Internet-scanning summary for a single (entity, port) pair — current state and open/closed history.
Premium featurePorts and Services data is only available to VirusTotal Enterprise users. Vulnerability data is only returned to users whose subscription includes vulnerability intelligence.
A Port Info object summarises what VirusTotal's internet scanning has observed for one network port of one entity (an IP address or a domain): when the port was first and last seen, whether it is currently open, and a snapshot of its most recent analysis. It is identified by {entity}:{port} (e.g. 1.2.3.4:443). The full time-series of individual scans is exposed through the Port Analysis object, reachable via the analysis relationship.
Object Attributes
netloc: <string> the entity (IP address or domain) this port belongs to.entity_type: <string> the kind of entitynetlocrefers to (e.g. the
network-location entity type used internally to distinguish IPs from domains).port: <integer> the port number.status: <string> current port state. One of:PORT_INFO_STATUS_OPEN— the port is currently open.PORT_INFO_STATUS_CLOSED— the port is closed.PORT_INFO_STATUS_RECENTLY_CLOSED— the port was open recently but is now closed.null— state not yet determined.
first_seen: <integer> Unix epoch UTC time (seconds) when this (entity, port)
pair was first observed by scanning.last_seen: <integer> Unix epoch UTC time (seconds) when this (entity, port)
pair was last observed by scanning (open or closed).open_since: <integer> Unix epoch UTC time (seconds) marking the start of the
current continuous open streak. Only returned when the port is open; absent
(null) whenstatusisPORT_INFO_STATUS_CLOSEDor
PORT_INFO_STATUS_RECENTLY_CLOSED. If the port opened on day 1, closed on
day 10, and reopened on day 15,open_sinceis day 15.last_seen_open: <integer> Unix epoch UTC time (seconds) of the most recent
scan that found the port open. When the port is currently open this equals the
date of the latest analysis; when closed/recently-closed it is the date of the
last analysis in which the port was still open.nullif never seen open.latest_analysis: <dictionary> theattributesof the most recent
Port Analysis for this port (same shape as that
object's attribute set), ornullif no analysis exists. This is a convenience
snapshot; use theanalysisrelationship to page through the full history.
Relationships
In addition to the previously described attributes, Port Info objects contain relationships with other objects in our dataset that can be retrieved as explained in the Relationships section. The available relationships are described in the following table:
| Relationship | Description | Accessibility | Return object type |
|---|---|---|---|
analysis | The scan history for this (entity, port): individual dated port analyses, most recent first. | Same users who can read Port Info. | List of Port Analysis objects. |
{
"type": "port_info",
"id": <string>,
"attributes": {
"netloc": <string>,
"entity_type": <string>,
"port": <integer>,
"status": <string>,
"first_seen": <integer>,
"last_seen": <integer>,
"open_since": <integer>,
"last_seen_open": <integer>,
"latest_analysis": <dictionary>
},
"links": {
"self": <string>
}
}{
"data": {
"type": "port_info",
"id": "1.2.3.4:443",
"attributes": {
"netloc": "1.2.3.4",
"entity_type": "ip_address",
"port": 443,
"status": "PORT_INFO_STATUS_OPEN",
"first_seen": 1700000000,
"last_seen": 1718534400,
"open_since": 1716000000,
"last_seen_open": 1718534400,
"latest_analysis": {
"netloc": "1.2.3.4",
"port": 443,
"date": 1718534400,
"risk_rating": "RISK_RATING_LOW",
"transport": "TRANSPORT_TCP",
"is_tls": true,
"port_state": "open",
"port_service": {
"protocol": "https",
"product": "nginx",
"version": "1.25.3"
}
}
},
"links": {
"self": "https://www.virustotal.com/api/v3/port_infos/1.2.3.4:443"
}
}
}