Global InfraGlobal Infra Cloud

Assets

Asset reference for Security.

Edit

This page documents the following assets:

  • Host — Host Vulnerabilities
  • Vulnerability — Represents a vulnerability detected on a host

Host

Host Vulnerabilities

Schema

The following properties describe a Host:

PropertyTypeDescription
compute_id
string
compute_type
string
count
integer
datacenter
string
host_id
integer
host_web_url
string
instance
string
name
string
risk_score
integer
team
string
vulnerabilities
list(string)

Examples


Vulnerability

Represents a vulnerability detected on a host

Schema

The following properties describe a Vulnerability:

PropertyTypeDescription
asset_criticality_scope
stringCriticality scope of the asset
asset_risk_score
stringRisk score of the asset
category
stringCategory of the vulnerability
cves
list(object)List of CVEs related to this vulnerability
detection_age_days
integerNumber of days since the vulnerability was first detected
diagnosis
stringDiagnosis of the vulnerability
first_found_datetime
Required
stringTimestamp when the vulnerability was first found
host_id
integerUnique ID of the host
host_name
stringHostname of the affected asset
host_web_url
stringURL to view the host details in the UI
ip
Required
stringIP address of the affected host
is_ignored
integerWhether the vulnerability is ignored (1 = yes, 0 = no)
last_found_datetime
Required
stringTimestamp when the vulnerability was last seen
last_test_datetime
Required
stringTimestamp of the last test
last_update_datetime
Required
stringTimestamp of the last update
overdue
booleanComputed: true when detection age exceeds remediation SLA (>30 days for critical/high, >90 days for medium)
patchable
booleanIndicates if the vulnerability is patchable
pci_flag
booleanIndicates if the vulnerability impacts PCI compliance
qds
integerQDS score
qds_severity
stringQDS severity as a string
qid
integerQualys QID
results
list(string)Results of the vulnerability
severity
integerSeverity score
severity_level
integerSeverity level (different from general severity)
ssl
integerIndicates if SSL is involved
status
stringStatus of the vulnerability
times_found
integerNumber of times the vulnerability has been found
title
stringTitle of the vulnerability
true_risk_score
stringTrue calculated risk score
type
stringType of vulnerability
unique_vulnerability_id
integerUnique identifier for the vulnerability instance
vulnerability_type
stringVulnerability classification/type

Examples

On this page