Assets
Asset reference for Security.
This page documents the following assets:
- Host — Host Vulnerabilities
- Vulnerability — Represents a vulnerability detected on a host
Host
Host Vulnerabilities
Schema
The following properties describe a Host:
| Property | Type | Description |
|---|---|---|
compute_id | string | |
compute_type | string | |
count | integer | |
datacenter | string | |
host_id | integer | |
host_web_url | string | |
instance | string | |
name | string | |
risk_score | integer | |
team | string | |
vulnerabilities | list(string) |
Examples
Vulnerability
Represents a vulnerability detected on a host
Schema
The following properties describe a Vulnerability:
| Property | Type | Description |
|---|---|---|
asset_criticality_scope | string | Criticality scope of the asset |
asset_risk_score | string | Risk score of the asset |
category | string | Category of the vulnerability |
cves | list(object) | List of CVEs related to this vulnerability |
detection_age_days | integer | Number of days since the vulnerability was first detected |
diagnosis | string | Diagnosis of the vulnerability |
first_found_datetime Required | string | Timestamp when the vulnerability was first found |
host_id | integer | Unique ID of the host |
host_name | string | Hostname of the affected asset |
host_web_url | string | URL to view the host details in the UI |
ip Required | string | IP address of the affected host |
is_ignored | integer | Whether the vulnerability is ignored (1 = yes, 0 = no) |
last_found_datetime Required | string | Timestamp when the vulnerability was last seen |
last_test_datetime Required | string | Timestamp of the last test |
last_update_datetime Required | string | Timestamp of the last update |
overdue | boolean | Computed: true when detection age exceeds remediation SLA (>30 days for critical/high, >90 days for medium) |
patchable | boolean | Indicates if the vulnerability is patchable |
pci_flag | boolean | Indicates if the vulnerability impacts PCI compliance |
qds | integer | QDS score |
qds_severity | string | QDS severity as a string |
qid | integer | Qualys QID |
results | list(string) | Results of the vulnerability |
severity | integer | Severity score |
severity_level | integer | Severity level (different from general severity) |
ssl | integer | Indicates if SSL is involved |
status | string | Status of the vulnerability |
times_found | integer | Number of times the vulnerability has been found |
title | string | Title of the vulnerability |
true_risk_score | string | True calculated risk score |
type | string | Type of vulnerability |
unique_vulnerability_id | integer | Unique identifier for the vulnerability instance |
vulnerability_type | string | Vulnerability classification/type |