Service inventory
When viewing services, use these keywords to search and filter.
Ports
Use port:<number> to search TCP and UDP services by port number. This search term supports numerical comparison operators (>, >=, <, <=, =).
port:<=25
TCP ports
Use tcp:<number> to search TCP services by port number.
tcp:53
Use service_ports_tcp:=<list> to find all services on assets with a specific list of TCP ports open. List the values in ascending numerical order, separated by commas.
service_ports_tcp:=80,443
UDP ports
Use udp:<number> to search UDP services by port number.
udp:443
Use service_ports_udp:=<list> to find all services on assets with a specific list of UDP ports open. List the values in ascending numerical order, separated by commas.
service_ports_udp:=53,123
Transport
Use transport:<term> to search the transport of a service by name.
transport:tcp
transport:udp
transport:icmp
Protocol
Use service_protocols:<term> (or protocol:<term> for short) to search the protocols associated with services.
protocol:http
protocol:telnet
Assets with product
Use service_products:<term> (or product:<term> for short) to search the identified service products associated with an asset and return all services for the matching assets.
product:openssh
service_products:nginx
Virtual host (vHost)
Use vhost:<text> to search the virtual hosts associated with a service by name.
vhost:"www"
Address
Use the service_address keyword to match the service IP address.
service_address:192.168.0.1
Public address
Use the keyword service_has_public and the syntax service_has_public:<boolean> to locate any service with a non-reserved IP address.
The term is a boolean value:
true,t,1, andyesrepresent truefalse,f,0, andnorepresent false
service_has_public:true
Private address
Use the keyword service_has_private and the syntax service_has_private:<boolean> to locate any service with a private IP address.
The term is a boolean value:
true,t,1, andyesrepresent truefalse,f,0, andnorepresent false
service_has_private:false
IPv6 address
Use the keyword service_has_ipv6 and the syntax service_has_ipv6:<boolean> to locate any service with an identified IPv6 address.
The term is a boolean value:
true,t,1, andyesrepresent truefalse,f,0, andnorepresent false
service_has_ipv6:false
Link-local IPv6 address
Use the keyword service_has_link_local and the syntax service_has_link_local:<boolean> to locate any service with an identified IPv6 link local (fe80::) address.
The term is a boolean value:
true,t,1, andyesrepresent truefalse,f,0, andnorepresent false
service_has_link_local:true
Assets with outlier score
Use outlier_score:<value> to search the calculated outlier score of assets and return all services on those assets. The outlier score ranges from 0 to 5 inclusive. This search term supports numerical comparison operators (>, >=, <, <=, =).
outlier_score:>2
outlier_score:0
Assets with MAC address vendors
Use mac_vendor:<text> to search the vendors associated with an asset’s MAC addresses and return all services on those assets.
mac_vendor:Apple
mac_vendor:"Intel Corporate"
Use newest_mac_vendor:<text> to search only the vendor of the newest MAC address.
newest_mac_vendor:Apple
Assets with MAC address age
Use mac_age:<term> to search the age of the newest MAC address on each asset and return all services on those assets. The term supports the standard runZero time comparison syntax.
mac_age:>1year
mac_age:<6months
mac_age:2019-12-31
Attributes
Use <attribute>:<term> to search any service attribute. This search term supports numerical comparison operators (>, >=, <, <=, =).
If the attribute name conflicts with an existing term, add the _service. prefix to disambiguate the query.
Service attribute searches can be slow, so it is often better to put an _asset.protocol:<term> filter in front of the service attribute query. For example, to search SSH banners, use _asset.protocol:ssh AND banner:<term>.
banner:password
service.product:"OpenSSH"
html.title:"Apache2 Ubuntu Default Page"
http.code:>=500
screenshot.image.size:=>100000
_service.arp.macVendor:Xerox
Use the has keyword to check whether a service has an attribute at all. Invert the has keyword with not has:<term> to find missing fields.
has:"http.head.server"
not has:"html.title"
Certificate fields
Use the following keywords to search the certificates related to a service.
Certificate ID
Use certificate_id:<uuid> to filter by certificate ID.
certificate_id:4e3a2b1c-5d6f-7a8b-9c0d-1e2f3a4b5c6d
Certificate fingerprint (bkhash)
Use fp_bkhash:=<text> to find services with a certificate matching the given bkhash fingerprint anywhere in the certificate chain.
fp_bkhash:=d2c7e8f9a1b2c3d4e5f6
Certificate fingerprint (SHA256)
Use fp_sha256:=<text> to find services with a certificate matching the given SHA256 fingerprint anywhere in the certificate chain.
fp_sha256:=SHA256:19vJPgdyh3BdGgTiSSavQsKx133lzFkJhu51n6fzG+k=
Certificate fingerprint (SHA1)
Use fp_sha1:=<text> to find services with a certificate matching the given SHA1 fingerprint anywhere in the certificate chain.
fp_sha1:=a1b2c3d4e5f6g7h8i9j0
Certificate validity fields
Use the following keywords to search the timestamps of the certificate found on the service. These fields support the standard runZero time comparison syntax.
certificate_valid_from:>2025-01-01
certificate_valid_until:<2026-01-01
certificate_created_at:<1year
certificate_updated_at:>2024-12-01
certificate_last_seen:<2months
Certificate authority key ID
Use certificate_authority_key_id:<text> to search by certificate authority key ID.
certificate_authority_key_id:"c03152cd5a50c3827c7471cecbe99cf97aeb82e2"
Certificate common name (CN)
Use certificate_cn:<text> to search by certificate common name.
certificate_cn:"example.com"
Certificate public key algorithm
Use certificate_public_key_algorithm:<text> to search by public key algorithm.
certificate_public_key_algorithm:rsaEncryption
Certificate serial number
Use certificate_serial:<text> to search by certificate serial number.
certificate_serial:123456
Certificate signature algorithm
Use certificate_signature_algorithm:<text> to search by signature algorithm.
certificate_signature_algorithm:sha256WithRSAEncryption
Certificate subject key ID
Use certificate_subject_key_id:<text> to search by subject key ID.
certificate_subject_key_id:"c769916e10f850397928f62bd34ca6ec39d8e00a"
Certificate type
Use certificate_type:<text> to search by certificate type.
certificate_type:x509
Certificate key usage
Use certificate_key_usage:<text> to search by key usage.
certificate_key_usage:"digitalSignature"
Certificate extended key usage
Use certificate_ext_key_usage:<text> to search by extended key usage.
certificate_ext_key_usage:"serverAuth"
Certificate OCSP server
Use certificate_ocsp_server:<text> to search by OCSP server.
certificate_ocsp_server:http://ocsp.example.com
Certificate CRL distribution points
Use certificate_crl_distribution_points:<text> to search by CRL distribution point.
certificate_crl_distribution_points:http://crl.example.com/
Certificate issuing certificate URL
Use certificate_issuing_certificate_url:<text> to search by issuing certificate URL.
certificate_issuing_certificate_url:http://issuer.example.com/
Certificate signature
Use certificate_signature:<text> to search by certificate signature.
certificate_signature:Bden73ipj8B2xb1Ozy5nOvIytCktGrht5xL7ZfFlaLIBQxbGO5Iuf6Y1yICcEpYqsgSJS6JKCdw5dujmPmGRwBZfVhIbSRb0exFQ4BVp82WtDHfy3QBgcmtusRIxLyM5ToTT2O53NxaSGaw3IRLXZ0y343RGlKOyQxEXeoHbLsVrpmMrqAKkHJkhjTKn7E9WDc4RCsAvd13BIDP80dDWK7OMZJnCDXGQwz2MkAYZNyjRRXA5XeO2cvMq36/4phyJDhIz1oDgDLOFDnCGKkW5gc8MjE0uxFIYTHKNkx+2WIU/j4uQGNAJQbqqCnupV4qjI29PQFnFecnphkKw==
Certificate public key
Use certificate_public_key:<text> to search by certificate public key.
certificate_public_key:MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJ899KGnqHjVuBekYqosp2l8zWbiyu2I62CzaqaouLtqn1nXaQLMdruhlNN9ShCPfCM2JAROVjrd1PwhxLvJxAMbC+UJz2914SRn+lhFQl7yo03t+OoobwSXyj+ukbOHp1lYklYjMauScZScIDdPmLEjwDa8pfSr2TQoihjSDeawIDAQAB
Certificate comments
Use certificate_comments:<text> to search comments on a certificate.
certificate_comments:"our self signed wildcard"
Certificate self-signed
Use certificate_self_signed:<boolean> to search for self-signed certificates.
certificate_self_signed:true
Certificate hidden
Use certificate_hidden:<boolean> to search for certificates hidden from the inventory.
certificate_hidden:true
Certificate signature algorithm insecure
Use certificate_signature_algorithm_insecure:<boolean> to search for certificates with insecure signature algorithms.
certificate_signature_algorithm_insecure:true
Certificate public key insecure
Use certificate_public_key_insecure:<boolean> to search for certificates with insecure public key algorithm and key size combinations.
certificate_public_key_insecure:true
Certificate is CA
Use certificate_is_ca:<boolean> to search for certificates that are certificate authorities (CAs).
certificate_is_ca:true