services
object
Show Fields
Show Fields
uint32
TSAP destination that completed setup communication. Operators:
: = != < <= > >=.string
Firmware version from SZL module identification records. Operators:
: = != =~ :~.string
Hardware version from SZL module identification records. Operators:
: = != =~ :~.string
Installation location from component identification records. Operators:
: = != =~ :~.string
Module identifier string from SZL module identification records. Operators:
: = != =~ :~.string
Module name from component identification records. Operators:
: = != =~ :~.string
Module type from component identification records. Operators:
: = != =~ :~.string
Plant identifier from component identification records. Operators:
: = != =~ :~.string
Device serial number from component identification records. Operators:
: = != =~ :~.string
System name from component identification records. Operators:
: = != =~ :~.object
Show Fields
Show Fields
InitialOpcode
Initial control opcode observed from the server. Operators:
: = != =~ :~.object
object
Show Fields
Show Fields
uint32
Steam app ID. Operators:
: = != < <= > >=.string
Source game description. Operators:
: = != =~ :~.string
Source game directory. Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.uint64
Optional full 64-bit Source game ID from the EDF tail. Operators:
: = != < <= > >=.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
7DTD metadata fields parsed from the keywords string. Operators:
: = != =~ :~.string
Raw Source keywords string, which carries the 7DTD metadata blob. Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Active map or level name from the A2S INFO response. Operators:
: = != =~ :~.uint32
Maximum player slots. Operators:
: = != < <= > >=.string
Server operating system (linux/windows/macos). Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.uint32
Current player count. Operators:
: = != < <= > >=.bool
Whether the server is private/passworded. Operators:
: = !=.bool
Whether VAC is enabled. Operators:
: = !=.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Source server name from the A2S INFO response. Operators:
: = != =~ :~.string
Server type (dedicated/listen/proxy). Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Operators:
: = != =~ :~.string
Reported server build/version from A2S INFO. Operators:
: = != =~ :~.object
Show Fields
Show Fields
object
Show Fields
Show Fields
uint32
SLP response error code. Operators:
: = != < <= > >=.uint32
SLP function identifier in the response. Operators:
: = != < <= > >=.string
Human-readable SLP function name. Operators:
: = != =~ :~.string
Language tag from response headers. Operators:
: = != =~ :~.repeated string
Service URLs returned by the responder. Operators:
: = != =~ :~.uint32
Number of URLs returned for service replies. Operators:
: = != < <= > >=.uint32
Transaction identifier. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
bool
Whether anonymous session access succeeded. Operators:
: = !=.string
Authentication mode (anonymous, required, unknown). Operators:
: = != =~ :~.repeated string
Protocol capabilities. Operators:
: = != =~ :~.string
Negotiated dialect label. Operators:
: = != =~ :~.string
NTLM DNS computer name from challenge metadata. Friendly label:
NTLM DNS Computer. Operators: : = != =~ :~.string
NTLM DNS domain name from challenge metadata. Friendly label:
NTLM DNS Domain. Operators: : = != =~ :~.string
NTLM DNS forest/tree name from challenge metadata. Friendly label:
NTLM DNS Tree. Operators: : = != =~ :~.string
NTLM NetBIOS computer name from challenge metadata. Friendly label:
NTLM NetBIOS Computer. Operators: : = != =~ :~.string
NTLM NetBIOS domain name from challenge metadata. Friendly label:
NTLM NetBIOS Domain. Operators: : = != =~ :~.string
NTLM target name from challenge metadata. Friendly label:
NTLM Target Name. Operators: : = != =~ :~.string
Native operating system hint. Operators:
: = != =~ :~.bool
Whether message signing is enabled. Operators:
: = !=.bool
Whether message signing is required. Operators:
: = !=.uint32
Preferred SMB major version (1 or 2). Operators:
: = != < <= > >=.string
Native software hint. Operators:
: = != =~ :~.bool
Whether SMB1 was observed. Operators:
: = !=.bool
Whether SMB2+ was observed. Operators:
: = !=.object
Show Fields
Show Fields
string
Share comment. Operators:
: = != =~ :~.bool
Whether share is special. Operators:
: = !=.bool
Whether share is temporary. Operators:
: = !=.string
Share kind (disk, ipc, printer, device, unknown). Operators:
: = != =~ :~.string
Share name. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
SMPP command status from the response header. Operators:
: = != < <= > >=.uint32
Interface version from optional TLV, if present. Operators:
: = != < <= > >=.ResponseType
Response type observed from the server. Operators:
: = != =~ :~.string
System ID returned by bind responses, if present. Operators:
: = != =~ :~.object
Show Fields
Show Fields
repeated string
Authentication mechanisms derived from AUTH capability. Operators:
: = != =~ :~.repeated string
EHLO capability lines, normalized and deduped. Operators:
: = != =~ :~.string
Server greeting line as received (CRLF preserved when present). Operators:
: = != =~ :~.uint32
Parsed SMTP reply code from greeting, when present. Operators:
: = != < <= > >=.string
Greeting text after the SMTP reply code. Operators:
: = != =~ :~.uint64
Maximum advertised message size parsed from SIZE capability. Operators:
: = != < <= > >=.string
Optional software hint extracted from greeting text (e.g. Postfix, Exim). Operators:
: = != =~ :~.bool
True when STARTTLS reply indicates acceptance. Operators:
: = !=.string
STARTTLS command reply line. Operators:
: = != =~ :~.bool
True when STARTTLS is advertised in capabilities. Operators:
: = !=.bool
True when scan connected with implicit TLS (usually port 465). Operators:
: = !=.object
Show Fields
Show Fields
repeated string
List of observed versions. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Boots counter. Operators:
: = != < <= > >=.string
Engine ID hex. Operators:
: = != =~ :~.uint32
Engine uptime seconds in seconds. Operators:
: = != < <= > >=.string
Enterprise name. Operators:
: = != =~ :~.uint32
Enterprise number. Operators:
: = != < <= > >=.string
ID layout. Operators:
: = != =~ :~.string
Probe descriptor. Operators:
: = != =~ :~.bool
Whether uses rfc3411 layout. Operators:
: = !=.object
object
Show Fields
Show Fields
string
Active user. Operators:
: = != =~ :~.string
Brand display name. Operators:
: = != =~ :~.string
Client ID. Operators:
: = != =~ :~.string
Device ID. Operators:
: = != =~ :~.string
Device type. Operators:
: = != =~ :~.string
Library version. Operators:
: = != =~ :~.string
Model display name. Operators:
: = != =~ :~.string
Remote name. Operators:
: = != =~ :~.string
Scope. Operators:
: = != =~ :~.string
Version. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Boot ID from BOOTID.UPNP.ORG when present. Operators:
: = != < <= > >=.uint32
Cache lifetime parsed from CACHE-CONTROL max-age. Operators:
: = != < <= > >=.uint32
Config ID from CONFIGID.UPNP.ORG when present. Operators:
: = != < <= > >=.string
Device description URL from the LOCATION header. Operators:
: = != =~ :~.string
Search target from the ST header. Operators:
: = != =~ :~.string
Software and UPnP stack hint from the SERVER header. Operators:
: = != =~ :~.uint32
HTTP status code from the M-SEARCH response. Operators:
: = != < <= > >=.string
HTTP status line from the responder. Operators:
: = != =~ :~.string
Unique service name from the USN header. Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
Client ID. Operators:
: = != =~ :~.string
Server ID. Included in overview projections. Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
Host key algorithm. Operators:
: = != =~ :~.string
Kex algorithm. Operators:
: = != =~ :~.object
object
object
Show Fields
Show Fields
repeated string
List of compression algorithms client to server. Operators:
: = != =~ :~.repeated string
List of compression algorithms server to client. Operators:
: = != =~ :~.repeated string
List of encryption algorithms client to server. Operators:
: = != =~ :~.repeated string
List of encryption algorithms server to client. Operators:
: = != =~ :~.repeated string
List of kex algorithms. Operators:
: = != =~ :~.repeated string
List of mac algorithms client to server. Operators:
: = != =~ :~.repeated string
List of mac algorithms server to client. Operators:
: = != =~ :~.repeated string
List of server host key algorithms. Operators:
: = != =~ :~.object
Show Fields
Show Fields
repeated string
List of client to server ciphers. Operators:
: = != =~ :~.repeated string
List of client to server compression. Operators:
: = != =~ :~.repeated string
List of client to server languages. Operators:
: = != =~ :~.repeated string
List of client to server macs. Operators:
: = != =~ :~.bool
Whether first kex follows. Operators:
: = !=.repeated string
List of host key algorithms. Operators:
: = != =~ :~.repeated string
List of kex algorithms. Operators:
: = != =~ :~.repeated string
List of server to client ciphers. Operators:
: = != =~ :~.repeated string
List of server to client compression. Operators:
: = != =~ :~.repeated string
List of server to client languages. Operators:
: = != =~ :~.repeated string
List of server to client macs. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Number of parsed instances. Operators:
: = != < <= > >=.uint32
SSRP message type from response header. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
bool
Whether the instance reports clustering enabled. Operators:
: = !=.string
SQL instance name. Operators:
: = != =~ :~.string
SQL instance named pipe endpoint. Operators:
: = != =~ :~.string
SQL host/server name. Operators:
: = != =~ :~.uint32
SQL instance TCP listener port. Operators:
: = != < <= > >=.string
SQL instance version string. Operators:
: = != =~ :~.object
Show Fields
Show Fields
bool
Whether broadcasting is active. Operators:
: = !=.string
Steam client identifier from the broadcast header. Operators:
: = != =~ :~.uint32
Reported remote connection port. Operators:
: = != < <= > >=.uint32
Enabled service bitmask. Operators:
: = != < <= > >=.int32
Reported Steam universe. Operators:
: = != < <= > >=.bool
Whether games are currently running. Operators:
: = !=.string
Reported device hostname. Operators:
: = != =~ :~.string
Steam instance identifier from the broadcast header. Operators:
: = != =~ :~.repeated string
Reported private or LAN addresses. Operators:
: = != =~ :~.bool
Whether the remote device reports a 64-bit OS. Operators:
: = !=.repeated string
Reported MAC addresses. Operators:
: = != =~ :~.string
Normalized broadcast message type. Operators:
: = != =~ :~.int32
Minimum supported Steam IHS protocol version. Operators:
: = != < <= > >=.int32
Reported operating system type. Operators:
: = != < <= > >=.string
Reported public IP address. Operators:
: = != =~ :~.bool
Whether Remote Play is active. Operators:
: = !=.bool
Whether the screen is currently locked. Operators:
: = !=.bool
Whether the device identifies as a Steam Deck. Operators:
: = !=.uint64
Reported Steam client build/version identifier. Operators:
: = != < <= > >=.uint32
Supported service bitmask. Operators:
: = != < <= > >=.string
Reported device timestamp in RFC3339 format. Operators:
: = != =~ :~.int32
Reported Steam IHS protocol version. Operators:
: = != < <= > >=.bool
Whether VR streaming is active. Operators:
: = !=.object
Show Fields
Show Fields
string
Content-Type header value when present. Operators:
: = != =~ :~.string
Error body when present. Operators:
: = != =~ :~.string
STOMP frame command (e.g. CONNECTED, ERROR). Operators:
: = != =~ :~.string
Heart-beat header value when present. Operators:
: = != =~ :~.string
Negotiated STOMP protocol version. Operators:
: = != =~ :~.string
Server header value when present. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Count of parsed STUN attributes. Operators:
: = != < <= > >=.bool
True when FINGERPRINT attribute is present. Operators:
: = !=.string
STUN message class (success, error, request, indication). Operators:
: = != =~ :~.bool
True when MESSAGE-INTEGRITY attribute is present. Operators:
: = !=.uint32
STUN method number. Operators:
: = != < <= > >=.string
REALM attribute value when present. Operators:
: = != =~ :~.string
SOFTWARE attribute value when present. Operators:
: = != =~ :~.object
object
object
object
object
Show Fields
Show Fields
repeated string
Supported authentication mechanisms. Operators:
: = != =~ :~.repeated string
Supported server capabilities. Operators:
: = != =~ :~.uint32
Maximum protocol version advertised by the server. Operators:
: = != < <= > >=.uint32
Minimum protocol version advertised by the server. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
uint32
Authentication status from AUTHEN/REPLY packets. Operators:
: = != < <= > >=.string
Human-readable authentication status. Operators:
: = != =~ :~.bool
True when the server indicated encrypted body semantics. Operators:
: = !=.uint32
TACACS+ body length from the header. Operators:
: = != < <= > >=.uint32
TACACS+ flags byte. Operators:
: = != < <= > >=.string
TACACS+ packet type (authentication/authorization/accounting). Operators:
: = != =~ :~.uint32
TACACS+ sequence number. Operators:
: = != < <= > >=.string
Server message from AUTHEN/REPLY when present. Operators:
: = != =~ :~.uint32
TACACS+ major version. Operators:
: = != < <= > >=.uint32
TACACS+ minor version. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
string
Build or release identifier reported by the query interface. Operators:
: = != =~ :~.string
TeamSpeak major generation, such as “2” or “3”. Operators:
: = != =~ :~.string
Interface variant used to identify the service, such as “serverquery”, “tcpquery”, or “voice”. Operators:
: = != =~ :~.string
Platform or operating system string reported by the server. Operators:
: = != =~ :~.string
Server name advertised by TeamSpeak 2 voice discovery. Operators:
: = != =~ :~.string
Server version reported by the query interface or inferred from a fixed voice-protocol signature. Operators:
: = != =~ :~.object
Show Fields
Show Fields
repeated uint32
List of do option codes. Operators:
: = != < <= > >=.repeated string
List of do option names. Operators:
: = != =~ :~.repeated uint32
List of dont option codes. Operators:
: = != < <= > >=.repeated string
List of dont option names. Operators:
: = != =~ :~.bool
True when START_TLS option (46) was observed. Operators:
: = !=.uint32
Number of iac command count. Operators:
: = != < <= > >=.bool
Whether negotiation seen. Operators:
: = !=.string
Printable text emitted before authentication (banner/prompts). Operators:
: = != =~ :~.repeated uint32
List of will option codes. Operators:
: = != < <= > >=.repeated string
List of will option names. Operators:
: = != =~ :~.repeated uint32
List of wont option codes. Operators:
: = != < <= > >=.repeated string
List of wont option names. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Block number from DATA/ACK packets when present. Operators:
: = != < <= > >=.uint32
DATA payload size in bytes. Operators:
: = != < <= > >=.uint32
TFTP error code from ERROR packets when present. Operators:
: = != < <= > >=.string
TFTP error message from ERROR packets. Operators:
: = != =~ :~.bool
True when an OACK packet was observed. Operators:
: = !=.uint32
First response opcode. Operators:
: = != < <= > >=.string
Symbolic response opcode label. Operators:
: = != =~ :~.uint32
Source UDP port used by the responder for transfer traffic. Operators:
: = != < <= > >=.string
Transfer mode echoed from the request. Operators:
: = != =~ :~.object
Show Fields
Show Fields
uint32
Listener error code when present. Operators:
: = != < <= > >=.string
Listener error details when present. Operators:
: = != =~ :~.string
Listener version string when present. Operators:
: = != =~ :~.uint32
TNS packet type value from the response header. Operators:
: = != < <= > >=.string
Human-readable TNS packet type. Operators:
: = != =~ :~.string
Raw VSNNUM value when present. Operators:
: = != =~ :~.object
object
Show Fields
Show Fields
uint32
Ubiquiti discovery response command value. Operators:
: = != < <= > >=.string
Adoption/configuration status when present. Operators:
: = != =~ :~.string
Wireless ESSID when present. Operators:
: = != =~ :~.string
Firmware string when present. Operators:
: = != =~ :~.string
Device hostname when present. Operators:
: = != =~ :~.repeated string
Observed interface IP addresses. Operators:
: = != =~ :~.repeated string
Observed MAC addresses. Operators:
: = != =~ :~.uint32
Management port when advertised. Operators:
: = != < <= > >=.string
Model string when present. Operators:
: = != =~ :~.string
Product string when present. Operators:
: = != =~ :~.uint32
Ubiquiti discovery protocol version (1 or 2). Operators:
: = != < <= > >=.string
Software version when present. Operators:
: = != =~ :~.uint32
Uptime in seconds when present. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
string
PLC hardware revision. Operators:
: = != =~ :~.string
Human-readable PLC model when recognized. Operators:
: = != =~ :~.string
Raw PLC model code returned by the device. Operators:
: = != =~ :~.uint32
PLC operating system build number. Operators:
: = != < <= > >=.string
PLC operating system version in major.minor form. Operators:
: = != =~ :~.string
PLC name configured on the controller. Operators:
: = != =~ :~.uint64
PLC unique identifier. Operators:
: = != < <= > >=.uint32
Unit ID of the PCOM master PLC. Operators:
: = != < <= > >=.object
Show Fields
Show Fields
repeated string
Callsigns observed in position/update traffic. Operators:
: = != =~ :~.string
Recipient identifier from the $DI greeting. Operators:
: = != =~ :~.bool
True when position/update traffic was also observed. Operators:
: = !=.string
Sender identifier from the $DI greeting. Operators:
: = != =~ :~.string
Advertised FSD version string. Operators:
: = != =~ :~.object
Show Fields
Show Fields
repeated string
Supported feature flags from the banner tail. Operators:
: = != =~ :~.uint32
Greeting status code. Operators:
: = != < <= > >=.string
Greeting text after the numeric status code. Operators:
: = != =~ :~.string
Advertised MKS display protocol, when present. Operators:
: = != =~ :~.string
Advertised server daemon protocol, when present. Operators:
: = != =~ :~.bool
True when the banner requires SSL/TLS. Operators:
: = !=.string
Authentication daemon version string. Operators:
: = != =~ :~.object
Show Fields
Show Fields
repeated uint32
Security types as raw numeric IDs. Operators:
: = != < <= > >=.repeated string
Security types decoded to labels. Operators:
: = != =~ :~.string
Best-effort implementation/vendor family hint. Operators:
: = != =~ :~.string
Raw banner version string from the server (e.g. “003.008”). Operators:
: = != =~ :~.object
Show Fields
Show Fields
object
Show Fields
Show Fields
string
Referral WHOIS server endpoint if present in response metadata. Operators:
: = != =~ :~.object
object
object
Show Fields
Show Fields
string
SOAP action from the response header when present. Operators:
: = != =~ :~.string
SOAP fault reason when present. Operators:
: = != =~ :~.bool
True when the response body is a SOAP fault. Operators:
: = !=.object
Show Fields
Show Fields
bool
True when the endpoint requires authentication. Operators:
: = !=.repeated string
Authentication schemes offered in WWW-Authenticate headers. Operators:
: = != =~ :~.string
SOAP fault code when the endpoint returned a WS-Man fault. Operators:
: = != =~ :~.string
SOAP fault reason when the endpoint returned a WS-Man fault. Operators:
: = != =~ :~.string
Product vendor reported by Identify. Operators:
: = != =~ :~.string
Product version reported by Identify. Operators:
: = != =~ :~.string
WS-Management protocol URI reported by Identify. Operators:
: = != =~ :~.WsmanResponseType
Classification of the first protocol-specific response. Operators:
: = != =~ :~.object
Show Fields
Show Fields
string
Optional failure reason text. Operators:
: = != =~ :~.uint32
X11 protocol major version. Operators:
: = != < <= > >=.uint32
X11 protocol minor version. Operators:
: = != < <= > >=.SetupStatus
Setup status returned by the X11 server. Operators:
: = != =~ :~.string
Optional X11 vendor string on successful setup. Operators:
: = != =~ :~.object
object
Show Fields
Show Fields
string
Authentication name selected by a Willing response. Operators:
: = != =~ :~.string
Human-readable manager hostname string. Operators:
: = != =~ :~.ResponseType
Whether the manager answered Willing or Unwilling. Operators:
: = != =~ :~.string
Human-readable manager status string. Operators:
: = != =~ :~.object
object
Show Fields
Show Fields
string
Stream error (for example host-unknown). Operators:
: = != =~ :~.bool
Whether the scan used implicit TLS. Operators:
: = !=.object
Show Fields
Show Fields
object
object
Show Fields
Show Fields
uint32
Reported active client connection count. Operators:
: = != < <= > >=.string
Server mode (leader, follower, standalone, read-only). Operators:
: = != =~ :~.uint32
Reported znode count. Operators:
: = != < <= > >=.bool
Whether the server reports read-only mode. Operators:
: = !=.string
Zookeeper version from 4lw output. Operators:
: = != =~ :~.object
Show Fields
Show Fields
object
object
Show Fields
Show Fields
uint32
Steam app ID. Operators:
: = != < <= > >=.string
Source game description. Operators:
: = != =~ :~.string
Source game directory. Operators:
: = != =~ :~.string
Active map name. Operators:
: = != =~ :~.uint32
Maximum player slots. Operators:
: = != < <= > >=.string
Source server name. Operators:
: = != =~ :~.string
Server operating system (linux/windows/macos). Operators:
: = != =~ :~.uint32
Current player count. Operators:
: = != < <= > >=.bool
Whether server is private/passworded. Operators:
: = !=.bool
Whether VAC is enabled. Operators:
: = !=.string
Server type (dedicated/listen/proxy). Operators:
: = != =~ :~.string
Reported game/server version. Operators:
: = != =~ :~.