VulnCheck Target Intelligence is a continuously updated index of internet-facing hosts confirmed to be running vulnerable software. Unlike traditional internet scanners that surface potentially vulnerable hosts, Target Intelligence applies fingerprinting and version detection techniques to identify hosts with a high degree of confidence, then maps those findings directly to CVEs.
This makes Target Intelligence useful as a stage 1 triage tool: before an attacker gets there, you can answer the question "which hosts on the internet are actually on the target list for this CVE right now?"
Base URL
https://api.vulncheck.com/v3/index/target-intel
Authentication
All requests require a bearer token in the Authorization header.
Authorization: Bearer <your_api_token>
VulnCheck port-scans the internet continuously from a catalog of ports, each assigned a scan cadence tier. Ports where exposure changes fastest are revisited most often: HTTP and HTTPS (80, 443) are re-scanned every 7 days, roughly a hundred further TCP ports and a set of UDP ports every 14 days, and a long tail every 30 days. The catalog covers well over 150 TCP ports and a set of UDP ports directly, and absorbs the remainder of the top 1,000 TCP and top 100 UDP ports at the slowest tier.
Ports are added to the catalog for a documented reason — a new fingerprint, a CVE that needs coverage, or a customer request — so coverage follows what is actually being exploited.
Every open port discovered by the port scan is handed to a banner-grab stage, which selects a protocol-specific module based on the port and speaks the real protocol to the service. Coverage spans HTTP/HTTPS and TLS, remote access and file transfer (SSH, FTP, Telnet, RDP, SMB), mail (SMTP, IMAP, POP3), databases (MySQL, PostgreSQL, MongoDB, Redis, MSSQL, Oracle), directory and messaging services (LDAP, MQTT, AMQP, NATS), and industrial protocols (Modbus, DNP3, BACnet, EtherNet/IP, Siemens S7, CODESYS, FINS) — around 48 protocols in total.
Where an HTTP response redirects to a different port, that port is followed and grabbed as well, so services hidden behind a redirect aren't missed.
Banner data is run through VulnCheck's library of scanning rules. Each rule inspects specific evidence — an HTTP Server header or body, a TLS certificate common name, an SSH or FTP banner, an EtherNet/IP response — and, when it matches, declares what the asset is: a vendor, a product, a version, and a CPE. Rules can extract the version string out of the matched data, and can send an active follow-up probe where passive banner data isn't enough to confirm or version the product.
The library carries thousands of rules drawn from VulnCheck's own research alongside normalized public fingerprint sources, with the heaviest coverage on HTTP, TLS, FTP, SSH, and SMTP.
Each fingerprinted CPE is then mapped to CVEs from two independent directions. A scanning rule can assert a CVE directly, when the matched evidence is itself proof of that vulnerability. Separately, the fingerprinted vendor/product/version is looked up in VulnCheck's CVE-to-CPE index, built from exact NVD CPE matches and from version ranges pre-resolved against observed versions.
Both paths are merged per CPE and graded with a confirmed flag, which tells you whether a CVE match survived a distro-backport check — the single largest source of false positives in version-based CVE matching. See Response Schema for how confirmed is computed and how to read it during triage.
Target Intelligence is:
Target Intelligence is not:
To look up hosts associated with an organization, query by ASN, CIDR range, or a list of known IPs.
| VulnCheck Index | Details | Product |
|---|---|---|
| target-intel | Internet-facing host-port-service observations with version-level fingerprints, CVE mappings graded by confidence, geolocation, ASN, infrastructure classifications, and protocol-specific service metadata. | Target Intelligence |
| ipintel-#d (3d, 10d, 30d, 90d) | Initial access targets and command and control infrastructure observed in the last # of days. | IP Intelligence |
| vulncheck-canaries | Exploitation attempts observed by VulnCheck's canary network. Source IPs seen attacking canaries are labelled on Target Intelligence records as the canary-attacker classification. | Canary Intelligence |
Browse the target-intel index in the VulnCheck API Sandbox.
Target Intelligence maintains a rolling window of scan data. The index is continuously updated as new scan results arrive, and older observations are expired on a rolling basis to keep the dataset current and operationally relevant.
The unique key per record is the combination of IP + port + fingerprint/service information. If a host is re-scanned, its record is updated with the latest observation — timestamp moves forward while date_added continues to record when that host-port first entered the index.
target-intel recordconfirmed and deprecated should be read