Full list of Google Threat Intelligence search modifiers

Although we have the most common modifiers documented with description and examples at:

File search modifiers article. IP Address search modifiers article. Domain search modifiers article.

In this article you will find the full list of modifiers for each entity:

List of File modifiers List of IP modifiers List of Domain modifiers List of URL modifiers List of Collection modifiers List of IOC Stream modifiers

List of File modifiers


acronisad_awareahnlab_v3alibaba
alibabacloudalyacandroguardandroguard_package
antiy_avlapexarcabitattack_tactic
attack_techniqueauthentihashavastavast_mobile
avgaviraavwarebabable
baidubehashbehaviourbehaviour_command_executions
behaviour_created_processesbehaviour_filesbehaviour_injected_processesbehaviour_network
behaviour_processesbehaviour_registrybehaviour_servicesbehaviour_signature
behaviour_tagsbitdam_atpbitdefenderbitdefenderfalx
bitdefenderthetabkavbytedefend_ai_analysisbytedefend_ai_verdict
c2aecapacapability_tagcape
cape_linuxcape_sandboxcat_quickhealclamav
cluecmccodeinsightcodeinsight_verdict
collectioncommentcomment_authorcontacted_ip
contentcpcreation_datecrowdsourced_ai_analysis
crowdsourced_idscrowdsourced_yara_rulecrowdstrikectx
cyber_adaptcybereasoncylancecynet
das_security_orcasdeepinstinctdetectiteasydns_lookup_count
docguarddr_web_vxcubedrwebelastic
elf_digestemail_subjectembedded_domainembedded_ip
embedded_urlemsisoftendgameengines
epeset_nod32exodialabs_ai_analysisexodialabs_ai_verdict
exportsf_protf_securef_secure_sandbox
filecondis_dhashfireeyefirst_submitterfortinet
fsgdatagooglegoogle_safe_browsing
google_safebrowsinggoresymgridinsoftgti_score
gti_severitygti_verdicthavehispasec_ai_analysis
hispasec_ai_verdicthttp_conversation_counthuorongikarus
imphashimportsinvinceaip_traffic_count
itwjiangmink7antivirusk7gw
kasperskykingsoftlalang
last_modification_datelastlinelionicls
magicmagikamain_icon_dhashmain_icon_md5
malware_configmalwarebytesmalwationmaxsecure
mbcmcafeemcafeedmetadata
microsoftmicrosoft_sysinternalsmicroworld_escanmin_engines_banker
min_engines_emotetnamenano_antivirusnetguid
nics_ai_analysisnics_ai_verdictnprotectnsfocus_poma
omniasec_ai_analysisomniasec_ai_verdictos_x_sandboxp
packerpaloaltopandapermhash
pickle_vhashqianxin_reddripqihoo_360reaqta_hive
reputationresourcerich_pe_header_hashrising
rising_movesssandbox_namesangfor
sangfor_zsandscan_timeoutscan_unsupportedsecneurx
secondwritesectionsectionmd5segment
sentinelonesha256sigchecksigma_critical
sigma_highsigma_lowsigma_mediumsigma_rule
sigma_rulesetsimilar-tosizeskyhigh
sndboxsophosssdeepsubmitter
subspansuggested_threat_labelsuperantispywaresymantec
symantecmobileinsightsymhashtachyontag
tehtristelfhashtencenttencent_habo
thehackerthreat_actortlshtotaldefense
traffictrapminetrellixenstrendmicro
trendmicro_housecalltridtrustlooktype
usvaristvba32venuseye_sandbox
vhashvipreviritvirobot
virustotal_androboxvirustotal_box_of_applesvirustotal_cuckooforkvirustotal_droidy
virustotal_jsboxvirustotal_jujuboxvirustotal_observervirustotal_r2dbox
vmraywebrootwhitearmorxcitium
yandexyomi_hunterzenboxzenbox
zenbox_androidzenbox_linuxzenbox_macoszillya
zonealarmzoner

List of IP modifiers


0xsi_f33dabusixacronisadminuslabs
ailabs__monitorapp_alienvaultalphamountain_aialphasoc
antiy_avlarcsight_threat_intelligenceasnaso
autoshunaxurbenkow_ccbfore_ai_precrime
bitdefenderbkavbluelivcertego
chainpatrolchong_lua_daocins_armycluster25
cmc_threat_intelligencecollectioncommentcomment_author
communicating_files_max_detectionscontinentcountrycrdf
criminal_ipcsis_security_groupcyancyble
cyradardesenmascara_medetected_communicating_files_countdetected_downloaded_files_count
detected_referring_files_countdetected_urls_countdns8domain_resolutions_count
downloaded_files_max_detectionsdr_webemergingthreatsemsisoft
enginesermesesetestsecurity
forcepoint_threatseekerfortinetg_datagcp_abuse_intelligence
google_safebrowsinggreensnowgreynoisegridinsoft
gti_scoregti_severitygti_verdictguardpot
haveheimdal_securityhunt_io_intelligenceip
ipsumjarmjuniper_networkskaspersky
last_modification_datelevelbluelioniclumu
malwaredmalwarepatrolmalwares_com_url_checkermalwareurl
mimecastnetcraftopenphishp
pathphishfortphishing_databasephishlabs
phishtankprebytesprecisionsecquick_heal
qutterareferring_files_max_detectionsregional_internet_registryreputation
safetoopensansec_ecomscanscantitanscumware_org
seclookupsecurebrainsecurolyticssnort_ip_sample_list
socradarsophosspam404ssl_issuer
ssl_not_afterssl_not_beforessl_serialssl_subject
ssl_thumbprintstopforumspamsucuri_sitechecktag
threat_actorthreathiveurlhausurlquery
urls_max_detectionsviettel_threat_intelligencevipreviriback
vx_vaultwebrootwhoiswhois_date
xcitium_verdict_cloudyandex_safebrowsingzerocertzerofox

List of Domain modifiers


0xsi_f33da_recorda_ttlaaaa_record
aaaa_ttlabusixacronisadminuslabs
ailabs__monitorapp_alexa_rankalienvaultalphamountain_ai
alphasocantiy_avlarcsight_threat_intelligenceasn
asoautoshunaxurbenkow_cc
bfore_ai_precrimebitdefenderbkavblueliv
caa_recordcaa_ttlcategorycertego
chainpatrolchong_lua_daocins_armycisco_umbrella_rank
cluster25cmc_threat_intelligencecname_recordcname_ttl
collectioncommentcomment_authorcommunicating_files_max_detections
crdfcreation_datecriminal_ipcsis_security_group
cyancyblecyradardepth
desenmascara_medetected_communicating_files_countdetected_downloaded_files_countdetected_referring_files_count
detected_urls_countdname_recorddname_ttldns8
domaindomain_regexdownloaded_files_max_detectionsdr_web
emergingthreatsemsisoftenginesermes
esetestsecurityforcepoint_threatseekerfortinet
fuzzy_domaing_datagcp_abuse_intelligencegoogle_safebrowsing
greensnowgreynoisegridinsoftgti_score
gti_severitygti_verdictguardpothave
heimdal_securityhunt_io_intelligenceipsumjarm
juniper_networkskasperskylast_modification_datelast_update_date
levelbluelioniclumumain_icon_dhash
main_icon_md5majestic_rankmalwaredmalwarepatrol
malwares_com_url_checkermalwareurlmimecastmx_record
mx_ttlnetcraftns_recordns_ttl
openphishpparent_domainpath
phishfortphishing_databasephishlabsphishtank
popularity_rankprebytesprecisionsecquick_heal
qutterareferring_files_max_detectionsregistrarreputation
safetoopensansec_ecomscanscantitanscumware_org
seclookupsecurebrainsecurolyticssnort_ip_sample_list
soa_recordsoa_ttlsocradarsophos
spam404ssl_issuerssl_not_afterssl_not_before
ssl_serialssl_subjectssl_thumbprintstatvoo_rank
stopforumspamsucuri_sitechecktagthreat_actor
threathivetldttltxt_record
txt_ttlurlhausurlqueryurls_max_detections
viettel_threat_intelligencevipreviribackvx_vault
webrootwhoiswhois_datexcitium_verdict_cloud
yandex_safebrowsingzerocert

List of URL modifiers


0xsi_f33dabusixacronisadminuslabs
ailabs__monitorapp_alienvaultalphamountain_aialphasoc
antiy_avlarcsight_threat_intelligenceasnaso
autoshunaxurbenkow_ccbfore_ai_precrime
bitdefenderbkavbluelivcategory
certegochainpatrolchong_lua_daocins_army
cluster25cmc_threat_intelligencecollectioncomment
comment_authorcontacted_domaincontacted_ipcontent
cookiecookie_valuecrdfcriminal_ip
csis_security_groupcyancyblecyradar
desenmascara_medetected_branddns8dr_web
emergingthreatsemsisoftenginesermes
esetestsecurityexact_pathextension
first_submitterforcepoint_threatseekerfortinetfs
fuzzy_hostnameg_datagcp_abuse_intelligencegoogle_safebrowsing
greensnowgreynoisegridinsoftgti_score
gti_severitygti_verdictguardpothave
headerheader_valueheimdal_securityhostname
hunt_io_intelligenceipipsumjuniper_networks
kasperskylalast_modification_datelevelblue
lioniclslumumain_icon_dhash
main_icon_md5malwaredmalwarepatrolmalwares_com_url_checker
malwareurlmax_url_positivesmetamimecast
netcraftopenphishoutgoing_linkp
parent_domainpasswordpathphishfort
phishing_databasephishlabsphishtankport
prebytesprecisionsecquery_fieldquery_value
quick_healqutteraredirects_toreputation
response_coderesponse_positivesresponse_sha256response_size
ssafetoopensansec_ecomscanscantitan
schemescumware_orgseclookupsecurebrain
securolyticssha256snort_ip_sample_listsocradar
sophosspam404stopforumspamsubmitter
sucuri_sitechecktagtargeted_brandthreat_actor
threathivetitletldtracker
urlurlhausurlqueryusername
viettel_threat_intelligencevipreviribackvx_vault
webrootxcitium_verdict_cloudyandex_safebrowsingzerocert
zerofox

List of Collection modifiers


available_mitigationcapabilitycollection_typecomment
comment_authorcreation_datecvss_2x_base_scorecvss_2x_temporal_score
cvss_3x_base_scorecvss_3x_temporal_scorecvss_4x_scoredescription
detectiondomainsexploitation_consequenceexploitation_state
exploitation_vectorfilesfirst_seenfs
haveipslast_modification_datelast_seen
lsmalware_rolemerged_actormotivation
nameoperating_systemoriginowner
prioritypublisherpublisher_prioritypublisher_relevance
publisher_reliabilityreferencesreport_typerisk_rating
shared_with_mesigma_rulessoftware_toolkitsource_region
suspected_threat_actortagtargeted_industrytargeted_industry_group
targeted_regionthreat_actorthreat_actorsthreat_category
threat_scapeurlsvulnerability_filtervulnerable_cpe
vulnerable_productvulnerable_vendor

List of IOC Stream modifiers


dateentity_typeoriginsource_type