Networks, devices, and sensors · GraphQL type

WlanAccessPoint type

A Wi-Fi access point radio, identified by the network name (SSID) it broadcasts and its BSSID, as heard by managed endpoints scanning for nearby networks. It records the radio's 802.11 standard, channel, band, width, signal strength, beacon interval, and the 802.11 information elements from its beacons. It belongs to a WlanNetwork, lists the endpoint WlanInterfaceConnection objects joined to it, and flags a possible evil twin when more than one transmitter is heard claiming the same SSID and BSSID.

Fields

Field Name Description
id - ID! The WlanAccessPoint's unique identifier on the security graph.
orgId - OrganizationId! Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to.
seen - SeenOnline! Describes when this WlanAccessPoint was seen.
objectType - GraphObjectType! The type of this graph object.
objectTypeLabel - String! A localized label describing the object type.
displayName - String! A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object.
firstSeen - Time! Time this object was first seen.
lastSeen - Time! Time this object was last seen.
createdAt - Time! The time this object was created in the security graph.
updatedAt - Time! The time this object was last mutated in the security graph.
snapshotInfo - GraphObjectSnapshotInfo! Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed.
interfaceId - String! Unique Id of the Wireless LAN interface where this AccessPoint was seen as identified on an endpoint. MS Windows: win32 GUID for more info see GUID structure (Microsoft) macOS: BSD-style interface name.
ssid - String! Service Set Identifier (SSID) or name of the Wireless LAN this AccessPoint is broadcasting. The SSID is used by clients to access the network.
bssId - Mac The basic service set identifier (BSSID) is the unique identify for each device participating in a Wireless LAN. The BSSID is usually the same as the devices Mac address. On some systems it may be unavailable.
mode - WlanInterfaceMode! The 802.11 operating mode of the radio as reported by the scan, such as INFRA_AP for an access point or IBSS for an ad hoc peer.
physicalType - WlanDot11PhysicalType! The highest physical hardware type or standard advertised by the AP.
rssiDbm - Int! Wireless LAN signal strength measured in -dBm.
noiseDbm - Int Wireless LAN noise level measured in -dBm if available.
channelNumber - Int Wireless LAN radio channel number if available.
channelWidth - WlanChannelWidth! Width of the radio channel the access point uses, in megahertz.
channelBand - WlanChannelBand! Frequency band of the radio channel the access point uses, such as 2.4 GHz or 5 GHz.
chCenterFrequency - String! Radio channel center frequency formatted as a string in Hertz with numbers representing Hz and an optional SI prefix: p, n, u, µ, m, k, M, G or T.
beaconPeriod - DurationMs! The beacon interval is how often the beacon is broadcast by the AccessPoint measured in milliseconds.
frameRawInfoElements - Binary Raw data blob of all 802.11 information elements (IE) seen in received frames if available. Can be parsed on your own according to IEEE Standard 802.11. See 802.11-2016.pdf p. 474.
infoElements - [WlanInformationElement!] Subset of 802.11 information elements (IE) recognized and parsed if available. See 802.11-2016.pdf p. 474.
wlanNetwork - WlanNetwork The Wireless LAN network this access point belongs to if available.
connections - WlanInterfaceConnectionConnection! The endpoint wlan interface connections that are currently connected to this access point.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

bssIdConflicts - [WlanAccessPointBssIdConflict!]!

The beacons heard claiming this access point's SSID and BSSID, recorded when more than one transmitter was heard claiming them. A BSSID is a radio's hardware address, so exactly one transmitter should beacon a given SSID and BSSID pair. Two doing so is an evil twin: an attacker has cloned both the network name and the hardware address of a legitimate access point, and is drawing clients onto their radio to intercept their traffic.

The transmitters are told apart by channel — one radio beacons on one channel — so each entry carries the channel its beacon came from and how strong it was. Empty for an uncontested access point.

A beacon no longer heard is kept here with isActive false. An access point is only visible to endpoints within radio range, so a beacon not heard right now may simply be out of range of whichever endpoint scanned most recently. Ordered by channel.

isPossibleEvilTwin - Boolean! Whether more than one transmitter was seen beaconing this access point's SSID and BSSID. True means a possible evil twin was detected, and it stays true for as long as the conflict record is retained. Use this rather than activeBssIdConflictCount to search for evil twins: whether the attacker's radio is audible right now depends on which endpoint scanned last, but whether it was ever heard does not.
activeBssIdConflictCount - Int!

How many transmitters beyond the one that should exist were beaconing this SSID and BSSID in the most recent scan. Zero means the identity is uncontested right now; one or more means an endpoint is in range of both the legitimate access point and a radio impersonating it.

This reflects only the endpoint that scanned most recently. An access point is one object seen by every endpoint in radio range, so an endpoint out of range of the impostor reports zero while an endpoint in range reports one, and this value alternates between them. Read it to see whether the impostor is still audible; use isPossibleEvilTwin to decide whether one was detected at all.

networks - NetworkConnection! Networks associated with this access point. When timeRange is null the default time range is used. When timeRange is specified all entries seen in the time range are returned.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

timeRange - DateTimeRangeInput

Optional time range filter.

includeSeen - Boolean

When true, the payload will include information about when the edge was seen in the relationship. The data set will be limited to the time range specified in the timeRange field. If includeSeen is true and timeRange is null then seen data for the default 7 day time range will be returned.

findings - FindingsPayload! Policy findings for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issues - IssuesPayload! Policy issues for this object.

Arguments

limit - Int

Maximum number of results to return.

skip - Int

Number of results to skip.

issuesSummary - IssuesSummary! Summary of the active policy issues currently open on this object, broken down by severity.

Returned by

  • wlanAccessPoint query: Retrieves a WlanAccessPoint by its graph object id: one Wi-Fi access point radio, identified by SSID and BSSID, heard by endpoint scans, with its…

Used by

  • GraphObjectType enum: An enumeration of the different types of security graph objects.
  • GraphObjectTypeCategory enum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
  • RuleApplyToOptionKey enum: Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type.
  • WlanAccessPointConnection type: Collection payload for WlanAccessPoint edges with total count.
  • WlanAccessPointEdge type: Edge payload for a WlanAccessPoint with optional seen data.
  • WlanAccessPointPayload type: Payload wrapper for a single WlanAccessPoint result.
  • WlanInterfaceConnection type: The association between an endpoint's WlanInterface and a Wi-Fi network, identified by the adapter, the network name (SSID), and the access point's…

Related types

  • WlanNetwork A Wi-Fi network identified by its network name (SSID), visible to managed endpoints when they scan for nearby networks on Windows, macOS, or Linux.

Example

Example

{
  "id": "4",
  "orgId": "615f3b3b28284380e28a7342",
  "seen": SeenOnline,
  "objectType": "ACCOUNT_POLICY",
  "objectTypeLabel": "abc123",
  "displayName": "xyz789",
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z",
  "createdAt": "2021-10-07T18:23:25.829Z",
  "updatedAt": "2021-10-07T18:23:25.829Z",
  "snapshotInfo": GraphObjectSnapshotInfo,
  "interfaceId": "xyz789",
  "ssid": "abc123",
  "bssId": "f0:18:98:14:8e:80",
  "mode": "INFRA_NON_AP",
  "physicalType": "UNKNOWN",
  "rssiDbm": 123,
  "noiseDbm": 123,
  "channelNumber": 987,
  "channelWidth": "UNKNOWN",
  "channelBand": "UNKNOWN",
  "chCenterFrequency": "xyz789",
  "beaconPeriod": "600",
  "frameRawInfoElements": Binary,
  "infoElements": [WlanInformationElement],
  "wlanNetwork": WlanNetwork,
  "connections": WlanInterfaceConnectionConnection,
  "bssIdConflicts": [WlanAccessPointBssIdConflict],
  "isPossibleEvilTwin": true,
  "activeBssIdConflictCount": 987,
  "networks": NetworkConnection,
  "findings": FindingsPayload,
  "issues": IssuesPayload,
  "issuesSummary": IssuesSummary
}