Asset Delete
https://api.deepinfo.com/v1/easm/assets/search:deleteRemoves every asset matching filters from monitoring. Deleted assets are listed under Deleted Assets.
The action applies to every record matching filters. Always send a filter (for example by id); an empty filter matches all records.
Authentication
Send your API key in the apikey request header.
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{
"filters": {
"must": [
{
"name": "asset",
"type": "eq",
"value": "acme.example"
}
]
}
}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "asset",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "asset",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with some of the filters of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value; Searchable Fields lists them all. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith wildcard fuzzy contains_ contains_ exists
| Field | Description |
|---|---|
asset | The asset's name: a domain, subdomain or IP address, or for a website asset host:port. |
tags | Your own labels on the asset, such as a business unit or an environment; each tag is 3 to 100 characters long. |
fqdn. | The asset's full host name (FQDN) in its readable Unicode form. |
fqdn. | The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals fqdn.unicode. |
fqdn. | The host name without its extension, in Unicode: acme for acme.example, www.acme for www.acme.example. |
fqdn. | Latin-letter spellings of a name that has non-Latin or accented letters, so a search for istanbul also finds names written with İ. |
fqdn. | The registrable domain the asset belongs to, in Unicode: acme.example for both acme.example and www.acme.example. |
fqdn. | The registrable domain the asset belongs to, in its ASCII (punycode) form. |
fqdn. | The domain's extension, everything after the name, such as com or co.uk. |
fqdn. | The top-level part of the extension: uk for both uk and co.uk. |
fqdn. | The second-level part of a two-part extension, such as co in co.uk; empty for single-part extensions. |
website. | The URL path of a website asset, such as /. |
website. | The URL scheme of a website asset, such as http. |
website. | The ID of the domain or subdomain asset that a website asset belongs to. |
website. | The name of the domain or subdomain asset that a website asset belongs to. |
whois. | The domain's EPP status codes from WHOIS, in lower case without spaces, such as clienttransferprohibited. |
whois. | The name servers listed in the WHOIS record, such as ns1.acme.example. |
whois. | The registrar the domain is registered through, as written in WHOIS (usually lower case). |
whois. | The registrant's organization in WHOIS; often a privacy placeholder such as redacted for privacy or a proxy service. |
whois. | The registrant's name in WHOIS; often a privacy placeholder such as redacted for privacy. |
whois. | The registrant's country in WHOIS, as a two-letter code in lower case such as us. |
whois. | The registrant's state or province in WHOIS. |
whois. | The registrant's city in WHOIS. |
whois. | The registrant's street address in WHOIS. |
whois. | The registrant's postal code in WHOIS. |
whois. | The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead. |
whois. | The registrant's phone number in WHOIS, in the registry format such as +1.4805551234. |
whois_ | Every registrant e-mail address seen for the domain over time, the current one included. |
whois_ | The registrar reduced to a short normalized name, such as godaddy or gandi, so the same registrar matches across spellings. |
whois_ | The registrant e-mail address after WHOIS normalization. |
whois_ | Another normalized registrant e-mail field, set on fewer domains than whois_normalized.registrant.email; in the samples it is set only where whois_privacy_enabled is false, with the same address. |
whois_ | The registrable domain of the registrant e-mail address: acme.example for user@mail.acme.example. |
whois_ | The full host name after the @ of the registrant e-mail address: mail.acme.example for user@mail.acme.example. |
whois_ | The registrant organization cleaned up across registrars: lower case, with spaces and punctuation removed, such as domainsbyproxyllc. |
whois_ | The registrant phone number reduced to its digits, such as 14805551234. |
whois_ | The WHOIS fields that changed in the last change seen, as field paths such as whois.update_date or whois.domain_status. |
dns. | The asset's current A records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's A records as they were before the last change, in the same text form as dns.a.value. |
dns. | The DNS response code returned for the asset's A lookup, such as NOERROR. |
dns. | The DNS response code of the A lookup before it last changed. |
dns. | An IPv4 address from the asset's A records (the A-record address); the other dns.a.ip_addresses fields hold its IP WHOIS (RDAP) data. |
dns. | The number of the autonomous system (ASN) that announces the A-record address, as a string such as 13335. |
dns. | The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup. |
dns. | The name and holder of the autonomous system that announces the A-record address, such as CLOUDFLARENET - Cloudflare, Inc., US. |
dns. | The country of the autonomous system that announces the A-record address, as a two-letter code such as US. |
dns. | The regional internet registry responsible for the A-record address, such as arin or ripencc. |
dns. | The handles of the registry contacts and organizations linked to the network of the A-record address, such as ACME-ARIN. |
dns. | The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation. |
dns. | The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, when it is kept. |
dns. | The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
dns. | The IP address that was looked up in IP WHOIS (RDAP), that is the A-record address. |
dns. | The raw IP WHOIS response for the A-record address, when it is kept; empty on every sampled asset. |
dns. | The registered network block that contains the A-record address, in CIDR notation, such as 192.0.2.0/24; a network made of several blocks lists them separated by commas. |
dns. | The name of the registered network that contains the A-record address, such as CLOUDFLARENET. |
dns. | The country of the registered network that contains the A-record address, as a two-letter code such as FR. |
dns. | The first address of the registered network block that contains the A-record address. |
dns. | The last address of the registered network block that contains the A-record address. |
dns. | The registry handle of the network that contains the A-record address, such as NET-192-0-2-0-1. |
dns. | The IP version of the network that contains the A-record address: v4 or v6. |
dns. | Links to the registry record of the network that contains the A-record address, such as its RDAP and WHOIS URLs. |
dns. | The handle of the larger network block from which the network of the A-record address was allocated. |
dns. | The raw RDAP network object for the A-record address, when it is kept. |
dns. | The registry status of the network that contains the A-record address, such as active. |
dns. | The registry's allocation type for the network that contains the A-record address, such as DIRECT ALLOCATION, ALLOCATION or ALLOCATED PA. |
dns. | The title of a notice the registry attached to the network record of the A-record address, such as Terms of Service. |
dns. | The text of a notice the registry attached to the network record of the A-record address. |
dns. | Links given in a notice on the network record of the A-record address. |
dns. | The title of a remark on the network record of the A-record address, such as Registration Comments. |
dns. | The text of a remark on the network record of the A-record address. |
dns. | Links given in a remark on the network record of the A-record address. |
dns. | An event in the history of the network record of the A-record address, such as registration or last changed. |
dns. | Who performed an event on the network record of the A-record address, when the registry names one. |
dns. | The handle of a registry contact or organization (RDAP entity) linked to the network of the A-record address, such as ACME-ARIN. |
dns. | The type of an e-mail address of a contact linked to the network of the A-record address, such as abuse. |
dns. | An e-mail address of a contact linked to the network of the A-record address. |
dns. | The type of a postal address of a contact linked to the network of the A-record address. |
dns. | A postal address of a contact linked to the network of the A-record address. |
dns. | The type of a phone number of a contact linked to the network of the A-record address, such as voice or work. |
dns. | A phone number of a contact linked to the network of the A-record address. |
dns. | What kind of contact is linked to the network of the A-record address: org, group or individual. |
dns. | The name of a contact or organization linked to the network of the A-record address, such as Abuse or a company name. |
dns. | The role given in the contact card of an entity linked to the network of the A-record address. |
dns. | The title given in the contact card of an entity linked to the network of the A-record address. |
dns. | Handles of further entities listed under a contact linked to the network of the A-record address. |
dns. | An event in the history of a contact record linked to the network of the A-record address, such as registration or last changed. |
dns. | Who performed an event on a contact record linked to the network of the A-record address, when the registry names one. |
dns. | Events in which a contact linked to the network of the A-record address is itself the actor (the RDAP asEventActor list), as text; empty on every sampled record. |
dns. | The registry handle of a contact or organization linked to the network of the A-record address. |
dns. | Links to the registry record of a contact linked to the network of the A-record address. |
dns. | The title of a notice on a contact record linked to the network of the A-record address, such as Terms of Service. |
dns. | The text of a notice on a contact record linked to the network of the A-record address. |
dns. | Links given in a notice on a contact record linked to the network of the A-record address. |
dns. | The raw RDAP object of a contact linked to the network of the A-record address, when it is kept. |
dns. | The title of a remark on a contact record linked to the network of the A-record address, such as Registration Comments. |
dns. | The text of a remark on a contact record linked to the network of the A-record address. |
dns. | Links given in a remark on a contact record linked to the network of the A-record address. |
dns. | The roles of a contact for the network of the A-record address, such as registrant, abuse or technical. |
dns. | The registry status of a contact linked to the network of the A-record address, such as validated. |
dns. | Every IPv4 address seen in the asset's A records over time, the current ones included. |
dns. | The asset's current AAAA records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's AAAA records as they were before the last change, in the same text form as dns.aaaa.value. |
dns. | The DNS response code returned for the asset's AAAA lookup, such as NOERROR. |
dns. | The DNS response code of the AAAA lookup before it last changed. |
dns. | The IPv6 addresses in the asset's AAAA records. |
dns. | The asset's current CAA records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's CAA records as they were before the last change, in the same text form as dns.caa.value. |
dns. | The DNS response code returned for the asset's CAA lookup, such as NOERROR. |
dns. | The DNS response code of the CAA lookup before it last changed. |
dns. | The certificate authorities allowed to issue certificates for the name, from the CAA issue tags, such as fernhill.example or kestrel.example. |
dns. | The certificate authorities allowed to issue wildcard certificates for the name, from the CAA issuewild tags. |
dns. | The e-mail addresses from the CAA iodef tags, where certificate authorities report requests that break the CAA policy. |
dns. | The asset's current CNAME records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's CNAME records as they were before the last change, in the same text form as dns.cname.value. |
dns. | The DNS response code returned for the asset's CNAME lookup, such as NOERROR. |
dns. | The DNS response code of the CNAME lookup before it last changed. |
dns. | The host names the asset's CNAME records point to (the alias targets). |
dns. | The asset's current DNSKEY records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's DNSKEY records as they were before the last change, in the same text form as dns.dnskey.value. |
dns. | The DNS response code returned for the asset's DNSKEY lookup, such as NOERROR. |
dns. | The DNS response code of the DNSKEY lookup before it last changed. |
dns. | The public key of a DNSKEY record, Base64-encoded and split into space-separated groups as in the zone-file text. |
dns. | The asset's current DS records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's DS records as they were before the last change, in the same text form as dns.ds.value. |
dns. | The DNS response code returned for the asset's DS lookup, such as NOERROR. |
dns. | The DNS response code of the DS lookup before it last changed. |
dns. | The digest of a DS record, the hash of the DNSKEY it refers to. |
dns. | The asset's current MX records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's MX records as they were before the last change, in the same text form as dns.mx.value. |
dns. | The DNS response code returned for the asset's MX lookup, such as NOERROR. |
dns. | The DNS response code of the MX lookup before it last changed. |
dns. | The mail server host names from the asset's MX records, such as mail.acme.example. |
dns. | The registrable domains of the asset's mail servers, such as acme.example. |
dns. | The asset's current NS records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's NS records as they were before the last change, in the same text form as dns.ns.value. |
dns. | The DNS response code returned for the asset's NS lookup, such as NOERROR. |
dns. | The DNS response code of the NS lookup before it last changed. |
dns. | The name server host names from the asset's NS records, such as ns1.acme.example. |
dns. | The registrable domains of the asset's name servers, such as acme.example. |
dns. | The asset's current NSEC records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's NSEC records as they were before the last change, in the same text form as dns.nsec.value. |
dns. | The DNS response code returned for the asset's NSEC lookup, such as NOERROR. |
dns. | The DNS response code of the NSEC lookup before it last changed. |
dns. | The next name in the zone, from an NSEC record. |
dns. | The record types that exist at the name, from an NSEC record's type list, such as A, NS or SOA. |
dns. | The asset's current NSEC3 records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's NSEC3 records as they were before the last change, in the same text form as dns.nsec3.value. |
dns. | The DNS response code returned for the asset's NSEC3 lookup, such as NOERROR. |
dns. | The DNS response code of the NSEC3 lookup before it last changed. |
dns. | The hashed next name in the zone, from an NSEC3 record. |
dns. | The record types that exist at the name, from an NSEC3 record's type list, such as A or MX. |
dns. | The asset's current RRSIG records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's RRSIG records as they were before the last change, in the same text form as dns.rrsig.value. |
dns. | The DNS response code returned for the asset's RRSIG lookup, such as NOERROR. |
dns. | The DNS response code of the RRSIG lookup before it last changed. |
dns. | The record type that an RRSIG signature covers, such as A or SOA. |
dns. | The signature data of an RRSIG record, Base64-encoded. |
dns. | The asset's current SOA records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's SOA records as they were before the last change, in the same text form as dns.soa.value. |
dns. | The DNS response code returned for the asset's SOA lookup, such as NOERROR. |
dns. | The DNS response code of the SOA lookup before it last changed. |
dns. | The MNAME of the SOA record: the primary name server of the zone, such as ns1.acme.example. |
dns. | The RNAME of the SOA record, the zone administrator's mailbox in DNS form: hostmaster.acme.example stands for the mailbox hostmaster at acme.example. |
dns. | The RNAME of the SOA record written as an e-mail address, such as user@acme.example. |
dns. | The asset's current SRV records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's SRV records as they were before the last change, in the same text form as dns.srv.value. |
dns. | The DNS response code returned for the asset's SRV lookup, such as NOERROR. |
dns. | The DNS response code of the SRV lookup before it last changed. |
dns. | The service named in an SRV record (the _service part of its name). |
dns. | The protocol named in an SRV record (the _proto part of its name, such as TCP or UDP). |
dns. | The host name an SRV record points to. |
dns. | The asset's current TXT records as zone-file text (name, TTL, class, type and data), all records in one string. |
dns. | The asset's TXT records as they were before the last change, in the same text form as dns.txt.value. |
dns. | The DNS response code returned for the asset's TXT lookup, such as NOERROR. |
dns. | The DNS response code of the TXT lookup before it last changed. |
dns. | Each TXT record of the asset as its quoted text, such as "v=spf1 include:_spf.acme.example ~all"; the quotes are part of the value. |
dns. | The text of an SPF record (a TXT record that starts with v=spf1), quoted as in dns.txt.values. |
dns. | The registrable domains that an SPF record refers to, such as acme.example for include:_spf.acme.example. |
dns. | The IP addresses and ranges that an SPF record authorizes to send mail (its ip4: and ip6: entries). |
dns. | The text of a site-verification TXT record, quoted as in dns.txt.values. |
dns. | The domain of the service a verification record is for, such as acme.example, fernhill.example or kestrel.example. |
dns. | The name of a verification record, such as site-verification or domain-verification. |
dns_ | The DNS fields that changed in the last change seen, as field paths such as dns.soa.mnames. |
ssl. | The host name that the asset's TLS certificate was collected from, normally the asset itself. |
ssl. | The serial number of the asset's TLS certificate, as a decimal string. |
ssl. | The MD5 fingerprint of the asset's TLS certificate, as lower-case hex. |
ssl. | The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex. |
ssl. | The SHA-256 fingerprint of the asset's TLS certificate, as lower-case hex; one fingerprint identifies one certificate. |
ssl. | The common name (CN) of the certificate authority that issued the asset's TLS certificate, such as WE1 or YE2. |
ssl. | The country (C) of the certificate authority that issued the asset's TLS certificate, as a two-letter code such as US. |
ssl. | The state or province (ST) of the certificate authority that issued the asset's TLS certificate. |
ssl. | The locality or city (L) of the certificate authority that issued the asset's TLS certificate. |
ssl. | The organization (O) of the certificate authority that issued the asset's TLS certificate, such as Let's Encrypt or Google Trust Services. |
ssl. | The organizational unit (OU) of the certificate authority that issued the asset's TLS certificate. |
ssl. | The full distinguished name of the issuer of the asset's TLS certificate, as one string such as CN=WE1,O=Google Trust Services,C=US. |
ssl. | The common name (CN) of the subject (holder) of the asset's TLS certificate, usually a host name such as acme.example. |
ssl. | The country (C) of the subject (holder) of the asset's TLS certificate, as a two-letter code. |
ssl. | The state or province (ST) of the subject (holder) of the asset's TLS certificate. |
ssl. | The locality or city (L) of the subject (holder) of the asset's TLS certificate. |
ssl. | The organization (O) of the subject (holder) of the asset's TLS certificate. |
ssl. | The organizational unit (OU) of the subject (holder) of the asset's TLS certificate. |
ssl. | The full distinguished name of the subject of the asset's TLS certificate, such as CN=acme.example; one that starts with CN=*. belongs to a wildcard certificate. |
ssl. | The signature of the asset's TLS certificate, Base64-encoded. |
ssl. | Why certificate validation failed, such as a host name mismatch or unable to get issuer certificate. |
ssl. | The hash algorithm of the signature on the asset's TLS certificate, such as sha256 or sha384. |
ssl. | The object identifier (OID) of the signature algorithm, such as 1.2.840.113549.1.1.11 (SHA-256 with RSA) or 1.2.840.10045.4.3.2 (ECDSA with SHA-256). |
ssl. | The Authority Key Identifier extension, which identifies the issuer's key, Base64-encoded. |
ssl. | The policy OIDs in the Certificate Policies extension, such as 2.23.140.1.2.1 (domain validated). |
ssl. | The ID of the Certificate Transparency log that issued a signed certificate timestamp (SCT) for the certificate, Base64-encoded. |
ssl. | The log's signature on a signed certificate timestamp, Base64-encoded. |
ssl. | The host names in the certificate's Subject Alternative Name extension, including wildcard names such as *.acme.example. |
ssl. | The Subject Key Identifier extension, which identifies the certificate's own key, Base64-encoded. |
ssl. | The hash algorithm used for ssl.subject_key_info.fingerprint.value, such as sha256 or sha384. |
ssl. | A hex fingerprint recorded under the certificate's subject key information, made with the hash in hash_algorithm. In the samples it equals ssl.fingerprint.sha256 when that hash is SHA-256. |
ssl. | The algorithm of the certificate's public key, such as RSA or ECDSA. |
ssl. | The X.509 version of the certificate, such as v3. |
ssl. | The X.509 version as encoded in the certificate, counted from zero: 2 means v3. |
ssl. | A SHA-256 fingerprint (hex) of the certificate's to-be-signed part, the certificate content without its signature. |
ssl. | The whole certificate, Base64-encoded (a PEM body without the header and footer lines). |
ssl. | The host names the certificate covers, with the *. of wildcard names removed and duplicates merged, so *.acme.example and acme.example both give acme.example. |
ssl_ | The certificate fields that changed in the last change seen, as field paths such as ssl.validity.end_date. |
http. | The URL the HTTP check started from, such as http://acme.example. |
http. | The registrable domain of the URL the HTTP check started from. |
http. | The host name of the URL the HTTP check started from. |
http. | The URL the HTTP check ended on after following all redirects. |
http. | The registrable domain the HTTP check ended on after redirects, such as acme.example. |
http. | The host name the HTTP check ended on after redirects, such as www.acme.example. |
http. | A URL in the redirect chain of the HTTP check, listed in the order visited. |
http. | The Accept header, when it was returned in the HTTP check. It is normally a request header (the content types a client accepts), so it is rarely set. |
http. | The Accept-Encoding header, when it was returned in the HTTP check. It is normally a request header (the compression formats a client accepts), so it is rarely set. |
http. | The Accept-Language header, when it was returned in the HTTP check. It is normally a request header (the languages a client prefers), so it is rarely set. |
http. | The Access-Control-Allow-Credentials header returned in the HTTP check; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS). |
http. | The Access-Control-Allow-Headers header returned in the HTTP check; it lists the request headers allowed in cross-origin requests (CORS), for example *. |
http. | The Access-Control-Allow-Methods header returned in the HTTP check; it lists the HTTP methods allowed in cross-origin requests (CORS), for example GET. |
http. | The Access-Control-Allow-Origin header returned in the HTTP check; it names the origins allowed to read the response (CORS), where * allows any origin. |
http. | The Access-Control-Expose-Headers header returned in the HTTP check; it lists the response headers that scripts from other origins may read (CORS). |
http. | The Access-Control-Max-Age header returned in the HTTP check; it says how many seconds browsers may cache a CORS preflight result. |
http. | The Alt-Svc header returned in the HTTP check; it advertises other protocols or ports that serve the site, for example h3=":443"; ma=86400 for HTTP/3. |
http. | The Authorization header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to the server), so it is rarely set. |
http. | The Cache-Control header returned in the HTTP check; it sets the caching rules for the response, for example no-cache, must-revalidate. |
http. | The Clear-Site-Data header returned in the HTTP check; it tells browsers to clear stored data for the site, such as cookies, storage or cache. |
http. | The Content-Disposition header returned in the HTTP check; it says whether the content is shown in the browser or downloaded as a file. |
http. | The Content-Encoding header returned in the HTTP check; it names the compression applied to the response body, for example gzip or br. |
http. | The Content-Language header returned in the HTTP check; it gives the language of the content, for example en or tr. |
http. | The Content-Length header returned in the HTTP check; it gives the size of the response body in bytes. |
http. | The Content-Range header returned in the HTTP check; it says which part of the full body a partial response holds. |
http. | The Content-Security-Policy header returned in the HTTP check; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from. |
http. | The Content-Type header returned in the HTTP check; it gives the media type and character set of the response body, for example text/html; charset=utf-8. |
http. | The Cookie header, when it was returned in the HTTP check. It is normally a request header (the cookies a client sends), so it is rarely set. |
http. | The Cross-Origin-Embedder-Policy header returned in the HTTP check; it controls whether the page may embed cross-origin resources that do not explicitly allow it. |
http. | The Cross-Origin-Opener-Policy header returned in the HTTP check; it controls whether the page shares its browsing context with cross-origin windows. |
http. | The Cross-Origin-Resource-Policy header returned in the HTTP check; it controls which sites may load the resource. |
http. | The Date header returned in the HTTP check; it gives the time the server generated the response, in HTTP date format, for example Sun, 01 Jun 2025 08:00:00 GMT. |
http. | The Early-Data header, when it was returned in the HTTP check. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set. |
http. | The Expect-CT header returned in the HTTP check; it is a deprecated header about Certificate Transparency enforcement. |
http. | The Expires header returned in the HTTP check; it gives the date after which the response counts as stale, in HTTP date format. |
http. | The Feature-Policy header returned in the HTTP check; it is the older name of Permissions-Policy and limits the browser features the page may use. |
http. | The Host header, when it was returned in the HTTP check. It is normally a request header (the host name a client asks for), so it is rarely set. |
http. | The If-Modified-Since header, when it was returned in the HTTP check. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set. |
http. | The If-None-Match header, when it was returned in the HTTP check. It is normally a request header (a condition based on an ETag), so it is rarely set. |
http. | The Last-Modified header returned in the HTTP check; it gives the time the server says the resource last changed, in HTTP date format. |
http. | The Origin-Isolation header returned in the HTTP check; it is an experimental header that asks browsers to isolate the site's origin. |
http. | The name of a header returned in the HTTP check that has no field of its own under headers, in lower case such as etag or cf-cache-status. |
http. | The value of a header listed in headers.others for the HTTP check. |
http. | The Permission-Policy header returned in the HTTP check; it is recorded under this singular spelling, separately from Permissions-Policy. |
http. | The Permissions-Policy header returned in the HTTP check; it limits the browser features the page may use, for example camera=(), microphone=(), geolocation=(). |
http. | The Pragma header returned in the HTTP check; it is an older HTTP/1.0 caching header, for example no-cache. |
http. | The Proxy-Authenticate header returned in the HTTP check; it tells a client how to authenticate to a proxy. |
http. | The Proxy-Authorization header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set. |
http. | The Public-Key-Pins header returned in the HTTP check; it is a deprecated header (HPKP) that pinned the site's public keys. |
http. | The Range header, when it was returned in the HTTP check. It is normally a request header (a request for only part of a resource), so it is rarely set. |
http. | The Referer header, when it was returned in the HTTP check. It is normally a request header (the address of the page a request came from), so it is rarely set. |
http. | The Referrer-Policy header returned in the HTTP check; it sets how much referrer information browsers send when leaving the page, for example strict-origin-when-cross-origin. |
http. | The Sec-Fetch-Dest header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the response will be used), so it is rarely set. |
http. | The Sec-Fetch-Mode header, when it was returned in the HTTP check. It is normally a request header (browser metadata on the request mode), so it is rarely set. |
http. | The Sec-Fetch-Site header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set. |
http. | The Sec-Fetch-User header, when it was returned in the HTTP check. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set. |
http. | The Server header returned in the HTTP check; it names the server software the site reports, for example nginx or Apache. |
http. | The Set-Cookie header returned in the HTTP check; it sets cookies, with their attributes. |
http. | The Strict-Transport-Security header returned in the HTTP check; it tells browsers to reach the site over HTTPS only (HSTS), for example max-age=31536000; includeSubDomains; preload. |
http. | The TE header, when it was returned in the HTTP check. It is normally a request header (the transfer encodings a client accepts), so it is rarely set. |
http. | The Transfer-Encoding header returned in the HTTP check; it says how the body is transferred, for example chunked. |
http. | The Upgrade header returned in the HTTP check; it offers or asks for a switch to another protocol. |
http. | The User-Agent header, when it was returned in the HTTP check. It is normally a request header (the client software), so it is rarely set. |
http. | The Vary header returned in the HTTP check; it tells caches which request headers change the response, for example Accept-Encoding. |
http. | The WWW-Authenticate header returned in the HTTP check; it tells a client how to authenticate, usually with a 401 response. |
http. | The X-Content-Type-Options header returned in the HTTP check; it stops browsers from guessing the content type when set to nosniff. |
http. | The X-Download-Options header returned in the HTTP check; it stops Internet Explorer from opening downloads directly when set to noopen. |
http. | The X-Frame-Options header returned in the HTTP check; it says whether the page may be shown in a frame (a protection against clickjacking), for example DENY or SAMEORIGIN. |
http. | The X-Permitted-Cross-Domain-Policies header returned in the HTTP check; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files. |
http. | The X-Powered-By header returned in the HTTP check; it names the technology the server reports running on, for example Express. |
http. | The X-XSS-Protection header returned in the HTTP check; it is an older setting for the browser's cross-site scripting filter, for example 1; mode=block or 0. |
http. | The name of a cookie set in the HTTP check. |
http. | The value of a cookie set in the HTTP check. |
http. | A SHA-256 hash of the page source returned in the HTTP check; the same hash means the same source. |
http_ | The HTTP check fields that changed in the last change seen, as field paths such as http.html.source_code_hash. |
webdata. | The URL the web data scan started from, such as http://acme.example. |
webdata. | The registrable domain of the URL the web data scan started from. |
webdata. | The host name of the URL the web data scan started from. |
webdata. | The host names of links on the scanned page that stay within the site's own domain, such as other subdomains. |
webdata. | The registrable domains of links on the scanned page that point to other domains, such as kestrel.example. |
webdata. | The host names of links on the scanned page that point to other domains, such as www.kestrel.example. |
webdata. | The full URLs of links on the scanned page that point to other domains. |
webdata. | The URLs of the scripts the scanned page loads. |
webdata. | The URLs of the frames (iframes) embedded in the scanned page. |
webdata. | The name of an analytics or advertising tracker found on the scanned page, such as google_adsense or google_tag_manager. |
webdata. | The IDs found for a tracker, such as a Google Analytics ID that starts with G- or UA-. |
webdata. | The e-mail addresses found on the scanned page. |
webdata. | The e-mail addresses found on the scanned page that belong to the site's own domain. |
webdata. | A SHA-256 hash of the page source in the web data scan; the same hash means the same source. |
webdata. | A SHA-256 hash of the page content in the web data scan, kept apart from source_code_hash, the hash of the raw source. |
webdata. | The most frequent words in the text of the scanned page. |
webdata. | The URLs of the icons the scanned page declares, such as its favicon and touch icons. |
webdata. | The site or application name declared in the scanned page's metadata. |
webdata. | The meta description of the scanned page. |
webdata. | The language the scanned page declares, such as en, tr or en-US. |
webdata. | The languages of the alternative versions the scanned page links to, such as en or ar. |
webdata. | The keywords listed in the keywords meta tag of the scanned page. |
webdata. | The character encoding the scanned page declares, such as utf-8. |
webdata. | The canonical URL the scanned page declares. |
webdata. | The title of the scanned page. |
webdata. | The URL of a site icon (favicon) recorded by the web data scan. |
webdata. | A SHA-256 hash of a site icon; the same hash means the same icon. |
webdata. | The URL the web data scan ended on after following all redirects. |
webdata. | The registrable domain the web data scan ended on after redirects, such as acme.example. |
webdata. | The host name the web data scan ended on after redirects, such as www.acme.example. |
webdata. | A URL in the redirect chain of the web data scan, listed in the order visited. |
webdata. | How a step of the web data scan's redirect chain was made; http-header (a redirect sent in the HTTP response) is the value in the samples. |
webdata. | The Accept header, when it was returned in the web data scan. It is normally a request header (the content types a client accepts), so it is rarely set. |
webdata. | The Accept-Encoding header, when it was returned in the web data scan. It is normally a request header (the compression formats a client accepts), so it is rarely set. |
webdata. | The Accept-Language header, when it was returned in the web data scan. It is normally a request header (the languages a client prefers), so it is rarely set. |
webdata. | The Access-Control-Allow-Credentials header returned in the web data scan; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS). |
webdata. | The Access-Control-Allow-Headers header returned in the web data scan; it lists the request headers allowed in cross-origin requests (CORS), for example *. |
webdata. | The Access-Control-Allow-Methods header returned in the web data scan; it lists the HTTP methods allowed in cross-origin requests (CORS), for example GET. |
webdata. | The Access-Control-Allow-Origin header returned in the web data scan; it names the origins allowed to read the response (CORS), where * allows any origin. |
webdata. | The Access-Control-Expose-Headers header returned in the web data scan; it lists the response headers that scripts from other origins may read (CORS). |
webdata. | The Access-Control-Max-Age header returned in the web data scan; it says how many seconds browsers may cache a CORS preflight result. |
webdata. | The Alt-Svc header returned in the web data scan; it advertises other protocols or ports that serve the site, for example h3=":443"; ma=86400 for HTTP/3. |
webdata. | The Authorization header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to the server), so it is rarely set. |
webdata. | The Cache-Control header returned in the web data scan; it sets the caching rules for the response, for example no-cache, must-revalidate. |
webdata. | The Clear-Site-Data header returned in the web data scan; it tells browsers to clear stored data for the site, such as cookies, storage or cache. |
webdata. | The Content-Disposition header returned in the web data scan; it says whether the content is shown in the browser or downloaded as a file. |
webdata. | The Content-Encoding header returned in the web data scan; it names the compression applied to the response body, for example gzip or br. |
webdata. | The Content-Language header returned in the web data scan; it gives the language of the content, for example en or tr. |
webdata. | The Content-Length header returned in the web data scan; it gives the size of the response body in bytes. |
webdata. | The Content-Range header returned in the web data scan; it says which part of the full body a partial response holds. |
webdata. | The Content-Security-Policy header returned in the web data scan; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from. |
webdata. | The Content-Type header returned in the web data scan; it gives the media type and character set of the response body, for example text/html; charset=utf-8. |
webdata. | The Cookie header, when it was returned in the web data scan. It is normally a request header (the cookies a client sends), so it is rarely set. |
webdata. | The Cross-Origin-Embedder-Policy header returned in the web data scan; it controls whether the page may embed cross-origin resources that do not explicitly allow it. |
webdata. | The Cross-Origin-Opener-Policy header returned in the web data scan; it controls whether the page shares its browsing context with cross-origin windows. |
webdata. | The Cross-Origin-Resource-Policy header returned in the web data scan; it controls which sites may load the resource. |
webdata. | The Date header returned in the web data scan; it gives the time the server generated the response, in HTTP date format, for example Sun, 01 Jun 2025 08:00:00 GMT. |
webdata. | The Early-Data header, when it was returned in the web data scan. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set. |
webdata. | The Expect-CT header returned in the web data scan; it is a deprecated header about Certificate Transparency enforcement. |
webdata. | The Expires header returned in the web data scan; it gives the date after which the response counts as stale, in HTTP date format. |
webdata. | The Feature-Policy header returned in the web data scan; it is the older name of Permissions-Policy and limits the browser features the page may use. |
webdata. | The Host header, when it was returned in the web data scan. It is normally a request header (the host name a client asks for), so it is rarely set. |
webdata. | The If-Modified-Since header, when it was returned in the web data scan. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set. |
webdata. | The If-None-Match header, when it was returned in the web data scan. It is normally a request header (a condition based on an ETag), so it is rarely set. |
webdata. | The Last-Modified header returned in the web data scan; it gives the time the server says the resource last changed, in HTTP date format. |
webdata. | The Origin-Isolation header returned in the web data scan; it is an experimental header that asks browsers to isolate the site's origin. |
webdata. | The name of a header returned in the web data scan that has no field of its own under headers, in lower case such as etag or cf-cache-status. |
webdata. | The value of a header listed in headers.others for the web data scan. |
webdata. | The Permission-Policy header returned in the web data scan; it is recorded under this singular spelling, separately from Permissions-Policy. |
webdata. | The Permissions-Policy header returned in the web data scan; it limits the browser features the page may use, for example camera=(), microphone=(), geolocation=(). |
webdata. | The Pragma header returned in the web data scan; it is an older HTTP/1.0 caching header, for example no-cache. |
webdata. | The Proxy-Authenticate header returned in the web data scan; it tells a client how to authenticate to a proxy. |
webdata. | The Proxy-Authorization header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set. |
webdata. | The Public-Key-Pins header returned in the web data scan; it is a deprecated header (HPKP) that pinned the site's public keys. |
webdata. | The Range header, when it was returned in the web data scan. It is normally a request header (a request for only part of a resource), so it is rarely set. |
webdata. | The Referer header, when it was returned in the web data scan. It is normally a request header (the address of the page a request came from), so it is rarely set. |
webdata. | The Referrer-Policy header returned in the web data scan; it sets how much referrer information browsers send when leaving the page, for example strict-origin-when-cross-origin. |
webdata. | The Sec-Fetch-Dest header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the response will be used), so it is rarely set. |
webdata. | The Sec-Fetch-Mode header, when it was returned in the web data scan. It is normally a request header (browser metadata on the request mode), so it is rarely set. |
webdata. | The Sec-Fetch-Site header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set. |
webdata. | The Sec-Fetch-User header, when it was returned in the web data scan. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set. |
webdata. | The Server header returned in the web data scan; it names the server software the site reports, for example nginx or Apache. |
webdata. | The Set-Cookie header returned in the web data scan; it sets cookies, with their attributes. |
webdata. | The Strict-Transport-Security header returned in the web data scan; it tells browsers to reach the site over HTTPS only (HSTS), for example max-age=31536000; includeSubDomains; preload. |
webdata. | The TE header, when it was returned in the web data scan. It is normally a request header (the transfer encodings a client accepts), so it is rarely set. |
webdata. | The Transfer-Encoding header returned in the web data scan; it says how the body is transferred, for example chunked. |
webdata. | The Upgrade header returned in the web data scan; it offers or asks for a switch to another protocol. |
webdata. | The User-Agent header, when it was returned in the web data scan. It is normally a request header (the client software), so it is rarely set. |
webdata. | The Vary header returned in the web data scan; it tells caches which request headers change the response, for example Accept-Encoding. |
webdata. | The WWW-Authenticate header returned in the web data scan; it tells a client how to authenticate, usually with a 401 response. |
webdata. | The X-Content-Type-Options header returned in the web data scan; it stops browsers from guessing the content type when set to nosniff. |
webdata. | The X-Download-Options header returned in the web data scan; it stops Internet Explorer from opening downloads directly when set to noopen. |
webdata. | The X-Frame-Options header returned in the web data scan; it says whether the page may be shown in a frame (a protection against clickjacking), for example DENY or SAMEORIGIN. |
webdata. | The X-Permitted-Cross-Domain-Policies header returned in the web data scan; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files. |
webdata. | The X-Powered-By header returned in the web data scan; it names the technology the server reports running on, for example Express. |
webdata. | The X-XSS-Protection header returned in the web data scan; it is an older setting for the browser's cross-site scripting filter, for example 1; mode=block or 0. |
webdata. | The name of a cookie set in the web data scan. |
webdata. | The value of a cookie set in the web data scan. |
webdata. | The domain a cookie set in the web data scan applies to, such as .acme.example. |
webdata. | The path a cookie set in the web data scan applies to, such as /. |
webdata. | The SameParty attribute of a cookie set in the web data scan; in the samples it always holds the same value as same_site, such as Lax or None. |
webdata. | The Priority attribute of a cookie set in the web data scan (Low, Medium or High in Chromium-based browsers). |
webdata. | The SameSite attribute of a cookie set in the web data scan, such as Lax, Strict or None. |
webdata. | A short identifier of a technology detected on the site, such as iis or windows-server. |
webdata. | The name of a technology detected on the site, such as IIS or Microsoft ASP.NET. |
webdata. | The file name of a detected technology's icon, such as acme.png. |
webdata. | The website of a detected technology's vendor or project. |
webdata. | The CPE identifier of a detected technology, such as cpe:/a:acme:acme-portal, used to match it to known vulnerabilities. |
webdata. | The detected version of a technology, such as 1.0. |
webdata. | The categories of a detected technology, such as Web servers or Operating systems. |
webdata. | A short description of a detected technology. |
webdata_ | The web data fields that changed in the last change seen, as field paths under webdata. |
ipwhois. | The number of the autonomous system (ASN) that announces the IP address asset, as a string such as 13335. |
ipwhois. | The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup. |
ipwhois. | The name and holder of the autonomous system that announces the IP address asset, such as CLOUDFLARENET - Cloudflare, Inc., US. |
ipwhois. | The country of the autonomous system that announces the IP address asset, as a two-letter code such as US. |
ipwhois. | The regional internet registry responsible for the IP address asset, such as arin or ripencc. |
ipwhois. | The handles of the registry contacts and organizations linked to the network of the IP address asset, such as ACME-ARIN. |
ipwhois. | The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation. |
ipwhois. | The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, when it is kept. |
ipwhois. | The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
ipwhois. | The IP address that was looked up in IP WHOIS (RDAP), that is the IP address asset. |
ipwhois. | The raw IP WHOIS response for the IP address asset, when it is kept; empty on every sampled asset. |
ipwhois. | The registered network block that contains the IP address asset, in CIDR notation, such as 192.0.2.0/24; a network made of several blocks lists them separated by commas. |
ipwhois. | The name of the registered network that contains the IP address asset, such as CLOUDFLARENET. |
ipwhois. | The country of the registered network that contains the IP address asset, as a two-letter code such as FR. |
ipwhois. | The first address of the registered network block that contains the IP address asset. |
ipwhois. | The last address of the registered network block that contains the IP address asset. |
ipwhois. | The registry handle of the network that contains the IP address asset, such as NET-192-0-2-0-1. |
ipwhois. | The IP version of the network that contains the IP address asset: v4 or v6. |
ipwhois. | Links to the registry record of the network that contains the IP address asset, such as its RDAP and WHOIS URLs. |
ipwhois. | The handle of the larger network block from which the network of the IP address asset was allocated. |
ipwhois. | The raw RDAP network object for the IP address asset, when it is kept. |
ipwhois. | The registry status of the network that contains the IP address asset, such as active. |
ipwhois. | The registry's allocation type for the network that contains the IP address asset, such as DIRECT ALLOCATION, ALLOCATION or ALLOCATED PA. |
ipwhois. | The title of a notice the registry attached to the network record of the IP address asset, such as Terms of Service. |
ipwhois. | The text of a notice the registry attached to the network record of the IP address asset. |
ipwhois. | Links given in a notice on the network record of the IP address asset. |
ipwhois. | The title of a remark on the network record of the IP address asset, such as Registration Comments. |
ipwhois. | The text of a remark on the network record of the IP address asset. |
ipwhois. | Links given in a remark on the network record of the IP address asset. |
ipwhois. | An event in the history of the network record of the IP address asset, such as registration or last changed. |
ipwhois. | Who performed an event on the network record of the IP address asset, when the registry names one. |
ipwhois. | The handle of a registry contact or organization (RDAP entity) linked to the network of the IP address asset, such as ACME-ARIN. |
ipwhois. | The type of an e-mail address of a contact linked to the network of the IP address asset, such as abuse. |
ipwhois. | An e-mail address of a contact linked to the network of the IP address asset. |
ipwhois. | The type of a postal address of a contact linked to the network of the IP address asset. |
ipwhois. | A postal address of a contact linked to the network of the IP address asset. |
ipwhois. | The type of a phone number of a contact linked to the network of the IP address asset, such as voice or work. |
ipwhois. | A phone number of a contact linked to the network of the IP address asset. |
ipwhois. | What kind of contact is linked to the network of the IP address asset: org, group or individual. |
ipwhois. | The name of a contact or organization linked to the network of the IP address asset, such as Abuse or a company name. |
ipwhois. | The role given in the contact card of an entity linked to the network of the IP address asset. |
ipwhois. | The title given in the contact card of an entity linked to the network of the IP address asset. |
ipwhois. | Handles of further entities listed under a contact linked to the network of the IP address asset. |
ipwhois. | An event in the history of a contact record linked to the network of the IP address asset, such as registration or last changed. |
ipwhois. | Who performed an event on a contact record linked to the network of the IP address asset, when the registry names one. |
ipwhois. | Events in which a contact linked to the network of the IP address asset is itself the actor (the RDAP asEventActor list), as text; empty on every sampled record. |
ipwhois. | The registry handle of a contact or organization linked to the network of the IP address asset. |
ipwhois. | Links to the registry record of a contact linked to the network of the IP address asset. |
ipwhois. | The title of a notice on a contact record linked to the network of the IP address asset, such as Terms of Service. |
ipwhois. | The text of a notice on a contact record linked to the network of the IP address asset. |
ipwhois. | Links given in a notice on a contact record linked to the network of the IP address asset. |
ipwhois. | The raw RDAP object of a contact linked to the network of the IP address asset, when it is kept. |
ipwhois. | The title of a remark on a contact record linked to the network of the IP address asset, such as Registration Comments. |
ipwhois. | The text of a remark on a contact record linked to the network of the IP address asset. |
ipwhois. | Links given in a remark on a contact record linked to the network of the IP address asset. |
ipwhois. | The roles of a contact for the network of the IP address asset, such as registrant, abuse or technical. |
ipwhois. | The registry status of a contact linked to the network of the IP address asset, such as validated. |
ipwhois_ | The IP WHOIS fields that changed in the last change seen, as field paths under ipwhois. |
ipdns. | The PTR (reverse DNS) host names of an IP address asset. |
ipdns_ | The reverse DNS fields that changed in the last change seen, as field paths under ipdns. |
issue_ | The name of an issue category in the per-category issue counts of the asset, such as DNS, SSL/TLS, Web Application, Domain/Whois or Network. |
technology_ | The name of a technology category in the per-category technology counts of the asset, such as Web servers or Analytics. |
domain_ | The name of an issue category in the per-category issue counts of the domain and its subdomains together, such as DNS, SSL/TLS, Web Application, Domain/Whois or Network. Set on domain assets. |
domain_ | The name of a technology category in the per-category technology counts of the domain and its subdomains together, such as Web servers or Analytics. Set on domain assets. |
Operators eq in gte lte exists
| Field | Description |
|---|---|
added_ | When the asset was added to your inventory (UTC date-time). |
latest_ | When the asset was last scanned, shown as the last check date in Inventory (UTC date-time). |
seems_ | When the asset was first found to seem inactive (UTC date-time). |
seems_ | When the asset was most recently found to seem inactive (UTC date-time). |
login_ | The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where is_login_page is true. |
fqdn. | The number of characters in the name without the extension: 4 for acme.example. |
website. | The port of a website asset, such as 443. |
whois. | When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time). |
whois. | When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time). |
whois. | When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time). |
whois_ | Every creation date seen for the domain over time, so a domain that was deleted and registered again keeps its earlier dates too (UTC date-times). |
whois_ | When the WHOIS record of the asset was last checked (UTC date-time). |
whois_ | When a change in the WHOIS record of the asset was last seen (UTC date-time). |
dns. | When the A record text (dns.a.value) last changed (UTC date-time). |
dns. | When the response code of the A lookup (dns.a.rcode) last changed (UTC date-time). |
dns. | When the asset's A records last changed, in their text or their response code (UTC date-time). |
dns. | The registry allocation date that the ASN lookup reports for the A-record address, as a date at midnight UTC. |
dns. | When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time). |
dns. | When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time). |
dns. | When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was created (UTC date-time). |
dns. | When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was last updated (UTC date-time). |
dns. | When an event on the network record of the A-record address happened (UTC date-time). |
dns. | When an event on a contact record linked to the network of the A-record address happened (UTC date-time). |
dns. | When the AAAA record text (dns.aaaa.value) last changed (UTC date-time). |
dns. | When the response code of the AAAA lookup (dns.aaaa.rcode) last changed (UTC date-time). |
dns. | When the asset's AAAA records last changed, in their text or their response code (UTC date-time). |
dns. | When the CAA record text (dns.caa.value) last changed (UTC date-time). |
dns. | When the response code of the CAA lookup (dns.caa.rcode) last changed (UTC date-time). |
dns. | When the asset's CAA records last changed, in their text or their response code (UTC date-time). |
dns. | When the CNAME record text (dns.cname.value) last changed (UTC date-time). |
dns. | When the response code of the CNAME lookup (dns.cname.rcode) last changed (UTC date-time). |
dns. | When the asset's CNAME records last changed, in their text or their response code (UTC date-time). |
dns. | When the DNSKEY record text (dns.dnskey.value) last changed (UTC date-time). |
dns. | When the response code of the DNSKEY lookup (dns.dnskey.rcode) last changed (UTC date-time). |
dns. | When the asset's DNSKEY records last changed, in their text or their response code (UTC date-time). |
dns. | When the DS record text (dns.ds.value) last changed (UTC date-time). |
dns. | When the response code of the DS lookup (dns.ds.rcode) last changed (UTC date-time). |
dns. | When the asset's DS records last changed, in their text or their response code (UTC date-time). |
dns. | The key tag (a number) of the DNSKEY that a DS record refers to. |
dns. | When the MX record text (dns.mx.value) last changed (UTC date-time). |
dns. | When the response code of the MX lookup (dns.mx.rcode) last changed (UTC date-time). |
dns. | When the asset's MX records last changed, in their text or their response code (UTC date-time). |
dns. | When the NS record text (dns.ns.value) last changed (UTC date-time). |
dns. | When the response code of the NS lookup (dns.ns.rcode) last changed (UTC date-time). |
dns. | When the asset's NS records last changed, in their text or their response code (UTC date-time). |
dns. | When the NSEC record text (dns.nsec.value) last changed (UTC date-time). |
dns. | When the response code of the NSEC lookup (dns.nsec.rcode) last changed (UTC date-time). |
dns. | When the asset's NSEC records last changed, in their text or their response code (UTC date-time). |
dns. | When the NSEC3 record text (dns.nsec3.value) last changed (UTC date-time). |
dns. | When the response code of the NSEC3 lookup (dns.nsec3.rcode) last changed (UTC date-time). |
dns. | When the asset's NSEC3 records last changed, in their text or their response code (UTC date-time). |
dns. | When the RRSIG record text (dns.rrsig.value) last changed (UTC date-time). |
dns. | When the response code of the RRSIG lookup (dns.rrsig.rcode) last changed (UTC date-time). |
dns. | When the asset's RRSIG records last changed, in their text or their response code (UTC date-time). |
dns. | When an RRSIG signature becomes valid (UTC date-time). |
dns. | When an RRSIG signature expires (UTC date-time). |
dns. | When the SOA record text (dns.soa.value) last changed (UTC date-time). |
dns. | When the response code of the SOA lookup (dns.soa.rcode) last changed (UTC date-time). |
dns. | When the asset's SOA records last changed, in their text or their response code (UTC date-time). |
dns. | When the SRV record text (dns.srv.value) last changed (UTC date-time). |
dns. | When the response code of the SRV lookup (dns.srv.rcode) last changed (UTC date-time). |
dns. | When the asset's SRV records last changed, in their text or their response code (UTC date-time). |
dns. | The port an SRV record points to. |
dns. | When the TXT record text (dns.txt.value) last changed (UTC date-time). |
dns. | When the response code of the TXT lookup (dns.txt.rcode) last changed (UTC date-time). |
dns. | When the asset's TXT records last changed, in their text or their response code (UTC date-time). |
dns_ | When the DNS records of the asset were last checked (UTC date-time). |
dns_ | When a change in the DNS records of the asset was last seen (UTC date-time). |
ssl. | The port that the asset's TLS certificate was collected on, such as 443. |
ssl. | The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time. |
ssl. | The date the asset's TLS certificate expires (Not After), as a UTC date-time. |
ssl. | The validity period of the certificate in seconds: 7,776,000 seconds are 90 days. |
ssl. | When a Certificate Transparency log recorded the certificate, from a signed certificate timestamp (UTC date-time). |
ssl. | The version of a signed certificate timestamp; 0 stands for version 1. |
ssl_ | When the TLS certificate of the asset was last checked (UTC date-time). |
ssl_ | When a change in the TLS certificate of the asset was last seen (UTC date-time). |
http. | The HTTP status code at a step of the redirect chain of the HTTP check, such as 301 or 200. |
http. | The HTTP status code of the first response in the HTTP check, such as 301 for a redirect or 200. |
http. | The HTTP status code of the last response in the HTTP check, after redirects, such as 200, 404 or 502. Inventory's HTTP status column shows this value. |
http_ | When the HTTP check of the asset last ran (UTC date-time). |
http_ | When a change in the HTTP check result of the asset was last seen (UTC date-time). |
webdata. | The HTTP status code at a step of the redirect chain of the web data scan, such as 301 or 200. |
webdata. | The HTTP status code of the first response in the web data scan, such as 301 for a redirect or 200. |
webdata. | The HTTP status code of the last response in the web data scan, after redirects, such as 200, 404 or 502. |
webdata. | The size of a cookie set in the web data scan, in bytes (name plus value). |
webdata. | When a cookie set in the web data scan expires (UTC date-time); session cookies show 1969-12-31T23:59:59Z. |
webdata. | How certain the detection of a technology is, from 0 to 100; every sampled detection has 100. |
webdata. | The major version of a detected technology as a whole number, such as 1 for version 1.0. |
webdata_ | When the web data scan of the asset, which collects the page content, headers and technologies, last ran (UTC date-time). |
webdata_ | When a change in the web data of the asset was last seen (UTC date-time). |
ipwhois. | The registry allocation date that the ASN lookup reports for the IP address asset, as a date at midnight UTC. |
ipwhois. | When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time). |
ipwhois. | When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time). |
ipwhois. | When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was created (UTC date-time). |
ipwhois. | When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was last updated (UTC date-time). |
ipwhois. | When an event on the network record of the IP address asset happened (UTC date-time). |
ipwhois. | When an event on a contact record linked to the network of the IP address asset happened (UTC date-time). |
ipwhois_ | When the IP WHOIS record of an IP address asset was last checked (UTC date-time). |
ipwhois_ | When a change in the IP WHOIS record of an IP address asset was last seen (UTC date-time). |
ipdns_ | When the reverse DNS (PTR) records of an IP address asset were last checked (UTC date-time). |
ipdns_ | When a change in the reverse DNS (PTR) records of an IP address asset was last seen (UTC date-time). |
subdomain_ | The number of subdomains of the domain in your inventory; set on domain assets. |
pointed_ | A count of host names (FQDNs) that point to the asset; no sampled asset had a value. |
redirected_ | The number of domain assets in your inventory whose HTTP check ends on this asset after redirects. |
redirected_ | The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects. |
average_ | The average duration of the issues on the asset, in seconds. |
average_ | The average time taken to fix the issues on the asset, in seconds. |
open_ | The number of open ports found on the asset. |
open_ | The open port numbers found on the asset, such as 80, 443 or 8080. |
issue_ | The number of issues on the asset in the newly_detected state, an active state set by the platform. |
issue_ | The number of issues on the asset in the reappeared state, an active state set by the platform. |
issue_ | The number of issues on the asset in the unresolved state, an active state set by the platform. |
issue_ | The number of issues on the asset in the marked_as_resolved state, an inactive state that a user sets. |
issue_ | The number of issues on the asset in the risk_accepted state, an inactive state that a user sets. |
issue_ | The number of issues on the asset in the ignored state, an inactive state that a user sets. |
issue_ | The number of issues on the asset in the marked_as_false_positive state, an inactive state that a user sets. |
issue_ | The number of issues on the asset in the not_applicable state, an inactive state set by the platform. |
issue_ | The number of issues on the asset in the verified_resolved state, an inactive state set by the platform. |
issue_ | The number of active issues in that category on the asset. |
issue_ | The number of active issues of critical severity in that category on the asset. |
issue_ | The number of active issues of high severity in that category on the asset. |
issue_ | The number of active issues of medium severity in that category on the asset. |
issue_ | The number of active issues of low severity in that category on the asset. |
issue_ | The number of active issues of information severity in that category on the asset. |
issue_ | The number of issues on the asset in any state, active or inactive. |
issue_ | The number of active issues on the asset: those in the newly_detected, unresolved or reappeared state. |
issue_ | The number of active issues of critical severity on the asset. |
issue_ | The number of active issues of high severity on the asset. |
issue_ | The number of active issues of medium severity on the asset. |
issue_ | The number of active issues of low severity on the asset. |
issue_ | The number of active issues of information severity on the asset. |
technology_ | The number of technologies detected on the asset. |
technology_ | The number of technologies in that category on the asset. |
vulnerability_ | The number of vulnerabilities (CVEs) found on the asset. |
vulnerability_ | The number of vulnerabilities (CVEs) of critical severity on the asset. |
vulnerability_ | The number of vulnerabilities (CVEs) of high severity on the asset. |
vulnerability_ | The number of vulnerabilities (CVEs) of medium severity on the asset. |
vulnerability_ | The number of vulnerabilities (CVEs) of low severity on the asset. |
vulnerability_ | The number of vulnerabilities (CVEs) on the asset whose severity is none. |
vulnerability_ | The number of vulnerabilities (CVEs) on the asset whose severity is unknown. |
security_ | The asset's External Attack Surface Management (EASM) security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300. |
weight | The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score. |
user_ | The weight you set for the asset, from 1 to 100; empty when you have not set one. |
system_ | The weight the platform calculates for the asset from many criteria; it can be above 100. |
domain_ | The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets. |
domain_ | The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets. |
domain_ | The number of open ports found on the domain and its subdomains together. Set on domain assets. |
domain_ | The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as security_score. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets. |
domain_ | The number of active issues on the domain and its subdomains together: those in the newly_detected, unresolved or reappeared state. Set on domain assets. |
domain_ | The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of high severity on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of low severity on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of information severity on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues in that category on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of critical severity in that category on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of high severity in that category on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of medium severity in that category on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of low severity in that category on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of information severity in that category on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the newly_detected state, an active state set by the platform. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the reappeared state, an active state set by the platform. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the unresolved state, an active state set by the platform. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the marked_as_resolved state, an inactive state that a user sets. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the risk_accepted state, an inactive state that a user sets. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the ignored state, an inactive state that a user sets. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the marked_as_false_positive state, an inactive state that a user sets. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the not_applicable state, an inactive state set by the platform. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the verified_resolved state, an inactive state set by the platform. Set on domain assets. |
domain_ | The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets. |
domain_ | The number of distinct technologies in that category across the domain and its subdomains, each counted once. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) whose severity is none across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) whose severity is unknown across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
Operators eq exists
| Field | Description |
|---|---|
is_ | True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports. |
seems_ | True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score. |
discovery_ | True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it. |
dns_ | True when the asset has an active wildcard DNS record (such as *.acme.example), so any subdomain name under it resolves. |
is_ | True when the asset serves a login page; Inventory marks it with a login page icon. |
fqdn. | True when the host name is an internationalized domain name (IDN) with non-ASCII characters. |
fqdn. | True when the name contains confusable characters that look like other letters, such as Cyrillic а for Latin a, a common trick in look-alike domains. |
fqdn. | True when the name (without the extension) contains a hyphen. |
fqdn. | True when the name (without the extension) contains a letter. |
fqdn. | True when the name (without the extension) contains a digit. |
fqdn. | True when the registrable domain is an internationalized domain name (IDN) with non-ASCII characters. |
whois_ | True when the platform flagged WHOIS privacy protection on the domain's registrant details; set on domain assets. |
ssl. | True when the asset's TLS certificate passed validation for the host; when false, ssl.signature.invalid_reason says why. |
ssl. | A flag for whether the certificate chain of the asset's TLS certificate is valid. It was true on every sampled certificate, even one whose validation failed with unable to get issuer certificate. |
ssl. | True when the asset's TLS certificate is self-signed, that is signed by its own key rather than by a certificate authority. |
ssl. | True when the certificate is a certificate authority (CA) certificate, from its Basic Constraints extension. |
ssl. | True when the Extended Key Usage extension allows TLS client authentication. |
ssl. | True when the Extended Key Usage extension allows TLS server authentication, as website certificates need. |
ssl. | True when the Key Usage extension allows the certificate's key to be used for content commitment (non-repudiation). |
ssl. | True when the Key Usage extension allows the certificate's key to be used for signing certificate revocation lists (CRL sign). |
ssl. | True when the Key Usage extension allows the certificate's key to be used for data encipherment. |
ssl. | True when the Key Usage extension allows the certificate's key to be used for digital signatures. |
ssl. | True when the Key Usage extension allows the certificate's key to be used for key agreement. |
ssl. | True when the Key Usage extension allows the certificate's key to be used for signing other certificates (certificate sign). |
ssl. | True when the Key Usage extension allows the certificate's key to be used for key encipherment. |
ssl. | True when the asset's TLS certificate is past its end date. |
http. | True when the HTTP check ended on a different registrable domain than it started on. |
http. | True when the HTTP check ended on a different host name than it started on, for example acme.example to www.acme.example. |
webdata. | A flag of the web data scan that marks pages whose inspection was disabled; it was false on every sampled asset. |
webdata. | True when the scanned page asks search engines not to index it (a noindex robots directive). |
webdata. | True when the web data scan ended on a different registrable domain than it started on. |
webdata. | True when the web data scan ended on a different host name than it started on, for example acme.example to www.acme.example. |
webdata. | True when a cookie set in the web data scan is sent over HTTPS only (Secure attribute). |
webdata. | True when scripts on the page cannot read a cookie set in the web data scan (HttpOnly attribute). |
webdata. | True when a cookie set in the web data scan is a session cookie, deleted when the browser closes. |
is_ | True when the asset is parked; Inventory marks it with a P badge whose tooltip shows where it redirects. |
Operators eq in exists
| Field | Description |
|---|---|
asset_ | The asset type: domain, subdomain, ip or website. |
creation_ | How the asset entered your inventory: manually_added (added directly), manually_approved (approved by someone in Discovery) or auto_approved (added by a discovery rule with auto approval). |
fqdn. | The kind of extension: gTLD for generic extensions such as com, ccTLD for country-code extensions such as de or co.uk. |
dns. | The role of a DNSKEY: ZSK (zone-signing key), KSK (key-signing key) or KSK_REVOKED (revoked key-signing key). |
dns. | The DNSSEC algorithm of a DNSKEY, such as ECDSAP256SHA256 or RSASHA256. |
dns. | The DNSSEC algorithm of the key that a DS record refers to, such as ECDSAP256SHA256 or RSASHA256. |
dns. | The hash used for a DS record's digest: SHA1, SHA256, SHA384, GOST or NULL. |
dns. | The DNSSEC algorithm of an RRSIG signature, such as ECDSAP256SHA256 or RSASHA256. |
Operators Not measured
| Field | Description |
|---|---|
website. | The asset type of the website's parent asset, such as subdomain. |
Sortable Fields
| Field | Description |
|---|---|
asset | The asset's name: a domain, subdomain or IP address, or for a website asset host:port. |
added_ | When the asset was added to your inventory (UTC date-time). |
creation_ | How the asset entered your inventory: manually_added (added directly), manually_approved (approved by someone in Discovery) or auto_approved (added by a discovery rule with auto approval). |
latest_ | When the asset was last scanned, shown as the last check date in Inventory (UTC date-time). |
is_ | True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports. |
seems_ | True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score. |
seems_ | When the asset was first found to seem inactive (UTC date-time). |
seems_ | When the asset was most recently found to seem inactive (UTC date-time). |
discovery_ | True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it. |
dns_ | True when the asset has an active wildcard DNS record (such as *.acme.example), so any subdomain name under it resolves. |
is_ | True when the asset serves a login page; Inventory marks it with a login page icon. |
login_ | The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where is_login_page is true. |
fqdn. | The asset's full host name (FQDN) in its readable Unicode form. |
fqdn. | The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals fqdn.unicode. |
fqdn. | The registrable domain the asset belongs to, in Unicode: acme.example for both acme.example and www.acme.example. |
fqdn. | The registrable domain the asset belongs to, in its ASCII (punycode) form. |
fqdn. | The domain's extension, everything after the name, such as com or co.uk. |
fqdn. | The top-level part of the extension: uk for both uk and co.uk. |
fqdn. | The kind of extension: gTLD for generic extensions such as com, ccTLD for country-code extensions such as de or co.uk. |
website. | The port of a website asset, such as 443. |
whois. | When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time). |
whois. | When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time). |
whois. | When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time). |
whois. | The domain's EPP status codes from WHOIS, in lower case without spaces, such as clienttransferprohibited. |
whois. | The name servers listed in the WHOIS record, such as ns1.acme.example. |
whois. | The registrar the domain is registered through, as written in WHOIS (usually lower case). |
whois. | The registrant's organization in WHOIS; often a privacy placeholder such as redacted for privacy or a proxy service. |
whois. | The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead. |
whois. | The registrant's phone number in WHOIS, in the registry format such as +1.4805551234. |
dns. | An IPv4 address from the asset's A records (the A-record address); the other dns.a.ip_addresses fields hold its IP WHOIS (RDAP) data. |
dns. | The number of the autonomous system (ASN) that announces the A-record address, as a string such as 13335. |
dns. | The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup. |
dns. | The name and holder of the autonomous system that announces the A-record address, such as CLOUDFLARENET - Cloudflare, Inc., US. |
dns. | The country of the autonomous system that announces the A-record address, as a two-letter code such as US. |
dns. | The regional internet registry responsible for the A-record address, such as arin or ripencc. |
dns. | The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation. |
dns. | The registered network block that contains the A-record address, in CIDR notation, such as 192.0.2.0/24; a network made of several blocks lists them separated by commas. |
dns. | The name of the registered network that contains the A-record address, such as CLOUDFLARENET. |
dns. | The country of the registered network that contains the A-record address, as a two-letter code such as FR. |
dns. | The name server host names from the asset's NS records, such as ns1.acme.example. |
dns. | The mail server host names from the asset's MX records, such as mail.acme.example. |
dns_ | When a change in the DNS records of the asset was last seen (UTC date-time). |
ssl. | The serial number of the asset's TLS certificate, as a decimal string. |
ssl. | The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex. |
ssl. | The organization (O) of the subject (holder) of the asset's TLS certificate. |
ssl. | The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time. |
ssl. | The date the asset's TLS certificate expires (Not After), as a UTC date-time. |
ssl_ | When a change in the TLS certificate of the asset was last seen (UTC date-time). |
http. | The registrable domain the HTTP check ended on after redirects, such as acme.example. |
http. | The host name the HTTP check ended on after redirects, such as www.acme.example. |
http. | The HTTP status code of the first response in the HTTP check, such as 301 for a redirect or 200. |
http. | The HTTP status code of the last response in the HTTP check, after redirects, such as 200, 404 or 502. Inventory's HTTP status column shows this value. |
http_ | When a change in the HTTP check result of the asset was last seen (UTC date-time). |
webdata. | The registrable domain the web data scan ended on after redirects, such as acme.example. |
webdata. | The host name the web data scan ended on after redirects, such as www.acme.example. |
webdata. | The HTTP status code of the first response in the web data scan, such as 301 for a redirect or 200. |
webdata. | The HTTP status code of the last response in the web data scan, after redirects, such as 200, 404 or 502. |
webdata_ | When a change in the web data of the asset was last seen (UTC date-time). |
ipwhois. | The number of the autonomous system (ASN) that announces the IP address asset, as a string such as 13335. |
ipwhois. | The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup. |
ipwhois. | The name and holder of the autonomous system that announces the IP address asset, such as CLOUDFLARENET - Cloudflare, Inc., US. |
ipwhois. | The country of the autonomous system that announces the IP address asset, as a two-letter code such as US. |
ipwhois. | The regional internet registry responsible for the IP address asset, such as arin or ripencc. |
ipwhois. | The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation. |
ipwhois. | The registered network block that contains the IP address asset, in CIDR notation, such as 192.0.2.0/24; a network made of several blocks lists them separated by commas. |
ipwhois. | The name of the registered network that contains the IP address asset, such as CLOUDFLARENET. |
ipwhois. | The country of the registered network that contains the IP address asset, as a two-letter code such as FR. |
subdomain_ | The number of subdomains of the domain in your inventory; set on domain assets. |
website_ | The number of website assets (host:port) in your inventory that belong to this asset. |
pointed_ | A count of host names (FQDNs) that point to the asset; no sampled asset had a value. |
redirected_ | The number of domain assets in your inventory whose HTTP check ends on this asset after redirects. |
redirected_ | The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects. |
open_ | The number of open ports found on the asset. |
average_ | The average duration of the issues on the asset, in seconds. |
average_ | The average time taken to fix the issues on the asset, in seconds. |
issue_ | The number of issues on the asset in the newly_detected state, an active state set by the platform. |
issue_ | The number of issues on the asset in the reappeared state, an active state set by the platform. |
issue_ | The number of issues on the asset in the unresolved state, an active state set by the platform. |
issue_ | The number of issues on the asset in the marked_as_resolved state, an inactive state that a user sets. |
issue_ | The number of issues on the asset in the risk_accepted state, an inactive state that a user sets. |
issue_ | The number of issues on the asset in the ignored state, an inactive state that a user sets. |
issue_ | The number of issues on the asset in the marked_as_false_positive state, an inactive state that a user sets. |
issue_ | The number of issues on the asset in the not_applicable state, an inactive state set by the platform. |
issue_ | The number of issues on the asset in the verified_resolved state, an inactive state set by the platform. |
issue_ | The number of issues on the asset in any state, active or inactive. |
issue_ | The number of active issues on the asset: those in the newly_detected, unresolved or reappeared state. |
issue_ | The number of active issues of critical severity on the asset. |
issue_ | The number of active issues of high severity on the asset. |
issue_ | The number of active issues of medium severity on the asset. |
technology_ | The number of technologies detected on the asset. |
vulnerability_ | The number of vulnerabilities (CVEs) found on the asset. |
vulnerability_ | The number of vulnerabilities (CVEs) of critical severity on the asset. |
security_ | The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300. |
weight | The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score. |
user_ | The weight you set for the asset, from 1 to 100; empty when you have not set one. |
system_ | The weight the platform calculates for the asset from many criteria; it can be above 100. |
domain_ | The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets. |
domain_ | The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets. |
domain_ | The number of open ports found on the domain and its subdomains together. Set on domain assets. |
domain_ | The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as security_score. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets. |
domain_ | The number of active issues on the domain and its subdomains together: those in the newly_detected, unresolved or reappeared state. Set on domain assets. |
domain_ | The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of high severity on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of low severity on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of active issues of information severity on the domain and its subdomains together. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the newly_detected state, an active state set by the platform. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the reappeared state, an active state set by the platform. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the unresolved state, an active state set by the platform. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the marked_as_resolved state, an inactive state that a user sets. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the risk_accepted state, an inactive state that a user sets. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the ignored state, an inactive state that a user sets. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the marked_as_false_positive state, an inactive state that a user sets. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the not_applicable state, an inactive state set by the platform. Set on domain assets. |
domain_ | The number of issues on the domain and its subdomains together in the verified_resolved state, an inactive state set by the platform. Set on domain assets. |
domain_ | The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) whose severity is none across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
domain_ | The number of vulnerabilities (CVEs) whose severity is unknown across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets. |
Response Fields
| Field | Type |
|---|---|
deleted_ | integer |
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
deleted_asset_count | number | 1 |
Examples
Selecting one loads it into the request and response panels.