---
title: GraphObjectType enum | Wartiva GraphQL API
description: An enumeration of the different types of security graph objects. Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/types/graph-object-type.html
updated: 2026-10-07
---

Graph search · GraphQL enum

# `GraphObjectType` enum

An enumeration of the different types of security graph objects.

## Values

| Enum Value | Description |
|---|---|
| `ACCOUNT_POLICY` | The [AccountPolicy](https://wartiva.com/api-docs/types/account-policy.html) graph object type. |
| `ACTIVE_DIRECTORY` | The [ActiveDirectory](https://wartiva.com/api-docs/types/active-directory.html) graph object type. |
| `ADMINISTRATIVE_TEMPLATES_WINDOWS` | The [AdministrativeTemplatesWindows](https://wartiva.com/api-docs/types/administrative-templates-windows.html) graph object type. |
| `APPLICATION` | The [Application](https://wartiva.com/api-docs/types/application.html) graph object type. |
| `APPLICATION_INSTALL` | The [ApplicationInstall](https://wartiva.com/api-docs/types/application-install.html) graph object type. |
| `APPLICATION_INSTALL_USER_SETTINGS` | The [ApplicationInstallUserSettings](https://wartiva.com/api-docs/types/application-install-user-settings.html) graph object type. |
| `ARP_TABLE_ENTRY` | The [ArpTableEntry](https://wartiva.com/api-docs/types/arp-table-entry.html) graph object type. |
| `AUDIT_POLICY` | The [AuditPolicy](https://wartiva.com/api-docs/types/audit-policy.html) graph object type. |
| `DEVICE` | The [Device](https://wartiva.com/api-docs/types/device.html) graph object type. |
| `DEVICE_MANUFACTURER` | The [DeviceManufacturer](https://wartiva.com/api-docs/types/device-manufacturer.html) graph object type. |
| `DEVICE_MODEL` | The [DeviceModel](https://wartiva.com/api-docs/types/device-model.html) graph object type. |
| `DISK` | The [Disk](https://wartiva.com/api-docs/types/disk.html) graph object type. |
| `DISK_MOUNT` | The [DiskMount](https://wartiva.com/api-docs/types/disk-mount.html) graph object type. |
| `ENDPOINT` | The [Endpoint](https://wartiva.com/api-docs/types/endpoint.html) graph object type. |
| `ENDPOINT_GROUP` | The [EndpointGroup](https://wartiva.com/api-docs/types/endpoint-group.html) graph object type. |
| `ENDPOINT_PATH` | The [EndpointPath](https://wartiva.com/api-docs/types/endpoint-path.html) graph object type. |
| `ENDPOINT_USER` | The [EndpointUser](https://wartiva.com/api-docs/types/endpoint-user.html) graph object type. |
| `EXECUTABLE` | The [Executable](https://wartiva.com/api-docs/types/executable.html) graph object type. |
| `FINDING` | The [Finding](https://wartiva.com/api-docs/types/finding.html) graph object type. |
| `INTERFACE` | The [Interface](https://wartiva.com/api-docs/types/interface.html) graph object type. |
| `ISSUE` | The [Issue](https://wartiva.com/api-docs/types/issue.html) graph object type. |
| `LOCAL_POLICIES` | The [LocalPolicies](https://wartiva.com/api-docs/types/local-policies.html) graph object type. |
| `LOCATION` | The [Location](https://wartiva.com/api-docs/types/location.html) graph object type. |
| `LOGON_SESSION` | The [LogonSession](https://wartiva.com/api-docs/types/logon-session.html) graph object type. |
| `NETWORK` | The [Network](https://wartiva.com/api-docs/types/network.html) graph object type. |
| `NETWORK_PREFIX` | The [NetworkPrefix](https://wartiva.com/api-docs/types/network-prefix.html) graph object type. |
| `OPEN_PORT` | The [OpenPort](https://wartiva.com/api-docs/types/open-port.html) graph object type. |
| `POSITION_SEEN` | The [PositionSeen](https://wartiva.com/api-docs/types/position-seen.html) graph object type. |
| `ROUTE` | The [Route](https://wartiva.com/api-docs/types/route.html) graph object type. |
| `RULE` | The [Rule](https://wartiva.com/api-docs/types/rule.html) graph object type. |
| `SECURITY` | The [Security](https://wartiva.com/api-docs/types/security.html) graph object type. |
| `SERVICE` | The [Service](https://wartiva.com/api-docs/types/service.html) graph object type. |
| `SOFTWARE_UPDATE_PREFERENCES` | The [SoftwareUpdatePreferences](https://wartiva.com/api-docs/types/software-update-preferences.html) graph object type. |
| `SYSTEM_SERVICE` | The [SystemService](https://wartiva.com/api-docs/types/system-service.html) graph object type. |
| `SYSTEM_SETTINGS` | The [SystemSettings](https://wartiva.com/api-docs/types/system-settings.html) graph object type. |
| `UNRECOGNIZED` | Unrecognized graph object type. |
| `USER_SYSTEM_SETTINGS` | The [UserSystemSettings](https://wartiva.com/api-docs/types/user-system-settings.html) graph object type. |
| `WLAN_INTERFACE` | The [WlanInterface](https://wartiva.com/api-docs/types/wlan-interface.html) graph object type. |
| `WLAN_INTERFACE_CONNECTION` | The [WlanInterfaceConnection](https://wartiva.com/api-docs/types/wlan-interface-connection.html) graph object type. |
| `WLAN_NETWORK` | The [WlanNetwork](https://wartiva.com/api-docs/types/wlan-network.html) graph object type. |
| `WLAN_ACCESS_POINT` | The [WlanAccessPoint](https://wartiva.com/api-docs/types/wlan-access-point.html) graph object type. |

## Used by

- [`AccountPolicy`](https://wartiva.com/api-docs/types/account-policy.html) type: The local account password and lockout policy in effect on an Endpoint.
- [`ActiveDirectory`](https://wartiva.com/api-docs/types/active-directory.html) type: The Active Directory (AD) domain membership and directory-binding configuration of an Endpoint.
- [`AdministrativeTemplatesWindows`](https://wartiva.com/api-docs/types/administrative-templates-windows.html) type: The Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.
- [`Application`](https://wartiva.com/api-docs/types/application.html) type: A software product as an identity shared across an organization, independent of any one computer.
- [`ApplicationInstall`](https://wartiva.com/api-docs/types/application-install.html) type: One installed copy of an application on one Endpoint.
- [`ApplicationInstallUserSettings`](https://wartiva.com/api-docs/types/application-install-user-settings.html) type: The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
- [`ArpTableEntry`](https://wartiva.com/api-docs/types/arp-table-entry.html) type: One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…
- [`AuditPolicy`](https://wartiva.com/api-docs/types/audit-policy.html) type: The security event auditing configuration of an Endpoint.
- [`Device`](https://wartiva.com/api-docs/types/device.html) type: A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
- [`DeviceManufacturer`](https://wartiva.com/api-docs/types/device-manufacturer.html) type: A hardware vendor that made one or more discovered Device objects in an organization.
- [`DeviceModel`](https://wartiva.com/api-docs/types/device-model.html) type: A specific product model, made by a DeviceManufacturer, that one or more discovered Device objects in an organization are instances of.
- [`Disk`](https://wartiva.com/api-docs/types/disk.html) type: A physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…
- [`DiskMount`](https://wartiva.com/api-docs/types/disk-mount.html) type: A file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).
- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`EndpointGroup`](https://wartiva.com/api-docs/types/endpoint-group.html) type: An operating system or domain group observed on an Endpoint.
- [`EndpointPath`](https://wartiva.com/api-docs/types/endpoint-path.html) type: The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…
- [`EndpointUser`](https://wartiva.com/api-docs/types/endpoint-user.html) type: An operating system or domain user account observed on an Endpoint.
- [`Executable`](https://wartiva.com/api-docs/types/executable.html) type: A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.
- [`Finding`](https://wartiva.com/api-docs/types/finding.html) type: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
- [`Interface`](https://wartiva.com/api-docs/types/interface.html) type: A network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…
- [`Issue`](https://wartiva.com/api-docs/types/issue.html) type: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
- [`LocalPolicies`](https://wartiva.com/api-docs/types/local-policies.html) type: The local security policy settings of an Endpoint.
- [`Location`](https://wartiva.com/api-docs/types/location.html) type: A physical place identified by its global plus code (Open Location Code), with a street address resolved by reverse geocoding.
- [`LogonSession`](https://wartiva.com/api-docs/types/logon-session.html) type: A user logon session observed on an Endpoint, identified by the username and the time the session started.
- [`Network`](https://wartiva.com/api-docs/types/network.html) type: An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
- [`NetworkPrefix`](https://wartiva.com/api-docs/types/network-prefix.html) type: A specific IP address together with its subnet prefix length (e.g.
- [`OpenPort`](https://wartiva.com/api-docs/types/open-port.html) type: One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
- [`PositionSeen`](https://wartiva.com/api-docs/types/position-seen.html) type: A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.
- [`Route`](https://wartiva.com/api-docs/types/route.html) type: One entry in an Endpoint's IP routing table, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.
- [`Security`](https://wartiva.com/api-docs/types/security.html) type: The security posture of an Endpoint: its firewall, anti-malware and disk encryption state, summarized as per-component health ratings in Health.
- [`Service`](https://wartiva.com/api-docs/types/service.html) type: A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
- [`SoftwareUpdatePreferences`](https://wartiva.com/api-docs/types/software-update-preferences.html) type: The operating system update configuration of an Endpoint and the updates currently available to it.
- [`SystemService`](https://wartiva.com/api-docs/types/system-service.html) type: A background service or daemon configured on an Endpoint.
- [`SystemSettings`](https://wartiva.com/api-docs/types/system-settings.html) type: The machine-wide operating system configuration of an Endpoint.
- [`UserSystemSettings`](https://wartiva.com/api-docs/types/user-system-settings.html) type: The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.
- [`WlanAccessPoint`](https://wartiva.com/api-docs/types/wlan-access-point.html) type: A Wi-Fi access point radio, identified by the network name (SSID) it broadcasts and its BSSID, as heard by managed endpoints scanning for nearby…
- [`WlanInterface`](https://wartiva.com/api-docs/types/wlan-interface.html) type: A wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.
- [`WlanNetwork`](https://wartiva.com/api-docs/types/wlan-network.html) type: A Wi-Fi network identified by its network name (SSID), visible to managed endpoints when they scan for nearby networks on Windows, macOS, or Linux.
- [`GraphObjectTypeInfo`](https://wartiva.com/api-docs/types/graph-object-type-info.html) type: Describes a single graph object type: its enum value, the relationships it participates in, and the properties available for use in search query…
- [`GraphObjectTypesInput`](https://wartiva.com/api-docs/types/graph-object-types-input.html) input: Input for selecting which graph object types are returned by a graph object types query.

And 10 more.

## Related types

- [`AccountPolicy`](https://wartiva.com/api-docs/types/account-policy.html) The local account password and lockout policy in effect on an Endpoint.
- [`ActiveDirectory`](https://wartiva.com/api-docs/types/active-directory.html) The Active Directory (AD) domain membership and directory-binding configuration of an Endpoint.
- [`AdministrativeTemplatesWindows`](https://wartiva.com/api-docs/types/administrative-templates-windows.html) The Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.
- [`Application`](https://wartiva.com/api-docs/types/application.html) A software product as an identity shared across an organization, independent of any one computer.
- [`ApplicationInstall`](https://wartiva.com/api-docs/types/application-install.html) One installed copy of an application on one Endpoint.
- [`ApplicationInstallUserSettings`](https://wartiva.com/api-docs/types/application-install-user-settings.html) The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
- [`ArpTableEntry`](https://wartiva.com/api-docs/types/arp-table-entry.html) One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…
- [`AuditPolicy`](https://wartiva.com/api-docs/types/audit-policy.html) The security event auditing configuration of an Endpoint.
- [`Device`](https://wartiva.com/api-docs/types/device.html) A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
- [`DeviceManufacturer`](https://wartiva.com/api-docs/types/device-manufacturer.html) A hardware vendor that made one or more discovered Device objects in an organization.
- [`DeviceModel`](https://wartiva.com/api-docs/types/device-model.html) A specific product model, made by a DeviceManufacturer, that one or more discovered Device objects in an organization are instances of.
- [`Disk`](https://wartiva.com/api-docs/types/disk.html) A physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…
- [`DiskMount`](https://wartiva.com/api-docs/types/disk-mount.html) A file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).
- [`Endpoint`](https://wartiva.com/api-docs/types/endpoint.html) A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
- [`EndpointGroup`](https://wartiva.com/api-docs/types/endpoint-group.html) An operating system or domain group observed on an Endpoint.
- [`EndpointPath`](https://wartiva.com/api-docs/types/endpoint-path.html) The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…
- [`EndpointUser`](https://wartiva.com/api-docs/types/endpoint-user.html) An operating system or domain user account observed on an Endpoint.
- [`Executable`](https://wartiva.com/api-docs/types/executable.html) A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.
- [`Finding`](https://wartiva.com/api-docs/types/finding.html) The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
- [`Interface`](https://wartiva.com/api-docs/types/interface.html) A network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…
- [`Issue`](https://wartiva.com/api-docs/types/issue.html) The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
- [`LocalPolicies`](https://wartiva.com/api-docs/types/local-policies.html) The local security policy settings of an Endpoint.
- [`Location`](https://wartiva.com/api-docs/types/location.html) A physical place identified by its global plus code (Open Location Code), with a street address resolved by reverse geocoding.
- [`LogonSession`](https://wartiva.com/api-docs/types/logon-session.html) A user logon session observed on an Endpoint, identified by the username and the time the session started.
- [`Network`](https://wartiva.com/api-docs/types/network.html) An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
- [`NetworkPrefix`](https://wartiva.com/api-docs/types/network-prefix.html) A specific IP address together with its subnet prefix length (e.g.
- [`OpenPort`](https://wartiva.com/api-docs/types/open-port.html) One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
- [`PositionSeen`](https://wartiva.com/api-docs/types/position-seen.html) A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.
- [`Route`](https://wartiva.com/api-docs/types/route.html) One entry in an Endpoint's IP routing table, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.
- [`Security`](https://wartiva.com/api-docs/types/security.html) The security posture of an Endpoint: its firewall, anti-malware and disk encryption state, summarized as per-component health ratings in Health.
- [`Service`](https://wartiva.com/api-docs/types/service.html) A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
- [`SoftwareUpdatePreferences`](https://wartiva.com/api-docs/types/software-update-preferences.html) The operating system update configuration of an Endpoint and the updates currently available to it.
- [`SystemService`](https://wartiva.com/api-docs/types/system-service.html) A background service or daemon configured on an Endpoint.
- [`SystemSettings`](https://wartiva.com/api-docs/types/system-settings.html) The machine-wide operating system configuration of an Endpoint.
- [`UserSystemSettings`](https://wartiva.com/api-docs/types/user-system-settings.html) The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.
- [`WlanAccessPoint`](https://wartiva.com/api-docs/types/wlan-access-point.html) A Wi-Fi access point radio, identified by the network name (SSID) it broadcasts and its BSSID, as heard by managed endpoints scanning for nearby…
- [`WlanInterface`](https://wartiva.com/api-docs/types/wlan-interface.html) A wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.
- [`WlanNetwork`](https://wartiva.com/api-docs/types/wlan-network.html) A Wi-Fi network identified by its network name (SSID), visible to managed endpoints when they scan for nearby networks on Windows, macOS, or Linux.

## Example

### Example

```json
"ACCOUNT_POLICY"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
