that starts with `CN=*.` belongs to a wildcard certificate.\n- `ssl.signature.value`: The signature of the asset's TLS certificate, Base64-encoded.\n- `ssl.signature.invalid_reason`: Why certificate validation failed, such as a host name mismatch or `unable to get issuer certificate`.\n- `ssl.signature.algorithm.name`: The hash algorithm of the signature on the asset's TLS certificate, such as `sha256` or `sha384`.\n- `ssl.signature.algorithm.oid`: The object identifier (OID) of the signature algorithm, such as `1.2.840.113549.1.1.11` (SHA-256 with RSA) or `1.2.840.10045.4.3.2` (ECDSA with SHA-256).\n- `ssl.extensions.authority_key_id`: The Authority Key Identifier extension, which identifies the issuer's key, Base64-encoded.\n- `ssl.extensions.certificate_policies`: The policy OIDs in the Certificate Policies extension, such as `2.23.140.1.2.1` (domain validated).\n- `ssl.extensions.signed_certificate_timestamps.log_id`: The ID of the Certificate Transparency log that issued a signed certificate timestamp (SCT) for the certificate, Base64-encoded.\n- `ssl.extensions.signed_certificate_timestamps.signature`: The log's signature on a signed certificate timestamp, Base64-encoded.\n- `ssl.extensions.subject_alt_name.dns_names`: The host names in the certificate's Subject Alternative Name extension, including wildcard names such as `*.acme.example`.\n- `ssl.extensions.subject_key_id`: The Subject Key Identifier extension, which identifies the certificate's own key, Base64-encoded.\n- `ssl.subject_key_info.fingerprint.hash_algorithm`: The hash algorithm used for `ssl.subject_key_info.fingerprint.value`, such as `sha256` or `sha384`.\n- `ssl.subject_key_info.fingerprint.value`: A hex fingerprint recorded under the certificate's subject key information, made with the hash in `hash_algorithm`. In the samples it equals `ssl.fingerprint.sha256` when that hash is SHA-256.\n- `ssl.subject_key_info.key_algorithm.name`: The algorithm of the certificate's public key, such as `RSA` or `ECDSA`.\n- `ssl.version.name`: The X.509 version of the certificate, such as `v3`.\n- `ssl.version.value`: The X.509 version as encoded in the certificate, counted from zero: `2` means `v3`.\n- `ssl.tbs_fingerprint`: A SHA-256 fingerprint (hex) of the certificate's to-be-signed part, the certificate content without its signature.\n- `ssl.certificate`: The whole certificate, Base64-encoded (a PEM body without the header and footer lines).\n- `ssl.fqdn_list`: The host names the certificate covers, with the `*.` of wildcard names removed and duplicates merged, so `*.acme.example` and `acme.example` both give `acme.example`.\n- `ssl_last_change_data`: The certificate fields that changed in the last change seen, as field paths such as `ssl.validity.end_date`.\n- `http.requested_url`: The URL the HTTP check started from, such as `http://acme.example`.\n- `http.requested_domain`: The registrable domain of the URL the HTTP check started from.\n- `http.requested_fqdn`: The host name of the URL the HTTP check started from.\n- `http.final_url`: The URL the HTTP check ended on after following all redirects.\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.redirection_history.url`: A URL in the redirect chain of the HTTP check, listed in the order visited.\n- `http.headers.accept`: The `Accept` header, when it was returned in the HTTP check. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the HTTP check. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `http.headers.accept_language`: The `Accept-Language` header, when it was returned in the HTTP check. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the HTTP check; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the HTTP check; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the HTTP check; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the HTTP check; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the HTTP check; it lists the response headers that scripts from other origins may read (CORS).\n- `http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the HTTP check; it says how many seconds browsers may cache a CORS preflight result.\n- `http.headers.alt_svc`: The `Alt-Svc` header returned in the HTTP check; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `http.headers.authorization`: The `Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `http.headers.cache_control`: The `Cache-Control` header returned in the HTTP check; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the HTTP check; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `http.headers.content_disposition`: The `Content-Disposition` header returned in the HTTP check; it says whether the content is shown in the browser or downloaded as a file.\n- `http.headers.content_encoding`: The `Content-Encoding` header returned in the HTTP check; it names the compression applied to the response body, for example `gzip` or `br`.\n- `http.headers.content_language`: The `Content-Language` header returned in the HTTP check; it gives the language of the content, for example `en` or `tr`.\n- `http.headers.content_length`: The `Content-Length` header returned in the HTTP check; it gives the size of the response body in bytes.\n- `http.headers.content_range`: The `Content-Range` header returned in the HTTP check; it says which part of the full body a partial response holds.\n- `http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the HTTP check; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `http.headers.content_type`: The `Content-Type` header returned in the HTTP check; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `http.headers.cookie`: The `Cookie` header, when it was returned in the HTTP check. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the HTTP check; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the HTTP check; it controls whether the page shares its browsing context with cross-origin windows.\n- `http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the HTTP check; it controls which sites may load the resource.\n- `http.headers.date`: The `Date` header returned in the HTTP check; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `http.headers.early_data`: The `Early-Data` header, when it was returned in the HTTP check. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `http.headers.expect_ct`: The `Expect-CT` header returned in the HTTP check; it is a deprecated header about Certificate Transparency enforcement.\n- `http.headers.expires`: The `Expires` header returned in the HTTP check; it gives the date after which the response counts as stale, in HTTP date format.\n- `http.headers.feature_policy`: The `Feature-Policy` header returned in the HTTP check; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `http.headers.host`: The `Host` header, when it was returned in the HTTP check. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the HTTP check. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the HTTP check. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `http.headers.last_modified`: The `Last-Modified` header returned in the HTTP check; it gives the time the server says the resource last changed, in HTTP date format.\n- `http.headers.origin_isolation`: The `Origin-Isolation` header returned in the HTTP check; it is an experimental header that asks browsers to isolate the site's origin.\n- `http.headers.others.name`: The name of a header returned in the HTTP check that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `http.headers.others.value`: The value of a header listed in `headers.others` for the HTTP check.\n- `http.headers.permission_policy`: The `Permission-Policy` header returned in the HTTP check; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `http.headers.permissions_policy`: The `Permissions-Policy` header returned in the HTTP check; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `http.headers.pragma`: The `Pragma` header returned in the HTTP check; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the HTTP check; it tells a client how to authenticate to a proxy.\n- `http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the HTTP check; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `http.headers.range`: The `Range` header, when it was returned in the HTTP check. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `http.headers.referer`: The `Referer` header, when it was returned in the HTTP check. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `http.headers.referrer_policy`: The `Referrer-Policy` header returned in the HTTP check; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the HTTP check. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `http.headers.server`: The `Server` header returned in the HTTP check; it names the server software the site reports, for example `nginx` or `Apache`.\n- `http.headers.set_cookie`: The `Set-Cookie` header returned in the HTTP check; it sets cookies, with their attributes.\n- `http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the HTTP check; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `http.headers.te`: The `TE` header, when it was returned in the HTTP check. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the HTTP check; it says how the body is transferred, for example `chunked`.\n- `http.headers.upgrade`: The `Upgrade` header returned in the HTTP check; it offers or asks for a switch to another protocol.\n- `http.headers.user_agent`: The `User-Agent` header, when it was returned in the HTTP check. It is normally a request header (the client software), so it is rarely set.\n- `http.headers.vary`: The `Vary` header returned in the HTTP check; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the HTTP check; it tells a client how to authenticate, usually with a `401` response.\n- `http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the HTTP check; it stops browsers from guessing the content type when set to `nosniff`.\n- `http.headers.x_download_options`: The `X-Download-Options` header returned in the HTTP check; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `http.headers.x_frame_options`: The `X-Frame-Options` header returned in the HTTP check; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the HTTP check; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `http.headers.x_powered_by`: The `X-Powered-By` header returned in the HTTP check; it names the technology the server reports running on, for example `Express`.\n- `http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the HTTP check; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `http.cookies.name`: The name of a cookie set in the HTTP check.\n- `http.cookies.value`: The value of a cookie set in the HTTP check.\n- `http.html.source_code_hash`: A SHA-256 hash of the page source returned in the HTTP check; the same hash means the same source.\n- `http_last_change_data`: The HTTP check fields that changed in the last change seen, as field paths such as `http.html.source_code_hash`.\n- `webdata.requested_url`: The URL the web data scan started from, such as `http://acme.example`.\n- `webdata.requested_domain`: The registrable domain of the URL the web data scan started from.\n- `webdata.requested_fqdn`: The host name of the URL the web data scan started from.\n- `webdata.html.internal_links_fqdns`: The host names of links on the scanned page that stay within the site's own domain, such as other subdomains.\n- `webdata.html.external_links_domains`: The registrable domains of links on the scanned page that point to other domains, such as `kestrel.example`.\n- `webdata.html.external_links_fqdns`: The host names of links on the scanned page that point to other domains, such as `www.kestrel.example`.\n- `webdata.html.external_links`: The full URLs of links on the scanned page that point to other domains.\n- `webdata.html.script_links`: The URLs of the scripts the scanned page loads.\n- `webdata.html.iframe_links`: The URLs of the frames (iframes) embedded in the scanned page.\n- `webdata.html.trackers.name`: The name of an analytics or advertising tracker found on the scanned page, such as `google_adsense` or `google_tag_manager`.\n- `webdata.html.trackers.values`: The IDs found for a tracker, such as a Google Analytics ID that starts with `G-` or `UA-`.\n- `webdata.html.emails`: The e-mail addresses found on the scanned page.\n- `webdata.html.emails_internal`: The e-mail addresses found on the scanned page that belong to the site's own domain.\n- `webdata.html.source_code_hash`: A SHA-256 hash of the page source in the web data scan; the same hash means the same source.\n- `webdata.html.content_hash`: A SHA-256 hash of the page content in the web data scan, kept apart from `source_code_hash`, the hash of the raw source.\n- `webdata.html.content_top_keywords`: The most frequent words in the text of the scanned page.\n- `webdata.html.favicon_links`: The URLs of the icons the scanned page declares, such as its favicon and touch icons.\n- `webdata.html.html_meta.name`: The site or application name declared in the scanned page's metadata.\n- `webdata.html.html_meta.description`: The meta description of the scanned page.\n- `webdata.html.html_meta.language`: The language the scanned page declares, such as `en`, `tr` or `en-US`.\n- `webdata.html.html_meta.language_alternatives`: The languages of the alternative versions the scanned page links to, such as `en` or `ar`.\n- `webdata.html.html_meta.keywords`: The keywords listed in the keywords meta tag of the scanned page.\n- `webdata.html.html_meta.encoding`: The character encoding the scanned page declares, such as `utf-8`.\n- `webdata.html.html_meta.canonical_url`: The canonical URL the scanned page declares.\n- `webdata.html.html_meta.title`: The title of the scanned page.\n- `webdata.favicon.url`: The URL of a site icon (favicon) recorded by the web data scan.\n- `webdata.favicon.hash`: A SHA-256 hash of a site icon; the same hash means the same icon.\n- `webdata.http.final_url`: The URL the web data scan ended on after following all redirects.\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.redirection_history.url`: A URL in the redirect chain of the web data scan, listed in the order visited.\n- `webdata.http.redirection_history.method`: How a step of the web data scan's redirect chain was made; `http-header` (a redirect sent in the HTTP response) is the value in the samples.\n- `webdata.http.headers.accept`: The `Accept` header, when it was returned in the web data scan. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the web data scan. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_language`: The `Accept-Language` header, when it was returned in the web data scan. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `webdata.http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the web data scan; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `webdata.http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the web data scan; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `webdata.http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the web data scan; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `webdata.http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the web data scan; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `webdata.http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the web data scan; it lists the response headers that scripts from other origins may read (CORS).\n- `webdata.http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the web data scan; it says how many seconds browsers may cache a CORS preflight result.\n- `webdata.http.headers.alt_svc`: The `Alt-Svc` header returned in the web data scan; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `webdata.http.headers.authorization`: The `Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `webdata.http.headers.cache_control`: The `Cache-Control` header returned in the web data scan; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `webdata.http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the web data scan; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `webdata.http.headers.content_disposition`: The `Content-Disposition` header returned in the web data scan; it says whether the content is shown in the browser or downloaded as a file.\n- `webdata.http.headers.content_encoding`: The `Content-Encoding` header returned in the web data scan; it names the compression applied to the response body, for example `gzip` or `br`.\n- `webdata.http.headers.content_language`: The `Content-Language` header returned in the web data scan; it gives the language of the content, for example `en` or `tr`.\n- `webdata.http.headers.content_length`: The `Content-Length` header returned in the web data scan; it gives the size of the response body in bytes.\n- `webdata.http.headers.content_range`: The `Content-Range` header returned in the web data scan; it says which part of the full body a partial response holds.\n- `webdata.http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the web data scan; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `webdata.http.headers.content_type`: The `Content-Type` header returned in the web data scan; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `webdata.http.headers.cookie`: The `Cookie` header, when it was returned in the web data scan. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `webdata.http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the web data scan; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `webdata.http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the web data scan; it controls whether the page shares its browsing context with cross-origin windows.\n- `webdata.http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the web data scan; it controls which sites may load the resource.\n- `webdata.http.headers.date`: The `Date` header returned in the web data scan; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `webdata.http.headers.early_data`: The `Early-Data` header, when it was returned in the web data scan. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `webdata.http.headers.expect_ct`: The `Expect-CT` header returned in the web data scan; it is a deprecated header about Certificate Transparency enforcement.\n- `webdata.http.headers.expires`: The `Expires` header returned in the web data scan; it gives the date after which the response counts as stale, in HTTP date format.\n- `webdata.http.headers.feature_policy`: The `Feature-Policy` header returned in the web data scan; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `webdata.http.headers.host`: The `Host` header, when it was returned in the web data scan. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `webdata.http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the web data scan. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `webdata.http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the web data scan. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `webdata.http.headers.last_modified`: The `Last-Modified` header returned in the web data scan; it gives the time the server says the resource last changed, in HTTP date format.\n- `webdata.http.headers.origin_isolation`: The `Origin-Isolation` header returned in the web data scan; it is an experimental header that asks browsers to isolate the site's origin.\n- `webdata.http.headers.others.name`: The name of a header returned in the web data scan that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `webdata.http.headers.others.value`: The value of a header listed in `headers.others` for the web data scan.\n- `webdata.http.headers.permission_policy`: The `Permission-Policy` header returned in the web data scan; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `webdata.http.headers.permissions_policy`: The `Permissions-Policy` header returned in the web data scan; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `webdata.http.headers.pragma`: The `Pragma` header returned in the web data scan; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `webdata.http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the web data scan; it tells a client how to authenticate to a proxy.\n- `webdata.http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `webdata.http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the web data scan; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `webdata.http.headers.range`: The `Range` header, when it was returned in the web data scan. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `webdata.http.headers.referer`: The `Referer` header, when it was returned in the web data scan. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `webdata.http.headers.referrer_policy`: The `Referrer-Policy` header returned in the web data scan; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `webdata.http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `webdata.http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the web data scan. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `webdata.http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `webdata.http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the web data scan. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `webdata.http.headers.server`: The `Server` header returned in the web data scan; it names the server software the site reports, for example `nginx` or `Apache`.\n- `webdata.http.headers.set_cookie`: The `Set-Cookie` header returned in the web data scan; it sets cookies, with their attributes.\n- `webdata.http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the web data scan; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `webdata.http.headers.te`: The `TE` header, when it was returned in the web data scan. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `webdata.http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the web data scan; it says how the body is transferred, for example `chunked`.\n- `webdata.http.headers.upgrade`: The `Upgrade` header returned in the web data scan; it offers or asks for a switch to another protocol.\n- `webdata.http.headers.user_agent`: The `User-Agent` header, when it was returned in the web data scan. It is normally a request header (the client software), so it is rarely set.\n- `webdata.http.headers.vary`: The `Vary` header returned in the web data scan; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `webdata.http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the web data scan; it tells a client how to authenticate, usually with a `401` response.\n- `webdata.http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the web data scan; it stops browsers from guessing the content type when set to `nosniff`.\n- `webdata.http.headers.x_download_options`: The `X-Download-Options` header returned in the web data scan; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `webdata.http.headers.x_frame_options`: The `X-Frame-Options` header returned in the web data scan; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `webdata.http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the web data scan; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `webdata.http.headers.x_powered_by`: The `X-Powered-By` header returned in the web data scan; it names the technology the server reports running on, for example `Express`.\n- `webdata.http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the web data scan; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `webdata.http.cookies.name`: The name of a cookie set in the web data scan.\n- `webdata.http.cookies.value`: The value of a cookie set in the web data scan.\n- `webdata.http.cookies.domain`: The domain a cookie set in the web data scan applies to, such as `.acme.example`.\n- `webdata.http.cookies.path`: The path a cookie set in the web data scan applies to, such as `/`.\n- `webdata.http.cookies.same_party`: The SameParty attribute of a cookie set in the web data scan; in the samples it always holds the same value as `same_site`, such as `Lax` or `None`.\n- `webdata.http.cookies.priority`: The Priority attribute of a cookie set in the web data scan (`Low`, `Medium` or `High` in Chromium-based browsers).\n- `webdata.http.cookies.same_site`: The SameSite attribute of a cookie set in the web data scan, such as `Lax`, `Strict` or `None`.\n- `webdata.technology.stacks.slug`: A short identifier of a technology detected on the site, such as `iis` or `windows-server`.\n- `webdata.technology.stacks.name`: The name of a technology detected on the site, such as `IIS` or `Microsoft ASP.NET`.\n- `webdata.technology.stacks.icon`: The file name of a detected technology's icon, such as `acme.png`.\n- `webdata.technology.stacks.website`: The website of a detected technology's vendor or project.\n- `webdata.technology.stacks.cpe`: The CPE identifier of a detected technology, such as `cpe:/a:acme:acme-portal`, used to match it to known vulnerabilities.\n- `webdata.technology.stacks.version`: The detected version of a technology, such as `1.0`.\n- `webdata.technology.stacks.categories`: The categories of a detected technology, such as `Web servers` or `Operating systems`.\n- `webdata.technology.stacks.description`: A short description of a detected technology.\n- `webdata_last_change_data`: The web data fields that changed in the last change seen, as field paths under `webdata`.\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.entities`: The handles of the registry contacts and organizations linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, when it is kept.\n- `ipwhois.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the IP address asset.\n- `ipwhois.raw`: The raw IP WHOIS response for the IP address asset, when it is kept; empty on every sampled asset.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `ipwhois.network.start_address`: The first address of the registered network block that contains the IP address asset.\n- `ipwhois.network.end_address`: The last address of the registered network block that contains the IP address asset.\n- `ipwhois.network.handle`: The registry handle of the network that contains the IP address asset, such as `NET-192-0-2-0-1`.\n- `ipwhois.network.ip_version`: The IP version of the network that contains the IP address asset: `v4` or `v6`.\n- `ipwhois.network.links`: Links to the registry record of the network that contains the IP address asset, such as its RDAP and WHOIS URLs.\n- `ipwhois.network.parent_handle`: The handle of the larger network block from which the network of the IP address asset was allocated.\n- `ipwhois.network.raw`: The raw RDAP network object for the IP address asset, when it is kept.\n- `ipwhois.network.status`: The registry status of the network that contains the IP address asset, such as `active`.\n- `ipwhois.network.type`: The registry's allocation type for the network that contains the IP address asset, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `ipwhois.network.notices.title`: The title of a notice the registry attached to the network record of the IP address asset, such as `Terms of Service`.\n- `ipwhois.network.notices.description`: The text of a notice the registry attached to the network record of the IP address asset.\n- `ipwhois.network.notices.links`: Links given in a notice on the network record of the IP address asset.\n- `ipwhois.network.remarks.title`: The title of a remark on the network record of the IP address asset, such as `Registration Comments`.\n- `ipwhois.network.remarks.description`: The text of a remark on the network record of the IP address asset.\n- `ipwhois.network.remarks.links`: Links given in a remark on the network record of the IP address asset.\n- `ipwhois.network.events.action`: An event in the history of the network record of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.network.events.actor`: Who performed an event on the network record of the IP address asset, when the registry names one.\n- `ipwhois.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the IP address asset, such as `abuse`.\n- `ipwhois.objects.contact.email.value`: An e-mail address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.value`: A postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the IP address asset, such as `voice` or `work`.\n- `ipwhois.objects.contact.phone.value`: A phone number of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.kind`: What kind of contact is linked to the network of the IP address asset: `org`, `group` or `individual`.\n- `ipwhois.objects.contact.name`: The name of a contact or organization linked to the network of the IP address asset, such as `Abuse` or a company name.\n- `ipwhois.objects.contact.role`: The role given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.contact.title`: The title given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.entities`: Handles of further entities listed under a contact linked to the network of the IP address asset.\n- `ipwhois.objects.events.action`: An event in the history of a contact record linked to the network of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.objects.events.actor`: Who performed an event on a contact record linked to the network of the IP address asset, when the registry names one.\n- `ipwhois.objects.events_actor`: Events in which a contact linked to the network of the IP address asset is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `ipwhois.objects.handle`: The registry handle of a contact or organization linked to the network of the IP address asset.\n- `ipwhois.objects.links`: Links to the registry record of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.notices.title`: The title of a notice on a contact record linked to the network of the IP address asset, such as `Terms of Service`.\n- `ipwhois.objects.notices.description`: The text of a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.notices.links`: Links given in a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.raw`: The raw RDAP object of a contact linked to the network of the IP address asset, when it is kept.\n- `ipwhois.objects.remarks.title`: The title of a remark on a contact record linked to the network of the IP address asset, such as `Registration Comments`.\n- `ipwhois.objects.remarks.description`: The text of a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.roles`: The roles of a contact for the network of the IP address asset, such as `registrant`, `abuse` or `technical`.\n- `ipwhois.objects.status`: The registry status of a contact linked to the network of the IP address asset, such as `validated`.\n- `ipwhois_last_change_data`: The IP WHOIS fields that changed in the last change seen, as field paths under `ipwhois`.\n- `ipdns.ptr_records`: The PTR (reverse DNS) host names of an IP address asset.\n- `ipdns_last_change_data`: The reverse DNS fields that changed in the last change seen, as field paths under `ipdns`.\n- `issue_category_stats.name`: The name of an issue category in the per-category issue counts of the asset, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`.\n- `technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the asset, such as `Web servers` or `Analytics`.\n- `domain_snapshot.issue_category_stats.name`: The name of an issue category in the per-category issue counts of the domain and its subdomains together, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the domain and its subdomains together, such as `Web servers` or `Analytics`. Set on domain assets.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 179 fields\n\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.name.length`: The number of characters in the name without the extension: `4` for `acme.example`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois_create_date_historical`: Every creation date seen for the domain over time, so a domain that was deleted and registered again keeps its earlier dates too (UTC date-times).\n- `whois_check_date`: When the WHOIS record of the asset was last checked (UTC date-time).\n- `whois_last_change_date`: When a change in the WHOIS record of the asset was last seen (UTC date-time).\n- `dns.a.value_last_change_date`: When the A record text (`dns.a.value`) last changed (UTC date-time).\n- `dns.a.rcode_last_change_date`: When the response code of the A lookup (`dns.a.rcode`) last changed (UTC date-time).\n- `dns.a.last_change_date`: When the asset's A records last changed, in their text or their response code (UTC date-time).\n- `dns.a.ip_addresses.asn_date`: The registry allocation date that the ASN lookup reports for the A-record address, as a date at midnight UTC.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was created (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was last updated (UTC date-time).\n- `dns.a.ip_addresses.network.events.timestamp`: When an event on the network record of the A-record address happened (UTC date-time).\n- `dns.a.ip_addresses.objects.events.timestamp`: When an event on a contact record linked to the network of the A-record address happened (UTC date-time).\n- `dns.aaaa.value_last_change_date`: When the AAAA record text (`dns.aaaa.value`) last changed (UTC date-time).\n- `dns.aaaa.rcode_last_change_date`: When the response code of the AAAA lookup (`dns.aaaa.rcode`) last changed (UTC date-time).\n- `dns.aaaa.last_change_date`: When the asset's AAAA records last changed, in their text or their response code (UTC date-time).\n- `dns.caa.value_last_change_date`: When the CAA record text (`dns.caa.value`) last changed (UTC date-time).\n- `dns.caa.rcode_last_change_date`: When the response code of the CAA lookup (`dns.caa.rcode`) last changed (UTC date-time).\n- `dns.caa.last_change_date`: When the asset's CAA records last changed, in their text or their response code (UTC date-time).\n- `dns.cname.value_last_change_date`: When the CNAME record text (`dns.cname.value`) last changed (UTC date-time).\n- `dns.cname.rcode_last_change_date`: When the response code of the CNAME lookup (`dns.cname.rcode`) last changed (UTC date-time).\n- `dns.cname.last_change_date`: When the asset's CNAME records last changed, in their text or their response code (UTC date-time).\n- `dns.dnskey.value_last_change_date`: When the DNSKEY record text (`dns.dnskey.value`) last changed (UTC date-time).\n- `dns.dnskey.rcode_last_change_date`: When the response code of the DNSKEY lookup (`dns.dnskey.rcode`) last changed (UTC date-time).\n- `dns.dnskey.last_change_date`: When the asset's DNSKEY records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.value_last_change_date`: When the DS record text (`dns.ds.value`) last changed (UTC date-time).\n- `dns.ds.rcode_last_change_date`: When the response code of the DS lookup (`dns.ds.rcode`) last changed (UTC date-time).\n- `dns.ds.last_change_date`: When the asset's DS records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.records.key_tag`: The key tag (a number) of the DNSKEY that a DS record refers to.\n- `dns.mx.value_last_change_date`: When the MX record text (`dns.mx.value`) last changed (UTC date-time).\n- `dns.mx.rcode_last_change_date`: When the response code of the MX lookup (`dns.mx.rcode`) last changed (UTC date-time).\n- `dns.mx.last_change_date`: When the asset's MX records last changed, in their text or their response code (UTC date-time).\n- `dns.ns.value_last_change_date`: When the NS record text (`dns.ns.value`) last changed (UTC date-time).\n- `dns.ns.rcode_last_change_date`: When the response code of the NS lookup (`dns.ns.rcode`) last changed (UTC date-time).\n- `dns.ns.last_change_date`: When the asset's NS records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec.value_last_change_date`: When the NSEC record text (`dns.nsec.value`) last changed (UTC date-time).\n- `dns.nsec.rcode_last_change_date`: When the response code of the NSEC lookup (`dns.nsec.rcode`) last changed (UTC date-time).\n- `dns.nsec.last_change_date`: When the asset's NSEC records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec3.value_last_change_date`: When the NSEC3 record text (`dns.nsec3.value`) last changed (UTC date-time).\n- `dns.nsec3.rcode_last_change_date`: When the response code of the NSEC3 lookup (`dns.nsec3.rcode`) last changed (UTC date-time).\n- `dns.nsec3.last_change_date`: When the asset's NSEC3 records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.value_last_change_date`: When the RRSIG record text (`dns.rrsig.value`) last changed (UTC date-time).\n- `dns.rrsig.rcode_last_change_date`: When the response code of the RRSIG lookup (`dns.rrsig.rcode`) last changed (UTC date-time).\n- `dns.rrsig.last_change_date`: When the asset's RRSIG records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.signature_inception`: When an RRSIG signature becomes valid (UTC date-time).\n- `dns.rrsig.signature_expiration`: When an RRSIG signature expires (UTC date-time).\n- `dns.soa.value_last_change_date`: When the SOA record text (`dns.soa.value`) last changed (UTC date-time).\n- `dns.soa.rcode_last_change_date`: When the response code of the SOA lookup (`dns.soa.rcode`) last changed (UTC date-time).\n- `dns.soa.last_change_date`: When the asset's SOA records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.value_last_change_date`: When the SRV record text (`dns.srv.value`) last changed (UTC date-time).\n- `dns.srv.rcode_last_change_date`: When the response code of the SRV lookup (`dns.srv.rcode`) last changed (UTC date-time).\n- `dns.srv.last_change_date`: When the asset's SRV records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.records.port`: The port an SRV record points to.\n- `dns.txt.value_last_change_date`: When the TXT record text (`dns.txt.value`) last changed (UTC date-time).\n- `dns.txt.rcode_last_change_date`: When the response code of the TXT lookup (`dns.txt.rcode`) last changed (UTC date-time).\n- `dns.txt.last_change_date`: When the asset's TXT records last changed, in their text or their response code (UTC date-time).\n- `dns_check_date`: When the DNS records of the asset were last checked (UTC date-time).\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.port`: The port that the asset's TLS certificate was collected on, such as `443`.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl.validity.length`: The validity period of the certificate in seconds: 7,776,000 seconds are 90 days.\n- `ssl.extensions.signed_certificate_timestamps.timestamp`: When a Certificate Transparency log recorded the certificate, from a signed certificate timestamp (UTC date-time).\n- `ssl.extensions.signed_certificate_timestamps.version`: The version of a signed certificate timestamp; `0` stands for version 1.\n- `ssl_check_date`: When the TLS certificate of the asset was last checked (UTC date-time).\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the HTTP check, such as `301` or `200`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_check_date`: When the HTTP check of the asset last ran (UTC date-time).\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the web data scan, such as `301` or `200`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata.http.cookies.size`: The size of a cookie set in the web data scan, in bytes (name plus value).\n- `webdata.http.cookies.expires`: When a cookie set in the web data scan expires (UTC date-time); session cookies show `1969-12-31T23:59:59Z`.\n- `webdata.technology.stacks.confidence`: How certain the detection of a technology is, from 0 to 100; every sampled detection has `100`.\n- `webdata.technology.stacks.clean_version`: The major version of a detected technology as a whole number, such as `1` for version `1.0`.\n- `webdata_check_date`: When the web data scan of the asset, which collects the page content, headers and technologies, last ran (UTC date-time).\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn_date`: The registry allocation date that the ASN lookup reports for the IP address asset, as a date at midnight UTC.\n- `ipwhois.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was created (UTC date-time).\n- `ipwhois.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was last updated (UTC date-time).\n- `ipwhois.network.events.timestamp`: When an event on the network record of the IP address asset happened (UTC date-time).\n- `ipwhois.objects.events.timestamp`: When an event on a contact record linked to the network of the IP address asset happened (UTC date-time).\n- `ipwhois_check_date`: When the IP WHOIS record of an IP address asset was last checked (UTC date-time).\n- `ipwhois_last_change_date`: When a change in the IP WHOIS record of an IP address asset was last seen (UTC date-time).\n- `ipdns_check_date`: When the reverse DNS (PTR) records of an IP address asset were last checked (UTC date-time).\n- `ipdns_last_change_date`: When a change in the reverse DNS (PTR) records of an IP address asset was last seen (UTC date-time).\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `open_port_count`: The number of open ports found on the asset.\n- `open_ports`: The open port numbers found on the asset, such as `80`, `443` or `8080`.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_category_stats.count`: The number of active issues in that category on the asset.\n- `issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the asset.\n- `issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the asset.\n- `issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the asset.\n- `issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the asset.\n- `issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the asset.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `issue_count.active_by_severity.low`: The number of active issues of low severity on the asset.\n- `issue_count.active_by_severity.information`: The number of active issues of information severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `technology_count.by_category.count`: The number of technologies in that category on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity on the asset.\n- `vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity on the asset.\n- `vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity on the asset.\n- `vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) on the asset whose severity is `none`.\n- `vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) on the asset whose severity is `unknown`.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.count`: The number of active issues in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.count`: The number of distinct technologies in that category across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n**`eq`, `exists`** — 36 fields\n\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `fqdn.is_idn`: True when the host name is an internationalized domain name (IDN) with non-ASCII characters.\n- `fqdn.name.contains_confusable`: True when the name contains confusable characters that look like other letters, such as Cyrillic `а` for Latin `a`, a common trick in look-alike domains.\n- `fqdn.name.contains_hyphen`: True when the name (without the extension) contains a hyphen.\n- `fqdn.name.contains_letter`: True when the name (without the extension) contains a letter.\n- `fqdn.name.contains_number`: True when the name (without the extension) contains a digit.\n- `fqdn.domain.is_idn`: True when the registrable domain is an internationalized domain name (IDN) with non-ASCII characters.\n- `whois_privacy_enabled`: True when the platform flagged WHOIS privacy protection on the domain's registrant details; set on domain assets.\n- `ssl.signature.is_valid`: True when the asset's TLS certificate passed validation for the host; when false, `ssl.signature.invalid_reason` says why.\n- `ssl.signature.is_valid_chain`: A flag for whether the certificate chain of the asset's TLS certificate is valid. It was true on every sampled certificate, even one whose validation failed with `unable to get issuer certificate`.\n- `ssl.signature.is_self_signed`: True when the asset's TLS certificate is self-signed, that is signed by its own key rather than by a certificate authority.\n- `ssl.extensions.basic_constraints.is_ca`: True when the certificate is a certificate authority (CA) certificate, from its Basic Constraints extension.\n- `ssl.extensions.extended_key_usage.client_auth`: True when the Extended Key Usage extension allows TLS client authentication.\n- `ssl.extensions.extended_key_usage.server_auth`: True when the Extended Key Usage extension allows TLS server authentication, as website certificates need.\n- `ssl.extensions.key_usage.content_commitment`: True when the Key Usage extension allows the certificate's key to be used for content commitment (non-repudiation).\n- `ssl.extensions.key_usage.crl_sign`: True when the Key Usage extension allows the certificate's key to be used for signing certificate revocation lists (CRL sign).\n- `ssl.extensions.key_usage.data_encipherment`: True when the Key Usage extension allows the certificate's key to be used for data encipherment.\n- `ssl.extensions.key_usage.digital_signature`: True when the Key Usage extension allows the certificate's key to be used for digital signatures.\n- `ssl.extensions.key_usage.key_agreement`: True when the Key Usage extension allows the certificate's key to be used for key agreement.\n- `ssl.extensions.key_usage.key_cert_sign`: True when the Key Usage extension allows the certificate's key to be used for signing other certificates (certificate sign).\n- `ssl.extensions.key_usage.key_encipherment`: True when the Key Usage extension allows the certificate's key to be used for key encipherment.\n- `ssl.has_expired`: True when the asset's TLS certificate is past its end date.\n- `http.external_domain_redirection`: True when the HTTP check ended on a different registrable domain than it started on.\n- `http.external_fqdn_redirection`: True when the HTTP check ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.html.inspect_disabled`: A flag of the web data scan that marks pages whose inspection was disabled; it was `false` on every sampled asset.\n- `webdata.html.html_meta.no_index_status`: True when the scanned page asks search engines not to index it (a `noindex` robots directive).\n- `webdata.http.external_domain_redirection`: True when the web data scan ended on a different registrable domain than it started on.\n- `webdata.http.external_fqdn_redirection`: True when the web data scan ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.http.cookies.secure`: True when a cookie set in the web data scan is sent over HTTPS only (Secure attribute).\n- `webdata.http.cookies.http_only`: True when scripts on the page cannot read a cookie set in the web data scan (HttpOnly attribute).\n- `webdata.http.cookies.session`: True when a cookie set in the web data scan is a session cookie, deleted when the browser closes.\n- `is_parked`: True when the asset is parked; Inventory marks it with a P badge whose tooltip shows where it redirects.\n\n**`eq`, `in`, `exists`** — 8 fields\n\n- `asset_type`: The asset type: `domain`, `subdomain`, `ip` or `website`.\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `dns.dnskey.records.key_type`: The role of a DNSKEY: `ZSK` (zone-signing key), `KSK` (key-signing key) or `KSK_REVOKED` (revoked key-signing key).\n- `dns.dnskey.records.algorithm`: The DNSSEC algorithm of a DNSKEY, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.algorithm`: The DNSSEC algorithm of the key that a DS record refers to, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.digest_type`: The hash used for a DS record's digest: `SHA1`, `SHA256`, `SHA384`, `GOST` or `NULL`.\n- `dns.rrsig.algorithm`: The DNSSEC algorithm of an RRSIG signature, such as `ECDSAP256SHA256` or `RSASHA256`.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `website.parent_asset.type`: The asset type of the website's parent asset, such as `subdomain`.\n\nSortable fields:\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `website_count`: The number of website assets (`host:port`) in your inventory that belong to this asset.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `open_port_count`: The number of open ports found on the asset.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `deleted_asset_count` | integer |  |\n\n> The saved example **Request template · 38 of 740 filters** holds this body with 38 of the 740 filters (the first 10 of each operator group); the full list is above (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"postman-docs-test.deepinfo.com\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Asset Enable Discovery",
              "id": "1d2f6c3d-0839-57f9-8964-9abbb584c2f3",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/search:enable-discovery?enabled=false",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "search:enable-discovery"
                  ],
                  "query": [
                    {
                      "key": "enabled",
                      "value": "false",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Enable Discovery API**\n\nEnables (`enabled=true`) or disables discovery for every asset matching `filters`.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 517 fields\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `tags`: Your own labels on the asset, such as a business unit or an environment; each tag is 3 to 100 characters long.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.name.unicode`: The host name without its extension, in Unicode: `acme` for `acme.example`, `www.acme` for `www.acme.example`.\n- `fqdn.name.latinized`: Latin-letter spellings of a name that has non-Latin or accented letters, so a search for `istanbul` also finds names written with `İ`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_sub.unicode`: The second-level part of a two-part extension, such as `co` in `co.uk`; empty for single-part extensions.\n- `website.path`: The URL path of a website asset, such as `/`.\n- `website.scheme`: The URL scheme of a website asset, such as `http`.\n- `website.parent_asset.id`: The ID of the domain or subdomain asset that a website asset belongs to.\n- `website.parent_asset.name`: The name of the domain or subdomain asset that a website asset belongs to.\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.name`: The registrant's name in WHOIS; often a privacy placeholder such as `redacted for privacy`.\n- `whois.registrant.country`: The registrant's country in WHOIS, as a two-letter code in lower case such as `us`.\n- `whois.registrant.state`: The registrant's state or province in WHOIS.\n- `whois.registrant.city`: The registrant's city in WHOIS.\n- `whois.registrant.street`: The registrant's street address in WHOIS.\n- `whois.registrant.postal_code`: The registrant's postal code in WHOIS.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `whois_registrant_email_historical`: Every registrant e-mail address seen for the domain over time, the current one included.\n- `whois_normalized.registrar`: The registrar reduced to a short normalized name, such as `godaddy` or `gandi`, so the same registrar matches across spellings.\n- `whois_normalized.registrant.email`: The registrant e-mail address after WHOIS normalization.\n- `whois_normalized.registrant.email_real`: Another normalized registrant e-mail field, set on fewer domains than `whois_normalized.registrant.email`; in the samples it is set only where `whois_privacy_enabled` is false, with the same address.\n- `whois_normalized.registrant.email_domain_apex`: The registrable domain of the registrant e-mail address: `acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.email_fqdn_apex`: The full host name after the `@` of the registrant e-mail address: `mail.acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.organization`: The registrant organization cleaned up across registrars: lower case, with spaces and punctuation removed, such as `domainsbyproxyllc`.\n- `whois_normalized.registrant.phone`: The registrant phone number reduced to its digits, such as `14805551234`.\n- `whois_last_change_data`: The WHOIS fields that changed in the last change seen, as field paths such as `whois.update_date` or `whois.domain_status`.\n- `dns.a.value`: The asset's current A records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.a.value_previous`: The asset's A records as they were before the last change, in the same text form as `dns.a.value`.\n- `dns.a.rcode`: The DNS response code returned for the asset's A lookup, such as `NOERROR`.\n- `dns.a.rcode_previous`: The DNS response code of the A lookup before it last changed.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.entities`: The handles of the registry contacts and organizations linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, when it is kept.\n- `dns.a.ip_addresses.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the A-record address.\n- `dns.a.ip_addresses.raw`: The raw IP WHOIS response for the A-record address, when it is kept; empty on every sampled asset.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.a.ip_addresses.network.start_address`: The first address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.end_address`: The last address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.handle`: The registry handle of the network that contains the A-record address, such as `NET-192-0-2-0-1`.\n- `dns.a.ip_addresses.network.ip_version`: The IP version of the network that contains the A-record address: `v4` or `v6`.\n- `dns.a.ip_addresses.network.links`: Links to the registry record of the network that contains the A-record address, such as its RDAP and WHOIS URLs.\n- `dns.a.ip_addresses.network.parent_handle`: The handle of the larger network block from which the network of the A-record address was allocated.\n- `dns.a.ip_addresses.network.raw`: The raw RDAP network object for the A-record address, when it is kept.\n- `dns.a.ip_addresses.network.status`: The registry status of the network that contains the A-record address, such as `active`.\n- `dns.a.ip_addresses.network.type`: The registry's allocation type for the network that contains the A-record address, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `dns.a.ip_addresses.network.notices.title`: The title of a notice the registry attached to the network record of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.network.notices.description`: The text of a notice the registry attached to the network record of the A-record address.\n- `dns.a.ip_addresses.network.notices.links`: Links given in a notice on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.title`: The title of a remark on the network record of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.network.remarks.description`: The text of a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.links`: Links given in a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.events.action`: An event in the history of the network record of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.network.events.actor`: Who performed an event on the network record of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the A-record address, such as `abuse`.\n- `dns.a.ip_addresses.objects.contact.email.value`: An e-mail address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.value`: A postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the A-record address, such as `voice` or `work`.\n- `dns.a.ip_addresses.objects.contact.phone.value`: A phone number of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.kind`: What kind of contact is linked to the network of the A-record address: `org`, `group` or `individual`.\n- `dns.a.ip_addresses.objects.contact.name`: The name of a contact or organization linked to the network of the A-record address, such as `Abuse` or a company name.\n- `dns.a.ip_addresses.objects.contact.role`: The role given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.title`: The title given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.entities`: Handles of further entities listed under a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.events.action`: An event in the history of a contact record linked to the network of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.objects.events.actor`: Who performed an event on a contact record linked to the network of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.events_actor`: Events in which a contact linked to the network of the A-record address is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `dns.a.ip_addresses.objects.handle`: The registry handle of a contact or organization linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.links`: Links to the registry record of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.title`: The title of a notice on a contact record linked to the network of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.objects.notices.description`: The text of a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.links`: Links given in a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.raw`: The raw RDAP object of a contact linked to the network of the A-record address, when it is kept.\n- `dns.a.ip_addresses.objects.remarks.title`: The title of a remark on a contact record linked to the network of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.objects.remarks.description`: The text of a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.roles`: The roles of a contact for the network of the A-record address, such as `registrant`, `abuse` or `technical`.\n- `dns.a.ip_addresses.objects.status`: The registry status of a contact linked to the network of the A-record address, such as `validated`.\n- `dns.a.ip_history`: Every IPv4 address seen in the asset's A records over time, the current ones included.\n- `dns.aaaa.value`: The asset's current AAAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.aaaa.value_previous`: The asset's AAAA records as they were before the last change, in the same text form as `dns.aaaa.value`.\n- `dns.aaaa.rcode`: The DNS response code returned for the asset's AAAA lookup, such as `NOERROR`.\n- `dns.aaaa.rcode_previous`: The DNS response code of the AAAA lookup before it last changed.\n- `dns.aaaa.ip_addresses`: The IPv6 addresses in the asset's AAAA records.\n- `dns.caa.value`: The asset's current CAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.caa.value_previous`: The asset's CAA records as they were before the last change, in the same text form as `dns.caa.value`.\n- `dns.caa.rcode`: The DNS response code returned for the asset's CAA lookup, such as `NOERROR`.\n- `dns.caa.rcode_previous`: The DNS response code of the CAA lookup before it last changed.\n- `dns.caa.issue_fqdns`: The certificate authorities allowed to issue certificates for the name, from the CAA `issue` tags, such as `fernhill.example` or `kestrel.example`.\n- `dns.caa.issuewild_fqdns`: The certificate authorities allowed to issue wildcard certificates for the name, from the CAA `issuewild` tags.\n- `dns.caa.iodef_emails`: The e-mail addresses from the CAA `iodef` tags, where certificate authorities report requests that break the CAA policy.\n- `dns.cname.value`: The asset's current CNAME records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.cname.value_previous`: The asset's CNAME records as they were before the last change, in the same text form as `dns.cname.value`.\n- `dns.cname.rcode`: The DNS response code returned for the asset's CNAME lookup, such as `NOERROR`.\n- `dns.cname.rcode_previous`: The DNS response code of the CNAME lookup before it last changed.\n- `dns.cname.canonical_fqdns`: The host names the asset's CNAME records point to (the alias targets).\n- `dns.dnskey.value`: The asset's current DNSKEY records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.dnskey.value_previous`: The asset's DNSKEY records as they were before the last change, in the same text form as `dns.dnskey.value`.\n- `dns.dnskey.rcode`: The DNS response code returned for the asset's DNSKEY lookup, such as `NOERROR`.\n- `dns.dnskey.rcode_previous`: The DNS response code of the DNSKEY lookup before it last changed.\n- `dns.dnskey.records.public_key`: The public key of a DNSKEY record, Base64-encoded and split into space-separated groups as in the zone-file text.\n- `dns.ds.value`: The asset's current DS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ds.value_previous`: The asset's DS records as they were before the last change, in the same text form as `dns.ds.value`.\n- `dns.ds.rcode`: The DNS response code returned for the asset's DS lookup, such as `NOERROR`.\n- `dns.ds.rcode_previous`: The DNS response code of the DS lookup before it last changed.\n- `dns.ds.records.digest`: The digest of a DS record, the hash of the DNSKEY it refers to.\n- `dns.mx.value`: The asset's current MX records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.mx.value_previous`: The asset's MX records as they were before the last change, in the same text form as `dns.mx.value`.\n- `dns.mx.rcode`: The DNS response code returned for the asset's MX lookup, such as `NOERROR`.\n- `dns.mx.rcode_previous`: The DNS response code of the MX lookup before it last changed.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns.mx.domains`: The registrable domains of the asset's mail servers, such as `acme.example`.\n- `dns.ns.value`: The asset's current NS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ns.value_previous`: The asset's NS records as they were before the last change, in the same text form as `dns.ns.value`.\n- `dns.ns.rcode`: The DNS response code returned for the asset's NS lookup, such as `NOERROR`.\n- `dns.ns.rcode_previous`: The DNS response code of the NS lookup before it last changed.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.ns.domains`: The registrable domains of the asset's name servers, such as `acme.example`.\n- `dns.nsec.value`: The asset's current NSEC records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec.value_previous`: The asset's NSEC records as they were before the last change, in the same text form as `dns.nsec.value`.\n- `dns.nsec.rcode`: The DNS response code returned for the asset's NSEC lookup, such as `NOERROR`.\n- `dns.nsec.rcode_previous`: The DNS response code of the NSEC lookup before it last changed.\n- `dns.nsec.records.next_domain`: The next name in the zone, from an NSEC record.\n- `dns.nsec.records.record_types`: The record types that exist at the name, from an NSEC record's type list, such as `A`, `NS` or `SOA`.\n- `dns.nsec3.value`: The asset's current NSEC3 records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec3.value_previous`: The asset's NSEC3 records as they were before the last change, in the same text form as `dns.nsec3.value`.\n- `dns.nsec3.rcode`: The DNS response code returned for the asset's NSEC3 lookup, such as `NOERROR`.\n- `dns.nsec3.rcode_previous`: The DNS response code of the NSEC3 lookup before it last changed.\n- `dns.nsec3.records.next_domain_hashed`: The hashed next name in the zone, from an NSEC3 record.\n- `dns.nsec3.records.record_types`: The record types that exist at the name, from an NSEC3 record's type list, such as `A` or `MX`.\n- `dns.rrsig.value`: The asset's current RRSIG records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.rrsig.value_previous`: The asset's RRSIG records as they were before the last change, in the same text form as `dns.rrsig.value`.\n- `dns.rrsig.rcode`: The DNS response code returned for the asset's RRSIG lookup, such as `NOERROR`.\n- `dns.rrsig.rcode_previous`: The DNS response code of the RRSIG lookup before it last changed.\n- `dns.rrsig.type_covered`: The record type that an RRSIG signature covers, such as `A` or `SOA`.\n- `dns.rrsig.signature`: The signature data of an RRSIG record, Base64-encoded.\n- `dns.soa.value`: The asset's current SOA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.soa.value_previous`: The asset's SOA records as they were before the last change, in the same text form as `dns.soa.value`.\n- `dns.soa.rcode`: The DNS response code returned for the asset's SOA lookup, such as `NOERROR`.\n- `dns.soa.rcode_previous`: The DNS response code of the SOA lookup before it last changed.\n- `dns.soa.mnames`: The MNAME of the SOA record: the primary name server of the zone, such as `ns1.acme.example`.\n- `dns.soa.rnames`: The RNAME of the SOA record, the zone administrator's mailbox in DNS form: `hostmaster.acme.example` stands for the mailbox `hostmaster` at `acme.example`.\n- `dns.soa.rname_emails`: The RNAME of the SOA record written as an e-mail address, such as `user@acme.example`.\n- `dns.srv.value`: The asset's current SRV records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.srv.value_previous`: The asset's SRV records as they were before the last change, in the same text form as `dns.srv.value`.\n- `dns.srv.rcode`: The DNS response code returned for the asset's SRV lookup, such as `NOERROR`.\n- `dns.srv.rcode_previous`: The DNS response code of the SRV lookup before it last changed.\n- `dns.srv.records.service`: The service named in an SRV record (the `_service` part of its name).\n- `dns.srv.records.protocol`: The protocol named in an SRV record (the `_proto` part of its name, such as TCP or UDP).\n- `dns.srv.records.target`: The host name an SRV record points to.\n- `dns.txt.value`: The asset's current TXT records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.txt.value_previous`: The asset's TXT records as they were before the last change, in the same text form as `dns.txt.value`.\n- `dns.txt.rcode`: The DNS response code returned for the asset's TXT lookup, such as `NOERROR`.\n- `dns.txt.rcode_previous`: The DNS response code of the TXT lookup before it last changed.\n- `dns.txt.values`: Each TXT record of the asset as its quoted text, such as `\"v=spf1 include:_spf.acme.example ~all\"`; the quotes are part of the value.\n- `dns.txt.spf_list.value`: The text of an SPF record (a TXT record that starts with `v=spf1`), quoted as in `dns.txt.values`.\n- `dns.txt.spf_list.allowed_domains`: The registrable domains that an SPF record refers to, such as `acme.example` for `include:_spf.acme.example`.\n- `dns.txt.spf_list.allowed_ips`: The IP addresses and ranges that an SPF record authorizes to send mail (its `ip4:` and `ip6:` entries).\n- `dns.txt.verifications.value`: The text of a site-verification TXT record, quoted as in `dns.txt.values`.\n- `dns.txt.verifications.domain`: The domain of the service a verification record is for, such as `acme.example`, `fernhill.example` or `kestrel.example`.\n- `dns.txt.verifications.name`: The name of a verification record, such as `site-verification` or `domain-verification`.\n- `dns_last_change_data`: The DNS fields that changed in the last change seen, as field paths such as `dns.soa.mnames`.\n- `ssl.target`: The host name that the asset's TLS certificate was collected from, normally the asset itself.\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.md5`: The MD5 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha256`: The SHA-256 fingerprint of the asset's TLS certificate, as lower-case hex; one fingerprint identifies one certificate.\n- `ssl.issuer.common_name`: The common name (CN) of the certificate authority that issued the asset's TLS certificate, such as `WE1` or `YE2`.\n- `ssl.issuer.country`: The country (C) of the certificate authority that issued the asset's TLS certificate, as a two-letter code such as `US`.\n- `ssl.issuer.state`: The state or province (ST) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.locality`: The locality or city (L) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.organization`: The organization (O) of the certificate authority that issued the asset's TLS certificate, such as `Let's Encrypt` or `Google Trust Services`.\n- `ssl.issuer.organizational_unit`: The organizational unit (OU) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer_dn`: The full distinguished name of the issuer of the asset's TLS certificate, as one string such as `CN=WE1,O=Google Trust Services,C=US`.\n- `ssl.subject.common_name`: The common name (CN) of the subject (holder) of the asset's TLS certificate, usually a host name such as `acme.example`.\n- `ssl.subject.country`: The country (C) of the subject (holder) of the asset's TLS certificate, as a two-letter code.\n- `ssl.subject.state`: The state or province (ST) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.locality`: The locality or city (L) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organizational_unit`: The organizational unit (OU) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject_dn`: The full distinguished name of the subject of the asset's TLS certificate, such as `CN=acme.example`; one that starts with `CN=*.` belongs to a wildcard certificate.\n- `ssl.signature.value`: The signature of the asset's TLS certificate, Base64-encoded.\n- `ssl.signature.invalid_reason`: Why certificate validation failed, such as a host name mismatch or `unable to get issuer certificate`.\n- `ssl.signature.algorithm.name`: The hash algorithm of the signature on the asset's TLS certificate, such as `sha256` or `sha384`.\n- `ssl.signature.algorithm.oid`: The object identifier (OID) of the signature algorithm, such as `1.2.840.113549.1.1.11` (SHA-256 with RSA) or `1.2.840.10045.4.3.2` (ECDSA with SHA-256).\n- `ssl.extensions.authority_key_id`: The Authority Key Identifier extension, which identifies the issuer's key, Base64-encoded.\n- `ssl.extensions.certificate_policies`: The policy OIDs in the Certificate Policies extension, such as `2.23.140.1.2.1` (domain validated).\n- `ssl.extensions.signed_certificate_timestamps.log_id`: The ID of the Certificate Transparency log that issued a signed certificate timestamp (SCT) for the certificate, Base64-encoded.\n- `ssl.extensions.signed_certificate_timestamps.signature`: The log's signature on a signed certificate timestamp, Base64-encoded.\n- `ssl.extensions.subject_alt_name.dns_names`: The host names in the certificate's Subject Alternative Name extension, including wildcard names such as `*.acme.example`.\n- `ssl.extensions.subject_key_id`: The Subject Key Identifier extension, which identifies the certificate's own key, Base64-encoded.\n- `ssl.subject_key_info.fingerprint.hash_algorithm`: The hash algorithm used for `ssl.subject_key_info.fingerprint.value`, such as `sha256` or `sha384`.\n- `ssl.subject_key_info.fingerprint.value`: A hex fingerprint recorded under the certificate's subject key information, made with the hash in `hash_algorithm`. In the samples it equals `ssl.fingerprint.sha256` when that hash is SHA-256.\n- `ssl.subject_key_info.key_algorithm.name`: The algorithm of the certificate's public key, such as `RSA` or `ECDSA`.\n- `ssl.version.name`: The X.509 version of the certificate, such as `v3`.\n- `ssl.version.value`: The X.509 version as encoded in the certificate, counted from zero: `2` means `v3`.\n- `ssl.tbs_fingerprint`: A SHA-256 fingerprint (hex) of the certificate's to-be-signed part, the certificate content without its signature.\n- `ssl.certificate`: The whole certificate, Base64-encoded (a PEM body without the header and footer lines).\n- `ssl.fqdn_list`: The host names the certificate covers, with the `*.` of wildcard names removed and duplicates merged, so `*.acme.example` and `acme.example` both give `acme.example`.\n- `ssl_last_change_data`: The certificate fields that changed in the last change seen, as field paths such as `ssl.validity.end_date`.\n- `http.requested_url`: The URL the HTTP check started from, such as `http://acme.example`.\n- `http.requested_domain`: The registrable domain of the URL the HTTP check started from.\n- `http.requested_fqdn`: The host name of the URL the HTTP check started from.\n- `http.final_url`: The URL the HTTP check ended on after following all redirects.\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.redirection_history.url`: A URL in the redirect chain of the HTTP check, listed in the order visited.\n- `http.headers.accept`: The `Accept` header, when it was returned in the HTTP check. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the HTTP check. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `http.headers.accept_language`: The `Accept-Language` header, when it was returned in the HTTP check. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the HTTP check; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the HTTP check; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the HTTP check; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the HTTP check; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the HTTP check; it lists the response headers that scripts from other origins may read (CORS).\n- `http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the HTTP check; it says how many seconds browsers may cache a CORS preflight result.\n- `http.headers.alt_svc`: The `Alt-Svc` header returned in the HTTP check; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `http.headers.authorization`: The `Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `http.headers.cache_control`: The `Cache-Control` header returned in the HTTP check; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the HTTP check; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `http.headers.content_disposition`: The `Content-Disposition` header returned in the HTTP check; it says whether the content is shown in the browser or downloaded as a file.\n- `http.headers.content_encoding`: The `Content-Encoding` header returned in the HTTP check; it names the compression applied to the response body, for example `gzip` or `br`.\n- `http.headers.content_language`: The `Content-Language` header returned in the HTTP check; it gives the language of the content, for example `en` or `tr`.\n- `http.headers.content_length`: The `Content-Length` header returned in the HTTP check; it gives the size of the response body in bytes.\n- `http.headers.content_range`: The `Content-Range` header returned in the HTTP check; it says which part of the full body a partial response holds.\n- `http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the HTTP check; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `http.headers.content_type`: The `Content-Type` header returned in the HTTP check; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `http.headers.cookie`: The `Cookie` header, when it was returned in the HTTP check. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the HTTP check; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the HTTP check; it controls whether the page shares its browsing context with cross-origin windows.\n- `http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the HTTP check; it controls which sites may load the resource.\n- `http.headers.date`: The `Date` header returned in the HTTP check; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `http.headers.early_data`: The `Early-Data` header, when it was returned in the HTTP check. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `http.headers.expect_ct`: The `Expect-CT` header returned in the HTTP check; it is a deprecated header about Certificate Transparency enforcement.\n- `http.headers.expires`: The `Expires` header returned in the HTTP check; it gives the date after which the response counts as stale, in HTTP date format.\n- `http.headers.feature_policy`: The `Feature-Policy` header returned in the HTTP check; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `http.headers.host`: The `Host` header, when it was returned in the HTTP check. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the HTTP check. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the HTTP check. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `http.headers.last_modified`: The `Last-Modified` header returned in the HTTP check; it gives the time the server says the resource last changed, in HTTP date format.\n- `http.headers.origin_isolation`: The `Origin-Isolation` header returned in the HTTP check; it is an experimental header that asks browsers to isolate the site's origin.\n- `http.headers.others.name`: The name of a header returned in the HTTP check that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `http.headers.others.value`: The value of a header listed in `headers.others` for the HTTP check.\n- `http.headers.permission_policy`: The `Permission-Policy` header returned in the HTTP check; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `http.headers.permissions_policy`: The `Permissions-Policy` header returned in the HTTP check; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `http.headers.pragma`: The `Pragma` header returned in the HTTP check; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the HTTP check; it tells a client how to authenticate to a proxy.\n- `http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the HTTP check; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `http.headers.range`: The `Range` header, when it was returned in the HTTP check. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `http.headers.referer`: The `Referer` header, when it was returned in the HTTP check. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `http.headers.referrer_policy`: The `Referrer-Policy` header returned in the HTTP check; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the HTTP check. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `http.headers.server`: The `Server` header returned in the HTTP check; it names the server software the site reports, for example `nginx` or `Apache`.\n- `http.headers.set_cookie`: The `Set-Cookie` header returned in the HTTP check; it sets cookies, with their attributes.\n- `http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the HTTP check; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `http.headers.te`: The `TE` header, when it was returned in the HTTP check. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the HTTP check; it says how the body is transferred, for example `chunked`.\n- `http.headers.upgrade`: The `Upgrade` header returned in the HTTP check; it offers or asks for a switch to another protocol.\n- `http.headers.user_agent`: The `User-Agent` header, when it was returned in the HTTP check. It is normally a request header (the client software), so it is rarely set.\n- `http.headers.vary`: The `Vary` header returned in the HTTP check; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the HTTP check; it tells a client how to authenticate, usually with a `401` response.\n- `http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the HTTP check; it stops browsers from guessing the content type when set to `nosniff`.\n- `http.headers.x_download_options`: The `X-Download-Options` header returned in the HTTP check; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `http.headers.x_frame_options`: The `X-Frame-Options` header returned in the HTTP check; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the HTTP check; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `http.headers.x_powered_by`: The `X-Powered-By` header returned in the HTTP check; it names the technology the server reports running on, for example `Express`.\n- `http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the HTTP check; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `http.cookies.name`: The name of a cookie set in the HTTP check.\n- `http.cookies.value`: The value of a cookie set in the HTTP check.\n- `http.html.source_code_hash`: A SHA-256 hash of the page source returned in the HTTP check; the same hash means the same source.\n- `http_last_change_data`: The HTTP check fields that changed in the last change seen, as field paths such as `http.html.source_code_hash`.\n- `webdata.requested_url`: The URL the web data scan started from, such as `http://acme.example`.\n- `webdata.requested_domain`: The registrable domain of the URL the web data scan started from.\n- `webdata.requested_fqdn`: The host name of the URL the web data scan started from.\n- `webdata.html.internal_links_fqdns`: The host names of links on the scanned page that stay within the site's own domain, such as other subdomains.\n- `webdata.html.external_links_domains`: The registrable domains of links on the scanned page that point to other domains, such as `kestrel.example`.\n- `webdata.html.external_links_fqdns`: The host names of links on the scanned page that point to other domains, such as `www.kestrel.example`.\n- `webdata.html.external_links`: The full URLs of links on the scanned page that point to other domains.\n- `webdata.html.script_links`: The URLs of the scripts the scanned page loads.\n- `webdata.html.iframe_links`: The URLs of the frames (iframes) embedded in the scanned page.\n- `webdata.html.trackers.name`: The name of an analytics or advertising tracker found on the scanned page, such as `google_adsense` or `google_tag_manager`.\n- `webdata.html.trackers.values`: The IDs found for a tracker, such as a Google Analytics ID that starts with `G-` or `UA-`.\n- `webdata.html.emails`: The e-mail addresses found on the scanned page.\n- `webdata.html.emails_internal`: The e-mail addresses found on the scanned page that belong to the site's own domain.\n- `webdata.html.source_code_hash`: A SHA-256 hash of the page source in the web data scan; the same hash means the same source.\n- `webdata.html.content_hash`: A SHA-256 hash of the page content in the web data scan, kept apart from `source_code_hash`, the hash of the raw source.\n- `webdata.html.content_top_keywords`: The most frequent words in the text of the scanned page.\n- `webdata.html.favicon_links`: The URLs of the icons the scanned page declares, such as its favicon and touch icons.\n- `webdata.html.html_meta.name`: The site or application name declared in the scanned page's metadata.\n- `webdata.html.html_meta.description`: The meta description of the scanned page.\n- `webdata.html.html_meta.language`: The language the scanned page declares, such as `en`, `tr` or `en-US`.\n- `webdata.html.html_meta.language_alternatives`: The languages of the alternative versions the scanned page links to, such as `en` or `ar`.\n- `webdata.html.html_meta.keywords`: The keywords listed in the keywords meta tag of the scanned page.\n- `webdata.html.html_meta.encoding`: The character encoding the scanned page declares, such as `utf-8`.\n- `webdata.html.html_meta.canonical_url`: The canonical URL the scanned page declares.\n- `webdata.html.html_meta.title`: The title of the scanned page.\n- `webdata.favicon.url`: The URL of a site icon (favicon) recorded by the web data scan.\n- `webdata.favicon.hash`: A SHA-256 hash of a site icon; the same hash means the same icon.\n- `webdata.http.final_url`: The URL the web data scan ended on after following all redirects.\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.redirection_history.url`: A URL in the redirect chain of the web data scan, listed in the order visited.\n- `webdata.http.redirection_history.method`: How a step of the web data scan's redirect chain was made; `http-header` (a redirect sent in the HTTP response) is the value in the samples.\n- `webdata.http.headers.accept`: The `Accept` header, when it was returned in the web data scan. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the web data scan. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_language`: The `Accept-Language` header, when it was returned in the web data scan. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `webdata.http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the web data scan; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `webdata.http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the web data scan; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `webdata.http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the web data scan; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `webdata.http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the web data scan; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `webdata.http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the web data scan; it lists the response headers that scripts from other origins may read (CORS).\n- `webdata.http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the web data scan; it says how many seconds browsers may cache a CORS preflight result.\n- `webdata.http.headers.alt_svc`: The `Alt-Svc` header returned in the web data scan; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `webdata.http.headers.authorization`: The `Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `webdata.http.headers.cache_control`: The `Cache-Control` header returned in the web data scan; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `webdata.http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the web data scan; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `webdata.http.headers.content_disposition`: The `Content-Disposition` header returned in the web data scan; it says whether the content is shown in the browser or downloaded as a file.\n- `webdata.http.headers.content_encoding`: The `Content-Encoding` header returned in the web data scan; it names the compression applied to the response body, for example `gzip` or `br`.\n- `webdata.http.headers.content_language`: The `Content-Language` header returned in the web data scan; it gives the language of the content, for example `en` or `tr`.\n- `webdata.http.headers.content_length`: The `Content-Length` header returned in the web data scan; it gives the size of the response body in bytes.\n- `webdata.http.headers.content_range`: The `Content-Range` header returned in the web data scan; it says which part of the full body a partial response holds.\n- `webdata.http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the web data scan; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `webdata.http.headers.content_type`: The `Content-Type` header returned in the web data scan; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `webdata.http.headers.cookie`: The `Cookie` header, when it was returned in the web data scan. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `webdata.http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the web data scan; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `webdata.http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the web data scan; it controls whether the page shares its browsing context with cross-origin windows.\n- `webdata.http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the web data scan; it controls which sites may load the resource.\n- `webdata.http.headers.date`: The `Date` header returned in the web data scan; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `webdata.http.headers.early_data`: The `Early-Data` header, when it was returned in the web data scan. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `webdata.http.headers.expect_ct`: The `Expect-CT` header returned in the web data scan; it is a deprecated header about Certificate Transparency enforcement.\n- `webdata.http.headers.expires`: The `Expires` header returned in the web data scan; it gives the date after which the response counts as stale, in HTTP date format.\n- `webdata.http.headers.feature_policy`: The `Feature-Policy` header returned in the web data scan; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `webdata.http.headers.host`: The `Host` header, when it was returned in the web data scan. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `webdata.http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the web data scan. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `webdata.http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the web data scan. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `webdata.http.headers.last_modified`: The `Last-Modified` header returned in the web data scan; it gives the time the server says the resource last changed, in HTTP date format.\n- `webdata.http.headers.origin_isolation`: The `Origin-Isolation` header returned in the web data scan; it is an experimental header that asks browsers to isolate the site's origin.\n- `webdata.http.headers.others.name`: The name of a header returned in the web data scan that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `webdata.http.headers.others.value`: The value of a header listed in `headers.others` for the web data scan.\n- `webdata.http.headers.permission_policy`: The `Permission-Policy` header returned in the web data scan; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `webdata.http.headers.permissions_policy`: The `Permissions-Policy` header returned in the web data scan; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `webdata.http.headers.pragma`: The `Pragma` header returned in the web data scan; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `webdata.http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the web data scan; it tells a client how to authenticate to a proxy.\n- `webdata.http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `webdata.http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the web data scan; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `webdata.http.headers.range`: The `Range` header, when it was returned in the web data scan. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `webdata.http.headers.referer`: The `Referer` header, when it was returned in the web data scan. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `webdata.http.headers.referrer_policy`: The `Referrer-Policy` header returned in the web data scan; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `webdata.http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `webdata.http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the web data scan. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `webdata.http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `webdata.http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the web data scan. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `webdata.http.headers.server`: The `Server` header returned in the web data scan; it names the server software the site reports, for example `nginx` or `Apache`.\n- `webdata.http.headers.set_cookie`: The `Set-Cookie` header returned in the web data scan; it sets cookies, with their attributes.\n- `webdata.http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the web data scan; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `webdata.http.headers.te`: The `TE` header, when it was returned in the web data scan. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `webdata.http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the web data scan; it says how the body is transferred, for example `chunked`.\n- `webdata.http.headers.upgrade`: The `Upgrade` header returned in the web data scan; it offers or asks for a switch to another protocol.\n- `webdata.http.headers.user_agent`: The `User-Agent` header, when it was returned in the web data scan. It is normally a request header (the client software), so it is rarely set.\n- `webdata.http.headers.vary`: The `Vary` header returned in the web data scan; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `webdata.http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the web data scan; it tells a client how to authenticate, usually with a `401` response.\n- `webdata.http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the web data scan; it stops browsers from guessing the content type when set to `nosniff`.\n- `webdata.http.headers.x_download_options`: The `X-Download-Options` header returned in the web data scan; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `webdata.http.headers.x_frame_options`: The `X-Frame-Options` header returned in the web data scan; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `webdata.http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the web data scan; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `webdata.http.headers.x_powered_by`: The `X-Powered-By` header returned in the web data scan; it names the technology the server reports running on, for example `Express`.\n- `webdata.http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the web data scan; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `webdata.http.cookies.name`: The name of a cookie set in the web data scan.\n- `webdata.http.cookies.value`: The value of a cookie set in the web data scan.\n- `webdata.http.cookies.domain`: The domain a cookie set in the web data scan applies to, such as `.acme.example`.\n- `webdata.http.cookies.path`: The path a cookie set in the web data scan applies to, such as `/`.\n- `webdata.http.cookies.same_party`: The SameParty attribute of a cookie set in the web data scan; in the samples it always holds the same value as `same_site`, such as `Lax` or `None`.\n- `webdata.http.cookies.priority`: The Priority attribute of a cookie set in the web data scan (`Low`, `Medium` or `High` in Chromium-based browsers).\n- `webdata.http.cookies.same_site`: The SameSite attribute of a cookie set in the web data scan, such as `Lax`, `Strict` or `None`.\n- `webdata.technology.stacks.slug`: A short identifier of a technology detected on the site, such as `iis` or `windows-server`.\n- `webdata.technology.stacks.name`: The name of a technology detected on the site, such as `IIS` or `Microsoft ASP.NET`.\n- `webdata.technology.stacks.icon`: The file name of a detected technology's icon, such as `acme.png`.\n- `webdata.technology.stacks.website`: The website of a detected technology's vendor or project.\n- `webdata.technology.stacks.cpe`: The CPE identifier of a detected technology, such as `cpe:/a:acme:acme-portal`, used to match it to known vulnerabilities.\n- `webdata.technology.stacks.version`: The detected version of a technology, such as `1.0`.\n- `webdata.technology.stacks.categories`: The categories of a detected technology, such as `Web servers` or `Operating systems`.\n- `webdata.technology.stacks.description`: A short description of a detected technology.\n- `webdata_last_change_data`: The web data fields that changed in the last change seen, as field paths under `webdata`.\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.entities`: The handles of the registry contacts and organizations linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, when it is kept.\n- `ipwhois.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the IP address asset.\n- `ipwhois.raw`: The raw IP WHOIS response for the IP address asset, when it is kept; empty on every sampled asset.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `ipwhois.network.start_address`: The first address of the registered network block that contains the IP address asset.\n- `ipwhois.network.end_address`: The last address of the registered network block that contains the IP address asset.\n- `ipwhois.network.handle`: The registry handle of the network that contains the IP address asset, such as `NET-192-0-2-0-1`.\n- `ipwhois.network.ip_version`: The IP version of the network that contains the IP address asset: `v4` or `v6`.\n- `ipwhois.network.links`: Links to the registry record of the network that contains the IP address asset, such as its RDAP and WHOIS URLs.\n- `ipwhois.network.parent_handle`: The handle of the larger network block from which the network of the IP address asset was allocated.\n- `ipwhois.network.raw`: The raw RDAP network object for the IP address asset, when it is kept.\n- `ipwhois.network.status`: The registry status of the network that contains the IP address asset, such as `active`.\n- `ipwhois.network.type`: The registry's allocation type for the network that contains the IP address asset, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `ipwhois.network.notices.title`: The title of a notice the registry attached to the network record of the IP address asset, such as `Terms of Service`.\n- `ipwhois.network.notices.description`: The text of a notice the registry attached to the network record of the IP address asset.\n- `ipwhois.network.notices.links`: Links given in a notice on the network record of the IP address asset.\n- `ipwhois.network.remarks.title`: The title of a remark on the network record of the IP address asset, such as `Registration Comments`.\n- `ipwhois.network.remarks.description`: The text of a remark on the network record of the IP address asset.\n- `ipwhois.network.remarks.links`: Links given in a remark on the network record of the IP address asset.\n- `ipwhois.network.events.action`: An event in the history of the network record of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.network.events.actor`: Who performed an event on the network record of the IP address asset, when the registry names one.\n- `ipwhois.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the IP address asset, such as `abuse`.\n- `ipwhois.objects.contact.email.value`: An e-mail address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.value`: A postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the IP address asset, such as `voice` or `work`.\n- `ipwhois.objects.contact.phone.value`: A phone number of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.kind`: What kind of contact is linked to the network of the IP address asset: `org`, `group` or `individual`.\n- `ipwhois.objects.contact.name`: The name of a contact or organization linked to the network of the IP address asset, such as `Abuse` or a company name.\n- `ipwhois.objects.contact.role`: The role given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.contact.title`: The title given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.entities`: Handles of further entities listed under a contact linked to the network of the IP address asset.\n- `ipwhois.objects.events.action`: An event in the history of a contact record linked to the network of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.objects.events.actor`: Who performed an event on a contact record linked to the network of the IP address asset, when the registry names one.\n- `ipwhois.objects.events_actor`: Events in which a contact linked to the network of the IP address asset is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `ipwhois.objects.handle`: The registry handle of a contact or organization linked to the network of the IP address asset.\n- `ipwhois.objects.links`: Links to the registry record of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.notices.title`: The title of a notice on a contact record linked to the network of the IP address asset, such as `Terms of Service`.\n- `ipwhois.objects.notices.description`: The text of a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.notices.links`: Links given in a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.raw`: The raw RDAP object of a contact linked to the network of the IP address asset, when it is kept.\n- `ipwhois.objects.remarks.title`: The title of a remark on a contact record linked to the network of the IP address asset, such as `Registration Comments`.\n- `ipwhois.objects.remarks.description`: The text of a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.roles`: The roles of a contact for the network of the IP address asset, such as `registrant`, `abuse` or `technical`.\n- `ipwhois.objects.status`: The registry status of a contact linked to the network of the IP address asset, such as `validated`.\n- `ipwhois_last_change_data`: The IP WHOIS fields that changed in the last change seen, as field paths under `ipwhois`.\n- `ipdns.ptr_records`: The PTR (reverse DNS) host names of an IP address asset.\n- `ipdns_last_change_data`: The reverse DNS fields that changed in the last change seen, as field paths under `ipdns`.\n- `issue_category_stats.name`: The name of an issue category in the per-category issue counts of the asset, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`.\n- `technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the asset, such as `Web servers` or `Analytics`.\n- `domain_snapshot.issue_category_stats.name`: The name of an issue category in the per-category issue counts of the domain and its subdomains together, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the domain and its subdomains together, such as `Web servers` or `Analytics`. Set on domain assets.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 179 fields\n\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.name.length`: The number of characters in the name without the extension: `4` for `acme.example`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois_create_date_historical`: Every creation date seen for the domain over time, so a domain that was deleted and registered again keeps its earlier dates too (UTC date-times).\n- `whois_check_date`: When the WHOIS record of the asset was last checked (UTC date-time).\n- `whois_last_change_date`: When a change in the WHOIS record of the asset was last seen (UTC date-time).\n- `dns.a.value_last_change_date`: When the A record text (`dns.a.value`) last changed (UTC date-time).\n- `dns.a.rcode_last_change_date`: When the response code of the A lookup (`dns.a.rcode`) last changed (UTC date-time).\n- `dns.a.last_change_date`: When the asset's A records last changed, in their text or their response code (UTC date-time).\n- `dns.a.ip_addresses.asn_date`: The registry allocation date that the ASN lookup reports for the A-record address, as a date at midnight UTC.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was created (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was last updated (UTC date-time).\n- `dns.a.ip_addresses.network.events.timestamp`: When an event on the network record of the A-record address happened (UTC date-time).\n- `dns.a.ip_addresses.objects.events.timestamp`: When an event on a contact record linked to the network of the A-record address happened (UTC date-time).\n- `dns.aaaa.value_last_change_date`: When the AAAA record text (`dns.aaaa.value`) last changed (UTC date-time).\n- `dns.aaaa.rcode_last_change_date`: When the response code of the AAAA lookup (`dns.aaaa.rcode`) last changed (UTC date-time).\n- `dns.aaaa.last_change_date`: When the asset's AAAA records last changed, in their text or their response code (UTC date-time).\n- `dns.caa.value_last_change_date`: When the CAA record text (`dns.caa.value`) last changed (UTC date-time).\n- `dns.caa.rcode_last_change_date`: When the response code of the CAA lookup (`dns.caa.rcode`) last changed (UTC date-time).\n- `dns.caa.last_change_date`: When the asset's CAA records last changed, in their text or their response code (UTC date-time).\n- `dns.cname.value_last_change_date`: When the CNAME record text (`dns.cname.value`) last changed (UTC date-time).\n- `dns.cname.rcode_last_change_date`: When the response code of the CNAME lookup (`dns.cname.rcode`) last changed (UTC date-time).\n- `dns.cname.last_change_date`: When the asset's CNAME records last changed, in their text or their response code (UTC date-time).\n- `dns.dnskey.value_last_change_date`: When the DNSKEY record text (`dns.dnskey.value`) last changed (UTC date-time).\n- `dns.dnskey.rcode_last_change_date`: When the response code of the DNSKEY lookup (`dns.dnskey.rcode`) last changed (UTC date-time).\n- `dns.dnskey.last_change_date`: When the asset's DNSKEY records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.value_last_change_date`: When the DS record text (`dns.ds.value`) last changed (UTC date-time).\n- `dns.ds.rcode_last_change_date`: When the response code of the DS lookup (`dns.ds.rcode`) last changed (UTC date-time).\n- `dns.ds.last_change_date`: When the asset's DS records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.records.key_tag`: The key tag (a number) of the DNSKEY that a DS record refers to.\n- `dns.mx.value_last_change_date`: When the MX record text (`dns.mx.value`) last changed (UTC date-time).\n- `dns.mx.rcode_last_change_date`: When the response code of the MX lookup (`dns.mx.rcode`) last changed (UTC date-time).\n- `dns.mx.last_change_date`: When the asset's MX records last changed, in their text or their response code (UTC date-time).\n- `dns.ns.value_last_change_date`: When the NS record text (`dns.ns.value`) last changed (UTC date-time).\n- `dns.ns.rcode_last_change_date`: When the response code of the NS lookup (`dns.ns.rcode`) last changed (UTC date-time).\n- `dns.ns.last_change_date`: When the asset's NS records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec.value_last_change_date`: When the NSEC record text (`dns.nsec.value`) last changed (UTC date-time).\n- `dns.nsec.rcode_last_change_date`: When the response code of the NSEC lookup (`dns.nsec.rcode`) last changed (UTC date-time).\n- `dns.nsec.last_change_date`: When the asset's NSEC records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec3.value_last_change_date`: When the NSEC3 record text (`dns.nsec3.value`) last changed (UTC date-time).\n- `dns.nsec3.rcode_last_change_date`: When the response code of the NSEC3 lookup (`dns.nsec3.rcode`) last changed (UTC date-time).\n- `dns.nsec3.last_change_date`: When the asset's NSEC3 records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.value_last_change_date`: When the RRSIG record text (`dns.rrsig.value`) last changed (UTC date-time).\n- `dns.rrsig.rcode_last_change_date`: When the response code of the RRSIG lookup (`dns.rrsig.rcode`) last changed (UTC date-time).\n- `dns.rrsig.last_change_date`: When the asset's RRSIG records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.signature_inception`: When an RRSIG signature becomes valid (UTC date-time).\n- `dns.rrsig.signature_expiration`: When an RRSIG signature expires (UTC date-time).\n- `dns.soa.value_last_change_date`: When the SOA record text (`dns.soa.value`) last changed (UTC date-time).\n- `dns.soa.rcode_last_change_date`: When the response code of the SOA lookup (`dns.soa.rcode`) last changed (UTC date-time).\n- `dns.soa.last_change_date`: When the asset's SOA records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.value_last_change_date`: When the SRV record text (`dns.srv.value`) last changed (UTC date-time).\n- `dns.srv.rcode_last_change_date`: When the response code of the SRV lookup (`dns.srv.rcode`) last changed (UTC date-time).\n- `dns.srv.last_change_date`: When the asset's SRV records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.records.port`: The port an SRV record points to.\n- `dns.txt.value_last_change_date`: When the TXT record text (`dns.txt.value`) last changed (UTC date-time).\n- `dns.txt.rcode_last_change_date`: When the response code of the TXT lookup (`dns.txt.rcode`) last changed (UTC date-time).\n- `dns.txt.last_change_date`: When the asset's TXT records last changed, in their text or their response code (UTC date-time).\n- `dns_check_date`: When the DNS records of the asset were last checked (UTC date-time).\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.port`: The port that the asset's TLS certificate was collected on, such as `443`.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl.validity.length`: The validity period of the certificate in seconds: 7,776,000 seconds are 90 days.\n- `ssl.extensions.signed_certificate_timestamps.timestamp`: When a Certificate Transparency log recorded the certificate, from a signed certificate timestamp (UTC date-time).\n- `ssl.extensions.signed_certificate_timestamps.version`: The version of a signed certificate timestamp; `0` stands for version 1.\n- `ssl_check_date`: When the TLS certificate of the asset was last checked (UTC date-time).\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the HTTP check, such as `301` or `200`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_check_date`: When the HTTP check of the asset last ran (UTC date-time).\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the web data scan, such as `301` or `200`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata.http.cookies.size`: The size of a cookie set in the web data scan, in bytes (name plus value).\n- `webdata.http.cookies.expires`: When a cookie set in the web data scan expires (UTC date-time); session cookies show `1969-12-31T23:59:59Z`.\n- `webdata.technology.stacks.confidence`: How certain the detection of a technology is, from 0 to 100; every sampled detection has `100`.\n- `webdata.technology.stacks.clean_version`: The major version of a detected technology as a whole number, such as `1` for version `1.0`.\n- `webdata_check_date`: When the web data scan of the asset, which collects the page content, headers and technologies, last ran (UTC date-time).\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn_date`: The registry allocation date that the ASN lookup reports for the IP address asset, as a date at midnight UTC.\n- `ipwhois.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was created (UTC date-time).\n- `ipwhois.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was last updated (UTC date-time).\n- `ipwhois.network.events.timestamp`: When an event on the network record of the IP address asset happened (UTC date-time).\n- `ipwhois.objects.events.timestamp`: When an event on a contact record linked to the network of the IP address asset happened (UTC date-time).\n- `ipwhois_check_date`: When the IP WHOIS record of an IP address asset was last checked (UTC date-time).\n- `ipwhois_last_change_date`: When a change in the IP WHOIS record of an IP address asset was last seen (UTC date-time).\n- `ipdns_check_date`: When the reverse DNS (PTR) records of an IP address asset were last checked (UTC date-time).\n- `ipdns_last_change_date`: When a change in the reverse DNS (PTR) records of an IP address asset was last seen (UTC date-time).\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `open_port_count`: The number of open ports found on the asset.\n- `open_ports`: The open port numbers found on the asset, such as `80`, `443` or `8080`.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_category_stats.count`: The number of active issues in that category on the asset.\n- `issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the asset.\n- `issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the asset.\n- `issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the asset.\n- `issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the asset.\n- `issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the asset.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `issue_count.active_by_severity.low`: The number of active issues of low severity on the asset.\n- `issue_count.active_by_severity.information`: The number of active issues of information severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `technology_count.by_category.count`: The number of technologies in that category on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity on the asset.\n- `vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity on the asset.\n- `vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity on the asset.\n- `vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) on the asset whose severity is `none`.\n- `vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) on the asset whose severity is `unknown`.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.count`: The number of active issues in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.count`: The number of distinct technologies in that category across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n**`eq`, `exists`** — 36 fields\n\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `fqdn.is_idn`: True when the host name is an internationalized domain name (IDN) with non-ASCII characters.\n- `fqdn.name.contains_confusable`: True when the name contains confusable characters that look like other letters, such as Cyrillic `а` for Latin `a`, a common trick in look-alike domains.\n- `fqdn.name.contains_hyphen`: True when the name (without the extension) contains a hyphen.\n- `fqdn.name.contains_letter`: True when the name (without the extension) contains a letter.\n- `fqdn.name.contains_number`: True when the name (without the extension) contains a digit.\n- `fqdn.domain.is_idn`: True when the registrable domain is an internationalized domain name (IDN) with non-ASCII characters.\n- `whois_privacy_enabled`: True when the platform flagged WHOIS privacy protection on the domain's registrant details; set on domain assets.\n- `ssl.signature.is_valid`: True when the asset's TLS certificate passed validation for the host; when false, `ssl.signature.invalid_reason` says why.\n- `ssl.signature.is_valid_chain`: A flag for whether the certificate chain of the asset's TLS certificate is valid. It was true on every sampled certificate, even one whose validation failed with `unable to get issuer certificate`.\n- `ssl.signature.is_self_signed`: True when the asset's TLS certificate is self-signed, that is signed by its own key rather than by a certificate authority.\n- `ssl.extensions.basic_constraints.is_ca`: True when the certificate is a certificate authority (CA) certificate, from its Basic Constraints extension.\n- `ssl.extensions.extended_key_usage.client_auth`: True when the Extended Key Usage extension allows TLS client authentication.\n- `ssl.extensions.extended_key_usage.server_auth`: True when the Extended Key Usage extension allows TLS server authentication, as website certificates need.\n- `ssl.extensions.key_usage.content_commitment`: True when the Key Usage extension allows the certificate's key to be used for content commitment (non-repudiation).\n- `ssl.extensions.key_usage.crl_sign`: True when the Key Usage extension allows the certificate's key to be used for signing certificate revocation lists (CRL sign).\n- `ssl.extensions.key_usage.data_encipherment`: True when the Key Usage extension allows the certificate's key to be used for data encipherment.\n- `ssl.extensions.key_usage.digital_signature`: True when the Key Usage extension allows the certificate's key to be used for digital signatures.\n- `ssl.extensions.key_usage.key_agreement`: True when the Key Usage extension allows the certificate's key to be used for key agreement.\n- `ssl.extensions.key_usage.key_cert_sign`: True when the Key Usage extension allows the certificate's key to be used for signing other certificates (certificate sign).\n- `ssl.extensions.key_usage.key_encipherment`: True when the Key Usage extension allows the certificate's key to be used for key encipherment.\n- `ssl.has_expired`: True when the asset's TLS certificate is past its end date.\n- `http.external_domain_redirection`: True when the HTTP check ended on a different registrable domain than it started on.\n- `http.external_fqdn_redirection`: True when the HTTP check ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.html.inspect_disabled`: A flag of the web data scan that marks pages whose inspection was disabled; it was `false` on every sampled asset.\n- `webdata.html.html_meta.no_index_status`: True when the scanned page asks search engines not to index it (a `noindex` robots directive).\n- `webdata.http.external_domain_redirection`: True when the web data scan ended on a different registrable domain than it started on.\n- `webdata.http.external_fqdn_redirection`: True when the web data scan ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.http.cookies.secure`: True when a cookie set in the web data scan is sent over HTTPS only (Secure attribute).\n- `webdata.http.cookies.http_only`: True when scripts on the page cannot read a cookie set in the web data scan (HttpOnly attribute).\n- `webdata.http.cookies.session`: True when a cookie set in the web data scan is a session cookie, deleted when the browser closes.\n- `is_parked`: True when the asset is parked; Inventory marks it with a P badge whose tooltip shows where it redirects.\n\n**`eq`, `in`, `exists`** — 8 fields\n\n- `asset_type`: The asset type: `domain`, `subdomain`, `ip` or `website`.\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `dns.dnskey.records.key_type`: The role of a DNSKEY: `ZSK` (zone-signing key), `KSK` (key-signing key) or `KSK_REVOKED` (revoked key-signing key).\n- `dns.dnskey.records.algorithm`: The DNSSEC algorithm of a DNSKEY, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.algorithm`: The DNSSEC algorithm of the key that a DS record refers to, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.digest_type`: The hash used for a DS record's digest: `SHA1`, `SHA256`, `SHA384`, `GOST` or `NULL`.\n- `dns.rrsig.algorithm`: The DNSSEC algorithm of an RRSIG signature, such as `ECDSAP256SHA256` or `RSASHA256`.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `website.parent_asset.type`: The asset type of the website's parent asset, such as `subdomain`.\n\nSortable fields:\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `website_count`: The number of website assets (`host:port`) in your inventory that belong to this asset.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `open_port_count`: The number of open ports found on the asset.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `updated_count` | integer |  |\n| `ignored_count` | integer |  |\n\n> The saved example **Request template · 38 of 740 filters** holds this body with 38 of the 740 filters (the first 10 of each operator group); the full list is above (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"postman-docs-test.deepinfo.com\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Asset Instant Scan",
              "id": "de1cb533-c31d-5651-8c70-dbd2dd1cf469",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/instant-scan",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "instant-scan"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "6ab2a3fa31c7bcfb2fb91a77",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Instant Scan API**\n\nStarts an on-demand scan of an asset. Track it with **Asset Instant Scan Status**.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `triggered` | boolean |  |"
              },
              "response": []
            },
            {
              "name": "Asset Set Tag",
              "id": "8f921701-2161-5d0f-a387-4d490b02f8e6",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/search:set-tag",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "search:set-tag"
                  ]
                },
                "description": "**Deepinfo EASM Asset Set Tag API**\n\nAdds `tags` (1–10) to every asset matching `filters`.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n| `tags` | array | yes | min items `1`; max items `10` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 517 fields\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `tags`: Your own labels on the asset, such as a business unit or an environment; each tag is 3 to 100 characters long.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.name.unicode`: The host name without its extension, in Unicode: `acme` for `acme.example`, `www.acme` for `www.acme.example`.\n- `fqdn.name.latinized`: Latin-letter spellings of a name that has non-Latin or accented letters, so a search for `istanbul` also finds names written with `İ`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_sub.unicode`: The second-level part of a two-part extension, such as `co` in `co.uk`; empty for single-part extensions.\n- `website.path`: The URL path of a website asset, such as `/`.\n- `website.scheme`: The URL scheme of a website asset, such as `http`.\n- `website.parent_asset.id`: The ID of the domain or subdomain asset that a website asset belongs to.\n- `website.parent_asset.name`: The name of the domain or subdomain asset that a website asset belongs to.\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.name`: The registrant's name in WHOIS; often a privacy placeholder such as `redacted for privacy`.\n- `whois.registrant.country`: The registrant's country in WHOIS, as a two-letter code in lower case such as `us`.\n- `whois.registrant.state`: The registrant's state or province in WHOIS.\n- `whois.registrant.city`: The registrant's city in WHOIS.\n- `whois.registrant.street`: The registrant's street address in WHOIS.\n- `whois.registrant.postal_code`: The registrant's postal code in WHOIS.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `whois_registrant_email_historical`: Every registrant e-mail address seen for the domain over time, the current one included.\n- `whois_normalized.registrar`: The registrar reduced to a short normalized name, such as `godaddy` or `gandi`, so the same registrar matches across spellings.\n- `whois_normalized.registrant.email`: The registrant e-mail address after WHOIS normalization.\n- `whois_normalized.registrant.email_real`: Another normalized registrant e-mail field, set on fewer domains than `whois_normalized.registrant.email`; in the samples it is set only where `whois_privacy_enabled` is false, with the same address.\n- `whois_normalized.registrant.email_domain_apex`: The registrable domain of the registrant e-mail address: `acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.email_fqdn_apex`: The full host name after the `@` of the registrant e-mail address: `mail.acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.organization`: The registrant organization cleaned up across registrars: lower case, with spaces and punctuation removed, such as `domainsbyproxyllc`.\n- `whois_normalized.registrant.phone`: The registrant phone number reduced to its digits, such as `14805551234`.\n- `whois_last_change_data`: The WHOIS fields that changed in the last change seen, as field paths such as `whois.update_date` or `whois.domain_status`.\n- `dns.a.value`: The asset's current A records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.a.value_previous`: The asset's A records as they were before the last change, in the same text form as `dns.a.value`.\n- `dns.a.rcode`: The DNS response code returned for the asset's A lookup, such as `NOERROR`.\n- `dns.a.rcode_previous`: The DNS response code of the A lookup before it last changed.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.entities`: The handles of the registry contacts and organizations linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, when it is kept.\n- `dns.a.ip_addresses.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the A-record address.\n- `dns.a.ip_addresses.raw`: The raw IP WHOIS response for the A-record address, when it is kept; empty on every sampled asset.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.a.ip_addresses.network.start_address`: The first address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.end_address`: The last address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.handle`: The registry handle of the network that contains the A-record address, such as `NET-192-0-2-0-1`.\n- `dns.a.ip_addresses.network.ip_version`: The IP version of the network that contains the A-record address: `v4` or `v6`.\n- `dns.a.ip_addresses.network.links`: Links to the registry record of the network that contains the A-record address, such as its RDAP and WHOIS URLs.\n- `dns.a.ip_addresses.network.parent_handle`: The handle of the larger network block from which the network of the A-record address was allocated.\n- `dns.a.ip_addresses.network.raw`: The raw RDAP network object for the A-record address, when it is kept.\n- `dns.a.ip_addresses.network.status`: The registry status of the network that contains the A-record address, such as `active`.\n- `dns.a.ip_addresses.network.type`: The registry's allocation type for the network that contains the A-record address, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `dns.a.ip_addresses.network.notices.title`: The title of a notice the registry attached to the network record of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.network.notices.description`: The text of a notice the registry attached to the network record of the A-record address.\n- `dns.a.ip_addresses.network.notices.links`: Links given in a notice on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.title`: The title of a remark on the network record of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.network.remarks.description`: The text of a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.links`: Links given in a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.events.action`: An event in the history of the network record of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.network.events.actor`: Who performed an event on the network record of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the A-record address, such as `abuse`.\n- `dns.a.ip_addresses.objects.contact.email.value`: An e-mail address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.value`: A postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the A-record address, such as `voice` or `work`.\n- `dns.a.ip_addresses.objects.contact.phone.value`: A phone number of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.kind`: What kind of contact is linked to the network of the A-record address: `org`, `group` or `individual`.\n- `dns.a.ip_addresses.objects.contact.name`: The name of a contact or organization linked to the network of the A-record address, such as `Abuse` or a company name.\n- `dns.a.ip_addresses.objects.contact.role`: The role given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.title`: The title given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.entities`: Handles of further entities listed under a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.events.action`: An event in the history of a contact record linked to the network of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.objects.events.actor`: Who performed an event on a contact record linked to the network of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.events_actor`: Events in which a contact linked to the network of the A-record address is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `dns.a.ip_addresses.objects.handle`: The registry handle of a contact or organization linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.links`: Links to the registry record of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.title`: The title of a notice on a contact record linked to the network of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.objects.notices.description`: The text of a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.links`: Links given in a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.raw`: The raw RDAP object of a contact linked to the network of the A-record address, when it is kept.\n- `dns.a.ip_addresses.objects.remarks.title`: The title of a remark on a contact record linked to the network of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.objects.remarks.description`: The text of a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.roles`: The roles of a contact for the network of the A-record address, such as `registrant`, `abuse` or `technical`.\n- `dns.a.ip_addresses.objects.status`: The registry status of a contact linked to the network of the A-record address, such as `validated`.\n- `dns.a.ip_history`: Every IPv4 address seen in the asset's A records over time, the current ones included.\n- `dns.aaaa.value`: The asset's current AAAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.aaaa.value_previous`: The asset's AAAA records as they were before the last change, in the same text form as `dns.aaaa.value`.\n- `dns.aaaa.rcode`: The DNS response code returned for the asset's AAAA lookup, such as `NOERROR`.\n- `dns.aaaa.rcode_previous`: The DNS response code of the AAAA lookup before it last changed.\n- `dns.aaaa.ip_addresses`: The IPv6 addresses in the asset's AAAA records.\n- `dns.caa.value`: The asset's current CAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.caa.value_previous`: The asset's CAA records as they were before the last change, in the same text form as `dns.caa.value`.\n- `dns.caa.rcode`: The DNS response code returned for the asset's CAA lookup, such as `NOERROR`.\n- `dns.caa.rcode_previous`: The DNS response code of the CAA lookup before it last changed.\n- `dns.caa.issue_fqdns`: The certificate authorities allowed to issue certificates for the name, from the CAA `issue` tags, such as `fernhill.example` or `kestrel.example`.\n- `dns.caa.issuewild_fqdns`: The certificate authorities allowed to issue wildcard certificates for the name, from the CAA `issuewild` tags.\n- `dns.caa.iodef_emails`: The e-mail addresses from the CAA `iodef` tags, where certificate authorities report requests that break the CAA policy.\n- `dns.cname.value`: The asset's current CNAME records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.cname.value_previous`: The asset's CNAME records as they were before the last change, in the same text form as `dns.cname.value`.\n- `dns.cname.rcode`: The DNS response code returned for the asset's CNAME lookup, such as `NOERROR`.\n- `dns.cname.rcode_previous`: The DNS response code of the CNAME lookup before it last changed.\n- `dns.cname.canonical_fqdns`: The host names the asset's CNAME records point to (the alias targets).\n- `dns.dnskey.value`: The asset's current DNSKEY records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.dnskey.value_previous`: The asset's DNSKEY records as they were before the last change, in the same text form as `dns.dnskey.value`.\n- `dns.dnskey.rcode`: The DNS response code returned for the asset's DNSKEY lookup, such as `NOERROR`.\n- `dns.dnskey.rcode_previous`: The DNS response code of the DNSKEY lookup before it last changed.\n- `dns.dnskey.records.public_key`: The public key of a DNSKEY record, Base64-encoded and split into space-separated groups as in the zone-file text.\n- `dns.ds.value`: The asset's current DS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ds.value_previous`: The asset's DS records as they were before the last change, in the same text form as `dns.ds.value`.\n- `dns.ds.rcode`: The DNS response code returned for the asset's DS lookup, such as `NOERROR`.\n- `dns.ds.rcode_previous`: The DNS response code of the DS lookup before it last changed.\n- `dns.ds.records.digest`: The digest of a DS record, the hash of the DNSKEY it refers to.\n- `dns.mx.value`: The asset's current MX records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.mx.value_previous`: The asset's MX records as they were before the last change, in the same text form as `dns.mx.value`.\n- `dns.mx.rcode`: The DNS response code returned for the asset's MX lookup, such as `NOERROR`.\n- `dns.mx.rcode_previous`: The DNS response code of the MX lookup before it last changed.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns.mx.domains`: The registrable domains of the asset's mail servers, such as `acme.example`.\n- `dns.ns.value`: The asset's current NS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ns.value_previous`: The asset's NS records as they were before the last change, in the same text form as `dns.ns.value`.\n- `dns.ns.rcode`: The DNS response code returned for the asset's NS lookup, such as `NOERROR`.\n- `dns.ns.rcode_previous`: The DNS response code of the NS lookup before it last changed.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.ns.domains`: The registrable domains of the asset's name servers, such as `acme.example`.\n- `dns.nsec.value`: The asset's current NSEC records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec.value_previous`: The asset's NSEC records as they were before the last change, in the same text form as `dns.nsec.value`.\n- `dns.nsec.rcode`: The DNS response code returned for the asset's NSEC lookup, such as `NOERROR`.\n- `dns.nsec.rcode_previous`: The DNS response code of the NSEC lookup before it last changed.\n- `dns.nsec.records.next_domain`: The next name in the zone, from an NSEC record.\n- `dns.nsec.records.record_types`: The record types that exist at the name, from an NSEC record's type list, such as `A`, `NS` or `SOA`.\n- `dns.nsec3.value`: The asset's current NSEC3 records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec3.value_previous`: The asset's NSEC3 records as they were before the last change, in the same text form as `dns.nsec3.value`.\n- `dns.nsec3.rcode`: The DNS response code returned for the asset's NSEC3 lookup, such as `NOERROR`.\n- `dns.nsec3.rcode_previous`: The DNS response code of the NSEC3 lookup before it last changed.\n- `dns.nsec3.records.next_domain_hashed`: The hashed next name in the zone, from an NSEC3 record.\n- `dns.nsec3.records.record_types`: The record types that exist at the name, from an NSEC3 record's type list, such as `A` or `MX`.\n- `dns.rrsig.value`: The asset's current RRSIG records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.rrsig.value_previous`: The asset's RRSIG records as they were before the last change, in the same text form as `dns.rrsig.value`.\n- `dns.rrsig.rcode`: The DNS response code returned for the asset's RRSIG lookup, such as `NOERROR`.\n- `dns.rrsig.rcode_previous`: The DNS response code of the RRSIG lookup before it last changed.\n- `dns.rrsig.type_covered`: The record type that an RRSIG signature covers, such as `A` or `SOA`.\n- `dns.rrsig.signature`: The signature data of an RRSIG record, Base64-encoded.\n- `dns.soa.value`: The asset's current SOA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.soa.value_previous`: The asset's SOA records as they were before the last change, in the same text form as `dns.soa.value`.\n- `dns.soa.rcode`: The DNS response code returned for the asset's SOA lookup, such as `NOERROR`.\n- `dns.soa.rcode_previous`: The DNS response code of the SOA lookup before it last changed.\n- `dns.soa.mnames`: The MNAME of the SOA record: the primary name server of the zone, such as `ns1.acme.example`.\n- `dns.soa.rnames`: The RNAME of the SOA record, the zone administrator's mailbox in DNS form: `hostmaster.acme.example` stands for the mailbox `hostmaster` at `acme.example`.\n- `dns.soa.rname_emails`: The RNAME of the SOA record written as an e-mail address, such as `user@acme.example`.\n- `dns.srv.value`: The asset's current SRV records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.srv.value_previous`: The asset's SRV records as they were before the last change, in the same text form as `dns.srv.value`.\n- `dns.srv.rcode`: The DNS response code returned for the asset's SRV lookup, such as `NOERROR`.\n- `dns.srv.rcode_previous`: The DNS response code of the SRV lookup before it last changed.\n- `dns.srv.records.service`: The service named in an SRV record (the `_service` part of its name).\n- `dns.srv.records.protocol`: The protocol named in an SRV record (the `_proto` part of its name, such as TCP or UDP).\n- `dns.srv.records.target`: The host name an SRV record points to.\n- `dns.txt.value`: The asset's current TXT records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.txt.value_previous`: The asset's TXT records as they were before the last change, in the same text form as `dns.txt.value`.\n- `dns.txt.rcode`: The DNS response code returned for the asset's TXT lookup, such as `NOERROR`.\n- `dns.txt.rcode_previous`: The DNS response code of the TXT lookup before it last changed.\n- `dns.txt.values`: Each TXT record of the asset as its quoted text, such as `\"v=spf1 include:_spf.acme.example ~all\"`; the quotes are part of the value.\n- `dns.txt.spf_list.value`: The text of an SPF record (a TXT record that starts with `v=spf1`), quoted as in `dns.txt.values`.\n- `dns.txt.spf_list.allowed_domains`: The registrable domains that an SPF record refers to, such as `acme.example` for `include:_spf.acme.example`.\n- `dns.txt.spf_list.allowed_ips`: The IP addresses and ranges that an SPF record authorizes to send mail (its `ip4:` and `ip6:` entries).\n- `dns.txt.verifications.value`: The text of a site-verification TXT record, quoted as in `dns.txt.values`.\n- `dns.txt.verifications.domain`: The domain of the service a verification record is for, such as `acme.example`, `fernhill.example` or `kestrel.example`.\n- `dns.txt.verifications.name`: The name of a verification record, such as `site-verification` or `domain-verification`.\n- `dns_last_change_data`: The DNS fields that changed in the last change seen, as field paths such as `dns.soa.mnames`.\n- `ssl.target`: The host name that the asset's TLS certificate was collected from, normally the asset itself.\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.md5`: The MD5 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha256`: The SHA-256 fingerprint of the asset's TLS certificate, as lower-case hex; one fingerprint identifies one certificate.\n- `ssl.issuer.common_name`: The common name (CN) of the certificate authority that issued the asset's TLS certificate, such as `WE1` or `YE2`.\n- `ssl.issuer.country`: The country (C) of the certificate authority that issued the asset's TLS certificate, as a two-letter code such as `US`.\n- `ssl.issuer.state`: The state or province (ST) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.locality`: The locality or city (L) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.organization`: The organization (O) of the certificate authority that issued the asset's TLS certificate, such as `Let's Encrypt` or `Google Trust Services`.\n- `ssl.issuer.organizational_unit`: The organizational unit (OU) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer_dn`: The full distinguished name of the issuer of the asset's TLS certificate, as one string such as `CN=WE1,O=Google Trust Services,C=US`.\n- `ssl.subject.common_name`: The common name (CN) of the subject (holder) of the asset's TLS certificate, usually a host name such as `acme.example`.\n- `ssl.subject.country`: The country (C) of the subject (holder) of the asset's TLS certificate, as a two-letter code.\n- `ssl.subject.state`: The state or province (ST) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.locality`: The locality or city (L) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organizational_unit`: The organizational unit (OU) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject_dn`: The full distinguished name of the subject of the asset's TLS certificate, such as `CN=acme.example`; one that starts with `CN=*.` belongs to a wildcard certificate.\n- `ssl.signature.value`: The signature of the asset's TLS certificate, Base64-encoded.\n- `ssl.signature.invalid_reason`: Why certificate validation failed, such as a host name mismatch or `unable to get issuer certificate`.\n- `ssl.signature.algorithm.name`: The hash algorithm of the signature on the asset's TLS certificate, such as `sha256` or `sha384`.\n- `ssl.signature.algorithm.oid`: The object identifier (OID) of the signature algorithm, such as `1.2.840.113549.1.1.11` (SHA-256 with RSA) or `1.2.840.10045.4.3.2` (ECDSA with SHA-256).\n- `ssl.extensions.authority_key_id`: The Authority Key Identifier extension, which identifies the issuer's key, Base64-encoded.\n- `ssl.extensions.certificate_policies`: The policy OIDs in the Certificate Policies extension, such as `2.23.140.1.2.1` (domain validated).\n- `ssl.extensions.signed_certificate_timestamps.log_id`: The ID of the Certificate Transparency log that issued a signed certificate timestamp (SCT) for the certificate, Base64-encoded.\n- `ssl.extensions.signed_certificate_timestamps.signature`: The log's signature on a signed certificate timestamp, Base64-encoded.\n- `ssl.extensions.subject_alt_name.dns_names`: The host names in the certificate's Subject Alternative Name extension, including wildcard names such as `*.acme.example`.\n- `ssl.extensions.subject_key_id`: The Subject Key Identifier extension, which identifies the certificate's own key, Base64-encoded.\n- `ssl.subject_key_info.fingerprint.hash_algorithm`: The hash algorithm used for `ssl.subject_key_info.fingerprint.value`, such as `sha256` or `sha384`.\n- `ssl.subject_key_info.fingerprint.value`: A hex fingerprint recorded under the certificate's subject key information, made with the hash in `hash_algorithm`. In the samples it equals `ssl.fingerprint.sha256` when that hash is SHA-256.\n- `ssl.subject_key_info.key_algorithm.name`: The algorithm of the certificate's public key, such as `RSA` or `ECDSA`.\n- `ssl.version.name`: The X.509 version of the certificate, such as `v3`.\n- `ssl.version.value`: The X.509 version as encoded in the certificate, counted from zero: `2` means `v3`.\n- `ssl.tbs_fingerprint`: A SHA-256 fingerprint (hex) of the certificate's to-be-signed part, the certificate content without its signature.\n- `ssl.certificate`: The whole certificate, Base64-encoded (a PEM body without the header and footer lines).\n- `ssl.fqdn_list`: The host names the certificate covers, with the `*.` of wildcard names removed and duplicates merged, so `*.acme.example` and `acme.example` both give `acme.example`.\n- `ssl_last_change_data`: The certificate fields that changed in the last change seen, as field paths such as `ssl.validity.end_date`.\n- `http.requested_url`: The URL the HTTP check started from, such as `http://acme.example`.\n- `http.requested_domain`: The registrable domain of the URL the HTTP check started from.\n- `http.requested_fqdn`: The host name of the URL the HTTP check started from.\n- `http.final_url`: The URL the HTTP check ended on after following all redirects.\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.redirection_history.url`: A URL in the redirect chain of the HTTP check, listed in the order visited.\n- `http.headers.accept`: The `Accept` header, when it was returned in the HTTP check. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the HTTP check. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `http.headers.accept_language`: The `Accept-Language` header, when it was returned in the HTTP check. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the HTTP check; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the HTTP check; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the HTTP check; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the HTTP check; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the HTTP check; it lists the response headers that scripts from other origins may read (CORS).\n- `http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the HTTP check; it says how many seconds browsers may cache a CORS preflight result.\n- `http.headers.alt_svc`: The `Alt-Svc` header returned in the HTTP check; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `http.headers.authorization`: The `Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `http.headers.cache_control`: The `Cache-Control` header returned in the HTTP check; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the HTTP check; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `http.headers.content_disposition`: The `Content-Disposition` header returned in the HTTP check; it says whether the content is shown in the browser or downloaded as a file.\n- `http.headers.content_encoding`: The `Content-Encoding` header returned in the HTTP check; it names the compression applied to the response body, for example `gzip` or `br`.\n- `http.headers.content_language`: The `Content-Language` header returned in the HTTP check; it gives the language of the content, for example `en` or `tr`.\n- `http.headers.content_length`: The `Content-Length` header returned in the HTTP check; it gives the size of the response body in bytes.\n- `http.headers.content_range`: The `Content-Range` header returned in the HTTP check; it says which part of the full body a partial response holds.\n- `http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the HTTP check; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `http.headers.content_type`: The `Content-Type` header returned in the HTTP check; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `http.headers.cookie`: The `Cookie` header, when it was returned in the HTTP check. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the HTTP check; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the HTTP check; it controls whether the page shares its browsing context with cross-origin windows.\n- `http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the HTTP check; it controls which sites may load the resource.\n- `http.headers.date`: The `Date` header returned in the HTTP check; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `http.headers.early_data`: The `Early-Data` header, when it was returned in the HTTP check. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `http.headers.expect_ct`: The `Expect-CT` header returned in the HTTP check; it is a deprecated header about Certificate Transparency enforcement.\n- `http.headers.expires`: The `Expires` header returned in the HTTP check; it gives the date after which the response counts as stale, in HTTP date format.\n- `http.headers.feature_policy`: The `Feature-Policy` header returned in the HTTP check; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `http.headers.host`: The `Host` header, when it was returned in the HTTP check. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the HTTP check. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the HTTP check. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `http.headers.last_modified`: The `Last-Modified` header returned in the HTTP check; it gives the time the server says the resource last changed, in HTTP date format.\n- `http.headers.origin_isolation`: The `Origin-Isolation` header returned in the HTTP check; it is an experimental header that asks browsers to isolate the site's origin.\n- `http.headers.others.name`: The name of a header returned in the HTTP check that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `http.headers.others.value`: The value of a header listed in `headers.others` for the HTTP check.\n- `http.headers.permission_policy`: The `Permission-Policy` header returned in the HTTP check; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `http.headers.permissions_policy`: The `Permissions-Policy` header returned in the HTTP check; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `http.headers.pragma`: The `Pragma` header returned in the HTTP check; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the HTTP check; it tells a client how to authenticate to a proxy.\n- `http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the HTTP check; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `http.headers.range`: The `Range` header, when it was returned in the HTTP check. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `http.headers.referer`: The `Referer` header, when it was returned in the HTTP check. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `http.headers.referrer_policy`: The `Referrer-Policy` header returned in the HTTP check; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the HTTP check. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `http.headers.server`: The `Server` header returned in the HTTP check; it names the server software the site reports, for example `nginx` or `Apache`.\n- `http.headers.set_cookie`: The `Set-Cookie` header returned in the HTTP check; it sets cookies, with their attributes.\n- `http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the HTTP check; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `http.headers.te`: The `TE` header, when it was returned in the HTTP check. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the HTTP check; it says how the body is transferred, for example `chunked`.\n- `http.headers.upgrade`: The `Upgrade` header returned in the HTTP check; it offers or asks for a switch to another protocol.\n- `http.headers.user_agent`: The `User-Agent` header, when it was returned in the HTTP check. It is normally a request header (the client software), so it is rarely set.\n- `http.headers.vary`: The `Vary` header returned in the HTTP check; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the HTTP check; it tells a client how to authenticate, usually with a `401` response.\n- `http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the HTTP check; it stops browsers from guessing the content type when set to `nosniff`.\n- `http.headers.x_download_options`: The `X-Download-Options` header returned in the HTTP check; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `http.headers.x_frame_options`: The `X-Frame-Options` header returned in the HTTP check; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the HTTP check; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `http.headers.x_powered_by`: The `X-Powered-By` header returned in the HTTP check; it names the technology the server reports running on, for example `Express`.\n- `http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the HTTP check; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `http.cookies.name`: The name of a cookie set in the HTTP check.\n- `http.cookies.value`: The value of a cookie set in the HTTP check.\n- `http.html.source_code_hash`: A SHA-256 hash of the page source returned in the HTTP check; the same hash means the same source.\n- `http_last_change_data`: The HTTP check fields that changed in the last change seen, as field paths such as `http.html.source_code_hash`.\n- `webdata.requested_url`: The URL the web data scan started from, such as `http://acme.example`.\n- `webdata.requested_domain`: The registrable domain of the URL the web data scan started from.\n- `webdata.requested_fqdn`: The host name of the URL the web data scan started from.\n- `webdata.html.internal_links_fqdns`: The host names of links on the scanned page that stay within the site's own domain, such as other subdomains.\n- `webdata.html.external_links_domains`: The registrable domains of links on the scanned page that point to other domains, such as `kestrel.example`.\n- `webdata.html.external_links_fqdns`: The host names of links on the scanned page that point to other domains, such as `www.kestrel.example`.\n- `webdata.html.external_links`: The full URLs of links on the scanned page that point to other domains.\n- `webdata.html.script_links`: The URLs of the scripts the scanned page loads.\n- `webdata.html.iframe_links`: The URLs of the frames (iframes) embedded in the scanned page.\n- `webdata.html.trackers.name`: The name of an analytics or advertising tracker found on the scanned page, such as `google_adsense` or `google_tag_manager`.\n- `webdata.html.trackers.values`: The IDs found for a tracker, such as a Google Analytics ID that starts with `G-` or `UA-`.\n- `webdata.html.emails`: The e-mail addresses found on the scanned page.\n- `webdata.html.emails_internal`: The e-mail addresses found on the scanned page that belong to the site's own domain.\n- `webdata.html.source_code_hash`: A SHA-256 hash of the page source in the web data scan; the same hash means the same source.\n- `webdata.html.content_hash`: A SHA-256 hash of the page content in the web data scan, kept apart from `source_code_hash`, the hash of the raw source.\n- `webdata.html.content_top_keywords`: The most frequent words in the text of the scanned page.\n- `webdata.html.favicon_links`: The URLs of the icons the scanned page declares, such as its favicon and touch icons.\n- `webdata.html.html_meta.name`: The site or application name declared in the scanned page's metadata.\n- `webdata.html.html_meta.description`: The meta description of the scanned page.\n- `webdata.html.html_meta.language`: The language the scanned page declares, such as `en`, `tr` or `en-US`.\n- `webdata.html.html_meta.language_alternatives`: The languages of the alternative versions the scanned page links to, such as `en` or `ar`.\n- `webdata.html.html_meta.keywords`: The keywords listed in the keywords meta tag of the scanned page.\n- `webdata.html.html_meta.encoding`: The character encoding the scanned page declares, such as `utf-8`.\n- `webdata.html.html_meta.canonical_url`: The canonical URL the scanned page declares.\n- `webdata.html.html_meta.title`: The title of the scanned page.\n- `webdata.favicon.url`: The URL of a site icon (favicon) recorded by the web data scan.\n- `webdata.favicon.hash`: A SHA-256 hash of a site icon; the same hash means the same icon.\n- `webdata.http.final_url`: The URL the web data scan ended on after following all redirects.\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.redirection_history.url`: A URL in the redirect chain of the web data scan, listed in the order visited.\n- `webdata.http.redirection_history.method`: How a step of the web data scan's redirect chain was made; `http-header` (a redirect sent in the HTTP response) is the value in the samples.\n- `webdata.http.headers.accept`: The `Accept` header, when it was returned in the web data scan. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the web data scan. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_language`: The `Accept-Language` header, when it was returned in the web data scan. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `webdata.http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the web data scan; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `webdata.http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the web data scan; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `webdata.http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the web data scan; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `webdata.http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the web data scan; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `webdata.http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the web data scan; it lists the response headers that scripts from other origins may read (CORS).\n- `webdata.http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the web data scan; it says how many seconds browsers may cache a CORS preflight result.\n- `webdata.http.headers.alt_svc`: The `Alt-Svc` header returned in the web data scan; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `webdata.http.headers.authorization`: The `Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `webdata.http.headers.cache_control`: The `Cache-Control` header returned in the web data scan; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `webdata.http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the web data scan; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `webdata.http.headers.content_disposition`: The `Content-Disposition` header returned in the web data scan; it says whether the content is shown in the browser or downloaded as a file.\n- `webdata.http.headers.content_encoding`: The `Content-Encoding` header returned in the web data scan; it names the compression applied to the response body, for example `gzip` or `br`.\n- `webdata.http.headers.content_language`: The `Content-Language` header returned in the web data scan; it gives the language of the content, for example `en` or `tr`.\n- `webdata.http.headers.content_length`: The `Content-Length` header returned in the web data scan; it gives the size of the response body in bytes.\n- `webdata.http.headers.content_range`: The `Content-Range` header returned in the web data scan; it says which part of the full body a partial response holds.\n- `webdata.http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the web data scan; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `webdata.http.headers.content_type`: The `Content-Type` header returned in the web data scan; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `webdata.http.headers.cookie`: The `Cookie` header, when it was returned in the web data scan. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `webdata.http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the web data scan; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `webdata.http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the web data scan; it controls whether the page shares its browsing context with cross-origin windows.\n- `webdata.http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the web data scan; it controls which sites may load the resource.\n- `webdata.http.headers.date`: The `Date` header returned in the web data scan; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `webdata.http.headers.early_data`: The `Early-Data` header, when it was returned in the web data scan. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `webdata.http.headers.expect_ct`: The `Expect-CT` header returned in the web data scan; it is a deprecated header about Certificate Transparency enforcement.\n- `webdata.http.headers.expires`: The `Expires` header returned in the web data scan; it gives the date after which the response counts as stale, in HTTP date format.\n- `webdata.http.headers.feature_policy`: The `Feature-Policy` header returned in the web data scan; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `webdata.http.headers.host`: The `Host` header, when it was returned in the web data scan. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `webdata.http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the web data scan. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `webdata.http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the web data scan. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `webdata.http.headers.last_modified`: The `Last-Modified` header returned in the web data scan; it gives the time the server says the resource last changed, in HTTP date format.\n- `webdata.http.headers.origin_isolation`: The `Origin-Isolation` header returned in the web data scan; it is an experimental header that asks browsers to isolate the site's origin.\n- `webdata.http.headers.others.name`: The name of a header returned in the web data scan that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `webdata.http.headers.others.value`: The value of a header listed in `headers.others` for the web data scan.\n- `webdata.http.headers.permission_policy`: The `Permission-Policy` header returned in the web data scan; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `webdata.http.headers.permissions_policy`: The `Permissions-Policy` header returned in the web data scan; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `webdata.http.headers.pragma`: The `Pragma` header returned in the web data scan; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `webdata.http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the web data scan; it tells a client how to authenticate to a proxy.\n- `webdata.http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `webdata.http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the web data scan; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `webdata.http.headers.range`: The `Range` header, when it was returned in the web data scan. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `webdata.http.headers.referer`: The `Referer` header, when it was returned in the web data scan. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `webdata.http.headers.referrer_policy`: The `Referrer-Policy` header returned in the web data scan; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `webdata.http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `webdata.http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the web data scan. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `webdata.http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `webdata.http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the web data scan. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `webdata.http.headers.server`: The `Server` header returned in the web data scan; it names the server software the site reports, for example `nginx` or `Apache`.\n- `webdata.http.headers.set_cookie`: The `Set-Cookie` header returned in the web data scan; it sets cookies, with their attributes.\n- `webdata.http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the web data scan; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `webdata.http.headers.te`: The `TE` header, when it was returned in the web data scan. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `webdata.http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the web data scan; it says how the body is transferred, for example `chunked`.\n- `webdata.http.headers.upgrade`: The `Upgrade` header returned in the web data scan; it offers or asks for a switch to another protocol.\n- `webdata.http.headers.user_agent`: The `User-Agent` header, when it was returned in the web data scan. It is normally a request header (the client software), so it is rarely set.\n- `webdata.http.headers.vary`: The `Vary` header returned in the web data scan; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `webdata.http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the web data scan; it tells a client how to authenticate, usually with a `401` response.\n- `webdata.http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the web data scan; it stops browsers from guessing the content type when set to `nosniff`.\n- `webdata.http.headers.x_download_options`: The `X-Download-Options` header returned in the web data scan; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `webdata.http.headers.x_frame_options`: The `X-Frame-Options` header returned in the web data scan; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `webdata.http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the web data scan; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `webdata.http.headers.x_powered_by`: The `X-Powered-By` header returned in the web data scan; it names the technology the server reports running on, for example `Express`.\n- `webdata.http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the web data scan; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `webdata.http.cookies.name`: The name of a cookie set in the web data scan.\n- `webdata.http.cookies.value`: The value of a cookie set in the web data scan.\n- `webdata.http.cookies.domain`: The domain a cookie set in the web data scan applies to, such as `.acme.example`.\n- `webdata.http.cookies.path`: The path a cookie set in the web data scan applies to, such as `/`.\n- `webdata.http.cookies.same_party`: The SameParty attribute of a cookie set in the web data scan; in the samples it always holds the same value as `same_site`, such as `Lax` or `None`.\n- `webdata.http.cookies.priority`: The Priority attribute of a cookie set in the web data scan (`Low`, `Medium` or `High` in Chromium-based browsers).\n- `webdata.http.cookies.same_site`: The SameSite attribute of a cookie set in the web data scan, such as `Lax`, `Strict` or `None`.\n- `webdata.technology.stacks.slug`: A short identifier of a technology detected on the site, such as `iis` or `windows-server`.\n- `webdata.technology.stacks.name`: The name of a technology detected on the site, such as `IIS` or `Microsoft ASP.NET`.\n- `webdata.technology.stacks.icon`: The file name of a detected technology's icon, such as `acme.png`.\n- `webdata.technology.stacks.website`: The website of a detected technology's vendor or project.\n- `webdata.technology.stacks.cpe`: The CPE identifier of a detected technology, such as `cpe:/a:acme:acme-portal`, used to match it to known vulnerabilities.\n- `webdata.technology.stacks.version`: The detected version of a technology, such as `1.0`.\n- `webdata.technology.stacks.categories`: The categories of a detected technology, such as `Web servers` or `Operating systems`.\n- `webdata.technology.stacks.description`: A short description of a detected technology.\n- `webdata_last_change_data`: The web data fields that changed in the last change seen, as field paths under `webdata`.\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.entities`: The handles of the registry contacts and organizations linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, when it is kept.\n- `ipwhois.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the IP address asset.\n- `ipwhois.raw`: The raw IP WHOIS response for the IP address asset, when it is kept; empty on every sampled asset.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `ipwhois.network.start_address`: The first address of the registered network block that contains the IP address asset.\n- `ipwhois.network.end_address`: The last address of the registered network block that contains the IP address asset.\n- `ipwhois.network.handle`: The registry handle of the network that contains the IP address asset, such as `NET-192-0-2-0-1`.\n- `ipwhois.network.ip_version`: The IP version of the network that contains the IP address asset: `v4` or `v6`.\n- `ipwhois.network.links`: Links to the registry record of the network that contains the IP address asset, such as its RDAP and WHOIS URLs.\n- `ipwhois.network.parent_handle`: The handle of the larger network block from which the network of the IP address asset was allocated.\n- `ipwhois.network.raw`: The raw RDAP network object for the IP address asset, when it is kept.\n- `ipwhois.network.status`: The registry status of the network that contains the IP address asset, such as `active`.\n- `ipwhois.network.type`: The registry's allocation type for the network that contains the IP address asset, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `ipwhois.network.notices.title`: The title of a notice the registry attached to the network record of the IP address asset, such as `Terms of Service`.\n- `ipwhois.network.notices.description`: The text of a notice the registry attached to the network record of the IP address asset.\n- `ipwhois.network.notices.links`: Links given in a notice on the network record of the IP address asset.\n- `ipwhois.network.remarks.title`: The title of a remark on the network record of the IP address asset, such as `Registration Comments`.\n- `ipwhois.network.remarks.description`: The text of a remark on the network record of the IP address asset.\n- `ipwhois.network.remarks.links`: Links given in a remark on the network record of the IP address asset.\n- `ipwhois.network.events.action`: An event in the history of the network record of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.network.events.actor`: Who performed an event on the network record of the IP address asset, when the registry names one.\n- `ipwhois.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the IP address asset, such as `abuse`.\n- `ipwhois.objects.contact.email.value`: An e-mail address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.value`: A postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the IP address asset, such as `voice` or `work`.\n- `ipwhois.objects.contact.phone.value`: A phone number of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.kind`: What kind of contact is linked to the network of the IP address asset: `org`, `group` or `individual`.\n- `ipwhois.objects.contact.name`: The name of a contact or organization linked to the network of the IP address asset, such as `Abuse` or a company name.\n- `ipwhois.objects.contact.role`: The role given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.contact.title`: The title given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.entities`: Handles of further entities listed under a contact linked to the network of the IP address asset.\n- `ipwhois.objects.events.action`: An event in the history of a contact record linked to the network of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.objects.events.actor`: Who performed an event on a contact record linked to the network of the IP address asset, when the registry names one.\n- `ipwhois.objects.events_actor`: Events in which a contact linked to the network of the IP address asset is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `ipwhois.objects.handle`: The registry handle of a contact or organization linked to the network of the IP address asset.\n- `ipwhois.objects.links`: Links to the registry record of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.notices.title`: The title of a notice on a contact record linked to the network of the IP address asset, such as `Terms of Service`.\n- `ipwhois.objects.notices.description`: The text of a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.notices.links`: Links given in a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.raw`: The raw RDAP object of a contact linked to the network of the IP address asset, when it is kept.\n- `ipwhois.objects.remarks.title`: The title of a remark on a contact record linked to the network of the IP address asset, such as `Registration Comments`.\n- `ipwhois.objects.remarks.description`: The text of a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.roles`: The roles of a contact for the network of the IP address asset, such as `registrant`, `abuse` or `technical`.\n- `ipwhois.objects.status`: The registry status of a contact linked to the network of the IP address asset, such as `validated`.\n- `ipwhois_last_change_data`: The IP WHOIS fields that changed in the last change seen, as field paths under `ipwhois`.\n- `ipdns.ptr_records`: The PTR (reverse DNS) host names of an IP address asset.\n- `ipdns_last_change_data`: The reverse DNS fields that changed in the last change seen, as field paths under `ipdns`.\n- `issue_category_stats.name`: The name of an issue category in the per-category issue counts of the asset, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`.\n- `technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the asset, such as `Web servers` or `Analytics`.\n- `domain_snapshot.issue_category_stats.name`: The name of an issue category in the per-category issue counts of the domain and its subdomains together, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the domain and its subdomains together, such as `Web servers` or `Analytics`. Set on domain assets.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 179 fields\n\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.name.length`: The number of characters in the name without the extension: `4` for `acme.example`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois_create_date_historical`: Every creation date seen for the domain over time, so a domain that was deleted and registered again keeps its earlier dates too (UTC date-times).\n- `whois_check_date`: When the WHOIS record of the asset was last checked (UTC date-time).\n- `whois_last_change_date`: When a change in the WHOIS record of the asset was last seen (UTC date-time).\n- `dns.a.value_last_change_date`: When the A record text (`dns.a.value`) last changed (UTC date-time).\n- `dns.a.rcode_last_change_date`: When the response code of the A lookup (`dns.a.rcode`) last changed (UTC date-time).\n- `dns.a.last_change_date`: When the asset's A records last changed, in their text or their response code (UTC date-time).\n- `dns.a.ip_addresses.asn_date`: The registry allocation date that the ASN lookup reports for the A-record address, as a date at midnight UTC.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was created (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was last updated (UTC date-time).\n- `dns.a.ip_addresses.network.events.timestamp`: When an event on the network record of the A-record address happened (UTC date-time).\n- `dns.a.ip_addresses.objects.events.timestamp`: When an event on a contact record linked to the network of the A-record address happened (UTC date-time).\n- `dns.aaaa.value_last_change_date`: When the AAAA record text (`dns.aaaa.value`) last changed (UTC date-time).\n- `dns.aaaa.rcode_last_change_date`: When the response code of the AAAA lookup (`dns.aaaa.rcode`) last changed (UTC date-time).\n- `dns.aaaa.last_change_date`: When the asset's AAAA records last changed, in their text or their response code (UTC date-time).\n- `dns.caa.value_last_change_date`: When the CAA record text (`dns.caa.value`) last changed (UTC date-time).\n- `dns.caa.rcode_last_change_date`: When the response code of the CAA lookup (`dns.caa.rcode`) last changed (UTC date-time).\n- `dns.caa.last_change_date`: When the asset's CAA records last changed, in their text or their response code (UTC date-time).\n- `dns.cname.value_last_change_date`: When the CNAME record text (`dns.cname.value`) last changed (UTC date-time).\n- `dns.cname.rcode_last_change_date`: When the response code of the CNAME lookup (`dns.cname.rcode`) last changed (UTC date-time).\n- `dns.cname.last_change_date`: When the asset's CNAME records last changed, in their text or their response code (UTC date-time).\n- `dns.dnskey.value_last_change_date`: When the DNSKEY record text (`dns.dnskey.value`) last changed (UTC date-time).\n- `dns.dnskey.rcode_last_change_date`: When the response code of the DNSKEY lookup (`dns.dnskey.rcode`) last changed (UTC date-time).\n- `dns.dnskey.last_change_date`: When the asset's DNSKEY records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.value_last_change_date`: When the DS record text (`dns.ds.value`) last changed (UTC date-time).\n- `dns.ds.rcode_last_change_date`: When the response code of the DS lookup (`dns.ds.rcode`) last changed (UTC date-time).\n- `dns.ds.last_change_date`: When the asset's DS records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.records.key_tag`: The key tag (a number) of the DNSKEY that a DS record refers to.\n- `dns.mx.value_last_change_date`: When the MX record text (`dns.mx.value`) last changed (UTC date-time).\n- `dns.mx.rcode_last_change_date`: When the response code of the MX lookup (`dns.mx.rcode`) last changed (UTC date-time).\n- `dns.mx.last_change_date`: When the asset's MX records last changed, in their text or their response code (UTC date-time).\n- `dns.ns.value_last_change_date`: When the NS record text (`dns.ns.value`) last changed (UTC date-time).\n- `dns.ns.rcode_last_change_date`: When the response code of the NS lookup (`dns.ns.rcode`) last changed (UTC date-time).\n- `dns.ns.last_change_date`: When the asset's NS records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec.value_last_change_date`: When the NSEC record text (`dns.nsec.value`) last changed (UTC date-time).\n- `dns.nsec.rcode_last_change_date`: When the response code of the NSEC lookup (`dns.nsec.rcode`) last changed (UTC date-time).\n- `dns.nsec.last_change_date`: When the asset's NSEC records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec3.value_last_change_date`: When the NSEC3 record text (`dns.nsec3.value`) last changed (UTC date-time).\n- `dns.nsec3.rcode_last_change_date`: When the response code of the NSEC3 lookup (`dns.nsec3.rcode`) last changed (UTC date-time).\n- `dns.nsec3.last_change_date`: When the asset's NSEC3 records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.value_last_change_date`: When the RRSIG record text (`dns.rrsig.value`) last changed (UTC date-time).\n- `dns.rrsig.rcode_last_change_date`: When the response code of the RRSIG lookup (`dns.rrsig.rcode`) last changed (UTC date-time).\n- `dns.rrsig.last_change_date`: When the asset's RRSIG records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.signature_inception`: When an RRSIG signature becomes valid (UTC date-time).\n- `dns.rrsig.signature_expiration`: When an RRSIG signature expires (UTC date-time).\n- `dns.soa.value_last_change_date`: When the SOA record text (`dns.soa.value`) last changed (UTC date-time).\n- `dns.soa.rcode_last_change_date`: When the response code of the SOA lookup (`dns.soa.rcode`) last changed (UTC date-time).\n- `dns.soa.last_change_date`: When the asset's SOA records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.value_last_change_date`: When the SRV record text (`dns.srv.value`) last changed (UTC date-time).\n- `dns.srv.rcode_last_change_date`: When the response code of the SRV lookup (`dns.srv.rcode`) last changed (UTC date-time).\n- `dns.srv.last_change_date`: When the asset's SRV records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.records.port`: The port an SRV record points to.\n- `dns.txt.value_last_change_date`: When the TXT record text (`dns.txt.value`) last changed (UTC date-time).\n- `dns.txt.rcode_last_change_date`: When the response code of the TXT lookup (`dns.txt.rcode`) last changed (UTC date-time).\n- `dns.txt.last_change_date`: When the asset's TXT records last changed, in their text or their response code (UTC date-time).\n- `dns_check_date`: When the DNS records of the asset were last checked (UTC date-time).\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.port`: The port that the asset's TLS certificate was collected on, such as `443`.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl.validity.length`: The validity period of the certificate in seconds: 7,776,000 seconds are 90 days.\n- `ssl.extensions.signed_certificate_timestamps.timestamp`: When a Certificate Transparency log recorded the certificate, from a signed certificate timestamp (UTC date-time).\n- `ssl.extensions.signed_certificate_timestamps.version`: The version of a signed certificate timestamp; `0` stands for version 1.\n- `ssl_check_date`: When the TLS certificate of the asset was last checked (UTC date-time).\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the HTTP check, such as `301` or `200`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_check_date`: When the HTTP check of the asset last ran (UTC date-time).\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the web data scan, such as `301` or `200`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata.http.cookies.size`: The size of a cookie set in the web data scan, in bytes (name plus value).\n- `webdata.http.cookies.expires`: When a cookie set in the web data scan expires (UTC date-time); session cookies show `1969-12-31T23:59:59Z`.\n- `webdata.technology.stacks.confidence`: How certain the detection of a technology is, from 0 to 100; every sampled detection has `100`.\n- `webdata.technology.stacks.clean_version`: The major version of a detected technology as a whole number, such as `1` for version `1.0`.\n- `webdata_check_date`: When the web data scan of the asset, which collects the page content, headers and technologies, last ran (UTC date-time).\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn_date`: The registry allocation date that the ASN lookup reports for the IP address asset, as a date at midnight UTC.\n- `ipwhois.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was created (UTC date-time).\n- `ipwhois.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was last updated (UTC date-time).\n- `ipwhois.network.events.timestamp`: When an event on the network record of the IP address asset happened (UTC date-time).\n- `ipwhois.objects.events.timestamp`: When an event on a contact record linked to the network of the IP address asset happened (UTC date-time).\n- `ipwhois_check_date`: When the IP WHOIS record of an IP address asset was last checked (UTC date-time).\n- `ipwhois_last_change_date`: When a change in the IP WHOIS record of an IP address asset was last seen (UTC date-time).\n- `ipdns_check_date`: When the reverse DNS (PTR) records of an IP address asset were last checked (UTC date-time).\n- `ipdns_last_change_date`: When a change in the reverse DNS (PTR) records of an IP address asset was last seen (UTC date-time).\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `open_port_count`: The number of open ports found on the asset.\n- `open_ports`: The open port numbers found on the asset, such as `80`, `443` or `8080`.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_category_stats.count`: The number of active issues in that category on the asset.\n- `issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the asset.\n- `issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the asset.\n- `issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the asset.\n- `issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the asset.\n- `issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the asset.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `issue_count.active_by_severity.low`: The number of active issues of low severity on the asset.\n- `issue_count.active_by_severity.information`: The number of active issues of information severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `technology_count.by_category.count`: The number of technologies in that category on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity on the asset.\n- `vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity on the asset.\n- `vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity on the asset.\n- `vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) on the asset whose severity is `none`.\n- `vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) on the asset whose severity is `unknown`.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.count`: The number of active issues in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.count`: The number of distinct technologies in that category across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n**`eq`, `exists`** — 36 fields\n\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `fqdn.is_idn`: True when the host name is an internationalized domain name (IDN) with non-ASCII characters.\n- `fqdn.name.contains_confusable`: True when the name contains confusable characters that look like other letters, such as Cyrillic `а` for Latin `a`, a common trick in look-alike domains.\n- `fqdn.name.contains_hyphen`: True when the name (without the extension) contains a hyphen.\n- `fqdn.name.contains_letter`: True when the name (without the extension) contains a letter.\n- `fqdn.name.contains_number`: True when the name (without the extension) contains a digit.\n- `fqdn.domain.is_idn`: True when the registrable domain is an internationalized domain name (IDN) with non-ASCII characters.\n- `whois_privacy_enabled`: True when the platform flagged WHOIS privacy protection on the domain's registrant details; set on domain assets.\n- `ssl.signature.is_valid`: True when the asset's TLS certificate passed validation for the host; when false, `ssl.signature.invalid_reason` says why.\n- `ssl.signature.is_valid_chain`: A flag for whether the certificate chain of the asset's TLS certificate is valid. It was true on every sampled certificate, even one whose validation failed with `unable to get issuer certificate`.\n- `ssl.signature.is_self_signed`: True when the asset's TLS certificate is self-signed, that is signed by its own key rather than by a certificate authority.\n- `ssl.extensions.basic_constraints.is_ca`: True when the certificate is a certificate authority (CA) certificate, from its Basic Constraints extension.\n- `ssl.extensions.extended_key_usage.client_auth`: True when the Extended Key Usage extension allows TLS client authentication.\n- `ssl.extensions.extended_key_usage.server_auth`: True when the Extended Key Usage extension allows TLS server authentication, as website certificates need.\n- `ssl.extensions.key_usage.content_commitment`: True when the Key Usage extension allows the certificate's key to be used for content commitment (non-repudiation).\n- `ssl.extensions.key_usage.crl_sign`: True when the Key Usage extension allows the certificate's key to be used for signing certificate revocation lists (CRL sign).\n- `ssl.extensions.key_usage.data_encipherment`: True when the Key Usage extension allows the certificate's key to be used for data encipherment.\n- `ssl.extensions.key_usage.digital_signature`: True when the Key Usage extension allows the certificate's key to be used for digital signatures.\n- `ssl.extensions.key_usage.key_agreement`: True when the Key Usage extension allows the certificate's key to be used for key agreement.\n- `ssl.extensions.key_usage.key_cert_sign`: True when the Key Usage extension allows the certificate's key to be used for signing other certificates (certificate sign).\n- `ssl.extensions.key_usage.key_encipherment`: True when the Key Usage extension allows the certificate's key to be used for key encipherment.\n- `ssl.has_expired`: True when the asset's TLS certificate is past its end date.\n- `http.external_domain_redirection`: True when the HTTP check ended on a different registrable domain than it started on.\n- `http.external_fqdn_redirection`: True when the HTTP check ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.html.inspect_disabled`: A flag of the web data scan that marks pages whose inspection was disabled; it was `false` on every sampled asset.\n- `webdata.html.html_meta.no_index_status`: True when the scanned page asks search engines not to index it (a `noindex` robots directive).\n- `webdata.http.external_domain_redirection`: True when the web data scan ended on a different registrable domain than it started on.\n- `webdata.http.external_fqdn_redirection`: True when the web data scan ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.http.cookies.secure`: True when a cookie set in the web data scan is sent over HTTPS only (Secure attribute).\n- `webdata.http.cookies.http_only`: True when scripts on the page cannot read a cookie set in the web data scan (HttpOnly attribute).\n- `webdata.http.cookies.session`: True when a cookie set in the web data scan is a session cookie, deleted when the browser closes.\n- `is_parked`: True when the asset is parked; Inventory marks it with a P badge whose tooltip shows where it redirects.\n\n**`eq`, `in`, `exists`** — 8 fields\n\n- `asset_type`: The asset type: `domain`, `subdomain`, `ip` or `website`.\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `dns.dnskey.records.key_type`: The role of a DNSKEY: `ZSK` (zone-signing key), `KSK` (key-signing key) or `KSK_REVOKED` (revoked key-signing key).\n- `dns.dnskey.records.algorithm`: The DNSSEC algorithm of a DNSKEY, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.algorithm`: The DNSSEC algorithm of the key that a DS record refers to, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.digest_type`: The hash used for a DS record's digest: `SHA1`, `SHA256`, `SHA384`, `GOST` or `NULL`.\n- `dns.rrsig.algorithm`: The DNSSEC algorithm of an RRSIG signature, such as `ECDSAP256SHA256` or `RSASHA256`.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `website.parent_asset.type`: The asset type of the website's parent asset, such as `subdomain`.\n\nSortable fields:\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `website_count`: The number of website assets (`host:port`) in your inventory that belong to this asset.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `open_port_count`: The number of open ports found on the asset.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `asset_count` | integer |  |\n\n> The saved example **Request template · 38 of 740 filters** holds this body with 38 of the 740 filters (the first 10 of each operator group); the full list is above (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"postman-docs-test.deepinfo.com\"\n      }\n    ]\n  },\n  \"tags\": [\n    \"postman-docs-test\"\n  ]\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Asset Set Weight",
              "id": "6a1b45f4-4e97-5735-a3bf-4389f0eb1b88",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/search:set-weight?weight=10",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "search:set-weight"
                  ],
                  "query": [
                    {
                      "key": "weight",
                      "value": "10",
                      "description": "Min `0`, max `1000`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Set Weight API**\n\nSets a business-importance `weight` (0–1000) on every asset matching `filters`. Weights influence prioritization and scores.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 517 fields\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `tags`: Your own labels on the asset, such as a business unit or an environment; each tag is 3 to 100 characters long.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.name.unicode`: The host name without its extension, in Unicode: `acme` for `acme.example`, `www.acme` for `www.acme.example`.\n- `fqdn.name.latinized`: Latin-letter spellings of a name that has non-Latin or accented letters, so a search for `istanbul` also finds names written with `İ`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_sub.unicode`: The second-level part of a two-part extension, such as `co` in `co.uk`; empty for single-part extensions.\n- `website.path`: The URL path of a website asset, such as `/`.\n- `website.scheme`: The URL scheme of a website asset, such as `http`.\n- `website.parent_asset.id`: The ID of the domain or subdomain asset that a website asset belongs to.\n- `website.parent_asset.name`: The name of the domain or subdomain asset that a website asset belongs to.\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.name`: The registrant's name in WHOIS; often a privacy placeholder such as `redacted for privacy`.\n- `whois.registrant.country`: The registrant's country in WHOIS, as a two-letter code in lower case such as `us`.\n- `whois.registrant.state`: The registrant's state or province in WHOIS.\n- `whois.registrant.city`: The registrant's city in WHOIS.\n- `whois.registrant.street`: The registrant's street address in WHOIS.\n- `whois.registrant.postal_code`: The registrant's postal code in WHOIS.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `whois_registrant_email_historical`: Every registrant e-mail address seen for the domain over time, the current one included.\n- `whois_normalized.registrar`: The registrar reduced to a short normalized name, such as `godaddy` or `gandi`, so the same registrar matches across spellings.\n- `whois_normalized.registrant.email`: The registrant e-mail address after WHOIS normalization.\n- `whois_normalized.registrant.email_real`: Another normalized registrant e-mail field, set on fewer domains than `whois_normalized.registrant.email`; in the samples it is set only where `whois_privacy_enabled` is false, with the same address.\n- `whois_normalized.registrant.email_domain_apex`: The registrable domain of the registrant e-mail address: `acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.email_fqdn_apex`: The full host name after the `@` of the registrant e-mail address: `mail.acme.example` for `user@mail.acme.example`.\n- `whois_normalized.registrant.organization`: The registrant organization cleaned up across registrars: lower case, with spaces and punctuation removed, such as `domainsbyproxyllc`.\n- `whois_normalized.registrant.phone`: The registrant phone number reduced to its digits, such as `14805551234`.\n- `whois_last_change_data`: The WHOIS fields that changed in the last change seen, as field paths such as `whois.update_date` or `whois.domain_status`.\n- `dns.a.value`: The asset's current A records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.a.value_previous`: The asset's A records as they were before the last change, in the same text form as `dns.a.value`.\n- `dns.a.rcode`: The DNS response code returned for the asset's A lookup, such as `NOERROR`.\n- `dns.a.rcode_previous`: The DNS response code of the A lookup before it last changed.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.entities`: The handles of the registry contacts and organizations linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, when it is kept.\n- `dns.a.ip_addresses.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.\n- `dns.a.ip_addresses.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the A-record address.\n- `dns.a.ip_addresses.raw`: The raw IP WHOIS response for the A-record address, when it is kept; empty on every sampled asset.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.a.ip_addresses.network.start_address`: The first address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.end_address`: The last address of the registered network block that contains the A-record address.\n- `dns.a.ip_addresses.network.handle`: The registry handle of the network that contains the A-record address, such as `NET-192-0-2-0-1`.\n- `dns.a.ip_addresses.network.ip_version`: The IP version of the network that contains the A-record address: `v4` or `v6`.\n- `dns.a.ip_addresses.network.links`: Links to the registry record of the network that contains the A-record address, such as its RDAP and WHOIS URLs.\n- `dns.a.ip_addresses.network.parent_handle`: The handle of the larger network block from which the network of the A-record address was allocated.\n- `dns.a.ip_addresses.network.raw`: The raw RDAP network object for the A-record address, when it is kept.\n- `dns.a.ip_addresses.network.status`: The registry status of the network that contains the A-record address, such as `active`.\n- `dns.a.ip_addresses.network.type`: The registry's allocation type for the network that contains the A-record address, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `dns.a.ip_addresses.network.notices.title`: The title of a notice the registry attached to the network record of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.network.notices.description`: The text of a notice the registry attached to the network record of the A-record address.\n- `dns.a.ip_addresses.network.notices.links`: Links given in a notice on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.title`: The title of a remark on the network record of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.network.remarks.description`: The text of a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.remarks.links`: Links given in a remark on the network record of the A-record address.\n- `dns.a.ip_addresses.network.events.action`: An event in the history of the network record of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.network.events.actor`: Who performed an event on the network record of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the A-record address, such as `ACME-ARIN`.\n- `dns.a.ip_addresses.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the A-record address, such as `abuse`.\n- `dns.a.ip_addresses.objects.contact.email.value`: An e-mail address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.address.value`: A postal address of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the A-record address, such as `voice` or `work`.\n- `dns.a.ip_addresses.objects.contact.phone.value`: A phone number of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.kind`: What kind of contact is linked to the network of the A-record address: `org`, `group` or `individual`.\n- `dns.a.ip_addresses.objects.contact.name`: The name of a contact or organization linked to the network of the A-record address, such as `Abuse` or a company name.\n- `dns.a.ip_addresses.objects.contact.role`: The role given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.contact.title`: The title given in the contact card of an entity linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.entities`: Handles of further entities listed under a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.events.action`: An event in the history of a contact record linked to the network of the A-record address, such as `registration` or `last changed`.\n- `dns.a.ip_addresses.objects.events.actor`: Who performed an event on a contact record linked to the network of the A-record address, when the registry names one.\n- `dns.a.ip_addresses.objects.events_actor`: Events in which a contact linked to the network of the A-record address is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `dns.a.ip_addresses.objects.handle`: The registry handle of a contact or organization linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.links`: Links to the registry record of a contact linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.title`: The title of a notice on a contact record linked to the network of the A-record address, such as `Terms of Service`.\n- `dns.a.ip_addresses.objects.notices.description`: The text of a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.notices.links`: Links given in a notice on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.raw`: The raw RDAP object of a contact linked to the network of the A-record address, when it is kept.\n- `dns.a.ip_addresses.objects.remarks.title`: The title of a remark on a contact record linked to the network of the A-record address, such as `Registration Comments`.\n- `dns.a.ip_addresses.objects.remarks.description`: The text of a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the A-record address.\n- `dns.a.ip_addresses.objects.roles`: The roles of a contact for the network of the A-record address, such as `registrant`, `abuse` or `technical`.\n- `dns.a.ip_addresses.objects.status`: The registry status of a contact linked to the network of the A-record address, such as `validated`.\n- `dns.a.ip_history`: Every IPv4 address seen in the asset's A records over time, the current ones included.\n- `dns.aaaa.value`: The asset's current AAAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.aaaa.value_previous`: The asset's AAAA records as they were before the last change, in the same text form as `dns.aaaa.value`.\n- `dns.aaaa.rcode`: The DNS response code returned for the asset's AAAA lookup, such as `NOERROR`.\n- `dns.aaaa.rcode_previous`: The DNS response code of the AAAA lookup before it last changed.\n- `dns.aaaa.ip_addresses`: The IPv6 addresses in the asset's AAAA records.\n- `dns.caa.value`: The asset's current CAA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.caa.value_previous`: The asset's CAA records as they were before the last change, in the same text form as `dns.caa.value`.\n- `dns.caa.rcode`: The DNS response code returned for the asset's CAA lookup, such as `NOERROR`.\n- `dns.caa.rcode_previous`: The DNS response code of the CAA lookup before it last changed.\n- `dns.caa.issue_fqdns`: The certificate authorities allowed to issue certificates for the name, from the CAA `issue` tags, such as `fernhill.example` or `kestrel.example`.\n- `dns.caa.issuewild_fqdns`: The certificate authorities allowed to issue wildcard certificates for the name, from the CAA `issuewild` tags.\n- `dns.caa.iodef_emails`: The e-mail addresses from the CAA `iodef` tags, where certificate authorities report requests that break the CAA policy.\n- `dns.cname.value`: The asset's current CNAME records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.cname.value_previous`: The asset's CNAME records as they were before the last change, in the same text form as `dns.cname.value`.\n- `dns.cname.rcode`: The DNS response code returned for the asset's CNAME lookup, such as `NOERROR`.\n- `dns.cname.rcode_previous`: The DNS response code of the CNAME lookup before it last changed.\n- `dns.cname.canonical_fqdns`: The host names the asset's CNAME records point to (the alias targets).\n- `dns.dnskey.value`: The asset's current DNSKEY records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.dnskey.value_previous`: The asset's DNSKEY records as they were before the last change, in the same text form as `dns.dnskey.value`.\n- `dns.dnskey.rcode`: The DNS response code returned for the asset's DNSKEY lookup, such as `NOERROR`.\n- `dns.dnskey.rcode_previous`: The DNS response code of the DNSKEY lookup before it last changed.\n- `dns.dnskey.records.public_key`: The public key of a DNSKEY record, Base64-encoded and split into space-separated groups as in the zone-file text.\n- `dns.ds.value`: The asset's current DS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ds.value_previous`: The asset's DS records as they were before the last change, in the same text form as `dns.ds.value`.\n- `dns.ds.rcode`: The DNS response code returned for the asset's DS lookup, such as `NOERROR`.\n- `dns.ds.rcode_previous`: The DNS response code of the DS lookup before it last changed.\n- `dns.ds.records.digest`: The digest of a DS record, the hash of the DNSKEY it refers to.\n- `dns.mx.value`: The asset's current MX records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.mx.value_previous`: The asset's MX records as they were before the last change, in the same text form as `dns.mx.value`.\n- `dns.mx.rcode`: The DNS response code returned for the asset's MX lookup, such as `NOERROR`.\n- `dns.mx.rcode_previous`: The DNS response code of the MX lookup before it last changed.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns.mx.domains`: The registrable domains of the asset's mail servers, such as `acme.example`.\n- `dns.ns.value`: The asset's current NS records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.ns.value_previous`: The asset's NS records as they were before the last change, in the same text form as `dns.ns.value`.\n- `dns.ns.rcode`: The DNS response code returned for the asset's NS lookup, such as `NOERROR`.\n- `dns.ns.rcode_previous`: The DNS response code of the NS lookup before it last changed.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.ns.domains`: The registrable domains of the asset's name servers, such as `acme.example`.\n- `dns.nsec.value`: The asset's current NSEC records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec.value_previous`: The asset's NSEC records as they were before the last change, in the same text form as `dns.nsec.value`.\n- `dns.nsec.rcode`: The DNS response code returned for the asset's NSEC lookup, such as `NOERROR`.\n- `dns.nsec.rcode_previous`: The DNS response code of the NSEC lookup before it last changed.\n- `dns.nsec.records.next_domain`: The next name in the zone, from an NSEC record.\n- `dns.nsec.records.record_types`: The record types that exist at the name, from an NSEC record's type list, such as `A`, `NS` or `SOA`.\n- `dns.nsec3.value`: The asset's current NSEC3 records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.nsec3.value_previous`: The asset's NSEC3 records as they were before the last change, in the same text form as `dns.nsec3.value`.\n- `dns.nsec3.rcode`: The DNS response code returned for the asset's NSEC3 lookup, such as `NOERROR`.\n- `dns.nsec3.rcode_previous`: The DNS response code of the NSEC3 lookup before it last changed.\n- `dns.nsec3.records.next_domain_hashed`: The hashed next name in the zone, from an NSEC3 record.\n- `dns.nsec3.records.record_types`: The record types that exist at the name, from an NSEC3 record's type list, such as `A` or `MX`.\n- `dns.rrsig.value`: The asset's current RRSIG records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.rrsig.value_previous`: The asset's RRSIG records as they were before the last change, in the same text form as `dns.rrsig.value`.\n- `dns.rrsig.rcode`: The DNS response code returned for the asset's RRSIG lookup, such as `NOERROR`.\n- `dns.rrsig.rcode_previous`: The DNS response code of the RRSIG lookup before it last changed.\n- `dns.rrsig.type_covered`: The record type that an RRSIG signature covers, such as `A` or `SOA`.\n- `dns.rrsig.signature`: The signature data of an RRSIG record, Base64-encoded.\n- `dns.soa.value`: The asset's current SOA records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.soa.value_previous`: The asset's SOA records as they were before the last change, in the same text form as `dns.soa.value`.\n- `dns.soa.rcode`: The DNS response code returned for the asset's SOA lookup, such as `NOERROR`.\n- `dns.soa.rcode_previous`: The DNS response code of the SOA lookup before it last changed.\n- `dns.soa.mnames`: The MNAME of the SOA record: the primary name server of the zone, such as `ns1.acme.example`.\n- `dns.soa.rnames`: The RNAME of the SOA record, the zone administrator's mailbox in DNS form: `hostmaster.acme.example` stands for the mailbox `hostmaster` at `acme.example`.\n- `dns.soa.rname_emails`: The RNAME of the SOA record written as an e-mail address, such as `user@acme.example`.\n- `dns.srv.value`: The asset's current SRV records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.srv.value_previous`: The asset's SRV records as they were before the last change, in the same text form as `dns.srv.value`.\n- `dns.srv.rcode`: The DNS response code returned for the asset's SRV lookup, such as `NOERROR`.\n- `dns.srv.rcode_previous`: The DNS response code of the SRV lookup before it last changed.\n- `dns.srv.records.service`: The service named in an SRV record (the `_service` part of its name).\n- `dns.srv.records.protocol`: The protocol named in an SRV record (the `_proto` part of its name, such as TCP or UDP).\n- `dns.srv.records.target`: The host name an SRV record points to.\n- `dns.txt.value`: The asset's current TXT records as zone-file text (name, TTL, class, type and data), all records in one string.\n- `dns.txt.value_previous`: The asset's TXT records as they were before the last change, in the same text form as `dns.txt.value`.\n- `dns.txt.rcode`: The DNS response code returned for the asset's TXT lookup, such as `NOERROR`.\n- `dns.txt.rcode_previous`: The DNS response code of the TXT lookup before it last changed.\n- `dns.txt.values`: Each TXT record of the asset as its quoted text, such as `\"v=spf1 include:_spf.acme.example ~all\"`; the quotes are part of the value.\n- `dns.txt.spf_list.value`: The text of an SPF record (a TXT record that starts with `v=spf1`), quoted as in `dns.txt.values`.\n- `dns.txt.spf_list.allowed_domains`: The registrable domains that an SPF record refers to, such as `acme.example` for `include:_spf.acme.example`.\n- `dns.txt.spf_list.allowed_ips`: The IP addresses and ranges that an SPF record authorizes to send mail (its `ip4:` and `ip6:` entries).\n- `dns.txt.verifications.value`: The text of a site-verification TXT record, quoted as in `dns.txt.values`.\n- `dns.txt.verifications.domain`: The domain of the service a verification record is for, such as `acme.example`, `fernhill.example` or `kestrel.example`.\n- `dns.txt.verifications.name`: The name of a verification record, such as `site-verification` or `domain-verification`.\n- `dns_last_change_data`: The DNS fields that changed in the last change seen, as field paths such as `dns.soa.mnames`.\n- `ssl.target`: The host name that the asset's TLS certificate was collected from, normally the asset itself.\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.md5`: The MD5 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.fingerprint.sha256`: The SHA-256 fingerprint of the asset's TLS certificate, as lower-case hex; one fingerprint identifies one certificate.\n- `ssl.issuer.common_name`: The common name (CN) of the certificate authority that issued the asset's TLS certificate, such as `WE1` or `YE2`.\n- `ssl.issuer.country`: The country (C) of the certificate authority that issued the asset's TLS certificate, as a two-letter code such as `US`.\n- `ssl.issuer.state`: The state or province (ST) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.locality`: The locality or city (L) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer.organization`: The organization (O) of the certificate authority that issued the asset's TLS certificate, such as `Let's Encrypt` or `Google Trust Services`.\n- `ssl.issuer.organizational_unit`: The organizational unit (OU) of the certificate authority that issued the asset's TLS certificate.\n- `ssl.issuer_dn`: The full distinguished name of the issuer of the asset's TLS certificate, as one string such as `CN=WE1,O=Google Trust Services,C=US`.\n- `ssl.subject.common_name`: The common name (CN) of the subject (holder) of the asset's TLS certificate, usually a host name such as `acme.example`.\n- `ssl.subject.country`: The country (C) of the subject (holder) of the asset's TLS certificate, as a two-letter code.\n- `ssl.subject.state`: The state or province (ST) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.locality`: The locality or city (L) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject.organizational_unit`: The organizational unit (OU) of the subject (holder) of the asset's TLS certificate.\n- `ssl.subject_dn`: The full distinguished name of the subject of the asset's TLS certificate, such as `CN=acme.example`; one that starts with `CN=*.` belongs to a wildcard certificate.\n- `ssl.signature.value`: The signature of the asset's TLS certificate, Base64-encoded.\n- `ssl.signature.invalid_reason`: Why certificate validation failed, such as a host name mismatch or `unable to get issuer certificate`.\n- `ssl.signature.algorithm.name`: The hash algorithm of the signature on the asset's TLS certificate, such as `sha256` or `sha384`.\n- `ssl.signature.algorithm.oid`: The object identifier (OID) of the signature algorithm, such as `1.2.840.113549.1.1.11` (SHA-256 with RSA) or `1.2.840.10045.4.3.2` (ECDSA with SHA-256).\n- `ssl.extensions.authority_key_id`: The Authority Key Identifier extension, which identifies the issuer's key, Base64-encoded.\n- `ssl.extensions.certificate_policies`: The policy OIDs in the Certificate Policies extension, such as `2.23.140.1.2.1` (domain validated).\n- `ssl.extensions.signed_certificate_timestamps.log_id`: The ID of the Certificate Transparency log that issued a signed certificate timestamp (SCT) for the certificate, Base64-encoded.\n- `ssl.extensions.signed_certificate_timestamps.signature`: The log's signature on a signed certificate timestamp, Base64-encoded.\n- `ssl.extensions.subject_alt_name.dns_names`: The host names in the certificate's Subject Alternative Name extension, including wildcard names such as `*.acme.example`.\n- `ssl.extensions.subject_key_id`: The Subject Key Identifier extension, which identifies the certificate's own key, Base64-encoded.\n- `ssl.subject_key_info.fingerprint.hash_algorithm`: The hash algorithm used for `ssl.subject_key_info.fingerprint.value`, such as `sha256` or `sha384`.\n- `ssl.subject_key_info.fingerprint.value`: A hex fingerprint recorded under the certificate's subject key information, made with the hash in `hash_algorithm`. In the samples it equals `ssl.fingerprint.sha256` when that hash is SHA-256.\n- `ssl.subject_key_info.key_algorithm.name`: The algorithm of the certificate's public key, such as `RSA` or `ECDSA`.\n- `ssl.version.name`: The X.509 version of the certificate, such as `v3`.\n- `ssl.version.value`: The X.509 version as encoded in the certificate, counted from zero: `2` means `v3`.\n- `ssl.tbs_fingerprint`: A SHA-256 fingerprint (hex) of the certificate's to-be-signed part, the certificate content without its signature.\n- `ssl.certificate`: The whole certificate, Base64-encoded (a PEM body without the header and footer lines).\n- `ssl.fqdn_list`: The host names the certificate covers, with the `*.` of wildcard names removed and duplicates merged, so `*.acme.example` and `acme.example` both give `acme.example`.\n- `ssl_last_change_data`: The certificate fields that changed in the last change seen, as field paths such as `ssl.validity.end_date`.\n- `http.requested_url`: The URL the HTTP check started from, such as `http://acme.example`.\n- `http.requested_domain`: The registrable domain of the URL the HTTP check started from.\n- `http.requested_fqdn`: The host name of the URL the HTTP check started from.\n- `http.final_url`: The URL the HTTP check ended on after following all redirects.\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.redirection_history.url`: A URL in the redirect chain of the HTTP check, listed in the order visited.\n- `http.headers.accept`: The `Accept` header, when it was returned in the HTTP check. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the HTTP check. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `http.headers.accept_language`: The `Accept-Language` header, when it was returned in the HTTP check. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the HTTP check; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the HTTP check; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the HTTP check; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the HTTP check; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the HTTP check; it lists the response headers that scripts from other origins may read (CORS).\n- `http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the HTTP check; it says how many seconds browsers may cache a CORS preflight result.\n- `http.headers.alt_svc`: The `Alt-Svc` header returned in the HTTP check; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `http.headers.authorization`: The `Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `http.headers.cache_control`: The `Cache-Control` header returned in the HTTP check; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the HTTP check; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `http.headers.content_disposition`: The `Content-Disposition` header returned in the HTTP check; it says whether the content is shown in the browser or downloaded as a file.\n- `http.headers.content_encoding`: The `Content-Encoding` header returned in the HTTP check; it names the compression applied to the response body, for example `gzip` or `br`.\n- `http.headers.content_language`: The `Content-Language` header returned in the HTTP check; it gives the language of the content, for example `en` or `tr`.\n- `http.headers.content_length`: The `Content-Length` header returned in the HTTP check; it gives the size of the response body in bytes.\n- `http.headers.content_range`: The `Content-Range` header returned in the HTTP check; it says which part of the full body a partial response holds.\n- `http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the HTTP check; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `http.headers.content_type`: The `Content-Type` header returned in the HTTP check; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `http.headers.cookie`: The `Cookie` header, when it was returned in the HTTP check. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the HTTP check; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the HTTP check; it controls whether the page shares its browsing context with cross-origin windows.\n- `http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the HTTP check; it controls which sites may load the resource.\n- `http.headers.date`: The `Date` header returned in the HTTP check; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `http.headers.early_data`: The `Early-Data` header, when it was returned in the HTTP check. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `http.headers.expect_ct`: The `Expect-CT` header returned in the HTTP check; it is a deprecated header about Certificate Transparency enforcement.\n- `http.headers.expires`: The `Expires` header returned in the HTTP check; it gives the date after which the response counts as stale, in HTTP date format.\n- `http.headers.feature_policy`: The `Feature-Policy` header returned in the HTTP check; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `http.headers.host`: The `Host` header, when it was returned in the HTTP check. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the HTTP check. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the HTTP check. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `http.headers.last_modified`: The `Last-Modified` header returned in the HTTP check; it gives the time the server says the resource last changed, in HTTP date format.\n- `http.headers.origin_isolation`: The `Origin-Isolation` header returned in the HTTP check; it is an experimental header that asks browsers to isolate the site's origin.\n- `http.headers.others.name`: The name of a header returned in the HTTP check that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `http.headers.others.value`: The value of a header listed in `headers.others` for the HTTP check.\n- `http.headers.permission_policy`: The `Permission-Policy` header returned in the HTTP check; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `http.headers.permissions_policy`: The `Permissions-Policy` header returned in the HTTP check; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `http.headers.pragma`: The `Pragma` header returned in the HTTP check; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the HTTP check; it tells a client how to authenticate to a proxy.\n- `http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the HTTP check; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `http.headers.range`: The `Range` header, when it was returned in the HTTP check. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `http.headers.referer`: The `Referer` header, when it was returned in the HTTP check. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `http.headers.referrer_policy`: The `Referrer-Policy` header returned in the HTTP check; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the HTTP check. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `http.headers.server`: The `Server` header returned in the HTTP check; it names the server software the site reports, for example `nginx` or `Apache`.\n- `http.headers.set_cookie`: The `Set-Cookie` header returned in the HTTP check; it sets cookies, with their attributes.\n- `http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the HTTP check; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `http.headers.te`: The `TE` header, when it was returned in the HTTP check. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the HTTP check; it says how the body is transferred, for example `chunked`.\n- `http.headers.upgrade`: The `Upgrade` header returned in the HTTP check; it offers or asks for a switch to another protocol.\n- `http.headers.user_agent`: The `User-Agent` header, when it was returned in the HTTP check. It is normally a request header (the client software), so it is rarely set.\n- `http.headers.vary`: The `Vary` header returned in the HTTP check; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the HTTP check; it tells a client how to authenticate, usually with a `401` response.\n- `http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the HTTP check; it stops browsers from guessing the content type when set to `nosniff`.\n- `http.headers.x_download_options`: The `X-Download-Options` header returned in the HTTP check; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `http.headers.x_frame_options`: The `X-Frame-Options` header returned in the HTTP check; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the HTTP check; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `http.headers.x_powered_by`: The `X-Powered-By` header returned in the HTTP check; it names the technology the server reports running on, for example `Express`.\n- `http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the HTTP check; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `http.cookies.name`: The name of a cookie set in the HTTP check.\n- `http.cookies.value`: The value of a cookie set in the HTTP check.\n- `http.html.source_code_hash`: A SHA-256 hash of the page source returned in the HTTP check; the same hash means the same source.\n- `http_last_change_data`: The HTTP check fields that changed in the last change seen, as field paths such as `http.html.source_code_hash`.\n- `webdata.requested_url`: The URL the web data scan started from, such as `http://acme.example`.\n- `webdata.requested_domain`: The registrable domain of the URL the web data scan started from.\n- `webdata.requested_fqdn`: The host name of the URL the web data scan started from.\n- `webdata.html.internal_links_fqdns`: The host names of links on the scanned page that stay within the site's own domain, such as other subdomains.\n- `webdata.html.external_links_domains`: The registrable domains of links on the scanned page that point to other domains, such as `kestrel.example`.\n- `webdata.html.external_links_fqdns`: The host names of links on the scanned page that point to other domains, such as `www.kestrel.example`.\n- `webdata.html.external_links`: The full URLs of links on the scanned page that point to other domains.\n- `webdata.html.script_links`: The URLs of the scripts the scanned page loads.\n- `webdata.html.iframe_links`: The URLs of the frames (iframes) embedded in the scanned page.\n- `webdata.html.trackers.name`: The name of an analytics or advertising tracker found on the scanned page, such as `google_adsense` or `google_tag_manager`.\n- `webdata.html.trackers.values`: The IDs found for a tracker, such as a Google Analytics ID that starts with `G-` or `UA-`.\n- `webdata.html.emails`: The e-mail addresses found on the scanned page.\n- `webdata.html.emails_internal`: The e-mail addresses found on the scanned page that belong to the site's own domain.\n- `webdata.html.source_code_hash`: A SHA-256 hash of the page source in the web data scan; the same hash means the same source.\n- `webdata.html.content_hash`: A SHA-256 hash of the page content in the web data scan, kept apart from `source_code_hash`, the hash of the raw source.\n- `webdata.html.content_top_keywords`: The most frequent words in the text of the scanned page.\n- `webdata.html.favicon_links`: The URLs of the icons the scanned page declares, such as its favicon and touch icons.\n- `webdata.html.html_meta.name`: The site or application name declared in the scanned page's metadata.\n- `webdata.html.html_meta.description`: The meta description of the scanned page.\n- `webdata.html.html_meta.language`: The language the scanned page declares, such as `en`, `tr` or `en-US`.\n- `webdata.html.html_meta.language_alternatives`: The languages of the alternative versions the scanned page links to, such as `en` or `ar`.\n- `webdata.html.html_meta.keywords`: The keywords listed in the keywords meta tag of the scanned page.\n- `webdata.html.html_meta.encoding`: The character encoding the scanned page declares, such as `utf-8`.\n- `webdata.html.html_meta.canonical_url`: The canonical URL the scanned page declares.\n- `webdata.html.html_meta.title`: The title of the scanned page.\n- `webdata.favicon.url`: The URL of a site icon (favicon) recorded by the web data scan.\n- `webdata.favicon.hash`: A SHA-256 hash of a site icon; the same hash means the same icon.\n- `webdata.http.final_url`: The URL the web data scan ended on after following all redirects.\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.redirection_history.url`: A URL in the redirect chain of the web data scan, listed in the order visited.\n- `webdata.http.redirection_history.method`: How a step of the web data scan's redirect chain was made; `http-header` (a redirect sent in the HTTP response) is the value in the samples.\n- `webdata.http.headers.accept`: The `Accept` header, when it was returned in the web data scan. It is normally a request header (the content types a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_encoding`: The `Accept-Encoding` header, when it was returned in the web data scan. It is normally a request header (the compression formats a client accepts), so it is rarely set.\n- `webdata.http.headers.accept_language`: The `Accept-Language` header, when it was returned in the web data scan. It is normally a request header (the languages a client prefers), so it is rarely set.\n- `webdata.http.headers.access_control_allow_credentials`: The `Access-Control-Allow-Credentials` header returned in the web data scan; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).\n- `webdata.http.headers.access_control_allow_headers`: The `Access-Control-Allow-Headers` header returned in the web data scan; it lists the request headers allowed in cross-origin requests (CORS), for example `*`.\n- `webdata.http.headers.access_control_allow_methods`: The `Access-Control-Allow-Methods` header returned in the web data scan; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`.\n- `webdata.http.headers.access_control_allow_origin`: The `Access-Control-Allow-Origin` header returned in the web data scan; it names the origins allowed to read the response (CORS), where `*` allows any origin.\n- `webdata.http.headers.access_control_expose_headers`: The `Access-Control-Expose-Headers` header returned in the web data scan; it lists the response headers that scripts from other origins may read (CORS).\n- `webdata.http.headers.access_control_max_age`: The `Access-Control-Max-Age` header returned in the web data scan; it says how many seconds browsers may cache a CORS preflight result.\n- `webdata.http.headers.alt_svc`: The `Alt-Svc` header returned in the web data scan; it advertises other protocols or ports that serve the site, for example `h3=\":443\"; ma=86400` for HTTP/3.\n- `webdata.http.headers.authorization`: The `Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to the server), so it is rarely set.\n- `webdata.http.headers.cache_control`: The `Cache-Control` header returned in the web data scan; it sets the caching rules for the response, for example `no-cache, must-revalidate`.\n- `webdata.http.headers.clear_site_data`: The `Clear-Site-Data` header returned in the web data scan; it tells browsers to clear stored data for the site, such as cookies, storage or cache.\n- `webdata.http.headers.content_disposition`: The `Content-Disposition` header returned in the web data scan; it says whether the content is shown in the browser or downloaded as a file.\n- `webdata.http.headers.content_encoding`: The `Content-Encoding` header returned in the web data scan; it names the compression applied to the response body, for example `gzip` or `br`.\n- `webdata.http.headers.content_language`: The `Content-Language` header returned in the web data scan; it gives the language of the content, for example `en` or `tr`.\n- `webdata.http.headers.content_length`: The `Content-Length` header returned in the web data scan; it gives the size of the response body in bytes.\n- `webdata.http.headers.content_range`: The `Content-Range` header returned in the web data scan; it says which part of the full body a partial response holds.\n- `webdata.http.headers.content_security_policy`: The `Content-Security-Policy` header returned in the web data scan; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.\n- `webdata.http.headers.content_type`: The `Content-Type` header returned in the web data scan; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`.\n- `webdata.http.headers.cookie`: The `Cookie` header, when it was returned in the web data scan. It is normally a request header (the cookies a client sends), so it is rarely set.\n- `webdata.http.headers.cross_origin_embedder_policy`: The `Cross-Origin-Embedder-Policy` header returned in the web data scan; it controls whether the page may embed cross-origin resources that do not explicitly allow it.\n- `webdata.http.headers.cross_origin_opener_policy`: The `Cross-Origin-Opener-Policy` header returned in the web data scan; it controls whether the page shares its browsing context with cross-origin windows.\n- `webdata.http.headers.cross_origin_resource_policy`: The `Cross-Origin-Resource-Policy` header returned in the web data scan; it controls which sites may load the resource.\n- `webdata.http.headers.date`: The `Date` header returned in the web data scan; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`.\n- `webdata.http.headers.early_data`: The `Early-Data` header, when it was returned in the web data scan. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.\n- `webdata.http.headers.expect_ct`: The `Expect-CT` header returned in the web data scan; it is a deprecated header about Certificate Transparency enforcement.\n- `webdata.http.headers.expires`: The `Expires` header returned in the web data scan; it gives the date after which the response counts as stale, in HTTP date format.\n- `webdata.http.headers.feature_policy`: The `Feature-Policy` header returned in the web data scan; it is the older name of `Permissions-Policy` and limits the browser features the page may use.\n- `webdata.http.headers.host`: The `Host` header, when it was returned in the web data scan. It is normally a request header (the host name a client asks for), so it is rarely set.\n- `webdata.http.headers.if_modified_since`: The `If-Modified-Since` header, when it was returned in the web data scan. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.\n- `webdata.http.headers.if_none_match`: The `If-None-Match` header, when it was returned in the web data scan. It is normally a request header (a condition based on an ETag), so it is rarely set.\n- `webdata.http.headers.last_modified`: The `Last-Modified` header returned in the web data scan; it gives the time the server says the resource last changed, in HTTP date format.\n- `webdata.http.headers.origin_isolation`: The `Origin-Isolation` header returned in the web data scan; it is an experimental header that asks browsers to isolate the site's origin.\n- `webdata.http.headers.others.name`: The name of a header returned in the web data scan that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`.\n- `webdata.http.headers.others.value`: The value of a header listed in `headers.others` for the web data scan.\n- `webdata.http.headers.permission_policy`: The `Permission-Policy` header returned in the web data scan; it is recorded under this singular spelling, separately from `Permissions-Policy`.\n- `webdata.http.headers.permissions_policy`: The `Permissions-Policy` header returned in the web data scan; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`.\n- `webdata.http.headers.pragma`: The `Pragma` header returned in the web data scan; it is an older HTTP/1.0 caching header, for example `no-cache`.\n- `webdata.http.headers.proxy_authenticate`: The `Proxy-Authenticate` header returned in the web data scan; it tells a client how to authenticate to a proxy.\n- `webdata.http.headers.proxy_authorization`: The `Proxy-Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.\n- `webdata.http.headers.public_key_pins`: The `Public-Key-Pins` header returned in the web data scan; it is a deprecated header (HPKP) that pinned the site's public keys.\n- `webdata.http.headers.range`: The `Range` header, when it was returned in the web data scan. It is normally a request header (a request for only part of a resource), so it is rarely set.\n- `webdata.http.headers.referer`: The `Referer` header, when it was returned in the web data scan. It is normally a request header (the address of the page a request came from), so it is rarely set.\n- `webdata.http.headers.referrer_policy`: The `Referrer-Policy` header returned in the web data scan; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`.\n- `webdata.http.headers.sec_fetch_dest`: The `Sec-Fetch-Dest` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.\n- `webdata.http.headers.sec_fetch_mode`: The `Sec-Fetch-Mode` header, when it was returned in the web data scan. It is normally a request header (browser metadata on the request mode), so it is rarely set.\n- `webdata.http.headers.sec_fetch_site`: The `Sec-Fetch-Site` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.\n- `webdata.http.headers.sec_fetch_user`: The `Sec-Fetch-User` header, when it was returned in the web data scan. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.\n- `webdata.http.headers.server`: The `Server` header returned in the web data scan; it names the server software the site reports, for example `nginx` or `Apache`.\n- `webdata.http.headers.set_cookie`: The `Set-Cookie` header returned in the web data scan; it sets cookies, with their attributes.\n- `webdata.http.headers.strict_transport_security`: The `Strict-Transport-Security` header returned in the web data scan; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`.\n- `webdata.http.headers.te`: The `TE` header, when it was returned in the web data scan. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.\n- `webdata.http.headers.transfer_encoding`: The `Transfer-Encoding` header returned in the web data scan; it says how the body is transferred, for example `chunked`.\n- `webdata.http.headers.upgrade`: The `Upgrade` header returned in the web data scan; it offers or asks for a switch to another protocol.\n- `webdata.http.headers.user_agent`: The `User-Agent` header, when it was returned in the web data scan. It is normally a request header (the client software), so it is rarely set.\n- `webdata.http.headers.vary`: The `Vary` header returned in the web data scan; it tells caches which request headers change the response, for example `Accept-Encoding`.\n- `webdata.http.headers.www_authenticate`: The `WWW-Authenticate` header returned in the web data scan; it tells a client how to authenticate, usually with a `401` response.\n- `webdata.http.headers.x_content_type_options`: The `X-Content-Type-Options` header returned in the web data scan; it stops browsers from guessing the content type when set to `nosniff`.\n- `webdata.http.headers.x_download_options`: The `X-Download-Options` header returned in the web data scan; it stops Internet Explorer from opening downloads directly when set to `noopen`.\n- `webdata.http.headers.x_frame_options`: The `X-Frame-Options` header returned in the web data scan; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`.\n- `webdata.http.headers.x_permitted_cross_domain_policies`: The `X-Permitted-Cross-Domain-Policies` header returned in the web data scan; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.\n- `webdata.http.headers.x_powered_by`: The `X-Powered-By` header returned in the web data scan; it names the technology the server reports running on, for example `Express`.\n- `webdata.http.headers.x_xss_protection`: The `X-XSS-Protection` header returned in the web data scan; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`.\n- `webdata.http.cookies.name`: The name of a cookie set in the web data scan.\n- `webdata.http.cookies.value`: The value of a cookie set in the web data scan.\n- `webdata.http.cookies.domain`: The domain a cookie set in the web data scan applies to, such as `.acme.example`.\n- `webdata.http.cookies.path`: The path a cookie set in the web data scan applies to, such as `/`.\n- `webdata.http.cookies.same_party`: The SameParty attribute of a cookie set in the web data scan; in the samples it always holds the same value as `same_site`, such as `Lax` or `None`.\n- `webdata.http.cookies.priority`: The Priority attribute of a cookie set in the web data scan (`Low`, `Medium` or `High` in Chromium-based browsers).\n- `webdata.http.cookies.same_site`: The SameSite attribute of a cookie set in the web data scan, such as `Lax`, `Strict` or `None`.\n- `webdata.technology.stacks.slug`: A short identifier of a technology detected on the site, such as `iis` or `windows-server`.\n- `webdata.technology.stacks.name`: The name of a technology detected on the site, such as `IIS` or `Microsoft ASP.NET`.\n- `webdata.technology.stacks.icon`: The file name of a detected technology's icon, such as `acme.png`.\n- `webdata.technology.stacks.website`: The website of a detected technology's vendor or project.\n- `webdata.technology.stacks.cpe`: The CPE identifier of a detected technology, such as `cpe:/a:acme:acme-portal`, used to match it to known vulnerabilities.\n- `webdata.technology.stacks.version`: The detected version of a technology, such as `1.0`.\n- `webdata.technology.stacks.categories`: The categories of a detected technology, such as `Web servers` or `Operating systems`.\n- `webdata.technology.stacks.description`: A short description of a detected technology.\n- `webdata_last_change_data`: The web data fields that changed in the last change seen, as field paths under `webdata`.\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.entities`: The handles of the registry contacts and organizations linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.nir.nets.address`: The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.nir.nets.contacts.admin.division`: The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.email`: The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.fax`: The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.organization`: The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.phone`: The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.reply_email`: The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.name`: The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.admin.title`: The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.division`: The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.email`: The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.fax`: The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.organization`: The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.phone`: The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.reply_email`: The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.name`: The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.contacts.tech.title`: The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.country`: The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.handle`: The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.name`: The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.nameservers`: The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.postal_code`: The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.nets.range`: The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.nir.raw`: The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, when it is kept.\n- `ipwhois.nir.query`: The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.\n- `ipwhois.query`: The IP address that was looked up in IP WHOIS (RDAP), that is the IP address asset.\n- `ipwhois.raw`: The raw IP WHOIS response for the IP address asset, when it is kept; empty on every sampled asset.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `ipwhois.network.start_address`: The first address of the registered network block that contains the IP address asset.\n- `ipwhois.network.end_address`: The last address of the registered network block that contains the IP address asset.\n- `ipwhois.network.handle`: The registry handle of the network that contains the IP address asset, such as `NET-192-0-2-0-1`.\n- `ipwhois.network.ip_version`: The IP version of the network that contains the IP address asset: `v4` or `v6`.\n- `ipwhois.network.links`: Links to the registry record of the network that contains the IP address asset, such as its RDAP and WHOIS URLs.\n- `ipwhois.network.parent_handle`: The handle of the larger network block from which the network of the IP address asset was allocated.\n- `ipwhois.network.raw`: The raw RDAP network object for the IP address asset, when it is kept.\n- `ipwhois.network.status`: The registry status of the network that contains the IP address asset, such as `active`.\n- `ipwhois.network.type`: The registry's allocation type for the network that contains the IP address asset, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`.\n- `ipwhois.network.notices.title`: The title of a notice the registry attached to the network record of the IP address asset, such as `Terms of Service`.\n- `ipwhois.network.notices.description`: The text of a notice the registry attached to the network record of the IP address asset.\n- `ipwhois.network.notices.links`: Links given in a notice on the network record of the IP address asset.\n- `ipwhois.network.remarks.title`: The title of a remark on the network record of the IP address asset, such as `Registration Comments`.\n- `ipwhois.network.remarks.description`: The text of a remark on the network record of the IP address asset.\n- `ipwhois.network.remarks.links`: Links given in a remark on the network record of the IP address asset.\n- `ipwhois.network.events.action`: An event in the history of the network record of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.network.events.actor`: Who performed an event on the network record of the IP address asset, when the registry names one.\n- `ipwhois.objects.uid`: The handle of a registry contact or organization (RDAP entity) linked to the network of the IP address asset, such as `ACME-ARIN`.\n- `ipwhois.objects.contact.email.type`: The type of an e-mail address of a contact linked to the network of the IP address asset, such as `abuse`.\n- `ipwhois.objects.contact.email.value`: An e-mail address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.type`: The type of a postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.address.value`: A postal address of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.phone.type`: The type of a phone number of a contact linked to the network of the IP address asset, such as `voice` or `work`.\n- `ipwhois.objects.contact.phone.value`: A phone number of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.contact.kind`: What kind of contact is linked to the network of the IP address asset: `org`, `group` or `individual`.\n- `ipwhois.objects.contact.name`: The name of a contact or organization linked to the network of the IP address asset, such as `Abuse` or a company name.\n- `ipwhois.objects.contact.role`: The role given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.contact.title`: The title given in the contact card of an entity linked to the network of the IP address asset.\n- `ipwhois.objects.entities`: Handles of further entities listed under a contact linked to the network of the IP address asset.\n- `ipwhois.objects.events.action`: An event in the history of a contact record linked to the network of the IP address asset, such as `registration` or `last changed`.\n- `ipwhois.objects.events.actor`: Who performed an event on a contact record linked to the network of the IP address asset, when the registry names one.\n- `ipwhois.objects.events_actor`: Events in which a contact linked to the network of the IP address asset is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record.\n- `ipwhois.objects.handle`: The registry handle of a contact or organization linked to the network of the IP address asset.\n- `ipwhois.objects.links`: Links to the registry record of a contact linked to the network of the IP address asset.\n- `ipwhois.objects.notices.title`: The title of a notice on a contact record linked to the network of the IP address asset, such as `Terms of Service`.\n- `ipwhois.objects.notices.description`: The text of a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.notices.links`: Links given in a notice on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.raw`: The raw RDAP object of a contact linked to the network of the IP address asset, when it is kept.\n- `ipwhois.objects.remarks.title`: The title of a remark on a contact record linked to the network of the IP address asset, such as `Registration Comments`.\n- `ipwhois.objects.remarks.description`: The text of a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.remarks.links`: Links given in a remark on a contact record linked to the network of the IP address asset.\n- `ipwhois.objects.roles`: The roles of a contact for the network of the IP address asset, such as `registrant`, `abuse` or `technical`.\n- `ipwhois.objects.status`: The registry status of a contact linked to the network of the IP address asset, such as `validated`.\n- `ipwhois_last_change_data`: The IP WHOIS fields that changed in the last change seen, as field paths under `ipwhois`.\n- `ipdns.ptr_records`: The PTR (reverse DNS) host names of an IP address asset.\n- `ipdns_last_change_data`: The reverse DNS fields that changed in the last change seen, as field paths under `ipdns`.\n- `issue_category_stats.name`: The name of an issue category in the per-category issue counts of the asset, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`.\n- `technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the asset, such as `Web servers` or `Analytics`.\n- `domain_snapshot.issue_category_stats.name`: The name of an issue category in the per-category issue counts of the domain and its subdomains together, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.name`: The name of a technology category in the per-category technology counts of the domain and its subdomains together, such as `Web servers` or `Analytics`. Set on domain assets.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 179 fields\n\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.name.length`: The number of characters in the name without the extension: `4` for `acme.example`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois_create_date_historical`: Every creation date seen for the domain over time, so a domain that was deleted and registered again keeps its earlier dates too (UTC date-times).\n- `whois_check_date`: When the WHOIS record of the asset was last checked (UTC date-time).\n- `whois_last_change_date`: When a change in the WHOIS record of the asset was last seen (UTC date-time).\n- `dns.a.value_last_change_date`: When the A record text (`dns.a.value`) last changed (UTC date-time).\n- `dns.a.rcode_last_change_date`: When the response code of the A lookup (`dns.a.rcode`) last changed (UTC date-time).\n- `dns.a.last_change_date`: When the asset's A records last changed, in their text or their response code (UTC date-time).\n- `dns.a.ip_addresses.asn_date`: The registry allocation date that the ASN lookup reports for the A-record address, as a date at midnight UTC.\n- `dns.a.ip_addresses.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was created (UTC date-time).\n- `dns.a.ip_addresses.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was last updated (UTC date-time).\n- `dns.a.ip_addresses.network.events.timestamp`: When an event on the network record of the A-record address happened (UTC date-time).\n- `dns.a.ip_addresses.objects.events.timestamp`: When an event on a contact record linked to the network of the A-record address happened (UTC date-time).\n- `dns.aaaa.value_last_change_date`: When the AAAA record text (`dns.aaaa.value`) last changed (UTC date-time).\n- `dns.aaaa.rcode_last_change_date`: When the response code of the AAAA lookup (`dns.aaaa.rcode`) last changed (UTC date-time).\n- `dns.aaaa.last_change_date`: When the asset's AAAA records last changed, in their text or their response code (UTC date-time).\n- `dns.caa.value_last_change_date`: When the CAA record text (`dns.caa.value`) last changed (UTC date-time).\n- `dns.caa.rcode_last_change_date`: When the response code of the CAA lookup (`dns.caa.rcode`) last changed (UTC date-time).\n- `dns.caa.last_change_date`: When the asset's CAA records last changed, in their text or their response code (UTC date-time).\n- `dns.cname.value_last_change_date`: When the CNAME record text (`dns.cname.value`) last changed (UTC date-time).\n- `dns.cname.rcode_last_change_date`: When the response code of the CNAME lookup (`dns.cname.rcode`) last changed (UTC date-time).\n- `dns.cname.last_change_date`: When the asset's CNAME records last changed, in their text or their response code (UTC date-time).\n- `dns.dnskey.value_last_change_date`: When the DNSKEY record text (`dns.dnskey.value`) last changed (UTC date-time).\n- `dns.dnskey.rcode_last_change_date`: When the response code of the DNSKEY lookup (`dns.dnskey.rcode`) last changed (UTC date-time).\n- `dns.dnskey.last_change_date`: When the asset's DNSKEY records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.value_last_change_date`: When the DS record text (`dns.ds.value`) last changed (UTC date-time).\n- `dns.ds.rcode_last_change_date`: When the response code of the DS lookup (`dns.ds.rcode`) last changed (UTC date-time).\n- `dns.ds.last_change_date`: When the asset's DS records last changed, in their text or their response code (UTC date-time).\n- `dns.ds.records.key_tag`: The key tag (a number) of the DNSKEY that a DS record refers to.\n- `dns.mx.value_last_change_date`: When the MX record text (`dns.mx.value`) last changed (UTC date-time).\n- `dns.mx.rcode_last_change_date`: When the response code of the MX lookup (`dns.mx.rcode`) last changed (UTC date-time).\n- `dns.mx.last_change_date`: When the asset's MX records last changed, in their text or their response code (UTC date-time).\n- `dns.ns.value_last_change_date`: When the NS record text (`dns.ns.value`) last changed (UTC date-time).\n- `dns.ns.rcode_last_change_date`: When the response code of the NS lookup (`dns.ns.rcode`) last changed (UTC date-time).\n- `dns.ns.last_change_date`: When the asset's NS records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec.value_last_change_date`: When the NSEC record text (`dns.nsec.value`) last changed (UTC date-time).\n- `dns.nsec.rcode_last_change_date`: When the response code of the NSEC lookup (`dns.nsec.rcode`) last changed (UTC date-time).\n- `dns.nsec.last_change_date`: When the asset's NSEC records last changed, in their text or their response code (UTC date-time).\n- `dns.nsec3.value_last_change_date`: When the NSEC3 record text (`dns.nsec3.value`) last changed (UTC date-time).\n- `dns.nsec3.rcode_last_change_date`: When the response code of the NSEC3 lookup (`dns.nsec3.rcode`) last changed (UTC date-time).\n- `dns.nsec3.last_change_date`: When the asset's NSEC3 records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.value_last_change_date`: When the RRSIG record text (`dns.rrsig.value`) last changed (UTC date-time).\n- `dns.rrsig.rcode_last_change_date`: When the response code of the RRSIG lookup (`dns.rrsig.rcode`) last changed (UTC date-time).\n- `dns.rrsig.last_change_date`: When the asset's RRSIG records last changed, in their text or their response code (UTC date-time).\n- `dns.rrsig.signature_inception`: When an RRSIG signature becomes valid (UTC date-time).\n- `dns.rrsig.signature_expiration`: When an RRSIG signature expires (UTC date-time).\n- `dns.soa.value_last_change_date`: When the SOA record text (`dns.soa.value`) last changed (UTC date-time).\n- `dns.soa.rcode_last_change_date`: When the response code of the SOA lookup (`dns.soa.rcode`) last changed (UTC date-time).\n- `dns.soa.last_change_date`: When the asset's SOA records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.value_last_change_date`: When the SRV record text (`dns.srv.value`) last changed (UTC date-time).\n- `dns.srv.rcode_last_change_date`: When the response code of the SRV lookup (`dns.srv.rcode`) last changed (UTC date-time).\n- `dns.srv.last_change_date`: When the asset's SRV records last changed, in their text or their response code (UTC date-time).\n- `dns.srv.records.port`: The port an SRV record points to.\n- `dns.txt.value_last_change_date`: When the TXT record text (`dns.txt.value`) last changed (UTC date-time).\n- `dns.txt.rcode_last_change_date`: When the response code of the TXT lookup (`dns.txt.rcode`) last changed (UTC date-time).\n- `dns.txt.last_change_date`: When the asset's TXT records last changed, in their text or their response code (UTC date-time).\n- `dns_check_date`: When the DNS records of the asset were last checked (UTC date-time).\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.port`: The port that the asset's TLS certificate was collected on, such as `443`.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl.validity.length`: The validity period of the certificate in seconds: 7,776,000 seconds are 90 days.\n- `ssl.extensions.signed_certificate_timestamps.timestamp`: When a Certificate Transparency log recorded the certificate, from a signed certificate timestamp (UTC date-time).\n- `ssl.extensions.signed_certificate_timestamps.version`: The version of a signed certificate timestamp; `0` stands for version 1.\n- `ssl_check_date`: When the TLS certificate of the asset was last checked (UTC date-time).\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the HTTP check, such as `301` or `200`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_check_date`: When the HTTP check of the asset last ran (UTC date-time).\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.redirection_history.status_code`: The HTTP status code at a step of the redirect chain of the web data scan, such as `301` or `200`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata.http.cookies.size`: The size of a cookie set in the web data scan, in bytes (name plus value).\n- `webdata.http.cookies.expires`: When a cookie set in the web data scan expires (UTC date-time); session cookies show `1969-12-31T23:59:59Z`.\n- `webdata.technology.stacks.confidence`: How certain the detection of a technology is, from 0 to 100; every sampled detection has `100`.\n- `webdata.technology.stacks.clean_version`: The major version of a detected technology as a whole number, such as `1` for version `1.0`.\n- `webdata_check_date`: When the web data scan of the asset, which collects the page content, headers and technologies, last ran (UTC date-time).\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn_date`: The registry allocation date that the ASN lookup reports for the IP address asset, as a date at midnight UTC.\n- `ipwhois.nir.nets.contacts.admin.updated`: When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.contacts.tech.updated`: When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).\n- `ipwhois.nir.nets.created`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was created (UTC date-time).\n- `ipwhois.nir.nets.updated`: When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was last updated (UTC date-time).\n- `ipwhois.network.events.timestamp`: When an event on the network record of the IP address asset happened (UTC date-time).\n- `ipwhois.objects.events.timestamp`: When an event on a contact record linked to the network of the IP address asset happened (UTC date-time).\n- `ipwhois_check_date`: When the IP WHOIS record of an IP address asset was last checked (UTC date-time).\n- `ipwhois_last_change_date`: When a change in the IP WHOIS record of an IP address asset was last seen (UTC date-time).\n- `ipdns_check_date`: When the reverse DNS (PTR) records of an IP address asset were last checked (UTC date-time).\n- `ipdns_last_change_date`: When a change in the reverse DNS (PTR) records of an IP address asset was last seen (UTC date-time).\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `open_port_count`: The number of open ports found on the asset.\n- `open_ports`: The open port numbers found on the asset, such as `80`, `443` or `8080`.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_category_stats.count`: The number of active issues in that category on the asset.\n- `issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the asset.\n- `issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the asset.\n- `issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the asset.\n- `issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the asset.\n- `issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the asset.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `issue_count.active_by_severity.low`: The number of active issues of low severity on the asset.\n- `issue_count.active_by_severity.information`: The number of active issues of information severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `technology_count.by_category.count`: The number of technologies in that category on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity on the asset.\n- `vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity on the asset.\n- `vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity on the asset.\n- `vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) on the asset whose severity is `none`.\n- `vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) on the asset whose severity is `unknown`.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.count`: The number of active issues in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.critical`: The number of active issues of critical severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.high`: The number of active issues of high severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.medium`: The number of active issues of medium severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.low`: The number of active issues of low severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_category_stats.severity_stats.information`: The number of active issues of information severity in that category on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.technology_count.by_category.count`: The number of distinct technologies in that category across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n**`eq`, `exists`** — 36 fields\n\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `fqdn.is_idn`: True when the host name is an internationalized domain name (IDN) with non-ASCII characters.\n- `fqdn.name.contains_confusable`: True when the name contains confusable characters that look like other letters, such as Cyrillic `а` for Latin `a`, a common trick in look-alike domains.\n- `fqdn.name.contains_hyphen`: True when the name (without the extension) contains a hyphen.\n- `fqdn.name.contains_letter`: True when the name (without the extension) contains a letter.\n- `fqdn.name.contains_number`: True when the name (without the extension) contains a digit.\n- `fqdn.domain.is_idn`: True when the registrable domain is an internationalized domain name (IDN) with non-ASCII characters.\n- `whois_privacy_enabled`: True when the platform flagged WHOIS privacy protection on the domain's registrant details; set on domain assets.\n- `ssl.signature.is_valid`: True when the asset's TLS certificate passed validation for the host; when false, `ssl.signature.invalid_reason` says why.\n- `ssl.signature.is_valid_chain`: A flag for whether the certificate chain of the asset's TLS certificate is valid. It was true on every sampled certificate, even one whose validation failed with `unable to get issuer certificate`.\n- `ssl.signature.is_self_signed`: True when the asset's TLS certificate is self-signed, that is signed by its own key rather than by a certificate authority.\n- `ssl.extensions.basic_constraints.is_ca`: True when the certificate is a certificate authority (CA) certificate, from its Basic Constraints extension.\n- `ssl.extensions.extended_key_usage.client_auth`: True when the Extended Key Usage extension allows TLS client authentication.\n- `ssl.extensions.extended_key_usage.server_auth`: True when the Extended Key Usage extension allows TLS server authentication, as website certificates need.\n- `ssl.extensions.key_usage.content_commitment`: True when the Key Usage extension allows the certificate's key to be used for content commitment (non-repudiation).\n- `ssl.extensions.key_usage.crl_sign`: True when the Key Usage extension allows the certificate's key to be used for signing certificate revocation lists (CRL sign).\n- `ssl.extensions.key_usage.data_encipherment`: True when the Key Usage extension allows the certificate's key to be used for data encipherment.\n- `ssl.extensions.key_usage.digital_signature`: True when the Key Usage extension allows the certificate's key to be used for digital signatures.\n- `ssl.extensions.key_usage.key_agreement`: True when the Key Usage extension allows the certificate's key to be used for key agreement.\n- `ssl.extensions.key_usage.key_cert_sign`: True when the Key Usage extension allows the certificate's key to be used for signing other certificates (certificate sign).\n- `ssl.extensions.key_usage.key_encipherment`: True when the Key Usage extension allows the certificate's key to be used for key encipherment.\n- `ssl.has_expired`: True when the asset's TLS certificate is past its end date.\n- `http.external_domain_redirection`: True when the HTTP check ended on a different registrable domain than it started on.\n- `http.external_fqdn_redirection`: True when the HTTP check ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.html.inspect_disabled`: A flag of the web data scan that marks pages whose inspection was disabled; it was `false` on every sampled asset.\n- `webdata.html.html_meta.no_index_status`: True when the scanned page asks search engines not to index it (a `noindex` robots directive).\n- `webdata.http.external_domain_redirection`: True when the web data scan ended on a different registrable domain than it started on.\n- `webdata.http.external_fqdn_redirection`: True when the web data scan ended on a different host name than it started on, for example `acme.example` to `www.acme.example`.\n- `webdata.http.cookies.secure`: True when a cookie set in the web data scan is sent over HTTPS only (Secure attribute).\n- `webdata.http.cookies.http_only`: True when scripts on the page cannot read a cookie set in the web data scan (HttpOnly attribute).\n- `webdata.http.cookies.session`: True when a cookie set in the web data scan is a session cookie, deleted when the browser closes.\n- `is_parked`: True when the asset is parked; Inventory marks it with a P badge whose tooltip shows where it redirects.\n\n**`eq`, `in`, `exists`** — 8 fields\n\n- `asset_type`: The asset type: `domain`, `subdomain`, `ip` or `website`.\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `dns.dnskey.records.key_type`: The role of a DNSKEY: `ZSK` (zone-signing key), `KSK` (key-signing key) or `KSK_REVOKED` (revoked key-signing key).\n- `dns.dnskey.records.algorithm`: The DNSSEC algorithm of a DNSKEY, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.algorithm`: The DNSSEC algorithm of the key that a DS record refers to, such as `ECDSAP256SHA256` or `RSASHA256`.\n- `dns.ds.records.digest_type`: The hash used for a DS record's digest: `SHA1`, `SHA256`, `SHA384`, `GOST` or `NULL`.\n- `dns.rrsig.algorithm`: The DNSSEC algorithm of an RRSIG signature, such as `ECDSAP256SHA256` or `RSASHA256`.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `website.parent_asset.type`: The asset type of the website's parent asset, such as `subdomain`.\n\nSortable fields:\n\n- `asset`: The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `added_date`: When the asset was added to your inventory (UTC date-time).\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `latest_scan_date`: When the asset was last scanned, shown as the last check date in Inventory (UTC date-time).\n- `is_main_asset`: True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `discovery_enabled`: True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.\n- `dns_wildcard_active`: True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves.\n- `is_login_page`: True when the asset serves a login page; Inventory marks it with a login page icon.\n- `login_page_probability`: The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true.\n- `fqdn.unicode`: The asset's full host name (FQDN) in its readable Unicode form.\n- `fqdn.punycode`: The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`.\n- `fqdn.domain.unicode`: The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`.\n- `fqdn.domain.punycode`: The registrable domain the asset belongs to, in its ASCII (punycode) form.\n- `fqdn.domain.extension.unicode`: The domain's extension, everything after the name, such as `com` or `co.uk`.\n- `fqdn.domain.extension_root.unicode`: The top-level part of the extension: `uk` for both `uk` and `co.uk`.\n- `fqdn.domain.extension_type`: The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`.\n- `website.port`: The port of a website asset, such as `443`.\n- `whois.create_date`: When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).\n- `whois.update_date`: When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.expiry_date`: When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).\n- `whois.domain_status`: The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`.\n- `whois.name_servers`: The name servers listed in the WHOIS record, such as `ns1.acme.example`.\n- `whois.registrar`: The registrar the domain is registered through, as written in WHOIS (usually lower case).\n- `whois.registrant.organization`: The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service.\n- `whois.registrant.email`: The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.\n- `whois.registrant.phone`: The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`.\n- `dns.a.ip_addresses.ip`: An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data.\n- `dns.a.ip_addresses.asn`: The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`.\n- `dns.a.ip_addresses.asn_cidr`: The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.\n- `dns.a.ip_addresses.asn_description`: The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `dns.a.ip_addresses.asn_country_code`: The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`.\n- `dns.a.ip_addresses.asn_registry`: The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`.\n- `dns.a.ip_addresses.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.\n- `dns.a.ip_addresses.network.cidr`: The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `dns.a.ip_addresses.network.name`: The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`.\n- `dns.a.ip_addresses.network.country`: The country of the registered network that contains the A-record address, as a two-letter code such as `FR`.\n- `dns.ns.name_servers`: The name server host names from the asset's NS records, such as `ns1.acme.example`.\n- `dns.mx.mail_servers`: The mail server host names from the asset's MX records, such as `mail.acme.example`.\n- `dns_last_change_date`: When a change in the DNS records of the asset was last seen (UTC date-time).\n- `ssl.serial_number`: The serial number of the asset's TLS certificate, as a decimal string.\n- `ssl.fingerprint.sha1`: The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.\n- `ssl.subject.organization`: The organization (O) of the subject (holder) of the asset's TLS certificate.\n- `ssl.validity.start_date`: The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.\n- `ssl.validity.end_date`: The date the asset's TLS certificate expires (Not After), as a UTC date-time.\n- `ssl_last_change_date`: When a change in the TLS certificate of the asset was last seen (UTC date-time).\n- `http.final_domain`: The registrable domain the HTTP check ended on after redirects, such as `acme.example`.\n- `http.final_fqdn`: The host name the HTTP check ended on after redirects, such as `www.acme.example`.\n- `http.first_status_code`: The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`.\n- `http.final_status_code`: The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value.\n- `http_last_change_date`: When a change in the HTTP check result of the asset was last seen (UTC date-time).\n- `webdata.http.final_domain`: The registrable domain the web data scan ended on after redirects, such as `acme.example`.\n- `webdata.http.final_fqdn`: The host name the web data scan ended on after redirects, such as `www.acme.example`.\n- `webdata.http.first_status_code`: The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`.\n- `webdata.http.final_status_code`: The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`.\n- `webdata_last_change_date`: When a change in the web data of the asset was last seen (UTC date-time).\n- `ipwhois.asn`: The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`.\n- `ipwhois.asn_cidr`: The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.\n- `ipwhois.asn_description`: The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`.\n- `ipwhois.asn_country_code`: The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`.\n- `ipwhois.asn_registry`: The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`.\n- `ipwhois.nir.nets.cidr`: The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.\n- `ipwhois.network.cidr`: The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas.\n- `ipwhois.network.name`: The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`.\n- `ipwhois.network.country`: The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`.\n- `subdomain_count`: The number of subdomains of the domain in your inventory; set on domain assets.\n- `website_count`: The number of website assets (`host:port`) in your inventory that belong to this asset.\n- `pointed_fqdn_count`: A count of host names (FQDNs) that point to the asset; no sampled asset had a value.\n- `redirected_domain_count`: The number of domain assets in your inventory whose HTTP check ends on this asset after redirects.\n- `redirected_asset_count`: The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.\n- `open_port_count`: The number of open ports found on the asset.\n- `average_issue_duration`: The average duration of the issues on the asset, in seconds.\n- `average_fix_duration`: The average time taken to fix the issues on the asset, in seconds.\n- `issue_state_stats.newly_detected`: The number of issues on the asset in the `newly_detected` state, an active state set by the platform.\n- `issue_state_stats.reappeared`: The number of issues on the asset in the `reappeared` state, an active state set by the platform.\n- `issue_state_stats.unresolved`: The number of issues on the asset in the `unresolved` state, an active state set by the platform.\n- `issue_state_stats.marked_as_resolved`: The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets.\n- `issue_state_stats.risk_accepted`: The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets.\n- `issue_state_stats.ignored`: The number of issues on the asset in the `ignored` state, an inactive state that a user sets.\n- `issue_state_stats.marked_as_false_positive`: The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets.\n- `issue_state_stats.not_applicable`: The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform.\n- `issue_state_stats.verified_resolved`: The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform.\n- `issue_count.total`: The number of issues on the asset in any state, active or inactive.\n- `issue_count.active`: The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state.\n- `issue_count.active_by_severity.critical`: The number of active issues of critical severity on the asset.\n- `issue_count.active_by_severity.high`: The number of active issues of high severity on the asset.\n- `issue_count.active_by_severity.medium`: The number of active issues of medium severity on the asset.\n- `technology_count.total`: The number of technologies detected on the asset.\n- `vulnerability_count.total`: The number of vulnerabilities (CVEs) found on the asset.\n- `vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity on the asset.\n- `security_score`: The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.\n- `weight`: The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.\n- `user_weight`: The weight you set for the asset, from 1 to 100; empty when you have not set one.\n- `system_weight`: The weight the platform calculates for the asset from many criteria; it can be above 100.\n- `domain_snapshot.average_issue_duration`: The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.average_fix_duration`: The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.\n- `domain_snapshot.open_port_count`: The number of open ports found on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.security_score`: The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets.\n- `domain_snapshot.issue_count.total`: The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.\n- `domain_snapshot.issue_count.active`: The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.critical`: The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.high`: The number of active issues of high severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.medium`: The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.low`: The number of active issues of low severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_count.active_by_severity.information`: The number of active issues of information severity on the domain and its subdomains together. Set on domain assets.\n- `domain_snapshot.issue_state_stats.newly_detected`: The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.reappeared`: The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.unresolved`: The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_resolved`: The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.risk_accepted`: The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.ignored`: The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.marked_as_false_positive`: The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets.\n- `domain_snapshot.issue_state_stats.not_applicable`: The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.issue_state_stats.verified_resolved`: The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets.\n- `domain_snapshot.technology_count.total`: The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.\n- `domain_snapshot.vulnerability_count.total`: The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.critical`: The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.high`: The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.medium`: The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.low`: The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.none`: The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n- `domain_snapshot.vulnerability_count.by_severity.unknown`: The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `asset_count` | integer |  |\n\n> The saved example **Request template · 38 of 740 filters** holds this body with 38 of the 740 filters (the first 10 of each operator group); the full list is above (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"postman-docs-test.deepinfo.com\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Asset Instant Scan Status",
              "id": "72f0c3fb-c540-57de-95fc-9dce0128ab87",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/instant-scan-status",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "instant-scan-status"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "6ab2a3fa31c7bcfb2fb91a77",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Instant Scan Status API**\n\nReturns the state of the latest on-demand scan: `pending`, `queued`, `monitoring`, `failed`, `issue_queued` or `finished`. Returns **404** if no instant scan was ever triggered for the asset.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `asset` | string |  |\n| `asset_type` | string | One of `domain`, `subdomain`, `ip`, `website` |\n| `state` | string | One of `pending`, `queued`, `monitoring`, `failed`, `issue_queued`, `finished` |\n| `state_update_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset Update",
              "id": "cda3dde7-fed8-5dbc-ac69-96093320ab79",
              "request": {
                "method": "PUT",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "6ab2a3fa31c7bcfb2fb91a77",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Update API**\n\nUpdates an asset's settings: `discovery_enabled` (use the asset as a discovery seed) and `is_main_asset`.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `discovery_enabled` | boolean | yes |  |\n| `is_main_asset` | boolean | yes |  |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"discovery_enabled\": false,\n  \"is_main_asset\": false\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Asset Remove Tag",
              "id": "2f21803c-048c-508d-9906-56a9a14bb5bb",
              "request": {
                "method": "DELETE",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/tags/:tag_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "tags",
                    ":tag_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "6ab2a7b96d8212775cf91d9d",
                      "description": "**Required.**"
                    },
                    {
                      "key": "tag_id",
                      "value": "postman-docs-test-renamed",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Remove Tag API**\n\nRemoves one tag from one asset. `tag_id` is the **tag name**. The tag itself stays in **Asset Tags** until you delete it there."
              },
              "response": []
            }
          ]
        },
        {
          "name": "Asset Tags",
          "id": "c8870037-797c-5749-9f56-060f983ac0d8",
          "description": "Tags you have put on assets. A tag is identified by its **name** (`{tag_id}` is the tag text).",
          "item": [
            {
              "name": "Asset Tag List",
              "id": "acaa4268-dafc-5e7c-a371-8d12f64bad16",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/asset-tags",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "asset-tags"
                  ]
                },
                "description": "**Deepinfo EASM Asset Tag List API**\n\nLists the tags used on your assets (tag names)."
              },
              "response": []
            },
            {
              "name": "Asset Tag Update",
              "id": "f8f60015-52e6-5870-ae5a-ccadef236a45",
              "request": {
                "method": "PUT",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/asset-tags/:tag_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "asset-tags",
                    ":tag_id"
                  ],
                  "variable": [
                    {
                      "key": "tag_id",
                      "value": "postman-docs-test",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Tag Update API**\n\nRenames a tag on every asset that has it. `tag_id` is the current **tag name**; `tag` (3–100 characters) is the new name.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `tag` | string | yes | min length `3`; max length `100` |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"tag\": \"postman-docs-test-renamed\"\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Asset Tag Delete",
              "id": "828478de-1a3d-5e18-b84d-bd93bf7aefdc",
              "request": {
                "method": "DELETE",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/asset-tags/:tag_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "asset-tags",
                    ":tag_id"
                  ],
                  "variable": [
                    {
                      "key": "tag_id",
                      "value": "postman-docs-test",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Tag Delete API**\n\nDeletes a tag and removes it from all assets. `tag_id` is the **tag name**."
              },
              "response": []
            }
          ]
        },
        {
          "name": "Deleted Assets",
          "id": "b0a5e503-ac77-523c-be07-10b4684271b8",
          "description": "Assets that were removed from monitoring.",
          "item": [
            {
              "name": "Deleted Asset Search",
              "id": "136ebe56-d2b9-5360-996b-c8c64795d42d",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/deleted-assets/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "deleted-assets",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Deleted Asset Search API**\n\nSearches assets that were removed from monitoring, with their `deleted_date`.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 5 fields\n\n- `added_date`: When the asset was added to your inventory, before it was removed (UTC date-time).\n- `deleted_date`: When the asset was removed from your inventory (UTC date-time).\n- `latest_scan_date`: When the asset was last scanned before it was removed (UTC date-time).\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n\n**`eq`, `exists`** — 3 fields\n\n- `is_main_asset`: True when the asset was set as a main asset, the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the asset seemed inactive: no active DNS records or WHOIS information were found (for a subdomain: no DNS records). The Deleted Assets list flags such assets.\n- `discovery_enabled`: True when discovery used the asset as a starting point to find related assets.\n\n**`eq`, `in`, `exists`** — 2 fields\n\n- `asset_type`: The asset type: `domain`, `subdomain`, `ip` or `website`.\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 2 fields\n\n- `asset`: The removed asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `tags`: Your own labels on the removed asset, such as a business unit or an environment.\n\nSortable fields:\n\n- `asset`: The removed asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `asset_type`: The asset type: `domain`, `subdomain`, `ip` or `website`.\n- `added_date`: When the asset was added to your inventory, before it was removed (UTC date-time).\n- `deleted_date`: When the asset was removed from your inventory (UTC date-time).\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `latest_scan_date`: When the asset was last scanned before it was removed (UTC date-time).\n- `is_main_asset`: True when the asset was set as a main asset, the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the asset seemed inactive: no active DNS records or WHOIS information were found (for a subdomain: no DNS records). The Deleted Assets list flags such assets.\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `discovery_enabled`: True when discovery used the asset as a starting point to find related assets.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].asset` | string |  |\n| `results[].asset_type` | string | One of `domain`, `subdomain`, `ip`, `website` |\n| `results[].added_date` | string | date-time |\n| `results[].deleted_date` | string | date-time |\n| `results[].tags` | array of string |  |\n| `results[].creation_method` | string | One of `manually_added`, `manually_approved`, `auto_approved` |\n| `results[].latest_scan_date` | string | date-time |\n| `results[].is_main_asset` | boolean |  |\n| `results[].seems_inactive` | boolean |  |\n| `results[].seems_inactive_first_seen` | string | date-time |\n| `results[].seems_inactive_last_seen` | string | date-time |\n| `results[].discovery_enabled` | boolean |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Deleted Asset Export",
              "id": "7dd327f0-d2ff-5d7e-b2ff-7583ef815596",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/deleted-assets/search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "deleted-assets",
                    "search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Deleted Asset Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 5 fields\n\n- `added_date`: When the asset was added to your inventory, before it was removed (UTC date-time).\n- `deleted_date`: When the asset was removed from your inventory (UTC date-time).\n- `latest_scan_date`: When the asset was last scanned before it was removed (UTC date-time).\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n\n**`eq`, `exists`** — 3 fields\n\n- `is_main_asset`: True when the asset was set as a main asset, the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the asset seemed inactive: no active DNS records or WHOIS information were found (for a subdomain: no DNS records). The Deleted Assets list flags such assets.\n- `discovery_enabled`: True when discovery used the asset as a starting point to find related assets.\n\n**`eq`, `in`, `exists`** — 2 fields\n\n- `asset_type`: The asset type: `domain`, `subdomain`, `ip` or `website`.\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 2 fields\n\n- `asset`: The removed asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `tags`: Your own labels on the removed asset, such as a business unit or an environment.\n\nSortable fields:\n\n- `asset`: The removed asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `asset_type`: The asset type: `domain`, `subdomain`, `ip` or `website`.\n- `added_date`: When the asset was added to your inventory, before it was removed (UTC date-time).\n- `deleted_date`: When the asset was removed from your inventory (UTC date-time).\n- `creation_method`: How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval).\n- `latest_scan_date`: When the asset was last scanned before it was removed (UTC date-time).\n- `is_main_asset`: True when the asset was set as a main asset, the primary asset for all related assets, configurations and reports.\n- `seems_inactive`: True when the asset seemed inactive: no active DNS records or WHOIS information were found (for a subdomain: no DNS records). The Deleted Assets list flags such assets.\n- `seems_inactive_first_seen`: When the asset was first found to seem inactive (UTC date-time).\n- `seems_inactive_last_seen`: When the asset was most recently found to seem inactive (UTC date-time).\n- `discovery_enabled`: True when discovery used the asset as a starting point to find related assets.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            }
          ]
        },
        {
          "name": "Asset History",
          "id": "70a3eed9-20b4-5bb1-9aa0-88fc258012bf",
          "description": "Every change Deepinfo recorded for an asset, per data type (WHOIS, DNS, SSL, port scan, HTTP, web data, IP DNS, IP WHOIS). List endpoints return snapshot ids with their `check_date`; detail endpoints return the full snapshot.\n\n| History | Available for asset types |\n|---|---|\n| WHOIS, DNS, SSL, port scan | domain, subdomain |\n| HTTP, web data | website |\n| IP DNS, IP WHOIS | ip |\n\nRequesting a history type the asset does not have returns **404** `30003` (e.g. *\"domain asset type does not include ipdns scope.\"*).",
          "item": [
            {
              "name": "Asset DNS History List",
              "id": "0564c63c-a481-5ff0-92c8-f976f39208e6",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/dns-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "dns-history"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset DNS History List API**\n\nLists the DNS snapshots recorded for an asset (newest first): `id` and `check_date` of each.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset HTTP History List",
              "id": "3a34de91-dcca-54c5-add4-b677d560841d",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/http-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "http-history"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "69fb3eb77d4513d5abe6f3d8",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset HTTP History List API**\n\nLists the HTTP snapshots recorded for an asset (newest first): `id` and `check_date` of each.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset IP DNS PTR History List",
              "id": "3bd9bab3-72a9-51c5-8897-0f03628cec26",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/ipdns-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "ipdns-history"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "<asset_id>",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset IP DNS PTR History List API**\n\nLists the IP DNS (PTR) snapshots recorded for an asset (newest first): `id` and `check_date` of each.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `check_date` | string | date-time |\n\n> No live example: the DEMO account has no data for this endpoint yet, or it returned an error during testing. The response shape is described above."
              },
              "response": []
            },
            {
              "name": "Asset IP Whois History List",
              "id": "822502ca-9bb5-54ad-8e68-0e15c65552a5",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/ipwhois-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "ipwhois-history"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "<asset_id>",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset IP Whois History List API**\n\nLists the IP WHOIS snapshots recorded for an asset (newest first): `id` and `check_date` of each.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `check_date` | string | date-time |\n\n> No live example: the DEMO account has no data for this endpoint yet, or it returned an error during testing. The response shape is described above."
              },
              "response": []
            },
            {
              "name": "Asset Port Scan History List",
              "id": "1da663fe-d094-5ab6-8bfb-75735f91c5fb",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/port-scan-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "port-scan-history"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Port Scan History List API**\n\nLists the port scan snapshots recorded for an asset (newest first): `id` and `check_date` of each.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset SSL History List",
              "id": "ba8f16d5-b852-58bd-8c01-f7ea3fa027fb",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/ssl-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "ssl-history"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset SSL History List API**\n\nLists the SSL certificate snapshots recorded for an asset (newest first): `id` and `check_date` of each.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset Webdata History List",
              "id": "3be31251-87a9-5140-bf12-3888952520dc",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/webdata-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "webdata-history"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "69fb3eb77d4513d5abe6f3d8",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Webdata History List API**\n\nLists the web data (page content, technologies, headers) snapshots recorded for an asset (newest first): `id` and `check_date` of each.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset Whois History List",
              "id": "ba07a705-aeb9-521a-850c-e588897d3a30",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/whois-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "whois-history"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Whois History List API**\n\nLists the WHOIS snapshots recorded for an asset (newest first): `id` and `check_date` of each.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset DNS History Detail",
              "id": "015d350e-a2c4-5d9f-be30-8b9583d6e764",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/dns-history/:history_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "dns-history",
                    ":history_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    },
                    {
                      "key": "history_id",
                      "value": "8b46eefe4ed8fc36f362daa822381597",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset DNS History Detail API**\n\nReturns one DNS snapshot of an asset, by the `history_id` returned by the list endpoint.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `result` | object |  |\n| `status` | boolean |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset HTTP History Detail",
              "id": "2240f254-b69b-5a37-be20-ebbf38070cec",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/http-history/:history_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "http-history",
                    ":history_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "69fb3eb77d4513d5abe6f3d8",
                      "description": "**Required.**"
                    },
                    {
                      "key": "history_id",
                      "value": "929283eeefc958357c2d70b8431eb6bf",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset HTTP History Detail API**\n\nReturns one HTTP snapshot of an asset, by the `history_id` returned by the list endpoint.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `result` | object |  |\n| `status` | boolean |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset IP DNS PTR History Detail",
              "id": "7cc515a6-0a48-599a-a2c1-cd43191784bf",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/ipdns-history/:history_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "ipdns-history",
                    ":history_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "<asset_id>",
                      "description": "**Required.**"
                    },
                    {
                      "key": "history_id",
                      "value": "<history_id>",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset IP DNS PTR History Detail API**\n\nReturns one IP DNS (PTR) snapshot of an asset, by the `history_id` returned by the list endpoint.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `result` | object |  |\n| `status` | boolean |  |\n| `check_date` | string | date-time |\n\n> No live example: the DEMO account has no data for this endpoint yet, or it returned an error during testing. The response shape is described above."
              },
              "response": []
            },
            {
              "name": "Asset IP Whois History Detail",
              "id": "dd202c29-9dcf-55ab-8878-d698be05bc27",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/ipwhois-history/:history_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "ipwhois-history",
                    ":history_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "<asset_id>",
                      "description": "**Required.**"
                    },
                    {
                      "key": "history_id",
                      "value": "<history_id>",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset IP Whois History Detail API**\n\nReturns one IP WHOIS snapshot of an asset, by the `history_id` returned by the list endpoint.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `result` | object |  |\n| `status` | boolean |  |\n| `check_date` | string | date-time |\n\n> No live example: the DEMO account has no data for this endpoint yet, or it returned an error during testing. The response shape is described above."
              },
              "response": []
            },
            {
              "name": "Asset Port Scan History Detail",
              "id": "9ba9c51b-71f5-5c9d-b29e-13f119c0ce2e",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/port-scan-history/:history_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "port-scan-history",
                    ":history_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    },
                    {
                      "key": "history_id",
                      "value": "8b46eefe4ed8fc36f362daa822381597",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Port Scan History Detail API**\n\nReturns one port scan snapshot of an asset, by the `history_id` returned by the list endpoint.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `result` | object |  |\n| `status` | boolean |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset SSL History Detail",
              "id": "75785613-7f9f-5bfd-a34a-eac3066e6213",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/ssl-history/:history_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "ssl-history",
                    ":history_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    },
                    {
                      "key": "history_id",
                      "value": "8b46eefe4ed8fc36f362daa822381597",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset SSL History Detail API**\n\nReturns one SSL certificate snapshot of an asset, by the `history_id` returned by the list endpoint.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `result` | object |  |\n| `status` | boolean |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset Webdata History Detail",
              "id": "eb1af54b-19b5-5d99-944d-2aa3a1c248e8",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/webdata-history/:history_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "webdata-history",
                    ":history_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "69fb3eb77d4513d5abe6f3d8",
                      "description": "**Required.**"
                    },
                    {
                      "key": "history_id",
                      "value": "929283eeefc958357c2d70b8431eb6bf",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Webdata History Detail API**\n\nReturns one web data (page content, technologies, headers) snapshot of an asset, by the `history_id` returned by the list endpoint.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `result` | object |  |\n| `status` | boolean |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset Whois History Detail",
              "id": "ebbb1d00-4b23-5b03-8498-2f56ebe19cc7",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/whois-history/:history_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "whois-history",
                    ":history_id"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    },
                    {
                      "key": "history_id",
                      "value": "8b46eefe4ed8fc36f362daa822381597",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Whois History Detail API**\n\nReturns one WHOIS snapshot of an asset, by the `history_id` returned by the list endpoint.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `result` | object |  |\n| `status` | boolean |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Open Ports",
          "id": "9e3e7bcc-7a5a-5b9c-a524-0a256a5d5103",
          "description": "Ports and services found on an asset, their history, and on-demand port scans.",
          "item": [
            {
              "name": "Asset Open Port History List",
              "id": "c0b4ef55-2132-59cb-ae86-8f3295cde41b",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/open-ports/history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "open-ports",
                    "history"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Open Port History List API**\n\nLists the port scan snapshots of an asset: `id` and `check_date`.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Asset Open Port List",
              "id": "e8f01e6a-5105-561e-bbca-f45ae7e7f409",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/open-ports?state__in=open&protocol__in=tcp&ordering=port",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "open-ports"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "100",
                      "description": "Min `25`, max `100`. Default `100`.",
                      "disabled": true
                    },
                    {
                      "key": "port__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "port__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "state__in",
                      "value": "open",
                      "description": ""
                    },
                    {
                      "key": "state__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "protocol__in",
                      "value": "tcp",
                      "description": ""
                    },
                    {
                      "key": "protocol__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "ordering",
                      "value": "port",
                      "description": ""
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Open Port List API**\n\nLists the ports found on an asset, with the `state` and `protocol` of each. Filter and sort with the optional query parameters.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].port` | integer |  |\n| `results[].state` | string | One of `open`, `closed`, `filtered`, `unfiltered`, `open|filtered`, `closed|filtered` |\n| `results[].protocol` | string |  |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Asset Open Port History Detail",
              "id": "8629e04d-e936-5bfc-8ca4-0a5bd72bfadd",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/open-ports/history/:history_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "open-ports",
                    "history",
                    ":history_id"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "100",
                      "description": "Min `25`, max `100`. Default `100`.",
                      "disabled": true
                    },
                    {
                      "key": "port__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "port__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "state__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "state__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "protocol__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "protocol__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "ordering",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    },
                    {
                      "key": "history_id",
                      "value": "8b46eefe4ed8fc36f362daa822381597",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Open Port History Detail API**\n\nReturns the ports of one historical port scan. Same filters as **Asset Open Port List**.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].port` | integer |  |\n| `results[].state` | string | One of `open`, `closed`, `filtered`, `unfiltered`, `open|filtered`, `closed|filtered` |\n| `results[].protocol` | string |  |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Asset Instant Open Port Scan",
              "id": "4af6519e-b86e-5474-b723-3f380b8b16d3",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/open-ports/instant-scan",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "open-ports",
                    "instant-scan"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "6ab2a3fa31c7bcfb2fb91a77",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Instant Open Port Scan API**\n\nRuns a port scan of the asset right away and returns the result in the response (`status` is `host_down` if the host did not respond).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `target` | string |  |\n| `check_date` | string | date-time |\n| `status` | string |  |\n| `target_ip` | string |  |\n| `port_data` | object |  |\n| `os` | array of string |  |"
              },
              "response": []
            },
            {
              "name": "Asset Open Port Count Timeline",
              "id": "b2468dcf-1925-583f-815b-cc9df17df779",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/open-ports/count-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "open-ports",
                    "count-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Open Port Count Timeline API**\n\nTime series of the number of open ports on an asset.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Asset Open Port State Stats",
              "id": "b615049b-3857-5733-832d-d05ef833e0ac",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/stats/open-port-state",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "stats",
                    "open-port-state"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Open Port State Stats API**\n\nCounts the asset's ports per state (`open`, `closed`, `filtered`, `unfiltered`, `open_filtered`, `closed_filtered`).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `open` | integer |  |\n| `closed` | integer |  |\n| `filtered` | integer |  |\n| `unfiltered` | integer |  |\n| `open_filtered` | integer |  |\n| `closed_filtered` | integer |  |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Asset Timelines",
          "id": "c821f793-bd41-5511-86ce-03c4dd4142eb",
          "description": "Time series for a single asset. `interval`: `daily`, `weekly` or `monthly`.",
          "item": [
            {
              "name": "Asset Issue Severity Stats Timeline",
              "id": "97f93c23-0cac-5ab0-a59b-3a6e46feca06",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/stats/issue-severity-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "stats",
                    "issue-severity-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Issue Severity Stats Timeline API**\n\nTime series of issue severity for the selected `interval` (`daily`, `weekly`, `monthly`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `severities` | array of object |  |"
              },
              "response": []
            },
            {
              "name": "Asset Security Score Timeline",
              "id": "f5995c57-96a8-5aa3-a515-a98b893af442",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/stats/security-score-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "stats",
                    "security-score-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Security Score Timeline API**\n\nTime series of security score for the selected `interval` (`daily`, `weekly`, `monthly`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `score` | number |  |"
              },
              "response": []
            },
            {
              "name": "Asset Technology Count Timeline",
              "id": "1e105d1f-b3f2-59ee-9a7e-742f19a22ddc",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/stats/technology-count-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "stats",
                    "technology-count-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Technology Count Timeline API**\n\nTime series of technology count for the selected `interval` (`daily`, `weekly`, `monthly`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Asset Vulnerability Severity Stats Timeline",
              "id": "63cf06c1-fb76-5adf-812b-bf1e4285d2c9",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/stats/vulnerability-severity-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "stats",
                    "vulnerability-severity-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Vulnerability Severity Stats Timeline API**\n\nTime series of vulnerability severity for the selected `interval` (`daily`, `weekly`, `monthly`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `severities` | array of object |  |"
              },
              "response": []
            },
            {
              "name": "Asset Website Count Timeline",
              "id": "5bd564f3-1fc6-50e9-9a8e-e380d437708d",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/stats/website-count-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "stats",
                    "website-count-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Website Count Timeline API**\n\nTime series of website count for the selected `interval` (`daily`, `weekly`, `monthly`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Domain Security Score Timeline",
              "id": "ea3a7abf-a902-5421-a498-339ad8f97f98",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/stats/domain-security-score-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "stats",
                    "domain-security-score-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Domain Security Score Timeline API**\n\nTime series of domain security score for the selected `interval` (`daily`, `weekly`, `monthly`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `score` | number |  |"
              },
              "response": []
            },
            {
              "name": "Domain Subdomain Count Timeline",
              "id": "94e01679-8e69-595a-bdda-9462ef6a36a9",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/stats/subdomain-count-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "stats",
                    "subdomain-count-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Domain Subdomain Count Timeline API**\n\nTime series of subdomain count for the selected `interval` (`daily`, `weekly`, `monthly`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `count` | integer |  |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Snapshots",
          "id": "a0b3decc-5b9f-55ab-b39a-f9361970c574",
          "description": "Pre-computed summaries (security score and statistics) of an asset, a domain or your whole attack surface. `instant-snapshot` recalculates one on demand; the result is available shortly after via `latest-snapshot`.",
          "item": [
            {
              "name": "Asset Instant Snapshot",
              "id": "feb2e4a2-0b1a-5f9f-8baa-64ca2bd4c1bd",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/instant-snapshot",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "instant-snapshot"
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "6ab2a3fa31c7bcfb2fb91a77",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Instant Snapshot API**\n\nRecalculates the asset snapshot now.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `triggered` | boolean |  |"
              },
              "response": []
            },
            {
              "name": "Asset Latest Snapshot",
              "id": "0cdbe030-1522-5093-b3cc-3f881e0039e4",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:asset_id/latest-snapshot",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":asset_id",
                    "latest-snapshot"
                  ],
                  "query": [
                    {
                      "key": "stats",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ],
                  "variable": [
                    {
                      "key": "asset_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Latest Snapshot API**\n\nReturns the latest pre-computed summary of an asset (security score and statistics) in `snapshot`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `snapshot` | object |  |\n| `date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Domain Instant Snapshot",
              "id": "917f5e2f-57b3-5cb6-ae8e-94d7b075b8ff",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:domain_id/domain-instant-snapshot",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":domain_id",
                    "domain-instant-snapshot"
                  ],
                  "variable": [
                    {
                      "key": "domain_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Domain Instant Snapshot API**\n\nRecalculates the domain snapshot now.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `triggered` | boolean |  |"
              },
              "response": []
            },
            {
              "name": "Domain Latest Snapshot",
              "id": "aa0b036e-e028-523d-99ac-6b997ef75e7f",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/:domain_id/domain-latest-snapshot",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    ":domain_id",
                    "domain-latest-snapshot"
                  ],
                  "query": [
                    {
                      "key": "stats",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ],
                  "variable": [
                    {
                      "key": "domain_id",
                      "value": "67c8238c0cc9818667cd99a1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Domain Latest Snapshot API**\n\nReturns the latest summary of a **domain** including all its subdomains and websites. `domain_id` is the asset id of a domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `snapshot` | object |  |\n| `date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Instant Snapshot",
              "id": "9b1d6e7e-c2bb-55ca-a860-a16078eb864f",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/instant-snapshot",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "instant-snapshot"
                  ]
                },
                "description": "**Deepinfo EASM Instant Snapshot API**\n\nRecalculates the attack-surface snapshot now.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `triggered` | boolean |  |"
              },
              "response": []
            },
            {
              "name": "Latest Snapshot",
              "id": "d0d0570e-9472-559a-99d4-f301101a0891",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/latest-snapshot",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "latest-snapshot"
                  ],
                  "query": [
                    {
                      "key": "stats",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo EASM Latest Snapshot API**\n\nReturns the latest summary of your whole attack surface.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `snapshot` | object |  |\n| `date` | string | date-time |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Dashboard",
          "id": "8c3fdf7e-8c64-58cd-b967-4b97c3b1ac62",
          "description": "Aggregated statistics across all your assets.",
          "item": [
            {
              "name": "Assets with Most Issues",
              "id": "c477cdf6-47f1-530f-8b9c-d32addf76d99",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/stats/most-issues",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "stats",
                    "most-issues"
                  ]
                },
                "description": "**Deepinfo EASM Assets with Most Issues API**\n\nLists your assets with the most active issues.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `asset` | string |  |\n| `asset_unicode` | string |  |\n| `asset_type` | string | One of `domain`, `subdomain`, `ip`, `website` |\n| `favicon` | string |  |\n| `added_date` | string | date-time |\n| `issue_count` | object |  |"
              },
              "response": []
            },
            {
              "name": "Assets with Most Websites",
              "id": "44a1cd70-978d-52c5-b1b6-b73f2b39b860",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/stats/most-websites",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "stats",
                    "most-websites"
                  ]
                },
                "description": "**Deepinfo EASM Assets with Most Websites API**\n\nLists your assets with the most websites.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `asset` | string |  |\n| `asset_unicode` | string |  |\n| `website_count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Domains with Most Subdomains",
              "id": "79a6d3d6-587f-5e26-9bd5-c35343f4a2b7",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/stats/most-subdomains",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "stats",
                    "most-subdomains"
                  ]
                },
                "description": "**Deepinfo EASM Domains with Most Subdomains API**\n\nLists your domains with the most subdomains.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `domain` | string |  |\n| `domain_unicode` | string |  |\n| `subdomain_count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Latest Added Assets",
              "id": "36c2d6e1-4f47-518f-8869-4d1295b6a09e",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/stats/latest",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "stats",
                    "latest"
                  ]
                },
                "description": "**Deepinfo EASM Latest Added Assets API**\n\nLists the most recently added assets.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `asset` | string |  |\n| `asset_unicode` | string |  |\n| `asset_type` | string | One of `domain`, `subdomain`, `ip`, `website` |\n| `favicon` | string |  |\n| `added_date` | string | date-time |\n| `issue_count` | object |  |"
              },
              "response": []
            },
            {
              "name": "Asset Type Stats",
              "id": "dfbac007-4feb-543c-90ce-b6a93a98629c",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/stats/type",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "stats",
                    "type"
                  ]
                },
                "description": "**Deepinfo EASM Asset Type Stats API**\n\nCounts your assets per type (`domain`, `subdomain`, `ip`, `website`).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `domain` | integer |  |\n| `subdomain` | integer |  |\n| `ip` | integer |  |\n| `website` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Asset Type Stats Timeline",
              "id": "81776001-8f70-542b-bcf0-ecd8826406e2",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/stats/type-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "stats",
                    "type-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Asset Type Stats Timeline API**\n\nTime series of your asset counts per type.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `types` | array of object |  |"
              },
              "response": []
            },
            {
              "name": "Insight Stats",
              "id": "b575ca69-cf25-5b76-80b5-fa7a04136775",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/assets/stats/insights?asset_type=domain&insight_by=whois_registrar",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "assets",
                    "stats",
                    "insights"
                  ],
                  "query": [
                    {
                      "key": "asset_type",
                      "value": "domain",
                      "description": "**Required.** One of: `domain`, `subdomain`, `ip`, `website`."
                    },
                    {
                      "key": "insight_by",
                      "value": "whois_registrar",
                      "description": "**Required.** One of: `whois_registrar`, `whois_expiry_date`, `whois_registrant_organization`, `dns_ip_address`, `dns_name_server`, `dns_mail_server`, `asn`, `ssl_certificate`, `ssl_issuer`, `ssl_subject_organization`, `http_status`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Insight Stats API**\n\nGroups assets of an `asset_type` by an attribute (`insight_by`: registrar, expiry date, registrant organization, IP, name server, mail server, ASN, SSL certificate, SSL issuer, SSL subject organization or HTTP status) and counts them.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `name` | string |  |\n| `count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Open Port Count Timeline",
              "id": "8b531ccc-8e60-5411-b0d0-b84e85a8bfee",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/stats/open-port-count-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "stats",
                    "open-port-count-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Open Port Count Timeline API**\n\nTime series of open ports across all your assets.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Security Score Timeline",
              "id": "3cbe20a2-ec1c-5ac4-8eff-a0d5ccf199b8",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/stats/security-score-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "stats",
                    "security-score-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Security Score Timeline API**\n\nTime series of your overall security score.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `score` | number |  |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Discovery",
          "id": "d83106ff-eb0b-5bbf-be8a-0f745d9f0273",
          "description": "Assets Deepinfo discovers around your attack surface, the rules that discover them, and discovery settings.",
          "item": [
            {
              "name": "Discovered Assets",
              "id": "b5d1ced5-9621-5655-a6ad-e5efb51e7fe2",
              "description": "Candidates found by discovery rules. Each is `in_review`, `approved` (added to your assets) or `ignored`.",
              "item": [
                {
                  "name": "Discovered Asset Search",
                  "id": "66a5e09a-8a3d-5c64-8ddd-ed683fc56afd",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/assets/search?page_size=25",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "assets",
                        "search"
                      ],
                      "query": [
                        {
                          "key": "page",
                          "value": "1",
                          "description": "Min `1`, max `800`. Default `1`.",
                          "disabled": true
                        },
                        {
                          "key": "page_size",
                          "value": "25",
                          "description": "Min `25`, max `100`. Default `100`."
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Discovered Asset Search API**\n\nSearches discovered assets (candidates found by discovery rules) and their state.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 4 fields\n\n- `asset`: The discovered asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `discovery_history.id`: The ID of a discovery rule that found the asset, a 32-character hex string; the Discovery page's rule name filter sends this ID.\n- `discovery_history.seed_value`: The seed value a rule started from when it found the asset, such as an IP address, a certificate fingerprint, a phone number or an organization name.\n- `organization_name`: An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as `redacted for privacy`.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `last_discovery_date`: When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time).\n- `ignore_date`: When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored.\n- `approve_date`: When the asset was approved into your inventory (UTC date-time); empty unless it is approved.\n\n**`eq`, `in`, `exists`** — 2 fields\n\n- `asset_type`: The discovered asset's type: `domain`, `subdomain`, `ip` or `website`.\n- `state`: The review state: `in_review` (found by a rule, waiting for a decision), `approved` (added to your inventory) or `ignored` (dismissed; it stays out of your inventory).\n\nSortable fields:\n\n- `asset`: The discovered asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `state`: The review state: `in_review` (found by a rule, waiting for a decision), `approved` (added to your inventory) or `ignored` (dismissed; it stays out of your inventory).\n- `discovery_history`: The rule matches that found the asset, each with the rule ID, rule name, rule type (`smart_discovery`, `smart_monitoring` or `custom`), seed value and discovery date.\n- `last_discovery_date`: When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time).\n- `organization_name`: An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as `redacted for privacy`.\n- `ignore_date`: When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored.\n- `approve_date`: When the asset was approved into your inventory (UTC date-time); empty unless it is approved.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].asset` | string |  |\n| `results[].asset_unicode` | string |  |\n| `results[].state` | string | One of `in_review`, `approved`, `ignored` |\n| `results[].asset_type` | string | One of `domain`, `subdomain`, `ip`, `website` |\n| `results[].discovery_history` | array of object |  |\n| `results[].last_discovery_date` | string | date-time |\n| `results[].organization_name` | string |  |\n| `results[].ignore_date` | string | date-time |\n| `results[].approve_date` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Discovered Asset Export",
                  "id": "2891d74b-c5ae-5451-9874-08c857e83a6a",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/assets/search:export?format=csv",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "assets",
                        "search:export"
                      ],
                      "query": [
                        {
                          "key": "format",
                          "value": "csv",
                          "description": "One of: `json`, `csv`."
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Discovered Asset Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 4 fields\n\n- `asset`: The discovered asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `discovery_history.id`: The ID of a discovery rule that found the asset, a 32-character hex string; the Discovery page's rule name filter sends this ID.\n- `discovery_history.seed_value`: The seed value a rule started from when it found the asset, such as an IP address, a certificate fingerprint, a phone number or an organization name.\n- `organization_name`: An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as `redacted for privacy`.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `last_discovery_date`: When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time).\n- `ignore_date`: When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored.\n- `approve_date`: When the asset was approved into your inventory (UTC date-time); empty unless it is approved.\n\n**`eq`, `in`, `exists`** — 2 fields\n\n- `asset_type`: The discovered asset's type: `domain`, `subdomain`, `ip` or `website`.\n- `state`: The review state: `in_review` (found by a rule, waiting for a decision), `approved` (added to your inventory) or `ignored` (dismissed; it stays out of your inventory).\n\nSortable fields:\n\n- `asset`: The discovered asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `state`: The review state: `in_review` (found by a rule, waiting for a decision), `approved` (added to your inventory) or `ignored` (dismissed; it stays out of your inventory).\n- `discovery_history`: The rule matches that found the asset, each with the rule ID, rule name, rule type (`smart_discovery`, `smart_monitoring` or `custom`), seed value and discovery date.\n- `last_discovery_date`: When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time).\n- `organization_name`: An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as `redacted for privacy`.\n- `ignore_date`: When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored.\n- `approve_date`: When the asset was approved into your inventory (UTC date-time); empty unless it is approved.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"approved\"\n      }\n    ]\n  }\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Discovered Asset Detail",
                  "id": "894cd2ea-86d7-5a6d-bcd7-2d96b7a0bb3d",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/assets/:asset_id",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "assets",
                        ":asset_id"
                      ],
                      "variable": [
                        {
                          "key": "asset_id",
                          "value": "b2228851c115720b1f0c29bd97386f6b",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Discovered Asset Detail API**\n\nReturns one discovered asset with the rules and seeds that discovered it.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `asset` | string |  |\n| `asset_unicode` | string |  |\n| `asset_type` | string | One of `domain`, `subdomain`, `ip`, `website` |\n| `state` | string | One of `in_review`, `approved`, `ignored` |\n| `discovery_history` | array of object |  |\n| `last_discovery_date` | string | date-time |\n| `monitoring` | object |  |\n| `approve_date` | string | date-time |\n| `ignore_date` | string | date-time |"
                  },
                  "response": []
                },
                {
                  "name": "Discovered Asset Approve",
                  "id": "cddc87f4-dd1e-5e59-ba05-f82c3936cbb8",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/assets/search:approve",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "assets",
                        "search:approve"
                      ]
                    },
                    "description": "**Deepinfo EASM Discovered Asset Approve API**\n\nApproves the discovered assets that match `filters` (`approved`). Approved assets are **added to your monitored assets**. An approval cannot be reverted; delete the asset instead.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 4 fields\n\n- `asset`: The discovered asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `discovery_history.id`: The ID of a discovery rule that found the asset, a 32-character hex string; the Discovery page's rule name filter sends this ID.\n- `discovery_history.seed_value`: The seed value a rule started from when it found the asset, such as an IP address, a certificate fingerprint, a phone number or an organization name.\n- `organization_name`: An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as `redacted for privacy`.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `last_discovery_date`: When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time).\n- `ignore_date`: When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored.\n- `approve_date`: When the asset was approved into your inventory (UTC date-time); empty unless it is approved.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `asset_type`: The discovered asset's type: `domain`, `subdomain`, `ip` or `website`.\n\nSortable fields:\n\n- `asset`: The discovered asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `discovery_history`: The rule matches that found the asset, each with the rule ID, rule name, rule type (`smart_discovery`, `smart_monitoring` or `custom`), seed value and discovery date.\n- `last_discovery_date`: When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time).\n- `organization_name`: An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as `redacted for privacy`.\n- `ignore_date`: When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored.\n- `approve_date`: When the asset was approved into your inventory (UTC date-time); empty unless it is approved.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `discovered_asset_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"assets.example-202.com\"\n      }\n    ]\n  }\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Discovered Asset Ignore",
                  "id": "8e446193-df09-5526-bbb6-243d289d21a1",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/assets/search:ignore",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "assets",
                        "search:ignore"
                      ]
                    },
                    "description": "**Deepinfo EASM Discovered Asset Ignore API**\n\nIgnores the discovered assets that match `filters` (`ignored`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 4 fields\n\n- `asset`: The discovered asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `discovery_history.id`: The ID of a discovery rule that found the asset, a 32-character hex string; the Discovery page's rule name filter sends this ID.\n- `discovery_history.seed_value`: The seed value a rule started from when it found the asset, such as an IP address, a certificate fingerprint, a phone number or an organization name.\n- `organization_name`: An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as `redacted for privacy`.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `last_discovery_date`: When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time).\n- `ignore_date`: When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored.\n- `approve_date`: When the asset was approved into your inventory (UTC date-time); empty unless it is approved.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `asset_type`: The discovered asset's type: `domain`, `subdomain`, `ip` or `website`.\n\nSortable fields:\n\n- `asset`: The discovered asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `discovery_history`: The rule matches that found the asset, each with the rule ID, rule name, rule type (`smart_discovery`, `smart_monitoring` or `custom`), seed value and discovery date.\n- `last_discovery_date`: When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time).\n- `organization_name`: An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as `redacted for privacy`.\n- `ignore_date`: When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored.\n- `approve_date`: When the asset was approved into your inventory (UTC date-time); empty unless it is approved.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `discovered_asset_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"assets.example-202.com\"\n      }\n    ]\n  }\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Discovered Asset Revert",
                  "id": "85e7f47d-057d-5e4e-a268-247bb071ff54",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/assets/search:revert",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "assets",
                        "search:revert"
                      ]
                    },
                    "description": "**Deepinfo EASM Discovered Asset Revert API**\n\nReverts the discovered assets that match `filters` to their previous, active state. Only states set by a user can be reverted.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 4 fields\n\n- `asset`: The discovered asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `discovery_history.id`: The ID of a discovery rule that found the asset, a 32-character hex string; the Discovery page's rule name filter sends this ID.\n- `discovery_history.seed_value`: The seed value a rule started from when it found the asset, such as an IP address, a certificate fingerprint, a phone number or an organization name.\n- `organization_name`: An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as `redacted for privacy`.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `last_discovery_date`: When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time).\n- `ignore_date`: When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored.\n- `approve_date`: When the asset was approved into your inventory (UTC date-time); empty unless it is approved.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `asset_type`: The discovered asset's type: `domain`, `subdomain`, `ip` or `website`.\n\nSortable fields:\n\n- `asset`: The discovered asset's name: a domain, subdomain or IP address, or for a website asset `host:port`.\n- `discovery_history`: The rule matches that found the asset, each with the rule ID, rule name, rule type (`smart_discovery`, `smart_monitoring` or `custom`), seed value and discovery date.\n- `last_discovery_date`: When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time).\n- `organization_name`: An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as `redacted for privacy`.\n- `ignore_date`: When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored.\n- `approve_date`: When the asset was approved into your inventory (UTC date-time); empty unless it is approved.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `discovered_asset_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"assets.example-202.com\"\n      }\n    ]\n  }\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Discovered Asset State Stats",
                  "id": "011af395-cd10-55ba-b243-62c44d88da69",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/stats/asset-state",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "stats",
                        "asset-state"
                      ]
                    },
                    "description": "**Deepinfo EASM Discovered Asset State Stats API**\n\nCounts discovered assets per state, overall and per rule type.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `in_review` | integer |  |\n| `approved` | integer |  |\n| `ignored` | integer |  |\n| `by_rule_type` | object |  |"
                  },
                  "response": []
                }
              ]
            },
            {
              "name": "Discovery Rules",
              "id": "f4856861-6983-51b4-99b2-5eb9e947d868",
              "description": "**Smart discovery** and **smart monitoring** rules are managed by Deepinfo (you can tune them); **custom rules** are your own.",
              "item": [
                {
                  "name": "Asset Discovery Custom Discovery Rule Search",
                  "id": "dbca5045-5823-512f-b3ef-597f702f6bd2",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/custom-rules/search",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "custom-rules",
                        "search"
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Custom Discovery Rule Search API**\n\nLists your custom discovery rules.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | object |  | One `{field, order}` object |\n\n### Filtering\n\nThis search takes `filters` as an object with one key per field, not as a `must` list. Each field takes the operators of its filter type as keys, and fields combine with AND. `sort` is one `{field, order}` object, not a list. Example body:\n\n```json\n{\n  \"filters\": {\n    \"name\": {\n      \"equals\": [\n        \"<value>\"\n      ]\n    }\n  },\n  \"sort\": {\n    \"field\": \"name\",\n    \"order\": \"desc\"\n  }\n}\n```\n\nOperators by field:\n\n| Field | Operators |\n|---|---|\n| `name` | `equals`, `not_equals`, `contains`, `not_contains`, `startswith`, `endswith`; each takes a list of values |\n| `discovered_asset_count` | `gt`, `gte`, `lt`, `lte` |\n| `tags` | `equals`, `not_equals`, `contains`, `not_contains`, `startswith`, `endswith`; each takes a list of values |\n| `enabled` | a plain boolean value |\n| `create_date` | `gt`, `gte`, `lt`, `lte` |\n| `last_update_date` | `gt`, `gte`, `lt`, `lte` |\n\nSearchable fields:\n\n- `name`: The custom discovery rule's name, as you gave it. Matching is case-insensitive.\n- `discovered_asset_count`: How many assets the rule has discovered.\n- `tags`: The tags on the rule.\n- `enabled`: `true` for rules that are switched on, `false` for rules that are switched off.\n- `create_date`: When the rule was created (ISO 8601 date-time).\n- `last_update_date`: When the rule was last changed (ISO 8601 date-time).\n\nSortable fields:\n\n- `name`: The custom discovery rule's name, as you gave it. Matching is case-insensitive.\n- `discovered_asset_count`: How many assets the rule has discovered.\n- `tags`: The tags on the rule.\n- `enabled`: `true` for rules that are switched on, `false` for rules that are switched off.\n- `create_date`: When the rule was created (ISO 8601 date-time).\n- `last_update_date`: When the rule was last changed (ISO 8601 date-time).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `discovered_asset_count` | integer |  |\n| `tags` | array of string |  |\n| `enabled` | boolean |  |\n| `create_date` | string | date-time |\n| `last_update_date` | string | date-time |",
                    "body": {
                      "mode": "raw",
                      "raw": "{}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Rule List",
                  "id": "6b7bad2a-7e70-55ac-b20f-6a722df67bfb",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/rules",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "rules"
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Rule List API**\n\nLists all discovery rules (smart discovery, smart monitoring and custom) with their counts.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `type` | string | One of `smart_discovery`, `smart_monitoring`, `custom` |\n| `enabled` | boolean |  |"
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Smart Discovery Rule List",
                  "id": "d2c3d2d2-612d-59b8-9af1-86771ec85712",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/smart-discovery-rules",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "smart-discovery-rules"
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Smart Discovery Rule List API**\n\nLists the smart discovery rules Deepinfo runs for you.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `description` | string |  |\n| `discovered_asset_count` | integer |  |\n| `enabled` | boolean |  |"
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Smart Monitoring Rule List",
                  "id": "cda1f1c8-54f2-5f6c-a9f6-b294b68a0af3",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/smart-monitoring-rules",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "smart-monitoring-rules"
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Smart Monitoring Rule List API**\n\nLists the smart monitoring rules Deepinfo runs for you.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `description` | string |  |\n| `discovered_asset_count` | integer |  |\n| `enabled` | boolean |  |"
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Custom Discovery Rule Detail",
                  "id": "f9f96c54-2a02-5708-ab43-9395a09ed940",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/custom-rules/:rule_id",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "custom-rules",
                        ":rule_id"
                      ],
                      "variable": [
                        {
                          "key": "rule_id",
                          "value": "94450762d615019e2b1923e5ca661afb",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Custom Discovery Rule Detail API**\n\nReturns one custom discovery rule.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `filters` | object |  |\n| `tags` | array of string |  |\n| `auto_approval` | boolean |  |\n| `enabled` | boolean |  |\n| `create_date` | string | date-time |\n| `last_update_date` | string | date-time |"
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Smart Discovery Rule Detail",
                  "id": "c7a6eeab-b8dd-5118-9cf1-ad22b8b07656",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/smart-discovery-rules/:rule_id",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "smart-discovery-rules",
                        ":rule_id"
                      ],
                      "variable": [
                        {
                          "key": "rule_id",
                          "value": "735656055b93a9f3ccb25c4e0e39833d",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Smart Discovery Rule Detail API**\n\nReturns one smart discovery rule.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `description` | string |  |\n| `excluded_seed_assets` | array of string |  |\n| `excluded_seed_values` | array of string |  |\n| `auto_approval` | boolean |  |\n| `global_blocklist` | boolean |  |\n| `enabled` | boolean |  |"
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Smart Monitoring Rule Detail",
                  "id": "625b26d0-5c05-5faa-8236-7f00b4680915",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/smart-monitoring-rules/:rule_id",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "smart-monitoring-rules",
                        ":rule_id"
                      ],
                      "variable": [
                        {
                          "key": "rule_id",
                          "value": "87dc939e2823bbec0ea98c0b42493016",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Smart Monitoring Rule Detail API**\n\nReturns one smart monitoring rule.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `description` | string |  |\n| `excluded_seed_assets` | array of string |  |\n| `auto_approval` | boolean |  |\n| `global_blocklist` | boolean |  |\n| `enabled` | boolean |  |"
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Custom Discovery Rule Create",
                  "id": "4f8f9984-bf88-5d59-96a9-3cc7c82c5aa4",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/custom-rules",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "custom-rules"
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Custom Discovery Rule Create API**\n\nCreates a custom discovery rule. `filters` select which domains in Deepinfo's dataset become candidates; `auto_approval` adds them to your assets directly.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `name` | string | yes | min length `1`; max length `255` |\n| `filters` | object | yes | The filters of the rule; see the example request body |\n| `tags` | array |  | max items `10` |\n| `auto_approval` | boolean | yes |  |\n| `enabled` | boolean | yes |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `filters` | object |  |\n| `tags` | array of string |  |\n| `auto_approval` | boolean |  |\n| `enabled` | boolean |  |\n| `create_date` | string | date-time |\n| `last_update_date` | string | date-time |",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"name\": \"Postman docs test rule\",\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"webdata.http.final_domain\",\n        \"value\": \"deepinfo.com\",\n        \"type\": \"eq\"\n      }\n    ],\n    \"must_not\": [],\n    \"should\": []\n  },\n  \"tags\": [],\n  \"auto_approval\": false,\n  \"enabled\": false\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Custom Discovery Rule Update",
                  "id": "86fb4ac8-434f-5cb9-85f8-6c0ba613ca4a",
                  "request": {
                    "method": "PUT",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/custom-rules/:rule_id",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "custom-rules",
                        ":rule_id"
                      ],
                      "variable": [
                        {
                          "key": "rule_id",
                          "value": "4f310b15aad7f6c763b3b43ff9f29131",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Custom Discovery Rule Update API**\n\nUpdates a custom discovery rule (send all fields).\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `name` | string | yes | min length `1`; max length `255` |\n| `filters` | object | yes | The filters of the rule; see the example request body |\n| `tags` | array |  | max items `10` |\n| `auto_approval` | boolean | yes |  |\n| `enabled` | boolean | yes |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `filters` | object |  |\n| `tags` | array of string |  |\n| `auto_approval` | boolean |  |\n| `enabled` | boolean |  |\n| `create_date` | string | date-time |\n| `last_update_date` | string | date-time |",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"name\": \"Postman docs test rule (updated)\",\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"webdata.http.final_domain\",\n        \"value\": \"deepinfo.com\",\n        \"type\": \"eq\"\n      }\n    ],\n    \"must_not\": [],\n    \"should\": []\n  },\n  \"tags\": [],\n  \"auto_approval\": false,\n  \"enabled\": false\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Smart Discovery Rule Update",
                  "id": "69bda5c3-c27e-592b-9c10-3dd4277e1195",
                  "request": {
                    "method": "PUT",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/smart-discovery-rules/:rule_id",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "smart-discovery-rules",
                        ":rule_id"
                      ],
                      "variable": [
                        {
                          "key": "rule_id",
                          "value": "735656055b93a9f3ccb25c4e0e39833d",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Smart Discovery Rule Update API**\n\nTunes a smart discovery rule with the settings in the request body.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `excluded_seed_assets` | array |  |  |\n| `excluded_seed_values` | array |  |  |\n| `auto_approval` | boolean | yes |  |\n| `global_blocklist` | boolean | yes |  |\n| `enabled` | boolean | yes |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `description` | string |  |\n| `excluded_seed_assets` | array of string |  |\n| `excluded_seed_values` | array of string |  |\n| `auto_approval` | boolean |  |\n| `global_blocklist` | boolean |  |\n| `enabled` | boolean |  |",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"excluded_seed_assets\": [],\n  \"excluded_seed_values\": [],\n  \"auto_approval\": false,\n  \"global_blocklist\": true,\n  \"enabled\": true\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Smart Monitoring Rule Update",
                  "id": "0f178f9c-5fff-558a-a330-c802526da059",
                  "request": {
                    "method": "PUT",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/smart-monitoring-rules/:rule_id",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "smart-monitoring-rules",
                        ":rule_id"
                      ],
                      "variable": [
                        {
                          "key": "rule_id",
                          "value": "87dc939e2823bbec0ea98c0b42493016",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Smart Monitoring Rule Update API**\n\nTunes a smart monitoring rule with the settings in the request body.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `excluded_seed_assets` | array |  |  |\n| `auto_approval` | boolean | yes |  |\n| `global_blocklist` | boolean | yes |  |\n| `enabled` | boolean | yes |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `description` | string |  |\n| `excluded_seed_assets` | array of string |  |\n| `auto_approval` | boolean |  |\n| `global_blocklist` | boolean |  |\n| `enabled` | boolean |  |",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"excluded_seed_assets\": [],\n  \"auto_approval\": false,\n  \"global_blocklist\": true,\n  \"enabled\": true\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Custom Discovery Rule Delete",
                  "id": "ca6a9a33-99a8-5b3b-8261-5b066cdbad45",
                  "request": {
                    "method": "DELETE",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/custom-rules/:rule_id",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "custom-rules",
                        ":rule_id"
                      ],
                      "variable": [
                        {
                          "key": "rule_id",
                          "value": "4f310b15aad7f6c763b3b43ff9f29131",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Custom Discovery Rule Delete API**\n\nDeletes a custom discovery rule."
                  },
                  "response": []
                }
              ]
            },
            {
              "name": "Settings",
              "id": "a20b493e-8e6f-5aef-81f1-524b04fb821a",
              "description": "Discovery-wide settings.",
              "item": [
                {
                  "name": "Asset Discovery Settings Detail",
                  "id": "06684a7c-b40f-5e28-aac1-960922e0d703",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/settings",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "settings"
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Settings Detail API**\n\nReturns discovery settings: `ignored_assets` are never proposed as candidates.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `ignored_assets` | array of string |  |"
                  },
                  "response": []
                },
                {
                  "name": "Asset Discovery Settings Update",
                  "id": "9aeb6f89-3027-5b34-948a-7d909066f80d",
                  "request": {
                    "method": "PUT",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/discovery/settings",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "discovery",
                        "settings"
                      ]
                    },
                    "description": "**Deepinfo EASM Asset Discovery Settings Update API**\n\nReplaces discovery settings. Send the **full** `ignored_assets` list.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `ignored_assets` | array | yes |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `ignored_assets` | array of string |  |",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"ignored_assets\": []\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                }
              ]
            }
          ]
        },
        {
          "name": "Issues",
          "id": "430b795b-5c25-5a1f-885e-3d8a214c9a1d",
          "description": "Security issues detected on your assets, grouped by issue **type** and **category**.",
          "item": [
            {
              "name": "Issues",
              "id": "bdfc70ff-b5c7-5101-bda4-770ef4467e82",
              "description": "Search issues and change their state.",
              "item": [
                {
                  "name": "Issue Search",
                  "id": "aa57f0f8-7440-54e5-9486-146a82b3dc96",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/search?page_size=25",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "search"
                      ],
                      "query": [
                        {
                          "key": "page",
                          "value": "1",
                          "description": "Min `1`, max `800`. Default `1`.",
                          "disabled": true
                        },
                        {
                          "key": "page_size",
                          "value": "25",
                          "description": "Min `25`, max `100`. Default `100`."
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Search API**\n\nSearches issues on your assets by state, severity, type, category, asset and dates.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 9 fields\n\n- `asset.id`: The ID of the asset the issue was found on, a 24-character hexadecimal string; it is the same ID that Asset Search returns for that asset.\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.tags`: Your own tags on the asset the issue was found on, as a list of strings (the asset's `tags` in Asset Search).\n- `asset.domain_asset.id`: The ID of the domain asset the issue's asset belongs to; for a domain it is the asset's own ID. `asset.domain_asset` is null when the asset's domain is not one of your assets.\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `type.id`: The ID of the issue type, a 24-character hexadecimal string. Pass it to Issue Type Detail (`GET /easm/issues/types/{issue_type_id}`), or filter on it to list every asset with that issue type.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.category.id`: The ID of the issue type's category, a 24-character hexadecimal string, as listed by Issue Categories (`GET /easm/issues/categories/list`).\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n\n**`eq`, `in`, `exists`** — 4 fields\n\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The issue's ID, a 24-character hexadecimal string. Pass it to Issue Detail (`GET /easm/issues/{issue_id}`), or filter on it with `in` to select exact issues.\n\nSortable fields:\n\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].asset` | object |  |\n| `results[].state` | string | One of `newly_detected`, `reappeared`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |\n| `results[].severity` | string | One of `Critical`, `High`, `Medium`, `Low`, `Information` |\n| `results[].first_seen_date` | string | date-time |\n| `results[].last_seen_date` | string | date-time |\n| `results[].last_check_date` | string | date-time |\n| `results[].type` | object |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Issue Export",
                  "id": "abf88f30-004d-582c-83a5-ce62fc5270a5",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/search:export?format=csv",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "search:export"
                      ],
                      "query": [
                        {
                          "key": "format",
                          "value": "csv",
                          "description": "One of: `json`, `csv`."
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 9 fields\n\n- `asset.id`: The ID of the asset the issue was found on, a 24-character hexadecimal string; it is the same ID that Asset Search returns for that asset.\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.tags`: Your own tags on the asset the issue was found on, as a list of strings (the asset's `tags` in Asset Search).\n- `asset.domain_asset.id`: The ID of the domain asset the issue's asset belongs to; for a domain it is the asset's own ID. `asset.domain_asset` is null when the asset's domain is not one of your assets.\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `type.id`: The ID of the issue type, a 24-character hexadecimal string. Pass it to Issue Type Detail (`GET /easm/issues/types/{issue_type_id}`), or filter on it to list every asset with that issue type.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.category.id`: The ID of the issue type's category, a 24-character hexadecimal string, as listed by Issue Categories (`GET /easm/issues/categories/list`).\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n\n**`eq`, `in`, `exists`** — 4 fields\n\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The issue's ID, a 24-character hexadecimal string. Pass it to Issue Detail (`GET /easm/issues/{issue_id}`), or filter on it with `in` to select exact issues.\n\nSortable fields:\n\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Issue Detail",
                  "id": "5bec69bc-cb72-5b95-beb4-552da9ea4d3d",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/:issue_id",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        ":issue_id"
                      ],
                      "variable": [
                        {
                          "key": "issue_id",
                          "value": "6a80a5430567c461d69f67ac",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Detail API**\n\nReturns one issue with its asset, type, state history and evidence.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `asset` | object |  |\n| `state` | string | One of `newly_detected`, `reappeared`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |\n| `severity` | string | One of `Critical`, `High`, `Medium`, `Low`, `Information` |\n| `proof` | object |  |\n| `context` | object |  |\n| `first_seen_date` | string | date-time |\n| `last_seen_date` | string | date-time |\n| `last_check_date` | string | date-time |\n| `labels` | array of string |  |\n| `type` | object |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Accept Risk",
                  "id": "ebd87a4b-342b-5d02-8cf8-44b49f1ebe05",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/search:accept-risk",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "search:accept-risk"
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Accept Risk API**\n\nAccepts the risk of the issues that match `filters` (`risk_accepted`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 9 fields\n\n- `asset.id`: The ID of the asset the issue was found on, a 24-character hexadecimal string; it is the same ID that Asset Search returns for that asset.\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.tags`: Your own tags on the asset the issue was found on, as a list of strings (the asset's `tags` in Asset Search).\n- `asset.domain_asset.id`: The ID of the domain asset the issue's asset belongs to; for a domain it is the asset's own ID. `asset.domain_asset` is null when the asset's domain is not one of your assets.\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `type.id`: The ID of the issue type, a 24-character hexadecimal string. Pass it to Issue Type Detail (`GET /easm/issues/types/{issue_type_id}`), or filter on it to list every asset with that issue type.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.category.id`: The ID of the issue type's category, a 24-character hexadecimal string, as listed by Issue Categories (`GET /easm/issues/categories/list`).\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n\n**`eq`, `in`, `exists`** — 4 fields\n\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The issue's ID, a 24-character hexadecimal string. Pass it to Issue Detail (`GET /easm/issues/{issue_id}`), or filter on it with `in` to select exact issues.\n\nSortable fields:\n\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `issue_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a80a5430567c461d69f67ac\"\n      }\n    ]\n  }\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Issue Ignore",
                  "id": "b17c6993-9c32-5b82-ac38-8e22389a5ae1",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/search:ignore",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "search:ignore"
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Ignore API**\n\nIgnores the issues that match `filters` (`ignored`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 9 fields\n\n- `asset.id`: The ID of the asset the issue was found on, a 24-character hexadecimal string; it is the same ID that Asset Search returns for that asset.\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.tags`: Your own tags on the asset the issue was found on, as a list of strings (the asset's `tags` in Asset Search).\n- `asset.domain_asset.id`: The ID of the domain asset the issue's asset belongs to; for a domain it is the asset's own ID. `asset.domain_asset` is null when the asset's domain is not one of your assets.\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `type.id`: The ID of the issue type, a 24-character hexadecimal string. Pass it to Issue Type Detail (`GET /easm/issues/types/{issue_type_id}`), or filter on it to list every asset with that issue type.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.category.id`: The ID of the issue type's category, a 24-character hexadecimal string, as listed by Issue Categories (`GET /easm/issues/categories/list`).\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n\n**`eq`, `in`, `exists`** — 4 fields\n\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The issue's ID, a 24-character hexadecimal string. Pass it to Issue Detail (`GET /easm/issues/{issue_id}`), or filter on it with `in` to select exact issues.\n\nSortable fields:\n\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `issue_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a80a5430567c461d69f67ac\"\n      }\n    ]\n  }\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Issue Mark False Positive",
                  "id": "276a5dd0-80d7-5c9e-96be-cc2424918868",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/search:mark-false-positive",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "search:mark-false-positive"
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Mark False Positive API**\n\nMarks the issues that match `filters` as false positive (`marked_as_false_positive`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 9 fields\n\n- `asset.id`: The ID of the asset the issue was found on, a 24-character hexadecimal string; it is the same ID that Asset Search returns for that asset.\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.tags`: Your own tags on the asset the issue was found on, as a list of strings (the asset's `tags` in Asset Search).\n- `asset.domain_asset.id`: The ID of the domain asset the issue's asset belongs to; for a domain it is the asset's own ID. `asset.domain_asset` is null when the asset's domain is not one of your assets.\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `type.id`: The ID of the issue type, a 24-character hexadecimal string. Pass it to Issue Type Detail (`GET /easm/issues/types/{issue_type_id}`), or filter on it to list every asset with that issue type.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.category.id`: The ID of the issue type's category, a 24-character hexadecimal string, as listed by Issue Categories (`GET /easm/issues/categories/list`).\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n\n**`eq`, `in`, `exists`** — 4 fields\n\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The issue's ID, a 24-character hexadecimal string. Pass it to Issue Detail (`GET /easm/issues/{issue_id}`), or filter on it with `in` to select exact issues.\n\nSortable fields:\n\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `issue_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a80a5430567c461d69f67ac\"\n      }\n    ]\n  }\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Issue Mark Resolved",
                  "id": "8b66cfa5-d1f1-5413-a0e1-2728158514e3",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/search:mark-resolved",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "search:mark-resolved"
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Mark Resolved API**\n\nMarks the issues that match `filters` as resolved (`marked_as_resolved`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 9 fields\n\n- `asset.id`: The ID of the asset the issue was found on, a 24-character hexadecimal string; it is the same ID that Asset Search returns for that asset.\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.tags`: Your own tags on the asset the issue was found on, as a list of strings (the asset's `tags` in Asset Search).\n- `asset.domain_asset.id`: The ID of the domain asset the issue's asset belongs to; for a domain it is the asset's own ID. `asset.domain_asset` is null when the asset's domain is not one of your assets.\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `type.id`: The ID of the issue type, a 24-character hexadecimal string. Pass it to Issue Type Detail (`GET /easm/issues/types/{issue_type_id}`), or filter on it to list every asset with that issue type.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.category.id`: The ID of the issue type's category, a 24-character hexadecimal string, as listed by Issue Categories (`GET /easm/issues/categories/list`).\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n\n**`eq`, `in`, `exists`** — 4 fields\n\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The issue's ID, a 24-character hexadecimal string. Pass it to Issue Detail (`GET /easm/issues/{issue_id}`), or filter on it with `in` to select exact issues.\n\nSortable fields:\n\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `issue_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a80a5430567c461d69f67ac\"\n      }\n    ]\n  }\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                },
                {
                  "name": "Issue Revert",
                  "id": "6133939f-3586-574c-8811-5246c3a5b67d",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      },
                      {
                        "key": "Content-Type",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/search:revert",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "search:revert"
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Revert API**\n\nReverts the issues that match `filters` to their previous, active state. Only states set by a user can be reverted.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 9 fields\n\n- `asset.id`: The ID of the asset the issue was found on, a 24-character hexadecimal string; it is the same ID that Asset Search returns for that asset.\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.tags`: Your own tags on the asset the issue was found on, as a list of strings (the asset's `tags` in Asset Search).\n- `asset.domain_asset.id`: The ID of the domain asset the issue's asset belongs to; for a domain it is the asset's own ID. `asset.domain_asset` is null when the asset's domain is not one of your assets.\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `type.id`: The ID of the issue type, a 24-character hexadecimal string. Pass it to Issue Type Detail (`GET /easm/issues/types/{issue_type_id}`), or filter on it to list every asset with that issue type.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.category.id`: The ID of the issue type's category, a 24-character hexadecimal string, as listed by Issue Categories (`GET /easm/issues/categories/list`).\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n\n**`eq`, `in`, `exists`** — 4 fields\n\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The issue's ID, a 24-character hexadecimal string. Pass it to Issue Detail (`GET /easm/issues/{issue_id}`), or filter on it with `in` to select exact issues.\n\nSortable fields:\n\n- `asset.name`: The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET.\n- `asset.type`: The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website).\n- `asset.domain_asset.name`: The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets.\n- `state`: The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `severity`: The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology.\n- `type.name`: The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it.\n- `type.severity`: The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it.\n- `type.category.name`: The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`.\n- `first_seen_date`: When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`.\n- `last_seen_date`: When the issue was most recently detected on the asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `issue_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                    "body": {
                      "mode": "raw",
                      "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a80a5430567c461d69f67ac\"\n      }\n    ]\n  }\n}",
                      "options": {
                        "raw": {
                          "language": "json"
                        }
                      }
                    }
                  },
                  "response": []
                }
              ]
            },
            {
              "name": "Issue Stats",
              "id": "1e23b4c5-6d4d-5457-ac64-7a3f0d1ff73c",
              "description": "Issue statistics across your assets.\n\nMost of them accept these filters:\n\n- `asset`\n- `type_id`\n- `type_category_id`",
              "item": [
                {
                  "name": "Issue Asset Type Stats",
                  "id": "27e9327e-6807-5a38-958b-06cc49a08424",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/stats/asset-type",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "stats",
                        "asset-type"
                      ],
                      "query": [
                        {
                          "key": "type_id",
                          "value": "",
                          "description": "",
                          "disabled": true
                        },
                        {
                          "key": "type_category_id",
                          "value": "",
                          "description": "",
                          "disabled": true
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Asset Type Stats API**\n\nCounts issues per asset type.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `asset_type` | string | One of `domain`, `subdomain`, `ip`, `website` |\n| `count` | integer |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Category Stats",
                  "id": "e759a252-a031-5e62-b09f-75a46dfa947a",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/stats/category-type",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "stats",
                        "category-type"
                      ],
                      "query": [
                        {
                          "key": "asset",
                          "value": "",
                          "description": "",
                          "disabled": true
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Category Stats API**\n\nCounts issues per category and type.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `category` | string |  |\n| `count` | integer |  |\n| `severity_stats` | array of object |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Duration Stats",
                  "id": "ad7b820e-bc74-57a6-95c9-e49a3bffe8a7",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/stats/duration",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "stats",
                        "duration"
                      ],
                      "query": [
                        {
                          "key": "asset",
                          "value": "",
                          "description": "",
                          "disabled": true
                        },
                        {
                          "key": "type_id",
                          "value": "",
                          "description": "",
                          "disabled": true
                        },
                        {
                          "key": "type_category_id",
                          "value": "",
                          "description": "",
                          "disabled": true
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Duration Stats API**\n\nAverage time issues stay open and time to fix.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `first_seen_date` | string | date-time |\n| `last_seen_date` | string | date-time |\n| `average_issue_duration` | integer |  |\n| `average_fix_duration` | integer |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Severity Stats",
                  "id": "de425d96-59d6-5ab4-a365-327e8a00569c",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/stats/severity",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "stats",
                        "severity"
                      ],
                      "query": [
                        {
                          "key": "asset",
                          "value": "",
                          "description": "",
                          "disabled": true
                        },
                        {
                          "key": "type_id",
                          "value": "",
                          "description": "",
                          "disabled": true
                        },
                        {
                          "key": "type_category_id",
                          "value": "",
                          "description": "",
                          "disabled": true
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Severity Stats API**\n\nCounts active issues per severity.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `severity` | string | One of `Critical`, `High`, `Medium`, `Low`, `Information` |\n| `count` | integer |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Severity Stats Timeline",
                  "id": "e6042b23-d2bb-55c4-bad3-5f2e5b8f99c0",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/stats/severity-timeline?interval=weekly",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "stats",
                        "severity-timeline"
                      ],
                      "query": [
                        {
                          "key": "interval",
                          "value": "weekly",
                          "description": "One of: `daily`, `weekly`, `monthly`."
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Severity Stats Timeline API**\n\nTime series of severity for the selected `interval` (`daily`, `weekly`, `monthly`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `severities` | array of object |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue State Stats",
                  "id": "580d9a64-2dda-5260-9f55-0a4696108faa",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/stats/state",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "stats",
                        "state"
                      ],
                      "query": [
                        {
                          "key": "asset",
                          "value": "",
                          "description": "",
                          "disabled": true
                        },
                        {
                          "key": "type_id",
                          "value": "",
                          "description": "",
                          "disabled": true
                        },
                        {
                          "key": "type_category_id",
                          "value": "",
                          "description": "",
                          "disabled": true
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue State Stats API**\n\nCounts issues per state.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `state` | string | One of `newly_detected`, `reappeared`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |\n| `count` | integer |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Type Stats",
                  "id": "a06c119a-5020-528c-a8e2-2dfcc38f0a8b",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/stats/type",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "stats",
                        "type"
                      ],
                      "query": [
                        {
                          "key": "severity",
                          "value": "",
                          "description": "",
                          "disabled": true
                        },
                        {
                          "key": "type_id",
                          "value": "",
                          "description": "",
                          "disabled": true
                        },
                        {
                          "key": "type_category_id",
                          "value": "",
                          "description": "",
                          "disabled": true
                        },
                        {
                          "key": "ordering",
                          "value": "",
                          "description": "",
                          "disabled": true
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Type Stats API**\n\nCounts issues per issue type (filter by `severity`, sort with `ordering`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `severity` | string | One of `Critical`, `High`, `Medium`, `Low`, `Information` |\n| `type` | object |  |\n| `affected_asset_count` | integer |  |"
                  },
                  "response": []
                }
              ]
            },
            {
              "name": "Issue Types",
              "id": "60577e0f-34ae-5b34-b6cc-5f1b7b29dafd",
              "description": "Details, score timeline and snapshot of one issue type.",
              "item": [
                {
                  "name": "Issue Type Detail",
                  "id": "096728d8-b65b-5310-bb8f-5a2725d6d956",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/types/:issue_type_id",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "types",
                        ":issue_type_id"
                      ],
                      "variable": [
                        {
                          "key": "issue_type_id",
                          "value": "676031e3618cc64619a9d372",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Type Detail API**\n\nReturns an issue type: description, severity, category and remediation.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `category` | object |  |\n| `certainty` | integer | One of `50`, `95`, `100` |\n| `severity` | string | One of `Critical`, `High`, `Medium`, `Low`, `Information` |\n| `context` | object |  |\n| `description` | string |  |\n| `impact` | string |  |\n| `remedy` | string |  |\n| `external_references` | string |  |\n| `classifications` | array of object |  |\n| `cvss` | string |  |\n| `scopes` | array of string |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Type Instant Snapshot",
                  "id": "e5c0a5c9-aec1-5fc2-8d6b-3714719fcad5",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/types/:issue_type_id/instant-snapshot",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "types",
                        ":issue_type_id",
                        "instant-snapshot"
                      ],
                      "variable": [
                        {
                          "key": "issue_type_id",
                          "value": "676031e3618cc64619a9d372",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Type Instant Snapshot API**\n\nRecalculates the issue type snapshot now.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `triggered` | boolean |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Type Latest Snapshot",
                  "id": "ed287280-d747-51fe-bd92-88d8e044dff1",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/types/:issue_type_id/latest-snapshot",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "types",
                        ":issue_type_id",
                        "latest-snapshot"
                      ],
                      "query": [
                        {
                          "key": "stats",
                          "value": "",
                          "description": "",
                          "disabled": true
                        }
                      ],
                      "variable": [
                        {
                          "key": "issue_type_id",
                          "value": "676031e3618cc64619a9d372",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Type Latest Snapshot API**\n\nLatest summary of one issue type across your assets.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `snapshot` | object |  |\n| `date` | string | date-time |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Type Security Score Timeline",
                  "id": "0e765eaf-b7d8-55f2-9954-95ba322c2f29",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/types/:issue_type_id/security-score-timeline?interval=weekly",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "types",
                        ":issue_type_id",
                        "security-score-timeline"
                      ],
                      "query": [
                        {
                          "key": "interval",
                          "value": "weekly",
                          "description": "One of: `daily`, `weekly`, `monthly`."
                        }
                      ],
                      "variable": [
                        {
                          "key": "issue_type_id",
                          "value": "676031e3618cc64619a9d372",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Type Security Score Timeline API**\n\nTime series of the security score for one issue type. `interval`: `daily`, `weekly`, `monthly`. Can take several seconds.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `score` | number |  |\n| `date` | string | date |"
                  },
                  "response": []
                }
              ]
            },
            {
              "name": "Issue Categories",
              "id": "5a911421-3a37-514e-9ad8-45c8de4c9245",
              "description": "Issue categories, with score timeline and snapshot per category.",
              "item": [
                {
                  "name": "Issue Categories",
                  "id": "e3d0c2e9-c3b0-59cb-acd7-9cbbaf3c3adf",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/categories/list",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "categories",
                        "list"
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Categories API**\n\nLists issue categories.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `description` | string |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Categories Instant Snapshot",
                  "id": "1997b68f-0cba-5ce8-a17e-6c5f51718996",
                  "request": {
                    "method": "POST",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/categories/:issue_type_category_id/instant-snapshot",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "categories",
                        ":issue_type_category_id",
                        "instant-snapshot"
                      ],
                      "variable": [
                        {
                          "key": "issue_type_category_id",
                          "value": "6332dd1aa5e451d178862aee",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Categories Instant Snapshot API**\n\nRecalculates the issue category snapshot now.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `triggered` | boolean |  |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Categories Latest Snapshot",
                  "id": "f5cca81f-bbb8-519c-bdab-08b9fa6700f2",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/categories/:issue_type_category_id/latest-snapshot",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "categories",
                        ":issue_type_category_id",
                        "latest-snapshot"
                      ],
                      "query": [
                        {
                          "key": "stats",
                          "value": "",
                          "description": "",
                          "disabled": true
                        }
                      ],
                      "variable": [
                        {
                          "key": "issue_type_category_id",
                          "value": "6332dd1aa5e451d178862aee",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Categories Latest Snapshot API**\n\nLatest summary of one issue category.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `snapshot` | object |  |\n| `date` | string | date-time |"
                  },
                  "response": []
                },
                {
                  "name": "Issue Categories Security Score Timeline",
                  "id": "d887b174-f978-5861-a083-9c6a53e52e35",
                  "request": {
                    "method": "GET",
                    "header": [
                      {
                        "key": "Accept",
                        "value": "application/json"
                      }
                    ],
                    "url": {
                      "raw": "{{api_base_url}}/{{api_version}}/easm/issues/categories/:issue_type_category_id/security-score-timeline?interval=weekly",
                      "host": [
                        "{{api_base_url}}"
                      ],
                      "path": [
                        "{{api_version}}",
                        "easm",
                        "issues",
                        "categories",
                        ":issue_type_category_id",
                        "security-score-timeline"
                      ],
                      "query": [
                        {
                          "key": "interval",
                          "value": "weekly",
                          "description": "One of: `daily`, `weekly`, `monthly`."
                        }
                      ],
                      "variable": [
                        {
                          "key": "issue_type_category_id",
                          "value": "6332dd1aa5e451d178862aee",
                          "description": "**Required.**"
                        }
                      ]
                    },
                    "description": "**Deepinfo EASM Issue Categories Security Score Timeline API**\n\nTime series of the security score for one issue category. `interval`: `daily`, `weekly`, `monthly`.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `score` | number |  |"
                  },
                  "response": []
                }
              ]
            }
          ]
        },
        {
          "name": "Vulnerabilities",
          "id": "3d96d488-109b-51a4-be53-2d25a55bc24f",
          "description": "Vulnerabilities (CVEs) that affect technologies found on your assets.",
          "item": [
            {
              "name": "Vulnerability Asset Search",
              "id": "201426e2-6fc5-5fb5-a174-42181bf4ed09",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/asset-search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "asset-search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Asset Search API**\n\nSearches vulnerabilities per asset (one record per asset + CVE), with state.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 21 fields\n\n- `asset`: The affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset `host:port`. Filter with `eq` and the exact name to get one asset's CVEs; responses carry it in `asset.name`.\n- `domain_asset`: The name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in `asset.domain_asset.name`.\n- `asset_tags`: Your own tags on the affected asset, for filtering; responses carry them in `asset.tags`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.enrichment.vdeep_metric.cvss_version`: CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`.\n- `cve.enrichment.cwe.owasptop10_2021`: OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip.\n- `cve.enrichment.cwe.name`: Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`.\n- `cve.enrichment.cwe.description`: The CWE catalog's description of a weakness linked to the CVE.\n- `cve.enrichment.cwe.scope`: Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`.\n- `cve.enrichment.cwe.impact`: Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`.\n- `cve.enrichment.cwe.detection_method`: Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD.\n- `cve.enrichment.cisa_kev.vendor_project`: Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.product`: Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`.\n- `cve.enrichment.cisa_kev.vulnerability_name`: Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`.\n- `cve.enrichment.cisa_kev.short_description`: CISA's short description of the vulnerability in the CVE's KEV entry.\n- `cve.enrichment.cisa_kev.required_action`: Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.`\n- `cve.enrichment.cisa_kev.known_ransomware_campaign_use`: Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`.\n- `cve.enrichment.cisa_kev.notes`: Notes in the CVE's CISA KEV entry, often reference URLs.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 13 fields\n\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.cwe.capec_id`: IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.epss_score.percentile`: Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score).\n- `cve.enrichment.epss_score.date`: Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.due_date`: Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this CVE, in ISO 8601 UTC; it equals `last_seen_date` while the CVE is still found and is later once the CVE is `verified_resolved`.\n\n**`eq`, `in`, `exists`** — 6 fields\n\n- `asset_type`: The affected asset's type, for filtering: `domain`, `subdomain`, `ip` or `website`; responses carry it in `asset.type`.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality`: Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`: Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability`: Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\nSortable fields:\n\n- `asset.name`: The affected asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. Sort only; filter with `asset`.\n- `asset.type`: The affected asset's type: `domain`, `subdomain`, `ip` or `website`. Sort only; filter with `asset_type`.\n- `asset.domain_asset.name`: The name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with `domain_asset`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].asset` | object |  |\n| `results[].technologies` | array of object |  |\n| `results[].cve` | object |  |\n| `results[].first_seen_date` | string | date-time |\n| `results[].last_seen_date` | string | date-time |\n| `results[].last_check_date` | string | date-time |\n| `results[].state` | string | One of `newly_detected`, `reappeared`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |\n| `results[].is_certain` | boolean |  |\n| `results[].is_potential` | boolean |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Vulnerability Search",
              "id": "523f7256-f069-5dff-a3cb-6706fceb6ef2",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Search API**\n\nSearches vulnerabilities (CVEs) affecting your assets, one record per CVE.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"cve.id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 29 fields\n\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.cwe.capec_id`: IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.epss_score.percentile`: Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score).\n- `cve.enrichment.epss_score.date`: Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.due_date`: Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.\n- `affected_asset_count.total`: Number of your assets the CVE is active on (state `newly_detected`, `unresolved` or `reappeared`); the Vulnerability List shows it as ASSETS.\n- `affected_asset_count.domain`: Number of domain assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.subdomain`: Number of subdomain assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.ip`: Number of IP address assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.website`: Number of website assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_domain_asset_count`: Number of domain assets the CVE is active on; in the samples it always equals `affected_asset_count.domain`.\n- `first_seen_date`: When the CVE was first detected on any of your assets, in ISO 8601 UTC: the earliest `first_seen_date` of its per-asset records. The platform marks a CVE first seen in the last 7 days as NEW.\n- `last_seen_date`: When the CVE was most recently detected on any of your assets, in ISO 8601 UTC: the latest `last_seen_date` of its per-asset records.\n- `last_check_date`: When your assets were last checked for the CVE, in ISO 8601 UTC: the latest `last_check_date` of its per-asset records.\n- `certainly_affected_asset_count.total`: Number of your assets on which the CVE is certain (verified through testing and confirmed as valid), whatever the per-asset state, active or inactive.\n- `certainly_affected_asset_count.domain`: Number of domain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.subdomain`: Number of subdomain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.ip`: Number of IP address assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.website`: Number of website assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `potentially_affected_asset_count.total`: Number of your assets on which the CVE is potential (identified through testing but not yet confirmed), whatever the per-asset state, active or inactive.\n- `potentially_affected_asset_count.domain`: Number of domain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.subdomain`: Number of subdomain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.ip`: Number of IP address assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.website`: Number of website assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 16 fields\n\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; the Vulnerability List's SEARCH box matches it.\n- `cve.enrichment.vdeep_metric.cvss_version`: CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`.\n- `cve.enrichment.cwe.owasptop10_2021`: OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip.\n- `cve.enrichment.cwe.name`: Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`.\n- `cve.enrichment.cwe.description`: The CWE catalog's description of a weakness linked to the CVE.\n- `cve.enrichment.cwe.scope`: Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`.\n- `cve.enrichment.cwe.impact`: Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`.\n- `cve.enrichment.cwe.detection_method`: Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD.\n- `cve.enrichment.cisa_kev.vendor_project`: Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.product`: Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`.\n- `cve.enrichment.cisa_kev.vulnerability_name`: Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`.\n- `cve.enrichment.cisa_kev.short_description`: CISA's short description of the vulnerability in the CVE's KEV entry.\n- `cve.enrichment.cisa_kev.required_action`: Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.`\n- `cve.enrichment.cisa_kev.known_ransomware_campaign_use`: Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`.\n- `cve.enrichment.cisa_kev.notes`: Notes in the CVE's CISA KEV entry, often reference URLs.\n- `affected_asset_tags`: Your own tags on the assets the CVE affects, as a list of strings; filter on it to find CVEs on assets with a given tag.\n\n**`eq`, `in`, `exists`** — 5 fields\n\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality`: Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`: Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability`: Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `state`: Whether the CVE is still active on at least one of your assets: `active` or `inactive`. The per-asset states are in Vulnerability Asset Search, and the Vulnerability List shows `active` CVEs only.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_certain`: `true` when the CVE is certain on at least one of your assets, that is, verified through testing and confirmed as valid; see `certainly_affected_asset_count`.\n- `is_potential`: `true` when the CVE is potential on at least one of your assets, that is, identified through testing but not yet confirmed; see `potentially_affected_asset_count`.\n\nSortable fields:\n\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; the Vulnerability List's SEARCH box matches it.\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `affected_asset_count.total`: Number of your assets the CVE is active on (state `newly_detected`, `unresolved` or `reappeared`); the Vulnerability List shows it as ASSETS.\n- `affected_asset_count.domain`: Number of domain assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.subdomain`: Number of subdomain assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.ip`: Number of IP address assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.website`: Number of website assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_domain_asset_count`: Number of domain assets the CVE is active on; in the samples it always equals `affected_asset_count.domain`.\n- `first_seen_date`: When the CVE was first detected on any of your assets, in ISO 8601 UTC: the earliest `first_seen_date` of its per-asset records. The platform marks a CVE first seen in the last 7 days as NEW.\n- `last_seen_date`: When the CVE was most recently detected on any of your assets, in ISO 8601 UTC: the latest `last_seen_date` of its per-asset records.\n- `state`: Whether the CVE is still active on at least one of your assets: `active` or `inactive`. The per-asset states are in Vulnerability Asset Search, and the Vulnerability List shows `active` CVEs only.\n- `is_certain`: `true` when the CVE is certain on at least one of your assets, that is, verified through testing and confirmed as valid; see `certainly_affected_asset_count`.\n- `is_potential`: `true` when the CVE is potential on at least one of your assets, that is, identified through testing but not yet confirmed; see `potentially_affected_asset_count`.\n- `certainly_affected_asset_count.total`: Number of your assets on which the CVE is certain (verified through testing and confirmed as valid), whatever the per-asset state, active or inactive.\n- `certainly_affected_asset_count.domain`: Number of domain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.subdomain`: Number of subdomain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.ip`: Number of IP address assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.website`: Number of website assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `potentially_affected_asset_count.total`: Number of your assets on which the CVE is potential (identified through testing but not yet confirmed), whatever the per-asset state, active or inactive.\n- `potentially_affected_asset_count.domain`: Number of domain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.subdomain`: Number of subdomain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.ip`: Number of IP address assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.website`: Number of website assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].cve` | object |  |\n| `results[].affected_asset_count` | object |  |\n| `results[].affected_domain_asset_count` | integer |  |\n| `results[].affected_asset_tags` | array of string |  |\n| `results[].first_seen_date` | string | date-time |\n| `results[].last_seen_date` | string | date-time |\n| `results[].last_check_date` | string | date-time |\n| `results[].state` | string | One of `active`, `inactive` |\n| `results[].is_certain` | boolean |  |\n| `results[].is_potential` | boolean |  |\n| `results[].certainly_affected_asset_count` | object |  |\n| `results[].potentially_affected_asset_count` | object |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Vulnerability Asset Export",
              "id": "7e86fd99-8a6d-56d6-9716-eed67b93d975",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/asset-search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "asset-search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Asset Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 21 fields\n\n- `asset`: The affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset `host:port`. Filter with `eq` and the exact name to get one asset's CVEs; responses carry it in `asset.name`.\n- `domain_asset`: The name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in `asset.domain_asset.name`.\n- `asset_tags`: Your own tags on the affected asset, for filtering; responses carry them in `asset.tags`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.enrichment.vdeep_metric.cvss_version`: CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`.\n- `cve.enrichment.cwe.owasptop10_2021`: OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip.\n- `cve.enrichment.cwe.name`: Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`.\n- `cve.enrichment.cwe.description`: The CWE catalog's description of a weakness linked to the CVE.\n- `cve.enrichment.cwe.scope`: Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`.\n- `cve.enrichment.cwe.impact`: Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`.\n- `cve.enrichment.cwe.detection_method`: Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD.\n- `cve.enrichment.cisa_kev.vendor_project`: Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.product`: Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`.\n- `cve.enrichment.cisa_kev.vulnerability_name`: Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`.\n- `cve.enrichment.cisa_kev.short_description`: CISA's short description of the vulnerability in the CVE's KEV entry.\n- `cve.enrichment.cisa_kev.required_action`: Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.`\n- `cve.enrichment.cisa_kev.known_ransomware_campaign_use`: Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`.\n- `cve.enrichment.cisa_kev.notes`: Notes in the CVE's CISA KEV entry, often reference URLs.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 13 fields\n\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.cwe.capec_id`: IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.epss_score.percentile`: Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score).\n- `cve.enrichment.epss_score.date`: Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.due_date`: Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this CVE, in ISO 8601 UTC; it equals `last_seen_date` while the CVE is still found and is later once the CVE is `verified_resolved`.\n\n**`eq`, `in`, `exists`** — 6 fields\n\n- `asset_type`: The affected asset's type, for filtering: `domain`, `subdomain`, `ip` or `website`; responses carry it in `asset.type`.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality`: Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`: Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability`: Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\nSortable fields:\n\n- `asset.name`: The affected asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. Sort only; filter with `asset`.\n- `asset.type`: The affected asset's type: `domain`, `subdomain`, `ip` or `website`. Sort only; filter with `asset_type`.\n- `asset.domain_asset.name`: The name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with `domain_asset`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"deepinfo.com\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Vulnerability Export",
              "id": "d68215e4-07e4-5689-aaf5-85ace55d962b",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"cve.id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 29 fields\n\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.cwe.capec_id`: IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.epss_score.percentile`: Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score).\n- `cve.enrichment.epss_score.date`: Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.due_date`: Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.\n- `affected_asset_count.total`: Number of your assets the CVE is active on (state `newly_detected`, `unresolved` or `reappeared`); the Vulnerability List shows it as ASSETS.\n- `affected_asset_count.domain`: Number of domain assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.subdomain`: Number of subdomain assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.ip`: Number of IP address assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.website`: Number of website assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_domain_asset_count`: Number of domain assets the CVE is active on; in the samples it always equals `affected_asset_count.domain`.\n- `first_seen_date`: When the CVE was first detected on any of your assets, in ISO 8601 UTC: the earliest `first_seen_date` of its per-asset records. The platform marks a CVE first seen in the last 7 days as NEW.\n- `last_seen_date`: When the CVE was most recently detected on any of your assets, in ISO 8601 UTC: the latest `last_seen_date` of its per-asset records.\n- `last_check_date`: When your assets were last checked for the CVE, in ISO 8601 UTC: the latest `last_check_date` of its per-asset records.\n- `certainly_affected_asset_count.total`: Number of your assets on which the CVE is certain (verified through testing and confirmed as valid), whatever the per-asset state, active or inactive.\n- `certainly_affected_asset_count.domain`: Number of domain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.subdomain`: Number of subdomain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.ip`: Number of IP address assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.website`: Number of website assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `potentially_affected_asset_count.total`: Number of your assets on which the CVE is potential (identified through testing but not yet confirmed), whatever the per-asset state, active or inactive.\n- `potentially_affected_asset_count.domain`: Number of domain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.subdomain`: Number of subdomain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.ip`: Number of IP address assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.website`: Number of website assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 16 fields\n\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; the Vulnerability List's SEARCH box matches it.\n- `cve.enrichment.vdeep_metric.cvss_version`: CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`.\n- `cve.enrichment.cwe.owasptop10_2021`: OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip.\n- `cve.enrichment.cwe.name`: Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`.\n- `cve.enrichment.cwe.description`: The CWE catalog's description of a weakness linked to the CVE.\n- `cve.enrichment.cwe.scope`: Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`.\n- `cve.enrichment.cwe.impact`: Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`.\n- `cve.enrichment.cwe.detection_method`: Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD.\n- `cve.enrichment.cisa_kev.vendor_project`: Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.product`: Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`.\n- `cve.enrichment.cisa_kev.vulnerability_name`: Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`.\n- `cve.enrichment.cisa_kev.short_description`: CISA's short description of the vulnerability in the CVE's KEV entry.\n- `cve.enrichment.cisa_kev.required_action`: Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.`\n- `cve.enrichment.cisa_kev.known_ransomware_campaign_use`: Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`.\n- `cve.enrichment.cisa_kev.notes`: Notes in the CVE's CISA KEV entry, often reference URLs.\n- `affected_asset_tags`: Your own tags on the assets the CVE affects, as a list of strings; filter on it to find CVEs on assets with a given tag.\n\n**`eq`, `in`, `exists`** — 5 fields\n\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality`: Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`: Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability`: Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `state`: Whether the CVE is still active on at least one of your assets: `active` or `inactive`. The per-asset states are in Vulnerability Asset Search, and the Vulnerability List shows `active` CVEs only.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_certain`: `true` when the CVE is certain on at least one of your assets, that is, verified through testing and confirmed as valid; see `certainly_affected_asset_count`.\n- `is_potential`: `true` when the CVE is potential on at least one of your assets, that is, identified through testing but not yet confirmed; see `potentially_affected_asset_count`.\n\nSortable fields:\n\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; the Vulnerability List's SEARCH box matches it.\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `affected_asset_count.total`: Number of your assets the CVE is active on (state `newly_detected`, `unresolved` or `reappeared`); the Vulnerability List shows it as ASSETS.\n- `affected_asset_count.domain`: Number of domain assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.subdomain`: Number of subdomain assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.ip`: Number of IP address assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_asset_count.website`: Number of website assets the CVE is active on; part of `affected_asset_count.total`.\n- `affected_domain_asset_count`: Number of domain assets the CVE is active on; in the samples it always equals `affected_asset_count.domain`.\n- `first_seen_date`: When the CVE was first detected on any of your assets, in ISO 8601 UTC: the earliest `first_seen_date` of its per-asset records. The platform marks a CVE first seen in the last 7 days as NEW.\n- `last_seen_date`: When the CVE was most recently detected on any of your assets, in ISO 8601 UTC: the latest `last_seen_date` of its per-asset records.\n- `state`: Whether the CVE is still active on at least one of your assets: `active` or `inactive`. The per-asset states are in Vulnerability Asset Search, and the Vulnerability List shows `active` CVEs only.\n- `is_certain`: `true` when the CVE is certain on at least one of your assets, that is, verified through testing and confirmed as valid; see `certainly_affected_asset_count`.\n- `is_potential`: `true` when the CVE is potential on at least one of your assets, that is, identified through testing but not yet confirmed; see `potentially_affected_asset_count`.\n- `certainly_affected_asset_count.total`: Number of your assets on which the CVE is certain (verified through testing and confirmed as valid), whatever the per-asset state, active or inactive.\n- `certainly_affected_asset_count.domain`: Number of domain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.subdomain`: Number of subdomain assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.ip`: Number of IP address assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `certainly_affected_asset_count.website`: Number of website assets on which the CVE is certain, active or inactive; part of `certainly_affected_asset_count.total`.\n- `potentially_affected_asset_count.total`: Number of your assets on which the CVE is potential (identified through testing but not yet confirmed), whatever the per-asset state, active or inactive.\n- `potentially_affected_asset_count.domain`: Number of domain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.subdomain`: Number of subdomain assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.ip`: Number of IP address assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n- `potentially_affected_asset_count.website`: Number of website assets on which the CVE is potential, active or inactive; part of `potentially_affected_asset_count.total`.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Vulnerability Detail",
              "id": "40599b95-42e4-5146-8047-ccc5d993a287",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/:vulnerability_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    ":vulnerability_id"
                  ],
                  "variable": [
                    {
                      "key": "vulnerability_id",
                      "value": "ca846e8f31156a4318a1cb4cfc8e0569",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Detail API**\n\nReturns one vulnerability with CVE details and affected assets.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `cve` | object |  |\n| `affected_asset_count` | object |  |\n| `affected_domain_asset_count` | integer |  |\n| `affected_asset_tags` | array of string |  |\n| `first_seen_date` | string | date-time |\n| `last_seen_date` | string | date-time |\n| `last_check_date` | string | date-time |\n| `state` | string | One of `active`, `inactive` |\n| `is_certain` | boolean |  |\n| `is_potential` | boolean |  |\n| `certainly_affected_asset_count` | object |  |\n| `potentially_affected_asset_count` | object |  |"
              },
              "response": []
            },
            {
              "name": "Vulnerability Accept Risk",
              "id": "7892e6c9-0ace-52cb-b8bb-a0158cfbdcf8",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/search:accept-risk",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "search:accept-risk"
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Accept Risk API**\n\nAccepts the risk of the asset vulnerabilities that match `filters` (`risk_accepted`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 21 fields\n\n- `asset`: The affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset `host:port`. Filter with `eq` and the exact name to get one asset's CVEs; responses carry it in `asset.name`.\n- `domain_asset`: The name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in `asset.domain_asset.name`.\n- `asset_tags`: Your own tags on the affected asset, for filtering; responses carry them in `asset.tags`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.enrichment.vdeep_metric.cvss_version`: CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`.\n- `cve.enrichment.cwe.owasptop10_2021`: OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip.\n- `cve.enrichment.cwe.name`: Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`.\n- `cve.enrichment.cwe.description`: The CWE catalog's description of a weakness linked to the CVE.\n- `cve.enrichment.cwe.scope`: Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`.\n- `cve.enrichment.cwe.impact`: Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`.\n- `cve.enrichment.cwe.detection_method`: Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD.\n- `cve.enrichment.cisa_kev.vendor_project`: Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.product`: Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`.\n- `cve.enrichment.cisa_kev.vulnerability_name`: Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`.\n- `cve.enrichment.cisa_kev.short_description`: CISA's short description of the vulnerability in the CVE's KEV entry.\n- `cve.enrichment.cisa_kev.required_action`: Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.`\n- `cve.enrichment.cisa_kev.known_ransomware_campaign_use`: Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`.\n- `cve.enrichment.cisa_kev.notes`: Notes in the CVE's CISA KEV entry, often reference URLs.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 13 fields\n\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.cwe.capec_id`: IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.epss_score.percentile`: Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score).\n- `cve.enrichment.epss_score.date`: Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.due_date`: Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this CVE, in ISO 8601 UTC; it equals `last_seen_date` while the CVE is still found and is later once the CVE is `verified_resolved`.\n\n**`eq`, `in`, `exists`** — 6 fields\n\n- `asset_type`: The affected asset's type, for filtering: `domain`, `subdomain`, `ip` or `website`; responses carry it in `asset.type`.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality`: Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`: Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability`: Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\nSortable fields:\n\n- `asset.name`: The affected asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. Sort only; filter with `asset`.\n- `asset.type`: The affected asset's type: `domain`, `subdomain`, `ip` or `website`. Sort only; filter with `asset_type`.\n- `asset.domain_asset.name`: The name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with `domain_asset`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `asset_vulnerability_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"example-2190.com\"\n      },\n      {\n        \"name\": \"cve.id\",\n        \"type\": \"eq\",\n        \"value\": \"CVE-2025-55182\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Vulnerability Ignore",
              "id": "dafe0c9e-4c9f-59da-a20a-d649a6dc4e9c",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/search:ignore",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "search:ignore"
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Ignore API**\n\nIgnores the asset vulnerabilities that match `filters` (`ignored`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 21 fields\n\n- `asset`: The affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset `host:port`. Filter with `eq` and the exact name to get one asset's CVEs; responses carry it in `asset.name`.\n- `domain_asset`: The name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in `asset.domain_asset.name`.\n- `asset_tags`: Your own tags on the affected asset, for filtering; responses carry them in `asset.tags`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.enrichment.vdeep_metric.cvss_version`: CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`.\n- `cve.enrichment.cwe.owasptop10_2021`: OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip.\n- `cve.enrichment.cwe.name`: Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`.\n- `cve.enrichment.cwe.description`: The CWE catalog's description of a weakness linked to the CVE.\n- `cve.enrichment.cwe.scope`: Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`.\n- `cve.enrichment.cwe.impact`: Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`.\n- `cve.enrichment.cwe.detection_method`: Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD.\n- `cve.enrichment.cisa_kev.vendor_project`: Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.product`: Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`.\n- `cve.enrichment.cisa_kev.vulnerability_name`: Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`.\n- `cve.enrichment.cisa_kev.short_description`: CISA's short description of the vulnerability in the CVE's KEV entry.\n- `cve.enrichment.cisa_kev.required_action`: Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.`\n- `cve.enrichment.cisa_kev.known_ransomware_campaign_use`: Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`.\n- `cve.enrichment.cisa_kev.notes`: Notes in the CVE's CISA KEV entry, often reference URLs.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 13 fields\n\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.cwe.capec_id`: IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.epss_score.percentile`: Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score).\n- `cve.enrichment.epss_score.date`: Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.due_date`: Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this CVE, in ISO 8601 UTC; it equals `last_seen_date` while the CVE is still found and is later once the CVE is `verified_resolved`.\n\n**`eq`, `in`, `exists`** — 6 fields\n\n- `asset_type`: The affected asset's type, for filtering: `domain`, `subdomain`, `ip` or `website`; responses carry it in `asset.type`.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality`: Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`: Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability`: Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\nSortable fields:\n\n- `asset.name`: The affected asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. Sort only; filter with `asset`.\n- `asset.type`: The affected asset's type: `domain`, `subdomain`, `ip` or `website`. Sort only; filter with `asset_type`.\n- `asset.domain_asset.name`: The name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with `domain_asset`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `asset_vulnerability_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"example-2190.com\"\n      },\n      {\n        \"name\": \"cve.id\",\n        \"type\": \"eq\",\n        \"value\": \"CVE-2025-55182\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Vulnerability Mark False Positive",
              "id": "d26511f8-9948-57b6-9b77-f8739e6296e6",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/search:mark-false-positive",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "search:mark-false-positive"
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Mark False Positive API**\n\nMarks the asset vulnerabilities that match `filters` as false positive (`marked_as_false_positive`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 21 fields\n\n- `asset`: The affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset `host:port`. Filter with `eq` and the exact name to get one asset's CVEs; responses carry it in `asset.name`.\n- `domain_asset`: The name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in `asset.domain_asset.name`.\n- `asset_tags`: Your own tags on the affected asset, for filtering; responses carry them in `asset.tags`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.enrichment.vdeep_metric.cvss_version`: CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`.\n- `cve.enrichment.cwe.owasptop10_2021`: OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip.\n- `cve.enrichment.cwe.name`: Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`.\n- `cve.enrichment.cwe.description`: The CWE catalog's description of a weakness linked to the CVE.\n- `cve.enrichment.cwe.scope`: Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`.\n- `cve.enrichment.cwe.impact`: Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`.\n- `cve.enrichment.cwe.detection_method`: Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD.\n- `cve.enrichment.cisa_kev.vendor_project`: Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.product`: Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`.\n- `cve.enrichment.cisa_kev.vulnerability_name`: Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`.\n- `cve.enrichment.cisa_kev.short_description`: CISA's short description of the vulnerability in the CVE's KEV entry.\n- `cve.enrichment.cisa_kev.required_action`: Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.`\n- `cve.enrichment.cisa_kev.known_ransomware_campaign_use`: Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`.\n- `cve.enrichment.cisa_kev.notes`: Notes in the CVE's CISA KEV entry, often reference URLs.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 13 fields\n\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.cwe.capec_id`: IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.epss_score.percentile`: Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score).\n- `cve.enrichment.epss_score.date`: Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.due_date`: Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this CVE, in ISO 8601 UTC; it equals `last_seen_date` while the CVE is still found and is later once the CVE is `verified_resolved`.\n\n**`eq`, `in`, `exists`** — 6 fields\n\n- `asset_type`: The affected asset's type, for filtering: `domain`, `subdomain`, `ip` or `website`; responses carry it in `asset.type`.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality`: Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`: Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability`: Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\nSortable fields:\n\n- `asset.name`: The affected asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. Sort only; filter with `asset`.\n- `asset.type`: The affected asset's type: `domain`, `subdomain`, `ip` or `website`. Sort only; filter with `asset_type`.\n- `asset.domain_asset.name`: The name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with `domain_asset`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `asset_vulnerability_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"example-2190.com\"\n      },\n      {\n        \"name\": \"cve.id\",\n        \"type\": \"eq\",\n        \"value\": \"CVE-2025-55182\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Vulnerability Mark Resolved",
              "id": "382d5834-8d8f-56e8-9d71-129b9bc6233c",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/search:mark-resolved",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "search:mark-resolved"
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Mark Resolved API**\n\nMarks the asset vulnerabilities that match `filters` as resolved (`marked_as_resolved`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 21 fields\n\n- `asset`: The affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset `host:port`. Filter with `eq` and the exact name to get one asset's CVEs; responses carry it in `asset.name`.\n- `domain_asset`: The name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in `asset.domain_asset.name`.\n- `asset_tags`: Your own tags on the affected asset, for filtering; responses carry them in `asset.tags`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.enrichment.vdeep_metric.cvss_version`: CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`.\n- `cve.enrichment.cwe.owasptop10_2021`: OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip.\n- `cve.enrichment.cwe.name`: Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`.\n- `cve.enrichment.cwe.description`: The CWE catalog's description of a weakness linked to the CVE.\n- `cve.enrichment.cwe.scope`: Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`.\n- `cve.enrichment.cwe.impact`: Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`.\n- `cve.enrichment.cwe.detection_method`: Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD.\n- `cve.enrichment.cisa_kev.vendor_project`: Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.product`: Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`.\n- `cve.enrichment.cisa_kev.vulnerability_name`: Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`.\n- `cve.enrichment.cisa_kev.short_description`: CISA's short description of the vulnerability in the CVE's KEV entry.\n- `cve.enrichment.cisa_kev.required_action`: Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.`\n- `cve.enrichment.cisa_kev.known_ransomware_campaign_use`: Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`.\n- `cve.enrichment.cisa_kev.notes`: Notes in the CVE's CISA KEV entry, often reference URLs.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 13 fields\n\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.cwe.capec_id`: IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.epss_score.percentile`: Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score).\n- `cve.enrichment.epss_score.date`: Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.due_date`: Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this CVE, in ISO 8601 UTC; it equals `last_seen_date` while the CVE is still found and is later once the CVE is `verified_resolved`.\n\n**`eq`, `in`, `exists`** — 6 fields\n\n- `asset_type`: The affected asset's type, for filtering: `domain`, `subdomain`, `ip` or `website`; responses carry it in `asset.type`.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality`: Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`: Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability`: Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\nSortable fields:\n\n- `asset.name`: The affected asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. Sort only; filter with `asset`.\n- `asset.type`: The affected asset's type: `domain`, `subdomain`, `ip` or `website`. Sort only; filter with `asset_type`.\n- `asset.domain_asset.name`: The name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with `domain_asset`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `asset_vulnerability_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"example-2190.com\"\n      },\n      {\n        \"name\": \"cve.id\",\n        \"type\": \"eq\",\n        \"value\": \"CVE-2025-55182\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Vulnerability Revert",
              "id": "1f27af88-047d-5a99-a90e-7e809bbf9ce2",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/search:revert",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "search:revert"
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Revert API**\n\nReverts the asset vulnerabilities that match `filters` to their previous, active state. Only states set by a user can be reverted.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"asset.name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 21 fields\n\n- `asset`: The affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset `host:port`. Filter with `eq` and the exact name to get one asset's CVEs; responses carry it in `asset.name`.\n- `domain_asset`: The name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in `asset.domain_asset.name`.\n- `asset_tags`: Your own tags on the affected asset, for filtering; responses carry them in `asset.tags`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.enrichment.vdeep_metric.cvss_version`: CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`.\n- `cve.enrichment.cwe.owasptop10_2021`: OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip.\n- `cve.enrichment.cwe.name`: Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`.\n- `cve.enrichment.cwe.description`: The CWE catalog's description of a weakness linked to the CVE.\n- `cve.enrichment.cwe.scope`: Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`.\n- `cve.enrichment.cwe.impact`: Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`.\n- `cve.enrichment.cwe.detection_method`: Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD.\n- `cve.enrichment.cisa_kev.vendor_project`: Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.product`: Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`.\n- `cve.enrichment.cisa_kev.vulnerability_name`: Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`.\n- `cve.enrichment.cisa_kev.short_description`: CISA's short description of the vulnerability in the CVE's KEV entry.\n- `cve.enrichment.cisa_kev.required_action`: Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.`\n- `cve.enrichment.cisa_kev.known_ransomware_campaign_use`: Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`.\n- `cve.enrichment.cisa_kev.notes`: Notes in the CVE's CISA KEV entry, often reference URLs.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 13 fields\n\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.cwe.capec_id`: IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.epss_score.percentile`: Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score).\n- `cve.enrichment.epss_score.date`: Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `cve.enrichment.cisa_kev.due_date`: Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `last_check_date`: When the asset was last checked for this CVE, in ISO 8601 UTC; it equals `last_seen_date` while the CVE is still found and is later once the CVE is `verified_resolved`.\n\n**`eq`, `in`, `exists`** — 6 fields\n\n- `asset_type`: The affected asset's type, for filtering: `domain`, `subdomain`, `ip` or `website`; responses carry it in `asset.type`.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality`: Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity`: Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability`: Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\nSortable fields:\n\n- `asset.name`: The affected asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. Sort only; filter with `asset`.\n- `asset.type`: The affected asset's type: `domain`, `subdomain`, `ip` or `website`. Sort only; filter with `asset_type`.\n- `asset.domain_asset.name`: The name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with `domain_asset`.\n- `technologies.vendor`: Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE.\n- `technologies.product`: Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`.\n- `technologies.version`: Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected.\n- `cve.id`: The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects.\n- `cve.published`: When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`).\n- `cve.last_modified`: When the CVE record was last changed, in ISO 8601 UTC.\n- `cve.enrichment.vdeep_metric.cvss_data.base_score`: CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY.\n- `cve.enrichment.vdeep_metric.cvss_data.base_severity`: Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it.\n- `cve.enrichment.cwe.id`: Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name.\n- `cve.enrichment.epss_score.epss`: EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage.\n- `cve.enrichment.cisa_kev.date_added`: Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog.\n- `first_seen_date`: When the CVE was first detected on this asset, in ISO 8601 UTC.\n- `last_seen_date`: When the CVE was most recently detected on this asset, in ISO 8601 UTC.\n- `state`: The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set.\n- `is_certain`: `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both.\n- `is_potential`: `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `asset_vulnerability_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"asset\",\n        \"type\": \"eq\",\n        \"value\": \"example-2190.com\"\n      },\n      {\n        \"name\": \"cve.id\",\n        \"type\": \"eq\",\n        \"value\": \"CVE-2025-55182\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Vulnerability Exploitability Score Stats",
              "id": "3ef08c31-78f4-5bea-8756-4bcb8a0ecf3b",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/stats/exploitability-score",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "stats",
                    "exploitability-score"
                  ],
                  "query": [
                    {
                      "key": "asset",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "vendor",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "product",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "version",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Exploitability Score Stats API**\n\nDistribution of vulnerabilities by exploitability score.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `average_exploitability_score_cve` | number |  |\n| `average_exploitability_score_asset_cve` | number |  |"
              },
              "response": []
            },
            {
              "name": "Vulnerability Known Exploitable Stats",
              "id": "293e7e7a-a069-5d47-a477-677765802434",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/stats/known-exploitable",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "stats",
                    "known-exploitable"
                  ],
                  "query": [
                    {
                      "key": "asset",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "vendor",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "product",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "version",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Known Exploitable Stats API**\n\nCounts known-exploited (CISA KEV) vulnerabilities.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `total_cve_count` | integer |  |\n| `total_asset_count` | integer |  |\n| `total_asset_cve_count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Vulnerability Severity Stats",
              "id": "3c41daa2-1ac9-57d7-b316-335169dc9c70",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/stats/severity",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "stats",
                    "severity"
                  ],
                  "query": [
                    {
                      "key": "asset",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "vendor",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "product",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "version",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Severity Stats API**\n\nCounts vulnerabilities per severity.\n\nFilters:\n\n- `asset`\n- `vendor`\n- `product`\n- `version`\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `severity` | string | One of `critical`, `high`, `medium`, `low`, `none`, `unknown` |\n| `count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Vulnerability Severity Stats Timeline",
              "id": "778e50f6-8df8-549e-ae94-9d3e72e69b7b",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/vulnerabilities/stats/severity-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "vulnerabilities",
                    "stats",
                    "severity-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Vulnerability Severity Stats Timeline API**\n\nTime series of severity for the selected `interval` (`daily`, `weekly`, `monthly`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `severities` | array of object |  |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Technologies",
          "id": "d97231ea-7db0-5fdb-91be-a27b831106dc",
          "description": "Technologies (software, frameworks, services) detected on your assets.",
          "item": [
            {
              "name": "Technology Asset Search",
              "id": "cdbb6974-a7e7-5e16-8867-2dc6b4d0eb38",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/asset-search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "asset-search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Technology Asset Search API**\n\nSearches technologies per asset (one record per asset + technology).\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | object |  | One `{field, order}` object |\n\n### Filtering\n\nThis search takes `filters` as an object with one key per field, not as a `must` list. Each field takes the operators of its filter type as keys, and fields combine with AND. `sort` is one `{field, order}` object, not a list. Example body:\n\n```json\n{\n  \"filters\": {\n    \"technology\": {\n      \"equals\": [\n        \"<value>\"\n      ]\n    }\n  },\n  \"sort\": {\n    \"field\": \"technology\",\n    \"order\": \"desc\"\n  }\n}\n```\n\nOperators by field:\n\n| Field | Operators |\n|---|---|\n| `technology` | `equals`, `not_equals`, `contains`, `not_contains`, `startswith`, `endswith`; each takes a list of values |\n| `asset` | `equals`, `not_equals`, `contains`, `not_contains`, `startswith`, `endswith`; each takes a list of values |\n| `categories` | `equals`, `not_equals`, `contains`, `not_contains` |\n| `versions` | `equals`, `not_equals`; each takes a list of values |\n| `latest_version` | `equals`, `not_equals` |\n| `vulnerabilities` | `gt`, `gte`, `lt`, `lte` |\n\nSearchable fields:\n\n- `technology`: The technology's name, such as `PHP`. Matching is case-insensitive.\n- `asset`: The name of the asset the technology was found on, such as `www.acme.example`.\n- `categories`: The technology's categories, such as `Web servers`.\n- `versions`: The versions of the technology found on this asset, such as `1.0.0`; `unknown` when no version was detected.\n- `latest_version`: The latest released version of the technology, such as `1.2.3`; `unknown` when it is not known.\n- `vulnerabilities`: The number of known vulnerabilities of the technology's versions on this asset (`vulnerability_stats.total` in the response).\n\nSortable fields:\n\n- `technology`: The technology's name, such as `PHP`. Matching is case-insensitive.\n- `asset`: The name of the asset the technology was found on, such as `www.acme.example`.\n- `categories`: The technology's categories, such as `Web servers`.\n- `versions`: The versions of the technology found on this asset, such as `1.0.0`; `unknown` when no version was detected.\n- `latest_version`: The latest released version of the technology, such as `1.2.3`; `unknown` when it is not known.\n- `vulnerabilities`: The number of known vulnerabilities of the technology's versions on this asset (`vulnerability_stats.total` in the response).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].technology` | string |  |\n| `results[].favicon` | string |  |\n| `results[].asset` | object |  |\n| `results[].categories` | array of string |  |\n| `results[].versions` | array of object |  |\n| `results[].latest_version` | string |  |\n| `results[].vulnerability_stats` | object |  |\n\nPaginated. See **Getting Started → Pagination**.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Technology Search",
              "id": "3df6ae85-17e6-5db2-a75f-0412f4530015",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Technology Search API**\n\nSearches technologies detected on your assets, with versions and vulnerability counts.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | object |  | One `{field, order}` object |\n\n### Filtering\n\nThis search takes `filters` as an object with one key per field, not as a `must` list. Each field takes the operators of its filter type as keys, and fields combine with AND. `sort` is one `{field, order}` object, not a list. Example body:\n\n```json\n{\n  \"filters\": {\n    \"technology\": {\n      \"equals\": \"<value>\"\n    }\n  },\n  \"sort\": {\n    \"field\": \"technology\",\n    \"order\": \"desc\"\n  }\n}\n```\n\nOperators by field:\n\n| Field | Operators |\n|---|---|\n| `technology` | `equals`, `not_equals`, `contains`, `not_contains` |\n| `categories` | `equals`, `not_equals`, `contains`, `not_contains` |\n| `affected_asset_count` | `gt`, `gte`, `lt`, `lte` |\n| `versions` | `equals`, `not_equals`; each takes a list of values |\n| `version_scope` | a plain value: `all`, `out_of_date` |\n| `latest_version` | `equals`, `not_equals` |\n| `vulnerability_stats` | `gt`, `gte`, `lt`, `lte` |\n\nSearchable fields:\n\n- `technology`: The technology's name, such as `PHP` or `nginx`; the list's TECHNOLOGY column. Matching is case-insensitive.\n- `categories`: The technology's categories, such as `Web servers` or `JavaScript libraries`. A technology can have several.\n- `affected_asset_count`: How many of your assets use the technology.\n- `versions`: The versions of the technology found on your assets, such as `1.0.0`; `unknown` when no version was detected. Each version says whether it has known vulnerabilities.\n- `version_scope`: `out_of_date` keeps only technologies with a version older than the latest one; `all` (the default) keeps every technology. The platform's VERSION SCOPE filter.\n- `latest_version`: The latest released version of the technology, such as `1.2.3`; `unknown` when it is not known.\n- `vulnerability_stats`: The number of known vulnerabilities of the technology's versions on your assets (`vulnerability_stats.total` in the response); the platform's TOTAL VULN. COUNT.\n\nSortable fields:\n\n- `technology`: The technology's name, such as `PHP` or `nginx`; the list's TECHNOLOGY column. Matching is case-insensitive.\n- `categories`: The technology's categories, such as `Web servers` or `JavaScript libraries`. A technology can have several.\n- `affected_asset_count`: How many of your assets use the technology.\n- `versions`: The versions of the technology found on your assets, such as `1.0.0`; `unknown` when no version was detected. Each version says whether it has known vulnerabilities.\n- `latest_version`: The latest released version of the technology, such as `1.2.3`; `unknown` when it is not known.\n- `vulnerability_stats`: The number of known vulnerabilities of the technology's versions on your assets (`vulnerability_stats.total` in the response); the platform's TOTAL VULN. COUNT.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].technology` | string |  |\n| `results[].favicon` | string |  |\n| `results[].categories` | array of string |  |\n| `results[].affected_asset_count` | integer |  |\n| `results[].versions` | array of object |  |\n| `results[].latest_version` | string |  |\n| `results[].vulnerability_stats` | object |  |\n\nPaginated. See **Getting Started → Pagination**.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Technology Asset Export",
              "id": "86484b14-7d90-5d74-a716-2a6efded0300",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/asset-search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "asset-search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Technology Asset Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | object |  | One `{field, order}` object |\n\n### Filtering\n\nThis search takes `filters` as an object with one key per field, not as a `must` list. Each field takes the operators of its filter type as keys, and fields combine with AND. `sort` is one `{field, order}` object, not a list. Example body:\n\n```json\n{\n  \"filters\": {\n    \"technology\": {\n      \"equals\": [\n        \"<value>\"\n      ]\n    }\n  },\n  \"sort\": {\n    \"field\": \"technology\",\n    \"order\": \"desc\"\n  }\n}\n```\n\nOperators by field:\n\n| Field | Operators |\n|---|---|\n| `technology` | `equals`, `not_equals`, `contains`, `not_contains`, `startswith`, `endswith`; each takes a list of values |\n| `asset` | `equals`, `not_equals`, `contains`, `not_contains`, `startswith`, `endswith`; each takes a list of values |\n| `categories` | `equals`, `not_equals`, `contains`, `not_contains` |\n| `versions` | `equals`, `not_equals`; each takes a list of values |\n| `latest_version` | `equals`, `not_equals` |\n| `vulnerabilities` | `gt`, `gte`, `lt`, `lte` |\n\nSearchable fields:\n\n- `technology`: The technology's name, such as `PHP`. Matching is case-insensitive.\n- `asset`: The name of the asset the technology was found on, such as `www.acme.example`.\n- `categories`: The technology's categories, such as `Web servers`.\n- `versions`: The versions of the technology found on this asset, such as `1.0.0`; `unknown` when no version was detected.\n- `latest_version`: The latest released version of the technology, such as `1.2.3`; `unknown` when it is not known.\n- `vulnerabilities`: The number of known vulnerabilities of the technology's versions on this asset (`vulnerability_stats.total` in the response).\n\nSortable fields:\n\n- `technology`: The technology's name, such as `PHP`. Matching is case-insensitive.\n- `asset`: The name of the asset the technology was found on, such as `www.acme.example`.\n- `categories`: The technology's categories, such as `Web servers`.\n- `versions`: The versions of the technology found on this asset, such as `1.0.0`; `unknown` when no version was detected.\n- `latest_version`: The latest released version of the technology, such as `1.2.3`; `unknown` when it is not known.\n- `vulnerabilities`: The number of known vulnerabilities of the technology's versions on this asset (`vulnerability_stats.total` in the response).",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Technology Export",
              "id": "320060c4-da12-554d-a347-8e31f3876bfb",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Technology Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | object |  | One `{field, order}` object |\n\n### Filtering\n\nThis search takes `filters` as an object with one key per field, not as a `must` list. Each field takes the operators of its filter type as keys, and fields combine with AND. `sort` is one `{field, order}` object, not a list. Example body:\n\n```json\n{\n  \"filters\": {\n    \"technology\": {\n      \"equals\": \"<value>\"\n    }\n  },\n  \"sort\": {\n    \"field\": \"technology\",\n    \"order\": \"desc\"\n  }\n}\n```\n\nOperators by field:\n\n| Field | Operators |\n|---|---|\n| `technology` | `equals`, `not_equals`, `contains`, `not_contains` |\n| `categories` | `equals`, `not_equals`, `contains`, `not_contains` |\n| `affected_asset_count` | `gt`, `gte`, `lt`, `lte` |\n| `versions` | `equals`, `not_equals`; each takes a list of values |\n| `version_scope` | a plain value: `all`, `out_of_date` |\n| `latest_version` | `equals`, `not_equals` |\n| `vulnerability_stats` | `gt`, `gte`, `lt`, `lte` |\n\nSearchable fields:\n\n- `technology`: The technology's name, such as `PHP` or `nginx`; the list's TECHNOLOGY column. Matching is case-insensitive.\n- `categories`: The technology's categories, such as `Web servers` or `JavaScript libraries`. A technology can have several.\n- `affected_asset_count`: How many of your assets use the technology.\n- `versions`: The versions of the technology found on your assets, such as `1.0.0`; `unknown` when no version was detected. Each version says whether it has known vulnerabilities.\n- `version_scope`: `out_of_date` keeps only technologies with a version older than the latest one; `all` (the default) keeps every technology. The platform's VERSION SCOPE filter.\n- `latest_version`: The latest released version of the technology, such as `1.2.3`; `unknown` when it is not known.\n- `vulnerability_stats`: The number of known vulnerabilities of the technology's versions on your assets (`vulnerability_stats.total` in the response); the platform's TOTAL VULN. COUNT.\n\nSortable fields:\n\n- `technology`: The technology's name, such as `PHP` or `nginx`; the list's TECHNOLOGY column. Matching is case-insensitive.\n- `categories`: The technology's categories, such as `Web servers` or `JavaScript libraries`. A technology can have several.\n- `affected_asset_count`: How many of your assets use the technology.\n- `versions`: The versions of the technology found on your assets, such as `1.0.0`; `unknown` when no version was detected. Each version says whether it has known vulnerabilities.\n- `latest_version`: The latest released version of the technology, such as `1.2.3`; `unknown` when it is not known.\n- `vulnerability_stats`: The number of known vulnerabilities of the technology's versions on your assets (`vulnerability_stats.total` in the response); the platform's TOTAL VULN. COUNT.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Technology Detail",
              "id": "1bc20cad-69ae-57f4-8d52-8f6a864f3f27",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/:tech_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    ":tech_id"
                  ],
                  "variable": [
                    {
                      "key": "tech_id",
                      "value": "b8599bb3064608b6aab542232c0680ae",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Technology Detail API**\n\nReturns one technology with its versions and affected assets.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `icon` | string |  |\n| `categories` | array of string |  |\n| `official_website` | string |  |\n| `description` | string |  |\n| `latest_version` | string |  |\n| `vendor` | string |  |\n| `product` | string |  |"
              },
              "response": []
            },
            {
              "name": "Most Vulnerable Technologies",
              "id": "ab59a587-da65-52b3-95ac-21418c3a119c",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/stats/most-vulnerable",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "stats",
                    "most-vulnerable"
                  ]
                },
                "description": "**Deepinfo EASM Most Vulnerable Technologies API**\n\nLists the technologies with the most vulnerabilities.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `technology` | string |  |\n| `favicon` | string |  |\n| `vulnerability_stats` | object |  |"
              },
              "response": []
            },
            {
              "name": "Technology End Of Life Status",
              "id": "e7fc2408-c8af-5dfa-a716-c236a03cfe97",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/eol/:product",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "eol",
                    ":product"
                  ],
                  "variable": [
                    {
                      "key": "product",
                      "value": "nginx",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo EASM Technology End Of Life Status API**\n\nReturns end-of-life information for a product (e.g. `nginx`, `php`).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `product` | string |  |\n| `cycles` | array of object |  |\n| `check_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Technology Vulnerabilities",
              "id": "f0a857b9-e847-51e2-9fb2-84f8f2c40eb2",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/vulnerabilities?tech_id=b8599bb3064608b6aab542232c0680ae",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "vulnerabilities"
                  ],
                  "query": [
                    {
                      "key": "tech_id",
                      "value": "b8599bb3064608b6aab542232c0680ae",
                      "description": "**Required.**"
                    },
                    {
                      "key": "version",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "severity",
                      "value": "",
                      "description": "One of: `critical`, `high`, `medium`, `low`, `none`, `unknown`.",
                      "disabled": true
                    },
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "100",
                      "description": "Min `25`, max `100`. Default `100`.",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo EASM Technology Vulnerabilities API**\n\nLists vulnerabilities of a technology (`tech_id`), optionally for a `version` and `severity`.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].cve_id` | string |  |\n| `results[].cvss_v3_score` | number |  |\n| `results[].cvss_v3_severity` | string | One of `critical`, `high`, `medium`, `low`, `none`, `unknown` |\n| `results[].published_date` | string | date-time |\n| `results[].last_modified_date` | string | date-time |\n| `results[].description` | string |  |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Technology Asset Stats",
              "id": "c3db90d3-4bfa-5184-adb7-7e1626cf9894",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/stats/assets",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "stats",
                    "assets"
                  ]
                },
                "description": "**Deepinfo EASM Technology Asset Stats API**\n\nCounts assets per technology.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `by_technology` | array of object |  |"
              },
              "response": []
            },
            {
              "name": "Technology Category Stats",
              "id": "7def117a-032f-5a96-a8ef-0cb952a23b28",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/stats/category",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "stats",
                    "category"
                  ],
                  "query": [
                    {
                      "key": "asset",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo EASM Technology Category Stats API**\n\nCounts technologies per category.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `total` | integer |  |\n| `by_category` | array of object |  |"
              },
              "response": []
            },
            {
              "name": "Technology Count Timeline",
              "id": "14b82c41-6610-51a9-b96e-7242b23b3521",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/stats/count-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "stats",
                    "count-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ]
                },
                "description": "**Deepinfo EASM Technology Count Timeline API**\n\nTime series of count for the selected `interval` (`daily`, `weekly`, `monthly`).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Technology Vulnerability Stats",
              "id": "9d313a18-c9e2-5cba-8aac-2ee840dfbd58",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/easm/technologies/stats/vulnerability",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "easm",
                    "technologies",
                    "stats",
                    "vulnerability"
                  ],
                  "query": [
                    {
                      "key": "tech_id",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "version",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo EASM Technology Vulnerability Stats API**\n\nVulnerability statistics for technologies (filter by `tech_id`, `version`).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `total` | integer |  |\n| `by_severity` | object |  |"
              },
              "response": []
            }
          ]
        }
      ]
    },
    {
      "name": "CTI",
      "id": "3970a3ec-0863-5e2c-a938-45d51f1c020b",
      "description": "Cyber Threat Intelligence: email breaches, compromised employee/client/payment credentials, compromised devices, threat actors and security news relevant to your organization.",
      "item": [
        {
          "name": "Email Breaches",
          "id": "ea457ae5-ffd1-5ac1-bdef-3ec79711b5f4",
          "description": "Public data breaches that include email addresses on your domains.",
          "item": [
            {
              "name": "Breached Account List",
              "id": "5f8df28a-8252-557a-a22d-49bc3e4f5d58",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/accounts?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "accounts"
                  ],
                  "query": [
                    {
                      "key": "ordering",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    },
                    {
                      "key": "email__contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "email__not_contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "domain__contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "domain__not_contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "vip",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "first_name__contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "first_name__not_contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "last_name__contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "last_name__not_contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "title__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "title__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "first_breach_date__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "first_breach_date__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "last_breach_date__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "last_breach_date__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "last_added_date__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "last_added_date__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breach",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breach__contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breach__not_contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breach_count__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breach_count__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "data_types__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "data_types__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo CTI Breached Account List API**\n\nLists your breached email accounts. Filter and sort with the optional query parameters.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].email` | string |  |\n| `results[].domain` | string |  |\n| `results[].vip` | boolean |  |\n| `results[].first_name` | string |  |\n| `results[].last_name` | string |  |\n| `results[].title` | string |  |\n| `results[].linkedin_url` | string |  |\n| `results[].first_breach_date` | string | date-time |\n| `results[].last_breach_date` | string | date-time |\n| `results[].last_added_date` | string | date-time |\n| `results[].breaches` | array of object |  |\n| `results[].breach_count` | integer |  |\n| `results[].data_types` | array of string |  |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Email Breach List",
              "id": "f0ba6c40-5a61-52ab-b68f-f60673c66d34",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/breaches?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "breaches"
                  ],
                  "query": [
                    {
                      "key": "ordering",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    },
                    {
                      "key": "title__contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "title__not_contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "domain__contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "domain__not_contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breach_date__lt",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breach_date__gt",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "added_date__lt",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "added_date__gt",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "total_breached_account_count__lt",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "total_breached_account_count__gt",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "data_types__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "data_types__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "is_verified",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "is_fabricated",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "is_sensitive",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "is_retired",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "is_spam_list",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "is_malware",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breached_account",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breached_account__contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breached_account__not_contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breached_account_count__lt",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "breached_account_count__gt",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo CTI Email Breach List API**\n\nLists breaches that include your email addresses. Filter and sort with the optional query parameters.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].name` | string |  |\n| `results[].title` | string |  |\n| `results[].domain` | string |  |\n| `results[].breach_date` | string | date-time |\n| `results[].added_date` | string | date-time |\n| `results[].modified_date` | string | date-time |\n| `results[].total_breached_account_count` | integer |  |\n| `results[].logo_path` | string |  |\n| `results[].data_types` | array of string |  |\n| `results[].is_verified` | boolean |  |\n| `results[].is_fabricated` | boolean |  |\n| `results[].is_sensitive` | boolean |  |\n| `results[].is_retired` | boolean |  |\n| `results[].is_spam_list` | boolean |  |\n| `results[].is_malware` | boolean |  |\n| `results[].is_subscription_free` | boolean |  |\n| `results[].breached_account_count` | integer |  |\n| `results[].breached_domains` | array of object |  |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Breached Account Detail",
              "id": "5100c933-1c93-50b8-8a02-c0bee5b73e55",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/accounts/:account_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "accounts",
                    ":account_id"
                  ],
                  "variable": [
                    {
                      "key": "account_id",
                      "value": "db30bd9dd9ed329b192e5e631fa86ae9",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo CTI Breached Account Detail API**\n\nReturns one breached account and its breaches.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `email` | string |  |\n| `vip` | boolean |  |\n| `first_name` | string |  |\n| `last_name` | string |  |\n| `title` | string |  |\n| `linkedin_url` | string |  |"
              },
              "response": []
            },
            {
              "name": "Email Breach Detail",
              "id": "2bcce1a9-1a63-52a4-a993-cc91d862904e",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/breaches/:breach_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "breaches",
                    ":breach_id"
                  ],
                  "variable": [
                    {
                      "key": "breach_id",
                      "value": "Baydoner",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo CTI Email Breach Detail API**\n\nReturns one breach: date, description, data types and affected accounts count.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `title` | string |  |\n| `domain` | string |  |\n| `breach_date` | string | date-time |\n| `added_date` | string | date-time |\n| `modified_date` | string | date-time |\n| `total_breached_account_count` | integer |  |\n| `description` | string |  |\n| `logo_path` | string |  |\n| `data_types` | array of string |  |\n| `is_verified` | boolean |  |\n| `is_fabricated` | boolean |  |\n| `is_sensitive` | boolean |  |\n| `is_retired` | boolean |  |\n| `is_spam_list` | boolean |  |\n| `is_malware` | boolean |  |\n| `is_subscription_free` | boolean |  |"
              },
              "response": []
            },
            {
              "name": "Email Breach Account Titles",
              "id": "fe482968-64dd-5983-9927-47712b8ce52e",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/account-titles",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "account-titles"
                  ]
                },
                "description": "**Deepinfo CTI Email Breach Account Titles API**\n\nLists the job titles set on breached accounts."
              },
              "response": []
            },
            {
              "name": "Email Breach Data Types",
              "id": "4a367ec1-71ca-56eb-b9e6-a308ca5f9099",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/data-types",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "data-types"
                  ]
                },
                "description": "**Deepinfo CTI Email Breach Data Types API**\n\nLists every data type (kind of exposed data) found in breaches."
              },
              "response": []
            },
            {
              "name": "Latest Email Breaches",
              "id": "4668111e-af41-5299-89ad-775ecbe5ba9b",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/breaches/latest",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "breaches",
                    "latest"
                  ]
                },
                "description": "**Deepinfo CTI Latest Email Breaches API**\n\nLists the most recent breaches affecting you.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `title` | string |  |\n| `domain` | string |  |\n| `breach_date` | string | date-time |\n| `added_date` | string | date-time |\n| `modified_date` | string | date-time |\n| `total_breached_account_count` | integer |  |\n| `description` | string |  |\n| `logo_path` | string |  |\n| `data_types` | array of string |  |\n| `is_verified` | boolean |  |\n| `is_fabricated` | boolean |  |\n| `is_sensitive` | boolean |  |\n| `is_retired` | boolean |  |\n| `is_spam_list` | boolean |  |\n| `is_malware` | boolean |  |\n| `is_subscription_free` | boolean |  |"
              },
              "response": []
            },
            {
              "name": "Breached Account Stats",
              "id": "2d9c0f47-de7e-5fc1-bb3d-58db34a80c08",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/accounts/:account_id/stats",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "accounts",
                    ":account_id",
                    "stats"
                  ],
                  "variable": [
                    {
                      "key": "account_id",
                      "value": "db30bd9dd9ed329b192e5e631fa86ae9",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo CTI Breached Account Stats API**\n\nBreach statistics for one account.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `breach_count` | integer |  |\n| `first_breach_date` | string | date-time |\n| `last_breach_date` | string | date-time |\n| `data_types` | array of string |  |\n| `timeline` | array of object |  |"
              },
              "response": []
            },
            {
              "name": "Breached Accounts Domain Stats",
              "id": "894d71e0-d3b0-538e-8f4e-fe0130637824",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/accounts/stats/domain",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "accounts",
                    "stats",
                    "domain"
                  ]
                },
                "description": "**Deepinfo CTI Breached Accounts Domain Stats API**\n\nBreached account counts per domain.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `domain` | string |  |\n| `affected_account_count` | integer |  |\n| `breach_count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Email Breach Stats",
              "id": "f766505c-3834-5e24-86a2-d7334b0c4e3d",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/breaches/stats",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "breaches",
                    "stats"
                  ]
                },
                "description": "**Deepinfo CTI Email Breach Stats API**\n\nBreach statistics.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `breach_count` | integer |  |\n| `breached_account_count` | integer |  |\n| `last_breach_date` | string | date-time |\n| `data_type_stats` | array of object |  |\n| `timeline` | array of object |  |"
              },
              "response": []
            },
            {
              "name": "Breached Account Update",
              "id": "507880c4-28db-5dd7-9074-373d2a162a94",
              "request": {
                "method": "PUT",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/email-breaches/accounts/:account_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "email-breaches",
                    "accounts",
                    ":account_id"
                  ],
                  "variable": [
                    {
                      "key": "account_id",
                      "value": "db30bd9dd9ed329b192e5e631fa86ae9",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo CTI Breached Account Update API**\n\nUpdates a breached account's profile with the fields in the request body.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `vip` | boolean | yes |  |\n| `first_name` | string |  | max length `100` |\n| `last_name` | string |  | max length `100` |\n| `title` | string |  | max length `100` |\n| `linkedin_url` | string |  | min length `1`; max length `2083` |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `email` | string |  |\n| `vip` | boolean |  |\n| `first_name` | string |  |\n| `last_name` | string |  |\n| `title` | string |  |\n| `linkedin_url` | string |  |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"vip\": false,\n  \"first_name\": null,\n  \"last_name\": null,\n  \"title\": null,\n  \"linkedin_url\": null\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            }
          ]
        },
        {
          "name": "Compromised Employee Accounts",
          "id": "1272f53f-a322-5b28-98ee-3e4e9bb89e27",
          "description": "Employee accounts found in leaked credential data.",
          "item": [
            {
              "name": "Compromised Employee Account Search",
              "id": "4c740e6d-50ce-52c9-850c-9f4615e7ef9e",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-accounts/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-accounts",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Account Search API**\n\nSearches employee accounts found in leaked credentials.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 34 fields\n\n- `security_profile.exposure.first_exposure_date`: When the employee's earliest leaked credential was added, shown as FIRST SEEN in the security profile (UTC date-time).\n- `security_profile.exposure.last_exposure_date`: When the employee's most recent leaked credential was added, shown as LAST EXPOSURE in the list and LAST SEEN in the security profile (UTC date-time). The list is sorted by it, newest first.\n- `security_profile.exposure.exposure_span_days`: The number of days between the first and the last exposure date (EXPOSURE SPAN); `0` when all of the employee's credentials were added on the same day.\n- `security_profile.password_behavior.unique_password_count`: The number of different passwords among the employee's leaked credentials, shown as UNIQUE PASSWORDS and in the PASSWORDS column.\n- `security_profile.password_behavior.avg_password_length`: The average length, in characters, of the passwords in the employee's leaked credentials (AVG LENGTH).\n- `security_profile.password_behavior.avg_strength_score`: The average password strength score of the employee's leaked credentials, on the 0 to 100 scale of `password_analysis.strength.score`. The platform shows it divided by 10, as AVG STRENGTH SCORE out of 10.\n- `security_profile.password_behavior.min_strength_score`: The lowest password strength score among the employee's leaked credentials, from 0 to 100 (the first number of MIN / MAX SCORE).\n- `security_profile.password_behavior.max_strength_score`: The highest password strength score among the employee's leaked credentials, from 0 to 100 (the second number of MIN / MAX SCORE).\n- `security_profile.password_behavior.strength_distribution.very_weak`: The number of the employee's leaked credentials whose password is rated `Very Weak`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.weak`: The number of the employee's leaked credentials whose password is rated `Weak`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.medium`: The number of the employee's leaked credentials whose password is rated `Medium`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.strong`: The number of the employee's leaked credentials whose password is rated `Strong`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.very_strong`: The number of the employee's leaked credentials whose password is rated `Very Strong`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.weak_password_percentage`: The share of the employee's leaked credentials whose password is rated `Very Weak` or `Weak`, as a percentage from 0 to 100 (WEAK PASSWORDS).\n- `security_profile.reuse_analysis.password_reuse_count`: The number of the employee's passwords that appear in more than one leaked credential (REUSED PASSWORDS).\n- `security_profile.reuse_analysis.password_reuse_percentage`: The share of the employee's different passwords that appear in more than one leaked credential, as a percentage from 0 to 100 (REUSE RATE and the REUSE column).\n- `security_profile.composition.common_password_count`: The number of the employee's leaked credentials whose password is a known common password (`password_analysis.dictionary_match.is_common_password`), shown as COMMON PASSWORDS.\n- `security_profile.composition.dictionary_word_count`: The number of the employee's leaked credentials whose password is a dictionary word (`password_analysis.dictionary_match.is_dictionary_word`), shown as DICTIONARY WORDS.\n- `security_profile.composition.keyboard_pattern_count`: The number of the employee's leaked credentials whose password contains a keyboard pattern (`password_analysis.patterns.has_keyboard_pattern`), shown as KEYBOARD PATTERNS.\n- `security_profile.composition.date_pattern_count`: The number of the employee's leaked credentials whose password contains a date pattern (`password_analysis.patterns.has_date_pattern`), shown as DATE PATTERNS.\n- `security_profile.composition.avg_character_classes`: The average number of character types (uppercase letters, lowercase letters, digits, special characters) per password across the employee's leaked credentials, from 1 to 4 (AVG CHAR CLASSES).\n- `security_profile.composition.all_four_classes_percentage`: The share of the employee's leaked credentials whose password uses all four character types, as a percentage from 0 to 100 (ALL CHAR CLASSES).\n- `security_profile.composition.structure_variety_count`: The number of different password structures among the employee's leaked credentials (STRUCTURE VARIETY).\n- `security_profile.temporal.days_since_last_exposure`: The number of days since the employee's last exposure (`security_profile.exposure.last_exposure_date`), shown as DAYS SINCE LAST.\n- `security_profile.temporal.exposure_velocity`: How often new leaked credentials of the account appear, in credentials per month (VELOCITY, shown as cred/mo).\n- `state_stats.total`: The number of the employee's leaked credentials, in any state (Total Credentials in the STATE filter group).\n- `state_stats.active_count`: The number of the employee's credentials in an active state, `newly_detected` or `unresolved` (Active Credential Count).\n- `state_stats.inactive_count`: The number of the employee's credentials in an inactive state, such as ignored, risk accepted or marked as resolved (Inactive Credential Count).\n- `state_stats.unresolved_count`: The number of the employee's credentials that are unresolved (Unresolved Credential Count).\n- `state_stats.resolved_count`: The number of the employee's credentials that are resolved (Resolved Credential Count).\n- `state_stats.risk_accepted_count`: The number of the employee's credentials in the `risk_accepted` state (Risk Accepted Credential Count).\n- `state_stats.ignored_count`: The number of the employee's credentials in the `ignored` state (Ignored Credential Count).\n- `state_stats.false_positive_count`: The number of the employee's credentials in the `marked_as_false_positive` state (False Positive Credential Count).\n- `risk_score`: The employee account's numeric risk score, which goes with its `risk_level`; a higher score means a higher risk.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 8 fields\n\n- `email`: The employee's e-mail address that was found in leaked credential data. It identifies the account and cannot be edited.\n- `domain`: The domain of the employee's e-mail address, one of your organization's domains; the list has one tab per domain.\n- `first_name`: The employee's first name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `last_name`: The employee's last name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `title`: The employee's job title (CURRENT TITLE when you edit it), when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `linkedin_url`: The address of the employee's LinkedIn profile, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `department`: The employee's department, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `security_profile.composition.dominant_structure`: The most common password structure among the employee's leaked credentials, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character. It shows the passwords' shape while they are masked, so treat it as sensitive.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_executive`: Whether the employee is marked as an executive; executives show a VIP icon. You set it with EDIT DETAILS or the Compromised Employee Account Update endpoint.\n- `security_profile.temporal.exposure_accelerating`: Whether new exposures of the account are becoming more frequent; the TREND figure shows `true` as ACCELERATING and `false` as STABLE.\n\n**`eq`, `in`, `exists`** — 2 fields\n\n- `computed_state`: The employee account's computed state (State in the STATE filter group). It takes the same values as a credential's `state`, such as `newly_detected` or `unresolved`.\n- `risk_level`: The employee's priority level: `low`, `medium`, `high` or `critical`. The platform describes it as a composite priority based on credential, role and recency.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The employee account's unique ID, a 24-character hex string. Exposed credentials refer to it as `account.id`.\n\nSortable fields:\n\n- `id`: The employee account's unique ID, a 24-character hex string. Exposed credentials refer to it as `account.id`.\n- `email`: The employee's e-mail address that was found in leaked credential data. It identifies the account and cannot be edited.\n- `domain`: The domain of the employee's e-mail address, one of your organization's domains; the list has one tab per domain.\n- `is_executive`: Whether the employee is marked as an executive; executives show a VIP icon. You set it with EDIT DETAILS or the Compromised Employee Account Update endpoint.\n- `first_name`: The employee's first name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `last_name`: The employee's last name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `title`: The employee's job title (CURRENT TITLE when you edit it), when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `linkedin_url`: The address of the employee's LinkedIn profile, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `department`: The employee's department, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `security_profile.exposure.first_exposure_date`: When the employee's earliest leaked credential was added, shown as FIRST SEEN in the security profile (UTC date-time).\n- `security_profile.exposure.last_exposure_date`: When the employee's most recent leaked credential was added, shown as LAST EXPOSURE in the list and LAST SEEN in the security profile (UTC date-time). The list is sorted by it, newest first.\n- `security_profile.exposure.exposure_span_days`: The number of days between the first and the last exposure date (EXPOSURE SPAN); `0` when all of the employee's credentials were added on the same day.\n- `security_profile.password_behavior.unique_password_count`: The number of different passwords among the employee's leaked credentials, shown as UNIQUE PASSWORDS and in the PASSWORDS column.\n- `security_profile.password_behavior.avg_password_length`: The average length, in characters, of the passwords in the employee's leaked credentials (AVG LENGTH).\n- `security_profile.password_behavior.avg_strength_score`: The average password strength score of the employee's leaked credentials, on the 0 to 100 scale of `password_analysis.strength.score`. The platform shows it divided by 10, as AVG STRENGTH SCORE out of 10.\n- `security_profile.password_behavior.min_strength_score`: The lowest password strength score among the employee's leaked credentials, from 0 to 100 (the first number of MIN / MAX SCORE).\n- `security_profile.password_behavior.max_strength_score`: The highest password strength score among the employee's leaked credentials, from 0 to 100 (the second number of MIN / MAX SCORE).\n- `security_profile.password_behavior.strength_distribution.very_weak`: The number of the employee's leaked credentials whose password is rated `Very Weak`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.weak`: The number of the employee's leaked credentials whose password is rated `Weak`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.medium`: The number of the employee's leaked credentials whose password is rated `Medium`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.strong`: The number of the employee's leaked credentials whose password is rated `Strong`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.very_strong`: The number of the employee's leaked credentials whose password is rated `Very Strong`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.weak_password_percentage`: The share of the employee's leaked credentials whose password is rated `Very Weak` or `Weak`, as a percentage from 0 to 100 (WEAK PASSWORDS).\n- `security_profile.reuse_analysis.password_reuse_count`: The number of the employee's passwords that appear in more than one leaked credential (REUSED PASSWORDS).\n- `security_profile.reuse_analysis.password_reuse_percentage`: The share of the employee's different passwords that appear in more than one leaked credential, as a percentage from 0 to 100 (REUSE RATE and the REUSE column).\n- `security_profile.composition.common_password_count`: The number of the employee's leaked credentials whose password is a known common password (`password_analysis.dictionary_match.is_common_password`), shown as COMMON PASSWORDS.\n- `security_profile.composition.dictionary_word_count`: The number of the employee's leaked credentials whose password is a dictionary word (`password_analysis.dictionary_match.is_dictionary_word`), shown as DICTIONARY WORDS.\n- `security_profile.composition.keyboard_pattern_count`: The number of the employee's leaked credentials whose password contains a keyboard pattern (`password_analysis.patterns.has_keyboard_pattern`), shown as KEYBOARD PATTERNS.\n- `security_profile.composition.date_pattern_count`: The number of the employee's leaked credentials whose password contains a date pattern (`password_analysis.patterns.has_date_pattern`), shown as DATE PATTERNS.\n- `security_profile.composition.avg_character_classes`: The average number of character types (uppercase letters, lowercase letters, digits, special characters) per password across the employee's leaked credentials, from 1 to 4 (AVG CHAR CLASSES).\n- `security_profile.composition.all_four_classes_percentage`: The share of the employee's leaked credentials whose password uses all four character types, as a percentage from 0 to 100 (ALL CHAR CLASSES).\n- `security_profile.composition.dominant_structure`: The most common password structure among the employee's leaked credentials, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character. It shows the passwords' shape while they are masked, so treat it as sensitive.\n- `security_profile.composition.structure_variety_count`: The number of different password structures among the employee's leaked credentials (STRUCTURE VARIETY).\n- `security_profile.temporal.days_since_last_exposure`: The number of days since the employee's last exposure (`security_profile.exposure.last_exposure_date`), shown as DAYS SINCE LAST.\n- `security_profile.temporal.exposure_accelerating`: Whether new exposures of the account are becoming more frequent; the TREND figure shows `true` as ACCELERATING and `false` as STABLE.\n- `security_profile.temporal.exposure_velocity`: How often new leaked credentials of the account appear, in credentials per month (VELOCITY, shown as cred/mo).\n- `computed_state`: The employee account's computed state (State in the STATE filter group). It takes the same values as a credential's `state`, such as `newly_detected` or `unresolved`.\n- `state_stats.total`: The number of the employee's leaked credentials, in any state (Total Credentials in the STATE filter group).\n- `state_stats.active_count`: The number of the employee's credentials in an active state, `newly_detected` or `unresolved` (Active Credential Count).\n- `state_stats.inactive_count`: The number of the employee's credentials in an inactive state, such as ignored, risk accepted or marked as resolved (Inactive Credential Count).\n- `state_stats.unresolved_count`: The number of the employee's credentials that are unresolved (Unresolved Credential Count).\n- `state_stats.resolved_count`: The number of the employee's credentials that are resolved (Resolved Credential Count).\n- `state_stats.risk_accepted_count`: The number of the employee's credentials in the `risk_accepted` state (Risk Accepted Credential Count).\n- `state_stats.ignored_count`: The number of the employee's credentials in the `ignored` state (Ignored Credential Count).\n- `state_stats.false_positive_count`: The number of the employee's credentials in the `marked_as_false_positive` state (False Positive Credential Count).\n- `risk_score`: The employee account's numeric risk score, which goes with its `risk_level`; a higher score means a higher risk.\n- `risk_level`: The employee's priority level: `low`, `medium`, `high` or `critical`. The platform describes it as a composite priority based on credential, role and recency.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].email` | string |  |\n| `results[].domain` | string |  |\n| `results[].is_executive` | boolean |  |\n| `results[].first_name` | string |  |\n| `results[].last_name` | string |  |\n| `results[].title` | string |  |\n| `results[].linkedin_url` | string |  |\n| `results[].department` | string |  |\n| `results[].security_profile` | object |  |\n| `results[].computed_state` | string | One of `newly_detected`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |\n| `results[].state_stats` | object |  |\n| `results[].risk_score` | integer |  |\n| `results[].risk_level` | string | One of `low`, `medium`, `high`, `critical` |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Employee Account Export",
              "id": "c4142257-46bf-53da-bc05-648306b51c96",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-accounts/search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-accounts",
                    "search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Account Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 34 fields\n\n- `security_profile.exposure.first_exposure_date`: When the employee's earliest leaked credential was added, shown as FIRST SEEN in the security profile (UTC date-time).\n- `security_profile.exposure.last_exposure_date`: When the employee's most recent leaked credential was added, shown as LAST EXPOSURE in the list and LAST SEEN in the security profile (UTC date-time). The list is sorted by it, newest first.\n- `security_profile.exposure.exposure_span_days`: The number of days between the first and the last exposure date (EXPOSURE SPAN); `0` when all of the employee's credentials were added on the same day.\n- `security_profile.password_behavior.unique_password_count`: The number of different passwords among the employee's leaked credentials, shown as UNIQUE PASSWORDS and in the PASSWORDS column.\n- `security_profile.password_behavior.avg_password_length`: The average length, in characters, of the passwords in the employee's leaked credentials (AVG LENGTH).\n- `security_profile.password_behavior.avg_strength_score`: The average password strength score of the employee's leaked credentials, on the 0 to 100 scale of `password_analysis.strength.score`. The platform shows it divided by 10, as AVG STRENGTH SCORE out of 10.\n- `security_profile.password_behavior.min_strength_score`: The lowest password strength score among the employee's leaked credentials, from 0 to 100 (the first number of MIN / MAX SCORE).\n- `security_profile.password_behavior.max_strength_score`: The highest password strength score among the employee's leaked credentials, from 0 to 100 (the second number of MIN / MAX SCORE).\n- `security_profile.password_behavior.strength_distribution.very_weak`: The number of the employee's leaked credentials whose password is rated `Very Weak`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.weak`: The number of the employee's leaked credentials whose password is rated `Weak`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.medium`: The number of the employee's leaked credentials whose password is rated `Medium`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.strong`: The number of the employee's leaked credentials whose password is rated `Strong`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.very_strong`: The number of the employee's leaked credentials whose password is rated `Very Strong`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.weak_password_percentage`: The share of the employee's leaked credentials whose password is rated `Very Weak` or `Weak`, as a percentage from 0 to 100 (WEAK PASSWORDS).\n- `security_profile.reuse_analysis.password_reuse_count`: The number of the employee's passwords that appear in more than one leaked credential (REUSED PASSWORDS).\n- `security_profile.reuse_analysis.password_reuse_percentage`: The share of the employee's different passwords that appear in more than one leaked credential, as a percentage from 0 to 100 (REUSE RATE and the REUSE column).\n- `security_profile.composition.common_password_count`: The number of the employee's leaked credentials whose password is a known common password (`password_analysis.dictionary_match.is_common_password`), shown as COMMON PASSWORDS.\n- `security_profile.composition.dictionary_word_count`: The number of the employee's leaked credentials whose password is a dictionary word (`password_analysis.dictionary_match.is_dictionary_word`), shown as DICTIONARY WORDS.\n- `security_profile.composition.keyboard_pattern_count`: The number of the employee's leaked credentials whose password contains a keyboard pattern (`password_analysis.patterns.has_keyboard_pattern`), shown as KEYBOARD PATTERNS.\n- `security_profile.composition.date_pattern_count`: The number of the employee's leaked credentials whose password contains a date pattern (`password_analysis.patterns.has_date_pattern`), shown as DATE PATTERNS.\n- `security_profile.composition.avg_character_classes`: The average number of character types (uppercase letters, lowercase letters, digits, special characters) per password across the employee's leaked credentials, from 1 to 4 (AVG CHAR CLASSES).\n- `security_profile.composition.all_four_classes_percentage`: The share of the employee's leaked credentials whose password uses all four character types, as a percentage from 0 to 100 (ALL CHAR CLASSES).\n- `security_profile.composition.structure_variety_count`: The number of different password structures among the employee's leaked credentials (STRUCTURE VARIETY).\n- `security_profile.temporal.days_since_last_exposure`: The number of days since the employee's last exposure (`security_profile.exposure.last_exposure_date`), shown as DAYS SINCE LAST.\n- `security_profile.temporal.exposure_velocity`: How often new leaked credentials of the account appear, in credentials per month (VELOCITY, shown as cred/mo).\n- `state_stats.total`: The number of the employee's leaked credentials, in any state (Total Credentials in the STATE filter group).\n- `state_stats.active_count`: The number of the employee's credentials in an active state, `newly_detected` or `unresolved` (Active Credential Count).\n- `state_stats.inactive_count`: The number of the employee's credentials in an inactive state, such as ignored, risk accepted or marked as resolved (Inactive Credential Count).\n- `state_stats.unresolved_count`: The number of the employee's credentials that are unresolved (Unresolved Credential Count).\n- `state_stats.resolved_count`: The number of the employee's credentials that are resolved (Resolved Credential Count).\n- `state_stats.risk_accepted_count`: The number of the employee's credentials in the `risk_accepted` state (Risk Accepted Credential Count).\n- `state_stats.ignored_count`: The number of the employee's credentials in the `ignored` state (Ignored Credential Count).\n- `state_stats.false_positive_count`: The number of the employee's credentials in the `marked_as_false_positive` state (False Positive Credential Count).\n- `risk_score`: The employee account's numeric risk score, which goes with its `risk_level`; a higher score means a higher risk.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 8 fields\n\n- `email`: The employee's e-mail address that was found in leaked credential data. It identifies the account and cannot be edited.\n- `domain`: The domain of the employee's e-mail address, one of your organization's domains; the list has one tab per domain.\n- `first_name`: The employee's first name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `last_name`: The employee's last name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `title`: The employee's job title (CURRENT TITLE when you edit it), when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `linkedin_url`: The address of the employee's LinkedIn profile, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `department`: The employee's department, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `security_profile.composition.dominant_structure`: The most common password structure among the employee's leaked credentials, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character. It shows the passwords' shape while they are masked, so treat it as sensitive.\n\n**`eq`, `exists`** — 2 fields\n\n- `is_executive`: Whether the employee is marked as an executive; executives show a VIP icon. You set it with EDIT DETAILS or the Compromised Employee Account Update endpoint.\n- `security_profile.temporal.exposure_accelerating`: Whether new exposures of the account are becoming more frequent; the TREND figure shows `true` as ACCELERATING and `false` as STABLE.\n\n**`eq`, `in`, `exists`** — 2 fields\n\n- `computed_state`: The employee account's computed state (State in the STATE filter group). It takes the same values as a credential's `state`, such as `newly_detected` or `unresolved`.\n- `risk_level`: The employee's priority level: `low`, `medium`, `high` or `critical`. The platform describes it as a composite priority based on credential, role and recency.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The employee account's unique ID, a 24-character hex string. Exposed credentials refer to it as `account.id`.\n\nSortable fields:\n\n- `id`: The employee account's unique ID, a 24-character hex string. Exposed credentials refer to it as `account.id`.\n- `email`: The employee's e-mail address that was found in leaked credential data. It identifies the account and cannot be edited.\n- `domain`: The domain of the employee's e-mail address, one of your organization's domains; the list has one tab per domain.\n- `is_executive`: Whether the employee is marked as an executive; executives show a VIP icon. You set it with EDIT DETAILS or the Compromised Employee Account Update endpoint.\n- `first_name`: The employee's first name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `last_name`: The employee's last name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `title`: The employee's job title (CURRENT TITLE when you edit it), when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `linkedin_url`: The address of the employee's LinkedIn profile, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `department`: The employee's department, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint.\n- `security_profile.exposure.first_exposure_date`: When the employee's earliest leaked credential was added, shown as FIRST SEEN in the security profile (UTC date-time).\n- `security_profile.exposure.last_exposure_date`: When the employee's most recent leaked credential was added, shown as LAST EXPOSURE in the list and LAST SEEN in the security profile (UTC date-time). The list is sorted by it, newest first.\n- `security_profile.exposure.exposure_span_days`: The number of days between the first and the last exposure date (EXPOSURE SPAN); `0` when all of the employee's credentials were added on the same day.\n- `security_profile.password_behavior.unique_password_count`: The number of different passwords among the employee's leaked credentials, shown as UNIQUE PASSWORDS and in the PASSWORDS column.\n- `security_profile.password_behavior.avg_password_length`: The average length, in characters, of the passwords in the employee's leaked credentials (AVG LENGTH).\n- `security_profile.password_behavior.avg_strength_score`: The average password strength score of the employee's leaked credentials, on the 0 to 100 scale of `password_analysis.strength.score`. The platform shows it divided by 10, as AVG STRENGTH SCORE out of 10.\n- `security_profile.password_behavior.min_strength_score`: The lowest password strength score among the employee's leaked credentials, from 0 to 100 (the first number of MIN / MAX SCORE).\n- `security_profile.password_behavior.max_strength_score`: The highest password strength score among the employee's leaked credentials, from 0 to 100 (the second number of MIN / MAX SCORE).\n- `security_profile.password_behavior.strength_distribution.very_weak`: The number of the employee's leaked credentials whose password is rated `Very Weak`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.weak`: The number of the employee's leaked credentials whose password is rated `Weak`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.medium`: The number of the employee's leaked credentials whose password is rated `Medium`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.strong`: The number of the employee's leaked credentials whose password is rated `Strong`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.strength_distribution.very_strong`: The number of the employee's leaked credentials whose password is rated `Very Strong`. Credentials are counted, so a reused password counts once for each credential.\n- `security_profile.password_behavior.weak_password_percentage`: The share of the employee's leaked credentials whose password is rated `Very Weak` or `Weak`, as a percentage from 0 to 100 (WEAK PASSWORDS).\n- `security_profile.reuse_analysis.password_reuse_count`: The number of the employee's passwords that appear in more than one leaked credential (REUSED PASSWORDS).\n- `security_profile.reuse_analysis.password_reuse_percentage`: The share of the employee's different passwords that appear in more than one leaked credential, as a percentage from 0 to 100 (REUSE RATE and the REUSE column).\n- `security_profile.composition.common_password_count`: The number of the employee's leaked credentials whose password is a known common password (`password_analysis.dictionary_match.is_common_password`), shown as COMMON PASSWORDS.\n- `security_profile.composition.dictionary_word_count`: The number of the employee's leaked credentials whose password is a dictionary word (`password_analysis.dictionary_match.is_dictionary_word`), shown as DICTIONARY WORDS.\n- `security_profile.composition.keyboard_pattern_count`: The number of the employee's leaked credentials whose password contains a keyboard pattern (`password_analysis.patterns.has_keyboard_pattern`), shown as KEYBOARD PATTERNS.\n- `security_profile.composition.date_pattern_count`: The number of the employee's leaked credentials whose password contains a date pattern (`password_analysis.patterns.has_date_pattern`), shown as DATE PATTERNS.\n- `security_profile.composition.avg_character_classes`: The average number of character types (uppercase letters, lowercase letters, digits, special characters) per password across the employee's leaked credentials, from 1 to 4 (AVG CHAR CLASSES).\n- `security_profile.composition.all_four_classes_percentage`: The share of the employee's leaked credentials whose password uses all four character types, as a percentage from 0 to 100 (ALL CHAR CLASSES).\n- `security_profile.composition.dominant_structure`: The most common password structure among the employee's leaked credentials, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character. It shows the passwords' shape while they are masked, so treat it as sensitive.\n- `security_profile.composition.structure_variety_count`: The number of different password structures among the employee's leaked credentials (STRUCTURE VARIETY).\n- `security_profile.temporal.days_since_last_exposure`: The number of days since the employee's last exposure (`security_profile.exposure.last_exposure_date`), shown as DAYS SINCE LAST.\n- `security_profile.temporal.exposure_accelerating`: Whether new exposures of the account are becoming more frequent; the TREND figure shows `true` as ACCELERATING and `false` as STABLE.\n- `security_profile.temporal.exposure_velocity`: How often new leaked credentials of the account appear, in credentials per month (VELOCITY, shown as cred/mo).\n- `computed_state`: The employee account's computed state (State in the STATE filter group). It takes the same values as a credential's `state`, such as `newly_detected` or `unresolved`.\n- `state_stats.total`: The number of the employee's leaked credentials, in any state (Total Credentials in the STATE filter group).\n- `state_stats.active_count`: The number of the employee's credentials in an active state, `newly_detected` or `unresolved` (Active Credential Count).\n- `state_stats.inactive_count`: The number of the employee's credentials in an inactive state, such as ignored, risk accepted or marked as resolved (Inactive Credential Count).\n- `state_stats.unresolved_count`: The number of the employee's credentials that are unresolved (Unresolved Credential Count).\n- `state_stats.resolved_count`: The number of the employee's credentials that are resolved (Resolved Credential Count).\n- `state_stats.risk_accepted_count`: The number of the employee's credentials in the `risk_accepted` state (Risk Accepted Credential Count).\n- `state_stats.ignored_count`: The number of the employee's credentials in the `ignored` state (Ignored Credential Count).\n- `state_stats.false_positive_count`: The number of the employee's credentials in the `marked_as_false_positive` state (False Positive Credential Count).\n- `risk_score`: The employee account's numeric risk score, which goes with its `risk_level`; a higher score means a higher risk.\n- `risk_level`: The employee's priority level: `low`, `medium`, `high` or `critical`. The platform describes it as a composite priority based on credential, role and recency.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Employee Account Detail",
              "id": "3bc2dd38-a424-5d88-9c96-ad3650745788",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-accounts/:account_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-accounts",
                    ":account_id"
                  ],
                  "variable": [
                    {
                      "key": "account_id",
                      "value": "6a8f0ffa817b7e829283ce4a",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Account Detail API**\n\nReturns one compromised employee account.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `email` | string |  |\n| `domain` | string |  |\n| `is_executive` | boolean |  |\n| `first_name` | string |  |\n| `last_name` | string |  |\n| `title` | string |  |\n| `linkedin_url` | string |  |\n| `department` | string |  |\n| `security_profile` | object |  |\n| `computed_state` | string | One of `newly_detected`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |\n| `state_stats` | object |  |\n| `risk_score` | integer |  |\n| `risk_level` | string | One of `low`, `medium`, `high`, `critical` |"
              },
              "response": []
            },
            {
              "name": "Compromised Employee Account Risk Distribution Stats",
              "id": "dea27c4a-6f56-553e-b0fb-58f978dbc6f0",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-accounts/stats/risk-distribution",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-accounts",
                    "stats",
                    "risk-distribution"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Account Risk Distribution Stats API**\n\nDistribution of compromised employee accounts by risk.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `critical` | integer |  |\n| `high` | integer |  |\n| `medium` | integer |  |\n| `low` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Compromised Employee Accounts Domain Stats",
              "id": "0e0c07ef-9a92-568b-9c7e-e78beb39dbbb",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-accounts/stats/domain",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-accounts",
                    "stats",
                    "domain"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Accounts Domain Stats API**\n\nCompromised employee account counts per domain.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `domain` | string |  |\n| `affected_account_count` | integer |  |\n| `credential_count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Compromised Employee Account Update",
              "id": "7cf28a9b-9818-550e-b908-14345281db93",
              "request": {
                "method": "PUT",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-accounts/:account_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-accounts",
                    ":account_id"
                  ],
                  "variable": [
                    {
                      "key": "account_id",
                      "value": "6a8f0ffa817b7e829283ce4a",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Account Update API**\n\nUpdates an account's profile with the fields in the request body.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `is_executive` | boolean | yes |  |\n| `first_name` | string |  | max length `100` |\n| `last_name` | string |  | max length `100` |\n| `title` | string |  | max length `100` |\n| `linkedin_url` | string |  | min length `1`; max length `2083` |\n| `department` | string |  | max length `100` |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `email` | string |  |\n| `is_executive` | boolean |  |\n| `first_name` | string |  |\n| `last_name` | string |  |\n| `title` | string |  |\n| `linkedin_url` | string |  |\n| `department` | string |  |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"is_executive\": false,\n  \"first_name\": null,\n  \"last_name\": null,\n  \"title\": null,\n  \"linkedin_url\": null,\n  \"department\": null\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            }
          ]
        },
        {
          "name": "Compromised Employee Credentials",
          "id": "4a2cd0a6-cc95-5a22-9a6e-84d14dab4de8",
          "description": "Leaked credentials of your employees.",
          "item": [
            {
              "name": "Compromised Employee Credential Search",
              "id": "03813e53-9b73-54e1-9e7e-2b90255b94b6",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-credentials/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-credentials",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Credential Search API**\n\nSearches leaked employee credentials and their state.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 22 fields\n\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n\n**`eq`, `exists`** — 17 fields\n\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\nSortable fields:\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].url` | string |  |\n| `results[].state` | string | One of `newly_detected`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |\n| `results[].account` | object |  |\n| `results[].added_at` | string | date-time |\n| `results[].password` | string |  |\n| `results[].password_analysis` | object |  |\n| `results[].target` | object |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Employee Credential Export",
              "id": "e0963e90-0adc-53d7-afd9-d2d36968b80d",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-credentials/search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-credentials",
                    "search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Credential Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 22 fields\n\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n\n**`eq`, `exists`** — 17 fields\n\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\nSortable fields:\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Employee Credential Accept Risk",
              "id": "66b37797-880e-5581-81fa-284b90414469",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-credentials/search:accept-risk",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-credentials",
                    "search:accept-risk"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Credential Accept Risk API**\n\nAccepts the risk of the compromised employee credentials that match `filters` (`risk_accepted`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 22 fields\n\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n\n**`eq`, `exists`** — 17 fields\n\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\nSortable fields:\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a9c172770265903fd89be73\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Employee Credential Ignore",
              "id": "abc6cd8c-e381-52fd-baa7-fccc6b6b3381",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-credentials/search:ignore",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-credentials",
                    "search:ignore"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Credential Ignore API**\n\nIgnores the compromised employee credentials that match `filters` (`ignored`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 22 fields\n\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n\n**`eq`, `exists`** — 17 fields\n\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\nSortable fields:\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a9c172770265903fd89be73\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Employee Credential Mark False Positive",
              "id": "d65130d5-aea4-5def-a31e-43ab1ac5916b",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-credentials/search:mark-false-positive",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-credentials",
                    "search:mark-false-positive"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Credential Mark False Positive API**\n\nMarks the compromised employee credentials that match `filters` as false positive (`marked_as_false_positive`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 22 fields\n\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n\n**`eq`, `exists`** — 17 fields\n\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\nSortable fields:\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a9c172770265903fd89be73\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Employee Credential Mark Resolved",
              "id": "41430284-300a-5ed4-9888-c09fe55524d1",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-credentials/search:mark-resolved",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-credentials",
                    "search:mark-resolved"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Credential Mark Resolved API**\n\nMarks the compromised employee credentials that match `filters` as resolved (`marked_as_resolved`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 22 fields\n\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n\n**`eq`, `exists`** — 17 fields\n\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\nSortable fields:\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a9c172770265903fd89be73\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Employee Credential Revert",
              "id": "2873fdfa-6be9-552f-a74f-61886d0d328e",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-credentials/search:revert",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-credentials",
                    "search:revert"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Credential Revert API**\n\nReverts the compromised employee credentials that match `filters` to their previous, active state. Only states set by a user can be reverted.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 22 fields\n\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n\n**`eq`, `exists`** — 17 fields\n\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\nSortable fields:\n\n- `id`: The exposed credential's unique ID, a 24-character hex string.\n- `url`: The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`.\n- `account.id`: The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the credential belongs to (ACCOUNT column).\n- `account.domain`: The domain of the employee's e-mail address, one of your organization's domains.\n- `account.is_executive`: Whether the employee the credential belongs to is marked as an executive.\n- `account.first_name`: The first name of the employee the credential belongs to, when known.\n- `account.last_name`: The last name of the employee the credential belongs to, when known.\n- `account.title`: The job title of the employee the credential belongs to, when known.\n- `account.linkedin_url`: The address of the LinkedIn profile of the employee the credential belongs to, when known.\n- `account.department`: The department of the employee the credential belongs to, when known.\n- `added_at`: When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.\n- `password_analysis.strength.level`: The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`.\n- `password_analysis.strength.score`: The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).\n- `password_analysis.strength.label`: The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column.\n- `password_analysis.strength.entropy_bits`: An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.\n- `password_analysis.composition.length`: The number of characters in the password (LENGTH).\n- `password_analysis.composition.structure`: The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.\n- `password_analysis.composition.character_classes_used`: How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).\n- `password_analysis.composition.contains_uppercase`: Whether the password contains an uppercase letter (A–Z).\n- `password_analysis.composition.contains_lowercase`: Whether the password contains a lowercase letter (a–z).\n- `password_analysis.composition.contains_number`: Whether the password contains a digit (0–9).\n- `password_analysis.composition.contains_special`: Whether the password contains a special character, such as `!`, `@` or `#`.\n- `password_analysis.composition.starts_with_uppercase`: Whether the password starts with an uppercase letter (START WITH UPPERCASE).\n- `password_analysis.composition.ends_with_numbers`: Whether the password ends with a digit (END WITH NUMBERS).\n- `password_analysis.composition.ends_with_special`: Whether the password ends with a special character (END WITH SPECIAL CHARACTER).\n- `password_analysis.patterns.has_keyboard_pattern`: Whether the password contains a keyboard pattern (KEYBOARD PATTERN).\n- `password_analysis.patterns.has_date_pattern`: Whether the password contains a date pattern (DATE PATTERN).\n- `password_analysis.patterns.has_leet_speak`: Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).\n- `password_analysis.patterns.has_sequential_chars`: Whether the password contains sequential characters (SEQUENTIAL CHARACTER).\n- `password_analysis.patterns.has_repeated_chars`: Whether the password contains repeated characters (REPEATED CHARACTER).\n- `password_analysis.dictionary_match.is_common_password`: Whether the password is a known common password (COMMON PASSWORD).\n- `password_analysis.dictionary_match.common_password_rank`: The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`.\n- `password_analysis.dictionary_match.is_dictionary_word`: Whether the whole password, ignoring letter case, is a dictionary word.\n- `password_analysis.dictionary_match.dictionary_word_found`: The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.\n- `target.url`: The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN).\n- `target.service`: The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.\n- `state`: The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a9c172770265903fd89be73\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Employee Credential Exposure Timeline",
              "id": "cfea0083-2aa6-52de-b522-2000d9fb58aa",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-credentials/stats/exposure-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-credentials",
                    "stats",
                    "exposure-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Credential Exposure Timeline API**\n\nTime series of newly exposed employee credentials.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `count` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Compromised Employee Credential Stats",
              "id": "e42d1dfc-fc8f-55c0-97b4-da9b47d5b149",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-credentials/stats",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-credentials",
                    "stats"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Credential Stats API**\n\nCompromised employee credential statistics.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `credential_count` | integer |  |\n| `credential_account_count` | integer |  |\n| `first_exposure_date` | string | date-time |\n| `timeline` | array of object |  |"
              },
              "response": []
            },
            {
              "name": "Compromised Employee Credential Status Stats",
              "id": "443bb948-c5a1-5a34-bd28-cf4d44d42c29",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-employee-credentials/stats/status",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-employee-credentials",
                    "stats",
                    "status"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Employee Credential Status Stats API**\n\nCompromised employee credential counts per state.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `active` | integer |  |\n| `inactive` | integer |  |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Compromised Client Credentials",
          "id": "9dd47d13-3823-59b1-8684-5f84b0086895",
          "description": "Leaked credentials of your customers on your services.",
          "item": [
            {
              "name": "Compromised Client Credential Search",
              "id": "d825e699-71f2-51b5-81bf-57212e34dcb9",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-client-credentials/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-client-credentials",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Client Credential Search API**\n\nSearches leaked credentials of your customers and their state.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 13 fields\n\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n\n**`eq`, `exists`** — 2 fields\n\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 1 field\n\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n\nSortable fields:\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].url` | string |  |\n| `results[].username` | string |  |\n| `results[].username_type` | string | One of `email`, `username` |\n| `results[].state` | string | One of `newly_detected`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |\n| `results[].added_at` | string | date-time |\n| `results[].password` | string |  |\n| `results[].target` | object |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Client Credential Export",
              "id": "055915e3-0846-53c9-9737-91ef26d39fcf",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-client-credentials/search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-client-credentials",
                    "search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Client Credential Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 13 fields\n\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n\n**`eq`, `exists`** — 2 fields\n\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 1 field\n\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n\nSortable fields:\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Client Credential Accept Risk",
              "id": "83263ac3-cdb0-5087-89c5-d4e62fc75898",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-client-credentials/search:accept-risk",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-client-credentials",
                    "search:accept-risk"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Client Credential Accept Risk API**\n\nAccepts the risk of the compromised client credentials that match `filters` (`risk_accepted`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 13 fields\n\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n\n**`eq`, `exists`** — 2 fields\n\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 1 field\n\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n\nSortable fields:\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a3fad039586a3258f3113fa\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Client Credential Ignore",
              "id": "97b5ebee-55a0-5fc3-9491-53fda6e21c9a",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-client-credentials/search:ignore",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-client-credentials",
                    "search:ignore"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Client Credential Ignore API**\n\nIgnores the compromised client credentials that match `filters` (`ignored`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 13 fields\n\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n\n**`eq`, `exists`** — 2 fields\n\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 1 field\n\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n\nSortable fields:\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a3fad039586a3258f3113fa\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Client Credential Mark False Positive",
              "id": "5b6f6757-62e6-5891-8d3b-2c3e8d34f2f3",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-client-credentials/search:mark-false-positive",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-client-credentials",
                    "search:mark-false-positive"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Client Credential Mark False Positive API**\n\nMarks the compromised client credentials that match `filters` as false positive (`marked_as_false_positive`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 13 fields\n\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n\n**`eq`, `exists`** — 2 fields\n\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 1 field\n\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n\nSortable fields:\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a3fad039586a3258f3113fa\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Client Credential Mark Resolved",
              "id": "abb64c15-2fe0-5297-93f2-37c5b879004b",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-client-credentials/search:mark-resolved",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-client-credentials",
                    "search:mark-resolved"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Client Credential Mark Resolved API**\n\nMarks the compromised client credentials that match `filters` as resolved (`marked_as_resolved`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 13 fields\n\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n\n**`eq`, `exists`** — 2 fields\n\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 1 field\n\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n\nSortable fields:\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a3fad039586a3258f3113fa\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Client Credential Revert",
              "id": "1a09ab14-c33b-5bd5-8936-4134e485b204",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-client-credentials/search:revert",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-client-credentials",
                    "search:revert"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Client Credential Revert API**\n\nReverts the compromised client credentials that match `filters` to their previous, active state. Only states set by a user can be reverted.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 13 fields\n\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n\n**`eq`, `exists`** — 2 fields\n\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n\n**`eq`, `in`** — 1 field\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n\n**`eq`, `in`, `exists`** — 1 field\n\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 1 field\n\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n\nSortable fields:\n\n- `id`: The client credential's unique ID, a 24-character hex string.\n- `url`: The address of the login page or app of your service where the customer's credential was used; in the samples it is the same as `target.url`.\n- `username`: The customer's username or e-mail address from the leaked login (USERNAME).\n- `username_type`: Whether `username` is an e-mail address (`email`) or a user name (`username`); it can be empty.\n- `added_at`: When the client credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).\n- `password`: The customer's leaked password in plain text. The platform's list does not show it, but API responses include it, so protect them.\n- `target.url`: The address of the site or app the credential belongs to. For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address.\n- `target.url_raw`: The raw form of the target URL; in the samples it is always the same as `target.url`.\n- `target.fqdn`: The host name of the target, such as `login.acme.example`. For an Android app it is the app's package name in reverse order.\n- `target.domain`: The registered domain of the target, such as `acme.example` for `login.acme.example`.\n- `target.service`: The name of your site or service the client credential belongs to.\n- `target.platform`: Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown with the login address in the TARGET column.\n- `target.main_category`: The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail`. Empty for a service without a category.\n- `target.sub_category`: A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider`. Empty for a service without a category.\n- `target.risk_tier`: The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW`. Empty for a service without a category.\n- `target.is_corporate`: Whether the target is a corporate service.\n- `target.requires_mfa_by_default`: Whether the target service enforces multi-factor authentication by default. Empty for a service without a category.\n- `state`: The client credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"id\",\n        \"type\": \"eq\",\n        \"value\": \"6a3fad039586a3258f3113fa\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Client Credential Stats",
              "id": "21cbfed8-916d-5590-a822-012fd1270915",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-client-credentials/stats",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-client-credentials",
                    "stats"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Client Credential Stats API**\n\nCompromised client credential statistics.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `credential_count` | integer |  |\n| `first_exposure_date` | string | date-time |\n| `timeline` | array of object |  |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Compromised Payment Credentials",
          "id": "110e986b-be60-5882-9526-6f693a6ebfb4",
          "description": "Leaked payment card data related to your organization.",
          "item": [
            {
              "name": "Compromised Payment Credential Search",
              "id": "1fdad75d-35cc-5d4b-832f-f04740590fc7",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-payment-credentials/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-payment-credentials",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Payment Credential Search API**\n\nSearches leaked payment cards and their state.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"pan_last_four\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 16 fields\n\n- `pan`: The full card number (primary account number) found in the leak. Treat it as sensitive.\n- `pan_masked`: The card number in masked form, with part of the digits hidden.\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `dedup_key`: A de-duplication key for the card record.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `card_type`: The card type: `credit`, `debit` or `prepaid`.\n- `card_level`: The card's product level: `classic`, `gold`, `world`, `platinum`, `business`, `signature`, `standard` or `enhanced`.\n- `issuer_name`: The name of the card's issuer.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `leak_name`: The names of the leaks the card was found in, as a list.\n- `source_url`: The address of the source where the card was found.\n- `harvest_url`: The address the card record was harvested (collected) from, recorded separately from `source_url`.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `expiry_year`: The card's expiry year; it can be empty.\n- `expiry_month`: The card's expiry month, as a number; it can be empty.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n\n**`eq`, `exists`** — 3 fields\n\n- `luhn_valid`: Whether the card number passes the Luhn check, the check-digit test that valid card numbers pass.\n- `has_cvv`: Whether the leaked record includes the card's security code (CVV).\n- `is_validated_live`: Whether the card has been validated as live.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `network`: Network names recorded for the card record, as a list of strings.\n\nSortable fields:\n\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `expiry_year`: The card's expiry year; it can be empty.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].pan` | string |  |\n| `results[].pan_masked` | string |  |\n| `results[].pan_last_four` | string |  |\n| `results[].bin` | string |  |\n| `results[].dedup_key` | string |  |\n| `results[].luhn_valid` | boolean |  |\n| `results[].expiry_year` | integer |  |\n| `results[].expiry_month` | integer |  |\n| `results[].expiry_raw` | string |  |\n| `results[].is_expired` | boolean |  |\n| `results[].has_cvv` | boolean |  |\n| `results[].card_brand` | string |  |\n| `results[].card_type` | string |  |\n| `results[].card_level` | string |  |\n| `results[].issuer_name` | string |  |\n| `results[].issuer_country` | string |  |\n| `results[].check_status` | string |  |\n| `results[].is_validated_live` | boolean |  |\n| `results[].confidence` | string |  |\n| `results[].source_format` | string |  |\n| `results[].network` | array of string |  |\n| `results[].leak_name` | array of string |  |\n| `results[].source_url` | string |  |\n| `results[].first_seen` | string | date-time |\n| `results[].last_seen` | string | date-time |\n| `results[].times_seen` | integer |  |\n| `results[].hackishness` | number |  |\n| `results[].harvest_url` | string |  |\n| `results[].co_listed_card_count` | integer |  |\n| `results[].other_context` | object |  |\n| `results[].state` | string |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Payment Credential Export",
              "id": "e0509c8e-a5a9-5b56-9e87-18e9e9fa7e32",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-payment-credentials/search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-payment-credentials",
                    "search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Payment Credential Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"pan_last_four\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 16 fields\n\n- `pan`: The full card number (primary account number) found in the leak. Treat it as sensitive.\n- `pan_masked`: The card number in masked form, with part of the digits hidden.\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `dedup_key`: A de-duplication key for the card record.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `card_type`: The card type: `credit`, `debit` or `prepaid`.\n- `card_level`: The card's product level: `classic`, `gold`, `world`, `platinum`, `business`, `signature`, `standard` or `enhanced`.\n- `issuer_name`: The name of the card's issuer.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `leak_name`: The names of the leaks the card was found in, as a list.\n- `source_url`: The address of the source where the card was found.\n- `harvest_url`: The address the card record was harvested (collected) from, recorded separately from `source_url`.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `expiry_year`: The card's expiry year; it can be empty.\n- `expiry_month`: The card's expiry month, as a number; it can be empty.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n\n**`eq`, `exists`** — 3 fields\n\n- `luhn_valid`: Whether the card number passes the Luhn check, the check-digit test that valid card numbers pass.\n- `has_cvv`: Whether the leaked record includes the card's security code (CVV).\n- `is_validated_live`: Whether the card has been validated as live.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `network`: Network names recorded for the card record, as a list of strings.\n\nSortable fields:\n\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `expiry_year`: The card's expiry year; it can be empty.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Payment Credential Detail",
              "id": "bf862844-e2de-5489-8c5e-0e462648addc",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-payment-credentials/:credential_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-payment-credentials",
                    ":credential_id"
                  ],
                  "variable": [
                    {
                      "key": "credential_id",
                      "value": "<credential_id>",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Payment Credential Detail API**\n\nReturns one compromised payment credential.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `pan` | string |  |\n| `pan_masked` | string |  |\n| `pan_last_four` | string |  |\n| `bin` | string |  |\n| `dedup_key` | string |  |\n| `luhn_valid` | boolean |  |\n| `expiry_year` | integer |  |\n| `expiry_month` | integer |  |\n| `expiry_raw` | string |  |\n| `is_expired` | boolean |  |\n| `has_cvv` | boolean |  |\n| `card_brand` | string |  |\n| `card_type` | string |  |\n| `card_level` | string |  |\n| `issuer_name` | string |  |\n| `issuer_country` | string |  |\n| `check_status` | string |  |\n| `is_validated_live` | boolean |  |\n| `confidence` | string |  |\n| `source_format` | string |  |\n| `network` | array of string |  |\n| `leak_name` | array of string |  |\n| `source_url` | string |  |\n| `first_seen` | string | date-time |\n| `last_seen` | string | date-time |\n| `times_seen` | integer |  |\n| `hackishness` | number |  |\n| `harvest_url` | string |  |\n| `co_listed_card_count` | integer |  |\n| `other_context` | object |  |\n| `state` | string |  |\n\n> No live example: the DEMO account has no data for this endpoint yet, or it returned an error during testing. The response shape is described above."
              },
              "response": []
            },
            {
              "name": "Compromised Payment Credential Accept Risk",
              "id": "7689e191-ca1d-5ffc-891c-b86a4435704e",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-payment-credentials/search:accept-risk",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-payment-credentials",
                    "search:accept-risk"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Payment Credential Accept Risk API**\n\nAccepts the risk of the compromised payment credentials that match `filters` (`risk_accepted`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"pan_last_four\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 16 fields\n\n- `pan`: The full card number (primary account number) found in the leak. Treat it as sensitive.\n- `pan_masked`: The card number in masked form, with part of the digits hidden.\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `dedup_key`: A de-duplication key for the card record.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `card_type`: The card type: `credit`, `debit` or `prepaid`.\n- `card_level`: The card's product level: `classic`, `gold`, `world`, `platinum`, `business`, `signature`, `standard` or `enhanced`.\n- `issuer_name`: The name of the card's issuer.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `leak_name`: The names of the leaks the card was found in, as a list.\n- `source_url`: The address of the source where the card was found.\n- `harvest_url`: The address the card record was harvested (collected) from, recorded separately from `source_url`.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `expiry_year`: The card's expiry year; it can be empty.\n- `expiry_month`: The card's expiry month, as a number; it can be empty.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n\n**`eq`, `exists`** — 3 fields\n\n- `luhn_valid`: Whether the card number passes the Luhn check, the check-digit test that valid card numbers pass.\n- `has_cvv`: Whether the leaked record includes the card's security code (CVV).\n- `is_validated_live`: Whether the card has been validated as live.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `network`: Network names recorded for the card record, as a list of strings.\n\nSortable fields:\n\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `expiry_year`: The card's expiry year; it can be empty.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"newly_detected\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Payment Credential Ignore",
              "id": "bdd4b3a2-006f-51e2-a982-01e5257f9ec1",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-payment-credentials/search:ignore",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-payment-credentials",
                    "search:ignore"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Payment Credential Ignore API**\n\nIgnores the compromised payment credentials that match `filters` (`ignored`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"pan_last_four\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 16 fields\n\n- `pan`: The full card number (primary account number) found in the leak. Treat it as sensitive.\n- `pan_masked`: The card number in masked form, with part of the digits hidden.\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `dedup_key`: A de-duplication key for the card record.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `card_type`: The card type: `credit`, `debit` or `prepaid`.\n- `card_level`: The card's product level: `classic`, `gold`, `world`, `platinum`, `business`, `signature`, `standard` or `enhanced`.\n- `issuer_name`: The name of the card's issuer.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `leak_name`: The names of the leaks the card was found in, as a list.\n- `source_url`: The address of the source where the card was found.\n- `harvest_url`: The address the card record was harvested (collected) from, recorded separately from `source_url`.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `expiry_year`: The card's expiry year; it can be empty.\n- `expiry_month`: The card's expiry month, as a number; it can be empty.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n\n**`eq`, `exists`** — 3 fields\n\n- `luhn_valid`: Whether the card number passes the Luhn check, the check-digit test that valid card numbers pass.\n- `has_cvv`: Whether the leaked record includes the card's security code (CVV).\n- `is_validated_live`: Whether the card has been validated as live.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `network`: Network names recorded for the card record, as a list of strings.\n\nSortable fields:\n\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `expiry_year`: The card's expiry year; it can be empty.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"newly_detected\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Payment Credential Mark False Positive",
              "id": "e7362c49-8443-59a9-aaa9-c228a9d4821a",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-payment-credentials/search:mark-false-positive",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-payment-credentials",
                    "search:mark-false-positive"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Payment Credential Mark False Positive API**\n\nMarks the compromised payment credentials that match `filters` as false positive (`marked_as_false_positive`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"pan_last_four\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 16 fields\n\n- `pan`: The full card number (primary account number) found in the leak. Treat it as sensitive.\n- `pan_masked`: The card number in masked form, with part of the digits hidden.\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `dedup_key`: A de-duplication key for the card record.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `card_type`: The card type: `credit`, `debit` or `prepaid`.\n- `card_level`: The card's product level: `classic`, `gold`, `world`, `platinum`, `business`, `signature`, `standard` or `enhanced`.\n- `issuer_name`: The name of the card's issuer.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `leak_name`: The names of the leaks the card was found in, as a list.\n- `source_url`: The address of the source where the card was found.\n- `harvest_url`: The address the card record was harvested (collected) from, recorded separately from `source_url`.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `expiry_year`: The card's expiry year; it can be empty.\n- `expiry_month`: The card's expiry month, as a number; it can be empty.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n\n**`eq`, `exists`** — 3 fields\n\n- `luhn_valid`: Whether the card number passes the Luhn check, the check-digit test that valid card numbers pass.\n- `has_cvv`: Whether the leaked record includes the card's security code (CVV).\n- `is_validated_live`: Whether the card has been validated as live.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `network`: Network names recorded for the card record, as a list of strings.\n\nSortable fields:\n\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `expiry_year`: The card's expiry year; it can be empty.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"newly_detected\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Payment Credential Mark Resolved",
              "id": "4ce79251-1b9b-59f9-be0f-a8fe83a9147b",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-payment-credentials/search:mark-resolved",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-payment-credentials",
                    "search:mark-resolved"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Payment Credential Mark Resolved API**\n\nMarks the compromised payment credentials that match `filters` as resolved (`marked_as_resolved`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"pan_last_four\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 16 fields\n\n- `pan`: The full card number (primary account number) found in the leak. Treat it as sensitive.\n- `pan_masked`: The card number in masked form, with part of the digits hidden.\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `dedup_key`: A de-duplication key for the card record.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `card_type`: The card type: `credit`, `debit` or `prepaid`.\n- `card_level`: The card's product level: `classic`, `gold`, `world`, `platinum`, `business`, `signature`, `standard` or `enhanced`.\n- `issuer_name`: The name of the card's issuer.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `leak_name`: The names of the leaks the card was found in, as a list.\n- `source_url`: The address of the source where the card was found.\n- `harvest_url`: The address the card record was harvested (collected) from, recorded separately from `source_url`.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `expiry_year`: The card's expiry year; it can be empty.\n- `expiry_month`: The card's expiry month, as a number; it can be empty.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n\n**`eq`, `exists`** — 3 fields\n\n- `luhn_valid`: Whether the card number passes the Luhn check, the check-digit test that valid card numbers pass.\n- `has_cvv`: Whether the leaked record includes the card's security code (CVV).\n- `is_validated_live`: Whether the card has been validated as live.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `network`: Network names recorded for the card record, as a list of strings.\n\nSortable fields:\n\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `expiry_year`: The card's expiry year; it can be empty.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"newly_detected\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Payment Credential Revert",
              "id": "98b82d29-de5c-546b-85e4-f2c2b91fd54c",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-payment-credentials/search:revert",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-payment-credentials",
                    "search:revert"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Payment Credential Revert API**\n\nReverts the compromised payment credentials that match `filters` to their previous, active state. Only states set by a user can be reverted.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"pan_last_four\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 16 fields\n\n- `pan`: The full card number (primary account number) found in the leak. Treat it as sensitive.\n- `pan_masked`: The card number in masked form, with part of the digits hidden.\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `dedup_key`: A de-duplication key for the card record.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `card_type`: The card type: `credit`, `debit` or `prepaid`.\n- `card_level`: The card's product level: `classic`, `gold`, `world`, `platinum`, `business`, `signature`, `standard` or `enhanced`.\n- `issuer_name`: The name of the card's issuer.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `leak_name`: The names of the leaks the card was found in, as a list.\n- `source_url`: The address of the source where the card was found.\n- `harvest_url`: The address the card record was harvested (collected) from, recorded separately from `source_url`.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 7 fields\n\n- `expiry_year`: The card's expiry year; it can be empty.\n- `expiry_month`: The card's expiry month, as a number; it can be empty.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n\n**`eq`, `exists`** — 3 fields\n\n- `luhn_valid`: Whether the card number passes the Luhn check, the check-digit test that valid card numbers pass.\n- `has_cvv`: Whether the leaked record includes the card's security code (CVV).\n- `is_validated_live`: Whether the card has been validated as live.\n\nOperators not measured (the DEMO account has no data for these fields):\n\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `network`: Network names recorded for the card record, as a list of strings.\n\nSortable fields:\n\n- `pan_last_four`: The last four digits of the card number.\n- `bin`: The card's bank identification number (BIN), the leading digits of the card number that identify the issuer.\n- `expiry_year`: The card's expiry year; it can be empty.\n- `card_brand`: The card brand: `visa`, `mastercard`, `amex`, `discover` or `unionpay`.\n- `issuer_country`: The country of the card's issuer.\n- `check_status`: The result of checking the card: `approved`, `declined` or `unknown`, which is the default.\n- `confidence`: The platform's confidence level for the record: `high`, `medium` or `low` (CONFIDENCE).\n- `source_format`: The kind of source the card was found in: `structured_dump`, `checker_bot`, `stealer_log`, `bare_ccn` or `other`.\n- `first_seen`: When the card was first seen (UTC date-time).\n- `last_seen`: When the card was last seen, shown as LAST SEEN (UTC date-time).\n- `times_seen`: How many times the card was seen (TIMES SEEN).\n- `hackishness`: The record's hackishness score (HACKISHNESS), the same kind of score as on dark web search results.\n- `co_listed_card_count`: The number of cards listed together with this card in its source.\n- `state`: The card record's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"newly_detected\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Payment Credential Stats",
              "id": "020fc3b3-7bd0-57f6-bad1-dd140eb0c24d",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-payment-credentials/stats",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-payment-credentials",
                    "stats"
                  ]
                },
                "description": "**Deepinfo CTI Compromised Payment Credential Stats API**\n\nCompromised payment credential statistics.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `credential_count` | integer |  |\n| `first_exposure_date` | string | date-time |\n| `timeline` | array of object |  |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Compromised Devices",
          "id": "48d7735a-ec29-5128-b469-f954e689b553",
          "description": "Infected devices (infostealer logs) linked to your employees.",
          "item": [
            {
              "name": "Compromised Device Search",
              "id": "3082355b-f032-58a9-a680-9f77c459bb5a",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-devices?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-devices"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Device Search API**\n\nSearches compromised (infostealer-infected) devices linked to your employees.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"compromised_device.hardware_id\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"compromised_device.hardware_id\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 71 fields\n\n- `compromised_device.hardware_id`: The hardware ID the infostealer recorded for the infected device, which identifies one machine across logs.\n- `compromised_device.user_info.username`: The operating-system user name on the infected device, as the stealer log recorded it.\n- `compromised_device.user_info.machine_name`: The computer name of the infected device; the platform shows it as MACHINE.\n- `compromised_device.user_info.country`: The country the infected device was in when the log was made, as the stealer recorded it.\n- `compromised_device.user_info.location`: The location the stealer log gives for the device, such as a city or region.\n- `compromised_device.user_info.zip_code`: The postal code the stealer log gives for the device's location.\n- `compromised_device.user_info.language`: The system language of the infected device; the platform shows it as LANGUAGE.\n- `compromised_device.user_info.time_zone`: The time zone set on the infected device; the platform shows it as TIMEZONE.\n- `compromised_device.user_info.operating_system`: The operating system of the infected device, such as a Windows version; the platform shows it as OS.\n- `compromised_device.user_info.screen_resolution`: The screen resolution of the infected device, as the stealer recorded it.\n- `compromised_device.user_info.ip_address`: The IP address the infected device had when the data was stolen; the platform shows it as IP.\n- `compromised_device.user_info.keyboard_layouts`: The keyboard layouts installed on the infected device, a list of language codes.\n- `compromised_device.system_info.ram`: The amount of memory (RAM) of the infected device, as text.\n- `compromised_device.system_info.cpu`: The processor (CPU) model of the infected device.\n- `compromised_device.system_info.gpu`: The graphics cards (GPU) of the infected device, a list.\n- `compromised_device.system_info.installed_antivirus`: The antivirus products found on the infected device, a list; the platform shows it as AV.\n- `compromised_device.installed_softwares.name`: The name of a program installed on the infected device.\n- `compromised_device.installed_softwares.version`: The version of a program installed on the infected device.\n- `compromised_device.installed_softwares.category`: The category of a program installed on the infected device.\n- `compromised_device.installed_browsers.name`: The name of a web browser installed on the infected device.\n- `compromised_device.installed_browsers.version`: The version of a web browser installed on the infected device.\n- `account.id`: The ID of the employee account the device is linked to, the `id` returned by Compromised Employee Account Search.\n- `account.email`: The e-mail address of the employee account the device is linked to.\n- `leaked_data.stealer_docs`: The names of the files the infostealer took from the device, a list.\n- `leaked_data.passwords.url`: The address of the login page a stolen password was saved for.\n- `leaked_data.passwords.fqdn`: The full host name of the login page a stolen password was saved for, such as `login.acme.example`.\n- `leaked_data.passwords.domain`: The registered domain of the login page a stolen password was saved for, such as `acme.example`.\n- `leaked_data.passwords.username`: The user name or e-mail address saved with a stolen password. Responses mask personal values.\n- `leaked_data.passwords.password`: The stolen password itself. Responses show it masked.\n- `leaked_data.passwords.leak_source_type`: Where the stolen password came from, such as the kind of stealer log.\n- `leaked_data.passwords.source_application`: The application the password was stolen from, such as a web browser.\n- `leaked_data.tokens.raw_value`: The stolen token itself, such as a session or API token. Responses show it masked.\n- `leaked_data.tokens.token_type`: The kind of stolen token, such as a session token or an API key.\n- `leaked_data.tokens.possible_issuer`: The service that probably issued the stolen token; the platform shows it as ISSUER.\n- `leaked_data.tokens.associated_user`: The user the stolen token belongs to; the platform shows it as USER.\n- `leaked_data.tokens.website`: The website the stolen token is used on.\n- `leaked_data.tokens.category`: The category of the stolen token's service.\n- `leaked_data.tokens.risk_reason`: Why the stolen token got its risk level, in words.\n- `leaked_data.tokens.source_application`: The application the token was stolen from, such as a web browser.\n- `leaked_data.auto_fills.field_name`: The name of a form field whose saved (autofill) value was stolen, such as `email` or `phone`.\n- `leaked_data.auto_fills.field_value`: The stolen autofill value. Responses mask personal values.\n- `leaked_data.auto_fills.data_type`: The kind of data in a stolen autofill value, such as an e-mail address or a phone number.\n- `leaked_data.auto_fills.source_application`: The application the autofill value was stolen from, such as a web browser.\n- `leaked_data.auto_fills.source_name`: The name of the browser profile or source the autofill value was read from.\n- `leaked_data.cookies.domain`: A domain the infected device had cookies for, such as `acme.example`.\n- `leaked_data.cookies.subdomains`: The subdomains of that domain the device had cookies for, a list.\n- `leaked_data.sensitive_cookies.domain`: The domain a stolen sensitive cookie (one that can open a session) belongs to.\n- `leaked_data.sensitive_cookies.name`: The name of a stolen sensitive cookie.\n- `leaked_data.sensitive_cookies.value`: The value of a stolen sensitive cookie. Responses show it masked.\n- `leaked_data.sensitive_cookies.path`: The path a stolen sensitive cookie applies to, such as `/`.\n- `leaked_data.sensitive_cookies.cookie_type`: The kind of stolen cookie, such as a session or authentication cookie.\n- `leaked_data.sensitive_cookies.risk_reason`: Why the stolen cookie got its risk level, in words.\n- `leaked_data.sensitive_cookies.source_application`: The application the cookie was stolen from, such as a web browser.\n- `leaked_data.documents.name`: The file name of a document the infostealer took from the device.\n- `leaked_data.documents.creator`: The author recorded in a stolen document's properties. Responses mask personal values.\n- `leaked_data.documents.last_modified_by`: The last editor recorded in a stolen document's properties. Responses mask personal values.\n- `leaked_data.documents.content`: The text of a stolen document. Responses do not show it.\n- `leaked_data.documents.language`: The language of a stolen document's text.\n- `leaked_data.documents.sensitive_data_score`: A score of how much sensitive data a stolen document holds.\n- `leaked_data.documents.sensitive_data_type`: The kinds of sensitive data found in a stolen document, a list.\n- `compromise_summary.corporate_email_address`: Your organization's e-mail addresses found on the device, a list.\n- `compromise_summary.other_email_addresses`: The other e-mail addresses found on the device, a list.\n- `compromise_summary.same_password_rate`: How often the same password is reused among the device's stolen passwords, as text.\n- `compromise_summary.accessed_internal_resources`: Internal resources of your organization the device had stolen access to, such as internal login pages, a list.\n- `compromise_summary.corporate_risk`: A short assessment of the risk to your organization; the platform shows it as CORPORATE RISK.\n- `compromise_summary.financial_risk`: A short assessment of the financial risk; the platform shows it as FINANCIAL RISK.\n- `compromise_summary.identity_theft_risk`: A short assessment of the identity theft risk; the platform shows it as IDENTITY THEFT.\n- `compromise_summary.corporate_espionage`: A short assessment of the corporate espionage risk.\n- `compromise_summary.ransomware_threat`: A short assessment of the ransomware threat; the platform shows it as RANSOMWARE THREAT.\n- `compromise_summary.phishing_risk`: A short assessment of the phishing risk; the platform shows it as PHISHING RISK.\n- `compromise_summary.session_hijacking_risk`: A short assessment of the session hijacking risk, from the stolen cookies and tokens; the platform shows it as SESSION HIJACKING.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 9 fields\n\n- `compromised_device.log_date`: When the infostealer log of this device was created, that is, when the data was stolen.\n- `leaked_data.sensitive_cookies.expiration_timestamp`: When the stolen cookie expires. A cookie that has not expired can still open a session.\n- `leaked_data.documents.created_date`: When a stolen document was created, from its properties.\n- `leaked_data.documents.modified_date`: When a stolen document was last changed, from its properties.\n- `compromise_summary.password_count`: The number of passwords stolen from the device; the platform shows it as PASSWORDS.\n- `compromise_summary.token_count`: The number of tokens stolen from the device; the platform shows it as TOKEN.\n- `compromise_summary.autofill_count`: The number of autofill values stolen from the device; the platform shows it as AUTOFILL.\n- `compromise_summary.cookie_count`: The number of cookies stolen from the device.\n- `compromise_summary.sensitive_cookie_count`: The number of sensitive cookies (ones that can open a session) stolen from the device; the platform shows it as COOKIE.\n\n**`eq`, `exists`** — 4 fields\n\n- `leaked_data.passwords.is_corporate`: `true` when the stolen password is for one of your organization's own services.\n- `leaked_data.sensitive_cookies.secure`: `true` when the stolen cookie is sent over HTTPS only.\n- `leaked_data.sensitive_cookies.http_only`: `true` when the stolen cookie is hidden from page scripts (HttpOnly).\n- `leaked_data.sensitive_cookies.include_subdomains`: `true` when the stolen cookie also applies to the domain's subdomains.\n\n**`eq`, `in`, `exists`** — 3 fields\n\n- `leaked_data.tokens.risk_level`: How risky the stolen token is: `low`, `medium`, `high` or `critical`.\n- `leaked_data.sensitive_cookies.risk_level`: How risky the stolen cookie is: `low`, `medium`, `high` or `critical`.\n- `compromise_summary.risk_level`: The device's overall risk level: `low`, `medium`, `high` or `critical`.\n\nSortable fields:\n\n- `compromised_device.hardware_id`: The hardware ID the infostealer recorded for the infected device, which identifies one machine across logs.\n- `compromised_device.log_date`: When the infostealer log of this device was created, that is, when the data was stolen.\n- `compromised_device.user_info.username`: The operating-system user name on the infected device, as the stealer log recorded it.\n- `compromised_device.user_info.machine_name`: The computer name of the infected device; the platform shows it as MACHINE.\n- `compromised_device.user_info.country`: The country the infected device was in when the log was made, as the stealer recorded it.\n- `compromised_device.user_info.language`: The system language of the infected device; the platform shows it as LANGUAGE.\n- `compromised_device.user_info.operating_system`: The operating system of the infected device, such as a Windows version; the platform shows it as OS.\n- `compromised_device.user_info.screen_resolution`: The screen resolution of the infected device, as the stealer recorded it.\n- `compromised_device.user_info.ip_address`: The IP address the infected device had when the data was stolen; the platform shows it as IP.\n- `compromise_summary.password_count`: The number of passwords stolen from the device; the platform shows it as PASSWORDS.\n- `compromise_summary.token_count`: The number of tokens stolen from the device; the platform shows it as TOKEN.\n- `compromise_summary.autofill_count`: The number of autofill values stolen from the device; the platform shows it as AUTOFILL.\n- `compromise_summary.cookie_count`: The number of cookies stolen from the device.\n- `compromise_summary.sensitive_cookie_count`: The number of sensitive cookies (ones that can open a session) stolen from the device; the platform shows it as COOKIE.\n- `compromise_summary.same_password_rate`: How often the same password is reused among the device's stolen passwords, as text.\n- `compromise_summary.risk_level`: The device's overall risk level: `low`, `medium`, `high` or `critical`.\n- `compromise_summary.corporate_risk`: A short assessment of the risk to your organization; the platform shows it as CORPORATE RISK.\n- `compromise_summary.financial_risk`: A short assessment of the financial risk; the platform shows it as FINANCIAL RISK.\n- `compromise_summary.identity_theft_risk`: A short assessment of the identity theft risk; the platform shows it as IDENTITY THEFT.\n- `compromise_summary.corporate_espionage`: A short assessment of the corporate espionage risk.\n- `compromise_summary.ransomware_threat`: A short assessment of the ransomware threat; the platform shows it as RANSOMWARE THREAT.\n- `compromise_summary.phishing_risk`: A short assessment of the phishing risk; the platform shows it as PHISHING RISK.\n- `compromise_summary.session_hijacking_risk`: A short assessment of the session hijacking risk, from the stolen cookies and tokens; the platform shows it as SESSION HIJACKING.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].account` | object |  |\n| `results[].compromised_device` | object |  |\n| `results[].leaked_data` | object |  |\n| `results[].compromise_summary` | object |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Compromised Device Detail",
              "id": "395359bf-5772-53fc-ba9b-77470d59b1d5",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/compromised-devices/:compromised_employee_device_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "compromised-devices",
                    ":compromised_employee_device_id"
                  ],
                  "variable": [
                    {
                      "key": "compromised_employee_device_id",
                      "value": "<compromised_employee_device_id>",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo CTI Compromised Device Detail API**\n\nReturns one compromised device.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `account` | object |  |\n| `compromised_device` | object |  |\n| `leaked_data` | object |  |\n| `compromise_summary` | object |  |\n\n> No live example: the DEMO account has no data for this endpoint yet, or it returned an error during testing. The response shape is described above."
              },
              "response": []
            }
          ]
        },
        {
          "name": "Threat Actors",
          "id": "2ec17b06-412f-5129-b41a-1feb2fdac2f4",
          "description": "Threat actors and what they target.",
          "item": [
            {
              "name": "Threat Actor Search",
              "id": "9281a516-8660-5ea5-8119-729502b387f2",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/threat-actors/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "threat-actors",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Threat Actor Search API**\n\nSearches threat actors.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"name\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"name\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 34 fields\n\n- `name`: The threat actor's main name; other names are in `aliases`.\n- `aliases`: Other names the threat actor is known by.\n- `actor_size`: The threat actor's size, as text.\n- `actor_types`: The threat actor's types, as a list of strings.\n- `actor_sophistication`: The threat actor's level of sophistication, as text.\n- `actor_specializations`: The threat actor's specializations, as a list of strings.\n- `description`: A text description of the threat actor.\n- `law_enforcement`: Law enforcement information recorded for the threat actor, as text.\n- `contact_info.email`: E-mail addresses listed in the threat actor's contact information.\n- `contact_info.telegram_username`: Telegram usernames listed in the threat actor's contact information.\n- `contact_info.telegram_channel`: Telegram channels listed in the threat actor's contact information.\n- `contact_info.discord_username`: Discord usernames listed in the threat actor's contact information.\n- `contact_info.jabber`: Jabber (XMPP) addresses listed in the threat actor's contact information.\n- `contact_info.tox`: Tox IDs listed in the threat actor's contact information.\n- `contact_info.skype`: Skype names listed in the threat actor's contact information.\n- `contact_info.icq`: ICQ contacts listed in the threat actor's contact information.\n- `contact_info.cdn`: CDN entries listed in the threat actor's contact information.\n- `contact_info.ip_ranges`: IP address ranges listed in the threat actor's contact information.\n- `social_media.twitter`: The threat actor's Twitter (X) accounts.\n- `social_media.vimeo`: The threat actor's Vimeo accounts.\n- `websites`: Websites linked to the threat actor.\n- `payment_info.bitcoin`: Bitcoin addresses in the threat actor's payment information.\n- `payment_info.ethereum`: Ethereum addresses in the threat actor's payment information.\n- `origin_countries`: The threat actor's countries of origin; the Most Actor Hosting Countries statistic counts actors per origin country.\n- `leak_names`: Names of leaks linked to the threat actor.\n- `forum_names`: Names of the forums the threat actor is active on.\n- `market_names`: Names of the markets the threat actor is active on.\n- `forum_market_usernames`: The usernames the threat actor uses on forums and markets.\n- `targeted_regions`: The regions the threat actor has targeted.\n- `targeted_countries`: The countries the threat actor has targeted; the Most Targeted Countries statistic counts them.\n- `targeted_industries`: The industries the threat actor has targeted; the Most Targeted Industries statistic counts them.\n- `targeted_organizations`: The organizations the threat actor has targeted; the Most Targeted Organizations statistic counts them.\n- `cves_used`: CVE IDs of the vulnerabilities the threat actor has used; the Most Used CVEs statistic counts them.\n- `tools_used`: The tools the threat actor has used; the Most Used Tools statistic counts them.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 3 fields\n\n- `date_updated`: When the threat actor's profile was last updated (UTC date-time).\n- `date_first_seen`: When the threat actor was first seen (UTC date-time).\n- `date_last_seen`: When the threat actor was last seen active (UTC date-time).\n\n**`eq`, `exists`** — 1 field\n\n- `is_active`: Whether the threat actor is considered active.\n\nSortable fields:\n\n- `name`: The threat actor's main name; other names are in `aliases`.\n- `date_updated`: When the threat actor's profile was last updated (UTC date-time).\n- `date_first_seen`: When the threat actor was first seen (UTC date-time).\n- `date_last_seen`: When the threat actor was last seen active (UTC date-time).\n- `is_active`: Whether the threat actor is considered active.\n- `actor_size`: The threat actor's size, as text.\n- `actor_sophistication`: The threat actor's level of sophistication, as text.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].name` | string |  |\n| `results[].aliases` | array of string |  |\n| `results[].date_updated` | string | date-time |\n| `results[].date_first_seen` | string | date-time |\n| `results[].date_last_seen` | string | date-time |\n| `results[].is_active` | boolean |  |\n| `results[].actor_size` | string |  |\n| `results[].actor_types` | array of string |  |\n| `results[].actor_sophistication` | string |  |\n| `results[].actor_specializations` | array of string |  |\n| `results[].description` | string |  |\n| `results[].law_enforcement` | string |  |\n| `results[].contact_info` | object |  |\n| `results[].social_media` | object |  |\n| `results[].websites` | array of string |  |\n| `results[].payment_info` | object |  |\n| `results[].origin_countries` | array of string |  |\n| `results[].leak_names` | array of string |  |\n| `results[].forum_names` | array of string |  |\n| `results[].market_names` | array of string |  |\n| `results[].forum_market_usernames` | array of string |  |\n| `results[].targeted_regions` | array of string |  |\n| `results[].targeted_countries` | array of string |  |\n| `results[].targeted_industries` | array of string |  |\n| `results[].targeted_organizations` | array of string |  |\n| `results[].cves_used` | array of string |  |\n| `results[].tools_used` | array of string |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Threat Actor Detail",
              "id": "65f21b4e-cc51-50d2-b63d-4fbdf6f4caa4",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/threat-actors/:threat_actor_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "threat-actors",
                    ":threat_actor_id"
                  ],
                  "variable": [
                    {
                      "key": "threat_actor_id",
                      "value": "<threat_actor_id>",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo CTI Threat Actor Detail API**\n\nReturns one threat actor profile.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `aliases` | array of string |  |\n| `date_updated` | string | date-time |\n| `date_first_seen` | string | date-time |\n| `date_last_seen` | string | date-time |\n| `is_active` | boolean |  |\n| `actor_size` | string |  |\n| `actor_types` | array of string |  |\n| `actor_sophistication` | string |  |\n| `actor_specializations` | array of string |  |\n| `description` | string |  |\n| `law_enforcement` | string |  |\n| `contact_info` | object |  |\n| `social_media` | object |  |\n| `websites` | array of string |  |\n| `payment_info` | object |  |\n| `origin_countries` | array of string |  |\n| `leak_names` | array of string |  |\n| `forum_names` | array of string |  |\n| `market_names` | array of string |  |\n| `forum_market_usernames` | array of string |  |\n| `targeted_regions` | array of string |  |\n| `targeted_countries` | array of string |  |\n| `targeted_industries` | array of string |  |\n| `targeted_organizations` | array of string |  |\n| `cves_used` | array of string |  |\n| `tools_used` | array of string |  |\n\n> No live example: the DEMO account has no data for this endpoint yet, or it returned an error during testing. The response shape is described above."
              },
              "response": []
            },
            {
              "name": "Most Actor Hosting Countries by Threat Actors",
              "id": "7b54952e-c690-5830-9f30-8c4f85dff5f5",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/threat-actors/stats/most-actor-hosting-countries?size=5",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "threat-actors",
                    "stats",
                    "most-actor-hosting-countries"
                  ],
                  "query": [
                    {
                      "key": "size",
                      "value": "5",
                      "description": "Min `1`, max `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Most Actor Hosting Countries by Threat Actors API**\n\nCountries hosting the most threat actors.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n| `origin_country` | string |  |"
              },
              "response": []
            },
            {
              "name": "Most Targeted Countries by Threat Actors",
              "id": "b9da7096-f324-52cd-bd62-273d2bf0bcb7",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/threat-actors/stats/most-targeted-countries?size=5",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "threat-actors",
                    "stats",
                    "most-targeted-countries"
                  ],
                  "query": [
                    {
                      "key": "size",
                      "value": "5",
                      "description": "Min `1`, max `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Most Targeted Countries by Threat Actors API**\n\nCountries most targeted by threat actors (`size`: number of rows).\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n| `target_country` | string |  |"
              },
              "response": []
            },
            {
              "name": "Most Targeted Industries by Threat Actors",
              "id": "b762a705-5019-5346-af1e-a093ceb102eb",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/threat-actors/stats/most-targeted-industries?size=5",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "threat-actors",
                    "stats",
                    "most-targeted-industries"
                  ],
                  "query": [
                    {
                      "key": "size",
                      "value": "5",
                      "description": "Min `1`, max `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Most Targeted Industries by Threat Actors API**\n\nIndustries most targeted by threat actors.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n| `target_industry` | string |  |"
              },
              "response": []
            },
            {
              "name": "Most Targeted Organizations by Threat Actors",
              "id": "e6a50223-04e5-51b0-82b7-6d364845dcbb",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/threat-actors/stats/most-targeted-organizations?size=5",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "threat-actors",
                    "stats",
                    "most-targeted-organizations"
                  ],
                  "query": [
                    {
                      "key": "size",
                      "value": "5",
                      "description": "Min `1`, max `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Most Targeted Organizations by Threat Actors API**\n\nOrganizations most targeted by threat actors.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n| `target_organization` | string |  |"
              },
              "response": []
            },
            {
              "name": "Most Used CVEs by Threat Actors",
              "id": "dd58ee09-dbfb-5947-8f4a-a51d06a26371",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/threat-actors/stats/most-used-cves?size=5",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "threat-actors",
                    "stats",
                    "most-used-cves"
                  ],
                  "query": [
                    {
                      "key": "size",
                      "value": "5",
                      "description": "Min `1`, max `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Most Used CVEs by Threat Actors API**\n\nCVEs most used by threat actors.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n| `cve` | string |  |"
              },
              "response": []
            },
            {
              "name": "Most Used Tools by Threat Actors",
              "id": "10fde485-b1f6-568b-a237-24135c0e64ed",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/threat-actors/stats/most-used-tools?size=5",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "threat-actors",
                    "stats",
                    "most-used-tools"
                  ],
                  "query": [
                    {
                      "key": "size",
                      "value": "5",
                      "description": "Min `1`, max `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Most Used Tools by Threat Actors API**\n\nTools most used by threat actors.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `count` | integer |  |\n| `tool` | string |  |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Security News",
          "id": "5aa71f06-8aa5-58d9-b3a2-008641804aea",
          "description": "Curated cybersecurity news.",
          "item": [
            {
              "name": "Security News Search",
              "id": "05b69b13-09dd-52cf-a175-aa3715722a5b",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/news/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "news",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo CTI Security News Search API**\n\nSearches curated cybersecurity news.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"title\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"title\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`** — 11 fields\n\n- `title`: The article's headline; the platform's news search box matches words in it.\n- `source`: The publisher of the article, such as `Bleeping Computer`, `The Hacker News` or `Security Affairs`; a few records hold the article's address instead.\n- `tags`: Topic tags of the article, in lower case with hyphens, such as `zero-day`, `active-exploitation` or `cisa`; they are the tag chips on the article cards.\n- `country`: Countries the article names as targets (TARGET COUNTRY), as English country names such as `Germany` rather than codes.\n- `industry`: Industries the article names as targets (TARGET INDUSTRY), as sector names such as `Education` or `Financial and Insurance Activities`.\n- `organization`: Organizations the article names as targets (TARGET ORGANIZATION).\n- `cve_vendor`: Vendor names linked to the CVEs in the article (VENDOR), in lower case with underscores, such as `microsoft` or `fortinet`.\n- `cve_product`: Product names linked to the CVEs in the article (PRODUCT), usually in lower case with underscores, such as `chrome` or `linux_kernel`.\n- `cve_id`: CVE IDs mentioned in the article, such as `CVE-2025-59718` (CVE in the article's side panel).\n- `threat_actor`: Threat actors the article names (THREAT ACTOR), such as `ShinyHunters`.\n- `related_issue_types`: Issue types the article is linked to, as a list of strings; empty on every article in the samples.\n\n**`eq`, `exists`** — 1 field\n\n- `featured`: Boolean flag for featured articles; `false` on every article in the samples.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 1 field\n\n- `publish_date`: When the article was published (UTC date-time); the news menu groups articles by it under TODAY and LAST 7 DAYS.\n\nSortable fields:\n\n- `title`: The article's headline; the platform's news search box matches words in it.\n- `source`: The publisher of the article, such as `Bleeping Computer`, `The Hacker News` or `Security Affairs`; a few records hold the article's address instead.\n- `publish_date`: When the article was published (UTC date-time); the news menu groups articles by it under TODAY and LAST 7 DAYS.\n- `tags`: Topic tags of the article, in lower case with hyphens, such as `zero-day`, `active-exploitation` or `cisa`; they are the tag chips on the article cards.\n- `country`: Countries the article names as targets (TARGET COUNTRY), as English country names such as `Germany` rather than codes.\n- `industry`: Industries the article names as targets (TARGET INDUSTRY), as sector names such as `Education` or `Financial and Insurance Activities`.\n- `organization`: Organizations the article names as targets (TARGET ORGANIZATION).\n- `cve_vendor`: Vendor names linked to the CVEs in the article (VENDOR), in lower case with underscores, such as `microsoft` or `fortinet`.\n- `cve_product`: Product names linked to the CVEs in the article (PRODUCT), usually in lower case with underscores, such as `chrome` or `linux_kernel`.\n- `cve_id`: CVE IDs mentioned in the article, such as `CVE-2025-59718` (CVE in the article's side panel).\n- `featured`: Boolean flag for featured articles; `false` on every article in the samples.\n- `threat_actor`: Threat actors the article names (THREAT ACTOR), such as `ShinyHunters`.\n- `related_issue_types`: Issue types the article is linked to, as a list of strings; empty on every article in the samples.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].title` | string |  |\n| `results[].image` | string |  |\n| `results[].source` | string |  |\n| `results[].source_url` | string |  |\n| `results[].publish_date` | string | date-time |\n| `results[].tags` | array of string |  |\n| `results[].country` | array of string |  |\n| `results[].industry` | array of string |  |\n| `results[].organization` | array of string |  |\n| `results[].cve_vendor` | array of string |  |\n| `results[].cve_product` | array of string |  |\n| `results[].cve_id` | array of string |  |\n| `results[].featured` | boolean |  |\n| `results[].threat_actor` | array of string |  |\n| `results[].related_issue_types` | array of string |  |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Security News Detail",
              "id": "7e157413-e0e0-5bbf-9390-3e25623fc2ad",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/cti/news/:id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "cti",
                    "news",
                    ":id"
                  ],
                  "variable": [
                    {
                      "key": "id",
                      "value": "6ab129afa012d715b0d5c21f",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo CTI Security News Detail API**\n\nReturns one news item.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `title` | string |  |\n| `content` | string |  |\n| `image` | string |  |\n| `source` | string |  |\n| `source_url` | string |  |\n| `publish_date` | string | date-time |\n| `tags` | array of string |  |\n| `country` | array of string |  |\n| `industry` | array of string |  |\n| `organization` | array of string |  |\n| `cve_vendor` | array of string |  |\n| `cve_product` | array of string |  |\n| `cve_id` | array of string |  |\n| `featured` | boolean |  |\n| `threat_actor` | array of string |  |\n| `related_issue_types` | array of string |  |"
              },
              "response": []
            }
          ]
        }
      ]
    },
    {
      "name": "BRP",
      "id": "880a96fa-999e-5650-9f91-77ec1fe5a3ae",
      "description": "Brand Risk Protection: domains that imitate your brand. **Suspicious domains** are candidates for review; approved ones become **fraudulent domains** and are monitored.",
      "item": [
        {
          "name": "Settings",
          "id": "f1d6b0a5-22d1-5037-ba99-1888a1258db5",
          "description": "Brand Risk Protection settings.",
          "item": [
            {
              "name": "Fraudulent Settings Detail",
              "id": "ea5e9ada-952e-59ce-a0d9-43b3de2f511e",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-settings",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-settings"
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Settings Detail API**\n\nReturns the Brand Risk Protection settings: `ignored_domains` are never reported.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `ignored_domains` | array of string |  |"
              },
              "response": []
            },
            {
              "name": "Fraudulent Settings Update",
              "id": "b0c808ea-7940-5c0c-8f15-32c110169403",
              "request": {
                "method": "PUT",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-settings",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-settings"
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Settings Update API**\n\nReplaces the Brand Risk Protection settings. Send the **full** `ignored_domains` list.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `ignored_domains` | array | yes |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `ignored_domains` | array of string |  |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"ignored_domains\": []\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            }
          ]
        },
        {
          "name": "Fraudulent Domains",
          "id": "1ff500fd-a0b8-5880-8225-565b0de108df",
          "description": "Monitored fraudulent domains, their scans, history and risk score.",
          "item": [
            {
              "name": "Fraudulent Domain Search",
              "id": "f52588ae-2db6-5632-bf20-e6f7a32ae81d",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Search API**\n\nSearches your monitored fraudulent domains by name, type, risk score and indicators.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fraudulent\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"fraudulent\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `exists`** — 7 fields\n\n- `fraudulent_type`: Whether the name is a `domain` or a `subdomain` (Domain and Subdomain in the TYPE filter); each detection rule looks at one or the other.\n- `monitoring_indicator.dns`: DNS indicator: `true` when the domain's DNS lookup at its last check returned records (such as A, NS or SOA; an address record is not required); `false` when the name did not exist (NXDOMAIN); null when there is no DNS result. The INDICATORS filter's DNS option finds the domains where it is `true`.\n- `monitoring_indicator.dns_mx`: DNS MX indicator: `true` when the domain had an MX (mail exchanger) record at its last check; `false` when it had none; null when there is no DNS result. The INDICATORS filter's DNS MX option finds the domains where it is `true`.\n- `monitoring_indicator.ssl`: SSL indicator: `true` when a TLS connection to the domain on port 443 succeeded and returned a certificate at its last check; `false` when it failed (for example refused or not resolved); null when there is no result for that check. The INDICATORS filter's SSL option finds the domains where it is `true`.\n- `monitoring_indicator.http`: HTTP indicator: `true` when the domain answered an HTTP request at its last check, after following redirects (in the samples a final 525 error status also counted); `false` when it did not (for example because the name did not resolve); null when there is no result for that check. The INDICATORS filter's HTTP option finds the domains where it is `true`.\n- `is_login_page`: `true` when the domain's site has a login page; the FRAUDULENT DOMAINS list shows a Login Page icon next to its name.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 5 fields\n\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `added_date`: When the domain was added to the fraudulent list (UTC date-time), that is when it was marked as fraudulent, by you or by a rule with Auto Approval.\n- `seems_inactive_first_seen`: When the domain was first found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n- `seems_inactive_last_seen`: When the domain was most recently found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 3 fields\n\n- `fraudulent`: The fraudulent domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history.id`: The ID of a detection rule that found the domain, a 24-character hexadecimal string; it is the rule's `id` in Fraudulent Rule Search. Filter on it to list the domains one rule detected.\n\nSortable fields:\n\n- `fraudulent`: The fraudulent domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history`: The detection rules that found the domain, one entry per rule with the rule's `id`, its name (`rule`), the `detection_date` and the `enabled` and `deleted` flags; the lists show it as RULES. It can be sorted on but not filtered: filter on `detection_history.id` instead.\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `monitoring_indicator`: The four indicator flags `dns`, `dns_mx`, `ssl` and `http` as one object (null when there is no check result); the lists show them as the INDICATORS icons. It can be sorted on but not filtered: filter on `monitoring_indicator.dns`, `monitoring_indicator.dns_mx`, `monitoring_indicator.ssl` or `monitoring_indicator.http` instead.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `added_date`: When the domain was added to the fraudulent list (UTC date-time), that is when it was marked as fraudulent, by you or by a rule with Auto Approval.\n- `is_login_page`: `true` when the domain's site has a login page; the FRAUDULENT DOMAINS list shows a Login Page icon next to its name.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n- `seems_inactive_first_seen`: When the domain was first found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n- `seems_inactive_last_seen`: When the domain was most recently found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].fraudulent` | string |  |\n| `results[].fraudulent_unicode` | string |  |\n| `results[].fraudulent_type` | string | One of `domain`, `subdomain` |\n| `results[].tags` | array of string |  |\n| `results[].detection_history` | array of object |  |\n| `results[].first_detection_date` | string | date-time |\n| `results[].monitoring_indicator` | object |  |\n| `results[].risk_score` | integer |  |\n| `results[].screenshot` | string |  |\n| `results[].thumbnail` | string |  |\n| `results[].added_date` | string | date-time |\n| `results[].is_login_page` | boolean |  |\n| `results[].seems_inactive` | boolean |  |\n| `results[].seems_inactive_first_seen` | string | date-time |\n| `results[].seems_inactive_last_seen` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Export",
              "id": "02c3554e-0975-5120-b43f-61d8b8206926",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    "search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fraudulent\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"fraudulent\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `exists`** — 7 fields\n\n- `fraudulent_type`: Whether the name is a `domain` or a `subdomain` (Domain and Subdomain in the TYPE filter); each detection rule looks at one or the other.\n- `monitoring_indicator.dns`: DNS indicator: `true` when the domain's DNS lookup at its last check returned records (such as A, NS or SOA; an address record is not required); `false` when the name did not exist (NXDOMAIN); null when there is no DNS result. The INDICATORS filter's DNS option finds the domains where it is `true`.\n- `monitoring_indicator.dns_mx`: DNS MX indicator: `true` when the domain had an MX (mail exchanger) record at its last check; `false` when it had none; null when there is no DNS result. The INDICATORS filter's DNS MX option finds the domains where it is `true`.\n- `monitoring_indicator.ssl`: SSL indicator: `true` when a TLS connection to the domain on port 443 succeeded and returned a certificate at its last check; `false` when it failed (for example refused or not resolved); null when there is no result for that check. The INDICATORS filter's SSL option finds the domains where it is `true`.\n- `monitoring_indicator.http`: HTTP indicator: `true` when the domain answered an HTTP request at its last check, after following redirects (in the samples a final 525 error status also counted); `false` when it did not (for example because the name did not resolve); null when there is no result for that check. The INDICATORS filter's HTTP option finds the domains where it is `true`.\n- `is_login_page`: `true` when the domain's site has a login page; the FRAUDULENT DOMAINS list shows a Login Page icon next to its name.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 5 fields\n\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `added_date`: When the domain was added to the fraudulent list (UTC date-time), that is when it was marked as fraudulent, by you or by a rule with Auto Approval.\n- `seems_inactive_first_seen`: When the domain was first found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n- `seems_inactive_last_seen`: When the domain was most recently found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 3 fields\n\n- `fraudulent`: The fraudulent domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history.id`: The ID of a detection rule that found the domain, a 24-character hexadecimal string; it is the rule's `id` in Fraudulent Rule Search. Filter on it to list the domains one rule detected.\n\nSortable fields:\n\n- `fraudulent`: The fraudulent domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history`: The detection rules that found the domain, one entry per rule with the rule's `id`, its name (`rule`), the `detection_date` and the `enabled` and `deleted` flags; the lists show it as RULES. It can be sorted on but not filtered: filter on `detection_history.id` instead.\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `monitoring_indicator`: The four indicator flags `dns`, `dns_mx`, `ssl` and `http` as one object (null when there is no check result); the lists show them as the INDICATORS icons. It can be sorted on but not filtered: filter on `monitoring_indicator.dns`, `monitoring_indicator.dns_mx`, `monitoring_indicator.ssl` or `monitoring_indicator.http` instead.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `added_date`: When the domain was added to the fraudulent list (UTC date-time), that is when it was marked as fraudulent, by you or by a rule with Auto Approval.\n- `is_login_page`: `true` when the domain's site has a login page; the FRAUDULENT DOMAINS list shows a Login Page icon next to its name.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n- `seems_inactive_first_seen`: When the domain was first found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n- `seems_inactive_last_seen`: When the domain was most recently found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Detail",
              "id": "de1b6c9d-9567-52e7-a99a-a94382e69925",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id"
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Detail API**\n\nReturns one fraudulent domain with its latest data and risk score.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `fraudulent` | string |  |\n| `fraudulent_unicode` | string |  |\n| `fraudulent_type` | string | One of `domain`, `subdomain` |\n| `detection_history` | array of object |  |\n| `first_detection_date` | string | date-time |\n| `added_date` | string | date-time |\n| `monitoring_indicator` | object |  |\n| `risk_score` | integer |  |\n| `screenshot` | string |  |\n| `thumbnail` | string |  |\n| `is_login_page` | boolean |  |\n| `seems_inactive` | boolean |  |\n| `seems_inactive_first_seen` | string | date-time |\n| `seems_inactive_last_seen` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Delete",
              "id": "4d136f6e-2c0c-5bb3-a9d8-83b32389e481",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/search:delete",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    "search:delete"
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Delete API**\n\nStops monitoring every fraudulent domain matching `filters`.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fraudulent\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"fraudulent\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `exists`** — 7 fields\n\n- `fraudulent_type`: Whether the name is a `domain` or a `subdomain` (Domain and Subdomain in the TYPE filter); each detection rule looks at one or the other.\n- `monitoring_indicator.dns`: DNS indicator: `true` when the domain's DNS lookup at its last check returned records (such as A, NS or SOA; an address record is not required); `false` when the name did not exist (NXDOMAIN); null when there is no DNS result. The INDICATORS filter's DNS option finds the domains where it is `true`.\n- `monitoring_indicator.dns_mx`: DNS MX indicator: `true` when the domain had an MX (mail exchanger) record at its last check; `false` when it had none; null when there is no DNS result. The INDICATORS filter's DNS MX option finds the domains where it is `true`.\n- `monitoring_indicator.ssl`: SSL indicator: `true` when a TLS connection to the domain on port 443 succeeded and returned a certificate at its last check; `false` when it failed (for example refused or not resolved); null when there is no result for that check. The INDICATORS filter's SSL option finds the domains where it is `true`.\n- `monitoring_indicator.http`: HTTP indicator: `true` when the domain answered an HTTP request at its last check, after following redirects (in the samples a final 525 error status also counted); `false` when it did not (for example because the name did not resolve); null when there is no result for that check. The INDICATORS filter's HTTP option finds the domains where it is `true`.\n- `is_login_page`: `true` when the domain's site has a login page; the FRAUDULENT DOMAINS list shows a Login Page icon next to its name.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 5 fields\n\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `added_date`: When the domain was added to the fraudulent list (UTC date-time), that is when it was marked as fraudulent, by you or by a rule with Auto Approval.\n- `seems_inactive_first_seen`: When the domain was first found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n- `seems_inactive_last_seen`: When the domain was most recently found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 3 fields\n\n- `fraudulent`: The fraudulent domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history.id`: The ID of a detection rule that found the domain, a 24-character hexadecimal string; it is the rule's `id` in Fraudulent Rule Search. Filter on it to list the domains one rule detected.\n\nSortable fields:\n\n- `fraudulent`: The fraudulent domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history`: The detection rules that found the domain, one entry per rule with the rule's `id`, its name (`rule`), the `detection_date` and the `enabled` and `deleted` flags; the lists show it as RULES. It can be sorted on but not filtered: filter on `detection_history.id` instead.\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `monitoring_indicator`: The four indicator flags `dns`, `dns_mx`, `ssl` and `http` as one object (null when there is no check result); the lists show them as the INDICATORS icons. It can be sorted on but not filtered: filter on `monitoring_indicator.dns`, `monitoring_indicator.dns_mx`, `monitoring_indicator.ssl` or `monitoring_indicator.http` instead.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `added_date`: When the domain was added to the fraudulent list (UTC date-time), that is when it was marked as fraudulent, by you or by a rule with Auto Approval.\n- `is_login_page`: `true` when the domain's site has a login page; the FRAUDULENT DOMAINS list shows a Login Page icon next to its name.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n- `seems_inactive_first_seen`: When the domain was first found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n- `seems_inactive_last_seen`: When the domain was most recently found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with `seems_inactive` true.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `deleted_fraudulent_count` | integer |  |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fraudulent\",\n        \"type\": \"eq\",\n        \"value\": \"no-such-domain-postman-docs.example\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Instant Scan",
              "id": "09ccfbbe-4246-513e-9feb-377733123c38",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id/instant-scan",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id",
                    "instant-scan"
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Instant Scan API**\n\nStarts an on-demand scan of a fraudulent domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `triggered` | boolean |  |"
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain DNS History",
              "id": "17e679db-68ac-5b0e-9e8f-07841d09c6ce",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id/dns-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id",
                    "dns-history"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "100",
                      "description": "Min `25`, max `100`. Default `100`.",
                      "disabled": true
                    }
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain DNS History API**\n\nReturns the DNS history recorded for a fraudulent domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].result` | object |  |\n| `results[].status` | boolean |  |\n| `results[].check_date` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Latest Scan",
              "id": "509f0f74-db53-591d-bf95-d1860028ebdd",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id/latest-scan",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id",
                    "latest-scan"
                  ],
                  "query": [
                    {
                      "key": "scope",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Latest Scan API**\n\nReturns the latest scan of a fraudulent domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `requested_scopes` | array of string |  |\n| `monitored_scopes` | array of string |  |\n| `results` | array of object |  |\n| `check_date` | string | date-time |\n| `results[].result` | object |  |\n| `results[].status` | boolean |  |\n| `results[].scope` | string | One of `whois`, `dns`, `ssl`, `port_scan`, `webdata`, `ipwhois`, `http`, `ipdns` |"
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Port Scan History",
              "id": "d55b9f5c-1798-5b59-8235-8f14132f3e74",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id/port-scan-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id",
                    "port-scan-history"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "100",
                      "description": "Min `25`, max `100`. Default `100`.",
                      "disabled": true
                    }
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Port Scan History API**\n\nReturns the port scan history recorded for a fraudulent domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].result` | object |  |\n| `results[].status` | boolean |  |\n| `results[].check_date` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain SSL History",
              "id": "09ceae9c-aba5-581e-9062-ad6055ee740b",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id/ssl-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id",
                    "ssl-history"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "100",
                      "description": "Min `25`, max `100`. Default `100`.",
                      "disabled": true
                    }
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain SSL History API**\n\nReturns the SSL certificate history recorded for a fraudulent domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].result` | object |  |\n| `results[].status` | boolean |  |\n| `results[].check_date` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Webdata History",
              "id": "19c5e4fa-8bf7-5d97-a101-b022fc4c4453",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id/webdata-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id",
                    "webdata-history"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "100",
                      "description": "Min `25`, max `100`. Default `100`.",
                      "disabled": true
                    }
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Webdata History API**\n\nReturns the web data (page content, technologies, headers) history recorded for a fraudulent domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].result` | object |  |\n| `results[].status` | boolean |  |\n| `results[].check_date` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Whois History",
              "id": "49471d3a-c595-5a8e-bd49-c960ff2a141d",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id/whois-history",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id",
                    "whois-history"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "100",
                      "description": "Min `25`, max `100`. Default `100`.",
                      "disabled": true
                    }
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Whois History API**\n\nReturns the WHOIS history recorded for a fraudulent domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].result` | object |  |\n| `results[].status` | boolean |  |\n| `results[].check_date` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Instant Snapshot",
              "id": "7d9f0641-7e5a-5419-9dfa-2fdd99cd8337",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id/instant-snapshot",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id",
                    "instant-snapshot"
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Instant Snapshot API**\n\nRecalculates the fraudulent domain snapshot now.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `triggered` | boolean |  |"
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Latest Snapshot",
              "id": "9c684485-8825-51c9-8367-bb96bc1760cf",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id/latest-snapshot",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id",
                    "latest-snapshot"
                  ],
                  "query": [
                    {
                      "key": "stats",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Latest Snapshot API**\n\nLatest summary of a fraudulent domain.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `snapshot` | object |  |\n| `date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Risk Score Timeline",
              "id": "458ee4e4-f199-5014-a142-cd305c2cb9e6",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/:fraudulent_id/risk-score-timeline?interval=weekly",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    ":fraudulent_id",
                    "risk-score-timeline"
                  ],
                  "query": [
                    {
                      "key": "interval",
                      "value": "weekly",
                      "description": "One of: `daily`, `weekly`, `monthly`."
                    }
                  ],
                  "variable": [
                    {
                      "key": "fraudulent_id",
                      "value": "6a5063f0528bfba848d80a75",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Risk Score Timeline API**\n\nTime series of a fraudulent domain's risk score.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `date` | string | date |\n| `score` | integer |  |"
              },
              "response": []
            },
            {
              "name": "Fraudulent Domain Type Stats",
              "id": "ad13c259-c215-5fcb-b97a-618f6515fec3",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-domains/stats/type",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-domains",
                    "stats",
                    "type"
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Domain Type Stats API**\n\nCounts fraudulent domains per type (`domain`, `subdomain`).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `domain` | integer |  |\n| `subdomain` | integer |  |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Suspicious Domains",
          "id": "fa28ab47-a23c-552e-ab74-418354695968",
          "description": "Candidates found by your fraudulent rules. Each is `in_review`, `approved` or `ignored`.",
          "item": [
            {
              "name": "Suspicious Domain Search",
              "id": "ab5cc82b-0922-5c9a-85c4-36b4d0e1e371",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/suspicious-domains/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "suspicious-domains",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo BRP Suspicious Domain Search API**\n\nSearches suspicious domains (candidates found by your fraudulent rules) and their state.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"fraudulent\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `exists`** — 7 fields\n\n- `fraudulent_type`: Whether the name is a `domain` or a `subdomain` (Domain and Subdomain in the TYPE filter); each detection rule looks at one or the other.\n- `state`: The review state: `in_review` (on the SUSPICIOUS DOMAINS list, waiting for your decision), `approved` (marked as fraudulent and moved to the fraudulent list) or `ignored` (dismissed, on Ignored Domains); the API also lists `initial`, which was not seen in the data. Without a `state` filter the search is not limited to one state: it returned both `in_review` and `approved` domains.\n- `monitoring_indicator.dns`: DNS indicator: `true` when the domain's DNS lookup at its last check returned records (such as A, NS or SOA; an address record is not required); `false` when the name did not exist (NXDOMAIN); null when there is no DNS result. The INDICATORS filter's DNS option finds the domains where it is `true`.\n- `monitoring_indicator.dns_mx`: DNS MX indicator: `true` when the domain had an MX (mail exchanger) record at its last check; `false` when it had none; null when there is no DNS result. The INDICATORS filter's DNS MX option finds the domains where it is `true`.\n- `monitoring_indicator.ssl`: SSL indicator: `true` when a TLS connection to the domain on port 443 succeeded and returned a certificate at its last check; `false` when it failed (for example refused or not resolved); null when there is no result for that check. The INDICATORS filter's SSL option finds the domains where it is `true`.\n- `monitoring_indicator.http`: HTTP indicator: `true` when the domain answered an HTTP request at its last check, after following redirects (in the samples a final 525 error status also counted); `false` when it did not (for example because the name did not resolve); null when there is no result for that check. The INDICATORS filter's HTTP option finds the domains where it is `true`.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 4 fields\n\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `ignore_date`: When the domain was ignored (UTC date-time), shown as IGNORED DATE; empty if it was never ignored. A domain restored from Ignored Domains keeps this date, so a filter on it can also match domains that are back in review.\n- `approve_date`: When the domain was marked as fraudulent (UTC date-time), shown as APPROVE DATE; empty on domains that are still waiting for review.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 3 fields\n\n- `fraudulent`: The suspicious domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history.id`: The ID of a detection rule that found the domain, a 24-character hexadecimal string; it is the rule's `id` in Fraudulent Rule Search. Filter on it to list the domains one rule detected.\n\nSortable fields:\n\n- `fraudulent`: The suspicious domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history`: The detection rules that found the domain, one entry per rule with the rule's `id`, its name (`rule`), the `detection_date` and the `enabled` and `deleted` flags; the lists show it as RULES. It can be sorted on but not filtered: filter on `detection_history.id` instead.\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `monitoring_indicator`: The four indicator flags `dns`, `dns_mx`, `ssl` and `http` as one object (null when there is no check result); the lists show them as the INDICATORS icons. It can be sorted on but not filtered: filter on `monitoring_indicator.dns`, `monitoring_indicator.dns_mx`, `monitoring_indicator.ssl` or `monitoring_indicator.http` instead.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `ignore_date`: When the domain was ignored (UTC date-time), shown as IGNORED DATE; empty if it was never ignored. A domain restored from Ignored Domains keeps this date, so a filter on it can also match domains that are back in review.\n- `approve_date`: When the domain was marked as fraudulent (UTC date-time), shown as APPROVE DATE; empty on domains that are still waiting for review.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].fraudulent` | string |  |\n| `results[].fraudulent_unicode` | string |  |\n| `results[].fraudulent_type` | string | One of `domain`, `subdomain` |\n| `results[].state` | string | One of `initial`, `in_review`, `approved`, `ignored` |\n| `results[].tags` | array of string |  |\n| `results[].detection_history` | array of object |  |\n| `results[].first_detection_date` | string | date-time |\n| `results[].monitoring_indicator` | object |  |\n| `results[].risk_score` | integer |  |\n| `results[].seems_inactive` | boolean |  |\n| `results[].approve_date` | string | date-time |\n| `results[].ignore_date` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Suspicious Domain Export",
              "id": "54f5c86f-bdfe-57ba-8de5-6018db387ac8",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/suspicious-domains/search:export?format=csv",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "suspicious-domains",
                    "search:export"
                  ],
                  "query": [
                    {
                      "key": "format",
                      "value": "csv",
                      "description": "One of: `json`, `csv`."
                    }
                  ]
                },
                "description": "**Deepinfo BRP Suspicious Domain Export API**\n\nExports every record matching `filters` (no pagination). `format=csv` returns CSV text; `format=json` returns a JSON array. Large exports can time out: narrow them with filters.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"state\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"fraudulent\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `exists`** — 7 fields\n\n- `fraudulent_type`: Whether the name is a `domain` or a `subdomain` (Domain and Subdomain in the TYPE filter); each detection rule looks at one or the other.\n- `state`: The review state: `in_review` (on the SUSPICIOUS DOMAINS list, waiting for your decision), `approved` (marked as fraudulent and moved to the fraudulent list) or `ignored` (dismissed, on Ignored Domains); the API also lists `initial`, which was not seen in the data. Without a `state` filter the search is not limited to one state: it returned both `in_review` and `approved` domains.\n- `monitoring_indicator.dns`: DNS indicator: `true` when the domain's DNS lookup at its last check returned records (such as A, NS or SOA; an address record is not required); `false` when the name did not exist (NXDOMAIN); null when there is no DNS result. The INDICATORS filter's DNS option finds the domains where it is `true`.\n- `monitoring_indicator.dns_mx`: DNS MX indicator: `true` when the domain had an MX (mail exchanger) record at its last check; `false` when it had none; null when there is no DNS result. The INDICATORS filter's DNS MX option finds the domains where it is `true`.\n- `monitoring_indicator.ssl`: SSL indicator: `true` when a TLS connection to the domain on port 443 succeeded and returned a certificate at its last check; `false` when it failed (for example refused or not resolved); null when there is no result for that check. The INDICATORS filter's SSL option finds the domains where it is `true`.\n- `monitoring_indicator.http`: HTTP indicator: `true` when the domain answered an HTTP request at its last check, after following redirects (in the samples a final 525 error status also counted); `false` when it did not (for example because the name did not resolve); null when there is no result for that check. The INDICATORS filter's HTTP option finds the domains where it is `true`.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 4 fields\n\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `ignore_date`: When the domain was ignored (UTC date-time), shown as IGNORED DATE; empty if it was never ignored. A domain restored from Ignored Domains keeps this date, so a filter on it can also match domains that are back in review.\n- `approve_date`: When the domain was marked as fraudulent (UTC date-time), shown as APPROVE DATE; empty on domains that are still waiting for review.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 3 fields\n\n- `fraudulent`: The suspicious domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history.id`: The ID of a detection rule that found the domain, a 24-character hexadecimal string; it is the rule's `id` in Fraudulent Rule Search. Filter on it to list the domains one rule detected.\n\nSortable fields:\n\n- `fraudulent`: The suspicious domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history`: The detection rules that found the domain, one entry per rule with the rule's `id`, its name (`rule`), the `detection_date` and the `enabled` and `deleted` flags; the lists show it as RULES. It can be sorted on but not filtered: filter on `detection_history.id` instead.\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `monitoring_indicator`: The four indicator flags `dns`, `dns_mx`, `ssl` and `http` as one object (null when there is no check result); the lists show them as the INDICATORS icons. It can be sorted on but not filtered: filter on `monitoring_indicator.dns`, `monitoring_indicator.dns_mx`, `monitoring_indicator.ssl` or `monitoring_indicator.http` instead.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `ignore_date`: When the domain was ignored (UTC date-time), shown as IGNORED DATE; empty if it was never ignored. A domain restored from Ignored Domains keeps this date, so a filter on it can also match domains that are back in review.\n- `approve_date`: When the domain was marked as fraudulent (UTC date-time), shown as APPROVE DATE; empty on domains that are still waiting for review.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].fraudulent` | string |  |\n| `results[].fraudulent_unicode` | string |  |\n| `results[].fraudulent_type` | string | One of `domain`, `subdomain` |\n| `results[].state` | string | One of `initial`, `in_review`, `approved`, `ignored` |\n| `results[].tags` | array of string |  |\n| `results[].detection_history` | array of object |  |\n| `results[].first_detection_date` | string | date-time |\n| `results[].monitoring_indicator` | object |  |\n| `results[].risk_score` | integer |  |\n| `results[].seems_inactive` | boolean |  |\n| `results[].approve_date` | string | date-time |\n| `results[].ignore_date` | string | date-time |\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Suspicious Domain Detail",
              "id": "6a160cd4-757b-53a5-8dc2-da2ae70ffe74",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/suspicious-domains/:detected_fraudulent_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "suspicious-domains",
                    ":detected_fraudulent_id"
                  ],
                  "variable": [
                    {
                      "key": "detected_fraudulent_id",
                      "value": "3a66820307137345a1fdf0497c2e6635",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Suspicious Domain Detail API**\n\nReturns one suspicious domain with the rule that detected it.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `fraudulent` | string |  |\n| `fraudulent_unicode` | string |  |\n| `fraudulent_type` | string | One of `domain`, `subdomain` |\n| `state` | string | One of `in_review`, `approved`, `ignored` |\n| `detection_history` | array of object |  |\n| `first_detection_date` | string | date-time |\n| `monitoring_indicator` | object |  |\n| `risk_score` | integer |  |\n| `monitoring` | object |  |\n| `approve_date` | string | date-time |\n| `ignore_date` | string | date-time |\n| `seems_inactive` | boolean |  |"
              },
              "response": []
            },
            {
              "name": "Suspicious Domain Approve",
              "id": "c72d903e-ea38-54ff-a364-f27fa85876e3",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/suspicious-domains/search:approve",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "suspicious-domains",
                    "search:approve"
                  ]
                },
                "description": "**Deepinfo BRP Suspicious Domain Approve API**\n\nApproves the suspicious domains that match `filters` (`approved`). Approved domains become **fraudulent domains** and are monitored.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fraudulent\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"fraudulent\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `exists`** — 6 fields\n\n- `fraudulent_type`: Whether the name is a `domain` or a `subdomain` (Domain and Subdomain in the TYPE filter); each detection rule looks at one or the other.\n- `monitoring_indicator.dns`: DNS indicator: `true` when the domain's DNS lookup at its last check returned records (such as A, NS or SOA; an address record is not required); `false` when the name did not exist (NXDOMAIN); null when there is no DNS result. The INDICATORS filter's DNS option finds the domains where it is `true`.\n- `monitoring_indicator.dns_mx`: DNS MX indicator: `true` when the domain had an MX (mail exchanger) record at its last check; `false` when it had none; null when there is no DNS result. The INDICATORS filter's DNS MX option finds the domains where it is `true`.\n- `monitoring_indicator.ssl`: SSL indicator: `true` when a TLS connection to the domain on port 443 succeeded and returned a certificate at its last check; `false` when it failed (for example refused or not resolved); null when there is no result for that check. The INDICATORS filter's SSL option finds the domains where it is `true`.\n- `monitoring_indicator.http`: HTTP indicator: `true` when the domain answered an HTTP request at its last check, after following redirects (in the samples a final 525 error status also counted); `false` when it did not (for example because the name did not resolve); null when there is no result for that check. The INDICATORS filter's HTTP option finds the domains where it is `true`.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 4 fields\n\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `ignore_date`: When the domain was ignored (UTC date-time), shown as IGNORED DATE; empty if it was never ignored. A domain restored from Ignored Domains keeps this date, so a filter on it can also match domains that are back in review.\n- `approve_date`: When the domain was marked as fraudulent (UTC date-time), shown as APPROVE DATE; empty on domains that are still waiting for review.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 3 fields\n\n- `fraudulent`: The suspicious domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history.id`: The ID of a detection rule that found the domain, a 24-character hexadecimal string; it is the rule's `id` in Fraudulent Rule Search. Filter on it to list the domains one rule detected.\n\nSortable fields:\n\n- `fraudulent`: The suspicious domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `state`: The review state: `in_review` (on the SUSPICIOUS DOMAINS list, waiting for your decision), `approved` (marked as fraudulent and moved to the fraudulent list) or `ignored` (dismissed, on Ignored Domains); the API also lists `initial`, which was not seen in the data. Without a `state` filter the search is not limited to one state: it returned both `in_review` and `approved` domains.\n- `detection_history`: The detection rules that found the domain, one entry per rule with the rule's `id`, its name (`rule`), the `detection_date` and the `enabled` and `deleted` flags; the lists show it as RULES. It can be sorted on but not filtered: filter on `detection_history.id` instead.\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `monitoring_indicator`: The four indicator flags `dns`, `dns_mx`, `ssl` and `http` as one object (null when there is no check result); the lists show them as the INDICATORS icons. It can be sorted on but not filtered: filter on `monitoring_indicator.dns`, `monitoring_indicator.dns_mx`, `monitoring_indicator.ssl` or `monitoring_indicator.http` instead.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `ignore_date`: When the domain was ignored (UTC date-time), shown as IGNORED DATE; empty if it was never ignored. A domain restored from Ignored Domains keeps this date, so a filter on it can also match domains that are back in review.\n- `approve_date`: When the domain was marked as fraudulent (UTC date-time), shown as APPROVE DATE; empty on domains that are still waiting for review.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fraudulent\",\n        \"type\": \"eq\",\n        \"value\": \"example-1168.com\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Suspicious Domain Ignore",
              "id": "1d9fb4ba-3c42-5411-850a-f192ca930865",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/suspicious-domains/search:ignore",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "suspicious-domains",
                    "search:ignore"
                  ]
                },
                "description": "**Deepinfo BRP Suspicious Domain Ignore API**\n\nIgnores the suspicious domains that match `filters` (`ignored`).\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fraudulent\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"fraudulent\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `exists`** — 6 fields\n\n- `fraudulent_type`: Whether the name is a `domain` or a `subdomain` (Domain and Subdomain in the TYPE filter); each detection rule looks at one or the other.\n- `monitoring_indicator.dns`: DNS indicator: `true` when the domain's DNS lookup at its last check returned records (such as A, NS or SOA; an address record is not required); `false` when the name did not exist (NXDOMAIN); null when there is no DNS result. The INDICATORS filter's DNS option finds the domains where it is `true`.\n- `monitoring_indicator.dns_mx`: DNS MX indicator: `true` when the domain had an MX (mail exchanger) record at its last check; `false` when it had none; null when there is no DNS result. The INDICATORS filter's DNS MX option finds the domains where it is `true`.\n- `monitoring_indicator.ssl`: SSL indicator: `true` when a TLS connection to the domain on port 443 succeeded and returned a certificate at its last check; `false` when it failed (for example refused or not resolved); null when there is no result for that check. The INDICATORS filter's SSL option finds the domains where it is `true`.\n- `monitoring_indicator.http`: HTTP indicator: `true` when the domain answered an HTTP request at its last check, after following redirects (in the samples a final 525 error status also counted); `false` when it did not (for example because the name did not resolve); null when there is no result for that check. The INDICATORS filter's HTTP option finds the domains where it is `true`.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 4 fields\n\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `ignore_date`: When the domain was ignored (UTC date-time), shown as IGNORED DATE; empty if it was never ignored. A domain restored from Ignored Domains keeps this date, so a filter on it can also match domains that are back in review.\n- `approve_date`: When the domain was marked as fraudulent (UTC date-time), shown as APPROVE DATE; empty on domains that are still waiting for review.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 3 fields\n\n- `fraudulent`: The suspicious domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history.id`: The ID of a detection rule that found the domain, a 24-character hexadecimal string; it is the rule's `id` in Fraudulent Rule Search. Filter on it to list the domains one rule detected.\n\nSortable fields:\n\n- `fraudulent`: The suspicious domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `state`: The review state: `in_review` (on the SUSPICIOUS DOMAINS list, waiting for your decision), `approved` (marked as fraudulent and moved to the fraudulent list) or `ignored` (dismissed, on Ignored Domains); the API also lists `initial`, which was not seen in the data. Without a `state` filter the search is not limited to one state: it returned both `in_review` and `approved` domains.\n- `detection_history`: The detection rules that found the domain, one entry per rule with the rule's `id`, its name (`rule`), the `detection_date` and the `enabled` and `deleted` flags; the lists show it as RULES. It can be sorted on but not filtered: filter on `detection_history.id` instead.\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `monitoring_indicator`: The four indicator flags `dns`, `dns_mx`, `ssl` and `http` as one object (null when there is no check result); the lists show them as the INDICATORS icons. It can be sorted on but not filtered: filter on `monitoring_indicator.dns`, `monitoring_indicator.dns_mx`, `monitoring_indicator.ssl` or `monitoring_indicator.http` instead.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `ignore_date`: When the domain was ignored (UTC date-time), shown as IGNORED DATE; empty if it was never ignored. A domain restored from Ignored Domains keeps this date, so a filter on it can also match domains that are back in review.\n- `approve_date`: When the domain was marked as fraudulent (UTC date-time), shown as APPROVE DATE; empty on domains that are still waiting for review.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fraudulent\",\n        \"type\": \"eq\",\n        \"value\": \"example-1168.com\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Suspicious Domain Revert",
              "id": "0ccacdc7-20dd-5076-b991-74fb1af95306",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/suspicious-domains/search:revert",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "suspicious-domains",
                    "search:revert"
                  ]
                },
                "description": "**Deepinfo BRP Suspicious Domain Revert API**\n\nReverts the suspicious domains that match `filters` to their previous, active state. Only states set by a user can be reverted.\n\nThe action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.\n\n> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | array |  | List of `{field, order}` |\n\n### Filtering\n\nExample body:\n\n```json\n{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fraudulent\",\n        \"type\": \"eq\",\n        \"value\": \"<value>\"\n      }\n    ]\n  },\n  \"sort\": [\n    {\n      \"field\": \"fraudulent\",\n      \"order\": \"desc\"\n    }\n  ]\n}\n```\n\nSee **Getting Started → Search & Filters** for the operators.\n\nSearchable fields, grouped by the operators they accept (measured against the API; sending another operator returns 400):\n\n**`eq`, `in`, `exists`** — 6 fields\n\n- `fraudulent_type`: Whether the name is a `domain` or a `subdomain` (Domain and Subdomain in the TYPE filter); each detection rule looks at one or the other.\n- `monitoring_indicator.dns`: DNS indicator: `true` when the domain's DNS lookup at its last check returned records (such as A, NS or SOA; an address record is not required); `false` when the name did not exist (NXDOMAIN); null when there is no DNS result. The INDICATORS filter's DNS option finds the domains where it is `true`.\n- `monitoring_indicator.dns_mx`: DNS MX indicator: `true` when the domain had an MX (mail exchanger) record at its last check; `false` when it had none; null when there is no DNS result. The INDICATORS filter's DNS MX option finds the domains where it is `true`.\n- `monitoring_indicator.ssl`: SSL indicator: `true` when a TLS connection to the domain on port 443 succeeded and returned a certificate at its last check; `false` when it failed (for example refused or not resolved); null when there is no result for that check. The INDICATORS filter's SSL option finds the domains where it is `true`.\n- `monitoring_indicator.http`: HTTP indicator: `true` when the domain answered an HTTP request at its last check, after following redirects (in the samples a final 525 error status also counted); `false` when it did not (for example because the name did not resolve); null when there is no result for that check. The INDICATORS filter's HTTP option finds the domains where it is `true`.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n**`eq`, `in`, `gte`, `lte`, `exists`** — 4 fields\n\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `ignore_date`: When the domain was ignored (UTC date-time), shown as IGNORED DATE; empty if it was never ignored. A domain restored from Ignored Domains keeps this date, so a filter on it can also match domains that are back in review.\n- `approve_date`: When the domain was marked as fraudulent (UTC date-time), shown as APPROVE DATE; empty on domains that are still waiting for review.\n\n**`eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`** — 3 fields\n\n- `fraudulent`: The suspicious domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `tags`: Tags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.\n- `detection_history.id`: The ID of a detection rule that found the domain, a 24-character hexadecimal string; it is the rule's `id` in Fraudulent Rule Search. Filter on it to list the domains one rule detected.\n\nSortable fields:\n\n- `fraudulent`: The suspicious domain or subdomain name in ASCII form, with internationalized names in punycode (starting with `xn--`); `fraudulent_unicode` in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.\n- `state`: The review state: `in_review` (on the SUSPICIOUS DOMAINS list, waiting for your decision), `approved` (marked as fraudulent and moved to the fraudulent list) or `ignored` (dismissed, on Ignored Domains); the API also lists `initial`, which was not seen in the data. Without a `state` filter the search is not limited to one state: it returned both `in_review` and `approved` domains.\n- `detection_history`: The detection rules that found the domain, one entry per rule with the rule's `id`, its name (`rule`), the `detection_date` and the `enabled` and `deleted` flags; the lists show it as RULES. It can be sorted on but not filtered: filter on `detection_history.id` instead.\n- `first_detection_date`: When a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest `detection_date` in `detection_history`.\n- `monitoring_indicator`: The four indicator flags `dns`, `dns_mx`, `ssl` and `http` as one object (null when there is no check result); the lists show them as the INDICATORS icons. It can be sorted on but not filtered: filter on `monitoring_indicator.dns`, `monitoring_indicator.dns_mx`, `monitoring_indicator.ssl` or `monitoring_indicator.http` instead.\n- `risk_score`: The domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.\n- `ignore_date`: When the domain was ignored (UTC date-time), shown as IGNORED DATE; empty if it was never ignored. A domain restored from Ignored Domains keeps this date, so a filter on it can also match domains that are back in review.\n- `approve_date`: When the domain was marked as fraudulent (UTC date-time), shown as APPROVE DATE; empty on domains that are still waiting for review.\n- `seems_inactive`: `true` when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.\n\n> The saved example **Request template · every filter** holds this body with every filter of this endpoint in one place (one entry per field, with a placeholder value and an operator the field accepts). Copy it, keep the lines you need, delete the rest.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"must\": [\n      {\n        \"name\": \"fraudulent\",\n        \"type\": \"eq\",\n        \"value\": \"example-1168.com\"\n      }\n    ]\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Suspicious Domain State Stats",
              "id": "fb62f37f-ec0c-54e9-a24e-a6abfa452c3f",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/suspicious-domains/stats/state",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "suspicious-domains",
                    "stats",
                    "state"
                  ]
                },
                "description": "**Deepinfo BRP Suspicious Domain State Stats API**\n\nCounts suspicious domains per state.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `in_review` | integer |  |\n| `ignored` | integer |  |\n| `approved` | integer |  |"
              },
              "response": []
            }
          ]
        },
        {
          "name": "Fraudulent Rules",
          "id": "47a74a62-4246-5db5-9503-2bd015a95aa0",
          "description": "Rules (keywords, match types) that detect domains imitating your brand.",
          "item": [
            {
              "name": "Fraudulent Rule Search",
              "id": "15aa69eb-3636-54c3-b5f0-4c186d3d5ee4",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-rules/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-rules",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Rule Search API**\n\nSearches your fraudulent rules.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object |  | See **Filtering** below |\n| `sort` | object |  | One `{field, order}` object |\n\n### Filtering\n\nThis search takes `filters` as an object with one key per field, not as a `must` list. Each field takes the operators of its filter type as keys, and fields combine with AND. `sort` is one `{field, order}` object, not a list. Example body:\n\n```json\n{\n  \"filters\": {\n    \"name\": {\n      \"equals\": [\n        \"<value>\"\n      ]\n    }\n  },\n  \"sort\": {\n    \"field\": \"name\",\n    \"order\": \"desc\"\n  }\n}\n```\n\nOperators by field:\n\n| Field | Operators |\n|---|---|\n| `name` | `equals`, `not_equals`, `contains`, `not_contains`, `startswith`, `endswith`; each takes a list of values |\n| `filters.match_type` | `equals`, `not_equals`; each takes a list of values |\n| `detected_fraudulent_count` | `gt`, `gte`, `lt`, `lte` |\n| `tags` | `equals`, `not_equals`, `contains`, `not_contains`, `startswith`, `endswith`; each takes a list of values |\n| `enabled` | a plain boolean value |\n| `create_date` | `gt`, `gte`, `lt`, `lte` |\n| `last_update_date` | `gt`, `gte`, `lt`, `lte` |\n\nSearchable fields:\n\n- `name`: The fraudulent domain rule's name, as you gave it.\n- `filters.match_type`: How the rule matches domain names to its keyword: `exact`, `contains`, `fuzzy`, `fuzzy_contains` or a `confusable_*` variant (look-alike characters). It sits in a nested `filters` object: `{\"filters\": {\"filters\": {\"match_type\": {\"equals\": [\"contains\"]}}}}`.\n- `detected_fraudulent_count`: How many fraudulent domains the rule has detected.\n- `tags`: The tags on the rule.\n- `enabled`: `true` for rules that are switched on, `false` for rules that are switched off.\n- `create_date`: When the rule was created (ISO 8601 date-time).\n- `last_update_date`: When the rule was last changed (ISO 8601 date-time).\n\nSortable fields:\n\n- `name`: The fraudulent domain rule's name, as you gave it.\n- `filters_match_type`: The rule's match type (`filters.match_type` in the response), for sorting.\n- `detected_fraudulent_count`: How many fraudulent domains the rule has detected.\n- `tags`: The tags on the rule.\n- `enabled`: `true` for rules that are switched on, `false` for rules that are switched off.\n- `create_date`: When the rule was created (ISO 8601 date-time).\n- `last_update_date`: When the rule was last changed (ISO 8601 date-time).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].name` | string |  |\n| `results[].filters` | object |  |\n| `results[].detected_fraudulent_count` | integer |  |\n| `results[].tags` | array of string |  |\n| `results[].enabled` | boolean |  |\n| `results[].create_date` | string | date-time |\n| `results[].last_update_date` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**.",
                "body": {
                  "mode": "raw",
                  "raw": "{}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Fraudulent Rule List",
              "id": "750b10a3-a414-5ae7-a777-3b4d3e98065d",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-rules",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-rules"
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Rule List API**\n\nLists your fraudulent rules.\n\n### Response\n\nAn array of objects:\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `enabled` | boolean |  |\n| `deleted` | boolean |  |"
              },
              "response": []
            },
            {
              "name": "Fraudulent Rule Detail",
              "id": "b9985205-60ee-5465-96ee-c82f95b2bf2d",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-rules/:rule_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-rules",
                    ":rule_id"
                  ],
                  "variable": [
                    {
                      "key": "rule_id",
                      "value": "69fb4768fbf83704dbf0c510",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Rule Detail API**\n\nReturns one fraudulent rule.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `filters` | object |  |\n| `tags` | array of string |  |\n| `include_past` | boolean |  |\n| `auto_approval` | boolean |  |\n| `enabled` | boolean |  |\n| `create_date` | string | date-time |\n| `last_update_date` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Fraudulent Rule Create",
              "id": "5cb77bca-d6e1-5dc5-938e-34178682d97d",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-rules",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-rules"
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Rule Create API**\n\nCreates a fraudulent rule: a `keyword` with `match_type` and helper keywords. `include_past` also scans already registered domains; `auto_approval` makes matches fraudulent domains directly.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `name` | string | yes | min length `1`; max length `255` |\n| `filters` | object | yes | The filters of the rule; see the example request body |\n| `tags` | array |  | max items `10` |\n| `include_past` | boolean | yes |  |\n| `auto_approval` | boolean | yes |  |\n| `enabled` | boolean | yes |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `filters` | object |  |\n| `tags` | array of string |  |\n| `include_past` | boolean |  |\n| `auto_approval` | boolean |  |\n| `enabled` | boolean |  |\n| `create_date` | string | date-time |\n| `last_update_date` | string | date-time |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"name\": \"Postman docs test rule\",\n  \"filters\": {\n    \"fqdn_type\": \"domain\",\n    \"keyword\": \"example\",\n    \"match_type\": \"exact\",\n    \"helper_keywords\": [],\n    \"discard_keywords\": [],\n    \"included_extensions\": [],\n    \"excluded_extensions\": []\n  },\n  \"tags\": [],\n  \"include_past\": false,\n  \"auto_approval\": false,\n  \"enabled\": false\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Fraudulent Rule Update",
              "id": "b56c26c4-1365-5552-844f-3b32c3ed9d51",
              "request": {
                "method": "PUT",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-rules/:rule_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-rules",
                    ":rule_id"
                  ],
                  "variable": [
                    {
                      "key": "rule_id",
                      "value": "6ab2a43b6d8212775cf91d9b",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Rule Update API**\n\nUpdates a fraudulent rule (send all fields).\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `name` | string | yes | min length `1`; max length `255` |\n| `filters` | object | yes | The filters of the rule; see the example request body |\n| `tags` | array |  | max items `10` |\n| `auto_approval` | boolean | yes |  |\n| `enabled` | boolean | yes |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `filters` | object |  |\n| `tags` | array of string |  |\n| `include_past` | boolean |  |\n| `auto_approval` | boolean |  |\n| `enabled` | boolean |  |\n| `create_date` | string | date-time |\n| `last_update_date` | string | date-time |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"name\": \"Postman docs test rule (updated)\",\n  \"filters\": {\n    \"fqdn_type\": \"domain\",\n    \"keyword\": \"example\",\n    \"match_type\": \"exact\",\n    \"helper_keywords\": [],\n    \"discard_keywords\": [],\n    \"included_extensions\": [],\n    \"excluded_extensions\": []\n  },\n  \"tags\": [],\n  \"auto_approval\": false,\n  \"enabled\": false\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Fraudulent Rule Delete",
              "id": "b66e4173-a11e-541c-874d-31e46818d55a",
              "request": {
                "method": "DELETE",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/brp/fraudulent-rules/:rule_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "brp",
                    "fraudulent-rules",
                    ":rule_id"
                  ],
                  "variable": [
                    {
                      "key": "rule_id",
                      "value": "6ab2a43b6d8212775cf91d9b",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo BRP Fraudulent Rule Delete API**\n\nDeletes a fraudulent rule."
              },
              "response": []
            }
          ]
        }
      ]
    },
    {
      "name": "Platform",
      "id": "cefe6177-cc05-5e54-a519-31e41e9b1e2d",
      "description": "Notifications and reports.",
      "item": [
        {
          "name": "Notifications",
          "id": "54a7e7ed-5b5f-5bce-96a0-b751c27293e7",
          "description": "Rules that send email notifications when an event of their `scope` happens, and the log of emails sent.",
          "item": [
            {
              "name": "Notification Email List",
              "id": "769f38de-de1a-5101-b6f8-f9e3eef127a8",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/notification-emails?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "notification-emails"
                  ],
                  "query": [
                    {
                      "key": "ordering",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    },
                    {
                      "key": "rule__id",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "rule__name__icontains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "rule__scope",
                      "value": "",
                      "description": "One of: `new_issue_detected`, `reappeared_issue_detected`, `asset_security_score_decreased`, `asset_security_score_changed`, `asset_ssl_changed`, `asset_whois_changed`, `asset_dns_changed`, `domain_security_score_decreased`, `domain_security_score_changed`, `new_asset_discovered`, `new_asset_added`, `new_vulnerability_detected`, `reappeared_vulnerability_detected`, `new_email_breach_detected`, `new_suspicious_domain_detected`, `new_fraudulent_domain_detected`, `new_open_port_detected`, `new_employee_credential_detected`, `new_client_credential_detected`, `new_payment_credential_detected`, `new_cybersecurity_news_added`.",
                      "disabled": true
                    },
                    {
                      "key": "rule__frequency",
                      "value": "",
                      "description": "One of: `instant`, `hourly`, `daily`, `weekly`, `monthly`.",
                      "disabled": true
                    },
                    {
                      "key": "sent_at__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "sent_at__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo Platform Notification Email List API**\n\nLists notification emails that were sent, with the rule that triggered them.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].rule` | object |  |\n| `results[].sent_at` | string | date-time |\n| `results[].recipients` | array of object |  |\n| `results[].context` | object |  |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Notification Rule List",
              "id": "d70e8a87-ec21-5f9d-acea-c9d8ca49162d",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/notification-rules?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "notification-rules"
                  ],
                  "query": [
                    {
                      "key": "ordering",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    },
                    {
                      "key": "name__contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "name__not_contains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "scope__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "scope__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "frequency__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "frequency__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "members__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "members__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "enabled",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "added_date__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "added_date__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "last_update_date__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "last_update_date__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo Platform Notification Rule List API**\n\nLists notification rules. Filter and sort with the optional query parameters.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].name` | string |  |\n| `results[].scope` | string | One of `new_issue_detected`, `reappeared_issue_detected`, `asset_security_score_decreased`, `asset_security_score_changed`, `asset_ssl_changed`, `asset_whois_changed`, `asset_dns_changed`, `domain_security_score_decreased`, `domain_security_score_changed`, `new_asset_discovered`, `new_asset_added`, `new_vulnerability_detected`, `reappeared_vulnerability_detected`, `new_email_breach_detected`, `new_suspicious_domain_detected`, `new_fraudulent_domain_detected`, `new_open_port_detected`, `new_employee_credential_detected`, `new_client_credential_detected`, `new_payment_credential_detected`, `new_cybersecurity_news_added` |\n| `results[].frequency` | string | One of `instant`, `hourly`, `daily`, `weekly`, `monthly` |\n| `results[].delivery_hour` | integer |  |\n| `results[].delivery_day_of_week` | integer |  |\n| `results[].members` | array of object |  |\n| `results[].enabled` | boolean |  |\n| `results[].added_date` | string | date-time |\n| `results[].last_update_date` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Notification Rule Detail",
              "id": "74024859-d64b-5a3e-b6b8-fd186346703c",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/notification-rules/:rule_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "notification-rules",
                    ":rule_id"
                  ],
                  "variable": [
                    {
                      "key": "rule_id",
                      "value": "6a73a186ff4e078dcdfc04c1",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo Platform Notification Rule Detail API**\n\nReturns one notification rule.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `scope` | string | One of `new_issue_detected`, `reappeared_issue_detected`, `asset_security_score_decreased`, `asset_security_score_changed`, `asset_ssl_changed`, `asset_whois_changed`, `asset_dns_changed`, `domain_security_score_decreased`, `domain_security_score_changed`, `new_asset_discovered`, `new_asset_added`, `new_vulnerability_detected`, `reappeared_vulnerability_detected`, `new_email_breach_detected`, `new_suspicious_domain_detected`, `new_fraudulent_domain_detected`, `new_open_port_detected`, `new_employee_credential_detected`, `new_client_credential_detected`, `new_payment_credential_detected`, `new_cybersecurity_news_added` |\n| `frequency` | string | One of `instant`, `hourly`, `daily`, `weekly`, `monthly` |\n| `delivery_hour` | integer |  |\n| `delivery_day_of_week` | integer |  |\n| `members` | array of object |  |\n| `enabled` | boolean |  |\n| `added_date` | string | date-time |\n| `last_update_date` | string | date-time |\n| `strategy` | object |  |"
              },
              "response": []
            },
            {
              "name": "Notification Rule Create",
              "id": "63cb9b59-7db2-5200-a39d-c0b39fe2b1fe",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/notification-rules",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "notification-rules"
                  ]
                },
                "description": "**Deepinfo Platform Notification Rule Create API**\n\nCreates a notification rule: the event `scope` (e.g. `new_issue_detected`), an optional `strategy` (conditions such as asset, severity, tags), `frequency` (`instant`, `hourly`, `daily`, `weekly`, `monthly`), `delivery_hour` / `delivery_day_of_week` and the team `members` (user ids) to email.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `name` | string | yes | min length `1`; max length `255` |\n| `scope` | string | yes | One of `new_issue_detected`, `reappeared_issue_detected`, `asset_security_score_decreased`, `asset_security_score_changed`, `asset_ssl_changed`, `asset_whois_changed`, `asset_dns_changed`, `domain_security_score_decreased`, `domain_security_score_changed`, `new_asset_discovered`, `new_asset_added`, `new_vulnerability_detected`, `reappeared_vulnerability_detected`, `new_email_breach_detected`, `new_suspicious_domain_detected`, `new_fraudulent_domain_detected`, `new_open_port_detected`, `new_employee_credential_detected`, `new_client_credential_detected`, `new_payment_credential_detected`, `new_cybersecurity_news_added` |\n| `strategy` | object |  |  |\n| `frequency` | string |  | One of `instant`, `hourly`, `daily`, `weekly`, `monthly` |\n| `delivery_hour` | integer |  | min `0.0`; max `23.0` |\n| `delivery_day_of_week` | integer |  | min `0.0`; max `6.0` |\n| `members` | array | yes | min items `1` |\n| `enabled` | boolean |  |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `scope` | string | One of `new_issue_detected`, `reappeared_issue_detected`, `asset_security_score_decreased`, `asset_security_score_changed`, `asset_ssl_changed`, `asset_whois_changed`, `asset_dns_changed`, `domain_security_score_decreased`, `domain_security_score_changed`, `new_asset_discovered`, `new_asset_added`, `new_vulnerability_detected`, `reappeared_vulnerability_detected`, `new_email_breach_detected`, `new_suspicious_domain_detected`, `new_fraudulent_domain_detected`, `new_open_port_detected`, `new_employee_credential_detected`, `new_client_credential_detected`, `new_payment_credential_detected`, `new_cybersecurity_news_added` |\n| `frequency` | string | One of `instant`, `hourly`, `daily`, `weekly`, `monthly` |\n| `delivery_hour` | integer |  |\n| `delivery_day_of_week` | integer |  |\n| `members` | array of object |  |\n| `enabled` | boolean |  |\n| `added_date` | string | date-time |\n| `last_update_date` | string | date-time |\n| `strategy` | object |  |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"name\": \"Postman docs test rule\",\n  \"scope\": \"new_asset_added\",\n  \"frequency\": \"daily\",\n  \"delivery_hour\": 9,\n  \"members\": [\n    \"9a1b2013-6551-4632-847e-56153518a701\"\n  ],\n  \"enabled\": false\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Notification Rule Update",
              "id": "2ab2abe1-21ae-5687-a748-b9bed01ef683",
              "request": {
                "method": "PUT",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/notification-rules/:rule_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "notification-rules",
                    ":rule_id"
                  ],
                  "variable": [
                    {
                      "key": "rule_id",
                      "value": "6ab2a441700d26dce9fba41c",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo Platform Notification Rule Update API**\n\nUpdates a notification rule's `name`, delivery time, `members` and `enabled`. `scope` and `strategy` cannot be changed.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `name` | string | yes | min length `1`; max length `255` |\n| `delivery_hour` | integer |  | min `0.0`; max `23.0` |\n| `delivery_day_of_week` | integer |  | min `0.0`; max `6.0` |\n| `members` | array | yes | min items `1` |\n| `enabled` | boolean | yes |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `scope` | string | One of `new_issue_detected`, `reappeared_issue_detected`, `asset_security_score_decreased`, `asset_security_score_changed`, `asset_ssl_changed`, `asset_whois_changed`, `asset_dns_changed`, `domain_security_score_decreased`, `domain_security_score_changed`, `new_asset_discovered`, `new_asset_added`, `new_vulnerability_detected`, `reappeared_vulnerability_detected`, `new_email_breach_detected`, `new_suspicious_domain_detected`, `new_fraudulent_domain_detected`, `new_open_port_detected`, `new_employee_credential_detected`, `new_client_credential_detected`, `new_payment_credential_detected`, `new_cybersecurity_news_added` |\n| `frequency` | string | One of `instant`, `hourly`, `daily`, `weekly`, `monthly` |\n| `delivery_hour` | integer |  |\n| `delivery_day_of_week` | integer |  |\n| `members` | array of object |  |\n| `enabled` | boolean |  |\n| `added_date` | string | date-time |\n| `last_update_date` | string | date-time |\n| `strategy` | object |  |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"name\": \"Postman docs test rule (updated)\",\n  \"delivery_hour\": 10,\n  \"members\": [\n    \"9a1b2013-6551-4632-847e-56153518a701\"\n  ],\n  \"enabled\": false\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Notification Rule Delete",
              "id": "aebc927d-e6db-58ba-a323-57fc41f7063b",
              "request": {
                "method": "DELETE",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/notification-rules/:rule_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "notification-rules",
                    ":rule_id"
                  ],
                  "variable": [
                    {
                      "key": "rule_id",
                      "value": "6ab2a441700d26dce9fba41c",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo Platform Notification Rule Delete API**\n\nDeletes a notification rule."
              },
              "response": []
            }
          ]
        },
        {
          "name": "Reports",
          "id": "a5fc4b4a-431d-5f4f-b18c-aca0af7a7e28",
          "description": "Generate, download and manage PDF reports.",
          "item": [
            {
              "name": "Report Search",
              "id": "3169451e-98ca-508d-a8bf-f3654f2558b1",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/reports/search?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "reports",
                    "search"
                  ],
                  "query": [
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    }
                  ]
                },
                "description": "**Deepinfo Platform Report Search API**\n\nSearches reports. **Different filter format:** `filters.type` is required, other filters use operators like `{\"name\": {\"contains\": \"…\"}}`.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `filters` | object | yes | See **Filtering** below |\n| `sort` | object |  | One `{field, order}` object |\n\n### Filtering\n\nThis search takes `filters` as an object with one key per field, not as a `must` list. Each field takes the operators of its filter type as keys, and fields combine with AND. `sort` is one `{field, order}` object, not a list. Example body:\n\n```json\n{\n  \"filters\": {\n    \"name\": {\n      \"equals\": \"<value>\"\n    }\n  },\n  \"sort\": {\n    \"field\": \"name\",\n    \"order\": \"desc\"\n  }\n}\n```\n\nOperators by field:\n\n| Field | Operators |\n|---|---|\n| `name` | `equals`, `not_equals`, `contains` |\n| `type` | a plain value: `easm_executive_summary`, `easm_weekly_progress`, `easm_asset_detail`, `easm_vulnerability_detail`, `easm_vulnerability_overview`, `easm_issue_overview`, `easm_issue_detail`, `cti_email_breach_summary` |\n| `type_context` | `equals`, `not_equals` |\n| `description` | `contains` |\n| `creation_date` | `gt`, `gte`, `lt`, `lte` |\n| `creation_method` | a plain value: `instant`, `scheduled` |\n| `rule_id` | a plain string value |\n\nSearchable fields:\n\n- `name`: The report's name, such as `executive-summary-2025-06-01-08:00`.\n- `type`: **Required.** The report type to search, such as `easm_executive_summary`, `easm_asset_detail` or `cti_email_breach_summary`. One search covers one type.\n- `type_context`: The options the report was made with (for example, which asset an asset detail report covers), an object compared as a whole.\n- `description`: The report's description.\n- `creation_date`: When the report was created (ISO 8601 date-time).\n- `creation_method`: How the report was made: `instant` (on demand) or `scheduled` (by a scheduled report rule).\n- `rule_id`: The ID of the scheduled report rule that made the report; `null` in the response for instant reports.\n\nSortable fields:\n\n- `name`: The report's name, such as `executive-summary-2025-06-01-08:00`.\n- `description`: The report's description.\n- `creation_date`: When the report was created (ISO 8601 date-time).\n- `creation_method`: How the report was made: `instant` (on demand) or `scheduled` (by a scheduled report rule).\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].name` | string |  |\n| `results[].description` | string |  |\n| `results[].creation_date` | string | date-time |\n| `results[].creation_method` | string | One of `instant`, `scheduled` |\n| `results[].rule_id` | string |  |\n\nPaginated. See **Getting Started → Pagination**.",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"filters\": {\n    \"type\": \"easm_executive_summary\"\n  }\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Report Detail",
              "id": "8dd11583-8047-5c84-84ff-5e3a03ef99f2",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/reports/:report_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "reports",
                    ":report_id"
                  ],
                  "variable": [
                    {
                      "key": "report_id",
                      "value": "6a5a395e95af0518ef60d4b0",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo Platform Report Detail API**\n\nReturns one report and its generation status.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `type` | string | One of `easm_executive_summary`, `easm_weekly_progress`, `easm_asset_detail`, `easm_vulnerability_detail`, `easm_vulnerability_overview`, `easm_issue_overview`, `easm_issue_detail`, `cti_email_breach_summary` |\n| `type_context` | object |  |\n| `description` | string |  |\n| `creation_date` | string | date-time |\n| `context` | object |  |\n| `creation_method` | string | One of `instant`, `scheduled` |\n| `rule_id` | string |  |"
              },
              "response": []
            },
            {
              "name": "Report Create",
              "id": "15774ce8-b6b8-54fc-81fb-9a2bb2067af5",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/reports",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "reports"
                  ]
                },
                "description": "**Deepinfo Platform Report Create API**\n\nGenerates a report. `type` is one of `easm_executive_summary`, `easm_weekly_progress`, `easm_asset_detail`, `easm_vulnerability_detail`, `easm_vulnerability_overview`, `easm_issue_overview`, `easm_issue_detail`, `cti_email_breach_summary`. Generation takes a while; poll **Report Detail**, then **Report Download**.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `name` | string | yes | min length `1`; max length `100` |\n| `type` | string | yes | One of `easm_executive_summary`, `easm_weekly_progress`, `easm_asset_detail`, `easm_vulnerability_detail`, `easm_vulnerability_overview`, `easm_issue_overview`, `easm_issue_detail`, `cti_email_breach_summary` |\n| `type_context` | object |  |  |\n| `description` | string |  | min length `1`; max length `350` |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `type` | string | One of `easm_executive_summary`, `easm_weekly_progress`, `easm_asset_detail`, `easm_vulnerability_detail`, `easm_vulnerability_overview`, `easm_issue_overview`, `easm_issue_detail`, `cti_email_breach_summary` |\n| `type_context` | object |  |\n| `description` | string |  |\n| `creation_date` | string | date-time |\n| `context` | object |  |\n| `creation_method` | string | One of `instant`, `scheduled` |\n| `rule_id` | string |  |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"name\": \"Postman docs test report\",\n  \"type\": \"easm_executive_summary\",\n  \"description\": \"Created by the Postman docs test run\"\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Report Download",
              "id": "545980a9-1439-57d2-9b4c-090a47d26624",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/reports/:report_id/download",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "reports",
                    ":report_id",
                    "download"
                  ],
                  "variable": [
                    {
                      "key": "report_id",
                      "value": "6a5a395e95af0518ef60d4b0",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo Platform Report Download API**\n\nReturns a pre-signed `download_url` for the report PDF.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `download_url` | string | uri |"
              },
              "response": []
            },
            {
              "name": "Report Delete",
              "id": "6f265e68-be2d-5758-929a-7ed07af73098",
              "request": {
                "method": "DELETE",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/reports/:report_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "reports",
                    ":report_id"
                  ],
                  "variable": [
                    {
                      "key": "report_id",
                      "value": "6ab2a443fb914c0e686e93af",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo Platform Report Delete API**\n\nDeletes a report."
              },
              "response": []
            }
          ]
        },
        {
          "name": "Scheduled Reports",
          "id": "fc8a39a4-c238-5df6-b0b2-717cc74e3677",
          "description": "Rules that generate and email reports on a schedule.",
          "item": [
            {
              "name": "Scheduled Report Rule List",
              "id": "a13be677-ceaf-5ff1-a2ce-d0cf1a7c2203",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/scheduled-reports/rules?page_size=25",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "scheduled-reports",
                    "rules"
                  ],
                  "query": [
                    {
                      "key": "ordering",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "page",
                      "value": "1",
                      "description": "Min `1`, max `800`. Default `1`.",
                      "disabled": true
                    },
                    {
                      "key": "page_size",
                      "value": "25",
                      "description": "Min `25`, max `100`. Default `100`."
                    },
                    {
                      "key": "name__icontains",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "type__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "type__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "frequency__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "frequency__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "members__in",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "members__nin",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "last_sent_date__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "last_sent_date__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "next_send_date__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "next_send_date__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "created_at__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "created_at__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "updated_at__lte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    },
                    {
                      "key": "updated_at__gte",
                      "value": "",
                      "description": "",
                      "disabled": true
                    }
                  ]
                },
                "description": "**Deepinfo Platform Scheduled Report Rule List API**\n\nLists scheduled report rules.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `page` | integer |  |\n| `page_size` | integer |  |\n| `result_count` | integer |  |\n| `results` | array of object |  |\n| `results[].id` | string |  |\n| `results[].name` | string |  |\n| `results[].type` | string | One of `easm_executive_summary`, `easm_weekly_progress`, `easm_asset_detail`, `easm_vulnerability_detail`, `easm_vulnerability_overview`, `easm_issue_overview`, `easm_issue_detail`, `cti_email_breach_summary` |\n| `results[].type_context` | object |  |\n| `results[].frequency` | string | One of `daily`, `weekly`, `monthly` |\n| `results[].members` | array of string |  |\n| `results[].last_sent_date` | string | date-time |\n| `results[].next_send_date` | string | date-time |\n| `results[].created_at` | string | date-time |\n| `results[].updated_at` | string | date-time |\n\nPaginated. See **Getting Started → Pagination**."
              },
              "response": []
            },
            {
              "name": "Scheduled Report Rule Detail",
              "id": "b20a9252-2afa-5176-bae6-b46c0ebfd4af",
              "request": {
                "method": "GET",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/scheduled-reports/rules/:rule_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "scheduled-reports",
                    "rules",
                    ":rule_id"
                  ],
                  "variable": [
                    {
                      "key": "rule_id",
                      "value": "6ab2a77d050aaa8c8a03f16c",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo Platform Scheduled Report Rule Detail API**\n\nReturns one scheduled report rule with last and next send dates.\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `type` | string | One of `easm_executive_summary`, `easm_weekly_progress`, `easm_asset_detail`, `easm_vulnerability_detail`, `easm_vulnerability_overview`, `easm_issue_overview`, `easm_issue_detail`, `cti_email_breach_summary` |\n| `type_context` | object |  |\n| `frequency` | string | One of `daily`, `weekly`, `monthly` |\n| `members` | array of string |  |\n| `last_sent_date` | string | date-time |\n| `next_send_date` | string | date-time |\n| `created_at` | string | date-time |\n| `updated_at` | string | date-time |"
              },
              "response": []
            },
            {
              "name": "Scheduled Report Rule Create",
              "id": "8bfb68a8-5696-532b-a90b-bbfc1136bb2a",
              "request": {
                "method": "POST",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  },
                  {
                    "key": "Content-Type",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/scheduled-reports/rules",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "scheduled-reports",
                    "rules"
                  ]
                },
                "description": "**Deepinfo Platform Scheduled Report Rule Create API**\n\nCreates a scheduled report: `type`, `frequency` (`daily`, `weekly`, `monthly`) and the team `members` (user ids) who receive it.\n\n### Request body\n\n| Field | Type | Required | Notes |\n|---|---|---|---|\n| `name` | string | yes | min length `1`; max length `255` |\n| `type` | string | yes | One of `easm_executive_summary`, `easm_weekly_progress`, `easm_asset_detail`, `easm_vulnerability_detail`, `easm_vulnerability_overview`, `easm_issue_overview`, `easm_issue_detail`, `cti_email_breach_summary` |\n| `type_context` | object |  |  |\n| `frequency` | string | yes | One of `daily`, `weekly`, `monthly` |\n| `members` | array |  |  |\n\n### Response\n\n| Field | Type | Notes |\n|---|---|---|\n| `id` | string |  |\n| `name` | string |  |\n| `type` | string | One of `easm_executive_summary`, `easm_weekly_progress`, `easm_asset_detail`, `easm_vulnerability_detail`, `easm_vulnerability_overview`, `easm_issue_overview`, `easm_issue_detail`, `cti_email_breach_summary` |\n| `type_context` | object |  |\n| `frequency` | string | One of `daily`, `weekly`, `monthly` |\n| `members` | array of string |  |\n| `last_sent_date` | string | date-time |\n| `next_send_date` | string | date-time |\n| `created_at` | string | date-time |\n| `updated_at` | string | date-time |",
                "body": {
                  "mode": "raw",
                  "raw": "{\n  \"name\": \"Postman docs test schedule\",\n  \"type\": \"easm_executive_summary\",\n  \"frequency\": \"monthly\",\n  \"members\": [\n    \"9a1b2013-6551-4632-847e-56153518a701\"\n  ]\n}",
                  "options": {
                    "raw": {
                      "language": "json"
                    }
                  }
                }
              },
              "response": []
            },
            {
              "name": "Scheduled Report Rule Delete",
              "id": "bc7c6ab4-e908-511e-9ad2-ab78fc75d48e",
              "request": {
                "method": "DELETE",
                "header": [
                  {
                    "key": "Accept",
                    "value": "application/json"
                  }
                ],
                "url": {
                  "raw": "{{api_base_url}}/{{api_version}}/platform/scheduled-reports/rules/:rule_id",
                  "host": [
                    "{{api_base_url}}"
                  ],
                  "path": [
                    "{{api_version}}",
                    "platform",
                    "scheduled-reports",
                    "rules",
                    ":rule_id"
                  ],
                  "variable": [
                    {
                      "key": "rule_id",
                      "value": "6ab2a77d050aaa8c8a03f16c",
                      "description": "**Required.**"
                    }
                  ]
                },
                "description": "**Deepinfo Platform Scheduled Report Rule Delete API**\n\nDeletes a scheduled report rule. (There is no update; delete and create again.)"
              },
              "response": []
            }
          ]
        }
      ]
    }
  ]
}
