Target Intelligence

Enrichment Data

Geolocation, ASN, infrastructure classifications, and protocol-specific service metadata available on target-intel records.

In addition to the fingerprint and CVE fields (see Response Schema), each target-intel record carries enrichment derived from the host itself: where it sits on the network, what kind of infrastructure it is, and the full protocol-level detail captured when its service was grabbed.

Enrichment fields follow the standard omitempty contract: a field is only present on a record if it was populated for that observation.

Network and Geolocation Fields

FieldTypeDescription
asnstringAutonomous System Number the host's IP belongs to (e.g. AS64500)
as_namestringName of the organization operating that Autonomous System
as_domainstringDomain of the organization operating that Autonomous System
countrystringCountry name (e.g. United States)
country_codestringISO 3166-1 alpha-2 country code (e.g. US)

asn, country, and country_code are all queryable. as_name and as_domain are returned for context but are not searchable — to find every host on a network operator's infrastructure, query by asn or cidr.

Classifications

classifications is a flat array of type:value strings describing what kind of infrastructure the host is, independent of what software it runs. A single host can carry several. Classifications come from the same scanning rules that identify products, plus one label computed from VulnCheck's canary network.

TypeWhat it meansExample values
c2Command and control server for a known offensive framework or malware familycobalt-strike, sliver, mythic, adaptixc2, msfconsole, gophish
attack-infrastructureInfrastructure supporting attacks without being a C2 in its own right — phishing kits, stealer panels, scanning tooling, botnet nodesinteractsh, acunetix, iptv-streamer, 63256-botnet, slowtempest
honeypotA deception host imitating a vulnerable systemconpot, qbittorrent, frankenpot, zyxel, screenconnect, elasticpot
proxyProxy, VPN endpoint, or tunnelling servicesquid, xray, traefik, softether, gost, tor-exit-node, ngrok
scannerHost running internet scanning or reconnaissance toolingrengine, qingscan, asset-reconnaissance-lighthouse
cdnHost fronted by, or belonging to, a content delivery networkcloudflare, akamai, fastly, imperva, cloudfront
icsIndustrial control system / OT device, labelled by the industrial protocol it speaksmodbus
mcpExposed Model Context Protocol servermcp-sdk, model-context-protocol
sectorIndustry vertical the asset belongs to, derived from HTTP and certificate evidencegovernment, healthcare, education, energy
canary-attackerThe host's IP has been observed attacking VulnCheck canaries. Always the literal value truetrue

The values above are examples, not the full set — each type carries many more, and the library grows as new frameworks and malware families are fingerprinted. Coverage per value also moves with the internet: a framework whose operators rotate infrastructure may have many matching hosts one week and none the next, so a value returning no results is normal rather than a sign the value is wrong.

canary-attacker is the join between Target Intelligence and Canary Intelligence: a host that both exposes a vulnerable service and actively attacks canaries is usually compromised infrastructure being used to attack others.

cdn and proxy are by far the most common classifications, and both are worth filtering out as much as in — a CDN-fronted host's fingerprint often describes the CDN edge rather than the origin.

See Query Parameters for how to filter on these, including why the combined type:value form should not be passed to the classifications parameter.

Protocol-Specific Service Metadata

The metadata object holds everything captured from the service during the banner grab. Its shape depends on the record's protocol field — there are around 48 distinct shapes, one per supported protocol. Consumers must branch on protocol before reading metadata.

A handful of examples, all real response shapes:

protocol: "ssh"

{
  "raw": "SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10",
  "hassh": "425d29fe50d8e4f5e37efb6e24bcf660",
  "host_key_algorithm": "ssh-rsa",
  "ja4ts": "42340_2-1-1-4-1-3_1460_9"
}

protocol: "modbus"

{
  "function_code": 43,
  "length": 8,
  "unit_id": 0,
  "response": "DgGDAAAA",
  "mei_response": {
    "conformity_level": 131,
    "mei_objects": [],
    "next_object_id": 0,
    "object_count": 0
  },
  "ja4ts": "64240_2-1-1-4-1-3_1460_10"
}

protocol: "http" — the richest shape, and the one most records carry:

FieldTypeDescription
status_codeintegerHTTP status code returned
statusstringHTTP status line
titlestringContents of the page's <title> element
bodystringResponse body, base64-encoded
body_sha_256stringSHA-256 of the response body, useful for clustering identical pages
content_lengthintegerResponse content length
serverstringServer response header
headersarrayAll response headers, as {key, value[]} objects
robots_txtstringContents of /robots.txt, where served
security_txtstringContents of security.txt, where served
favicon_sha_256stringSHA-256 of the site favicon
http_header_order_hashstringHash of the response header order — a server-implementation fingerprint that survives header-value changes
http_misconfigurationsarrayHTTP misconfigurations detected on the response
used_quic / used_dtlsbooleanWhether the observation was made over QUIC or DTLS

Every TLS-capable protocol — HTTP, FTP, SMTP, IMAP, POP3, RDP and others — also carries a shared block of TLS handshake and certificate fields:

FieldTypeDescription
tls_version / tls_selected_versionstringTLS version offered and negotiated
tls_ciphersuite / tls_ciphersuite_nameinteger / stringNegotiated cipher suite
tls_extension_identifiersarrayTLS extensions present in the handshake
cert_common_namestringCertificate subject common name
cert_issuer_common_namestringCertificate issuer common name
cert_subject_dn / cert_issuer_dnstringFull subject and issuer distinguished names
subject_alternative_namesarrayCertificate SANs
cert_not_before / cert_not_afterintegerCertificate validity window, as Unix milliseconds
cert_chain_fingerprintsarraySHA-256 fingerprints of the presented certificate chain
jarmstringJARM fingerprint of the TLS server
ja3s / ja4sstringJA3S / JA4S server-side TLS fingerprints
ja4x_fingerprintsarrayJA4X certificate fingerprints
misconfigurationsarrayTLS misconfigurations detected on the handshake

Certificate and TLS fingerprint fields are where a lot of the analytic value sits. jarm, ja4s, and ja4x_fingerprints identify server implementations independently of banners, which is how much of the c2 classification coverage is built — several C2 frameworks are identifiable only by their TLS certificate or handshake, never by an HTTP response.

ja4ts — a TCP-level fingerprint — is present on essentially every protocol shape, including those with no TLS at all.

Note on certificate identities: cert_common_name, cert_subject_dn, cert_issuer_dn, and subject_alternative_names are returned but not searchable. The hostname and domain parameters search reverse DNS only, so a host whose certificate names your organization cannot be found by certificate identity through this API.

Note on empty-by-design fields: a few fields exist in the metadata schema but are not populated in this export — body_shodan_hash, favicon_shodan_hash, favicon_md5, and redirects on HTTP, and host_key / host_key_fingerprint_sha256 on SSH. Treat them as reserved rather than as "no data observed".