Result of a single internet-scanning probe of one port at one point in time.
Premium featurePorts and Services data is only available to VirusTotal Enterprise users. Vulnerability data is only returned to users whose subscription includes vulnerability intelligence.
A Port Analysis object is the result of one scan of one port at one point in time. Where Port Info gives the aggregated current state of a (entity, port) pair, a Port Analysis is a single dated observation: the detected service, banner, TLS status, fingerprints, and any probe-script output captured during that scan. It is identified by {entity}:{port}:{timestamp} (e.g. 1.2.3.4:443:1718534400). The history of analyses for a port is exposed through the Port Info analysis relationship.
Object Attributes
A Port Analysis object contains the following attributes:
netloc: <string> the entity (IP address or domain) scanned.entity_type: <string> the kind of entitynetlocrefers to.port: <integer> the port number scanned.date: <integer> UTC timestamp (seconds) when the scan was performed.risk_rating: <string> risk assessment for the service exposed on this port. One ofRISK_RATING_LOW,RISK_RATING_MEDIUM,RISK_RATING_HIGH, ornullwhen not rated.transport: <string> transport protocol used by the scan. One ofTRANSPORT_TCP,TRANSPORT_UDP, ornullwhen unspecified.is_tls: <boolean> whether the connection was secured with TLS/SSL. This is a plain boolean with no "unknown" state — a port that was never probed for TLS reads back asfalse, indistinguishable from "probed, no TLS".port_state: <string> free-text state of the port as reported by the scanner (e.g.open,filtered).nullwhen not set.host_state: <string> network state of the host at scan time. One ofHOST_STATE_UP,HOST_STATE_DOWN, ornullwhen unspecified.banner: <string> raw service banner captured from the port.port_service: <dictionary> structured details of the detected service, ornullwhen no service was identified. Common keys (present when detected):protocol: <string> application protocol (e.g.https,ssh).request_source: <string> origin/source of the probe request.product: <string> detected product name.version: <string> detected product version.cpes: <list of dictionaries> CPE identifiers for the detected software. Each entry is{ "cpe": <raw CPE 2.2/2.3 string>, "product": <human-readable product>, "version": <human-readable version> }(the readable fields are derived from the CPE; empty string when not extractable).- A service-specific block depending on the protocol:
http({ body_sha256, transfer_encoding[], content_length, headers[{key, value}], http_protocol{major, minor, name}, status_code, status_line }),ssh({ server_id{raw, software, version, comment}, host_key_fingerprint, host_key_type, is_password_auth_enabled }),smtp({ auth_methods[] }), orrdp({ fingerprint, os_version, target_name }).
os_type: <string> host operating system name/type inferred from stack behaviour.nullwhen not inferred.device_type: <string> type of hardware device detected (e.g.router,webcam).nullwhen not detected.hostname: <string> hostname/DNS name associated with the service.nullwhen none.extra_info: <string> extra textual context extracted by the scanner.nullwhen none.scripts: <list of dictionaries> output of custom probe/vulnerability scripts run by the scanner. Each entry is{ "id": <script identifier>, "output": <plaintext output> }.nullwhen no scripts ran.
Relationships
In addition to the previously described attributes, Port Analysis objects contain relationships with other objects in our dataset that can be retrieved as explained in the Relationships section. The available relationships are described in the following table:
| Relationship | Description | Accessibility | Return object type |
|---|---|---|---|
vulnerabilities | Vulnerabilities associated with this port analysis — e.g. CVEs whose affected-product CPEs match the service detected on the port. | Users whose licence includes vulnerability intelligence; empty for other users. | List of collections of type vulnerability. |
{
"type": "port_analysis",
"id": <string>,
"attributes": {
"netloc": <string>,
"entity_type": <string>,
"port": <integer>,
"date": <integer>,
"risk_rating": <string>,
"transport": <string>,
"is_tls": <boolean>,
"port_state": <string>,
"host_state": <string>,
"banner": <string>,
"port_service": <dictionary>,
"os_type": <string>,
"device_type": <string>,
"hostname": <string>,
"extra_info": <string>,
"scripts": <list of dictionaries>
},
"links": {
"self": <string>
}
}{
"data": {
"type": "port_analysis",
"id": "1.2.3.4:443:1718534400",
"attributes": {
"netloc": "1.2.3.4",
"entity_type": "ip_address",
"port": 443,
"date": 1718534400,
"risk_rating": "RISK_RATING_MEDIUM",
"transport": "TRANSPORT_TCP",
"is_tls": true,
"port_state": "open",
"host_state": "HOST_STATE_UP",
"banner": "HTTP/1.1 200 OK ...",
"os_type": "Linux",
"device_type": null,
"hostname": "www.example.com",
"extra_info": null,
"port_service": {
"protocol": "https",
"product": "nginx",
"version": "1.25.3",
"cpes": [
{
"cpe": "cpe:2.3:a:nginx:nginx:1.25.3:*:*:*:*:*:*:*",
"product": "Nginx Nginx",
"version": "1.25.3"
}
],
"http": {
"status_code": 200,
"status_line": "200 OK",
"content_length": 1234,
"http_protocol": { "major": 1, "minor": 1, "name": "HTTP" },
"headers": [{ "key": "Server", "value": "nginx" }]
}
},
"scripts": [
{ "id": "ssl-cert", "output": "Subject: CN=www.example.com ..." }
]
},
"links": {
"self": "https://www.virustotal.com/api/v3/port_analyses/1.2.3.4:443:1718534400"
}
}
}