# Asset Set Weight

POST /easm/assets/search:set-weight: Sets a business-importance weight (0–1000) on every asset matching filters. Weights influence prioritization and scores.

Source: https://docs.deepinfo.com/reference/easm/asset-set-weight/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/easm/assets/search:set-weight`

Sets a business-importance `weight` (0–1000) on every asset matching `filters`. Weights influence prioritization and scores.

The action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `weight` | Optional | Min `0`, max `1000`. | `100` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "acme.example"
      }
    ]
  }
}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "asset",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with some of the filters of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value; Searchable Fields lists them all. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `asset` | The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. |
| `tags` | Your own labels on the asset, such as a business unit or an environment; each tag is 3 to 100 characters long. |
| `fqdn.unicode` | The asset's full host name (FQDN) in its readable Unicode form. |
| `fqdn.punycode` | The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`. |
| `fqdn.name.unicode` | The host name without its extension, in Unicode: `acme` for `acme.example`, `www.acme` for `www.acme.example`. |
| `fqdn.name.latinized` | Latin-letter spellings of a name that has non-Latin or accented letters, so a search for `istanbul` also finds names written with `İ`. |
| `fqdn.domain.unicode` | The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`. |
| `fqdn.domain.punycode` | The registrable domain the asset belongs to, in its ASCII (punycode) form. |
| `fqdn.domain.extension.unicode` | The domain's extension, everything after the name, such as `com` or `co.uk`. |
| `fqdn.domain.extension_root.unicode` | The top-level part of the extension: `uk` for both `uk` and `co.uk`. |
| `fqdn.domain.extension_sub.unicode` | The second-level part of a two-part extension, such as `co` in `co.uk`; empty for single-part extensions. |
| `website.path` | The URL path of a website asset, such as `/`. |
| `website.scheme` | The URL scheme of a website asset, such as `http`. |
| `website.parent_asset.id` | The ID of the domain or subdomain asset that a website asset belongs to. |
| `website.parent_asset.name` | The name of the domain or subdomain asset that a website asset belongs to. |
| `whois.domain_status` | The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`. |
| `whois.name_servers` | The name servers listed in the WHOIS record, such as `ns1.acme.example`. |
| `whois.registrar` | The registrar the domain is registered through, as written in WHOIS (usually lower case). |
| `whois.registrant.organization` | The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service. |
| `whois.registrant.name` | The registrant's name in WHOIS; often a privacy placeholder such as `redacted for privacy`. |
| `whois.registrant.country` | The registrant's country in WHOIS, as a two-letter code in lower case such as `us`. |
| `whois.registrant.state` | The registrant's state or province in WHOIS. |
| `whois.registrant.city` | The registrant's city in WHOIS. |
| `whois.registrant.street` | The registrant's street address in WHOIS. |
| `whois.registrant.postal_code` | The registrant's postal code in WHOIS. |
| `whois.registrant.email` | The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead. |
| `whois.registrant.phone` | The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`. |
| `whois_registrant_email_historical` | Every registrant e-mail address seen for the domain over time, the current one included. |
| `whois_normalized.registrar` | The registrar reduced to a short normalized name, such as `godaddy` or `gandi`, so the same registrar matches across spellings. |
| `whois_normalized.registrant.email` | The registrant e-mail address after WHOIS normalization. |
| `whois_normalized.registrant.email_real` | Another normalized registrant e-mail field, set on fewer domains than `whois_normalized.registrant.email`; in the samples it is set only where `whois_privacy_enabled` is false, with the same address. |
| `whois_normalized.registrant.email_domain_apex` | The registrable domain of the registrant e-mail address: `acme.example` for `user@mail.acme.example`. |
| `whois_normalized.registrant.email_fqdn_apex` | The full host name after the `@` of the registrant e-mail address: `mail.acme.example` for `user@mail.acme.example`. |
| `whois_normalized.registrant.organization` | The registrant organization cleaned up across registrars: lower case, with spaces and punctuation removed, such as `domainsbyproxyllc`. |
| `whois_normalized.registrant.phone` | The registrant phone number reduced to its digits, such as `14805551234`. |
| `whois_last_change_data` | The WHOIS fields that changed in the last change seen, as field paths such as `whois.update_date` or `whois.domain_status`. |
| `dns.a.value` | The asset's current A records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.a.value_previous` | The asset's A records as they were before the last change, in the same text form as `dns.a.value`. |
| `dns.a.rcode` | The DNS response code returned for the asset's A lookup, such as `NOERROR`. |
| `dns.a.rcode_previous` | The DNS response code of the A lookup before it last changed. |
| `dns.a.ip_addresses.ip` | An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data. |
| `dns.a.ip_addresses.asn` | The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`. |
| `dns.a.ip_addresses.asn_cidr` | The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup. |
| `dns.a.ip_addresses.asn_description` | The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`. |
| `dns.a.ip_addresses.asn_country_code` | The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`. |
| `dns.a.ip_addresses.asn_registry` | The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`. |
| `dns.a.ip_addresses.entities` | The handles of the registry contacts and organizations linked to the network of the A-record address, such as `ACME-ARIN`. |
| `dns.a.ip_addresses.nir.nets.address` | The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.cidr` | The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation. |
| `dns.a.ip_addresses.nir.nets.contacts.admin.division` | The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.admin.email` | The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.admin.fax` | The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.admin.organization` | The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.admin.phone` | The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.admin.reply_email` | The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.admin.name` | The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.admin.title` | The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.tech.division` | The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.tech.email` | The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.tech.fax` | The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.tech.organization` | The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.tech.phone` | The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.tech.reply_email` | The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.tech.name` | The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.contacts.tech.title` | The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.country` | The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.handle` | The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.name` | The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.nameservers` | The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.postal_code` | The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.nets.range` | The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.nir.raw` | The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, when it is kept. |
| `dns.a.ip_addresses.nir.query` | The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address. |
| `dns.a.ip_addresses.query` | The IP address that was looked up in IP WHOIS (RDAP), that is the A-record address. |
| `dns.a.ip_addresses.raw` | The raw IP WHOIS response for the A-record address, when it is kept; empty on every sampled asset. |
| `dns.a.ip_addresses.network.cidr` | The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas. |
| `dns.a.ip_addresses.network.name` | The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`. |
| `dns.a.ip_addresses.network.country` | The country of the registered network that contains the A-record address, as a two-letter code such as `FR`. |
| `dns.a.ip_addresses.network.start_address` | The first address of the registered network block that contains the A-record address. |
| `dns.a.ip_addresses.network.end_address` | The last address of the registered network block that contains the A-record address. |
| `dns.a.ip_addresses.network.handle` | The registry handle of the network that contains the A-record address, such as `NET-192-0-2-0-1`. |
| `dns.a.ip_addresses.network.ip_version` | The IP version of the network that contains the A-record address: `v4` or `v6`. |
| `dns.a.ip_addresses.network.links` | Links to the registry record of the network that contains the A-record address, such as its RDAP and WHOIS URLs. |
| `dns.a.ip_addresses.network.parent_handle` | The handle of the larger network block from which the network of the A-record address was allocated. |
| `dns.a.ip_addresses.network.raw` | The raw RDAP network object for the A-record address, when it is kept. |
| `dns.a.ip_addresses.network.status` | The registry status of the network that contains the A-record address, such as `active`. |
| `dns.a.ip_addresses.network.type` | The registry's allocation type for the network that contains the A-record address, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`. |
| `dns.a.ip_addresses.network.notices.title` | The title of a notice the registry attached to the network record of the A-record address, such as `Terms of Service`. |
| `dns.a.ip_addresses.network.notices.description` | The text of a notice the registry attached to the network record of the A-record address. |
| `dns.a.ip_addresses.network.notices.links` | Links given in a notice on the network record of the A-record address. |
| `dns.a.ip_addresses.network.remarks.title` | The title of a remark on the network record of the A-record address, such as `Registration Comments`. |
| `dns.a.ip_addresses.network.remarks.description` | The text of a remark on the network record of the A-record address. |
| `dns.a.ip_addresses.network.remarks.links` | Links given in a remark on the network record of the A-record address. |
| `dns.a.ip_addresses.network.events.action` | An event in the history of the network record of the A-record address, such as `registration` or `last changed`. |
| `dns.a.ip_addresses.network.events.actor` | Who performed an event on the network record of the A-record address, when the registry names one. |
| `dns.a.ip_addresses.objects.uid` | The handle of a registry contact or organization (RDAP entity) linked to the network of the A-record address, such as `ACME-ARIN`. |
| `dns.a.ip_addresses.objects.contact.email.type` | The type of an e-mail address of a contact linked to the network of the A-record address, such as `abuse`. |
| `dns.a.ip_addresses.objects.contact.email.value` | An e-mail address of a contact linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.contact.address.type` | The type of a postal address of a contact linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.contact.address.value` | A postal address of a contact linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.contact.phone.type` | The type of a phone number of a contact linked to the network of the A-record address, such as `voice` or `work`. |
| `dns.a.ip_addresses.objects.contact.phone.value` | A phone number of a contact linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.contact.kind` | What kind of contact is linked to the network of the A-record address: `org`, `group` or `individual`. |
| `dns.a.ip_addresses.objects.contact.name` | The name of a contact or organization linked to the network of the A-record address, such as `Abuse` or a company name. |
| `dns.a.ip_addresses.objects.contact.role` | The role given in the contact card of an entity linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.contact.title` | The title given in the contact card of an entity linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.entities` | Handles of further entities listed under a contact linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.events.action` | An event in the history of a contact record linked to the network of the A-record address, such as `registration` or `last changed`. |
| `dns.a.ip_addresses.objects.events.actor` | Who performed an event on a contact record linked to the network of the A-record address, when the registry names one. |
| `dns.a.ip_addresses.objects.events_actor` | Events in which a contact linked to the network of the A-record address is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record. |
| `dns.a.ip_addresses.objects.handle` | The registry handle of a contact or organization linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.links` | Links to the registry record of a contact linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.notices.title` | The title of a notice on a contact record linked to the network of the A-record address, such as `Terms of Service`. |
| `dns.a.ip_addresses.objects.notices.description` | The text of a notice on a contact record linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.notices.links` | Links given in a notice on a contact record linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.raw` | The raw RDAP object of a contact linked to the network of the A-record address, when it is kept. |
| `dns.a.ip_addresses.objects.remarks.title` | The title of a remark on a contact record linked to the network of the A-record address, such as `Registration Comments`. |
| `dns.a.ip_addresses.objects.remarks.description` | The text of a remark on a contact record linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.remarks.links` | Links given in a remark on a contact record linked to the network of the A-record address. |
| `dns.a.ip_addresses.objects.roles` | The roles of a contact for the network of the A-record address, such as `registrant`, `abuse` or `technical`. |
| `dns.a.ip_addresses.objects.status` | The registry status of a contact linked to the network of the A-record address, such as `validated`. |
| `dns.a.ip_history` | Every IPv4 address seen in the asset's A records over time, the current ones included. |
| `dns.aaaa.value` | The asset's current AAAA records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.aaaa.value_previous` | The asset's AAAA records as they were before the last change, in the same text form as `dns.aaaa.value`. |
| `dns.aaaa.rcode` | The DNS response code returned for the asset's AAAA lookup, such as `NOERROR`. |
| `dns.aaaa.rcode_previous` | The DNS response code of the AAAA lookup before it last changed. |
| `dns.aaaa.ip_addresses` | The IPv6 addresses in the asset's AAAA records. |
| `dns.caa.value` | The asset's current CAA records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.caa.value_previous` | The asset's CAA records as they were before the last change, in the same text form as `dns.caa.value`. |
| `dns.caa.rcode` | The DNS response code returned for the asset's CAA lookup, such as `NOERROR`. |
| `dns.caa.rcode_previous` | The DNS response code of the CAA lookup before it last changed. |
| `dns.caa.issue_fqdns` | The certificate authorities allowed to issue certificates for the name, from the CAA `issue` tags, such as `fernhill.example` or `kestrel.example`. |
| `dns.caa.issuewild_fqdns` | The certificate authorities allowed to issue wildcard certificates for the name, from the CAA `issuewild` tags. |
| `dns.caa.iodef_emails` | The e-mail addresses from the CAA `iodef` tags, where certificate authorities report requests that break the CAA policy. |
| `dns.cname.value` | The asset's current CNAME records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.cname.value_previous` | The asset's CNAME records as they were before the last change, in the same text form as `dns.cname.value`. |
| `dns.cname.rcode` | The DNS response code returned for the asset's CNAME lookup, such as `NOERROR`. |
| `dns.cname.rcode_previous` | The DNS response code of the CNAME lookup before it last changed. |
| `dns.cname.canonical_fqdns` | The host names the asset's CNAME records point to (the alias targets). |
| `dns.dnskey.value` | The asset's current DNSKEY records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.dnskey.value_previous` | The asset's DNSKEY records as they were before the last change, in the same text form as `dns.dnskey.value`. |
| `dns.dnskey.rcode` | The DNS response code returned for the asset's DNSKEY lookup, such as `NOERROR`. |
| `dns.dnskey.rcode_previous` | The DNS response code of the DNSKEY lookup before it last changed. |
| `dns.dnskey.records.public_key` | The public key of a DNSKEY record, Base64-encoded and split into space-separated groups as in the zone-file text. |
| `dns.ds.value` | The asset's current DS records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.ds.value_previous` | The asset's DS records as they were before the last change, in the same text form as `dns.ds.value`. |
| `dns.ds.rcode` | The DNS response code returned for the asset's DS lookup, such as `NOERROR`. |
| `dns.ds.rcode_previous` | The DNS response code of the DS lookup before it last changed. |
| `dns.ds.records.digest` | The digest of a DS record, the hash of the DNSKEY it refers to. |
| `dns.mx.value` | The asset's current MX records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.mx.value_previous` | The asset's MX records as they were before the last change, in the same text form as `dns.mx.value`. |
| `dns.mx.rcode` | The DNS response code returned for the asset's MX lookup, such as `NOERROR`. |
| `dns.mx.rcode_previous` | The DNS response code of the MX lookup before it last changed. |
| `dns.mx.mail_servers` | The mail server host names from the asset's MX records, such as `mail.acme.example`. |
| `dns.mx.domains` | The registrable domains of the asset's mail servers, such as `acme.example`. |
| `dns.ns.value` | The asset's current NS records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.ns.value_previous` | The asset's NS records as they were before the last change, in the same text form as `dns.ns.value`. |
| `dns.ns.rcode` | The DNS response code returned for the asset's NS lookup, such as `NOERROR`. |
| `dns.ns.rcode_previous` | The DNS response code of the NS lookup before it last changed. |
| `dns.ns.name_servers` | The name server host names from the asset's NS records, such as `ns1.acme.example`. |
| `dns.ns.domains` | The registrable domains of the asset's name servers, such as `acme.example`. |
| `dns.nsec.value` | The asset's current NSEC records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.nsec.value_previous` | The asset's NSEC records as they were before the last change, in the same text form as `dns.nsec.value`. |
| `dns.nsec.rcode` | The DNS response code returned for the asset's NSEC lookup, such as `NOERROR`. |
| `dns.nsec.rcode_previous` | The DNS response code of the NSEC lookup before it last changed. |
| `dns.nsec.records.next_domain` | The next name in the zone, from an NSEC record. |
| `dns.nsec.records.record_types` | The record types that exist at the name, from an NSEC record's type list, such as `A`, `NS` or `SOA`. |
| `dns.nsec3.value` | The asset's current NSEC3 records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.nsec3.value_previous` | The asset's NSEC3 records as they were before the last change, in the same text form as `dns.nsec3.value`. |
| `dns.nsec3.rcode` | The DNS response code returned for the asset's NSEC3 lookup, such as `NOERROR`. |
| `dns.nsec3.rcode_previous` | The DNS response code of the NSEC3 lookup before it last changed. |
| `dns.nsec3.records.next_domain_hashed` | The hashed next name in the zone, from an NSEC3 record. |
| `dns.nsec3.records.record_types` | The record types that exist at the name, from an NSEC3 record's type list, such as `A` or `MX`. |
| `dns.rrsig.value` | The asset's current RRSIG records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.rrsig.value_previous` | The asset's RRSIG records as they were before the last change, in the same text form as `dns.rrsig.value`. |
| `dns.rrsig.rcode` | The DNS response code returned for the asset's RRSIG lookup, such as `NOERROR`. |
| `dns.rrsig.rcode_previous` | The DNS response code of the RRSIG lookup before it last changed. |
| `dns.rrsig.type_covered` | The record type that an RRSIG signature covers, such as `A` or `SOA`. |
| `dns.rrsig.signature` | The signature data of an RRSIG record, Base64-encoded. |
| `dns.soa.value` | The asset's current SOA records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.soa.value_previous` | The asset's SOA records as they were before the last change, in the same text form as `dns.soa.value`. |
| `dns.soa.rcode` | The DNS response code returned for the asset's SOA lookup, such as `NOERROR`. |
| `dns.soa.rcode_previous` | The DNS response code of the SOA lookup before it last changed. |
| `dns.soa.mnames` | The MNAME of the SOA record: the primary name server of the zone, such as `ns1.acme.example`. |
| `dns.soa.rnames` | The RNAME of the SOA record, the zone administrator's mailbox in DNS form: `hostmaster.acme.example` stands for the mailbox `hostmaster` at `acme.example`. |
| `dns.soa.rname_emails` | The RNAME of the SOA record written as an e-mail address, such as `user@acme.example`. |
| `dns.srv.value` | The asset's current SRV records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.srv.value_previous` | The asset's SRV records as they were before the last change, in the same text form as `dns.srv.value`. |
| `dns.srv.rcode` | The DNS response code returned for the asset's SRV lookup, such as `NOERROR`. |
| `dns.srv.rcode_previous` | The DNS response code of the SRV lookup before it last changed. |
| `dns.srv.records.service` | The service named in an SRV record (the `_service` part of its name). |
| `dns.srv.records.protocol` | The protocol named in an SRV record (the `_proto` part of its name, such as TCP or UDP). |
| `dns.srv.records.target` | The host name an SRV record points to. |
| `dns.txt.value` | The asset's current TXT records as zone-file text (name, TTL, class, type and data), all records in one string. |
| `dns.txt.value_previous` | The asset's TXT records as they were before the last change, in the same text form as `dns.txt.value`. |
| `dns.txt.rcode` | The DNS response code returned for the asset's TXT lookup, such as `NOERROR`. |
| `dns.txt.rcode_previous` | The DNS response code of the TXT lookup before it last changed. |
| `dns.txt.values` | Each TXT record of the asset as its quoted text, such as `"v=spf1 include:_spf.acme.example ~all"`; the quotes are part of the value. |
| `dns.txt.spf_list.value` | The text of an SPF record (a TXT record that starts with `v=spf1`), quoted as in `dns.txt.values`. |
| `dns.txt.spf_list.allowed_domains` | The registrable domains that an SPF record refers to, such as `acme.example` for `include:_spf.acme.example`. |
| `dns.txt.spf_list.allowed_ips` | The IP addresses and ranges that an SPF record authorizes to send mail (its `ip4:` and `ip6:` entries). |
| `dns.txt.verifications.value` | The text of a site-verification TXT record, quoted as in `dns.txt.values`. |
| `dns.txt.verifications.domain` | The domain of the service a verification record is for, such as `acme.example`, `fernhill.example` or `kestrel.example`. |
| `dns.txt.verifications.name` | The name of a verification record, such as `site-verification` or `domain-verification`. |
| `dns_last_change_data` | The DNS fields that changed in the last change seen, as field paths such as `dns.soa.mnames`. |
| `ssl.target` | The host name that the asset's TLS certificate was collected from, normally the asset itself. |
| `ssl.serial_number` | The serial number of the asset's TLS certificate, as a decimal string. |
| `ssl.fingerprint.md5` | The MD5 fingerprint of the asset's TLS certificate, as lower-case hex. |
| `ssl.fingerprint.sha1` | The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex. |
| `ssl.fingerprint.sha256` | The SHA-256 fingerprint of the asset's TLS certificate, as lower-case hex; one fingerprint identifies one certificate. |
| `ssl.issuer.common_name` | The common name (CN) of the certificate authority that issued the asset's TLS certificate, such as `WE1` or `YE2`. |
| `ssl.issuer.country` | The country (C) of the certificate authority that issued the asset's TLS certificate, as a two-letter code such as `US`. |
| `ssl.issuer.state` | The state or province (ST) of the certificate authority that issued the asset's TLS certificate. |
| `ssl.issuer.locality` | The locality or city (L) of the certificate authority that issued the asset's TLS certificate. |
| `ssl.issuer.organization` | The organization (O) of the certificate authority that issued the asset's TLS certificate, such as `Let's Encrypt` or `Google Trust Services`. |
| `ssl.issuer.organizational_unit` | The organizational unit (OU) of the certificate authority that issued the asset's TLS certificate. |
| `ssl.issuer_dn` | The full distinguished name of the issuer of the asset's TLS certificate, as one string such as `CN=WE1,O=Google Trust Services,C=US`. |
| `ssl.subject.common_name` | The common name (CN) of the subject (holder) of the asset's TLS certificate, usually a host name such as `acme.example`. |
| `ssl.subject.country` | The country (C) of the subject (holder) of the asset's TLS certificate, as a two-letter code. |
| `ssl.subject.state` | The state or province (ST) of the subject (holder) of the asset's TLS certificate. |
| `ssl.subject.locality` | The locality or city (L) of the subject (holder) of the asset's TLS certificate. |
| `ssl.subject.organization` | The organization (O) of the subject (holder) of the asset's TLS certificate. |
| `ssl.subject.organizational_unit` | The organizational unit (OU) of the subject (holder) of the asset's TLS certificate. |
| `ssl.subject_dn` | The full distinguished name of the subject of the asset's TLS certificate, such as `CN=acme.example`; one that starts with `CN=*.` belongs to a wildcard certificate. |
| `ssl.signature.value` | The signature of the asset's TLS certificate, Base64-encoded. |
| `ssl.signature.invalid_reason` | Why certificate validation failed, such as a host name mismatch or `unable to get issuer certificate`. |
| `ssl.signature.algorithm.name` | The hash algorithm of the signature on the asset's TLS certificate, such as `sha256` or `sha384`. |
| `ssl.signature.algorithm.oid` | The object identifier (OID) of the signature algorithm, such as `1.2.840.113549.1.1.11` (SHA-256 with RSA) or `1.2.840.10045.4.3.2` (ECDSA with SHA-256). |
| `ssl.extensions.authority_key_id` | The Authority Key Identifier extension, which identifies the issuer's key, Base64-encoded. |
| `ssl.extensions.certificate_policies` | The policy OIDs in the Certificate Policies extension, such as `2.23.140.1.2.1` (domain validated). |
| `ssl.extensions.signed_certificate_timestamps.log_id` | The ID of the Certificate Transparency log that issued a signed certificate timestamp (SCT) for the certificate, Base64-encoded. |
| `ssl.extensions.signed_certificate_timestamps.signature` | The log's signature on a signed certificate timestamp, Base64-encoded. |
| `ssl.extensions.subject_alt_name.dns_names` | The host names in the certificate's Subject Alternative Name extension, including wildcard names such as `*.acme.example`. |
| `ssl.extensions.subject_key_id` | The Subject Key Identifier extension, which identifies the certificate's own key, Base64-encoded. |
| `ssl.subject_key_info.fingerprint.hash_algorithm` | The hash algorithm used for `ssl.subject_key_info.fingerprint.value`, such as `sha256` or `sha384`. |
| `ssl.subject_key_info.fingerprint.value` | A hex fingerprint recorded under the certificate's subject key information, made with the hash in `hash_algorithm`. In the samples it equals `ssl.fingerprint.sha256` when that hash is SHA-256. |
| `ssl.subject_key_info.key_algorithm.name` | The algorithm of the certificate's public key, such as `RSA` or `ECDSA`. |
| `ssl.version.name` | The X.509 version of the certificate, such as `v3`. |
| `ssl.version.value` | The X.509 version as encoded in the certificate, counted from zero: `2` means `v3`. |
| `ssl.tbs_fingerprint` | A SHA-256 fingerprint (hex) of the certificate's to-be-signed part, the certificate content without its signature. |
| `ssl.certificate` | The whole certificate, Base64-encoded (a PEM body without the header and footer lines). |
| `ssl.fqdn_list` | The host names the certificate covers, with the `*.` of wildcard names removed and duplicates merged, so `*.acme.example` and `acme.example` both give `acme.example`. |
| `ssl_last_change_data` | The certificate fields that changed in the last change seen, as field paths such as `ssl.validity.end_date`. |
| `http.requested_url` | The URL the HTTP check started from, such as `http://acme.example`. |
| `http.requested_domain` | The registrable domain of the URL the HTTP check started from. |
| `http.requested_fqdn` | The host name of the URL the HTTP check started from. |
| `http.final_url` | The URL the HTTP check ended on after following all redirects. |
| `http.final_domain` | The registrable domain the HTTP check ended on after redirects, such as `acme.example`. |
| `http.final_fqdn` | The host name the HTTP check ended on after redirects, such as `www.acme.example`. |
| `http.redirection_history.url` | A URL in the redirect chain of the HTTP check, listed in the order visited. |
| `http.headers.accept` | The `Accept` header, when it was returned in the HTTP check. It is normally a request header (the content types a client accepts), so it is rarely set. |
| `http.headers.accept_encoding` | The `Accept-Encoding` header, when it was returned in the HTTP check. It is normally a request header (the compression formats a client accepts), so it is rarely set. |
| `http.headers.accept_language` | The `Accept-Language` header, when it was returned in the HTTP check. It is normally a request header (the languages a client prefers), so it is rarely set. |
| `http.headers.access_control_allow_credentials` | The `Access-Control-Allow-Credentials` header returned in the HTTP check; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS). |
| `http.headers.access_control_allow_headers` | The `Access-Control-Allow-Headers` header returned in the HTTP check; it lists the request headers allowed in cross-origin requests (CORS), for example `*`. |
| `http.headers.access_control_allow_methods` | The `Access-Control-Allow-Methods` header returned in the HTTP check; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`. |
| `http.headers.access_control_allow_origin` | The `Access-Control-Allow-Origin` header returned in the HTTP check; it names the origins allowed to read the response (CORS), where `*` allows any origin. |
| `http.headers.access_control_expose_headers` | The `Access-Control-Expose-Headers` header returned in the HTTP check; it lists the response headers that scripts from other origins may read (CORS). |
| `http.headers.access_control_max_age` | The `Access-Control-Max-Age` header returned in the HTTP check; it says how many seconds browsers may cache a CORS preflight result. |
| `http.headers.alt_svc` | The `Alt-Svc` header returned in the HTTP check; it advertises other protocols or ports that serve the site, for example `h3=":443"; ma=86400` for HTTP/3. |
| `http.headers.authorization` | The `Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to the server), so it is rarely set. |
| `http.headers.cache_control` | The `Cache-Control` header returned in the HTTP check; it sets the caching rules for the response, for example `no-cache, must-revalidate`. |
| `http.headers.clear_site_data` | The `Clear-Site-Data` header returned in the HTTP check; it tells browsers to clear stored data for the site, such as cookies, storage or cache. |
| `http.headers.content_disposition` | The `Content-Disposition` header returned in the HTTP check; it says whether the content is shown in the browser or downloaded as a file. |
| `http.headers.content_encoding` | The `Content-Encoding` header returned in the HTTP check; it names the compression applied to the response body, for example `gzip` or `br`. |
| `http.headers.content_language` | The `Content-Language` header returned in the HTTP check; it gives the language of the content, for example `en` or `tr`. |
| `http.headers.content_length` | The `Content-Length` header returned in the HTTP check; it gives the size of the response body in bytes. |
| `http.headers.content_range` | The `Content-Range` header returned in the HTTP check; it says which part of the full body a partial response holds. |
| `http.headers.content_security_policy` | The `Content-Security-Policy` header returned in the HTTP check; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from. |
| `http.headers.content_type` | The `Content-Type` header returned in the HTTP check; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`. |
| `http.headers.cookie` | The `Cookie` header, when it was returned in the HTTP check. It is normally a request header (the cookies a client sends), so it is rarely set. |
| `http.headers.cross_origin_embedder_policy` | The `Cross-Origin-Embedder-Policy` header returned in the HTTP check; it controls whether the page may embed cross-origin resources that do not explicitly allow it. |
| `http.headers.cross_origin_opener_policy` | The `Cross-Origin-Opener-Policy` header returned in the HTTP check; it controls whether the page shares its browsing context with cross-origin windows. |
| `http.headers.cross_origin_resource_policy` | The `Cross-Origin-Resource-Policy` header returned in the HTTP check; it controls which sites may load the resource. |
| `http.headers.date` | The `Date` header returned in the HTTP check; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`. |
| `http.headers.early_data` | The `Early-Data` header, when it was returned in the HTTP check. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set. |
| `http.headers.expect_ct` | The `Expect-CT` header returned in the HTTP check; it is a deprecated header about Certificate Transparency enforcement. |
| `http.headers.expires` | The `Expires` header returned in the HTTP check; it gives the date after which the response counts as stale, in HTTP date format. |
| `http.headers.feature_policy` | The `Feature-Policy` header returned in the HTTP check; it is the older name of `Permissions-Policy` and limits the browser features the page may use. |
| `http.headers.host` | The `Host` header, when it was returned in the HTTP check. It is normally a request header (the host name a client asks for), so it is rarely set. |
| `http.headers.if_modified_since` | The `If-Modified-Since` header, when it was returned in the HTTP check. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set. |
| `http.headers.if_none_match` | The `If-None-Match` header, when it was returned in the HTTP check. It is normally a request header (a condition based on an ETag), so it is rarely set. |
| `http.headers.last_modified` | The `Last-Modified` header returned in the HTTP check; it gives the time the server says the resource last changed, in HTTP date format. |
| `http.headers.origin_isolation` | The `Origin-Isolation` header returned in the HTTP check; it is an experimental header that asks browsers to isolate the site's origin. |
| `http.headers.others.name` | The name of a header returned in the HTTP check that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`. |
| `http.headers.others.value` | The value of a header listed in `headers.others` for the HTTP check. |
| `http.headers.permission_policy` | The `Permission-Policy` header returned in the HTTP check; it is recorded under this singular spelling, separately from `Permissions-Policy`. |
| `http.headers.permissions_policy` | The `Permissions-Policy` header returned in the HTTP check; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`. |
| `http.headers.pragma` | The `Pragma` header returned in the HTTP check; it is an older HTTP/1.0 caching header, for example `no-cache`. |
| `http.headers.proxy_authenticate` | The `Proxy-Authenticate` header returned in the HTTP check; it tells a client how to authenticate to a proxy. |
| `http.headers.proxy_authorization` | The `Proxy-Authorization` header, when it was returned in the HTTP check. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set. |
| `http.headers.public_key_pins` | The `Public-Key-Pins` header returned in the HTTP check; it is a deprecated header (HPKP) that pinned the site's public keys. |
| `http.headers.range` | The `Range` header, when it was returned in the HTTP check. It is normally a request header (a request for only part of a resource), so it is rarely set. |
| `http.headers.referer` | The `Referer` header, when it was returned in the HTTP check. It is normally a request header (the address of the page a request came from), so it is rarely set. |
| `http.headers.referrer_policy` | The `Referrer-Policy` header returned in the HTTP check; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`. |
| `http.headers.sec_fetch_dest` | The `Sec-Fetch-Dest` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the response will be used), so it is rarely set. |
| `http.headers.sec_fetch_mode` | The `Sec-Fetch-Mode` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on the request mode), so it is rarely set. |
| `http.headers.sec_fetch_site` | The `Sec-Fetch-Site` header, when it was returned in the HTTP check. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set. |
| `http.headers.sec_fetch_user` | The `Sec-Fetch-User` header, when it was returned in the HTTP check. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set. |
| `http.headers.server` | The `Server` header returned in the HTTP check; it names the server software the site reports, for example `nginx` or `Apache`. |
| `http.headers.set_cookie` | The `Set-Cookie` header returned in the HTTP check; it sets cookies, with their attributes. |
| `http.headers.strict_transport_security` | The `Strict-Transport-Security` header returned in the HTTP check; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`. |
| `http.headers.te` | The `TE` header, when it was returned in the HTTP check. It is normally a request header (the transfer encodings a client accepts), so it is rarely set. |
| `http.headers.transfer_encoding` | The `Transfer-Encoding` header returned in the HTTP check; it says how the body is transferred, for example `chunked`. |
| `http.headers.upgrade` | The `Upgrade` header returned in the HTTP check; it offers or asks for a switch to another protocol. |
| `http.headers.user_agent` | The `User-Agent` header, when it was returned in the HTTP check. It is normally a request header (the client software), so it is rarely set. |
| `http.headers.vary` | The `Vary` header returned in the HTTP check; it tells caches which request headers change the response, for example `Accept-Encoding`. |
| `http.headers.www_authenticate` | The `WWW-Authenticate` header returned in the HTTP check; it tells a client how to authenticate, usually with a `401` response. |
| `http.headers.x_content_type_options` | The `X-Content-Type-Options` header returned in the HTTP check; it stops browsers from guessing the content type when set to `nosniff`. |
| `http.headers.x_download_options` | The `X-Download-Options` header returned in the HTTP check; it stops Internet Explorer from opening downloads directly when set to `noopen`. |
| `http.headers.x_frame_options` | The `X-Frame-Options` header returned in the HTTP check; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`. |
| `http.headers.x_permitted_cross_domain_policies` | The `X-Permitted-Cross-Domain-Policies` header returned in the HTTP check; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files. |
| `http.headers.x_powered_by` | The `X-Powered-By` header returned in the HTTP check; it names the technology the server reports running on, for example `Express`. |
| `http.headers.x_xss_protection` | The `X-XSS-Protection` header returned in the HTTP check; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`. |
| `http.cookies.name` | The name of a cookie set in the HTTP check. |
| `http.cookies.value` | The value of a cookie set in the HTTP check. |
| `http.html.source_code_hash` | A SHA-256 hash of the page source returned in the HTTP check; the same hash means the same source. |
| `http_last_change_data` | The HTTP check fields that changed in the last change seen, as field paths such as `http.html.source_code_hash`. |
| `webdata.requested_url` | The URL the web data scan started from, such as `http://acme.example`. |
| `webdata.requested_domain` | The registrable domain of the URL the web data scan started from. |
| `webdata.requested_fqdn` | The host name of the URL the web data scan started from. |
| `webdata.html.internal_links_fqdns` | The host names of links on the scanned page that stay within the site's own domain, such as other subdomains. |
| `webdata.html.external_links_domains` | The registrable domains of links on the scanned page that point to other domains, such as `kestrel.example`. |
| `webdata.html.external_links_fqdns` | The host names of links on the scanned page that point to other domains, such as `www.kestrel.example`. |
| `webdata.html.external_links` | The full URLs of links on the scanned page that point to other domains. |
| `webdata.html.script_links` | The URLs of the scripts the scanned page loads. |
| `webdata.html.iframe_links` | The URLs of the frames (iframes) embedded in the scanned page. |
| `webdata.html.trackers.name` | The name of an analytics or advertising tracker found on the scanned page, such as `google_adsense` or `google_tag_manager`. |
| `webdata.html.trackers.values` | The IDs found for a tracker, such as a Google Analytics ID that starts with `G-` or `UA-`. |
| `webdata.html.emails` | The e-mail addresses found on the scanned page. |
| `webdata.html.emails_internal` | The e-mail addresses found on the scanned page that belong to the site's own domain. |
| `webdata.html.source_code_hash` | A SHA-256 hash of the page source in the web data scan; the same hash means the same source. |
| `webdata.html.content_hash` | A SHA-256 hash of the page content in the web data scan, kept apart from `source_code_hash`, the hash of the raw source. |
| `webdata.html.content_top_keywords` | The most frequent words in the text of the scanned page. |
| `webdata.html.favicon_links` | The URLs of the icons the scanned page declares, such as its favicon and touch icons. |
| `webdata.html.html_meta.name` | The site or application name declared in the scanned page's metadata. |
| `webdata.html.html_meta.description` | The meta description of the scanned page. |
| `webdata.html.html_meta.language` | The language the scanned page declares, such as `en`, `tr` or `en-US`. |
| `webdata.html.html_meta.language_alternatives` | The languages of the alternative versions the scanned page links to, such as `en` or `ar`. |
| `webdata.html.html_meta.keywords` | The keywords listed in the keywords meta tag of the scanned page. |
| `webdata.html.html_meta.encoding` | The character encoding the scanned page declares, such as `utf-8`. |
| `webdata.html.html_meta.canonical_url` | The canonical URL the scanned page declares. |
| `webdata.html.html_meta.title` | The title of the scanned page. |
| `webdata.favicon.url` | The URL of a site icon (favicon) recorded by the web data scan. |
| `webdata.favicon.hash` | A SHA-256 hash of a site icon; the same hash means the same icon. |
| `webdata.http.final_url` | The URL the web data scan ended on after following all redirects. |
| `webdata.http.final_domain` | The registrable domain the web data scan ended on after redirects, such as `acme.example`. |
| `webdata.http.final_fqdn` | The host name the web data scan ended on after redirects, such as `www.acme.example`. |
| `webdata.http.redirection_history.url` | A URL in the redirect chain of the web data scan, listed in the order visited. |
| `webdata.http.redirection_history.method` | How a step of the web data scan's redirect chain was made; `http-header` (a redirect sent in the HTTP response) is the value in the samples. |
| `webdata.http.headers.accept` | The `Accept` header, when it was returned in the web data scan. It is normally a request header (the content types a client accepts), so it is rarely set. |
| `webdata.http.headers.accept_encoding` | The `Accept-Encoding` header, when it was returned in the web data scan. It is normally a request header (the compression formats a client accepts), so it is rarely set. |
| `webdata.http.headers.accept_language` | The `Accept-Language` header, when it was returned in the web data scan. It is normally a request header (the languages a client prefers), so it is rarely set. |
| `webdata.http.headers.access_control_allow_credentials` | The `Access-Control-Allow-Credentials` header returned in the web data scan; it tells browsers whether cross-origin requests may carry credentials such as cookies (CORS). |
| `webdata.http.headers.access_control_allow_headers` | The `Access-Control-Allow-Headers` header returned in the web data scan; it lists the request headers allowed in cross-origin requests (CORS), for example `*`. |
| `webdata.http.headers.access_control_allow_methods` | The `Access-Control-Allow-Methods` header returned in the web data scan; it lists the HTTP methods allowed in cross-origin requests (CORS), for example `GET`. |
| `webdata.http.headers.access_control_allow_origin` | The `Access-Control-Allow-Origin` header returned in the web data scan; it names the origins allowed to read the response (CORS), where `*` allows any origin. |
| `webdata.http.headers.access_control_expose_headers` | The `Access-Control-Expose-Headers` header returned in the web data scan; it lists the response headers that scripts from other origins may read (CORS). |
| `webdata.http.headers.access_control_max_age` | The `Access-Control-Max-Age` header returned in the web data scan; it says how many seconds browsers may cache a CORS preflight result. |
| `webdata.http.headers.alt_svc` | The `Alt-Svc` header returned in the web data scan; it advertises other protocols or ports that serve the site, for example `h3=":443"; ma=86400` for HTTP/3. |
| `webdata.http.headers.authorization` | The `Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to the server), so it is rarely set. |
| `webdata.http.headers.cache_control` | The `Cache-Control` header returned in the web data scan; it sets the caching rules for the response, for example `no-cache, must-revalidate`. |
| `webdata.http.headers.clear_site_data` | The `Clear-Site-Data` header returned in the web data scan; it tells browsers to clear stored data for the site, such as cookies, storage or cache. |
| `webdata.http.headers.content_disposition` | The `Content-Disposition` header returned in the web data scan; it says whether the content is shown in the browser or downloaded as a file. |
| `webdata.http.headers.content_encoding` | The `Content-Encoding` header returned in the web data scan; it names the compression applied to the response body, for example `gzip` or `br`. |
| `webdata.http.headers.content_language` | The `Content-Language` header returned in the web data scan; it gives the language of the content, for example `en` or `tr`. |
| `webdata.http.headers.content_length` | The `Content-Length` header returned in the web data scan; it gives the size of the response body in bytes. |
| `webdata.http.headers.content_range` | The `Content-Range` header returned in the web data scan; it says which part of the full body a partial response holds. |
| `webdata.http.headers.content_security_policy` | The `Content-Security-Policy` header returned in the web data scan; it sets the Content Security Policy (CSP), which limits where the page may load scripts and other content from. |
| `webdata.http.headers.content_type` | The `Content-Type` header returned in the web data scan; it gives the media type and character set of the response body, for example `text/html; charset=utf-8`. |
| `webdata.http.headers.cookie` | The `Cookie` header, when it was returned in the web data scan. It is normally a request header (the cookies a client sends), so it is rarely set. |
| `webdata.http.headers.cross_origin_embedder_policy` | The `Cross-Origin-Embedder-Policy` header returned in the web data scan; it controls whether the page may embed cross-origin resources that do not explicitly allow it. |
| `webdata.http.headers.cross_origin_opener_policy` | The `Cross-Origin-Opener-Policy` header returned in the web data scan; it controls whether the page shares its browsing context with cross-origin windows. |
| `webdata.http.headers.cross_origin_resource_policy` | The `Cross-Origin-Resource-Policy` header returned in the web data scan; it controls which sites may load the resource. |
| `webdata.http.headers.date` | The `Date` header returned in the web data scan; it gives the time the server generated the response, in HTTP date format, for example `Sun, 01 Jun 2025 08:00:00 GMT`. |
| `webdata.http.headers.early_data` | The `Early-Data` header, when it was returned in the web data scan. It is normally a request header (a marker that a request was sent in TLS early data), so it is rarely set. |
| `webdata.http.headers.expect_ct` | The `Expect-CT` header returned in the web data scan; it is a deprecated header about Certificate Transparency enforcement. |
| `webdata.http.headers.expires` | The `Expires` header returned in the web data scan; it gives the date after which the response counts as stale, in HTTP date format. |
| `webdata.http.headers.feature_policy` | The `Feature-Policy` header returned in the web data scan; it is the older name of `Permissions-Policy` and limits the browser features the page may use. |
| `webdata.http.headers.host` | The `Host` header, when it was returned in the web data scan. It is normally a request header (the host name a client asks for), so it is rarely set. |
| `webdata.http.headers.if_modified_since` | The `If-Modified-Since` header, when it was returned in the web data scan. It is normally a request header (a condition to send the content only if it changed after a date), so it is rarely set. |
| `webdata.http.headers.if_none_match` | The `If-None-Match` header, when it was returned in the web data scan. It is normally a request header (a condition based on an ETag), so it is rarely set. |
| `webdata.http.headers.last_modified` | The `Last-Modified` header returned in the web data scan; it gives the time the server says the resource last changed, in HTTP date format. |
| `webdata.http.headers.origin_isolation` | The `Origin-Isolation` header returned in the web data scan; it is an experimental header that asks browsers to isolate the site's origin. |
| `webdata.http.headers.others.name` | The name of a header returned in the web data scan that has no field of its own under `headers`, in lower case such as `etag` or `cf-cache-status`. |
| `webdata.http.headers.others.value` | The value of a header listed in `headers.others` for the web data scan. |
| `webdata.http.headers.permission_policy` | The `Permission-Policy` header returned in the web data scan; it is recorded under this singular spelling, separately from `Permissions-Policy`. |
| `webdata.http.headers.permissions_policy` | The `Permissions-Policy` header returned in the web data scan; it limits the browser features the page may use, for example `camera=(), microphone=(), geolocation=()`. |
| `webdata.http.headers.pragma` | The `Pragma` header returned in the web data scan; it is an older HTTP/1.0 caching header, for example `no-cache`. |
| `webdata.http.headers.proxy_authenticate` | The `Proxy-Authenticate` header returned in the web data scan; it tells a client how to authenticate to a proxy. |
| `webdata.http.headers.proxy_authorization` | The `Proxy-Authorization` header, when it was returned in the web data scan. It is normally a request header (the credentials a client sends to a proxy), so it is rarely set. |
| `webdata.http.headers.public_key_pins` | The `Public-Key-Pins` header returned in the web data scan; it is a deprecated header (HPKP) that pinned the site's public keys. |
| `webdata.http.headers.range` | The `Range` header, when it was returned in the web data scan. It is normally a request header (a request for only part of a resource), so it is rarely set. |
| `webdata.http.headers.referer` | The `Referer` header, when it was returned in the web data scan. It is normally a request header (the address of the page a request came from), so it is rarely set. |
| `webdata.http.headers.referrer_policy` | The `Referrer-Policy` header returned in the web data scan; it sets how much referrer information browsers send when leaving the page, for example `strict-origin-when-cross-origin`. |
| `webdata.http.headers.sec_fetch_dest` | The `Sec-Fetch-Dest` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the response will be used), so it is rarely set. |
| `webdata.http.headers.sec_fetch_mode` | The `Sec-Fetch-Mode` header, when it was returned in the web data scan. It is normally a request header (browser metadata on the request mode), so it is rarely set. |
| `webdata.http.headers.sec_fetch_site` | The `Sec-Fetch-Site` header, when it was returned in the web data scan. It is normally a request header (browser metadata on how the requesting site relates to the target), so it is rarely set. |
| `webdata.http.headers.sec_fetch_user` | The `Sec-Fetch-User` header, when it was returned in the web data scan. It is normally a request header (browser metadata that marks a request started by the user), so it is rarely set. |
| `webdata.http.headers.server` | The `Server` header returned in the web data scan; it names the server software the site reports, for example `nginx` or `Apache`. |
| `webdata.http.headers.set_cookie` | The `Set-Cookie` header returned in the web data scan; it sets cookies, with their attributes. |
| `webdata.http.headers.strict_transport_security` | The `Strict-Transport-Security` header returned in the web data scan; it tells browsers to reach the site over HTTPS only (HSTS), for example `max-age=31536000; includeSubDomains; preload`. |
| `webdata.http.headers.te` | The `TE` header, when it was returned in the web data scan. It is normally a request header (the transfer encodings a client accepts), so it is rarely set. |
| `webdata.http.headers.transfer_encoding` | The `Transfer-Encoding` header returned in the web data scan; it says how the body is transferred, for example `chunked`. |
| `webdata.http.headers.upgrade` | The `Upgrade` header returned in the web data scan; it offers or asks for a switch to another protocol. |
| `webdata.http.headers.user_agent` | The `User-Agent` header, when it was returned in the web data scan. It is normally a request header (the client software), so it is rarely set. |
| `webdata.http.headers.vary` | The `Vary` header returned in the web data scan; it tells caches which request headers change the response, for example `Accept-Encoding`. |
| `webdata.http.headers.www_authenticate` | The `WWW-Authenticate` header returned in the web data scan; it tells a client how to authenticate, usually with a `401` response. |
| `webdata.http.headers.x_content_type_options` | The `X-Content-Type-Options` header returned in the web data scan; it stops browsers from guessing the content type when set to `nosniff`. |
| `webdata.http.headers.x_download_options` | The `X-Download-Options` header returned in the web data scan; it stops Internet Explorer from opening downloads directly when set to `noopen`. |
| `webdata.http.headers.x_frame_options` | The `X-Frame-Options` header returned in the web data scan; it says whether the page may be shown in a frame (a protection against clickjacking), for example `DENY` or `SAMEORIGIN`. |
| `webdata.http.headers.x_permitted_cross_domain_policies` | The `X-Permitted-Cross-Domain-Policies` header returned in the web data scan; it says whether Adobe clients such as Flash or Acrobat may load cross-domain policy files. |
| `webdata.http.headers.x_powered_by` | The `X-Powered-By` header returned in the web data scan; it names the technology the server reports running on, for example `Express`. |
| `webdata.http.headers.x_xss_protection` | The `X-XSS-Protection` header returned in the web data scan; it is an older setting for the browser's cross-site scripting filter, for example `1; mode=block` or `0`. |
| `webdata.http.cookies.name` | The name of a cookie set in the web data scan. |
| `webdata.http.cookies.value` | The value of a cookie set in the web data scan. |
| `webdata.http.cookies.domain` | The domain a cookie set in the web data scan applies to, such as `.acme.example`. |
| `webdata.http.cookies.path` | The path a cookie set in the web data scan applies to, such as `/`. |
| `webdata.http.cookies.same_party` | The SameParty attribute of a cookie set in the web data scan; in the samples it always holds the same value as `same_site`, such as `Lax` or `None`. |
| `webdata.http.cookies.priority` | The Priority attribute of a cookie set in the web data scan (`Low`, `Medium` or `High` in Chromium-based browsers). |
| `webdata.http.cookies.same_site` | The SameSite attribute of a cookie set in the web data scan, such as `Lax`, `Strict` or `None`. |
| `webdata.technology.stacks.slug` | A short identifier of a technology detected on the site, such as `iis` or `windows-server`. |
| `webdata.technology.stacks.name` | The name of a technology detected on the site, such as `IIS` or `Microsoft ASP.NET`. |
| `webdata.technology.stacks.icon` | The file name of a detected technology's icon, such as `acme.png`. |
| `webdata.technology.stacks.website` | The website of a detected technology's vendor or project. |
| `webdata.technology.stacks.cpe` | The CPE identifier of a detected technology, such as `cpe:/a:acme:acme-portal`, used to match it to known vulnerabilities. |
| `webdata.technology.stacks.version` | The detected version of a technology, such as `1.0`. |
| `webdata.technology.stacks.categories` | The categories of a detected technology, such as `Web servers` or `Operating systems`. |
| `webdata.technology.stacks.description` | A short description of a detected technology. |
| `webdata_last_change_data` | The web data fields that changed in the last change seen, as field paths under `webdata`. |
| `ipwhois.asn` | The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`. |
| `ipwhois.asn_cidr` | The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup. |
| `ipwhois.asn_description` | The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`. |
| `ipwhois.asn_country_code` | The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`. |
| `ipwhois.asn_registry` | The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`. |
| `ipwhois.entities` | The handles of the registry contacts and organizations linked to the network of the IP address asset, such as `ACME-ARIN`. |
| `ipwhois.nir.nets.address` | The postal address of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.cidr` | The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation. |
| `ipwhois.nir.nets.contacts.admin.division` | The division of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.admin.email` | The e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.admin.fax` | The fax number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.admin.organization` | The organization of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.admin.phone` | The phone number of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.admin.reply_email` | The reply e-mail address of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.admin.name` | The name of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.admin.title` | The job title of the administrative contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.tech.division` | The division of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.tech.email` | The e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.tech.fax` | The fax number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.tech.organization` | The organization of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.tech.phone` | The phone number of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.tech.reply_email` | The reply e-mail address of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.tech.name` | The name of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.contacts.tech.title` | The job title of the technical contact of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.country` | The country code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.handle` | The registry handle of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.name` | The name of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.nameservers` | The name servers listed for a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.postal_code` | The postal code of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.nets.range` | The address range (first and last address) of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.nir.raw` | The raw text of the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, when it is kept. |
| `ipwhois.nir.query` | The IP address sent in the query for the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset. |
| `ipwhois.query` | The IP address that was looked up in IP WHOIS (RDAP), that is the IP address asset. |
| `ipwhois.raw` | The raw IP WHOIS response for the IP address asset, when it is kept; empty on every sampled asset. |
| `ipwhois.network.cidr` | The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas. |
| `ipwhois.network.name` | The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`. |
| `ipwhois.network.country` | The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`. |
| `ipwhois.network.start_address` | The first address of the registered network block that contains the IP address asset. |
| `ipwhois.network.end_address` | The last address of the registered network block that contains the IP address asset. |
| `ipwhois.network.handle` | The registry handle of the network that contains the IP address asset, such as `NET-192-0-2-0-1`. |
| `ipwhois.network.ip_version` | The IP version of the network that contains the IP address asset: `v4` or `v6`. |
| `ipwhois.network.links` | Links to the registry record of the network that contains the IP address asset, such as its RDAP and WHOIS URLs. |
| `ipwhois.network.parent_handle` | The handle of the larger network block from which the network of the IP address asset was allocated. |
| `ipwhois.network.raw` | The raw RDAP network object for the IP address asset, when it is kept. |
| `ipwhois.network.status` | The registry status of the network that contains the IP address asset, such as `active`. |
| `ipwhois.network.type` | The registry's allocation type for the network that contains the IP address asset, such as `DIRECT ALLOCATION`, `ALLOCATION` or `ALLOCATED PA`. |
| `ipwhois.network.notices.title` | The title of a notice the registry attached to the network record of the IP address asset, such as `Terms of Service`. |
| `ipwhois.network.notices.description` | The text of a notice the registry attached to the network record of the IP address asset. |
| `ipwhois.network.notices.links` | Links given in a notice on the network record of the IP address asset. |
| `ipwhois.network.remarks.title` | The title of a remark on the network record of the IP address asset, such as `Registration Comments`. |
| `ipwhois.network.remarks.description` | The text of a remark on the network record of the IP address asset. |
| `ipwhois.network.remarks.links` | Links given in a remark on the network record of the IP address asset. |
| `ipwhois.network.events.action` | An event in the history of the network record of the IP address asset, such as `registration` or `last changed`. |
| `ipwhois.network.events.actor` | Who performed an event on the network record of the IP address asset, when the registry names one. |
| `ipwhois.objects.uid` | The handle of a registry contact or organization (RDAP entity) linked to the network of the IP address asset, such as `ACME-ARIN`. |
| `ipwhois.objects.contact.email.type` | The type of an e-mail address of a contact linked to the network of the IP address asset, such as `abuse`. |
| `ipwhois.objects.contact.email.value` | An e-mail address of a contact linked to the network of the IP address asset. |
| `ipwhois.objects.contact.address.type` | The type of a postal address of a contact linked to the network of the IP address asset. |
| `ipwhois.objects.contact.address.value` | A postal address of a contact linked to the network of the IP address asset. |
| `ipwhois.objects.contact.phone.type` | The type of a phone number of a contact linked to the network of the IP address asset, such as `voice` or `work`. |
| `ipwhois.objects.contact.phone.value` | A phone number of a contact linked to the network of the IP address asset. |
| `ipwhois.objects.contact.kind` | What kind of contact is linked to the network of the IP address asset: `org`, `group` or `individual`. |
| `ipwhois.objects.contact.name` | The name of a contact or organization linked to the network of the IP address asset, such as `Abuse` or a company name. |
| `ipwhois.objects.contact.role` | The role given in the contact card of an entity linked to the network of the IP address asset. |
| `ipwhois.objects.contact.title` | The title given in the contact card of an entity linked to the network of the IP address asset. |
| `ipwhois.objects.entities` | Handles of further entities listed under a contact linked to the network of the IP address asset. |
| `ipwhois.objects.events.action` | An event in the history of a contact record linked to the network of the IP address asset, such as `registration` or `last changed`. |
| `ipwhois.objects.events.actor` | Who performed an event on a contact record linked to the network of the IP address asset, when the registry names one. |
| `ipwhois.objects.events_actor` | Events in which a contact linked to the network of the IP address asset is itself the actor (the RDAP `asEventActor` list), as text; empty on every sampled record. |
| `ipwhois.objects.handle` | The registry handle of a contact or organization linked to the network of the IP address asset. |
| `ipwhois.objects.links` | Links to the registry record of a contact linked to the network of the IP address asset. |
| `ipwhois.objects.notices.title` | The title of a notice on a contact record linked to the network of the IP address asset, such as `Terms of Service`. |
| `ipwhois.objects.notices.description` | The text of a notice on a contact record linked to the network of the IP address asset. |
| `ipwhois.objects.notices.links` | Links given in a notice on a contact record linked to the network of the IP address asset. |
| `ipwhois.objects.raw` | The raw RDAP object of a contact linked to the network of the IP address asset, when it is kept. |
| `ipwhois.objects.remarks.title` | The title of a remark on a contact record linked to the network of the IP address asset, such as `Registration Comments`. |
| `ipwhois.objects.remarks.description` | The text of a remark on a contact record linked to the network of the IP address asset. |
| `ipwhois.objects.remarks.links` | Links given in a remark on a contact record linked to the network of the IP address asset. |
| `ipwhois.objects.roles` | The roles of a contact for the network of the IP address asset, such as `registrant`, `abuse` or `technical`. |
| `ipwhois.objects.status` | The registry status of a contact linked to the network of the IP address asset, such as `validated`. |
| `ipwhois_last_change_data` | The IP WHOIS fields that changed in the last change seen, as field paths under `ipwhois`. |
| `ipdns.ptr_records` | The PTR (reverse DNS) host names of an IP address asset. |
| `ipdns_last_change_data` | The reverse DNS fields that changed in the last change seen, as field paths under `ipdns`. |
| `issue_category_stats.name` | The name of an issue category in the per-category issue counts of the asset, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`. |
| `technology_count.by_category.name` | The name of a technology category in the per-category technology counts of the asset, such as `Web servers` or `Analytics`. |
| `domain_snapshot.issue_category_stats.name` | The name of an issue category in the per-category issue counts of the domain and its subdomains together, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois` or `Network`. Set on domain assets. |
| `domain_snapshot.technology_count.by_category.name` | The name of a technology category in the per-category technology counts of the domain and its subdomains together, such as `Web servers` or `Analytics`. Set on domain assets. |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `added_date` | When the asset was added to your inventory (UTC date-time). |
| `latest_scan_date` | When the asset was last scanned, shown as the last check date in Inventory (UTC date-time). |
| `seems_inactive_first_seen` | When the asset was first found to seem inactive (UTC date-time). |
| `seems_inactive_last_seen` | When the asset was most recently found to seem inactive (UTC date-time). |
| `login_page_probability` | The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true. |
| `fqdn.name.length` | The number of characters in the name without the extension: `4` for `acme.example`. |
| `website.port` | The port of a website asset, such as `443`. |
| `whois.create_date` | When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time). |
| `whois.update_date` | When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time). |
| `whois.expiry_date` | When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time). |
| `whois_create_date_historical` | Every creation date seen for the domain over time, so a domain that was deleted and registered again keeps its earlier dates too (UTC date-times). |
| `whois_check_date` | When the WHOIS record of the asset was last checked (UTC date-time). |
| `whois_last_change_date` | When a change in the WHOIS record of the asset was last seen (UTC date-time). |
| `dns.a.value_last_change_date` | When the A record text (`dns.a.value`) last changed (UTC date-time). |
| `dns.a.rcode_last_change_date` | When the response code of the A lookup (`dns.a.rcode`) last changed (UTC date-time). |
| `dns.a.last_change_date` | When the asset's A records last changed, in their text or their response code (UTC date-time). |
| `dns.a.ip_addresses.asn_date` | The registry allocation date that the ASN lookup reports for the A-record address, as a date at midnight UTC. |
| `dns.a.ip_addresses.nir.nets.contacts.admin.updated` | When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time). |
| `dns.a.ip_addresses.nir.nets.contacts.tech.updated` | When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address (UTC date-time). |
| `dns.a.ip_addresses.nir.nets.created` | When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was created (UTC date-time). |
| `dns.a.ip_addresses.nir.nets.updated` | When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address was last updated (UTC date-time). |
| `dns.a.ip_addresses.network.events.timestamp` | When an event on the network record of the A-record address happened (UTC date-time). |
| `dns.a.ip_addresses.objects.events.timestamp` | When an event on a contact record linked to the network of the A-record address happened (UTC date-time). |
| `dns.aaaa.value_last_change_date` | When the AAAA record text (`dns.aaaa.value`) last changed (UTC date-time). |
| `dns.aaaa.rcode_last_change_date` | When the response code of the AAAA lookup (`dns.aaaa.rcode`) last changed (UTC date-time). |
| `dns.aaaa.last_change_date` | When the asset's AAAA records last changed, in their text or their response code (UTC date-time). |
| `dns.caa.value_last_change_date` | When the CAA record text (`dns.caa.value`) last changed (UTC date-time). |
| `dns.caa.rcode_last_change_date` | When the response code of the CAA lookup (`dns.caa.rcode`) last changed (UTC date-time). |
| `dns.caa.last_change_date` | When the asset's CAA records last changed, in their text or their response code (UTC date-time). |
| `dns.cname.value_last_change_date` | When the CNAME record text (`dns.cname.value`) last changed (UTC date-time). |
| `dns.cname.rcode_last_change_date` | When the response code of the CNAME lookup (`dns.cname.rcode`) last changed (UTC date-time). |
| `dns.cname.last_change_date` | When the asset's CNAME records last changed, in their text or their response code (UTC date-time). |
| `dns.dnskey.value_last_change_date` | When the DNSKEY record text (`dns.dnskey.value`) last changed (UTC date-time). |
| `dns.dnskey.rcode_last_change_date` | When the response code of the DNSKEY lookup (`dns.dnskey.rcode`) last changed (UTC date-time). |
| `dns.dnskey.last_change_date` | When the asset's DNSKEY records last changed, in their text or their response code (UTC date-time). |
| `dns.ds.value_last_change_date` | When the DS record text (`dns.ds.value`) last changed (UTC date-time). |
| `dns.ds.rcode_last_change_date` | When the response code of the DS lookup (`dns.ds.rcode`) last changed (UTC date-time). |
| `dns.ds.last_change_date` | When the asset's DS records last changed, in their text or their response code (UTC date-time). |
| `dns.ds.records.key_tag` | The key tag (a number) of the DNSKEY that a DS record refers to. |
| `dns.mx.value_last_change_date` | When the MX record text (`dns.mx.value`) last changed (UTC date-time). |
| `dns.mx.rcode_last_change_date` | When the response code of the MX lookup (`dns.mx.rcode`) last changed (UTC date-time). |
| `dns.mx.last_change_date` | When the asset's MX records last changed, in their text or their response code (UTC date-time). |
| `dns.ns.value_last_change_date` | When the NS record text (`dns.ns.value`) last changed (UTC date-time). |
| `dns.ns.rcode_last_change_date` | When the response code of the NS lookup (`dns.ns.rcode`) last changed (UTC date-time). |
| `dns.ns.last_change_date` | When the asset's NS records last changed, in their text or their response code (UTC date-time). |
| `dns.nsec.value_last_change_date` | When the NSEC record text (`dns.nsec.value`) last changed (UTC date-time). |
| `dns.nsec.rcode_last_change_date` | When the response code of the NSEC lookup (`dns.nsec.rcode`) last changed (UTC date-time). |
| `dns.nsec.last_change_date` | When the asset's NSEC records last changed, in their text or their response code (UTC date-time). |
| `dns.nsec3.value_last_change_date` | When the NSEC3 record text (`dns.nsec3.value`) last changed (UTC date-time). |
| `dns.nsec3.rcode_last_change_date` | When the response code of the NSEC3 lookup (`dns.nsec3.rcode`) last changed (UTC date-time). |
| `dns.nsec3.last_change_date` | When the asset's NSEC3 records last changed, in their text or their response code (UTC date-time). |
| `dns.rrsig.value_last_change_date` | When the RRSIG record text (`dns.rrsig.value`) last changed (UTC date-time). |
| `dns.rrsig.rcode_last_change_date` | When the response code of the RRSIG lookup (`dns.rrsig.rcode`) last changed (UTC date-time). |
| `dns.rrsig.last_change_date` | When the asset's RRSIG records last changed, in their text or their response code (UTC date-time). |
| `dns.rrsig.signature_inception` | When an RRSIG signature becomes valid (UTC date-time). |
| `dns.rrsig.signature_expiration` | When an RRSIG signature expires (UTC date-time). |
| `dns.soa.value_last_change_date` | When the SOA record text (`dns.soa.value`) last changed (UTC date-time). |
| `dns.soa.rcode_last_change_date` | When the response code of the SOA lookup (`dns.soa.rcode`) last changed (UTC date-time). |
| `dns.soa.last_change_date` | When the asset's SOA records last changed, in their text or their response code (UTC date-time). |
| `dns.srv.value_last_change_date` | When the SRV record text (`dns.srv.value`) last changed (UTC date-time). |
| `dns.srv.rcode_last_change_date` | When the response code of the SRV lookup (`dns.srv.rcode`) last changed (UTC date-time). |
| `dns.srv.last_change_date` | When the asset's SRV records last changed, in their text or their response code (UTC date-time). |
| `dns.srv.records.port` | The port an SRV record points to. |
| `dns.txt.value_last_change_date` | When the TXT record text (`dns.txt.value`) last changed (UTC date-time). |
| `dns.txt.rcode_last_change_date` | When the response code of the TXT lookup (`dns.txt.rcode`) last changed (UTC date-time). |
| `dns.txt.last_change_date` | When the asset's TXT records last changed, in their text or their response code (UTC date-time). |
| `dns_check_date` | When the DNS records of the asset were last checked (UTC date-time). |
| `dns_last_change_date` | When a change in the DNS records of the asset was last seen (UTC date-time). |
| `ssl.port` | The port that the asset's TLS certificate was collected on, such as `443`. |
| `ssl.validity.start_date` | The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time. |
| `ssl.validity.end_date` | The date the asset's TLS certificate expires (Not After), as a UTC date-time. |
| `ssl.validity.length` | The validity period of the certificate in seconds: 7,776,000 seconds are 90 days. |
| `ssl.extensions.signed_certificate_timestamps.timestamp` | When a Certificate Transparency log recorded the certificate, from a signed certificate timestamp (UTC date-time). |
| `ssl.extensions.signed_certificate_timestamps.version` | The version of a signed certificate timestamp; `0` stands for version 1. |
| `ssl_check_date` | When the TLS certificate of the asset was last checked (UTC date-time). |
| `ssl_last_change_date` | When a change in the TLS certificate of the asset was last seen (UTC date-time). |
| `http.redirection_history.status_code` | The HTTP status code at a step of the redirect chain of the HTTP check, such as `301` or `200`. |
| `http.first_status_code` | The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`. |
| `http.final_status_code` | The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value. |
| `http_check_date` | When the HTTP check of the asset last ran (UTC date-time). |
| `http_last_change_date` | When a change in the HTTP check result of the asset was last seen (UTC date-time). |
| `webdata.http.redirection_history.status_code` | The HTTP status code at a step of the redirect chain of the web data scan, such as `301` or `200`. |
| `webdata.http.first_status_code` | The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`. |
| `webdata.http.final_status_code` | The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`. |
| `webdata.http.cookies.size` | The size of a cookie set in the web data scan, in bytes (name plus value). |
| `webdata.http.cookies.expires` | When a cookie set in the web data scan expires (UTC date-time); session cookies show `1969-12-31T23:59:59Z`. |
| `webdata.technology.stacks.confidence` | How certain the detection of a technology is, from 0 to 100; every sampled detection has `100`. |
| `webdata.technology.stacks.clean_version` | The major version of a detected technology as a whole number, such as `1` for version `1.0`. |
| `webdata_check_date` | When the web data scan of the asset, which collects the page content, headers and technologies, last ran (UTC date-time). |
| `webdata_last_change_date` | When a change in the web data of the asset was last seen (UTC date-time). |
| `ipwhois.asn_date` | The registry allocation date that the ASN lookup reports for the IP address asset, as a date at midnight UTC. |
| `ipwhois.nir.nets.contacts.admin.updated` | When the administrative contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time). |
| `ipwhois.nir.nets.contacts.tech.updated` | When the technical contact entry of a network block was last updated, in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset (UTC date-time). |
| `ipwhois.nir.nets.created` | When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was created (UTC date-time). |
| `ipwhois.nir.nets.updated` | When a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset was last updated (UTC date-time). |
| `ipwhois.network.events.timestamp` | When an event on the network record of the IP address asset happened (UTC date-time). |
| `ipwhois.objects.events.timestamp` | When an event on a contact record linked to the network of the IP address asset happened (UTC date-time). |
| `ipwhois_check_date` | When the IP WHOIS record of an IP address asset was last checked (UTC date-time). |
| `ipwhois_last_change_date` | When a change in the IP WHOIS record of an IP address asset was last seen (UTC date-time). |
| `ipdns_check_date` | When the reverse DNS (PTR) records of an IP address asset were last checked (UTC date-time). |
| `ipdns_last_change_date` | When a change in the reverse DNS (PTR) records of an IP address asset was last seen (UTC date-time). |
| `subdomain_count` | The number of subdomains of the domain in your inventory; set on domain assets. |
| `pointed_fqdn_count` | A count of host names (FQDNs) that point to the asset; no sampled asset had a value. |
| `redirected_domain_count` | The number of domain assets in your inventory whose HTTP check ends on this asset after redirects. |
| `redirected_asset_count` | The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects. |
| `average_issue_duration` | The average duration of the issues on the asset, in seconds. |
| `average_fix_duration` | The average time taken to fix the issues on the asset, in seconds. |
| `open_port_count` | The number of open ports found on the asset. |
| `open_ports` | The open port numbers found on the asset, such as `80`, `443` or `8080`. |
| `issue_state_stats.newly_detected` | The number of issues on the asset in the `newly_detected` state, an active state set by the platform. |
| `issue_state_stats.reappeared` | The number of issues on the asset in the `reappeared` state, an active state set by the platform. |
| `issue_state_stats.unresolved` | The number of issues on the asset in the `unresolved` state, an active state set by the platform. |
| `issue_state_stats.marked_as_resolved` | The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets. |
| `issue_state_stats.risk_accepted` | The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets. |
| `issue_state_stats.ignored` | The number of issues on the asset in the `ignored` state, an inactive state that a user sets. |
| `issue_state_stats.marked_as_false_positive` | The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets. |
| `issue_state_stats.not_applicable` | The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform. |
| `issue_state_stats.verified_resolved` | The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform. |
| `issue_category_stats.count` | The number of active issues in that category on the asset. |
| `issue_category_stats.severity_stats.critical` | The number of active issues of critical severity in that category on the asset. |
| `issue_category_stats.severity_stats.high` | The number of active issues of high severity in that category on the asset. |
| `issue_category_stats.severity_stats.medium` | The number of active issues of medium severity in that category on the asset. |
| `issue_category_stats.severity_stats.low` | The number of active issues of low severity in that category on the asset. |
| `issue_category_stats.severity_stats.information` | The number of active issues of information severity in that category on the asset. |
| `issue_count.total` | The number of issues on the asset in any state, active or inactive. |
| `issue_count.active` | The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state. |
| `issue_count.active_by_severity.critical` | The number of active issues of critical severity on the asset. |
| `issue_count.active_by_severity.high` | The number of active issues of high severity on the asset. |
| `issue_count.active_by_severity.medium` | The number of active issues of medium severity on the asset. |
| `issue_count.active_by_severity.low` | The number of active issues of low severity on the asset. |
| `issue_count.active_by_severity.information` | The number of active issues of information severity on the asset. |
| `technology_count.total` | The number of technologies detected on the asset. |
| `technology_count.by_category.count` | The number of technologies in that category on the asset. |
| `vulnerability_count.total` | The number of vulnerabilities (CVEs) found on the asset. |
| `vulnerability_count.by_severity.critical` | The number of vulnerabilities (CVEs) of critical severity on the asset. |
| `vulnerability_count.by_severity.high` | The number of vulnerabilities (CVEs) of high severity on the asset. |
| `vulnerability_count.by_severity.medium` | The number of vulnerabilities (CVEs) of medium severity on the asset. |
| `vulnerability_count.by_severity.low` | The number of vulnerabilities (CVEs) of low severity on the asset. |
| `vulnerability_count.by_severity.none` | The number of vulnerabilities (CVEs) on the asset whose severity is `none`. |
| `vulnerability_count.by_severity.unknown` | The number of vulnerabilities (CVEs) on the asset whose severity is `unknown`. |
| `security_score` | The asset's External Attack Surface Management (EASM) security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300. |
| `weight` | The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score. |
| `user_weight` | The weight you set for the asset, from 1 to 100; empty when you have not set one. |
| `system_weight` | The weight the platform calculates for the asset from many criteria; it can be above 100. |
| `domain_snapshot.average_issue_duration` | The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets. |
| `domain_snapshot.average_fix_duration` | The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets. |
| `domain_snapshot.open_port_count` | The number of open ports found on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.security_score` | The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets. |
| `domain_snapshot.issue_count.total` | The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets. |
| `domain_snapshot.issue_count.active` | The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets. |
| `domain_snapshot.issue_count.active_by_severity.critical` | The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_count.active_by_severity.high` | The number of active issues of high severity on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_count.active_by_severity.medium` | The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_count.active_by_severity.low` | The number of active issues of low severity on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_count.active_by_severity.information` | The number of active issues of information severity on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_category_stats.count` | The number of active issues in that category on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_category_stats.severity_stats.critical` | The number of active issues of critical severity in that category on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_category_stats.severity_stats.high` | The number of active issues of high severity in that category on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_category_stats.severity_stats.medium` | The number of active issues of medium severity in that category on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_category_stats.severity_stats.low` | The number of active issues of low severity in that category on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_category_stats.severity_stats.information` | The number of active issues of information severity in that category on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_state_stats.newly_detected` | The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets. |
| `domain_snapshot.issue_state_stats.reappeared` | The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets. |
| `domain_snapshot.issue_state_stats.unresolved` | The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets. |
| `domain_snapshot.issue_state_stats.marked_as_resolved` | The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets. |
| `domain_snapshot.issue_state_stats.risk_accepted` | The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets. |
| `domain_snapshot.issue_state_stats.ignored` | The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets. |
| `domain_snapshot.issue_state_stats.marked_as_false_positive` | The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets. |
| `domain_snapshot.issue_state_stats.not_applicable` | The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets. |
| `domain_snapshot.issue_state_stats.verified_resolved` | The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets. |
| `domain_snapshot.technology_count.total` | The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets. |
| `domain_snapshot.technology_count.by_category.count` | The number of distinct technologies in that category across the domain and its subdomains, each counted once. Set on domain assets. |
| `domain_snapshot.vulnerability_count.total` | The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.critical` | The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.high` | The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.medium` | The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.low` | The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.none` | The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.unknown` | The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `is_main_asset` | True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports. |
| `seems_inactive` | True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score. |
| `discovery_enabled` | True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it. |
| `dns_wildcard_active` | True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves. |
| `is_login_page` | True when the asset serves a login page; Inventory marks it with a login page icon. |
| `fqdn.is_idn` | True when the host name is an internationalized domain name (IDN) with non-ASCII characters. |
| `fqdn.name.contains_confusable` | True when the name contains confusable characters that look like other letters, such as Cyrillic `а` for Latin `a`, a common trick in look-alike domains. |
| `fqdn.name.contains_hyphen` | True when the name (without the extension) contains a hyphen. |
| `fqdn.name.contains_letter` | True when the name (without the extension) contains a letter. |
| `fqdn.name.contains_number` | True when the name (without the extension) contains a digit. |
| `fqdn.domain.is_idn` | True when the registrable domain is an internationalized domain name (IDN) with non-ASCII characters. |
| `whois_privacy_enabled` | True when the platform flagged WHOIS privacy protection on the domain's registrant details; set on domain assets. |
| `ssl.signature.is_valid` | True when the asset's TLS certificate passed validation for the host; when false, `ssl.signature.invalid_reason` says why. |
| `ssl.signature.is_valid_chain` | A flag for whether the certificate chain of the asset's TLS certificate is valid. It was true on every sampled certificate, even one whose validation failed with `unable to get issuer certificate`. |
| `ssl.signature.is_self_signed` | True when the asset's TLS certificate is self-signed, that is signed by its own key rather than by a certificate authority. |
| `ssl.extensions.basic_constraints.is_ca` | True when the certificate is a certificate authority (CA) certificate, from its Basic Constraints extension. |
| `ssl.extensions.extended_key_usage.client_auth` | True when the Extended Key Usage extension allows TLS client authentication. |
| `ssl.extensions.extended_key_usage.server_auth` | True when the Extended Key Usage extension allows TLS server authentication, as website certificates need. |
| `ssl.extensions.key_usage.content_commitment` | True when the Key Usage extension allows the certificate's key to be used for content commitment (non-repudiation). |
| `ssl.extensions.key_usage.crl_sign` | True when the Key Usage extension allows the certificate's key to be used for signing certificate revocation lists (CRL sign). |
| `ssl.extensions.key_usage.data_encipherment` | True when the Key Usage extension allows the certificate's key to be used for data encipherment. |
| `ssl.extensions.key_usage.digital_signature` | True when the Key Usage extension allows the certificate's key to be used for digital signatures. |
| `ssl.extensions.key_usage.key_agreement` | True when the Key Usage extension allows the certificate's key to be used for key agreement. |
| `ssl.extensions.key_usage.key_cert_sign` | True when the Key Usage extension allows the certificate's key to be used for signing other certificates (certificate sign). |
| `ssl.extensions.key_usage.key_encipherment` | True when the Key Usage extension allows the certificate's key to be used for key encipherment. |
| `ssl.has_expired` | True when the asset's TLS certificate is past its end date. |
| `http.external_domain_redirection` | True when the HTTP check ended on a different registrable domain than it started on. |
| `http.external_fqdn_redirection` | True when the HTTP check ended on a different host name than it started on, for example `acme.example` to `www.acme.example`. |
| `webdata.html.inspect_disabled` | A flag of the web data scan that marks pages whose inspection was disabled; it was `false` on every sampled asset. |
| `webdata.html.html_meta.no_index_status` | True when the scanned page asks search engines not to index it (a `noindex` robots directive). |
| `webdata.http.external_domain_redirection` | True when the web data scan ended on a different registrable domain than it started on. |
| `webdata.http.external_fqdn_redirection` | True when the web data scan ended on a different host name than it started on, for example `acme.example` to `www.acme.example`. |
| `webdata.http.cookies.secure` | True when a cookie set in the web data scan is sent over HTTPS only (Secure attribute). |
| `webdata.http.cookies.http_only` | True when scripts on the page cannot read a cookie set in the web data scan (HttpOnly attribute). |
| `webdata.http.cookies.session` | True when a cookie set in the web data scan is a session cookie, deleted when the browser closes. |
| `is_parked` | True when the asset is parked; Inventory marks it with a P badge whose tooltip shows where it redirects. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `asset_type` | The asset type: `domain`, `subdomain`, `ip` or `website`. |
| `creation_method` | How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval). |
| `fqdn.domain.extension_type` | The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`. |
| `dns.dnskey.records.key_type` | The role of a DNSKEY: `ZSK` (zone-signing key), `KSK` (key-signing key) or `KSK_REVOKED` (revoked key-signing key). |
| `dns.dnskey.records.algorithm` | The DNSSEC algorithm of a DNSKEY, such as `ECDSAP256SHA256` or `RSASHA256`. |
| `dns.ds.records.algorithm` | The DNSSEC algorithm of the key that a DS record refers to, such as `ECDSAP256SHA256` or `RSASHA256`. |
| `dns.ds.records.digest_type` | The hash used for a DS record's digest: `SHA1`, `SHA256`, `SHA384`, `GOST` or `NULL`. |
| `dns.rrsig.algorithm` | The DNSSEC algorithm of an RRSIG signature, such as `ECDSAP256SHA256` or `RSASHA256`. |

Operators: not measured

| Field | Description |
|---|---|
| `website.parent_asset.type` | The asset type of the website's parent asset, such as `subdomain`. |

### Sortable Fields

| Field | Description |
|---|---|
| `asset` | The asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. |
| `added_date` | When the asset was added to your inventory (UTC date-time). |
| `creation_method` | How the asset entered your inventory: `manually_added` (added directly), `manually_approved` (approved by someone in Discovery) or `auto_approved` (added by a discovery rule with auto approval). |
| `latest_scan_date` | When the asset was last scanned, shown as the last check date in Inventory (UTC date-time). |
| `is_main_asset` | True for an asset you set as a main asset, which the platform describes as the primary asset for all related assets, configurations and reports. |
| `seems_inactive` | True when the platform found no active DNS records or WHOIS information for the asset (for a subdomain: no DNS records). An inactive asset gets no security score. |
| `seems_inactive_first_seen` | When the asset was first found to seem inactive (UTC date-time). |
| `seems_inactive_last_seen` | When the asset was most recently found to seem inactive (UTC date-time). |
| `discovery_enabled` | True when discovery uses the asset as a starting point to find related assets; false when discovery no longer finds new assets through it. |
| `dns_wildcard_active` | True when the asset has an active wildcard DNS record (such as `*.acme.example`), so any subdomain name under it resolves. |
| `is_login_page` | True when the asset serves a login page; Inventory marks it with a login page icon. |
| `login_page_probability` | The login page detector's confidence, from 0 to 1, that the asset serves a login page. In the samples it is set only on assets where `is_login_page` is true. |
| `fqdn.unicode` | The asset's full host name (FQDN) in its readable Unicode form. |
| `fqdn.punycode` | The asset's full host name (FQDN) in its ASCII (punycode) form, as used in DNS; for names without special characters it equals `fqdn.unicode`. |
| `fqdn.domain.unicode` | The registrable domain the asset belongs to, in Unicode: `acme.example` for both `acme.example` and `www.acme.example`. |
| `fqdn.domain.punycode` | The registrable domain the asset belongs to, in its ASCII (punycode) form. |
| `fqdn.domain.extension.unicode` | The domain's extension, everything after the name, such as `com` or `co.uk`. |
| `fqdn.domain.extension_root.unicode` | The top-level part of the extension: `uk` for both `uk` and `co.uk`. |
| `fqdn.domain.extension_type` | The kind of extension: `gTLD` for generic extensions such as `com`, `ccTLD` for country-code extensions such as `de` or `co.uk`. |
| `website.port` | The port of a website asset, such as `443`. |
| `whois.create_date` | When the domain was registered (created), from the WHOIS record of a domain asset (UTC date-time). |
| `whois.update_date` | When the domain registration was last updated, from the WHOIS record of a domain asset (UTC date-time). |
| `whois.expiry_date` | When the domain registration expires, from the WHOIS record of a domain asset (UTC date-time). |
| `whois.domain_status` | The domain's EPP status codes from WHOIS, in lower case without spaces, such as `clienttransferprohibited`. |
| `whois.name_servers` | The name servers listed in the WHOIS record, such as `ns1.acme.example`. |
| `whois.registrar` | The registrar the domain is registered through, as written in WHOIS (usually lower case). |
| `whois.registrant.organization` | The registrant's organization in WHOIS; often a privacy placeholder such as `redacted for privacy` or a proxy service. |
| `whois.registrant.email` | The registrant's e-mail address in WHOIS; some registrars put a contact-form URL here instead. |
| `whois.registrant.phone` | The registrant's phone number in WHOIS, in the registry format such as `+1.4805551234`. |
| `dns.a.ip_addresses.ip` | An IPv4 address from the asset's A records (the A-record address); the other `dns.a.ip_addresses` fields hold its IP WHOIS (RDAP) data. |
| `dns.a.ip_addresses.asn` | The number of the autonomous system (ASN) that announces the A-record address, as a string such as `13335`. |
| `dns.a.ip_addresses.asn_cidr` | The routed prefix that contains the A-record address, in CIDR notation, from the ASN lookup. |
| `dns.a.ip_addresses.asn_description` | The name and holder of the autonomous system that announces the A-record address, such as `CLOUDFLARENET - Cloudflare, Inc., US`. |
| `dns.a.ip_addresses.asn_country_code` | The country of the autonomous system that announces the A-record address, as a two-letter code such as `US`. |
| `dns.a.ip_addresses.asn_registry` | The regional internet registry responsible for the A-record address, such as `arin` or `ripencc`. |
| `dns.a.ip_addresses.nir.nets.cidr` | The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the A-record address, in CIDR notation. |
| `dns.a.ip_addresses.network.cidr` | The registered network block that contains the A-record address, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas. |
| `dns.a.ip_addresses.network.name` | The name of the registered network that contains the A-record address, such as `CLOUDFLARENET`. |
| `dns.a.ip_addresses.network.country` | The country of the registered network that contains the A-record address, as a two-letter code such as `FR`. |
| `dns.ns.name_servers` | The name server host names from the asset's NS records, such as `ns1.acme.example`. |
| `dns.mx.mail_servers` | The mail server host names from the asset's MX records, such as `mail.acme.example`. |
| `dns_last_change_date` | When a change in the DNS records of the asset was last seen (UTC date-time). |
| `ssl.serial_number` | The serial number of the asset's TLS certificate, as a decimal string. |
| `ssl.fingerprint.sha1` | The SHA-1 fingerprint of the asset's TLS certificate, as lower-case hex. |
| `ssl.subject.organization` | The organization (O) of the subject (holder) of the asset's TLS certificate. |
| `ssl.validity.start_date` | The date the asset's TLS certificate becomes valid (Not Before), as a UTC date-time. |
| `ssl.validity.end_date` | The date the asset's TLS certificate expires (Not After), as a UTC date-time. |
| `ssl_last_change_date` | When a change in the TLS certificate of the asset was last seen (UTC date-time). |
| `http.final_domain` | The registrable domain the HTTP check ended on after redirects, such as `acme.example`. |
| `http.final_fqdn` | The host name the HTTP check ended on after redirects, such as `www.acme.example`. |
| `http.first_status_code` | The HTTP status code of the first response in the HTTP check, such as `301` for a redirect or `200`. |
| `http.final_status_code` | The HTTP status code of the last response in the HTTP check, after redirects, such as `200`, `404` or `502`. Inventory's HTTP status column shows this value. |
| `http_last_change_date` | When a change in the HTTP check result of the asset was last seen (UTC date-time). |
| `webdata.http.final_domain` | The registrable domain the web data scan ended on after redirects, such as `acme.example`. |
| `webdata.http.final_fqdn` | The host name the web data scan ended on after redirects, such as `www.acme.example`. |
| `webdata.http.first_status_code` | The HTTP status code of the first response in the web data scan, such as `301` for a redirect or `200`. |
| `webdata.http.final_status_code` | The HTTP status code of the last response in the web data scan, after redirects, such as `200`, `404` or `502`. |
| `webdata_last_change_date` | When a change in the web data of the asset was last seen (UTC date-time). |
| `ipwhois.asn` | The number of the autonomous system (ASN) that announces the IP address asset, as a string such as `13335`. |
| `ipwhois.asn_cidr` | The routed prefix that contains the IP address asset, in CIDR notation, from the ASN lookup. |
| `ipwhois.asn_description` | The name and holder of the autonomous system that announces the IP address asset, such as `CLOUDFLARENET - Cloudflare, Inc., US`. |
| `ipwhois.asn_country_code` | The country of the autonomous system that announces the IP address asset, as a two-letter code such as `US`. |
| `ipwhois.asn_registry` | The regional internet registry responsible for the IP address asset, such as `arin` or `ripencc`. |
| `ipwhois.nir.nets.cidr` | The range of a network block in the NIR (national internet registry, such as JPNIC or KRNIC) record of the IP address asset, in CIDR notation. |
| `ipwhois.network.cidr` | The registered network block that contains the IP address asset, in CIDR notation, such as `192.0.2.0/24`; a network made of several blocks lists them separated by commas. |
| `ipwhois.network.name` | The name of the registered network that contains the IP address asset, such as `CLOUDFLARENET`. |
| `ipwhois.network.country` | The country of the registered network that contains the IP address asset, as a two-letter code such as `FR`. |
| `subdomain_count` | The number of subdomains of the domain in your inventory; set on domain assets. |
| `website_count` | The number of website assets (`host:port`) in your inventory that belong to this asset. |
| `pointed_fqdn_count` | A count of host names (FQDNs) that point to the asset; no sampled asset had a value. |
| `redirected_domain_count` | The number of domain assets in your inventory whose HTTP check ends on this asset after redirects. |
| `redirected_asset_count` | The number of assets of any type in your inventory whose HTTP check ends on this asset after redirects. |
| `open_port_count` | The number of open ports found on the asset. |
| `average_issue_duration` | The average duration of the issues on the asset, in seconds. |
| `average_fix_duration` | The average time taken to fix the issues on the asset, in seconds. |
| `issue_state_stats.newly_detected` | The number of issues on the asset in the `newly_detected` state, an active state set by the platform. |
| `issue_state_stats.reappeared` | The number of issues on the asset in the `reappeared` state, an active state set by the platform. |
| `issue_state_stats.unresolved` | The number of issues on the asset in the `unresolved` state, an active state set by the platform. |
| `issue_state_stats.marked_as_resolved` | The number of issues on the asset in the `marked_as_resolved` state, an inactive state that a user sets. |
| `issue_state_stats.risk_accepted` | The number of issues on the asset in the `risk_accepted` state, an inactive state that a user sets. |
| `issue_state_stats.ignored` | The number of issues on the asset in the `ignored` state, an inactive state that a user sets. |
| `issue_state_stats.marked_as_false_positive` | The number of issues on the asset in the `marked_as_false_positive` state, an inactive state that a user sets. |
| `issue_state_stats.not_applicable` | The number of issues on the asset in the `not_applicable` state, an inactive state set by the platform. |
| `issue_state_stats.verified_resolved` | The number of issues on the asset in the `verified_resolved` state, an inactive state set by the platform. |
| `issue_count.total` | The number of issues on the asset in any state, active or inactive. |
| `issue_count.active` | The number of active issues on the asset: those in the `newly_detected`, `unresolved` or `reappeared` state. |
| `issue_count.active_by_severity.critical` | The number of active issues of critical severity on the asset. |
| `issue_count.active_by_severity.high` | The number of active issues of high severity on the asset. |
| `issue_count.active_by_severity.medium` | The number of active issues of medium severity on the asset. |
| `technology_count.total` | The number of technologies detected on the asset. |
| `vulnerability_count.total` | The number of vulnerabilities (CVEs) found on the asset. |
| `vulnerability_count.by_severity.critical` | The number of vulnerabilities (CVEs) of critical severity on the asset. |
| `security_score` | The asset's EASM security score; higher is better. Grades: A from 800, B from 700, C from 600, D from 500, E from 400, F from 300, and no grade below 300. |
| `weight` | The asset's effective weight: your user weight if you set one, otherwise the system weight. It affects your organization's overall security score. |
| `user_weight` | The weight you set for the asset, from 1 to 100; empty when you have not set one. |
| `system_weight` | The weight the platform calculates for the asset from many criteria; it can be above 100. |
| `domain_snapshot.average_issue_duration` | The average duration of the issues on the domain and its subdomains together, in seconds. Set on domain assets. |
| `domain_snapshot.average_fix_duration` | The average time taken to fix the issues on the domain and its subdomains together, in seconds. Set on domain assets. |
| `domain_snapshot.open_port_count` | The number of open ports found on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.security_score` | The domain-level security score, which includes the impact of the domain's subdomains; it uses the same A to F bands as `security_score`. Set on domain assets. |
| `domain_snapshot.issue_count.total` | The number of issues on the domain and its subdomains together in any state, active or inactive. Set on domain assets. |
| `domain_snapshot.issue_count.active` | The number of active issues on the domain and its subdomains together: those in the `newly_detected`, `unresolved` or `reappeared` state. Set on domain assets. |
| `domain_snapshot.issue_count.active_by_severity.critical` | The number of active issues of critical severity on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_count.active_by_severity.high` | The number of active issues of high severity on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_count.active_by_severity.medium` | The number of active issues of medium severity on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_count.active_by_severity.low` | The number of active issues of low severity on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_count.active_by_severity.information` | The number of active issues of information severity on the domain and its subdomains together. Set on domain assets. |
| `domain_snapshot.issue_state_stats.newly_detected` | The number of issues on the domain and its subdomains together in the `newly_detected` state, an active state set by the platform. Set on domain assets. |
| `domain_snapshot.issue_state_stats.reappeared` | The number of issues on the domain and its subdomains together in the `reappeared` state, an active state set by the platform. Set on domain assets. |
| `domain_snapshot.issue_state_stats.unresolved` | The number of issues on the domain and its subdomains together in the `unresolved` state, an active state set by the platform. Set on domain assets. |
| `domain_snapshot.issue_state_stats.marked_as_resolved` | The number of issues on the domain and its subdomains together in the `marked_as_resolved` state, an inactive state that a user sets. Set on domain assets. |
| `domain_snapshot.issue_state_stats.risk_accepted` | The number of issues on the domain and its subdomains together in the `risk_accepted` state, an inactive state that a user sets. Set on domain assets. |
| `domain_snapshot.issue_state_stats.ignored` | The number of issues on the domain and its subdomains together in the `ignored` state, an inactive state that a user sets. Set on domain assets. |
| `domain_snapshot.issue_state_stats.marked_as_false_positive` | The number of issues on the domain and its subdomains together in the `marked_as_false_positive` state, an inactive state that a user sets. Set on domain assets. |
| `domain_snapshot.issue_state_stats.not_applicable` | The number of issues on the domain and its subdomains together in the `not_applicable` state, an inactive state set by the platform. Set on domain assets. |
| `domain_snapshot.issue_state_stats.verified_resolved` | The number of issues on the domain and its subdomains together in the `verified_resolved` state, an inactive state set by the platform. Set on domain assets. |
| `domain_snapshot.technology_count.total` | The number of distinct technologies detected across the domain and its subdomains, each counted once. Set on domain assets. |
| `domain_snapshot.vulnerability_count.total` | The number of vulnerabilities (CVEs) found across the domain and its subdomains, which in the samples is lower than the sum of their own counts. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.critical` | The number of vulnerabilities (CVEs) of critical severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.high` | The number of vulnerabilities (CVEs) of high severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.medium` | The number of vulnerabilities (CVEs) of medium severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.low` | The number of vulnerabilities (CVEs) of low severity across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.none` | The number of vulnerabilities (CVEs) whose severity is `none` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |
| `domain_snapshot.vulnerability_count.by_severity.unknown` | The number of vulnerabilities (CVEs) whose severity is `unknown` across the domain and its subdomains, counted like `domain_snapshot.vulnerability_count.total`. Set on domain assets. |

## Response Fields

| Field | Type |
|---|---|
| `asset_count` | integer |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `asset_count` | number |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/assets/search:set-weight?weight=100' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "acme.example"
      }
    ]
  }
}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "asset_count": 1
}
```

### 400 · Malformed JSON

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/assets/search:set-weight' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{"filters": '
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "details": [
    "Invalid JSON data."
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/assets/search:set-weight?weight=100' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "tags",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "fqdn.unicode",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "fqdn.punycode",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "fqdn.name.unicode",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "fqdn.name.latinized",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "fqdn.domain.unicode",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "fqdn.domain.punycode",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "fqdn.domain.extension.unicode",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "fqdn.domain.extension_root.unicode",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "added_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "latest_scan_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "seems_inactive_first_seen",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "seems_inactive_last_seen",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "login_page_probability",
        "type": "eq",
        "value": 0
      },
      {
        "name": "fqdn.name.length",
        "type": "eq",
        "value": 0
      },
      {
        "name": "website.port",
        "type": "eq",
        "value": 0
      },
      {
        "name": "whois.create_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "whois.update_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "whois.expiry_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "is_main_asset",
        "type": "eq",
        "value": true
      },
      {
        "name": "seems_inactive",
        "type": "eq",
        "value": true
      },
      {
        "name": "discovery_enabled",
        "type": "eq",
        "value": true
      },
      {
        "name": "dns_wildcard_active",
        "type": "eq",
        "value": true
      },
      {
        "name": "is_login_page",
        "type": "eq",
        "value": true
      },
      {
        "name": "fqdn.is_idn",
        "type": "eq",
        "value": true
      },
      {
        "name": "fqdn.name.contains_confusable",
        "type": "eq",
        "value": true
      },
      {
        "name": "fqdn.name.contains_hyphen",
        "type": "eq",
        "value": true
      },
      {
        "name": "fqdn.name.contains_letter",
        "type": "eq",
        "value": true
      },
      {
        "name": "fqdn.name.contains_number",
        "type": "eq",
        "value": true
      },
      {
        "name": "asset_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "creation_method",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "fqdn.domain.extension_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.dnskey.records.key_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.dnskey.records.algorithm",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.ds.records.algorithm",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.ds.records.digest_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "dns.rrsig.algorithm",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "asset",
      "order": "desc"
    }
  ]
}'
```
