Skip to main content
One host result represents an IP address with current network attribution and summarized services. Dataset: hosts
Host queries can use every service field with the services. prefix. For example, use services.protocol:ssh instead of protocol:ssh. Browse the service field reference for those fields.
Host-prefixed service fields support positive matching and ordered comparisons. Negated (!=) and substring-regex (:~) service clauses are not available in host queries.
integer
Current numeric autonomous system number attributed to the host IP. Friendly label: ASN. Operators: : = != < <= > >=.
string
Current ISO 3166-1 alpha-2 country code attributed to the host IP. Operators: : = != =~ :~.
integer
Distinct TLS leaf certs over the host’s current services. Operators: : = != < <= > >=.
integer
Distinct domains over the host’s current services (shared-hosting/CDN signal). Operators: : = != < <= > >=.
integer
Distinct JA4S over the host’s current services (TLS-stack diversity). Friendly label: Distinct JA4S. Operators: : = != < <= > >=.
integer
Distinct HTTP server strings over the host’s current services. Operators: : = != < <= > >=.
timestamp
Earliest accepted observation timestamp for this host. Operators: : = != < <= > >=.
ip
IP address for the current host record. Operators: : = !=.
string
Current ISP or network organization name attributed to the host IP. Friendly label: ISP Name. Operators: : = != =~ :~.
timestamp
Most recent accepted observation timestamp for this host. Operators: : = != < <= > >=.
integer
Number of current services summarized on this host. Operators: : = != < <= > >=.
repeated integer
Distinct current service ports summarized on this host. Operators: : = != < <= > >=.
repeated string
Distinct current service protocols summarized on this host. Operators: : = != =~ :~.
repeated string
Distinct current service transports summarized on this host. Operators: : = != =~ :~.
string
Visible tag slug or name. Operators: : = !=.