Skip to content
FullHunt

Search Filters

47 Search filters
7 Filter categories
47 Runnable examples

Core search filters

10 filters

Domains, hosts, technologies, and basic asset attributes.

Filter Description Examples
domain text Domain (required for all filters)
ip text IP address associated with the asset
tech text Identified technologies and frameworks
host text Specific host or asset
subdomain text ยท same as host Subdomain matching
tld text Top-level domain
tag text Asset category tags
organization text Organization the asset is registered to
is_cdn boolean Assets behind a CDN or DDoS-prevention edge
cdn text CDN or DDoS-prevention provider by name

Ports, connectivity, and DNS records

12 filters

Filter Description Examples
port integer Network port number
has_private_ip boolean Has private IP address associated with the asset
has_ipv6 boolean Has IPv6 address
is_live boolean Is the asset currently live
is_resolvable boolean Is the asset resolvable via DNS
dns_a text Type A DNS records
dns_aaaa text Type AAAA DNS records (IPv6)
dns_cname text Type CNAME DNS records
dns_mx text Type MX DNS records (mail servers)
dns_txt text Type TXT DNS records
dns_ptr text Type PTR DNS records (reverse DNS)
dns_ns text Type NS DNS records (name servers)

Headers, responses, and web content

3 filters

Filter Description Examples
http_title text HTTP page title
http_status_code integer HTTP status code
http_favicon_hash text HTTP favicon MD5 hash

Country, city, and ASN

4 filters

Filter Description Examples
country_code text Country code (ISO 3166-1 alpha-2)
country text ยท same as country_code Country (same as country_code)
city text City location
asn integer Autonomous System Number

Cloud providers and regions

3 filters

Filter Description Examples
is_cloud boolean Asset running on cloud infrastructure
cloud_provider text Cloud provider name (AWS, Azure, GCP, etc.)
cloud_region text Cloud provider region

Products, services, and technology stacks

2 filters

Filter Description Examples
product text Identified product or software
service text Identified service type

SSL/TLS certificate attributes

13 filters

Filter Description Examples
cert_issuer_common_name text Certificate issuer common name
cert_issuer_organization text Certificate issuer organization
cert_issuer_country text Certificate issuer country
cert_issuer_serial_number text Certificate issuer serial number. Accepted, but FullHunt does not currently populate this field, so it returns no assets.
cert_signature_algorithm text Certificate signature algorithm
cert_subject_common_name text Certificate subject common name
cert_subject_country text Certificate subject country
cert_subject_province text Certificate subject province/state
cert_subject_locality text Certificate subject locality/city
cert_subject_organization text Certificate subject organization
cert_sha256_fingerprint text Certificate SHA256 fingerprint
cert_md5_fingerprint text Certificate MD5 fingerprint
cert_sha1_fingerprint text Certificate SHA1 fingerprint

Search tips

Combining filters

Use spaces to combine multiple filters into one query.

domain:kaspersky.com port:443 tech:nginx

Exact matches

Use quotation marks for exact phrase matching.

http_title:"Login Page"

Boolean filters

Toggle asset properties with true or false values.

domain:kaspersky.com is_cloud:true is_live:true

Complex queries

Stack filters for precise asset discovery.

domain:kaspersky.com is_cloud:true port:443

Ready to query your attack surface?

Combine 47 filters to discover, monitor, and secure your external assets with precision.