Skip to main content
Choose the result you want first, then use its field reference to build the query. Only fields available through the public search API appear here. A typed field browser with dataset and field groups

Hosts

IP attribution, exposure summaries, observation dates, tags, and nested service fields.

Services

Ports, protocols, banners, HTTP, TLS, fingerprints, and typed scan evidence.

DNS

Names, record types, answers, response codes, and observation dates.

OSINT

Reports, sources, publication dates, and associated IP indicators.

Dataset grain

Read a field entry

Each leaf field documents:
  • Its path and value type.
  • The operators accepted by InfraQL.
  • What the value means.
  • Whether the field can be grouped by the aggregate API.
Host queries prefix service fields with services.. Use same_service(...) when several conditions must match one endpoint.

Learn InfraQL

Compose queries, combine clauses, validate fields, and paginate results.

Follow an investigation

Start from an IP, DNS name, service hypothesis, indicator list, or result set.

Use the API

Browse request parameters, response schemas, and copyable examples.

Understand the taxonomy

See how tags, categories, and classifications fit together.