Target Intelligence

Query Parameters

API query parameters supported by VulnCheck Target Intelligence for filtering the target-intel index.

VulnCheck Target Intelligence makes it easy to query our internet scan data set with a number of API query parameters, useful for filtering the results. Parameters can be combined. All parameters are optional, but at least one should be provided for meaningful results.

Query ParameterTypeDescription
cidrstringCIDR range for subnet lookups. Use /32 for a single host (e.g., 203.0.113.42/32)
hostnamestringHostname derived from DNS lookup at time of scan. Matched as a substring. Comma-delimited for multiple hostnames
domainstringDomain to match against the end of the host's DNS hostname. Comma-delimited for multiple domains. See Domain vs. Hostname
cvestringCVE ID to retrieve all confirmed vulnerable hosts (e.g., CVE-2024-21887)
vendorstringSoftware vendor name
productstringSoftware product name
versionstringSoftware version string
cpestringFull CPE string
asnstringAutonomous System Number (e.g., AS15169)
countrystringCountry name (e.g., United States, Germany)
country_codestringISO 3166-1 alpha-2 country code (e.g., US, DE)
protocolstringApplication protocol observed on the port (e.g., http, ssh, modbus)
transportstringTransport protocol: tcp or udp
portintegerPort number. Applies to both TCP and UDP observations — combine with transport to disambiguate
contains_cvebooleanWhen true, returns only hosts where a CVE is associated with the fingerprinted service
confirmedbooleanWhen true, returns only hosts with at least one high-confidence (rule-authored or exact-version) CVE match. When false, returns only hosts whose CVE matches are all unconfirmed
classificationsstringClassification to filter by. See Filtering by Classification
datestringFilter to records first added to the index on a date, in YYYY-MM-DD format. See Date Filtering
limitintegerMaximum number of results to return per page. Default 100, maximum 2000
pageintegerPage number to return
cursorstringCursor for a paginated query session. See Paging Through Large Result Sets

Note on vendor, product, and version: These parameters work in any combination. Querying by vendor alone or version alone is supported but may return broad results. Combining two or more produces more targeted output.

Domain vs. Hostname

hostname and domain both search the reverse-DNS hostname observed at scan time. They differ only in where the value has to appear.

hostname matches the value anywhere in the hostname. hostname=test.com returns mail.test.com, and also test.com.example.net.

domain matches the value at the end of the hostname. domain=test.com returns mail.test.com but not test.com.example.net. Every domain result is therefore also a hostname result; domain is the stricter of the two.

Both parameters accept a comma-delimited list of values, which are OR'd together: domain=test.com,example.org.

Note on hostname coverage: only about a quarter of observed host-port records carry a hostname at all, so both parameters see the same limited slice of the index. A host with no reverse DNS cannot be found by either one, whatever its certificate says or whose network it sits in.

Note on what domain does not search: domain does not match the TLS certificate identity (metadata.cert_common_name, cert_subject_dn, cert_issuer_dn), and it does not match as_domain, the domain of the organization operating the host's Autonomous System. Those values are returned on each record but are not searchable. To find hosts by network operator, use asn.

Note on label boundaries: the suffix match is not aligned to a dot, so domain=test.com also matches a hostname ending in mytest.com.

Filtering by Classification

Classifications are returned on a record as type:value strings — c2:cobalt-strike, honeypot:conpot, sector:government. The classifications parameter accepts either a type or a value, and which one you pass decides how broad the result is:

To findPassExample
Every host of a classification typethe typeclassifications=c2 — all C2 servers
Hosts matching one specific framework, product, or sectorthe bare valueclassifications=cobalt-strike — only Cobalt Strike C2 servers

Do not pass the combined type:value form. classifications=c2:cobalt-strike does not narrow to Cobalt Strike — everything after the colon is ignored, and the query returns every c2 host. Pass classifications=cobalt-strike instead.

Valid types are c2, scanner, proxy, attack-infrastructure, honeypot, mcp, cdn, ics, sector, and canary-attacker. See Enrichment Data for what each type means and the values available under it.

Date Filtering

date filters on date_added — the day a host-port record first entered the index — not on the day it was last scanned. date=2026-09-13 therefore answers "what showed up as newly exposed on this date", which is the useful question for tracking newly appearing infrastructure. A host added in June and re-scanned yesterday still matches its June date.

The standard v3 index date filters also apply to target-intel:

ParameterFilters on
pubStartDate / pubEndDatedate_added, as a range — the range form of date
lastModStartDate / lastModEndDatethe index's own _timestamp (when the record was last written to the index), which trails the scan timestamp

See the /v3/index/{index} endpoint reference for the full set of shared parameters.

Paging Through Large Result Sets

A single page returns at most 2000 records (limit), and the default is 100. For broad queries this matters a lot: a common product or a widely-deployed CVE can match millions of host-port records, far more than page-based access is meant to walk.

For anything beyond the first few pages, use cursor pagination. Start a session with start_cursor, then follow _meta.next_cursor on each response:

# Start a paginated session
curl -H "Authorization: Bearer <token>" \
  "https://api.vulncheck.com/v3/index/target-intel?cve=CVE-2024-21887&limit=500&start_cursor"

# Continue it with the next_cursor value from the previous response
curl -H "Authorization: Bearer <token>" \
  "https://api.vulncheck.com/v3/index/target-intel?cve=CVE-2024-21887&limit=500&cursor=MTc4OTQ0Mjc4NTQ4Mw=="

If you need the whole index rather than a slice of it, pull the offline backup instead of paging.

Example: A CVE Filtered to One Country

By combining two of the API query parameters (CVE and country) we can narrow a CVE's target list to a single country.

curl --request GET \
    --url 'https://api.vulncheck.com/v3/index/target-intel?cve=CVE-2024-21887&country_code=US' \
    --header 'Accept: application/json' \
    --header 'Authorization: Bearer insert_token_here'

Note on the CLI: vulncheck index browse exposes the shared index flags — --cve, --country, --countrycode, --asn, --hostname, --limit, --cursor, and the date flags. The Target Intelligence-specific filters (cidr, vendor, product, version, cpe, protocol, transport, port, contains_cve, confirmed, classifications, domain) are available over HTTP and through the SDKs.

Product-Centric Queries

QuestionAPI Call Example
Which internet-facing systems are vulnerable to a given CVE??cve=CVE-2021-36260
Which internet-facing systems are using a given vendor and product??vendor=ivanti&product=connect+secure
Which internet-facing systems are using a given vendor, product, and specific version??vendor=ivanti&product=connect+secure&version=22.7.2.5367
Which internet-facing systems match a specific CPE string??cpe=cpe:2.3:o:qnap:qts:-:*:*:*:*:*:*:*
Which hosts have a high-confidence match for a CVE??cve=CVE-2024-21887&confirmed=true
Which hosts run a product but have no known CVEs??product=tomcat&contains_cve=false
Filter by country of origin??country_code=US
Filter by ASN??asn=AS7018
Filter by port??port=443
Filter by protocol??protocol=modbus
Filter by IP range (CIDR notation)??cidr=203.0.113.0/24

Classification Queries

QuestionAPI Call Example
Where are all the C2 servers on the internet??classifications=c2
Where are all the Cobalt Strike C2 servers??classifications=cobalt-strike
Where are all the honeypots on the internet??classifications=honeypot
Where are all the canary attackers on the internet??classifications=canary-attacker
Where are all the proxies on the internet??classifications=proxy
Where are all the identified attack infrastructure assets??classifications=attack-infrastructure
Where are all the known scanners on the internet??classifications=scanner
Where are all the ICS/OT assets??classifications=ics
Where are all the government, healthcare, education, and energy assets??classifications=sector
Where are all the exposed MCP servers??classifications=mcp

Asset-Centric Queries

QuestionAPI Call Example
What do you have for IPv4 a.b.c.d??cidr=203.0.113.42/32
What do you have for IPv6 y:y:y:y:y:y:x.x.x.x??cidr=2001:4860:4860::8888 (supported, no IPv6 data yet)
What do you have for a hostname??hostname=test.com
What do you have for hosts under an organization's domain??domain=test.com
What was newly added to the index on a given day??date=2026-09-13