POSThttps://api.deepinfo.com/v1/easm/assets/search:set-tag

Adds tags (1–10) to every asset matching filters.

The action applies to every record matching filters. Always send a filter (for example by id); an empty filter matches all records.

Authentication

Send your API key in the apikey request header.

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
tagsarrayRequired
min items 1; max items 10
application/json
{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "acme.example"
      }
    ]
  },
  "tags": [
    "production"
  ]
}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "asset",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with some of the filters of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value; Searchable Fields lists them all. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in startswith endswith wildcard fuzzy contains_any contains_all exists

FieldDescription
assetThe asset's name: a domain, subdomain or IP address, or for a website asset host:port.
tagsYour own labels on the asset, such as a business unit or an environment; each tag is 3 to 100 characters long.
fqdn.unicodeThe asset's full host name (FQDN) in its readable Unicode form.
fqdn.punycodeThe asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals fqdn.unicode.
fqdn.name.unicodeThe host name without its extension, in Unicode: acme for acme.example, www.acme for www.acme.example.
fqdn.name.latinizedLatin-letter spellings of a name that has non-Latin or accented letters, so a search for istanbul also finds names written with İ.
fqdn.domain.unicodeThe registrable domain the asset belongs to, in Unicode: acme.example for both acme.example and www.acme.example.
fqdn.domain.punycodeThe registrable domain the asset belongs to, in its ASCII (punycode) form.
fqdn.domain.extension.unicodeThe domain's extension, everything after the name, such as com or co.uk.
fqdn.domain.extension_root.unicodeThe top-level part of the extension: uk for both uk and co.uk.
fqdn.domain.extension_sub.unicodeThe second-level part of a two-part extension, such as co in co.uk; empty for single-part extensions.
website.pathThe URL path of a website asset, such as /.
website.schemeThe URL scheme of a website asset, such as http.
website.parent_asset.idThe ID of the domain or subdomain asset that a website asset belongs to.
website.parent_asset.nameThe name of the domain or subdomain asset that a website asset belongs to.
whois.domain_statusThe domain's EPP status codes from WHOIS, in lower case without spaces, such as clienttransferprohibited.
whois.name_serversThe name servers listed in the WHOIS record, such as ns1.acme.example.
whois.registrarThe registrar the domain is registered through, as written in WHOIS (usually lower case).
whois.registrant.organizationThe registrant's organization in WHOIS; often a privacy placeholder such as redacted for privacy or a proxy service.
whois.registrant.nameThe registrant's name in WHOIS; often a privacy placeholder such as redacted for privacy.
whois.registrant.countryThe registrant's country in WHOIS, as a two-letter code in lower case such as us.
whois.registrant.stateThe registrant's state or province in WHOIS.
whois.registrant.cityThe registrant's city in WHOIS.
whois.registrant.streetThe registrant's street address in WHOIS.
whois.registrant.postal_codeThe registrant's postal code in WHOIS.
whois.registrant.emailThe registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.
whois.registrant.phoneThe registrant's phone number in WHOIS, in the registry format such as +1.4805551234.
whois_registrant_email_historicalEvery registrant e-mail address seen for the domain over time, the current one included.
whois_normalized.registrarThe registrar reduced to a short normalized name, such as godaddy or gandi, so the same registrar matches across spellings.
whois_normalized.registrant.emailThe registrant e-mail address after WHOIS normalization.
whois_normalized.registrant.email_realAnother normalized registrant e-mail field, set on fewer domains than whois_normalized.registrant.email; in the samples it is set only where whois_privacy_enabled is false, with the same address.
whois_normalized.registrant.email_domain_apexThe registrable domain of the registrant e-mail address: acme.example for user@mail.acme.example.
whois_normalized.registrant.email_fqdn_apexThe full host name after the @ of the registrant e-mail address: mail.acme.example for user@mail.acme.example.
whois_normalized.registrant.organizationThe registrant organization cleaned up across registrars: lower case, with spaces and punctuation removed, such as domainsbyproxyllc.
whois_normalized.registrant.phoneThe registrant phone number reduced to its digits, such as 14805551234.
whois_last_change_dataThe WHOIS fields that changed in the last change seen, as field paths such as whois.update_date or whois.domain_status.
dns.a.valueThe asset's current A records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.a.value_previousThe asset's A records as they were before the last change, in the same text form as dns.a.value.
dns.a.rcodeThe DNS response code returned for the asset's A lookup, such as NOERROR.
dns.a.rcode_previousThe DNS response code of the A lookup before it last changed.
dns.a.ip_addresses.ipAn IPv4 address from the asset's A records (the A-record address); the other dns.a.ip_addresses fields hold its IP WHOIS (RDAP) data.
dns.a.ip_addresses.asnThe number of the autonomous system (ASN) that announces the A-record address, as a string such as 13335.
dns.a.ip_addresses.asn_cidrThe routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.
dns.a.ip_addresses.asn_descriptionThe name and holder of the autonomous system that announces the A-record address, such as CLOUDFLARENET - Cloudflare, Inc., US.
dns.a.ip_addresses.asn_country_codeThe country of the autonomous system that announces the A-record address, as a two-letter code such as US.
dns.a.ip_addresses.asn_registryThe regional internet registry responsible for the A-record address, such as arin or ripencc.
dns.a.ip_addresses.entitiesThe handles of the registry contacts and organizations linked to the network of the A-record address, such as ACME-ARIN.
dns.a.ip_addresses.nir.nets.addressThe postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.cidrThe range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.
dns.a.ip_addresses.nir.nets.contacts.admin.divisionThe division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.admin.emailThe e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.admin.faxThe fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.admin.organizationThe organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.admin.phoneThe phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.admin.reply_emailThe reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.admin.nameThe name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.admin.titleThe job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.tech.divisionThe division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.tech.emailThe e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.tech.faxThe fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.tech.organizationThe organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.tech.phoneThe phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.tech.reply_emailThe reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.tech.nameThe name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.contacts.tech.titleThe job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.countryThe country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.handleThe registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.nameThe name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.nameserversThe name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.postal_codeThe postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.nets.rangeThe address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.nir.rawThe raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, when it is kept.
dns.a.ip_addresses.nir.queryThe IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address.
dns.a.ip_addresses.queryThe IP address that was looked up in IP WHOIS (RDAP), that is the A-record address.
dns.a.ip_addresses.rawThe raw IP WHOIS response for the A-record address, when it is kept; empty on every sampled asset.
dns.a.ip_addresses.network.cidrThe registered network block that contains the A-record address, in CIDR notation, such as 192.0.2.0/24; a network made of several blocks lists them separated by commas.
dns.a.ip_addresses.network.nameThe name of the registered network that contains the A-record address, such as CLOUDFLARENET.
dns.a.ip_addresses.network.countryThe country of the registered network that contains the A-record address, as a two-letter code such as FR.
dns.a.ip_addresses.network.start_addressThe first address of the registered network block that contains the A-record address.
dns.a.ip_addresses.network.end_addressThe last address of the registered network block that contains the A-record address.
dns.a.ip_addresses.network.handleThe registry handle of the network that contains the A-record address, such as NET-192-0-2-0-1.
dns.a.ip_addresses.network.ip_versionThe IP version of the network that contains the A-record address: v4 or v6.
dns.a.ip_addresses.network.linksLinks to the registry record of the network that contains the A-record address, such as its RDAP and WHOIS URLs.
dns.a.ip_addresses.network.parent_handleThe handle of the larger network block from which the network of the A-record address was allocated.
dns.a.ip_addresses.network.rawThe raw RDAP network object for the A-record address, when it is kept.
dns.a.ip_addresses.network.statusThe registry status of the network that contains the A-record address, such as active.
dns.a.ip_addresses.network.typeThe registry's allocation type for the network that contains the A-record address, such as DIRECT ALLOCATION, ALLOCATION or ALLOCATED PA.
dns.a.ip_addresses.network.notices.titleThe title of a notice the registry attached to the network record of the A-record address, such as Terms of Service.
dns.a.ip_addresses.network.notices.descriptionThe text of a notice the registry attached to the network record of the A-record address.
dns.a.ip_addresses.network.notices.linksLinks given in a notice on the network record of the A-record address.
dns.a.ip_addresses.network.remarks.titleThe title of a remark on the network record of the A-record address, such as Registration Comments.
dns.a.ip_addresses.network.remarks.descriptionThe text of a remark on the network record of the A-record address.
dns.a.ip_addresses.network.remarks.linksLinks given in a remark on the network record of the A-record address.
dns.a.ip_addresses.network.events.actionAn event in the history of the network record of the A-record address, such as registration or last changed.
dns.a.ip_addresses.network.events.actorWho performed an event on the network record of the A-record address, when the registry names one.
dns.a.ip_addresses.objects.uidThe handle of a registry contact or organization (RDAP entity) linked to the network of the A-record address, such as ACME-ARIN.
dns.a.ip_addresses.objects.contact.email.typeThe type of an e-mail address of a contact linked to the network of the A-record address, such as abuse.
dns.a.ip_addresses.objects.contact.email.valueAn e-mail address of a contact linked to the network of the A-record address.
dns.a.ip_addresses.objects.contact.address.typeThe type of a postal address of a contact linked to the network of the A-record address.
dns.a.ip_addresses.objects.contact.address.valueA postal address of a contact linked to the network of the A-record address.
dns.a.ip_addresses.objects.contact.phone.typeThe type of a phone number of a contact linked to the network of the A-record address, such as voice or work.
dns.a.ip_addresses.objects.contact.phone.valueA phone number of a contact linked to the network of the A-record address.
dns.a.ip_addresses.objects.contact.kindWhat kind of contact is linked to the network of the A-record address: org, group or individual.
dns.a.ip_addresses.objects.contact.nameThe name of a contact or organization linked to the network of the A-record address, such as Abuse or a company name.
dns.a.ip_addresses.objects.contact.roleThe role given in the contact card of an entity linked to the network of the A-record address.
dns.a.ip_addresses.objects.contact.titleThe title given in the contact card of an entity linked to the network of the A-record address.
dns.a.ip_addresses.objects.entitiesHandles of further entities listed under a contact linked to the network of the A-record address.
dns.a.ip_addresses.objects.events.actionAn event in the history of a contact record linked to the network of the A-record address, such as registration or last changed.
dns.a.ip_addresses.objects.events.actorWho performed an event on a contact record linked to the network of the A-record address, when the registry names one.
dns.a.ip_addresses.objects.events_actorEvents in which a contact linked to the network of the A-record address is itself the actor (the RDAP asEventActor list), as text; empty on every sampled record.
dns.a.ip_addresses.objects.handleThe registry handle of a contact or organization linked to the network of the A-record address.
dns.a.ip_addresses.objects.linksLinks to the registry record of a contact linked to the network of the A-record address.
dns.a.ip_addresses.objects.notices.titleThe title of a notice on a contact record linked to the network of the A-record address, such as Terms of Service.
dns.a.ip_addresses.objects.notices.descriptionThe text of a notice on a contact record linked to the network of the A-record address.
dns.a.ip_addresses.objects.notices.linksLinks given in a notice on a contact record linked to the network of the A-record address.
dns.a.ip_addresses.objects.rawThe raw RDAP object of a contact linked to the network of the A-record address, when it is kept.
dns.a.ip_addresses.objects.remarks.titleThe title of a remark on a contact record linked to the network of the A-record address, such as Registration Comments.
dns.a.ip_addresses.objects.remarks.descriptionThe text of a remark on a contact record linked to the network of the A-record address.
dns.a.ip_addresses.objects.remarks.linksLinks given in a remark on a contact record linked to the network of the A-record address.
dns.a.ip_addresses.objects.rolesThe roles of a contact for the network of the A-record address, such as registrant, abuse or technical.
dns.a.ip_addresses.objects.statusThe registry status of a contact linked to the network of the A-record address, such as validated.
dns.a.ip_historyEvery IPv4 address seen in the asset's A records over time, the current ones included.
dns.aaaa.valueThe asset's current AAAA records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.aaaa.value_previousThe asset's AAAA records as they were before the last change, in the same text form as dns.aaaa.value.
dns.aaaa.rcodeThe DNS response code returned for the asset's AAAA lookup, such as NOERROR.
dns.aaaa.rcode_previousThe DNS response code of the AAAA lookup before it last changed.
dns.aaaa.ip_addressesThe IPv6 addresses in the asset's AAAA records.
dns.caa.valueThe asset's current CAA records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.caa.value_previousThe asset's CAA records as they were before the last change, in the same text form as dns.caa.value.
dns.caa.rcodeThe DNS response code returned for the asset's CAA lookup, such as NOERROR.
dns.caa.rcode_previousThe DNS response code of the CAA lookup before it last changed.
dns.caa.issue_fqdnsThe certificate authorities allowed to issue certificates for the name, from the CAA issue tags, such as fernhill.example or kestrel.example.
dns.caa.issuewild_fqdnsThe certificate authorities allowed to issue wildcard certificates for the name, from the CAA issuewild tags.
dns.caa.iodef_emailsThe e-mail addresses from the CAA iodef tags, where certificate authorities report requests that break the CAA policy.
dns.cname.valueThe asset's current CNAME records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.cname.value_previousThe asset's CNAME records as they were before the last change, in the same text form as dns.cname.value.
dns.cname.rcodeThe DNS response code returned for the asset's CNAME lookup, such as NOERROR.
dns.cname.rcode_previousThe DNS response code of the CNAME lookup before it last changed.
dns.cname.canonical_fqdnsThe host names the asset's CNAME records point to (the alias targets).
dns.dnskey.valueThe asset's current DNSKEY records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.dnskey.value_previousThe asset's DNSKEY records as they were before the last change, in the same text form as dns.dnskey.value.
dns.dnskey.rcodeThe DNS response code returned for the asset's DNSKEY lookup, such as NOERROR.
dns.dnskey.rcode_previousThe DNS response code of the DNSKEY lookup before it last changed.
dns.dnskey.records.public_keyThe public key of a DNSKEY record, Base64-encoded and split into space-separated groups as in the zone-file text.
dns.ds.valueThe asset's current DS records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.ds.value_previousThe asset's DS records as they were before the last change, in the same text form as dns.ds.value.
dns.ds.rcodeThe DNS response code returned for the asset's DS lookup, such as NOERROR.
dns.ds.rcode_previousThe DNS response code of the DS lookup before it last changed.
dns.ds.records.digestThe digest of a DS record, the hash of the DNSKEY it refers to.
dns.mx.valueThe asset's current MX records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.mx.value_previousThe asset's MX records as they were before the last change, in the same text form as dns.mx.value.
dns.mx.rcodeThe DNS response code returned for the asset's MX lookup, such as NOERROR.
dns.mx.rcode_previousThe DNS response code of the MX lookup before it last changed.
dns.mx.mail_serversThe mail server host names from the asset's MX records, such as mail.acme.example.
dns.mx.domainsThe registrable domains of the asset's mail servers, such as acme.example.
dns.ns.valueThe asset's current NS records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.ns.value_previousThe asset's NS records as they were before the last change, in the same text form as dns.ns.value.
dns.ns.rcodeThe DNS response code returned for the asset's NS lookup, such as NOERROR.
dns.ns.rcode_previousThe DNS response code of the NS lookup before it last changed.
dns.ns.name_serversThe name server host names from the asset's NS records, such as ns1.acme.example.
dns.ns.domainsThe registrable domains of the asset's name servers, such as acme.example.
dns.nsec.valueThe asset's current NSEC records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.nsec.value_previousThe asset's NSEC records as they were before the last change, in the same text form as dns.nsec.value.
dns.nsec.rcodeThe DNS response code returned for the asset's NSEC lookup, such as NOERROR.
dns.nsec.rcode_previousThe DNS response code of the NSEC lookup before it last changed.
dns.nsec.records.next_domainThe next name in the zone, from an NSEC record.
dns.nsec.records.record_typesThe record types that exist at the name, from an NSEC record's type list, such as A, NS or SOA.
dns.nsec3.valueThe asset's current NSEC3 records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.nsec3.value_previousThe asset's NSEC3 records as they were before the last change, in the same text form as dns.nsec3.value.
dns.nsec3.rcodeThe DNS response code returned for the asset's NSEC3 lookup, such as NOERROR.
dns.nsec3.rcode_previousThe DNS response code of the NSEC3 lookup before it last changed.
dns.nsec3.records.next_domain_hashedThe hashed next name in the zone, from an NSEC3 record.
dns.nsec3.records.record_typesThe record types that exist at the name, from an NSEC3 record's type list, such as A or MX.
dns.rrsig.valueThe asset's current RRSIG records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.rrsig.value_previousThe asset's RRSIG records as they were before the last change, in the same text form as dns.rrsig.value.
dns.rrsig.rcodeThe DNS response code returned for the asset's RRSIG lookup, such as NOERROR.
dns.rrsig.rcode_previousThe DNS response code of the RRSIG lookup before it last changed.
dns.rrsig.type_coveredThe record type that an RRSIG signature covers, such as A or SOA.
dns.rrsig.signatureThe signature data of an RRSIG record, Base64-encoded.
dns.soa.valueThe asset's current SOA records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.soa.value_previousThe asset's SOA records as they were before the last change, in the same text form as dns.soa.value.
dns.soa.rcodeThe DNS response code returned for the asset's SOA lookup, such as NOERROR.
dns.soa.rcode_previousThe DNS response code of the SOA lookup before it last changed.
dns.soa.mnamesThe MNAME of the SOA record: the primary name server of the zone, such as ns1.acme.example.
dns.soa.rnamesThe RNAME of the SOA record, the zone administrator's mailbox in DNS form: hostmaster.acme.example stands for the mailbox hostmaster at acme.example.
dns.soa.rname_emailsThe RNAME of the SOA record written as an e-mail address, such as user@acme.example.
dns.srv.valueThe asset's current SRV records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.srv.value_previousThe asset's SRV records as they were before the last change, in the same text form as dns.srv.value.
dns.srv.rcodeThe DNS response code returned for the asset's SRV lookup, such as NOERROR.
dns.srv.rcode_previousThe DNS response code of the SRV lookup before it last changed.
dns.srv.records.serviceThe service named in an SRV record (the _service part of its name).
dns.srv.records.protocolThe protocol named in an SRV record (the _proto part of its name, such as TCP or UDP).
dns.srv.records.targetThe host name an SRV record points to.
dns.txt.valueThe asset's current TXT records as zone-file text (name, TTL, class, type and data), all records in one string.
dns.txt.value_previousThe asset's TXT records as they were before the last change, in the same text form as dns.txt.value.
dns.txt.rcodeThe DNS response code returned for the asset's TXT lookup, such as NOERROR.
dns.txt.rcode_previousThe DNS response code of the TXT lookup before it last changed.
dns.txt.valuesEach TXT record of the asset as its quoted text, such as "v=spf1 include:_spf.acme.example ~all"; the quotes are part of the value.
dns.txt.spf_list.valueThe text of an SPF record (a TXT record that starts with v=spf1), quoted as in dns.txt.values.
dns.txt.spf_list.allowed_domainsThe registrable domains that an SPF record refers to, such as acme.example for include:_spf.acme.example.
dns.txt.spf_list.allowed_ipsThe IP addresses and ranges that an SPF record authorizes to send mail (its ip4: and ip6: entries).
dns.txt.verifications.valueThe text of a site-verification TXT record, quoted as in dns.txt.values.
dns.txt.verifications.domainThe domain of the service a verification record is for, such as acme.example, fernhill.example or kestrel.example.
dns.txt.verifications.nameThe name of a verification record, such as site-verification or domain-verification.
dns_last_change_dataThe DNS fields that changed in the last change seen, as field paths such as dns.soa.mnames.
ssl.targetThe host name that the asset's TLS certificate was collected from, normally the asset itself.
ssl.serial_numberThe serial number of the asset's TLS certificate, as a decimal string.
ssl.fingerprint.md5The MD5 fingerprint of the asset's TLS certificate, as lower-case hex.
ssl.fingerprint.sha1The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.
ssl.fingerprint.sha256The SHA-256 fingerprint of the asset's TLS certificate, as lower-case hex; one fingerprint identifies one certificate.
ssl.issuer.common_nameThe common name (CN) of the certificate authority that issued the asset's TLS certificate, such as WE1 or YE2.
ssl.issuer.countryThe country (C) of the certificate authority that issued the asset's TLS certificate, as a two-letter code such as US.
ssl.issuer.stateThe state or province (ST) of the certificate authority that issued the asset's TLS certificate.
ssl.issuer.localityThe locality or city (L) of the certificate authority that issued the asset's TLS certificate.
ssl.issuer.organizationThe organization (O) of the certificate authority that issued the asset's TLS certificate, such as Let's Encrypt or Google Trust Services.
ssl.issuer.organizational_unitThe organizational unit (OU) of the certificate authority that issued the asset's TLS certificate.
ssl.issuer_dnThe full distinguished name of the issuer of the asset's TLS certificate, as one string such as CN=WE1,O=Google Trust Services,C=US.
ssl.subject.common_nameThe common name (CN) of the subject (holder) of the asset's TLS certificate, usually a host name such as acme.example.
ssl.subject.countryThe country (C) of the subject (holder) of the asset's TLS certificate, as a two-letter code.
ssl.subject.stateThe state or province (ST) of the subject (holder) of the asset's TLS certificate.
ssl.subject.localityThe locality or city (L) of the subject (holder) of the asset's TLS certificate.
ssl.subject.organizationThe organization (O) of the subject (holder) of the asset's TLS certificate.
ssl.subject.organizational_unitThe organizational unit (OU) of the subject (holder) of the asset's TLS certificate.
ssl.subject_dnThe full distinguished name of the subject of the asset's TLS certificate, such as CN=acme.example; one that starts with CN=*. belongs to a wildcard certificate.
ssl.signature.valueThe signature of the asset's TLS certificate, Base64-encoded.
ssl.signature.invalid_reasonWhy certificate validation failed, such as a host name mismatch or unable to get issuer certificate.
ssl.signature.algorithm.nameThe hash algorithm of the signature on the asset's TLS certificate, such as sha256 or sha384.
ssl.signature.algorithm.oidThe object identifier (OID) of the signature algorithm, such as 1.2.840.113549.1.1.11 (SHA-256 with RSA) or 1.2.840.10045.4.3.2 (ECDSA with SHA-256).
ssl.extensions.authority_key_idThe Authority Key Identifier extension, which identifies the issuer's key, Base64-encoded.
ssl.extensions.certificate_policiesThe policy OIDs in the Certificate Policies extension, such as 2.23.140.1.2.1 (domain validated).
ssl.extensions.signed_certificate_timestamps.log_idThe ID of the Certificate Transparency log that issued a signed certificate timestamp (SCT) for the certificate, Base64-encoded.
ssl.extensions.signed_certificate_timestamps.signatureThe log's signature on a signed certificate timestamp, Base64-encoded.
ssl.extensions.subject_alt_name.dns_namesThe host names in the certificate's Subject Alternative Name extension, including wildcard names such as *.acme.example.
ssl.extensions.subject_key_idThe Subject Key Identifier extension, which identifies the certificate's own key, Base64-encoded.
ssl.subject_key_info.fingerprint.hash_algorithmThe hash algorithm used for ssl.subject_key_info.fingerprint.value, such as sha256 or sha384.
ssl.subject_key_info.fingerprint.valueA hex fingerprint recorded under the certificate's subject key information, made with the hash in hash_algorithm. In the samples it equals ssl.fingerprint.sha256 when that hash is SHA-256.
ssl.subject_key_info.key_algorithm.nameThe algorithm of the certificate's public key, such as RSA or ECDSA.
ssl.version.nameThe X.509 version of the certificate, such as v3.
ssl.version.valueThe X.509 version as encoded in the certificate, counted from zero: 2 means v3.
ssl.tbs_fingerprintA SHA-256 fingerprint (hex) of the certificate's to-be-signed part, the certificate content without its signature.
ssl.certificateThe whole certificate, Base64-encoded (a PEM body without the header and footer lines).
ssl.fqdn_listThe host names the certificate covers, with the *. of wildcard names removed and duplicates merged, so *.acme.example and acme.example both give acme.example.
ssl_last_change_dataThe certificate fields that changed in the last change seen, as field paths such as ssl.validity.end_date.
http.requested_urlThe URL the HTTP check started from, such as http://acme.example.
http.requested_domainThe registrable domain of the URL the HTTP check started from.
http.requested_fqdnThe host name of the URL the HTTP check started from.
http.final_urlThe URL the HTTP check ended on after following all redirects.
http.final_domainThe registrable domain the HTTP check ended on after redirects, such as acme.example.
http.final_fqdnThe host name the HTTP check ended on after redirects, such as www.acme.example.
http.redirection_history.urlA URL in the redirect chain of the HTTP check, listed in the order visited.
http.headers.acceptThe Accept header, when it was returned in the HTTP check. It is normally a request header (the content types a client accepts), so it is rarely set.
http.headers.accept_encodingThe Accept-Encoding header, when it was returned in the HTTP check. It is normally a request header (the compression formats a client accepts), so it is rarely set.
http.headers.accept_languageThe Accept-Language header, when it was returned in the HTTP check. It is normally a request header (the languages a client prefers), so it is rarely set.
http.headers.access_control_allow_credentialsThe Access-Control-Allow-Credentials header returned in the HTTP check; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).
http.headers.access_control_allow_headersThe Access-Control-Allow-Headers header returned in the HTTP check; it lists the request headers allowed in cross-origin requests (CORS), for example *.
http.headers.access_control_allow_methodsThe Access-Control-Allow-Methods header returned in the HTTP check; it lists the HTTP methods allowed in cross-origin requests (CORS), for example GET.
http.headers.access_control_allow_originThe Access-Control-Allow-Origin header returned in the HTTP check; it names the origins allowed to read the response (CORS), where * allows any origin.
http.headers.access_control_expose_headersThe Access-Control-Expose-Headers header returned in the HTTP check; it lists the response headers that scripts from other origins may read (CORS).
http.headers.access_control_max_ageThe Access-Control-Max-Age header returned in the HTTP check; it says how many seconds browsers may cache a CORS preflight result.
http.headers.alt_svcThe Alt-Svc header returned in the HTTP check; it advertises other protocols or ports that serve the site, for example h3=":443"; ma=86400 for HTTP/3.
http.headers.authorizationThe Authorization header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to the server), so it is rarely set.
http.headers.cache_controlThe Cache-Control header returned in the HTTP check; it sets the caching rules for the response, for example no-cache, must-revalidate.
http.headers.clear_site_dataThe Clear-Site-Data header returned in the HTTP check; it tells browsers to clear stored data for the site, such as cookies, storage or cache.
http.headers.content_dispositionThe Content-Disposition header returned in the HTTP check; it says whether the content is shown in the browser or downloaded as a file.
http.headers.content_encodingThe Content-Encoding header returned in the HTTP check; it names the compression applied to the response body, for example gzip or br.
http.headers.content_languageThe Content-Language header returned in the HTTP check; it gives the language of the content, for example en or tr.
http.headers.content_lengthThe Content-Length header returned in the HTTP check; it gives the size of the response body in bytes.
http.headers.content_rangeThe Content-Range header returned in the HTTP check; it says which part of the full body a partial response holds.
http.headers.content_security_policyThe Content-Security-Policy header returned in the HTTP check; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.
http.headers.content_typeThe Content-Type header returned in the HTTP check; it gives the media type and character set of the response body, for example text/html; charset=utf-8.
http.headers.cookieThe Cookie header, when it was returned in the HTTP check. It is normally a request header (the cookies a client sends), so it is rarely set.
http.headers.cross_origin_embedder_policyThe Cross-Origin-Embedder-Policy header returned in the HTTP check; it controls whether the page may embed cross-origin resources that do not explicitly allow it.
http.headers.cross_origin_opener_policyThe Cross-Origin-Opener-Policy header returned in the HTTP check; it controls whether the page shares its browsing context with cross-origin windows.
http.headers.cross_origin_resource_policyThe Cross-Origin-Resource-Policy header returned in the HTTP check; it controls which sites may load the resource.
http.headers.dateThe Date header returned in the HTTP check; it gives the time the server generated the response, in HTTP date format, for example Sun, 01 Jun 2025 08:00:00 GMT.
http.headers.early_dataThe Early-Data header, when it was returned in the HTTP check. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.
http.headers.expect_ctThe Expect-CT header returned in the HTTP check; it is a deprecated header about Certificate Transparency enforcement.
http.headers.expiresThe Expires header returned in the HTTP check; it gives the date after which the response counts as stale, in HTTP date format.
http.headers.feature_policyThe Feature-Policy header returned in the HTTP check; it is the older name of Permissions-Policy and limits the browser features the page may use.
http.headers.hostThe Host header, when it was returned in the HTTP check. It is normally a request header (the host name a client asks for), so it is rarely set.
http.headers.if_modified_sinceThe If-Modified-Since header, when it was returned in the HTTP check. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.
http.headers.if_none_matchThe If-None-Match header, when it was returned in the HTTP check. It is normally a request header (a condition based on an ETag), so it is rarely set.
http.headers.last_modifiedThe Last-Modified header returned in the HTTP check; it gives the time the server says the resource last changed, in HTTP date format.
http.headers.origin_isolationThe Origin-Isolation header returned in the HTTP check; it is an experimental header that asks browsers to isolate the site's origin.
http.headers.others.nameThe name of a header returned in the HTTP check that has no field of its own under headers, in lower case such as etag or cf-cache-status.
http.headers.others.valueThe value of a header listed in headers.others for the HTTP check.
http.headers.permission_policyThe Permission-Policy header returned in the HTTP check; it is recorded under this singular spelling, separately from Permissions-Policy.
http.headers.permissions_policyThe Permissions-Policy header returned in the HTTP check; it limits the browser features the page may use, for example camera=(), microphone=(), geolocation=().
http.headers.pragmaThe Pragma header returned in the HTTP check; it is an older HTTP/1.0 caching header, for example no-cache.
http.headers.proxy_authenticateThe Proxy-Authenticate header returned in the HTTP check; it tells a client how to authenticate to a proxy.
http.headers.proxy_authorizationThe Proxy-Authorization header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.
http.headers.public_key_pinsThe Public-Key-Pins header returned in the HTTP check; it is a deprecated header (HPKP) that pinned the site's public keys.
http.headers.rangeThe Range header, when it was returned in the HTTP check. It is normally a request header (a request for only part of a resource), so it is rarely set.
http.headers.refererThe Referer header, when it was returned in the HTTP check. It is normally a request header (the address of the page a request came from), so it is rarely set.
http.headers.referrer_policyThe Referrer-Policy header returned in the HTTP check; it sets how much referrer information browsers send when leaving the page, for example strict-origin-when-cross-origin.
http.headers.sec_fetch_destThe Sec-Fetch-Dest header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.
http.headers.sec_fetch_modeThe Sec-Fetch-Mode header, when it was returned in the HTTP check. It is normally a request header (browser metadata on the request mode), so it is rarely set.
http.headers.sec_fetch_siteThe Sec-Fetch-Site header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.
http.headers.sec_fetch_userThe Sec-Fetch-User header, when it was returned in the HTTP check. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.
http.headers.serverThe Server header returned in the HTTP check; it names the server software the site reports, for example nginx or Apache.
http.headers.set_cookieThe Set-Cookie header returned in the HTTP check; it sets cookies, with their attributes.
http.headers.strict_transport_securityThe Strict-Transport-Security header returned in the HTTP check; it tells browsers to reach the site over HTTPS only (HSTS), for example max-age=31536000; includeSubDomains; preload.
http.headers.teThe TE header, when it was returned in the HTTP check. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.
http.headers.transfer_encodingThe Transfer-Encoding header returned in the HTTP check; it says how the body is transferred, for example chunked.
http.headers.upgradeThe Upgrade header returned in the HTTP check; it offers or asks for a switch to another protocol.
http.headers.user_agentThe User-Agent header, when it was returned in the HTTP check. It is normally a request header (the client software), so it is rarely set.
http.headers.varyThe Vary header returned in the HTTP check; it tells caches which request headers change the response, for example Accept-Encoding.
http.headers.www_authenticateThe WWW-Authenticate header returned in the HTTP check; it tells a client how to authenticate, usually with a 401 response.
http.headers.x_content_type_optionsThe X-Content-Type-Options header returned in the HTTP check; it stops browsers from guessing the content type when set to nosniff.
http.headers.x_download_optionsThe X-Download-Options header returned in the HTTP check; it stops Internet Explorer from opening downloads directly when set to noopen.
http.headers.x_frame_optionsThe X-Frame-Options header returned in the HTTP check; it says whether the page may be shown in a frame (a protection against clickjacking), for example DENY or SAMEORIGIN.
http.headers.x_permitted_cross_domain_policiesThe X-Permitted-Cross-Domain-Policies header returned in the HTTP check; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.
http.headers.x_powered_byThe X-Powered-By header returned in the HTTP check; it names the technology the server reports running on, for example Express.
http.headers.x_xss_protectionThe X-XSS-Protection header returned in the HTTP check; it is an older setting for the browser's cross-site scripting filter, for example 1; mode=block or 0.
http.cookies.nameThe name of a cookie set in the HTTP check.
http.cookies.valueThe value of a cookie set in the HTTP check.
http.html.source_code_hashA SHA-256 hash of the page source returned in the HTTP check; the same hash means the same source.
http_last_change_dataThe HTTP check fields that changed in the last change seen, as field paths such as http.html.source_code_hash.
webdata.requested_urlThe URL the web data scan started from, such as http://acme.example.
webdata.requested_domainThe registrable domain of the URL the web data scan started from.
webdata.requested_fqdnThe host name of the URL the web data scan started from.
webdata.html.internal_links_fqdnsThe host names of links on the scanned page that stay within the site's own domain, such as other subdomains.
webdata.html.external_links_domainsThe registrable domains of links on the scanned page that point to other domains, such as kestrel.example.
webdata.html.external_links_fqdnsThe host names of links on the scanned page that point to other domains, such as www.kestrel.example.
webdata.html.external_linksThe full URLs of links on the scanned page that point to other domains.
webdata.html.script_linksThe URLs of the scripts the scanned page loads.
webdata.html.iframe_linksThe URLs of the frames (iframes) embedded in the scanned page.
webdata.html.trackers.nameThe name of an analytics or advertising tracker found on the scanned page, such as google_adsense or google_tag_manager.
webdata.html.trackers.valuesThe IDs found for a tracker, such as a Google Analytics ID that starts with G- or UA-.
webdata.html.emailsThe e-mail addresses found on the scanned page.
webdata.html.emails_internalThe e-mail addresses found on the scanned page that belong to the site's own domain.
webdata.html.source_code_hashA SHA-256 hash of the page source in the web data scan; the same hash means the same source.
webdata.html.content_hashA SHA-256 hash of the page content in the web data scan, kept apart from source_code_hash, the hash of the raw source.
webdata.html.content_top_keywordsThe most frequent words in the text of the scanned page.
webdata.html.favicon_linksThe URLs of the icons the scanned page declares, such as its favicon and touch icons.
webdata.html.html_meta.nameThe site or application name declared in the scanned page's metadata.
webdata.html.html_meta.descriptionThe meta description of the scanned page.
webdata.html.html_meta.languageThe language the scanned page declares, such as en, tr or en-US.
webdata.html.html_meta.language_alternativesThe languages of the alternative versions the scanned page links to, such as en or ar.
webdata.html.html_meta.keywordsThe keywords listed in the keywords meta tag of the scanned page.
webdata.html.html_meta.encodingThe character encoding the scanned page declares, such as utf-8.
webdata.html.html_meta.canonical_urlThe canonical URL the scanned page declares.
webdata.html.html_meta.titleThe title of the scanned page.
webdata.favicon.urlThe URL of a site icon (favicon) recorded by the web data scan.
webdata.favicon.hashA SHA-256 hash of a site icon; the same hash means the same icon.
webdata.http.final_urlThe URL the web data scan ended on after following all redirects.
webdata.http.final_domainThe registrable domain the web data scan ended on after redirects, such as acme.example.
webdata.http.final_fqdnThe host name the web data scan ended on after redirects, such as www.acme.example.
webdata.http.redirection_history.urlA URL in the redirect chain of the web data scan, listed in the order visited.
webdata.http.redirection_history.methodHow a step of the web data scan's redirect chain was made; http-header (a redirect sent in the HTTP response) is the value in the samples.
webdata.http.headers.acceptThe Accept header, when it was returned in the web data scan. It is normally a request header (the content types a client accepts), so it is rarely set.
webdata.http.headers.accept_encodingThe Accept-Encoding header, when it was returned in the web data scan. It is normally a request header (the compression formats a client accepts), so it is rarely set.
webdata.http.headers.accept_languageThe Accept-Language header, when it was returned in the web data scan. It is normally a request header (the languages a client prefers), so it is rarely set.
webdata.http.headers.access_control_allow_credentialsThe Access-Control-Allow-Credentials header returned in the web data scan; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS).
webdata.http.headers.access_control_allow_headersThe Access-Control-Allow-Headers header returned in the web data scan; it lists the request headers allowed in cross-origin requests (CORS), for example *.
webdata.http.headers.access_control_allow_methodsThe Access-Control-Allow-Methods header returned in the web data scan; it lists the HTTP methods allowed in cross-origin requests (CORS), for example GET.
webdata.http.headers.access_control_allow_originThe Access-Control-Allow-Origin header returned in the web data scan; it names the origins allowed to read the response (CORS), where * allows any origin.
webdata.http.headers.access_control_expose_headersThe Access-Control-Expose-Headers header returned in the web data scan; it lists the response headers that scripts from other origins may read (CORS).
webdata.http.headers.access_control_max_ageThe Access-Control-Max-Age header returned in the web data scan; it says how many seconds browsers may cache a CORS preflight result.
webdata.http.headers.alt_svcThe Alt-Svc header returned in the web data scan; it advertises other protocols or ports that serve the site, for example h3=":443"; ma=86400 for HTTP/3.
webdata.http.headers.authorizationThe Authorization header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to the server), so it is rarely set.
webdata.http.headers.cache_controlThe Cache-Control header returned in the web data scan; it sets the caching rules for the response, for example no-cache, must-revalidate.
webdata.http.headers.clear_site_dataThe Clear-Site-Data header returned in the web data scan; it tells browsers to clear stored data for the site, such as cookies, storage or cache.
webdata.http.headers.content_dispositionThe Content-Disposition header returned in the web data scan; it says whether the content is shown in the browser or downloaded as a file.
webdata.http.headers.content_encodingThe Content-Encoding header returned in the web data scan; it names the compression applied to the response body, for example gzip or br.
webdata.http.headers.content_languageThe Content-Language header returned in the web data scan; it gives the language of the content, for example en or tr.
webdata.http.headers.content_lengthThe Content-Length header returned in the web data scan; it gives the size of the response body in bytes.
webdata.http.headers.content_rangeThe Content-Range header returned in the web data scan; it says which part of the full body a partial response holds.
webdata.http.headers.content_security_policyThe Content-Security-Policy header returned in the web data scan; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from.
webdata.http.headers.content_typeThe Content-Type header returned in the web data scan; it gives the media type and character set of the response body, for example text/html; charset=utf-8.
webdata.http.headers.cookieThe Cookie header, when it was returned in the web data scan. It is normally a request header (the cookies a client sends), so it is rarely set.
webdata.http.headers.cross_origin_embedder_policyThe Cross-Origin-Embedder-Policy header returned in the web data scan; it controls whether the page may embed cross-origin resources that do not explicitly allow it.
webdata.http.headers.cross_origin_opener_policyThe Cross-Origin-Opener-Policy header returned in the web data scan; it controls whether the page shares its browsing context with cross-origin windows.
webdata.http.headers.cross_origin_resource_policyThe Cross-Origin-Resource-Policy header returned in the web data scan; it controls which sites may load the resource.
webdata.http.headers.dateThe Date header returned in the web data scan; it gives the time the server generated the response, in HTTP date format, for example Sun, 01 Jun 2025 08:00:00 GMT.
webdata.http.headers.early_dataThe Early-Data header, when it was returned in the web data scan. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set.
webdata.http.headers.expect_ctThe Expect-CT header returned in the web data scan; it is a deprecated header about Certificate Transparency enforcement.
webdata.http.headers.expiresThe Expires header returned in the web data scan; it gives the date after which the response counts as stale, in HTTP date format.
webdata.http.headers.feature_policyThe Feature-Policy header returned in the web data scan; it is the older name of Permissions-Policy and limits the browser features the page may use.
webdata.http.headers.hostThe Host header, when it was returned in the web data scan. It is normally a request header (the host name a client asks for), so it is rarely set.
webdata.http.headers.if_modified_sinceThe If-Modified-Since header, when it was returned in the web data scan. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set.
webdata.http.headers.if_none_matchThe If-None-Match header, when it was returned in the web data scan. It is normally a request header (a condition based on an ETag), so it is rarely set.
webdata.http.headers.last_modifiedThe Last-Modified header returned in the web data scan; it gives the time the server says the resource last changed, in HTTP date format.
webdata.http.headers.origin_isolationThe Origin-Isolation header returned in the web data scan; it is an experimental header that asks browsers to isolate the site's origin.
webdata.http.headers.others.nameThe name of a header returned in the web data scan that has no field of its own under headers, in lower case such as etag or cf-cache-status.
webdata.http.headers.others.valueThe value of a header listed in headers.others for the web data scan.
webdata.http.headers.permission_policyThe Permission-Policy header returned in the web data scan; it is recorded under this singular spelling, separately from Permissions-Policy.
webdata.http.headers.permissions_policyThe Permissions-Policy header returned in the web data scan; it limits the browser features the page may use, for example camera=(), microphone=(), geolocation=().
webdata.http.headers.pragmaThe Pragma header returned in the web data scan; it is an older HTTP/1.0 caching header, for example no-cache.
webdata.http.headers.proxy_authenticateThe Proxy-Authenticate header returned in the web data scan; it tells a client how to authenticate to a proxy.
webdata.http.headers.proxy_authorizationThe Proxy-Authorization header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set.
webdata.http.headers.public_key_pinsThe Public-Key-Pins header returned in the web data scan; it is a deprecated header (HPKP) that pinned the site's public keys.
webdata.http.headers.rangeThe Range header, when it was returned in the web data scan. It is normally a request header (a request for only part of a resource), so it is rarely set.
webdata.http.headers.refererThe Referer header, when it was returned in the web data scan. It is normally a request header (the address of the page a request came from), so it is rarely set.
webdata.http.headers.referrer_policyThe Referrer-Policy header returned in the web data scan; it sets how much referrer information browsers send when leaving the page, for example strict-origin-when-cross-origin.
webdata.http.headers.sec_fetch_destThe Sec-Fetch-Dest header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the response will be used), so it is rarely set.
webdata.http.headers.sec_fetch_modeThe Sec-Fetch-Mode header, when it was returned in the web data scan. It is normally a request header (browser metadata on the request mode), so it is rarely set.
webdata.http.headers.sec_fetch_siteThe Sec-Fetch-Site header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set.
webdata.http.headers.sec_fetch_userThe Sec-Fetch-User header, when it was returned in the web data scan. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set.
webdata.http.headers.serverThe Server header returned in the web data scan; it names the server software the site reports, for example nginx or Apache.
webdata.http.headers.set_cookieThe Set-Cookie header returned in the web data scan; it sets cookies, with their attributes.
webdata.http.headers.strict_transport_securityThe Strict-Transport-Security header returned in the web data scan; it tells browsers to reach the site over HTTPS only (HSTS), for example max-age=31536000; includeSubDomains; preload.
webdata.http.headers.teThe TE header, when it was returned in the web data scan. It is normally a request header (the transfer encodings a client accepts), so it is rarely set.
webdata.http.headers.transfer_encodingThe Transfer-Encoding header returned in the web data scan; it says how the body is transferred, for example chunked.
webdata.http.headers.upgradeThe Upgrade header returned in the web data scan; it offers or asks for a switch to another protocol.
webdata.http.headers.user_agentThe User-Agent header, when it was returned in the web data scan. It is normally a request header (the client software), so it is rarely set.
webdata.http.headers.varyThe Vary header returned in the web data scan; it tells caches which request headers change the response, for example Accept-Encoding.
webdata.http.headers.www_authenticateThe WWW-Authenticate header returned in the web data scan; it tells a client how to authenticate, usually with a 401 response.
webdata.http.headers.x_content_type_optionsThe X-Content-Type-Options header returned in the web data scan; it stops browsers from guessing the content type when set to nosniff.
webdata.http.headers.x_download_optionsThe X-Download-Options header returned in the web data scan; it stops Internet Explorer from opening downloads directly when set to noopen.
webdata.http.headers.x_frame_optionsThe X-Frame-Options header returned in the web data scan; it says whether the page may be shown in a frame (a protection against clickjacking), for example DENY or SAMEORIGIN.
webdata.http.headers.x_permitted_cross_domain_policiesThe X-Permitted-Cross-Domain-Policies header returned in the web data scan; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files.
webdata.http.headers.x_powered_byThe X-Powered-By header returned in the web data scan; it names the technology the server reports running on, for example Express.
webdata.http.headers.x_xss_protectionThe X-XSS-Protection header returned in the web data scan; it is an older setting for the browser's cross-site scripting filter, for example 1; mode=block or 0.
webdata.http.cookies.nameThe name of a cookie set in the web data scan.
webdata.http.cookies.valueThe value of a cookie set in the web data scan.
webdata.http.cookies.domainThe domain a cookie set in the web data scan applies to, such as .acme.example.
webdata.http.cookies.pathThe path a cookie set in the web data scan applies to, such as /.
webdata.http.cookies.same_partyThe SameParty attribute of a cookie set in the web data scan; in the samples it always holds the same value as same_site, such as Lax or None.
webdata.http.cookies.priorityThe Priority attribute of a cookie set in the web data scan (Low, Medium or High in Chromium-based browsers).
webdata.http.cookies.same_siteThe SameSite attribute of a cookie set in the web data scan, such as Lax, Strict or None.
webdata.technology.stacks.slugA short identifier of a technology detected on the site, such as iis or windows-server.
webdata.technology.stacks.nameThe name of a technology detected on the site, such as IIS or Microsoft ASP.NET.
webdata.technology.stacks.iconThe file name of a detected technology's icon, such as acme.png.
webdata.technology.stacks.websiteThe website of a detected technology's vendor or project.
webdata.technology.stacks.cpeThe CPE identifier of a detected technology, such as cpe:/a:acme:acme-portal, used to match it to known vulnerabilities.
webdata.technology.stacks.versionThe detected version of a technology, such as 1.0.
webdata.technology.stacks.categoriesThe categories of a detected technology, such as Web servers or Operating systems.
webdata.technology.stacks.descriptionA short description of a detected technology.
webdata_last_change_dataThe web data fields that changed in the last change seen, as field paths under webdata.
ipwhois.asnThe number of the autonomous system (ASN) that announces the IP address asset, as a string such as 13335.
ipwhois.asn_cidrThe routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.
ipwhois.asn_descriptionThe name and holder of the autonomous system that announces the IP address asset, such as CLOUDFLARENET - Cloudflare, Inc., US.
ipwhois.asn_country_codeThe country of the autonomous system that announces the IP address asset, as a two-letter code such as US.
ipwhois.asn_registryThe regional internet registry responsible for the IP address asset, such as arin or ripencc.
ipwhois.entitiesThe handles of the registry contacts and organizations linked to the network of the IP address asset, such as ACME-ARIN.
ipwhois.nir.nets.addressThe postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.cidrThe range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.
ipwhois.nir.nets.contacts.admin.divisionThe division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.admin.emailThe e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.admin.faxThe fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.admin.organizationThe organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.admin.phoneThe phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.admin.reply_emailThe reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.admin.nameThe name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.admin.titleThe job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.tech.divisionThe division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.tech.emailThe e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.tech.faxThe fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.tech.organizationThe organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.tech.phoneThe phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.tech.reply_emailThe reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.tech.nameThe name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.contacts.tech.titleThe job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.countryThe country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.handleThe registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.nameThe name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.nameserversThe name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.postal_codeThe postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.nets.rangeThe address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.nir.rawThe raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, when it is kept.
ipwhois.nir.queryThe IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset.
ipwhois.queryThe IP address that was looked up in IP WHOIS (RDAP), that is the IP address asset.
ipwhois.rawThe raw IP WHOIS response for the IP address asset, when it is kept; empty on every sampled asset.
ipwhois.network.cidrThe registered network block that contains the IP address asset, in CIDR notation, such as 192.0.2.0/24; a network made of several blocks lists them separated by commas.
ipwhois.network.nameThe name of the registered network that contains the IP address asset, such as CLOUDFLARENET.
ipwhois.network.countryThe country of the registered network that contains the IP address asset, as a two-letter code such as FR.
ipwhois.network.start_addressThe first address of the registered network block that contains the IP address asset.
ipwhois.network.end_addressThe last address of the registered network block that contains the IP address asset.
ipwhois.network.handleThe registry handle of the network that contains the IP address asset, such as NET-192-0-2-0-1.
ipwhois.network.ip_versionThe IP version of the network that contains the IP address asset: v4 or v6.
ipwhois.network.linksLinks to the registry record of the network that contains the IP address asset, such as its RDAP and WHOIS URLs.
ipwhois.network.parent_handleThe handle of the larger network block from which the network of the IP address asset was allocated.
ipwhois.network.rawThe raw RDAP network object for the IP address asset, when it is kept.
ipwhois.network.statusThe registry status of the network that contains the IP address asset, such as active.
ipwhois.network.typeThe registry's allocation type for the network that contains the IP address asset, such as DIRECT ALLOCATION, ALLOCATION or ALLOCATED PA.
ipwhois.network.notices.titleThe title of a notice the registry attached to the network record of the IP address asset, such as Terms of Service.
ipwhois.network.notices.descriptionThe text of a notice the registry attached to the network record of the IP address asset.
ipwhois.network.notices.linksLinks given in a notice on the network record of the IP address asset.
ipwhois.network.remarks.titleThe title of a remark on the network record of the IP address asset, such as Registration Comments.
ipwhois.network.remarks.descriptionThe text of a remark on the network record of the IP address asset.
ipwhois.network.remarks.linksLinks given in a remark on the network record of the IP address asset.
ipwhois.network.events.actionAn event in the history of the network record of the IP address asset, such as registration or last changed.
ipwhois.network.events.actorWho performed an event on the network record of the IP address asset, when the registry names one.
ipwhois.objects.uidThe handle of a registry contact or organization (RDAP entity) linked to the network of the IP address asset, such as ACME-ARIN.
ipwhois.objects.contact.email.typeThe type of an e-mail address of a contact linked to the network of the IP address asset, such as abuse.
ipwhois.objects.contact.email.valueAn e-mail address of a contact linked to the network of the IP address asset.
ipwhois.objects.contact.address.typeThe type of a postal address of a contact linked to the network of the IP address asset.
ipwhois.objects.contact.address.valueA postal address of a contact linked to the network of the IP address asset.
ipwhois.objects.contact.phone.typeThe type of a phone number of a contact linked to the network of the IP address asset, such as voice or work.
ipwhois.objects.contact.phone.valueA phone number of a contact linked to the network of the IP address asset.
ipwhois.objects.contact.kindWhat kind of contact is linked to the network of the IP address asset: org, group or individual.
ipwhois.objects.contact.nameThe name of a contact or organization linked to the network of the IP address asset, such as Abuse or a company name.
ipwhois.objects.contact.roleThe role given in the contact card of an entity linked to the network of the IP address asset.
ipwhois.objects.contact.titleThe title given in the contact card of an entity linked to the network of the IP address asset.
ipwhois.objects.entitiesHandles of further entities listed under a contact linked to the network of the IP address asset.
ipwhois.objects.events.actionAn event in the history of a contact record linked to the network of the IP address asset, such as registration or last changed.
ipwhois.objects.events.actorWho performed an event on a contact record linked to the network of the IP address asset, when the registry names one.
ipwhois.objects.events_actorEvents in which a contact linked to the network of the IP address asset is itself the actor (the RDAP asEventActor list), as text; empty on every sampled record.
ipwhois.objects.handleThe registry handle of a contact or organization linked to the network of the IP address asset.
ipwhois.objects.linksLinks to the registry record of a contact linked to the network of the IP address asset.
ipwhois.objects.notices.titleThe title of a notice on a contact record linked to the network of the IP address asset, such as Terms of Service.
ipwhois.objects.notices.descriptionThe text of a notice on a contact record linked to the network of the IP address asset.
ipwhois.objects.notices.linksLinks given in a notice on a contact record linked to the network of the IP address asset.
ipwhois.objects.rawThe raw RDAP object of a contact linked to the network of the IP address asset, when it is kept.
ipwhois.objects.remarks.titleThe title of a remark on a contact record linked to the network of the IP address asset, such as Registration Comments.
ipwhois.objects.remarks.descriptionThe text of a remark on a contact record linked to the network of the IP address asset.
ipwhois.objects.remarks.linksLinks given in a remark on a contact record linked to the network of the IP address asset.
ipwhois.objects.rolesThe roles of a contact for the network of the IP address asset, such as registrant, abuse or technical.
ipwhois.objects.statusThe registry status of a contact linked to the network of the IP address asset, such as validated.
ipwhois_last_change_dataThe IP WHOIS fields that changed in the last change seen, as field paths under ipwhois.
ipdns.ptr_recordsThe PTR (reverse DNS) host names of an IP address asset.
ipdns_last_change_dataThe reverse DNS fields that changed in the last change seen, as field paths under ipdns.
issue_category_stats.nameThe name of an issue category in the per-category issue counts of the asset, such as DNS, SSL/TLS, Web Application, Domain/Whois or Network.
technology_count.by_category.nameThe name of a technology category in the per-category technology counts of the asset, such as Web servers or Analytics.
domain_snapshot.issue_category_stats.nameThe name of an issue category in the per-category issue counts of the domain and its subdomains together, such as DNS, SSL/TLS, Web Application, Domain/Whois or Network. Set on domain assets.
domain_snapshot.technology_count.by_category.nameThe name of a technology category in the per-category technology counts of the domain and its subdomains together, such as Web servers or Analytics. Set on domain assets.

Operators eq in gte lte exists

FieldDescription
added_dateWhen the asset was added to your inventory (UTC date-time).
latest_scan_dateWhen the asset was last scanned, shown as the last check date in Inventory (UTC date-time).
seems_inactive_first_seenWhen the asset was first found to seem inactive (UTC date-time).
seems_inactive_last_seenWhen the asset was most recently found to seem inactive (UTC date-time).
login_page_probabilityThe login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where is_login_page is true.
fqdn.name.lengthThe number of characters in the name without the extension: 4 for acme.example.
website.portThe port of a website asset, such as 443.
whois.create_dateWhen the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).
whois.update_dateWhen the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).
whois.expiry_dateWhen the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).
whois_create_date_historicalEvery creation date seen for the domain over time, so a domain that was deleted and registered again keeps its earlier dates too (UTC date-times).
whois_check_dateWhen the WHOIS record of the asset was last checked (UTC date-time).
whois_last_change_dateWhen a change in the WHOIS record of the asset was last seen (UTC date-time).
dns.a.value_last_change_dateWhen the A record text (dns.a.value) last changed (UTC date-time).
dns.a.rcode_last_change_dateWhen the response code of the A lookup (dns.a.rcode) last changed (UTC date-time).
dns.a.last_change_dateWhen the asset's A records last changed, in their text or their response code (UTC date-time).
dns.a.ip_addresses.asn_dateThe registry allocation date that the ASN lookup reports for the A-record address, as a date at midnight UTC.
dns.a.ip_addresses.nir.nets.contacts.admin.updatedWhen the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).
dns.a.ip_addresses.nir.nets.contacts.tech.updatedWhen the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time).
dns.a.ip_addresses.nir.nets.createdWhen a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was created (UTC date-time).
dns.a.ip_addresses.nir.nets.updatedWhen a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was last updated (UTC date-time).
dns.a.ip_addresses.network.events.timestampWhen an event on the network record of the A-record address happened (UTC date-time).
dns.a.ip_addresses.objects.events.timestampWhen an event on a contact record linked to the network of the A-record address happened (UTC date-time).
dns.aaaa.value_last_change_dateWhen the AAAA record text (dns.aaaa.value) last changed (UTC date-time).
dns.aaaa.rcode_last_change_dateWhen the response code of the AAAA lookup (dns.aaaa.rcode) last changed (UTC date-time).
dns.aaaa.last_change_dateWhen the asset's AAAA records last changed, in their text or their response code (UTC date-time).
dns.caa.value_last_change_dateWhen the CAA record text (dns.caa.value) last changed (UTC date-time).
dns.caa.rcode_last_change_dateWhen the response code of the CAA lookup (dns.caa.rcode) last changed (UTC date-time).
dns.caa.last_change_dateWhen the asset's CAA records last changed, in their text or their response code (UTC date-time).
dns.cname.value_last_change_dateWhen the CNAME record text (dns.cname.value) last changed (UTC date-time).
dns.cname.rcode_last_change_dateWhen the response code of the CNAME lookup (dns.cname.rcode) last changed (UTC date-time).
dns.cname.last_change_dateWhen the asset's CNAME records last changed, in their text or their response code (UTC date-time).
dns.dnskey.value_last_change_dateWhen the DNSKEY record text (dns.dnskey.value) last changed (UTC date-time).
dns.dnskey.rcode_last_change_dateWhen the response code of the DNSKEY lookup (dns.dnskey.rcode) last changed (UTC date-time).
dns.dnskey.last_change_dateWhen the asset's DNSKEY records last changed, in their text or their response code (UTC date-time).
dns.ds.value_last_change_dateWhen the DS record text (dns.ds.value) last changed (UTC date-time).
dns.ds.rcode_last_change_dateWhen the response code of the DS lookup (dns.ds.rcode) last changed (UTC date-time).
dns.ds.last_change_dateWhen the asset's DS records last changed, in their text or their response code (UTC date-time).
dns.ds.records.key_tagThe key tag (a number) of the DNSKEY that a DS record refers to.
dns.mx.value_last_change_dateWhen the MX record text (dns.mx.value) last changed (UTC date-time).
dns.mx.rcode_last_change_dateWhen the response code of the MX lookup (dns.mx.rcode) last changed (UTC date-time).
dns.mx.last_change_dateWhen the asset's MX records last changed, in their text or their response code (UTC date-time).
dns.ns.value_last_change_dateWhen the NS record text (dns.ns.value) last changed (UTC date-time).
dns.ns.rcode_last_change_dateWhen the response code of the NS lookup (dns.ns.rcode) last changed (UTC date-time).
dns.ns.last_change_dateWhen the asset's NS records last changed, in their text or their response code (UTC date-time).
dns.nsec.value_last_change_dateWhen the NSEC record text (dns.nsec.value) last changed (UTC date-time).
dns.nsec.rcode_last_change_dateWhen the response code of the NSEC lookup (dns.nsec.rcode) last changed (UTC date-time).
dns.nsec.last_change_dateWhen the asset's NSEC records last changed, in their text or their response code (UTC date-time).
dns.nsec3.value_last_change_dateWhen the NSEC3 record text (dns.nsec3.value) last changed (UTC date-time).
dns.nsec3.rcode_last_change_dateWhen the response code of the NSEC3 lookup (dns.nsec3.rcode) last changed (UTC date-time).
dns.nsec3.last_change_dateWhen the asset's NSEC3 records last changed, in their text or their response code (UTC date-time).
dns.rrsig.value_last_change_dateWhen the RRSIG record text (dns.rrsig.value) last changed (UTC date-time).
dns.rrsig.rcode_last_change_dateWhen the response code of the RRSIG lookup (dns.rrsig.rcode) last changed (UTC date-time).
dns.rrsig.last_change_dateWhen the asset's RRSIG records last changed, in their text or their response code (UTC date-time).
dns.rrsig.signature_inceptionWhen an RRSIG signature becomes valid (UTC date-time).
dns.rrsig.signature_expirationWhen an RRSIG signature expires (UTC date-time).
dns.soa.value_last_change_dateWhen the SOA record text (dns.soa.value) last changed (UTC date-time).
dns.soa.rcode_last_change_dateWhen the response code of the SOA lookup (dns.soa.rcode) last changed (UTC date-time).
dns.soa.last_change_dateWhen the asset's SOA records last changed, in their text or their response code (UTC date-time).
dns.srv.value_last_change_dateWhen the SRV record text (dns.srv.value) last changed (UTC date-time).
dns.srv.rcode_last_change_dateWhen the response code of the SRV lookup (dns.srv.rcode) last changed (UTC date-time).
dns.srv.last_change_dateWhen the asset's SRV records last changed, in their text or their response code (UTC date-time).
dns.srv.records.portThe port an SRV record points to.
dns.txt.value_last_change_dateWhen the TXT record text (dns.txt.value) last changed (UTC date-time).
dns.txt.rcode_last_change_dateWhen the response code of the TXT lookup (dns.txt.rcode) last changed (UTC date-time).
dns.txt.last_change_dateWhen the asset's TXT records last changed, in their text or their response code (UTC date-time).
dns_check_dateWhen the DNS records of the asset were last checked (UTC date-time).
dns_last_change_dateWhen a change in the DNS records of the asset was last seen (UTC date-time).
ssl.portThe port that the asset's TLS certificate was collected on, such as 443.
ssl.validity.start_dateThe date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.
ssl.validity.end_dateThe date the asset's TLS certificate expires (Not After), as a UTC date-time.
ssl.validity.lengthThe validity period of the certificate in seconds: 7,776,000 seconds are 90 days.
ssl.extensions.signed_certificate_timestamps.timestampWhen a Certificate Transparency log recorded the certificate, from a signed certificate timestamp (UTC date-time).
ssl.extensions.signed_certificate_timestamps.versionThe version of a signed certificate timestamp; 0 stands for version 1.
ssl_check_dateWhen the TLS certificate of the asset was last checked (UTC date-time).
ssl_last_change_dateWhen a change in the TLS certificate of the asset was last seen (UTC date-time).
http.redirection_history.status_codeThe HTTP status code at a step of the redirect chain of the HTTP check, such as 301 or 200.
http.first_status_codeThe HTTP status code of the first response in the HTTP check, such as 301 for a redirect or 200.
http.final_status_codeThe HTTP status code of the last response in the HTTP check, after redirects, such as 200, 404 or 502. Inventory's HTTP status column shows this value.
http_check_dateWhen the HTTP check of the asset last ran (UTC date-time).
http_last_change_dateWhen a change in the HTTP check result of the asset was last seen (UTC date-time).
webdata.http.redirection_history.status_codeThe HTTP status code at a step of the redirect chain of the web data scan, such as 301 or 200.
webdata.http.first_status_codeThe HTTP status code of the first response in the web data scan, such as 301 for a redirect or 200.
webdata.http.final_status_codeThe HTTP status code of the last response in the web data scan, after redirects, such as 200, 404 or 502.
webdata.http.cookies.sizeThe size of a cookie set in the web data scan, in bytes (name plus value).
webdata.http.cookies.expiresWhen a cookie set in the web data scan expires (UTC date-time); session cookies show 1969-12-31T23:59:59Z.
webdata.technology.stacks.confidenceHow certain the detection of a technology is, from 0 to 100; every sampled detection has 100.
webdata.technology.stacks.clean_versionThe major version of a detected technology as a whole number, such as 1 for version 1.0.
webdata_check_dateWhen the web data scan of the asset, which collects the page content, headers and technologies, last ran (UTC date-time).
webdata_last_change_dateWhen a change in the web data of the asset was last seen (UTC date-time).
ipwhois.asn_dateThe registry allocation date that the ASN lookup reports for the IP address asset, as a date at midnight UTC.
ipwhois.nir.nets.contacts.admin.updatedWhen the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).
ipwhois.nir.nets.contacts.tech.updatedWhen the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time).
ipwhois.nir.nets.createdWhen a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was created (UTC date-time).
ipwhois.nir.nets.updatedWhen a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was last updated (UTC date-time).
ipwhois.network.events.timestampWhen an event on the network record of the IP address asset happened (UTC date-time).
ipwhois.objects.events.timestampWhen an event on a contact record linked to the network of the IP address asset happened (UTC date-time).
ipwhois_check_dateWhen the IP WHOIS record of an IP address asset was last checked (UTC date-time).
ipwhois_last_change_dateWhen a change in the IP WHOIS record of an IP address asset was last seen (UTC date-time).
ipdns_check_dateWhen the reverse DNS (PTR) records of an IP address asset were last checked (UTC date-time).
ipdns_last_change_dateWhen a change in the reverse DNS (PTR) records of an IP address asset was last seen (UTC date-time).
subdomain_countThe number of subdomains of the domain in your inventory; set on domain assets.
pointed_fqdn_countA count of host names (FQDNs) that point to the asset; no sampled asset had a value.
redirected_domain_countThe number of domain assets in your inventory whose HTTP check ends on this asset after redirects.
redirected_asset_countThe number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.
average_issue_durationThe average duration of the issues on the asset, in seconds.
average_fix_durationThe average time taken to fix the issues on the asset, in seconds.
open_port_countThe number of open ports found on the asset.
open_portsThe open port numbers found on the asset, such as 80, 443 or 8080.
issue_state_stats.newly_detectedThe number of issues on the asset in the newly_detected state, an active state set by the platform.
issue_state_stats.reappearedThe number of issues on the asset in the reappeared state, an active state set by the platform.
issue_state_stats.unresolvedThe number of issues on the asset in the unresolved state, an active state set by the platform.
issue_state_stats.marked_as_resolvedThe number of issues on the asset in the marked_as_resolved state, an inactive state that a user sets.
issue_state_stats.risk_acceptedThe number of issues on the asset in the risk_accepted state, an inactive state that a user sets.
issue_state_stats.ignoredThe number of issues on the asset in the ignored state, an inactive state that a user sets.
issue_state_stats.marked_as_false_positiveThe number of issues on the asset in the marked_as_false_positive state, an inactive state that a user sets.
issue_state_stats.not_applicableThe number of issues on the asset in the not_applicable state, an inactive state set by the platform.
issue_state_stats.verified_resolvedThe number of issues on the asset in the verified_resolved state, an inactive state set by the platform.
issue_category_stats.countThe number of active issues in that category on the asset.
issue_category_stats.severity_stats.criticalThe number of active issues of critical severity in that category on the asset.
issue_category_stats.severity_stats.highThe number of active issues of high severity in that category on the asset.
issue_category_stats.severity_stats.mediumThe number of active issues of medium severity in that category on the asset.
issue_category_stats.severity_stats.lowThe number of active issues of low severity in that category on the asset.
issue_category_stats.severity_stats.informationThe number of active issues of information severity in that category on the asset.
issue_count.totalThe number of issues on the asset in any state, active or inactive.
issue_count.activeThe number of active issues on the asset: those in the newly_detected, unresolved or reappeared state.
issue_count.active_by_severity.criticalThe number of active issues of critical severity on the asset.
issue_count.active_by_severity.highThe number of active issues of high severity on the asset.
issue_count.active_by_severity.mediumThe number of active issues of medium severity on the asset.
issue_count.active_by_severity.lowThe number of active issues of low severity on the asset.
issue_count.active_by_severity.informationThe number of active issues of information severity on the asset.
technology_count.totalThe number of technologies detected on the asset.
technology_count.by_category.countThe number of technologies in that category on the asset.
vulnerability_count.totalThe number of vulnerabilities (CVEs) found on the asset.
vulnerability_count.by_severity.criticalThe number of vulnerabilities (CVEs) of critical severity on the asset.
vulnerability_count.by_severity.highThe number of vulnerabilities (CVEs) of high severity on the asset.
vulnerability_count.by_severity.mediumThe number of vulnerabilities (CVEs) of medium severity on the asset.
vulnerability_count.by_severity.lowThe number of vulnerabilities (CVEs) of low severity on the asset.
vulnerability_count.by_severity.noneThe number of vulnerabilities (CVEs) on the asset whose severity is none.
vulnerability_count.by_severity.unknownThe number of vulnerabilities (CVEs) on the asset whose severity is unknown.
security_scoreThe asset's External Attack Surface Management (EASM) security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.
weightThe asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.
user_weightThe weight you set for the asset, from 1 to 100; empty when you have not set one.
system_weightThe weight the platform calculates for the asset from many criteria; it can be above 100.
domain_snapshot.average_issue_durationThe average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.
domain_snapshot.average_fix_durationThe average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.
domain_snapshot.open_port_countThe number of open ports found on the domain and its subdomains together. Set on domain assets.
domain_snapshot.security_scoreThe domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as security_score. Set on domain assets.
domain_snapshot.issue_count.totalThe number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.
domain_snapshot.issue_count.activeThe number of active issues on the domain and its subdomains together: those in the newly_detected, unresolved or reappeared state. Set on domain assets.
domain_snapshot.issue_count.active_by_severity.criticalThe number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_count.active_by_severity.highThe number of active issues of high severity on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_count.active_by_severity.mediumThe number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_count.active_by_severity.lowThe number of active issues of low severity on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_count.active_by_severity.informationThe number of active issues of information severity on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_category_stats.countThe number of active issues in that category on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_category_stats.severity_stats.criticalThe number of active issues of critical severity in that category on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_category_stats.severity_stats.highThe number of active issues of high severity in that category on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_category_stats.severity_stats.mediumThe number of active issues of medium severity in that category on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_category_stats.severity_stats.lowThe number of active issues of low severity in that category on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_category_stats.severity_stats.informationThe number of active issues of information severity in that category on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_state_stats.newly_detectedThe number of issues on the domain and its subdomains together in the newly_detected state, an active state set by the platform. Set on domain assets.
domain_snapshot.issue_state_stats.reappearedThe number of issues on the domain and its subdomains together in the reappeared state, an active state set by the platform. Set on domain assets.
domain_snapshot.issue_state_stats.unresolvedThe number of issues on the domain and its subdomains together in the unresolved state, an active state set by the platform. Set on domain assets.
domain_snapshot.issue_state_stats.marked_as_resolvedThe number of issues on the domain and its subdomains together in the marked_as_resolved state, an inactive state that a user sets. Set on domain assets.
domain_snapshot.issue_state_stats.risk_acceptedThe number of issues on the domain and its subdomains together in the risk_accepted state, an inactive state that a user sets. Set on domain assets.
domain_snapshot.issue_state_stats.ignoredThe number of issues on the domain and its subdomains together in the ignored state, an inactive state that a user sets. Set on domain assets.
domain_snapshot.issue_state_stats.marked_as_false_positiveThe number of issues on the domain and its subdomains together in the marked_as_false_positive state, an inactive state that a user sets. Set on domain assets.
domain_snapshot.issue_state_stats.not_applicableThe number of issues on the domain and its subdomains together in the not_applicable state, an inactive state set by the platform. Set on domain assets.
domain_snapshot.issue_state_stats.verified_resolvedThe number of issues on the domain and its subdomains together in the verified_resolved state, an inactive state set by the platform. Set on domain assets.
domain_snapshot.technology_count.totalThe number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.
domain_snapshot.technology_count.by_category.countThe number of distinct technologies in that category across the domain and its subdomains, each counted once. Set on domain assets.
domain_snapshot.vulnerability_count.totalThe number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.criticalThe number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.highThe number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.mediumThe number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.lowThe number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.noneThe number of vulnerabilities (CVEs) whose severity is none across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.unknownThe number of vulnerabilities (CVEs) whose severity is unknown across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.

Operators eq exists

FieldDescription
is_main_assetTrue for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.
seems_inactiveTrue when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.
discovery_enabledTrue when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.
dns_wildcard_activeTrue when the asset has an active wildcard DNS record (such as *.acme.example), so any subdomain name under it resolves.
is_login_pageTrue when the asset serves a login page; Inventory marks it with a login page icon.
fqdn.is_idnTrue when the host name is an internationalized domain name (IDN) with non-ASCII characters.
fqdn.name.contains_confusableTrue when the name contains confusable characters that look like other letters, such as Cyrillic а for Latin a, a common trick in look-alike domains.
fqdn.name.contains_hyphenTrue when the name (without the extension) contains a hyphen.
fqdn.name.contains_letterTrue when the name (without the extension) contains a letter.
fqdn.name.contains_numberTrue when the name (without the extension) contains a digit.
fqdn.domain.is_idnTrue when the registrable domain is an internationalized domain name (IDN) with non-ASCII characters.
whois_privacy_enabledTrue when the platform flagged WHOIS privacy protection on the domain's registrant details; set on domain assets.
ssl.signature.is_validTrue when the asset's TLS certificate passed validation for the host; when false, ssl.signature.invalid_reason says why.
ssl.signature.is_valid_chainA flag for whether the certificate chain of the asset's TLS certificate is valid. It was true on every sampled certificate, even one whose validation failed with unable to get issuer certificate.
ssl.signature.is_self_signedTrue when the asset's TLS certificate is self-signed, that is signed by its own key rather than by a certificate authority.
ssl.extensions.basic_constraints.is_caTrue when the certificate is a certificate authority (CA) certificate, from its Basic Constraints extension.
ssl.extensions.extended_key_usage.client_authTrue when the Extended Key Usage extension allows TLS client authentication.
ssl.extensions.extended_key_usage.server_authTrue when the Extended Key Usage extension allows TLS server authentication, as website certificates need.
ssl.extensions.key_usage.content_commitmentTrue when the Key Usage extension allows the certificate's key to be used for content commitment (non-repudiation).
ssl.extensions.key_usage.crl_signTrue when the Key Usage extension allows the certificate's key to be used for signing certificate revocation lists (CRL sign).
ssl.extensions.key_usage.data_enciphermentTrue when the Key Usage extension allows the certificate's key to be used for data encipherment.
ssl.extensions.key_usage.digital_signatureTrue when the Key Usage extension allows the certificate's key to be used for digital signatures.
ssl.extensions.key_usage.key_agreementTrue when the Key Usage extension allows the certificate's key to be used for key agreement.
ssl.extensions.key_usage.key_cert_signTrue when the Key Usage extension allows the certificate's key to be used for signing other certificates (certificate sign).
ssl.extensions.key_usage.key_enciphermentTrue when the Key Usage extension allows the certificate's key to be used for key encipherment.
ssl.has_expiredTrue when the asset's TLS certificate is past its end date.
http.external_domain_redirectionTrue when the HTTP check ended on a different registrable domain than it started on.
http.external_fqdn_redirectionTrue when the HTTP check ended on a different host name than it started on, for example acme.example to www.acme.example.
webdata.html.inspect_disabledA flag of the web data scan that marks pages whose inspection was disabled; it was false on every sampled asset.
webdata.html.html_meta.no_index_statusTrue when the scanned page asks search engines not to index it (a noindex robots directive).
webdata.http.external_domain_redirectionTrue when the web data scan ended on a different registrable domain than it started on.
webdata.http.external_fqdn_redirectionTrue when the web data scan ended on a different host name than it started on, for example acme.example to www.acme.example.
webdata.http.cookies.secureTrue when a cookie set in the web data scan is sent over HTTPS only (Secure attribute).
webdata.http.cookies.http_onlyTrue when scripts on the page cannot read a cookie set in the web data scan (HttpOnly attribute).
webdata.http.cookies.sessionTrue when a cookie set in the web data scan is a session cookie, deleted when the browser closes.
is_parkedTrue when the asset is parked; Inventory marks it with a P badge whose tooltip shows where it redirects.

Operators eq in exists

FieldDescription
asset_typeThe asset type: domain, subdomain, ip or website.
creation_methodHow the asset entered your inventory: manually_added (added directly), manually_approved (approved by someone in Discovery) or auto_approved (added by a discovery rule with auto approval).
fqdn.domain.extension_typeThe kind of extension: gTLD for generic extensions such as com, ccTLD for country-code extensions such as de or co.uk.
dns.dnskey.records.key_typeThe role of a DNSKEY: ZSK (zone-signing key), KSK (key-signing key) or KSK_REVOKED (revoked key-signing key).
dns.dnskey.records.algorithmThe DNSSEC algorithm of a DNSKEY, such as ECDSAP256SHA256 or RSASHA256.
dns.ds.records.algorithmThe DNSSEC algorithm of the key that a DS record refers to, such as ECDSAP256SHA256 or RSASHA256.
dns.ds.records.digest_typeThe hash used for a DS record's digest: SHA1, SHA256, SHA384, GOST or NULL.
dns.rrsig.algorithmThe DNSSEC algorithm of an RRSIG signature, such as ECDSAP256SHA256 or RSASHA256.

Operators Not measured

FieldDescription
website.parent_asset.typeThe asset type of the website's parent asset, such as subdomain.

Sortable Fields

FieldDescription
assetThe asset's name: a domain, subdomain or IP address, or for a website asset host:port.
added_dateWhen the asset was added to your inventory (UTC date-time).
creation_methodHow the asset entered your inventory: manually_added (added directly), manually_approved (approved by someone in Discovery) or auto_approved (added by a discovery rule with auto approval).
latest_scan_dateWhen the asset was last scanned, shown as the last check date in Inventory (UTC date-time).
is_main_assetTrue for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports.
seems_inactiveTrue when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score.
seems_inactive_first_seenWhen the asset was first found to seem inactive (UTC date-time).
seems_inactive_last_seenWhen the asset was most recently found to seem inactive (UTC date-time).
discovery_enabledTrue when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it.
dns_wildcard_activeTrue when the asset has an active wildcard DNS record (such as *.acme.example), so any subdomain name under it resolves.
is_login_pageTrue when the asset serves a login page; Inventory marks it with a login page icon.
login_page_probabilityThe login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where is_login_page is true.
fqdn.unicodeThe asset's full host name (FQDN) in its readable Unicode form.
fqdn.punycodeThe asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals fqdn.unicode.
fqdn.domain.unicodeThe registrable domain the asset belongs to, in Unicode: acme.example for both acme.example and www.acme.example.
fqdn.domain.punycodeThe registrable domain the asset belongs to, in its ASCII (punycode) form.
fqdn.domain.extension.unicodeThe domain's extension, everything after the name, such as com or co.uk.
fqdn.domain.extension_root.unicodeThe top-level part of the extension: uk for both uk and co.uk.
fqdn.domain.extension_typeThe kind of extension: gTLD for generic extensions such as com, ccTLD for country-code extensions such as de or co.uk.
website.portThe port of a website asset, such as 443.
whois.create_dateWhen the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time).
whois.update_dateWhen the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time).
whois.expiry_dateWhen the domain registration expires, from the WHOIS record of a domain asset (UTC date-time).
whois.domain_statusThe domain's EPP status codes from WHOIS, in lower case without spaces, such as clienttransferprohibited.
whois.name_serversThe name servers listed in the WHOIS record, such as ns1.acme.example.
whois.registrarThe registrar the domain is registered through, as written in WHOIS (usually lower case).
whois.registrant.organizationThe registrant's organization in WHOIS; often a privacy placeholder such as redacted for privacy or a proxy service.
whois.registrant.emailThe registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead.
whois.registrant.phoneThe registrant's phone number in WHOIS, in the registry format such as +1.4805551234.
dns.a.ip_addresses.ipAn IPv4 address from the asset's A records (the A-record address); the other dns.a.ip_addresses fields hold its IP WHOIS (RDAP) data.
dns.a.ip_addresses.asnThe number of the autonomous system (ASN) that announces the A-record address, as a string such as 13335.
dns.a.ip_addresses.asn_cidrThe routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup.
dns.a.ip_addresses.asn_descriptionThe name and holder of the autonomous system that announces the A-record address, such as CLOUDFLARENET - Cloudflare, Inc., US.
dns.a.ip_addresses.asn_country_codeThe country of the autonomous system that announces the A-record address, as a two-letter code such as US.
dns.a.ip_addresses.asn_registryThe regional internet registry responsible for the A-record address, such as arin or ripencc.
dns.a.ip_addresses.nir.nets.cidrThe range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation.
dns.a.ip_addresses.network.cidrThe registered network block that contains the A-record address, in CIDR notation, such as 192.0.2.0/24; a network made of several blocks lists them separated by commas.
dns.a.ip_addresses.network.nameThe name of the registered network that contains the A-record address, such as CLOUDFLARENET.
dns.a.ip_addresses.network.countryThe country of the registered network that contains the A-record address, as a two-letter code such as FR.
dns.ns.name_serversThe name server host names from the asset's NS records, such as ns1.acme.example.
dns.mx.mail_serversThe mail server host names from the asset's MX records, such as mail.acme.example.
dns_last_change_dateWhen a change in the DNS records of the asset was last seen (UTC date-time).
ssl.serial_numberThe serial number of the asset's TLS certificate, as a decimal string.
ssl.fingerprint.sha1The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex.
ssl.subject.organizationThe organization (O) of the subject (holder) of the asset's TLS certificate.
ssl.validity.start_dateThe date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time.
ssl.validity.end_dateThe date the asset's TLS certificate expires (Not After), as a UTC date-time.
ssl_last_change_dateWhen a change in the TLS certificate of the asset was last seen (UTC date-time).
http.final_domainThe registrable domain the HTTP check ended on after redirects, such as acme.example.
http.final_fqdnThe host name the HTTP check ended on after redirects, such as www.acme.example.
http.first_status_codeThe HTTP status code of the first response in the HTTP check, such as 301 for a redirect or 200.
http.final_status_codeThe HTTP status code of the last response in the HTTP check, after redirects, such as 200, 404 or 502. Inventory's HTTP status column shows this value.
http_last_change_dateWhen a change in the HTTP check result of the asset was last seen (UTC date-time).
webdata.http.final_domainThe registrable domain the web data scan ended on after redirects, such as acme.example.
webdata.http.final_fqdnThe host name the web data scan ended on after redirects, such as www.acme.example.
webdata.http.first_status_codeThe HTTP status code of the first response in the web data scan, such as 301 for a redirect or 200.
webdata.http.final_status_codeThe HTTP status code of the last response in the web data scan, after redirects, such as 200, 404 or 502.
webdata_last_change_dateWhen a change in the web data of the asset was last seen (UTC date-time).
ipwhois.asnThe number of the autonomous system (ASN) that announces the IP address asset, as a string such as 13335.
ipwhois.asn_cidrThe routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup.
ipwhois.asn_descriptionThe name and holder of the autonomous system that announces the IP address asset, such as CLOUDFLARENET - Cloudflare, Inc., US.
ipwhois.asn_country_codeThe country of the autonomous system that announces the IP address asset, as a two-letter code such as US.
ipwhois.asn_registryThe regional internet registry responsible for the IP address asset, such as arin or ripencc.
ipwhois.nir.nets.cidrThe range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation.
ipwhois.network.cidrThe registered network block that contains the IP address asset, in CIDR notation, such as 192.0.2.0/24; a network made of several blocks lists them separated by commas.
ipwhois.network.nameThe name of the registered network that contains the IP address asset, such as CLOUDFLARENET.
ipwhois.network.countryThe country of the registered network that contains the IP address asset, as a two-letter code such as FR.
subdomain_countThe number of subdomains of the domain in your inventory; set on domain assets.
website_countThe number of website assets (host:port) in your inventory that belong to this asset.
pointed_fqdn_countA count of host names (FQDNs) that point to the asset; no sampled asset had a value.
redirected_domain_countThe number of domain assets in your inventory whose HTTP check ends on this asset after redirects.
redirected_asset_countThe number of assets of any type in your inventory whose HTTP check ends on this asset after redirects.
open_port_countThe number of open ports found on the asset.
average_issue_durationThe average duration of the issues on the asset, in seconds.
average_fix_durationThe average time taken to fix the issues on the asset, in seconds.
issue_state_stats.newly_detectedThe number of issues on the asset in the newly_detected state, an active state set by the platform.
issue_state_stats.reappearedThe number of issues on the asset in the reappeared state, an active state set by the platform.
issue_state_stats.unresolvedThe number of issues on the asset in the unresolved state, an active state set by the platform.
issue_state_stats.marked_as_resolvedThe number of issues on the asset in the marked_as_resolved state, an inactive state that a user sets.
issue_state_stats.risk_acceptedThe number of issues on the asset in the risk_accepted state, an inactive state that a user sets.
issue_state_stats.ignoredThe number of issues on the asset in the ignored state, an inactive state that a user sets.
issue_state_stats.marked_as_false_positiveThe number of issues on the asset in the marked_as_false_positive state, an inactive state that a user sets.
issue_state_stats.not_applicableThe number of issues on the asset in the not_applicable state, an inactive state set by the platform.
issue_state_stats.verified_resolvedThe number of issues on the asset in the verified_resolved state, an inactive state set by the platform.
issue_count.totalThe number of issues on the asset in any state, active or inactive.
issue_count.activeThe number of active issues on the asset: those in the newly_detected, unresolved or reappeared state.
issue_count.active_by_severity.criticalThe number of active issues of critical severity on the asset.
issue_count.active_by_severity.highThe number of active issues of high severity on the asset.
issue_count.active_by_severity.mediumThe number of active issues of medium severity on the asset.
technology_count.totalThe number of technologies detected on the asset.
vulnerability_count.totalThe number of vulnerabilities (CVEs) found on the asset.
vulnerability_count.by_severity.criticalThe number of vulnerabilities (CVEs) of critical severity on the asset.
security_scoreThe asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300.
weightThe asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score.
user_weightThe weight you set for the asset, from 1 to 100; empty when you have not set one.
system_weightThe weight the platform calculates for the asset from many criteria; it can be above 100.
domain_snapshot.average_issue_durationThe average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets.
domain_snapshot.average_fix_durationThe average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets.
domain_snapshot.open_port_countThe number of open ports found on the domain and its subdomains together. Set on domain assets.
domain_snapshot.security_scoreThe domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as security_score. Set on domain assets.
domain_snapshot.issue_count.totalThe number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets.
domain_snapshot.issue_count.activeThe number of active issues on the domain and its subdomains together: those in the newly_detected, unresolved or reappeared state. Set on domain assets.
domain_snapshot.issue_count.active_by_severity.criticalThe number of active issues of critical severity on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_count.active_by_severity.highThe number of active issues of high severity on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_count.active_by_severity.mediumThe number of active issues of medium severity on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_count.active_by_severity.lowThe number of active issues of low severity on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_count.active_by_severity.informationThe number of active issues of information severity on the domain and its subdomains together. Set on domain assets.
domain_snapshot.issue_state_stats.newly_detectedThe number of issues on the domain and its subdomains together in the newly_detected state, an active state set by the platform. Set on domain assets.
domain_snapshot.issue_state_stats.reappearedThe number of issues on the domain and its subdomains together in the reappeared state, an active state set by the platform. Set on domain assets.
domain_snapshot.issue_state_stats.unresolvedThe number of issues on the domain and its subdomains together in the unresolved state, an active state set by the platform. Set on domain assets.
domain_snapshot.issue_state_stats.marked_as_resolvedThe number of issues on the domain and its subdomains together in the marked_as_resolved state, an inactive state that a user sets. Set on domain assets.
domain_snapshot.issue_state_stats.risk_acceptedThe number of issues on the domain and its subdomains together in the risk_accepted state, an inactive state that a user sets. Set on domain assets.
domain_snapshot.issue_state_stats.ignoredThe number of issues on the domain and its subdomains together in the ignored state, an inactive state that a user sets. Set on domain assets.
domain_snapshot.issue_state_stats.marked_as_false_positiveThe number of issues on the domain and its subdomains together in the marked_as_false_positive state, an inactive state that a user sets. Set on domain assets.
domain_snapshot.issue_state_stats.not_applicableThe number of issues on the domain and its subdomains together in the not_applicable state, an inactive state set by the platform. Set on domain assets.
domain_snapshot.issue_state_stats.verified_resolvedThe number of issues on the domain and its subdomains together in the verified_resolved state, an inactive state set by the platform. Set on domain assets.
domain_snapshot.technology_count.totalThe number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets.
domain_snapshot.vulnerability_count.totalThe number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.criticalThe number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.highThe number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.mediumThe number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.lowThe number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.noneThe number of vulnerabilities (CVEs) whose severity is none across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.
domain_snapshot.vulnerability_count.by_severity.unknownThe number of vulnerabilities (CVEs) whose severity is unknown across the domain and its subdomains, counted like domain_snapshot.vulnerability_count.total. Set on domain assets.

Response Fields

FieldType
asset_countinteger

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
asset_countnumber1

Examples

Selecting one loads it into the request and response panels.

Reference updated