One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by Wartiva's server-side sensors scanning public addresses. It keeps the port's open and closed history (when it was first and last seen open, and when last seen closed), the number of endpoints that currently observe it open, and whether it is exposed to the public Internet. Each open port links to the Network and NetworkPrefix where it was found and to the Service objects identified on it.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
Unique identifier for this graph object. |
orgId - OrganizationId!
|
Unique identifier for the owning organization. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
seen - SeenOnline!
|
When this graph object was seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
device - Device
|
The Device this open port belongs to. |
network - Network
|
The Network this open port was found on if known. |
networkPrefix - NetworkPrefix
|
The NetworkPrefix containing the IP this open port was found on if known. |
ip - IpAddress!
|
IP address where the port was found open. |
isOpen - Boolean!
|
True if the last known state was open. |
public - Boolean!
|
True if the port is on a public IP address and has been observed open from the public Internet. |
port - Int!
|
The IP port number, an unsigned 16-bit integer. |
protocol - IpProtocol!
|
The transport protocol of the port, TCP or UDP. |
state - PortState!
|
Last known state e.g. open or closed. |
services - ServiceConnection!
|
Services found on this open port. |
endpoints - EndpointConnection!
|
Endpoints that have seen this port open. When timeRange is null the last 30 days will be returned. When timeRange is specified all entries seen in the time range are returned. |
|
Arguments
Maximum number of results to return.
Number of results to skip.
Optional time range filter.
When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned. |
|
firstSeenOpen - Time
|
The time when the port was first detected as open. |
lastSeenOpen - Time
|
The time the port was last seen open. |
lastSeenClosed - Time
|
The time the port was last seen closed. Will be null if always seen open. |
seenOpen - SeenOnline!
|
Describes when this port was seen open. |
openToEndpointCount - Int!
|
The number of Endpoints that currently observe this port as open. |
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
openPortquery: Retrieves an OpenPort by its graph object id: a TCP or UDP port on a discovered device, found by endpoint port scans of local devices or by…
Used by
Endpointtype: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.Networktype: An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…NetworkPrefixtype: A specific IP address together with its subnet prefix length (e.g.Servicetype: A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.OpenPortConnectiontype: Connection for OpenPort edges with total count.OpenPortEdgetype: Edge payload for an OpenPort with optional seen data.OpenPortPayloadtype: Payload wrapper for a single OpenPort result.OpenPortSummarytype: An abbreviated summary of an OpenPort.RuleApplyToOptionKeyenum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.
Related types
DeviceA physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…NetworkAn IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…NetworkPrefixA specific IP address together with its subnet prefix length (e.g.
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "abc123",
"displayName": "xyz789",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"seen": SeenOnline,
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"device": Device,
"network": Network,
"networkPrefix": NetworkPrefix,
"ip": IpAddress,
"isOpen": true,
"public": false,
"port": 987,
"protocol": "TCP",
"state": "OPEN",
"services": ServiceConnection,
"endpoints": EndpointConnection,
"firstSeenOpen": "2021-10-07T18:23:25.829Z",
"lastSeenOpen": "2021-10-07T18:23:25.829Z",
"lastSeenClosed": "2021-10-07T18:23:25.829Z",
"seenOpen": SeenOnline,
"openToEndpointCount": 123,
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}