Target Intelligence

Offline Backups

Full-index offline backup of VulnCheck Target Intelligence data for bulk analysis.

VulnCheck Target Intelligence is also available as an offline backup, so you can pull the whole index at once instead of paging through it. This is the right approach for any bulk workload — loading Target Intelligence into a data warehouse, correlating it against your own asset inventory, or working with a query whose result set runs to millions of host-port records.

Unlike Canary Intelligence, Target Intelligence is distributed as a single full-index snapshot rather than rolling 3/10/30/90-day windows. Each snapshot is a complete copy of the index, rebuilt daily.

Offline BackupDescription
target-intelComplete Target Intelligence index — all current host-port-service observations, fingerprints, CVE mappings, classifications, and service metadata

To request the backup, call /v3/backup/:index as follows:

curl --request GET \
    --url https://api.vulncheck.com/v3/backup/target-intel \
    --header 'Accept: application/json' \
    --header 'Authorization: Bearer insert_token_here'

Backup Response

The endpoint does not return the data itself — it returns metadata and a set of time-limited download URLs:

{
  "data": [
    {
      "filename": "target-intel-1789352538306259459.avro",
      "sha256": "a9d27fb2ea909860f7092ac1d9417dcaed8e42a233c88b332382573ee83fdcf5",
      "date_added": "2026-09-14T02:22:18.306Z",
      "url": "https://...",
      "url_mrap": "https://...",
      "url_us-east-1": "https://...",
      "url_us-west-2": "https://...",
      "url_eu-west-2": "https://...",
      "url_ap-southeast-2": "https://...",
      "url_ttl_minutes": 15,
      "url_expires": "2026-09-14T02:37:18.306Z"
    }
  ]
}
FieldDescription
filenameName of the backup file. Target Intelligence backups are distributed in Avro format
sha256SHA-256 checksum of the file — verify your download against this
date_addedWhen this snapshot was built
urlDefault download URL
url_mrapMulti-region access point URL, which routes to the nearest available region
url_<region>Region-specific URLs. Pick the one closest to where you're processing the data
url_ttl_minutesLifetime of the download URLs, in minutes
url_expiresTimestamp at which the URLs stop working

Two operational notes:

  • Download URLs expire. They are presigned and valid for 15 minutes from the time the backup metadata was generated. Fetch the metadata immediately before downloading rather than caching URLs — a stale URL fails rather than redirecting.
  • Snapshots are rebuilt daily, so date_added tells you the vintage of the data you're holding. Re-request the endpoint to pick up the next day's snapshot; comparing sha256 against the last file you loaded tells you whether a new snapshot is actually available.

The file is Avro, not NDJSON — record fields match the response schema returned by the index endpoint.