Target Intelligence

レコードの例

VulnCheck Target Intelligence で CVE をクエリする方法と、target-intel のレスポンスの構造。

VulnCheck API を使えば、VulnCheck Target Intelligence を簡単に使い始めることができます。まずは、次のように /v3/index/:index?cve=:cve API を使って target-intel インデックスをクエリするだけです。

curl --request GET \
    --url https://api.vulncheck.com/v3/index/target-intel?cve=CVE-2024-21887 \
    --header 'Accept: application/json' \
    --header 'Authorization: Bearer insert_token_here'

上記の例では、target-intel インデックスで、CVE-2024-21887 の影響を受けるソフトウェアを実行していることが確認されたすべてのホストを検索します。

CVE による target-intel の API レスポンスの例

各結果は、観測された単一の ホスト・ポート・サービスの組 を表します。つまり、1 つの IP、1 つのポート、そしてそのポート上で特定されたサービスです。複数のサービスを公開しているホストは、複数のレコードとして現れます。

有効な CVE 識別子を使用して /v3/index/target-intel?cve=:cve API エンドポイントを呼び出すと、次のようなレスポンスが返されます。

{
  "_benchmark": 0.050314,
  "_meta": {
    "timestamp": "2026-09-14T18:22:27.132288937Z",
    "index": "target-intel",
    "limit": 100,
    "total_documents": 411,
    "sort": "_timestamp",
    "order": "desc",
    "page": 1,
    "total_pages": 5,
    // ...
  },
  "data": [
    {
      "ip": "203.0.113.42",
      "hostname": "vpn.test.com",
      "port": 443,
      "timestamp": "2026-09-13T22:12:36.749Z",
      "date_added": "2026-06-11T11:22:30.592Z",
      "protocol": "http",
      "transport": "tcp",
      "cpe": [
        "cpe:2.3:a:ivanti:connect_secure:9.1:r15.2:*:*:*:*:*:*"
      ],
      "cve": [
        "CVE-2023-46805",
        "CVE-2024-21887",
        "CVE-2024-21893"
      ],
      "cve_confirmed": [
        { "cve_id": "CVE-2023-46805", "confirmed": true },
        { "cve_id": "CVE-2024-21887", "confirmed": true },
        { "cve_id": "CVE-2024-21893", "confirmed": true }
      ],
      "vendor": ["ivanti"],
      "product": ["connect secure"],
      "version": ["9.1"],
      "fingerprints": [
        {
          "cpe": "cpe:2.3:a:ivanti:connect_secure:9.1:r15.2:*:*:*:*:*:*",
          "vendor": "ivanti",
          "product": "connect secure",
          "version": "9.1",
          "deprecated": false,
          "cves": [
            { "cve_id": "CVE-2023-46805", "confirmed": true },
            { "cve_id": "CVE-2024-21887", "confirmed": true },
            { "cve_id": "CVE-2024-21893", "confirmed": true }
          ]
        }
      ],
      "contains_cve": true,
      "summary": {
        "cve_count": 3,
        "confirmed_count": 3,
        "fingerprint_count": 1,
        "contains_cve": true
      },
      "asn": "AS64500",
      "as_name": "Example ISP",
      "as_domain": "test.com",
      "country": "United States",
      "country_code": "US",
      "metadata": {
        "status_code": 200,
        "title": "Web Interface",
        "server": "",
        "cert_common_name": "vpn.test.com",
        "jarm": "29d3fd00029d29d00042d43d00041d598ac0c1012db967bb1ad0ff2491b3ae"
        // ...
      }
    }
  ]
}

上記のレコードは一般的なケースで、1 つのフィンガープリント、1 つの CPE、そしてすべてが確度チェックを通過した一連の CVE で構成されています。フィールド同士の関係について、知っておくべき点が 3 つあります。

  • トップレベルの cpe、vendor、product、version 配列は、fingerprints 内のすべての要素をフラットに集約したものです。ホストに複数のフィンガープリントがある場合、これらの配列にはそのすべての値がまとめて格納されるため、配列の位置で対応付けて読まないでください。どのバージョンがどの製品に属するかを知る必要がある場合は、fingerprints を使用してください。
  • cve は CVE ID の単純な配列で、cve_confirmed は同じリストに CVE ごとの確度を付与したものです。confirmed クエリパラメータ がフィルタリングに使用するのは、この confirmed フラグです。
  • summary は事前に計算された集計値であるため、配列の長さを自分で数える必要はありません。

フィンガープリントされたサービスに CVE が関連付けられていない場合、cve フィールドは null(空の配列ではありません)になり、contains_cve は false になります。

{
  "ip": "198.51.100.7",
  "hostname": "",
  "port": 80,
  "timestamp": "2026-09-13T09:10:00Z",
  "date_added": "2026-04-02T14:55:11.201Z",
  "protocol": "http",
  "transport": "tcp",
  "cpe": ["cpe:2.3:a:apache:tomcat:10.1.0:*:*:*:*:*:*:*"],
  "cve": null,
  "vendor": ["apache"],
  "product": ["tomcat"],
  "version": ["10.1.0"],
  "fingerprints": [
    {
      "cpe": "cpe:2.3:a:apache:tomcat:10.1.0:*:*:*:*:*:*:*",
      "vendor": "apache",
      "product": "tomcat",
      "version": "10.1.0",
      "deprecated": false
    }
  ],
  "contains_cve": false,
  "summary": {
    "cve_count": 0,
    "confirmed_count": 0,
    "fingerprint_count": 1,
    "contains_cve": false
  },
  "asn": "AS64501",
  "country": "Germany",
  "country_code": "DE"
}

CVE を持たないフィンガープリント済みホストも有用なデータです。これは「誰が脆弱か」ではなく「誰がこの製品を実行しているか」という問いに答えます。これらのレコードを完全に除外するには、contains_cve=true を指定してください。

fingerprints 配列、deprecated フラグ、そして confirmed が実際に何を証明するかを含むフィールドの完全なリファレンスについては、レスポンススキーマ を参照してください。上記で省略したプロトコル固有の metadata オブジェクトについては、エンリッチメントデータ を参照してください。