In addition to the fingerprint and CVE fields (see Response Schema), each target-intel record carries enrichment derived from the host itself: where it sits on the network, what kind of infrastructure it is, and the full protocol-level detail captured when its service was grabbed.
Enrichment fields follow the standard omitempty contract: a field is only present on a record if it was populated for that observation.
| Field | Type | Description |
|---|---|---|
asn | string | Autonomous System Number the host's IP belongs to (e.g. AS64500) |
as_name | string | Name of the organization operating that Autonomous System |
as_domain | string | Domain of the organization operating that Autonomous System |
country | string | Country name (e.g. United States) |
country_code | string | ISO 3166-1 alpha-2 country code (e.g. US) |
asn, country, and country_code are all queryable. as_name and as_domain are returned for context but are not searchable — to find every host on a network operator's infrastructure, query by asn or cidr.
classifications is a flat array of type:value strings describing what kind of infrastructure the host is, independent of what software it runs. A single host can carry several. Classifications come from the same scanning rules that identify products, plus one label computed from VulnCheck's canary network.
| Type | What it means | Example values |
|---|---|---|
c2 | Command and control server for a known offensive framework or malware family | cobalt-strike, sliver, mythic, adaptixc2, msfconsole, gophish |
attack-infrastructure | Infrastructure supporting attacks without being a C2 in its own right — phishing kits, stealer panels, scanning tooling, botnet nodes | interactsh, acunetix, iptv-streamer, 63256-botnet, slowtempest |
honeypot | A deception host imitating a vulnerable system | conpot, qbittorrent, frankenpot, zyxel, screenconnect, elasticpot |
proxy | Proxy, VPN endpoint, or tunnelling service | squid, xray, traefik, softether, gost, tor-exit-node, ngrok |
scanner | Host running internet scanning or reconnaissance tooling | rengine, qingscan, asset-reconnaissance-lighthouse |
cdn | Host fronted by, or belonging to, a content delivery network | cloudflare, akamai, fastly, imperva, cloudfront |
ics | Industrial control system / OT device, labelled by the industrial protocol it speaks | modbus |
mcp | Exposed Model Context Protocol server | mcp-sdk, model-context-protocol |
sector | Industry vertical the asset belongs to, derived from HTTP and certificate evidence | government, healthcare, education, energy |
canary-attacker | The host's IP has been observed attacking VulnCheck canaries. Always the literal value true | true |
The values above are examples, not the full set — each type carries many more, and the library grows as new frameworks and malware families are fingerprinted. Coverage per value also moves with the internet: a framework whose operators rotate infrastructure may have many matching hosts one week and none the next, so a value returning no results is normal rather than a sign the value is wrong.
canary-attacker is the join between Target Intelligence and Canary Intelligence: a host that both exposes a vulnerable service and actively attacks canaries is usually compromised infrastructure being used to attack others.
cdn and proxy are by far the most common classifications, and both are worth filtering out as much as in — a CDN-fronted host's fingerprint often describes the CDN edge rather than the origin.
See Query Parameters for how to filter on these, including why the combined type:value form should not be passed to the classifications parameter.
The metadata object holds everything captured from the service during the banner grab. Its shape depends on the record's protocol field — there are around 48 distinct shapes, one per supported protocol. Consumers must branch on protocol before reading metadata.
A handful of examples, all real response shapes:
protocol: "ssh"
{
"raw": "SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10",
"hassh": "425d29fe50d8e4f5e37efb6e24bcf660",
"host_key_algorithm": "ssh-rsa",
"ja4ts": "42340_2-1-1-4-1-3_1460_9"
}
protocol: "modbus"
{
"function_code": 43,
"length": 8,
"unit_id": 0,
"response": "DgGDAAAA",
"mei_response": {
"conformity_level": 131,
"mei_objects": [],
"next_object_id": 0,
"object_count": 0
},
"ja4ts": "64240_2-1-1-4-1-3_1460_10"
}
protocol: "http" — the richest shape, and the one most records carry:
| Field | Type | Description |
|---|---|---|
status_code | integer | HTTP status code returned |
status | string | HTTP status line |
title | string | Contents of the page's <title> element |
body | string | Response body, base64-encoded |
body_sha_256 | string | SHA-256 of the response body, useful for clustering identical pages |
content_length | integer | Response content length |
server | string | Server response header |
headers | array | All response headers, as {key, value[]} objects |
robots_txt | string | Contents of /robots.txt, where served |
security_txt | string | Contents of security.txt, where served |
favicon_sha_256 | string | SHA-256 of the site favicon |
http_header_order_hash | string | Hash of the response header order — a server-implementation fingerprint that survives header-value changes |
http_misconfigurations | array | HTTP misconfigurations detected on the response |
used_quic / used_dtls | boolean | Whether the observation was made over QUIC or DTLS |
Every TLS-capable protocol — HTTP, FTP, SMTP, IMAP, POP3, RDP and others — also carries a shared block of TLS handshake and certificate fields:
| Field | Type | Description |
|---|---|---|
tls_version / tls_selected_version | string | TLS version offered and negotiated |
tls_ciphersuite / tls_ciphersuite_name | integer / string | Negotiated cipher suite |
tls_extension_identifiers | array | TLS extensions present in the handshake |
cert_common_name | string | Certificate subject common name |
cert_issuer_common_name | string | Certificate issuer common name |
cert_subject_dn / cert_issuer_dn | string | Full subject and issuer distinguished names |
subject_alternative_names | array | Certificate SANs |
cert_not_before / cert_not_after | integer | Certificate validity window, as Unix milliseconds |
cert_chain_fingerprints | array | SHA-256 fingerprints of the presented certificate chain |
jarm | string | JARM fingerprint of the TLS server |
ja3s / ja4s | string | JA3S / JA4S server-side TLS fingerprints |
ja4x_fingerprints | array | JA4X certificate fingerprints |
misconfigurations | array | TLS misconfigurations detected on the handshake |
Certificate and TLS fingerprint fields are where a lot of the analytic value sits. jarm, ja4s, and ja4x_fingerprints identify server implementations independently of banners, which is how much of the c2 classification coverage is built — several C2 frameworks are identifiable only by their TLS certificate or handshake, never by an HTTP response.
ja4ts — a TCP-level fingerprint — is present on essentially every protocol shape, including those with no TLS at all.
Note on certificate identities: cert_common_name, cert_subject_dn, cert_issuer_dn, and subject_alternative_names are returned but not searchable. The hostname and domain parameters search reverse DNS only, so a host whose certificate names your organization cannot be found by certificate identity through this API.
Note on empty-by-design fields: a few fields exist in the metadata schema but are not populated in this export — body_shodan_hash, favicon_shodan_hash, favicon_md5, and redirects on HTTP, and host_key / host_key_fingerprint_sha256 on SSH. Treat them as reserved rather than as "no data observed".