services
object
Show Fields
Show Fields
repeated string
Supported AFP version strings. Operators:
: = != =~ :~.repeated string
Optional directory service principal names. Operators:
: = != =~ :~.string
Server machine type string. Operators:
: = != =~ :~.string
Legacy server name from the status block. Operators:
: = != =~ :~.repeated string
Supported authentication methods. Operators:
: = != =~ :~.string
UTF-8 server name when advertised separately. Operators:
: = != =~ :~.object
Show Fields
Show Fields
repeated string
Authentication mechanisms. Operators:
: = != =~ :~.repeated string
Enabled capabilities. Operators:
: = != =~ :~.string
Cluster name. Operators:
: = != =~ :~.string
Copyright notice. Operators:
: = != =~ :~.string
Additional product information. Operators:
: = != =~ :~.repeated string
Locale preferences. Operators:
: = != =~ :~.string
Protocol version label. Operators:
: = != =~ :~.uint32
Protocol major version. Operators:
: = != < <= > >=.uint32
Protocol minor version. Operators:
: = != < <= > >=.string
Runtime platform. Operators:
: = != =~ :~.string
Software name. Operators:
: = != =~ :~.string
Software version. Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
Exact response returned by the Android remote mouse server probe. Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
Device build version when reported. Operators:
: = != =~ :~.string
Device class, for example iPhone or iPad. Operators:
: = != =~ :~.string
Device hardware product identifier, for example iPhone13,2. Operators:
: = != =~ :~.string
Device software version string, for example 17.4.1. Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
Destination/software identifier from the packet line. Operators:
: = != =~ :~.string
APRS-IS entry or igate callsign following the q-construct. Operators:
: = != =~ :~.string
Raw APRS information field after ’:’. Operators:
: = != =~ :~.string
q-construct value from the APRS-IS path, e.g. qAI. Operators:
: = != =~ :~.string
APRS gateway software banner, e.g. “udpgate 0.81”. Operators:
: = != =~ :~.string
Source callsign/SSID from the packet line. Operators:
: = != =~ :~.object
object
object
Show Fields
Show Fields
uint32
Height from resize(…). Operators:
: = != < <= > >=.uint32
Width from resize(…). Operators:
: = != < <= > >=.uint32
Total parsed command lines. Operators:
: = != < <= > >=.uint32
Object count from startDefinition(…), when present. Operators:
: = != < <= > >=.string
ProcessView protocol version from pvsVersion(…). Operators:
: = != =~ :~.repeated string
Distinct widget classes referenced in the definition, e.g. QLabel. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
BACnet APDU type from the primary response. Operators:
: = != < <= > >=.string
BACnet application software version. Operators:
: = != =~ :~.string
BACnet description. Operators:
: = != =~ :~.string
BACnet firmware version. Operators:
: = != =~ :~.uint32
BACnet device instance ID. Operators:
: = != < <= > >=.string
BACnet location. Operators:
: = != =~ :~.string
BACnet model name. Operators:
: = != =~ :~.string
BACnet object name. Operators:
: = != =~ :~.uint32
BACnet vendor ID. Operators:
: = != < <= > >=.string
BACnet vendor name. Operators:
: = != =~ :~.object
object
Show Fields
Show Fields
string
Initial banner keyword, typically “teamtalk” or “welcome”. Operators:
: = != =~ :~.uint32
Maximum allowed logins per IP. Operators:
: = != < <= > >=.uint32
Maximum allowed concurrent users. Operators:
: = != < <= > >=.string
TeamTalk protocol version string. Operators:
: = != =~ :~.string
Configured TeamTalk server name. Operators:
: = != =~ :~.uint32
Assigned user or session ID. Operators:
: = != < <= > >=.uint32
User timeout in seconds. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
string
MIME content type of the greeting payload. Operators:
: = != =~ :~.string
BEEP frame header as observed on the wire. Operators:
: = != =~ :~.string
BEEP frame verb from the greeting, e.g. RPY or MSG. Operators:
: = != =~ :~.repeated string
Advertised BEEP profile URIs. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Effective peer ASN (4-byte ASN capability preferred when present). Friendly label:
ASN. Operators: : = != < <= > >=.string
Reported BGP identifier. Operators:
: = != =~ :~.uint32
Reported hold timer in seconds. Operators:
: = != < <= > >=.string
BGP message type label observed in response. Operators:
: = != =~ :~.uint32
Notification code when NOTIFICATION was received. Operators:
: = != < <= > >=.uint32
Notification subcode when NOTIFICATION was received. Operators:
: = != < <= > >=.repeated uint32
Operators:
: = != < <= > >=.uint32
Reported BGP version when OPEN was received. Operators:
: = != < <= > >=.object
object
Show Fields
Show Fields
string
Network identifier derived from transport magic bytes. Operators:
: = != =~ :~.uint32
Reported Bitcoin protocol version. Operators:
: = != < <= > >=.string
Reported remote node time in RFC3339 format. Operators:
: = != =~ :~.uint32
Bitcoin transport version (1 legacy, 2 when BIP-324 support is signaled). Operators:
: = != < <= > >=.string
Reported node user agent string. Operators:
: = != =~ :~.object
object
Show Fields
Show Fields
BittorrentTrackerAnnounceOutcome
Outcome of the optional announce follow-up. Operators:
: = != =~ :~.string
Human-readable tracker error from an announce error packet. Operators:
: = != =~ :~.uint32
Announce interval in seconds when returned by the tracker. Operators:
: = != < <= > >=.uint32
Reported leecher count when returned by the tracker. Operators:
: = != < <= > >=.uint32
Reported seeder count when returned by the tracker. Operators:
: = != < <= > >=.object
object
object
object
Show Fields
Show Fields
ControlAckStyle
Control reply style returned by the responder. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Number of consecutive ICA signature blocks at the response start. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
string
RootDSE default naming context. Operators:
: = != =~ :~.string
RootDSE DNS host name. Operators:
: = != =~ :~.string
LDAP diagnostic message. Operators:
: = != =~ :~.uint32
LDAP message ID from the received packet. Operators:
: = != < <= > >=.repeated string
RootDSE naming contexts. Operators:
: = != =~ :~.bool
Whether a Netlogon attribute value was returned. Operators:
: = !=.uint32
Total size in bytes of returned Netlogon values. Operators:
: = != < <= > >=.uint32
LDAP result code when present. Operators:
: = != < <= > >=.string
LDAP result code label. Operators:
: = != =~ :~.string
RootDSE root domain naming context. Operators:
: = != =~ :~.repeated string
Supported LDAP extensions. Operators:
: = != =~ :~.repeated uint32
Supported LDAP versions. Operators:
: = != < <= > >=.repeated string
Supported SASL mechanisms. Operators:
: = != =~ :~.object
Show Fields
Show Fields
bool
True when the exception indicates authentication or access control is required. Operators:
: = !=.string
Optional display name from ServerHello. Operators:
: = != =~ :~.int32
Native exception code from ServerException. Operators:
: = != < <= > >=.string
Native exception message from ServerException. Operators:
: = != =~ :~.string
Native exception name from ServerException. Operators:
: = != =~ :~.ClickhouseResponseType
First server packet type observed after ClientHello. Operators:
: = != =~ :~.uint32
Native protocol revision from ServerHello. Operators:
: = != < <= > >=.string
Server name from ServerHello. Operators:
: = != =~ :~.string
Server timezone from ServerHello. Operators:
: = != =~ :~.uint32
Server major version from ServerHello. Operators:
: = != < <= > >=.uint32
Server minor version from ServerHello. Operators:
: = != < <= > >=.uint32
Server patch version when advertised by the server revision. Operators:
: = != < <= > >=.object
object
Show Fields
Show Fields
bool
Whether the response used Block2. Operators:
: = !=.uint32
Response content format when present. Operators:
: = != < <= > >=.string
Diagnostic payload text for error responses. Operators:
: = != =~ :~.uint32
Raw CoAP response code. Operators:
: = != < <= > >=.string
Human-readable response code label. Operators:
: = != =~ :~.bool
Whether discovery data was incomplete or truncated. Operators:
: = !=.object
Show Fields
Show Fields
repeated uint32
Declared content formats. Operators:
: = != < <= > >=.repeated string
Interface descriptions. Operators:
: = != =~ :~.bool
Whether the resource is observable. Operators:
: = !=.string
Resource path or URI reference. Operators:
: = != =~ :~.repeated string
Resource types. Operators:
: = != =~ :~.string
Resource title. Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
OS name string at offset 0x40 in the v2 discovery reply. Operators:
: = != =~ :~.string
OS type string at offset 0x60 in the v2 discovery reply. Operators:
: = != =~ :~.string
Product type string at offset 0x80 in the v2 discovery reply. Operators:
: = != =~ :~.string
Query variant that produced the response. Operators:
: = != =~ :~.object
object
object
object
object
Show Fields
Show Fields
bool
True when the endpoint requires authentication. Operators:
: = !=.repeated string
Authentication schemes offered in WWW-Authenticate headers. Operators:
: = != =~ :~.string
CWMP version inferred from the namespace URI. Operators:
: = != =~ :~.string
SOAP fault code when the endpoint returned a CWMP fault. Operators:
: = != =~ :~.string
SOAP fault string when the endpoint returned a CWMP fault. Operators:
: = != =~ :~.CwmpResponseType
Classification of the first protocol-specific response. Operators:
: = != =~ :~.object
object
object
Show Fields
Show Fields
object
Show Fields
Show Fields
bool
Whether bind succeeded. Operators:
: = !=.uint32
Number of endpoint count. Operators:
: = != < <= > >=.uint32
Status code from the final ept_lookup response. Operators:
: = != < <= > >=.string
Endpoint query status label. Operators:
: = != =~ :~.bool
Whether endpoint query succeeded. Operators:
: = !=.bool
Whether an LSA interface family (MS-LSAD or MS-LSAT) was observed. Operators:
: = !=.bool
Whether a Netlogon (MS-NRPC) interface was observed. Operators:
: = !=.bool
Whether a SAMR (MS-SAMR) interface was observed. Operators:
: = !=.bool
Whether a Server Service interface (MS-SRVS) was observed. Operators:
: = !=.uint32
Lookup rounds. Operators:
: = != < <= > >=.uint32
Number of collected named-pipe bindings across all endpoints. Operators:
: = != < <= > >=.uint32
Number of collected TCP/IP bindings across all endpoints. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
repeated string
Collected transport bindings for this interface. Operators:
: = != =~ :~.string
“<uuid> vX.Y …” label enriched with known interface names where possible. Operators:
: = != =~ :~.string
Interface UUID. Operators:
: = != =~ :~.uint32
Interface version major. Operators:
: = != < <= > >=.uint32
Interface version minor. Operators:
: = != < <= > >=.string
“[MS-XXX]: …” when protocol metadata is known. Operators:
: = != =~ :~.string
Server-side binary / component hint (usually annotation from EPM). Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
Remote implementation class UID from user information negotiation. Operators:
: = != =~ :~.string
Remote implementation version name when advertised. Operators:
: = != =~ :~.uint32
Maximum PDU length the acceptor reports it can receive. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
string
Abstract syntax UID offered for the presentation context. Operators:
: = != =~ :~.uint32
Presentation context identifier from the association response. Operators:
: = != < <= > >=.uint32
Result/reason code from the association response. Operators:
: = != < <= > >=.string
Human-readable result/reason label. Operators:
: = != =~ :~.string
Accepted transfer syntax UID when the presentation context is accepted. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Rejection diagnostic code. Operators:
: = != < <= > >=.string
Human-readable rejection diagnostic label. Operators:
: = != =~ :~.uint32
Association rejection result code. Operators:
: = != < <= > >=.string
Human-readable rejection result label. Operators:
: = != =~ :~.uint32
Rejection source code. Operators:
: = != < <= > >=.string
Human-readable rejection source label. Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
Human-readable text from the 220 greeting line. Operators:
: = != =~ :~.repeated string
Greeting capability atoms from the optional capability token. Operators:
: = != =~ :~.uint32
Number of databases advertised by SHOW DB. Operators:
: = != < <= > >=.repeated string
Bounded list of advertised database names. Operators:
: = != =~ :~.string
RFC 2229 message identifier from the greeting line. Operators:
: = != =~ :~.object
Show Fields
Show Fields
object
Show Fields
Show Fields
bool
Authoritative Answer (AA) flag. Operators:
: = !=.repeated string
Self-declared server hostnames (e.g. hostname.bind / id.server). Operators:
: = != =~ :~.bool
Recursion Available (RA) flag. Operators:
: = !=.bool
Best-effort open recursion signal for this source IP. Operators:
: = !=.uint32
Response code from the primary probe. Operators:
: = != < <= > >=.string
Symbolic response code label. Operators:
: = != =~ :~.string
Banner hint from version.bind TXT when available. Operators:
: = != =~ :~.object
Show Fields
Show Fields
bool
Whether callback query casing indicates DNS-0x20 randomization. Operators:
: = !=.bool
Whether returned callback answer matched the authoritative answer. Operators:
: = !=.string
Source IP that performed the callback lookup. Operators:
: = != =~ :~.string
Callback transport protocol used by the resolver. Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
Main remoting error message, when present. Operators:
: = != =~ :~.string
Exception class leaked by the server, when present. Operators:
: = != =~ :~.bool
True when the response carries the .NET remoting transport preamble. Operators:
: = !=.string
Stack frame method leaked by the server, when present. Operators:
: = != =~ :~.string
Transport protocol version parsed from the preamble. Operators:
: = != =~ :~.object
object
Show Fields
Show Fields
string
Device or appliance identifier from mESAID. Operators:
: = != =~ :~.string
Service header prefix observed ahead of the XML document. Operators:
: = != =~ :~.string
Update signature value, for example ESAINFO. Operators:
: = != =~ :~.uint32
Update size in bytes when present. Operators:
: = != < <= > >=.uint32
Update format version from the XML metadata. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
repeated string
Advertised capability flags from the negotiation line. Operators:
: = != =~ :~.string
Product flavor token, for example ESUITE. Operators:
: = != =~ :~.string
Advertised operating-system token. Operators:
: = != =~ :~.repeated string
Advertised protocol families, for example AGENT or INSTALL. Operators:
: = != =~ :~.uint32
Advertised Dr.Web protocol major version from the negotiation line. Operators:
: = != < <= > >=.uint32
Advertised Dr.Web protocol minor version from the negotiation line. Operators:
: = != < <= > >=.string
Violation text from a follow-up response line, when present. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Channel count reported by the device. Operators:
: = != < <= > >=.uint32
Numeric device type reported by the protocol. Operators:
: = != < <= > >=.string
Device hostname from the discovery reply. Operators:
: = != =~ :~.uint32
Embedded HTTP port reported by the device. Operators:
: = != < <= > >=.string
Device MAC address when present. Operators:
: = != =~ :~.string
Device serial number when present. Operators:
: = != =~ :~.uint32
Embedded HTTPS port reported by the device. Operators:
: = != < <= > >=.uint32
DVRIP TCP port reported by the device. Operators:
: = != < <= > >=.string
Firmware or software version from the discovery reply. Operators:
: = != =~ :~.object
object
Show Fields
Show Fields
bool
Operators:
: = !=.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.bool
Operators:
: = !=.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Operators:
: = != < <= > >=.string
Operators:
: = != =~ :~.uint64
Operators:
: = != < <= > >=.object
object
object
Show Fields
Show Fields
string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.repeated string
Operators:
: = != =~ :~.bool
Operators:
: = !=.string
Operators:
: = != =~ :~.bool
Operators:
: = !=.string
Operators:
: = != =~ :~.repeated string
Operators:
: = != =~ :~.bool
Operators:
: = !=.bool
Operators:
: = !=.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.object
Show Fields
Show Fields
repeated string
Operators:
: = != =~ :~.bool
Operators:
: = !=.repeated string
Operators:
: = != =~ :~.bool
Operators:
: = !=.repeated string
Operators:
: = != =~ :~.bool
Operators:
: = !=.uint64
Operators:
: = != < <= > >=.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.object
object
object
Show Fields
Show Fields
uint32
Product code from the identity object. Operators:
: = != < <= > >=.string
Product name reported by the identity object. Operators:
: = != =~ :~.string
Product revision string (major.minor). Operators:
: = != =~ :~.uint32
Serial number from the identity object. Operators:
: = != < <= > >=.object
object
object
object
object
Show Fields
Show Fields
repeated string
Raw response lines returned by the daemon. Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
Human-readable response code label. Operators:
: = != =~ :~.uint32
FINS command response code. Operators:
: = != < <= > >=.object
object
Show Fields
Show Fields
uint32
Number of DM words. Operators:
: = != < <= > >=.uint32
Expansion DM size value. Operators:
: = != < <= > >=.uint32
I/O memory size value. Operators:
: = != < <= > >=.uint32
Program area size value. Operators:
: = != < <= > >=.uint32
Number of steps/transitions value. Operators:
: = != < <= > >=.uint32
Timer/counter capacity value. Operators:
: = != < <= > >=.object
object
Show Fields
Show Fields
string
Application name. Operators:
: = != =~ :~.string
Application version. Operators:
: = != =~ :~.string
Fatal message. Operators:
: = != =~ :~.string
FOX protocol version. Operators:
: = != =~ :~.string
Greeting line. Operators:
: = != =~ :~.string
Host address. Operators:
: = != =~ :~.string
Host name. Operators:
: = != =~ :~.string
Language. Operators:
: = != =~ :~.string
Operating system name. Operators:
: = != =~ :~.string
Operating system version. Operators:
: = != =~ :~.int32
Station identifier. Operators:
: = != < <= > >=.string
Station name. Operators:
: = != =~ :~.string
Time zone. Operators:
: = != =~ :~.object
Show Fields
Show Fields
object
Show Fields
Show Fields
string
Auth SSL reply. Operators:
: = != =~ :~.string
Auth TLS reply. Friendly label:
AUTH TLS Reply. Included in overview projections. Operators: : = != =~ :~.uint32
Greeting code. Operators:
: = != < <= > >=.string
Greeting text. Operators:
: = != =~ :~.bool
Whether used implicit TLS. Operators:
: = !=.object
Show Fields
Show Fields
object