Premium featurePorts and Services data is only available to VirusTotal Enterprise users. Vulnerability data is only returned to users whose subscription includes vulnerability intelligence.
Returns one row per technology (product and version) detected by internet scanning on any port of the IP address, with the ports where it was found and the vulnerabilities that affect it. A vulnerability is attached to a technology when their CPEs match; if a vulnerability found on a port matches none of that port's technologies, it is attached to all of them.
Each row contains:
technology: <string> product name.version: <string> product version (empty string if unknown).ports: <list of integers> ports where the technology was detected, sorted.vulnerabilities: <list of dictionaries> vulnerabilities affecting the technology. Each one contains:id: <string> vulnerability collection ID (e.g.vulnerability--cve-2021-23017).cve_id: <string> CVE identifier.mve_id: <string> Mandiant vulnerability identifier, if any.risk_rating: <string> VirusTotal risk rating of the vulnerability.cvss: <dictionary> CVSS scores, same format as in the vulnerability collection.epss: <dictionary> EPSS score and percentile, same format as in the vulnerability collection.
Filtering
Use the filter parameter to narrow the rows. It accepts these modifiers, which can be combined (all must match):
technology:<text>: technology name contains the text.version:<text>: version contains the text.port:<number>: the technology was found on that port.cve:<text>: a vulnerability's CVE or MVE identifier contains the text.
Any free-text term must match the technology, version, a port or a vulnerability identifier. Example: filter=technology:nginx port:443.
Ordering
By default rows are sorted by their most severe vulnerability first. Use order with technology, version, vulnerabilities_count or max_severity, followed by + (ascending) or - (descending). Example: order=vulnerabilities_count-.
