Service inventory

View as Markdown

When viewing services, use these keywords to search and filter.

Ports

Use port:<number> to search TCP and UDP services by port number. This search term supports numerical comparison operators (>, >=, <, <=, =).

port:<=25

TCP ports

Use tcp:<number> to search TCP services by port number.

tcp:53

Use service_ports_tcp:=<list> to find all services on assets with a specific list of TCP ports open. List the values in ascending numerical order, separated by commas.

service_ports_tcp:=80,443

UDP ports

Use udp:<number> to search UDP services by port number.

udp:443

Use service_ports_udp:=<list> to find all services on assets with a specific list of UDP ports open. List the values in ascending numerical order, separated by commas.

service_ports_udp:=53,123

Transport

Use transport:<term> to search the transport of a service by name.

transport:tcp
transport:udp
transport:icmp

Protocol

Use service_protocols:<term> (or protocol:<term> for short) to search the protocols associated with services.

protocol:http
protocol:telnet

Assets with product

Use service_products:<term> (or product:<term> for short) to search the identified service products associated with an asset and return all services for the matching assets.

product:openssh
service_products:nginx

Virtual host (vHost)

Use vhost:<text> to search the virtual hosts associated with a service by name.

vhost:"www"

Address

Use the service_address keyword to match the service IP address.

service_address:192.168.0.1

Public address

Use the keyword service_has_public and the syntax service_has_public:<boolean> to locate any service with a non-reserved IP address.

The term is a boolean value:

  • true, t, 1, and yes represent true
  • false, f, 0, and no represent false
service_has_public:true

Private address

Use the keyword service_has_private and the syntax service_has_private:<boolean> to locate any service with a private IP address.

The term is a boolean value:

  • true, t, 1, and yes represent true
  • false, f, 0, and no represent false
service_has_private:false

IPv6 address

Use the keyword service_has_ipv6 and the syntax service_has_ipv6:<boolean> to locate any service with an identified IPv6 address.

The term is a boolean value:

  • true, t, 1, and yes represent true
  • false, f, 0, and no represent false
service_has_ipv6:false

Link-local IPv6 address

Use the keyword service_has_link_local and the syntax service_has_link_local:<boolean> to locate any service with an identified IPv6 link local (fe80::) address.

The term is a boolean value:

  • true, t, 1, and yes represent true
  • false, f, 0, and no represent false
service_has_link_local:true

Assets with outlier score

Use outlier_score:<value> to search the calculated outlier score of assets and return all services on those assets. The outlier score ranges from 0 to 5 inclusive. This search term supports numerical comparison operators (>, >=, <, <=, =).

outlier_score:>2
outlier_score:0

Assets with MAC address vendors

Use mac_vendor:<text> to search the vendors associated with an asset’s MAC addresses and return all services on those assets.

mac_vendor:Apple
mac_vendor:"Intel Corporate"

Use newest_mac_vendor:<text> to search only the vendor of the newest MAC address.

newest_mac_vendor:Apple

Assets with MAC address age

Use mac_age:<term> to search the age of the newest MAC address on each asset and return all services on those assets. The term supports the standard runZero time comparison syntax.

mac_age:>1year
mac_age:<6months
mac_age:2019-12-31

Attributes

Use <attribute>:<term> to search any service attribute. This search term supports numerical comparison operators (>, >=, <, <=, =).

If the attribute name conflicts with an existing term, add the _service. prefix to disambiguate the query.

Service attribute searches can be slow, so it is often better to put an _asset.protocol:<term> filter in front of the service attribute query. For example, to search SSH banners, use _asset.protocol:ssh AND banner:<term>.

banner:password
service.product:"OpenSSH"
html.title:"Apache2 Ubuntu Default Page"
http.code:>=500
screenshot.image.size:=>100000
_service.arp.macVendor:Xerox

Use the has keyword to check whether a service has an attribute at all. Invert the has keyword with not has:<term> to find missing fields.

has:"http.head.server"
not has:"html.title"

Certificate fields

Use the following keywords to search the certificates related to a service.

Certificate ID

Use certificate_id:<uuid> to filter by certificate ID.

certificate_id:4e3a2b1c-5d6f-7a8b-9c0d-1e2f3a4b5c6d

Certificate fingerprint (bkhash)

Use fp_bkhash:=<text> to find services with a certificate matching the given bkhash fingerprint anywhere in the certificate chain.

fp_bkhash:=d2c7e8f9a1b2c3d4e5f6

Certificate fingerprint (SHA256)

Use fp_sha256:=<text> to find services with a certificate matching the given SHA256 fingerprint anywhere in the certificate chain.

fp_sha256:=SHA256:19vJPgdyh3BdGgTiSSavQsKx133lzFkJhu51n6fzG+k=

Certificate fingerprint (SHA1)

Use fp_sha1:=<text> to find services with a certificate matching the given SHA1 fingerprint anywhere in the certificate chain.

fp_sha1:=a1b2c3d4e5f6g7h8i9j0

Certificate validity fields

Use the following keywords to search the timestamps of the certificate found on the service. These fields support the standard runZero time comparison syntax.

certificate_valid_from:>2025-01-01
certificate_valid_until:<2026-01-01
certificate_created_at:<1year
certificate_updated_at:>2024-12-01
certificate_last_seen:<2months

Certificate authority key ID

Use certificate_authority_key_id:<text> to search by certificate authority key ID.

certificate_authority_key_id:"c03152cd5a50c3827c7471cecbe99cf97aeb82e2"

Certificate common name (CN)

Use certificate_cn:<text> to search by certificate common name.

certificate_cn:"example.com"

Certificate public key algorithm

Use certificate_public_key_algorithm:<text> to search by public key algorithm.

certificate_public_key_algorithm:rsaEncryption

Certificate serial number

Use certificate_serial:<text> to search by certificate serial number.

certificate_serial:123456

Certificate signature algorithm

Use certificate_signature_algorithm:<text> to search by signature algorithm.

certificate_signature_algorithm:sha256WithRSAEncryption

Certificate subject key ID

Use certificate_subject_key_id:<text> to search by subject key ID.

certificate_subject_key_id:"c769916e10f850397928f62bd34ca6ec39d8e00a"

Certificate type

Use certificate_type:<text> to search by certificate type.

certificate_type:x509

Certificate key usage

Use certificate_key_usage:<text> to search by key usage.

certificate_key_usage:"digitalSignature"

Certificate extended key usage

Use certificate_ext_key_usage:<text> to search by extended key usage.

certificate_ext_key_usage:"serverAuth"

Certificate OCSP server

Use certificate_ocsp_server:<text> to search by OCSP server.

certificate_ocsp_server:http://ocsp.example.com

Certificate CRL distribution points

Use certificate_crl_distribution_points:<text> to search by CRL distribution point.

certificate_crl_distribution_points:http://crl.example.com/

Certificate issuing certificate URL

Use certificate_issuing_certificate_url:<text> to search by issuing certificate URL.

certificate_issuing_certificate_url:http://issuer.example.com/

Certificate signature

Use certificate_signature:<text> to search by certificate signature.

certificate_signature:Bden73ipj8B2xb1Ozy5nOvIytCktGrht5xL7ZfFlaLIBQxbGO5Iuf6Y1yICcEpYqsgSJS6JKCdw5dujmPmGRwBZfVhIbSRb0exFQ4BVp82WtDHfy3QBgcmtusRIxLyM5ToTT2O53NxaSGaw3IRLXZ0y343RGlKOyQxEXeoHbLsVrpmMrqAKkHJkhjTKn7E9WDc4RCsAvd13BIDP80dDWK7OMZJnCDXGQwz2MkAYZNyjRRXA5XeO2cvMq36/4phyJDhIz1oDgDLOFDnCGKkW5gc8MjE0uxFIYTHKNkx+2WIU/j4uQGNAJQbqqCnupV4qjI29PQFnFecnphkKw==

Certificate public key

Use certificate_public_key:<text> to search by certificate public key.

certificate_public_key:MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJ899KGnqHjVuBekYqosp2l8zWbiyu2I62CzaqaouLtqn1nXaQLMdruhlNN9ShCPfCM2JAROVjrd1PwhxLvJxAMbC+UJz2914SRn+lhFQl7yo03t+OoobwSXyj+ukbOHp1lYklYjMauScZScIDdPmLEjwDa8pfSr2TQoihjSDeawIDAQAB

Certificate comments

Use certificate_comments:<text> to search comments on a certificate.

certificate_comments:"our self signed wildcard"

Certificate self-signed

Use certificate_self_signed:<boolean> to search for self-signed certificates.

certificate_self_signed:true

Certificate hidden

Use certificate_hidden:<boolean> to search for certificates hidden from the inventory.

certificate_hidden:true

Certificate signature algorithm insecure

Use certificate_signature_algorithm_insecure:<boolean> to search for certificates with insecure signature algorithms.

certificate_signature_algorithm_insecure:true

Certificate public key insecure

Use certificate_public_key_insecure:<boolean> to search for certificates with insecure public key algorithm and key size combinations.

certificate_public_key_insecure:true

Certificate is CA

Use certificate_is_ca:<boolean> to search for certificates that are certificate authorities (CAs).

certificate_is_ca:true
Updated