Image Search Parameters
The API has endpoints for querying our data in which you can use free text search together with one or more of the filters listed below.
Free Text: not specifying a field will search on the full records, which can include other information not stated below. Although free text search without specifying fields is available, it might be processed differently from searching on specific fields. For better results, always specify search fields.
Conditionals: the following conditionals are available: NOT, AND, OR. Must be UPPERCASE. You can also use the minus sign (-) as a replacement for the NOT conditional. By default, a sequence of search terms without conditionals will be interpreted as if using the AND conditional.
Comparison: you can use comparison operators on number fields. E.g. field:>100.
Field existence or omission: you can search for records that have a specific field by using _exists_:field. Conversely, for records missing a field it would be NOT _exists_:field.
Wildcards: you can use wildcards on your query terms. However, for the best results and performance, try to be as specific as you can. E.g. field:security*
String fields: if the string is expected to have spaces, some kind of punctuation in the middle, or special symbols, try quoting the search terms, i.e. instead of querying field:value try field:"value". You can also try instead field.keyword:"value". The first one will search for any occurrence of any of the words in value, while the second one will search for an exact match of the string. Finally, in the case of some special symbols, you might require escaping in order to make the query valid.
Regular Expressions: regular expressions are not supported at the moment.
Search by AS name.
Search by ASN.
Search by timestamp.
e.g. ts:[2018-09-01 TO 2018-10-01] ts:2018-09-01
Search using ISO2 Country Codes.
Search by IP address or CIDR.
e.g ip:"192.168.1.1/24" or ip:192.168.1.1
Search for IPv6 results:
Search using city names.
Search using country names.
Search by port number.
Search by protocol. Can be TCP or UDP.
Search for images with faces detected.
Search by image height (supports ranges).
Search by RDNS.
Search by RDNS root.
Search by tags. Can be mobile, rdp, vnc, windows, x11.
Search by image width (supports ranges).
Search by text found by OCR.