Full list of Google Threat Intelligence search modifiers

Although we have the most common modifiers documented with description and examples at:

File search modifiers article. IP Address search modifiers article. Domain search modifiers article.

In this article you will find the full list of modifiers for each entity:

List of File modifiers List of IP modifiers List of Domain modifiers List of URL modifiers List of Collection modifiers List of IOC Stream modifiers

List of File modifiers


acronisad_awareahnlab_v3alibaba
alibabacloudalyacandroguardandroguard_package
antiy_avlapexarcabitattack_tactic
attack_techniqueauthentihashavastavast_mobile
avgaviraavwarebabable
baidubehashbehaviourbehaviour_command_executions
behaviour_created_processesbehaviour_filesbehaviour_injected_processesbehaviour_network
behaviour_processesbehaviour_registrybehaviour_servicesbehaviour_signature
behaviour_tagsbitdam_atpbitdefenderbitdefenderfalx
bitdefenderthetabkavbytedefend_ai_analysisbytedefend_ai_verdict
c2aecapacapability_tagcape
cape_linuxcape_sandboxcat_quickhealclamav
cluecmccodeinsightcodeinsight_verdict
collectioncommentcomment_authorcontacted_ip
contentcpcreation_datecrowdsourced_ai_analysis
crowdsourced_idscrowdsourced_yara_rulecrowdstrikectx
cyber_adaptcybereasoncylancecynet
das_security_orcasdeepinstinctdetectiteasydns_lookup_count
docguarddr_web_vxcubedrwebelastic
elf_digestemail_subjectembedded_domainembedded_ip
embedded_urlemsisoftendgameengines
epeset_nod32exodialabs_ai_analysisexodialabs_ai_verdict
exportsf_protf_securef_secure_sandbox
filecondis_dhashfireeyefirst_submitterfortinet
fsgdatagooglegoogle_safe_browsing
google_safebrowsinggoresymgridinsoftgti_score
gti_severitygti_verdicthavehispasec_ai_analysis
hispasec_ai_verdicthttp_conversation_counthuorongikarus
imphashimportsinvinceaip_traffic_count
itwjiangmink7antivirusk7gw
kasperskykingsoftlalang
last_modification_datelastlinelionicls
magicmagikamain_icon_dhashmain_icon_md5
malware_configmalwarebytesmalwationmaxsecure
mbcmcafeemcafeedmetadata
microsoftmicrosoft_sysinternalsmicroworld_escanmin_engines_banker
min_engines_emotetnamenano_antivirusnetguid
nics_ai_analysisnics_ai_verdictnprotectnsfocus_poma
os_x_sandboxppackerpaloalto
pandapermhashpickle_vhashqianxin_reddrip
qihoo_360reaqta_hivereputationresource
rich_pe_header_hashrisingrising_movess
sandbox_namesangforsangfor_zsandscan_timeout
scan_unsupportedsecneurxsecondwritesection
sectionmd5segmentsentinelonesha256
sigchecksigma_criticalsigma_highsigma_low
sigma_mediumsigma_rulesigma_rulesetsimilar-to
sizeskyhighsndboxsophos
ssdeepsubmittersubspansuggested_threat_label
superantispywaresymantecsymantecmobileinsightsymhash
tachyontagtehtristelfhash
tencenttencent_habothehackerthreat_actor
tlshtotaldefensetraffictrapmine
trellixenstrendmicrotrendmicro_housecalltrid
trustlooktypeusvarist
vba32venuseye_sandboxvhashvipre
viritvirobotvirustotal_androboxvirustotal_box_of_apples
virustotal_cuckooforkvirustotal_droidyvirustotal_jsboxvirustotal_jujubox
virustotal_observervirustotal_r2dboxvmraywebroot
whitearmorxcitiumyandexyomi_hunter
zenboxzenbox_androidzenbox_linuxzenbox_macos
zillyazonealarmzonerzscaler

List of IP modifiers


0xsi_f33dabusixacronisadminuslabs
ailabs__monitorapp_alienvaultalphamountain_aialphasoc
antiy_avlarcsight_threat_intelligenceasnaso
autoshunaxurbenkow_ccbfore_ai_precrime
bitdefenderbkavbluelivcertego
chainpatrolchong_lua_daocins_armycluster25
cmc_threat_intelligencecollectioncommentcomment_author
communicating_files_max_detectionscontinentcountrycrdf
criminal_ipcsis_security_groupcyancyble
cyradardesenmascara_medetected_communicating_files_countdetected_downloaded_files_count
detected_referring_files_countdetected_urls_countdns8domain_resolutions_count
downloaded_files_max_detectionsdr_webemergingthreatsemsisoft
enginesermesesetestsecurity
forcepoint_threatseekerfortinetg_datagcp_abuse_intelligence
google_safebrowsinggreensnowgridinsoftgti_score
gti_severitygti_verdicthaveheimdal_security
hunt_io_intelligenceipipsumjarm
juniper_networkskasperskylast_modification_datelionic
lumumalwaredmalwarepatrolmalwares_com_url_checker
malwareurlmimecastnetcraftopenphish
ppathphishfortphishing_database
phishlabsphishtankprebytesprecisionsec
quick_healqutterareferring_files_max_detectionsregional_internet_registry
reputationsafetoopensansec_ecomscanscantitan
scumware_orgseclookupsecurebrainsecurolytics
snort_ip_sample_listsocradarsophosspam404
ssl_issuerssl_not_afterssl_not_beforessl_serial
ssl_subjectssl_thumbprintstopforumspamsucuri_sitecheck
tagthreat_actorthreathivetrustwave
urlhausurlqueryurls_max_detectionsviettel_threat_intelligence
vipreviribackvx_vaultwebroot
whoiswhois_datexcitium_verdict_cloudyandex_safebrowsing
zerocertzerofox

List of Domain modifiers


0xsi_f33da_recorda_ttlaaaa_record
aaaa_ttlabusixacronisadminuslabs
ailabs__monitorapp_alexa_rankalienvaultalphamountain_ai
alphasocantiy_avlarcsight_threat_intelligenceasn
asoautoshunaxurbenkow_cc
bfore_ai_precrimebitdefenderbkavblueliv
caa_recordcaa_ttlcategorycertego
chainpatrolchong_lua_daocins_armycisco_umbrella_rank
cluster25cmc_threat_intelligencecname_recordcname_ttl
collectioncommentcomment_authorcommunicating_files_max_detections
crdfcreation_datecriminal_ipcsis_security_group
cyancyblecyradardepth
desenmascara_medetected_communicating_files_countdetected_downloaded_files_countdetected_referring_files_count
detected_urls_countdname_recorddname_ttldns8
domaindomain_regexdownloaded_files_max_detectionsdr_web
emergingthreatsemsisoftenginesermes
esetestsecurityforcepoint_threatseekerfortinet
fuzzy_domaing_datagcp_abuse_intelligencegoogle_safebrowsing
greensnowgridinsoftgti_scoregti_severity
gti_verdicthaveheimdal_securityhunt_io_intelligence
ipsumjarmjuniper_networkskaspersky
last_modification_datelast_update_datelioniclumu
main_icon_dhashmain_icon_md5majestic_rankmalwared
malwarepatrolmalwares_com_url_checkermalwareurlmimecast
mx_recordmx_ttlnetcraftns_record
ns_ttlopenphishpparent_domain
pathphishfortphishing_databasephishlabs
phishtankpopularity_rankprebytesprecisionsec
quick_healqutterareferring_files_max_detectionsregistrar
reputationsafetoopensansec_ecomscanscantitan
scumware_orgseclookupsecurebrainsecurolytics
snort_ip_sample_listsoa_recordsoa_ttlsocradar
sophosspam404ssl_issuerssl_not_after
ssl_not_beforessl_serialssl_subjectssl_thumbprint
statvoo_rankstopforumspamsucuri_sitechecktag
threat_actorthreathivetldtracker
trustwavettltxt_recordtxt_ttl
urlhausurlqueryurls_max_detectionsviettel_threat_intelligence
vipreviribackvx_vaultwebroot
whoiswhois_datexcitium_verdict_cloudyandex_safebrowsing
zerocertzerofox

List of URL modifiers


0xsi_f33dabusixacronisadminuslabs
ailabs__monitorapp_alienvaultalphamountain_aialphasoc
antiy_avlarcsight_threat_intelligenceasnaso
autoshunaxurbenkow_ccbfore_ai_precrime
bitdefenderbkavbluelivcategory
certegochainpatrolchong_lua_daocins_army
cluster25cmc_threat_intelligencecollectioncomment
comment_authorcontacted_domaincontacted_ipcontent
cookiecookie_valuecrdfcriminal_ip
csis_security_groupcyancyblecyradar
desenmascara_medetected_branddns8dr_web
emergingthreatsemsisoftenginesermes
esetestsecurityexact_pathextension
first_submitterforcepoint_threatseekerfortinetfs
fuzzy_hostnameg_datagcp_abuse_intelligencegoogle_safebrowsing
greensnowgridinsoftgti_scoregti_severity
gti_verdicthaveheaderheader_value
heimdal_securityhostnamehunt_io_intelligenceip
ipsumjuniper_networkskasperskyla
last_modification_datelioniclslumu
main_icon_dhashmain_icon_md5malwaredmalwarepatrol
malwares_com_url_checkermalwareurlmax_url_positivesmeta
mimecastnetcraftopenphishoutgoing_link
pparent_domainpasswordpath
phishfortphishing_databasephishlabsphishtank
portprebytesprecisionsecquery_field
query_valuequick_healqutteraredirects_to
reputationresponse_coderesponse_positivesresponse_sha256
response_sizessafetoopensansec_ecomscan
scantitanschemescumware_orgseclookup
securebrainsecurolyticssha256snort_ip_sample_list
socradarsophosspam404stopforumspam
submittersucuri_sitechecktagtargeted_brand
threat_actorthreathivetitletld
trackertrustwaveurlurlhaus
urlqueryusernameviettel_threat_intelligencevipre
viribackvx_vaultwebrootxcitium_verdict_cloud
yandex_safebrowsingzerocertzerofox

List of Collection modifiers


available_mitigationcapabilitycollection_typecomment
comment_authorcreation_datecvss_2x_base_scorecvss_2x_temporal_score
cvss_3x_base_scorecvss_3x_temporal_scorecvss_4x_scoredescription
detectiondomainsexploitation_consequenceexploitation_state
exploitation_vectorfilesfirst_seenfs
haveipslast_modification_datelast_seen
lsmalware_rolemerged_actormotivation
nameoperating_systemoriginowner
prioritypublisherpublisher_prioritypublisher_relevance
publisher_reliabilityreferencesreport_typerisk_rating
shared_with_mesigma_rulessoftware_toolkitsource_region
suspected_threat_actortagtargeted_industrytargeted_industry_group
targeted_regionthreat_actorthreat_actorsthreat_category
threat_scapeurlsvulnerability_filtervulnerable_cpe
vulnerable_productvulnerable_vendoryara_rulesets

List of IOC Stream modifiers


dateentity_typeoriginsource_type