Discovered Asset Search
https://api.deepinfo.com/v1/easm/discovery/assets/searchSearches discovered assets (candidates found by discovery rules) and their state.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
page_ | Optional | Min 25, max 100. Default 100.Example 25 |
page | Optional | Min 1, max 800. Default 1.Example 1 |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "state",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "asset",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith wildcard fuzzy contains_ contains_ exists
| Field | Description |
|---|---|
asset | The discovered asset's name: a domain, subdomain or IP address, or for a website asset host:port. |
discovery_ | The ID of a discovery rule that found the asset, a 32-character hex string; the Discovery page's rule name filter sends this ID. |
discovery_ | The seed value a rule started from when it found the asset, such as an IP address, a certificate fingerprint, a phone number or an organization name. |
organization_ | An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as redacted for privacy. |
Operators eq in gte lte exists
| Field | Description |
|---|---|
last_ | When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time). |
ignore_ | When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored. |
approve_ | When the asset was approved into your inventory (UTC date-time); empty unless it is approved. |
Operators eq in exists
| Field | Description |
|---|---|
asset_ | The discovered asset's type: domain, subdomain, ip or website. |
state | The review state: in_review (found by a rule, waiting for a decision), approved (added to your inventory) or ignored (dismissed; it stays out of your inventory). |
Sortable Fields
| Field | Description |
|---|---|
asset | The discovered asset's name: a domain, subdomain or IP address, or for a website asset host:port. |
state | The review state: in_review (found by a rule, waiting for a decision), approved (added to your inventory) or ignored (dismissed; it stays out of your inventory). |
discovery_ | The rule matches that found the asset, each with the rule ID, rule name, rule type (smart_discovery, smart_monitoring or custom), seed value and discovery date. |
last_ | When a rule last found the asset, shown as the discovery date in Discovery (UTC date-time). |
organization_ | An organization name recorded for the discovered asset; in the samples it is set only on some domains and holds WHOIS-style values such as redacted for privacy. |
ignore_ | When the asset was ignored in Discovery (UTC date-time); empty unless it is ignored. |
approve_ | When the asset was approved into your inventory (UTC date-time); empty unless it is approved. |
Response Fields
| Field | Type | Description |
|---|---|---|
page | integer | |
page_ | integer | |
result_ | integer | |
results | array of object | |
results[]. | string | |
results[]. | string | |
results[]. | string | |
results[]. | string | One of in_review, approved, ignored |
results[]. | string | One of domain, subdomain, ip, website |
results[]. | array of object | |
results[]. | string | date-time |
results[]. | string | |
results[]. | string | date-time |
results[]. | string | date-time |
Paginated. See Getting Started → Pagination.
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
page | number | 1 |
page_size | number | 25 |
result_count | number | 21 |
results | array< | |
results[]. | string | "00000000000000000000000ea4f90001" |
results[]. | string | "acme.example" |
results[]. | string | "acme.example" |
results[]. | string | "in_review" |
results[]. | string | "domain" |
results[]. | array< | |
results[]. | string | "00000000000000000000000e56420001" |
results[]. | string | "Main domains" |
results[]. | string | "smart_monitoring" |
results[]. | boolean | true |
results[]. | boolean | false |
results[]. | string | "acme.example" |
results[]. | null | |
results[]. | string | "2025-06-01T08:00:00Z" |
results[]. | string | "2025-06-01T08:00:00Z" |
results[]. | null | |
results[]. | null | |
results[]. | null |
Examples
Selecting one loads it into the request and response panels.