Validin Query Language
Learn how to use the Validin Query Language (VQL) to discover files from open directory content
How this differs from Advanced Search VQL
Open Directories has its own query fields and matching rules. Use this reference when searching Open Directories. The Advanced Search VQL reference describes queries for services, registration, and DNS.
Open Directories supports:
- Fully qualified conditions, such as
open_dir.file.ext = "zip", without a surrounding group. AND,OR, and parentheses to control how conditions combine.- Multiple groups and nested groups.
- A special
open_dir.file:(...)group that requires conditions to match the same fetched file. - Regular expressions on text fields.
Use the open_dir fields listed below. Cross-source joins with services:, dns:, or registration: and Advanced Search WITH filters are not supported here. Open Directories does not require a primary-key condition in each group.
Query structure
A condition contains a field, an operator, and a value:
open_dir.file.ext = "zip"Group fields under a shared prefix to avoid repeating it:
open_dir:(host = "files.example.com" AND file.ext = "zip")The same query can be written with fully qualified fields:
open_dir.host = "files.example.com" AND open_dir.file.ext = "zip"Quote text, dates, addresses, and hashes. Write numbers without quotes. Regex patterns use /.../ with the =~ operator.
You can also enter a domain or IP address directly in the search box. Validin converts it to an open_dir.host or open_dir.ip condition.
Combine conditions
Use AND when all conditions must match and OR when either side can match.
open_dir.file.ext = "zip" OR open_dir.file.ext = "7z"AND takes precedence over OR. Use parentheses to make the intended grouping clear:
open_dir.host = "files.example.com" AND (open_dir.file.ext = "zip" OR open_dir.file.ext = "7z")Match a crawl or match one file
This distinction matters whenever you combine file attributes.
Top-level conditions match at the crawl level. Different files in the same crawl can satisfy different conditions:
open_dir.file.ext = "zip" AND open_dir.file.ext = "py"This finds crawls containing both a fetched ZIP file and a fetched Python file.
A file group matches one fetched file. Use open_dir.file:(...) when one file must satisfy the combined conditions:
open_dir.file:(ext = "zip" AND size > 1000000)This finds crawls containing a fetched ZIP file larger than 1,000,000 bytes. Without the group, a small ZIP file and a separate large file could satisfy those conditions.
You can combine a file group with other conditions:
open_dir.host = "files.example.com" AND open_dir.file:(ext = "zip" AND size > 1000000)Operators
| Operator | Meaning | Supported fields |
|---|---|---|
= | Equality, with the field-specific matching described below | All fields |
=~ | Regular expression match | Text fields |
> | Greater than | Integer and date fields |
>= | Greater than or equal to | Integer and date fields |
< | Less than | Integer and date fields |
<= | Less than or equal to | Integer and date fields |
Host and network matching
Use a CIDR block to search a network range:
open_dir.ip = "192.0.2.0/24"Use a *. prefix for a domain-zone search:
open_dir.host = "*.example.com"Filename wildcards
The file.name and file.listed.name fields support a single leading or trailing * in a quoted value:
| Query | Meaning |
|---|---|
open_dir.file.name = "config.json" | Exact filename |
open_dir.file.name = "backup*" | Filename starts with backup; case-sensitive |
open_dir.file.name = "*.json" | Filename ends with .json; case-insensitive |
These are limited filename patterns, not general glob syntax. Use a regular expression for more complex patterns. Extensions use suffix matching and are case-insensitive; write file.ext = "zip" without a leading dot.
Regular expressions
Use =~ followed by a slash-delimited pattern:
open_dir.server =~ /nginx/Anchor a pattern with ^ and $ when you want to match the entire value:
open_dir.file.name =~ /^backup[0-9]+[.]zip$/Regex matching is case-sensitive. Flags such as /pattern/i and inline modifiers such as (?i) are not supported. An explicit character class can cover selected case variants:
open_dir.server =~ /[Nn]ginx/Use =~ /pattern/ for regex matching. = "/pattern/" searches for the literal text, including the slashes.
Sizes and dates
Sizes are integers in bytes:
open_dir.file:(ext = "zip" AND size >= 1000000 AND size < 10000000)Use date comparisons for file modification times:
open_dir.file:(ext = "py" AND mtime >= "2026-01-01T00:00:00Z" AND mtime < "2026-02-01T00:00:00Z")Supported fields
Crawl and infrastructure fields
| Field | Type | Description |
|---|---|---|
open_dir.ip | IP address or CIDR | Address or network serving the directory; supports IPv4 and IPv6. |
open_dir.host | Domain | Domain or virtual host; supports a *. zone prefix. |
open_dir.port | Integer | TCP port. |
open_dir.server | Text | HTTP Server header. |
open_dir.title | Text | Directory index page title. |
open_dir.total_bytes | Integer | Total bytes across fetched files in the crawl. |
open_dir.file_count | Integer | Number of fetched files in the crawl. |
open_dir.listing_count | Integer | Number of fetched directory listings in the crawl. |
File fields
Outside a same-file group, each field finds crawls containing a matching file. Inside open_dir.file:(...), omit the open_dir.file. prefix.
| Field | Type | Description |
|---|---|---|
open_dir.file.name | Text | Fetched filename, without its parent path. Supports exact, prefix, suffix, and regex matching. |
open_dir.file.path | Text | Full fetched file path within the directory hierarchy. |
open_dir.file.ext | Text | Fetched filename extension, such as zip or env. |
open_dir.file.size | Integer | Fetched file size in bytes. |
open_dir.file.mtime | Date | File last-modified time. |
open_dir.file.mime | Text | Server-reported Content-Type. |
open_dir.file.magika_mime | Text | MIME type detected by Magika from the content. |
open_dir.file.magika_label | Text | Magika content label, such as pebin, elf, macho, javascript, or eml. |
open_dir.file.detected_type | Text | Content description detected by libmagic. |
open_dir.file.sha256 | Hash | File SHA-256 hash. |
open_dir.file.sha1 | Hash | File SHA-1 hash. |
open_dir.file.md5 | Hash | File MD5 hash. |
Detected types describe the collected content. A filename extension or server-reported MIME type may disagree with that detection.
Include files advertised in listings
By default, file.name, file.path, and file.ext search fetched files. These fields broaden the search to include entries advertised in a directory listing even when their content was not fetched:
| Field | Type | Description |
|---|---|---|
open_dir.file.listed.name | Text | Fetched or advertised filename; supports the same filename patterns as file.name. |
open_dir.file.listed.path | Text | Fetched or advertised file path. |
open_dir.file.listed.ext | Text | Fetched or advertised filename extension. |
open_dir.file.listed.name = "backup*"A listing-only match does not imply that a preview, hash, or downloadable capture exists. It may qualify a crawl without producing a fetched matching-file entry.
Note: The same-file group
open_dir.file:(...)evaluates fetched files. Usinglisted.name,listed.path, orlisted.extinside that group does not extend it to unfetched entries. Use listing fields outside a same-file group to discover advertised-but-unfetched files.
Directory fields
| Field | Type | Description |
|---|---|---|
open_dir.dir.path | Text | A fetched directory path in the crawl. |
open_dir.dir.title | Text | A directory index page title. |
open_dir.dir.path =~ /backup/Examples
Find captured executables by detected type
open_dir.file:(magika_label = "pebin" OR magika_label = "elf" OR magika_label = "macho")Find JavaScript content saved with a text extension
open_dir.file:(ext = "txt" AND magika_label = "javascript")Search for a known file hash
Replace the sample hash with the SHA-256 value from your investigation:
open_dir.file.sha256 = "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"See Open Directories for exploring matches, viewing captures, and comparing changes.
Updated 11 days ago
