Core search filters
10 filters
Domains, hosts, technologies, and basic asset attributes.
| Filter | Description | Examples |
|---|---|---|
domain
text |
Domain (required for all filters) | |
ip
text |
IP address associated with the asset | |
tech
text |
Identified technologies and frameworks | |
host
text |
Specific host or asset | |
subdomain
text ยท same as host |
Subdomain matching | |
tld
text |
Top-level domain | |
tag
text |
Asset category tags | |
organization
text |
Organization the asset is registered to | |
is_cdn
boolean |
Assets behind a CDN or DDoS-prevention edge | |
cdn
text |
CDN or DDoS-prevention provider by name |
Ports, connectivity, and DNS records
12 filters
| Filter | Description | Examples |
|---|---|---|
port
integer |
Network port number | |
has_private_ip
boolean |
Has private IP address associated with the asset | |
has_ipv6
boolean |
Has IPv6 address | |
is_live
boolean |
Is the asset currently live | |
is_resolvable
boolean |
Is the asset resolvable via DNS | |
dns_a
text |
Type A DNS records |
|
dns_aaaa
text |
Type AAAA DNS records (IPv6) |
|
dns_cname
text |
Type CNAME DNS records |
|
dns_mx
text |
Type MX DNS records (mail servers) |
|
dns_txt
text |
Type TXT DNS records |
|
dns_ptr
text |
Type PTR DNS records (reverse DNS) |
|
dns_ns
text |
Type NS DNS records (name servers) |
Headers, responses, and web content
3 filters
| Filter | Description | Examples |
|---|---|---|
http_title
text |
HTTP page title | |
http_status_code
integer |
HTTP status code | |
http_favicon_hash
text |
HTTP favicon MD5 hash |
Country, city, and ASN
4 filters
| Filter | Description | Examples |
|---|---|---|
country_code
text |
Country code (ISO 3166-1 alpha-2) | |
country
text ยท same as country_code |
Country (same as country_code) |
|
city
text |
City location | |
asn
integer |
Autonomous System Number |
Cloud providers and regions
3 filters
| Filter | Description | Examples |
|---|---|---|
is_cloud
boolean |
Asset running on cloud infrastructure | |
cloud_provider
text |
Cloud provider name (AWS, Azure, GCP, etc.) | |
cloud_region
text |
Cloud provider region |
Products, services, and technology stacks
2 filters
| Filter | Description | Examples |
|---|---|---|
product
text |
Identified product or software | |
service
text |
Identified service type |
SSL/TLS certificate attributes
13 filters
| Filter | Description | Examples |
|---|---|---|
cert_issuer_common_name
text |
Certificate issuer common name | |
cert_issuer_organization
text |
Certificate issuer organization | |
cert_issuer_country
text |
Certificate issuer country | |
cert_issuer_serial_number
text |
Certificate issuer serial number. Accepted, but FullHunt does not currently populate this field, so it returns no assets. | — |
cert_signature_algorithm
text |
Certificate signature algorithm | |
cert_subject_common_name
text |
Certificate subject common name | |
cert_subject_country
text |
Certificate subject country | |
cert_subject_province
text |
Certificate subject province/state | |
cert_subject_locality
text |
Certificate subject locality/city | |
cert_subject_organization
text |
Certificate subject organization | |
cert_sha256_fingerprint
text |
Certificate SHA256 fingerprint | |
cert_md5_fingerprint
text |
Certificate MD5 fingerprint | |
cert_sha1_fingerprint
text |
Certificate SHA1 fingerprint |
Search tips
Combining filters
Use spaces to combine multiple filters into one query.
domain:kaspersky.com port:443 tech:nginx
Exact matches
Use quotation marks for exact phrase matching.
http_title:"Login Page"
Boolean filters
Toggle asset properties with true or false values.
domain:kaspersky.com is_cloud:true is_live:true
Complex queries
Stack filters for precise asset discovery.
domain:kaspersky.com is_cloud:true port:443
Ready to query your attack surface?
Combine 47 filters to discover, monitor, and secure your external assets with precision.