VulnCheck Target Intelligence makes it easy to query our internet scan data set with a number of API query parameters, useful for filtering the results. Parameters can be combined. All parameters are optional, but at least one should be provided for meaningful results.
| Query Parameter | Type | Description |
|---|---|---|
cidr | string | CIDR range for subnet lookups. Use /32 for a single host (e.g., 203.0.113.42/32) |
hostname | string | Hostname derived from DNS lookup at time of scan. Matched as a substring. Comma-delimited for multiple hostnames |
domain | string | Domain to match against the end of the host's DNS hostname. Comma-delimited for multiple domains. See Domain vs. Hostname |
cve | string | CVE ID to retrieve all confirmed vulnerable hosts (e.g., CVE-2024-21887) |
vendor | string | Software vendor name |
product | string | Software product name |
version | string | Software version string |
cpe | string | Full CPE string |
asn | string | Autonomous System Number (e.g., AS15169) |
country | string | Country name (e.g., United States, Germany) |
country_code | string | ISO 3166-1 alpha-2 country code (e.g., US, DE) |
protocol | string | Application protocol observed on the port (e.g., http, ssh, modbus) |
transport | string | Transport protocol: tcp or udp |
port | integer | Port number. Applies to both TCP and UDP observations — combine with transport to disambiguate |
contains_cve | boolean | When true, returns only hosts where a CVE is associated with the fingerprinted service |
confirmed | boolean | When true, returns only hosts with at least one high-confidence (rule-authored or exact-version) CVE match. When false, returns only hosts whose CVE matches are all unconfirmed |
classifications | string | Classification to filter by. See Filtering by Classification |
date | string | Filter to records first added to the index on a date, in YYYY-MM-DD format. See Date Filtering |
limit | integer | Maximum number of results to return per page. Default 100, maximum 2000 |
page | integer | Page number to return |
cursor | string | Cursor for a paginated query session. See Paging Through Large Result Sets |
Note on vendor, product, and version: These parameters work in any combination. Querying by vendor alone or version alone is supported but may return broad results. Combining two or more produces more targeted output.
hostname and domain both search the reverse-DNS hostname observed at scan time. They differ only in where the value has to appear.
hostname matches the value anywhere in the hostname. hostname=test.com returns mail.test.com, and also test.com.example.net.
domain matches the value at the end of the hostname. domain=test.com returns mail.test.com but not test.com.example.net. Every domain result is therefore also a hostname result; domain is the stricter of the two.
Both parameters accept a comma-delimited list of values, which are OR'd together: domain=test.com,example.org.
Note on hostname coverage: only about a quarter of observed host-port records carry a hostname at all, so both parameters see the same limited slice of the index. A host with no reverse DNS cannot be found by either one, whatever its certificate says or whose network it sits in.
Note on what domain does not search: domain does not match the TLS certificate identity (metadata.cert_common_name, cert_subject_dn, cert_issuer_dn), and it does not match as_domain, the domain of the organization operating the host's Autonomous System. Those values are returned on each record but are not searchable. To find hosts by network operator, use asn.
Note on label boundaries: the suffix match is not aligned to a dot, so domain=test.com also matches a hostname ending in mytest.com.
Classifications are returned on a record as type:value strings — c2:cobalt-strike, honeypot:conpot, sector:government. The classifications parameter accepts either a type or a value, and which one you pass decides how broad the result is:
| To find | Pass | Example |
|---|---|---|
| Every host of a classification type | the type | classifications=c2 — all C2 servers |
| Hosts matching one specific framework, product, or sector | the bare value | classifications=cobalt-strike — only Cobalt Strike C2 servers |
Do not pass the combined type:value form. classifications=c2:cobalt-strike does not narrow to Cobalt Strike — everything after the colon is ignored, and the query returns every c2 host. Pass classifications=cobalt-strike instead.
Valid types are c2, scanner, proxy, attack-infrastructure, honeypot, mcp, cdn, ics, sector, and canary-attacker. See Enrichment Data for what each type means and the values available under it.
date filters on date_added — the day a host-port record first entered the index — not on the day it was last scanned. date=2026-09-13 therefore answers "what showed up as newly exposed on this date", which is the useful question for tracking newly appearing infrastructure. A host added in June and re-scanned yesterday still matches its June date.
The standard v3 index date filters also apply to target-intel:
| Parameter | Filters on |
|---|---|
pubStartDate / pubEndDate | date_added, as a range — the range form of date |
lastModStartDate / lastModEndDate | the index's own _timestamp (when the record was last written to the index), which trails the scan timestamp |
See the /v3/index/{index} endpoint reference for the full set of shared parameters.
A single page returns at most 2000 records (limit), and the default is 100. For broad queries this matters a lot: a common product or a widely-deployed CVE can match millions of host-port records, far more than page-based access is meant to walk.
For anything beyond the first few pages, use cursor pagination. Start a session with start_cursor, then follow _meta.next_cursor on each response:
# Start a paginated session
curl -H "Authorization: Bearer <token>" \
"https://api.vulncheck.com/v3/index/target-intel?cve=CVE-2024-21887&limit=500&start_cursor"
# Continue it with the next_cursor value from the previous response
curl -H "Authorization: Bearer <token>" \
"https://api.vulncheck.com/v3/index/target-intel?cve=CVE-2024-21887&limit=500&cursor=MTc4OTQ0Mjc4NTQ4Mw=="
If you need the whole index rather than a slice of it, pull the offline backup instead of paging.
By combining two of the API query parameters (CVE and country) we can narrow a CVE's target list to a single country.
curl --request GET \
--url 'https://api.vulncheck.com/v3/index/target-intel?cve=CVE-2024-21887&country_code=US' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer insert_token_here'
package main
import (
"context"
"encoding/json"
"fmt"
"log"
"os"
vulncheck "github.com/vulncheck-oss/sdk-go-v2/v2"
)
func main() {
configuration := vulncheck.NewConfiguration()
configuration.Scheme = "https"
configuration.Host = "api.vulncheck.com"
client := vulncheck.NewAPIClient(configuration)
token := os.Getenv("VULNCHECK_API_TOKEN")
auth := context.WithValue(
context.Background(),
vulncheck.ContextAPIKeys,
map[string]vulncheck.APIKey{
"Bearer": {Key: token},
},
)
resp, httpRes, err := client.IndicesAPI.IndexTargetIntelGet(auth).Cve("CVE-2024-21887").CountryCode("US").Execute()
if err != nil || httpRes.StatusCode != 200 {
log.Fatal(err)
}
prettyJSON, err := json.MarshalIndent(resp.Data, "", " ")
if err != nil {
log.Fatalf("Failed to generate JSON: %v", err)
return
}
fmt.Println(string(prettyJSON))
}
import vulncheck_sdk
configuration = vulncheck_sdk.Configuration(host="https://api.vulncheck.com/v3")
configuration.api_key["Bearer"] = "insert_token_here"
with vulncheck_sdk.ApiClient(configuration) as api_client:
indices_client = vulncheck_sdk.IndicesApi(api_client)
api_response = indices_client.index_target_intel_get(cve="CVE-2024-21887", country_code="US")
print(api_response.data)
vulncheck index browse target-intel --cve CVE-2024-21887 --countrycode US
Note on the CLI: vulncheck index browse exposes the shared index flags — --cve, --country, --countrycode, --asn, --hostname, --limit, --cursor, and the date flags. The Target Intelligence-specific filters (cidr, vendor, product, version, cpe, protocol, transport, port, contains_cve, confirmed, classifications, domain) are available over HTTP and through the SDKs.
| Question | API Call Example |
|---|---|
| Which internet-facing systems are vulnerable to a given CVE? | ?cve=CVE-2021-36260 |
| Which internet-facing systems are using a given vendor and product? | ?vendor=ivanti&product=connect+secure |
| Which internet-facing systems are using a given vendor, product, and specific version? | ?vendor=ivanti&product=connect+secure&version=22.7.2.5367 |
| Which internet-facing systems match a specific CPE string? | ?cpe=cpe:2.3:o:qnap:qts:-:*:*:*:*:*:*:* |
| Which hosts have a high-confidence match for a CVE? | ?cve=CVE-2024-21887&confirmed=true |
| Which hosts run a product but have no known CVEs? | ?product=tomcat&contains_cve=false |
| Filter by country of origin? | ?country_code=US |
| Filter by ASN? | ?asn=AS7018 |
| Filter by port? | ?port=443 |
| Filter by protocol? | ?protocol=modbus |
| Filter by IP range (CIDR notation)? | ?cidr=203.0.113.0/24 |
| Question | API Call Example |
|---|---|
| Where are all the C2 servers on the internet? | ?classifications=c2 |
| Where are all the Cobalt Strike C2 servers? | ?classifications=cobalt-strike |
| Where are all the honeypots on the internet? | ?classifications=honeypot |
| Where are all the canary attackers on the internet? | ?classifications=canary-attacker |
| Where are all the proxies on the internet? | ?classifications=proxy |
| Where are all the identified attack infrastructure assets? | ?classifications=attack-infrastructure |
| Where are all the known scanners on the internet? | ?classifications=scanner |
| Where are all the ICS/OT assets? | ?classifications=ics |
| Where are all the government, healthcare, education, and energy assets? | ?classifications=sector |
| Where are all the exposed MCP servers? | ?classifications=mcp |
| Question | API Call Example |
|---|---|
| What do you have for IPv4 a.b.c.d? | ?cidr=203.0.113.42/32 |
| What do you have for IPv6 y:y:y:y:y:y:x.x.x.x? | ?cidr=2001:4860:4860::8888 (supported, no IPv6 data yet) |
| What do you have for a hostname? | ?hostname=test.com |
| What do you have for hosts under an organization's domain? | ?domain=test.com |
| What was newly added to the index on a given day? | ?date=2026-09-13 |