Port Analysis

Result of a single internet-scanning probe of one port at one point in time.

🚧

Premium feature

Ports and Services data is only available to VirusTotal Enterprise users. Vulnerability data is only returned to users whose subscription includes vulnerability intelligence.

A Port Analysis object is the result of one scan of one port at one point in time. Where Port Info gives the aggregated current state of a (entity, port) pair, a Port Analysis is a single dated observation: the detected service, banner, TLS status, fingerprints, and any probe-script output captured during that scan. It is identified by {entity}:{port}:{timestamp} (e.g. 1.2.3.4:443:1718534400). The history of analyses for a port is exposed through the Port Info analysis relationship.

Object Attributes

A Port Analysis object contains the following attributes:

  • netloc: <string> the entity (IP address or domain) scanned.
  • entity_type: <string> the kind of entity netloc refers to.
  • port: <integer> the port number scanned.
  • date: <integer> UTC timestamp (seconds) when the scan was performed.
  • risk_rating: <string> risk assessment for the service exposed on this port. One of RISK_RATING_LOW, RISK_RATING_MEDIUM, RISK_RATING_HIGH, or null when not rated.
  • transport: <string> transport protocol used by the scan. One of TRANSPORT_TCP, TRANSPORT_UDP, or null when unspecified.
  • is_tls: <boolean> whether the connection was secured with TLS/SSL. This is a plain boolean with no "unknown" state — a port that was never probed for TLS reads back as false, indistinguishable from "probed, no TLS".
  • port_state: <string> free-text state of the port as reported by the scanner (e.g. open, filtered). null when not set.
  • host_state: <string> network state of the host at scan time. One of HOST_STATE_UP, HOST_STATE_DOWN, or null when unspecified.
  • banner: <string> raw service banner captured from the port.
  • port_service: <dictionary> structured details of the detected service, or null when no service was identified. Common keys (present when detected):
    • protocol: <string> application protocol (e.g. https, ssh).
    • request_source: <string> origin/source of the probe request.
    • product: <string> detected product name.
    • version: <string> detected product version.
    • cpes: <list of dictionaries> CPE identifiers for the detected software. Each entry is { "cpe": <raw CPE 2.2/2.3 string>, "product": <human-readable product>, "version": <human-readable version> } (the readable fields are derived from the CPE; empty string when not extractable).
    • A service-specific block depending on the protocol: http ({ body_sha256, transfer_encoding[], content_length, headers[{key, value}], http_protocol{major, minor, name}, status_code, status_line }), ssh ({ server_id{raw, software, version, comment}, host_key_fingerprint, host_key_type, is_password_auth_enabled }), smtp ({ auth_methods[] }), or rdp ({ fingerprint, os_version, target_name }).
  • os_type: <string> host operating system name/type inferred from stack behaviour. null when not inferred.
  • device_type: <string> type of hardware device detected (e.g. router, webcam). null when not detected.
  • hostname: <string> hostname/DNS name associated with the service. null when none.
  • extra_info: <string> extra textual context extracted by the scanner. null when none.
  • scripts: <list of dictionaries> output of custom probe/vulnerability scripts run by the scanner. Each entry is { "id": <script identifier>, "output": <plaintext output> }. null when no scripts ran.

Relationships

In addition to the previously described attributes, Port Analysis objects contain relationships with other objects in our dataset that can be retrieved as explained in the Relationships section. The available relationships are described in the following table:

RelationshipDescriptionAccessibilityReturn object type
vulnerabilitiesVulnerabilities associated with this port analysis — e.g. CVEs whose affected-product CPEs match the service detected on the port.Users whose licence includes vulnerability intelligence; empty for other users.List of collections of type vulnerability.
{
  "type": "port_analysis",
  "id": <string>,
  "attributes": {
    "netloc": <string>,
    "entity_type": <string>,
    "port": <integer>,
    "date": <integer>,
    "risk_rating": <string>,
    "transport": <string>,
    "is_tls": <boolean>,
    "port_state": <string>,
    "host_state": <string>,
    "banner": <string>,
    "port_service": <dictionary>,
    "os_type": <string>,
    "device_type": <string>,
    "hostname": <string>,
    "extra_info": <string>,
    "scripts": <list of dictionaries>
  },
  "links": {
    "self": <string>
  }
}
{
  "data": {
    "type": "port_analysis",
    "id": "1.2.3.4:443:1718534400",
    "attributes": {
      "netloc": "1.2.3.4",
      "entity_type": "ip_address",
      "port": 443,
      "date": 1718534400,
      "risk_rating": "RISK_RATING_MEDIUM",
      "transport": "TRANSPORT_TCP",
      "is_tls": true,
      "port_state": "open",
      "host_state": "HOST_STATE_UP",
      "banner": "HTTP/1.1 200 OK ...",
      "os_type": "Linux",
      "device_type": null,
      "hostname": "www.example.com",
      "extra_info": null,
      "port_service": {
        "protocol": "https",
        "product": "nginx",
        "version": "1.25.3",
        "cpes": [
          {
            "cpe": "cpe:2.3:a:nginx:nginx:1.25.3:*:*:*:*:*:*:*",
            "product": "Nginx Nginx",
            "version": "1.25.3"
          }
        ],
        "http": {
          "status_code": 200,
          "status_line": "200 OK",
          "content_length": 1234,
          "http_protocol": { "major": 1, "minor": 1, "name": "HTTP" },
          "headers": [{ "key": "Server", "value": "nginx" }]
        }
      },
      "scripts": [
        { "id": "ssl-cert", "output": "Subject: CN=www.example.com ..." }
      ]
    },
    "links": {
      "self": "https://www.virustotal.com/api/v3/port_analyses/1.2.3.4:443:1718534400"
    }
  }
}