Information about an artifact. The artifact can only be an IP.
| JSON representation |
|---|
{ "ip" : string , "prevalence" : { object ( |
| Fields | |
|---|---|
ip
|
IP address of the artifact. This field can be used as an entity indicator for an external destination IP entity. |
prevalence
|
The prevalence of the artifact within the customer's environment. |
firstSeenTime
|
First seen timestamp of the IP in the customer's environment. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
lastSeenTime
|
Last seen timestamp of the IP address in the customer's environment. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
location
|
Location of the Artifact's IP address. |
network
|
Network information related to the Artifact's IP address. |
asOwner
|
Owner of the Autonomous System to which the IP address belongs. |
asn
|
Autonomous System Number to which the IP address belongs. |
jarm
|
The JARM hash for the IP address. ( https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a) . |
lastHttpsCertificate
|
SSL certificate information about the IP address. |
lastHttpsCertificateDate
|
Most recent date for the certificate in VirusTotal. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
regionalInternetRegistry
|
RIR (one of the current RIRs: AFRINIC, ARIN, APNIC, LACNIC or RIPE NCC). |
tags[]
|
Identification attributes |
whois
|
WHOIS information as returned from the pertinent WHOIS server. |
whoisDate
|
Date of the last update of the WHOIS record in VirusTotal. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
tunnels[]
|
VPN tunnels. |
anonymous
|
Whether the VPN tunnels are configured for anonymous browsing or not. |
artifactClient
|
Entity or software accessing or utilizing network resources. |
risks[]
|
This field lists potential risks associated with the network activity. |
Tunnels
VPN tunnels.
| JSON representation |
|---|
{ "provider" : string , "type" : string } |
| Fields | |
|---|---|
provider
|
The provider of the VPN tunnels being used. |
type
|
The type of the VPN tunnels. |
ArtifactClient
Entity or software accessing or utilizing network resources.
| JSON representation |
|---|
{ "behaviors" : [ string ] , "proxies" : [ string ] } |
| Fields | |
|---|---|
behaviors[]
|
The behaviors of the client accessing the network. |
proxies[]
|
The type of proxies used by the client. |

