hosts
Host queries can use every service field with the
services. prefix. For example, use services.protocol:ssh instead of protocol:ssh. Browse the service field reference for those fields.!=) and substring-regex (:~) service clauses are not available in host queries.
integer
Current numeric autonomous system number attributed to the host IP. Friendly label:
ASN. Operators: : = != < <= > >=.string
Current ISO 3166-1 alpha-2 country code attributed to the host IP. Operators:
: = != =~ :~.integer
Distinct TLS leaf certs over the host’s current services. Operators:
: = != < <= > >=.integer
Distinct domains over the host’s current services (shared-hosting/CDN signal). Operators:
: = != < <= > >=.integer
Distinct JA4S over the host’s current services (TLS-stack diversity). Friendly label:
Distinct JA4S. Operators: : = != < <= > >=.integer
Distinct HTTP server strings over the host’s current services. Operators:
: = != < <= > >=.timestamp
Earliest accepted observation timestamp for this host. Operators:
: = != < <= > >=.ip
IP address for the current host record. Operators:
: = !=.string
Current ISP or network organization name attributed to the host IP. Friendly label:
ISP Name. Operators: : = != =~ :~.timestamp
Most recent accepted observation timestamp for this host. Operators:
: = != < <= > >=.integer
Number of current services summarized on this host. Operators:
: = != < <= > >=.repeated integer
Distinct current service ports summarized on this host. Operators:
: = != < <= > >=.repeated string
Distinct current service protocols summarized on this host. Operators:
: = != =~ :~.repeated string
Distinct current service transports summarized on this host. Operators:
: = != =~ :~.string
Visible tag slug or name. Operators:
: = !=.