Results from scans run using either the Command Line or Constructor appear in a collapsible Results table.
The default columns shown for all queries are:
Domain
- The final domain that a scanned URL resolved toIP
- The final IP that a scanned URL resolved toFavicon Murmur 3
- Favicon Murmur 3 hash of the final domainHTML Body SSDeep
- HTML Body SSDeep of the final domainHTML Title
- HTML Title SSDeep of the final domainResponse
- The HTML repsonse code received from the webserverScan Date
- Timestamp of when a scan was performedSSL SHA1
- SHA1 fingerprint of the domain's SSL certificateSSL Subject Common Name
- Common name of the domain's SSL subject (e.g. DigiCert)URL
- The final URL that was scannedOrigin URL
- The first URL that was scanned
Expanding on results and adding data to a query
Individual search results can be expanded upon from within the results table, providing additional Field name
data that can be added to the current query using an Operator
:
-
Execute a query and obtain a set of results
-
Click
Expand
on the far right -
You'll now see a list of
Field Names
for the expanded result -
To add any of the expanded
Field names
to your current query, left click any text that's colored blue and chose the relevantOperator
-
The chosen
Field name
is added to the end of your query, which can be re-run with the new parameters
Including or excluding data from results
Results tables can be modified to only display certain data types:
-
Click the vertical line icon next to
Basic Raw Data
-
Use the checkboxes to include or exclude certain
Field name
data
Copying, exporting, and viewing raw data
Outputted data can be utilised in a number of ways, using the buttons on the top left of the Results table:
-
Click Copy to copy all visible results to the clipboard, or use the checkboxes to copy selected results
-
Click the Download icon to export visible or selected results either as a CSV or JSON
-
Click
Basic Raw Data
to view the raw data behind all results, and copy the data to the clipboard
Enriching and pivoting on domains and IPs
Web Scanner domain and IP results can be pivoted on or enriched, with one-click from within the Results table:
- Wherever you see a blue domain or IP in the results table, left-click to bring up the contextual menu:
- Click the radial button next to a
Query
(forward) orAnswer
(reverse) lookup type and clickLookup PADNS
to perform a pivot in a new tab - Click the
Enrich
button to open an Enrichment page for your chosen domain or URL in a new tab
Adding results to a feed
Web Scanner results can be added to a feed or collection, or used to create a new feed.
- Left-click your chosen domain or IP from the results set
- Select `Add to Feed/Collection'
- Select
Existing
orNew