Products

Target Intelligence

You give us a CVE. We tell you every vulnerable host on the internet right now.

VulnCheck Target Intelligence is a continuously updated index of internet-facing hosts confirmed to be running vulnerable software. Unlike traditional internet scanners that surface potentially vulnerable hosts, Target Intelligence applies fingerprinting and version detection techniques to identify hosts with a high degree of confidence, then maps those findings directly to CVEs.

This makes Target Intelligence useful as a stage 1 triage tool: before an attacker gets there, you can answer the question "which hosts on the internet are actually on the target list for this CVE right now?"

Base URL

https://api.vulncheck.com/v3/index/target-intel

Authentication

All requests require a bearer token in the Authorization header.

Authorization: Bearer <your_api_token>

How does Target Intelligence Work?

VulnCheck Scans the Internet on a Tiered Cadence

VulnCheck port-scans the internet continuously from a catalog of ports, each assigned a scan cadence tier. Ports where exposure changes fastest are revisited most often: HTTP and HTTPS (80, 443) are re-scanned every 7 days, roughly a hundred further TCP ports and a set of UDP ports every 14 days, and a long tail every 30 days. The catalog covers well over 150 TCP ports and a set of UDP ports directly, and absorbs the remainder of the top 1,000 TCP and top 100 UDP ports at the slowest tier.

Ports are added to the catalog for a documented reason — a new fingerprint, a CVE that needs coverage, or a customer request — so coverage follows what is actually being exploited.

VulnCheck Grabs Banners from Discovered Services

Every open port discovered by the port scan is handed to a banner-grab stage, which selects a protocol-specific module based on the port and speaks the real protocol to the service. Coverage spans HTTP/HTTPS and TLS, remote access and file transfer (SSH, FTP, Telnet, RDP, SMB), mail (SMTP, IMAP, POP3), databases (MySQL, PostgreSQL, MongoDB, Redis, MSSQL, Oracle), directory and messaging services (LDAP, MQTT, AMQP, NATS), and industrial protocols (Modbus, DNP3, BACnet, EtherNet/IP, Siemens S7, CODESYS, FINS) — around 48 protocols in total.

Where an HTTP response redirects to a different port, that port is followed and grabbed as well, so services hidden behind a redirect aren't missed.

VulnCheck Identifies the Product and Version

Banner data is run through VulnCheck's library of scanning rules. Each rule inspects specific evidence — an HTTP Server header or body, a TLS certificate common name, an SSH or FTP banner, an EtherNet/IP response — and, when it matches, declares what the asset is: a vendor, a product, a version, and a CPE. Rules can extract the version string out of the matched data, and can send an active follow-up probe where passive banner data isn't enough to confirm or version the product.

The library carries thousands of rules drawn from VulnCheck's own research alongside normalized public fingerprint sources, with the heaviest coverage on HTTP, TLS, FTP, SSH, and SMTP.

VulnCheck Maps Fingerprints to CVEs

Each fingerprinted CPE is then mapped to CVEs from two independent directions. A scanning rule can assert a CVE directly, when the matched evidence is itself proof of that vulnerability. Separately, the fingerprinted vendor/product/version is looked up in VulnCheck's CVE-to-CPE index, built from exact NVD CPE matches and from version ranges pre-resolved against observed versions.

Both paths are merged per CPE and graded with a confirmed flag, which tells you whether a CVE match survived a distro-backport check — the single largest source of false positives in version-based CVE matching. See Response Schema for how confirmed is computed and how to read it during triage.

What This API Is and Is Not

Target Intelligence is:

  • A confirmed exploitation target queue for known-vulnerable internet-facing hosts
  • A pre-loss triage tool for understanding exposure at the moment a CVE is disclosed
  • A source of high-confidence, CVE-mapped host data with version-level fingerprinting

Target Intelligence is not:

  • An Attack Surface Management (ASM) tool — it does not take a seed domain and enumerate assets
  • A complete inventory of all internet-facing assets for a given organization
  • A replacement for internal asset discovery

To look up hosts associated with an organization, query by ASN, CIDR range, or a list of known IPs.

What VulnCheck Indices Contain Target Intelligence?

VulnCheck IndexDetailsProduct
target-intelInternet-facing host-port-service observations with version-level fingerprints, CVE mappings graded by confidence, geolocation, ASN, infrastructure classifications, and protocol-specific service metadata.Target Intelligence
ipintel-#d (3d, 10d, 30d, 90d)Initial access targets and command and control infrastructure observed in the last # of days.IP Intelligence
vulncheck-canariesExploitation attempts observed by VulnCheck's canary network. Source IPs seen attacking canaries are labelled on Target Intelligence records as the canary-attacker classification.Canary Intelligence

Browse the target-intel index in the VulnCheck API Sandbox.

Data Freshness

Target Intelligence maintains a rolling window of scan data. The index is continuously updated as new scan results arrive, and older observations are expired on a rolling basis to keep the dataset current and operationally relevant.

The unique key per record is the combination of IP + port + fingerprint/service information. If a host is re-scanned, its record is updated with the latest observation — timestamp moves forward while date_added continues to record when that host-port first entered the index.

Learn More

  • Example Records — querying the API and the shape of a target-intel record
  • Query Parameters — filtering by CVE, product, CPE, network, geography, classification, and confidence
  • Response Schema — every returned field, plus how confirmed and deprecated should be read
  • Enrichment Data — geolocation, ASN, infrastructure classifications, and protocol-specific service metadata
  • Offline Backups — full-index bulk export