VulnCheck Target Intelligence is also available as an offline backup, so you can pull the whole index at once instead of paging through it. This is the right approach for any bulk workload — loading Target Intelligence into a data warehouse, correlating it against your own asset inventory, or working with a query whose result set runs to millions of host-port records.
Unlike Canary Intelligence, Target Intelligence is distributed as a single full-index snapshot rather than rolling 3/10/30/90-day windows. Each snapshot is a complete copy of the index, rebuilt daily.
| Offline Backup | Description |
|---|---|
| target-intel | Complete Target Intelligence index — all current host-port-service observations, fingerprints, CVE mappings, classifications, and service metadata |
To request the backup, call /v3/backup/:index as follows:
curl --request GET \
--url https://api.vulncheck.com/v3/backup/target-intel \
--header 'Accept: application/json' \
--header 'Authorization: Bearer insert_token_here'
package main
import (
"context"
"encoding/json"
"fmt"
"log"
"os"
vulncheck "github.com/vulncheck-oss/sdk-go-v2/v2"
)
func main() {
configuration := vulncheck.NewConfiguration()
configuration.Scheme = "https"
configuration.Host = "api.vulncheck.com"
client := vulncheck.NewAPIClient(configuration)
token := os.Getenv("VULNCHECK_API_TOKEN")
auth := context.WithValue(
context.Background(),
vulncheck.ContextAPIKeys,
map[string]vulncheck.APIKey{
"Bearer": {Key: token},
},
)
resp, httpRes, err := client.EndpointsAPI.BackupIndexGet(auth, "target-intel").Execute()
if err != nil || httpRes.StatusCode != 200 {
log.Fatal(err)
}
prettyJSON, err := json.MarshalIndent(resp.Data, "", " ")
if err != nil {
log.Fatalf("Failed to generate JSON: %v", err)
return
}
fmt.Println(string(prettyJSON))
}
import vulncheck_sdk
configuration = vulncheck_sdk.Configuration(host="https://api.vulncheck.com/v3")
configuration.api_key["Bearer"] = "insert_token_here"
with vulncheck_sdk.ApiClient(configuration) as api_client:
endpoints_client = vulncheck_sdk.EndpointsApi(api_client)
api_response = endpoints_client.backup_index_get("target-intel")
print(api_response.data[0].url)
vulncheck backup download target-intel
The endpoint does not return the data itself — it returns metadata and a set of time-limited download URLs:
{
"data": [
{
"filename": "target-intel-1789352538306259459.avro",
"sha256": "a9d27fb2ea909860f7092ac1d9417dcaed8e42a233c88b332382573ee83fdcf5",
"date_added": "2026-09-14T02:22:18.306Z",
"url": "https://...",
"url_mrap": "https://...",
"url_us-east-1": "https://...",
"url_us-west-2": "https://...",
"url_eu-west-2": "https://...",
"url_ap-southeast-2": "https://...",
"url_ttl_minutes": 15,
"url_expires": "2026-09-14T02:37:18.306Z"
}
]
}
| Field | Description |
|---|---|
filename | Name of the backup file. Target Intelligence backups are distributed in Avro format |
sha256 | SHA-256 checksum of the file — verify your download against this |
date_added | When this snapshot was built |
url | Default download URL |
url_mrap | Multi-region access point URL, which routes to the nearest available region |
url_<region> | Region-specific URLs. Pick the one closest to where you're processing the data |
url_ttl_minutes | Lifetime of the download URLs, in minutes |
url_expires | Timestamp at which the URLs stop working |
Two operational notes:
date_added tells you the vintage of the data you're holding. Re-request the endpoint to pick up the next day's snapshot; comparing sha256 against the last file you loaded tells you whether a new snapshot is actually available.The file is Avro, not NDJSON — record fields match the response schema returned by the index endpoint.