Validin Query Language

Learn how to use the Validin Query Language (VQL) to discover files from open directory content

How this differs from Advanced Search VQL

Open Directories has its own query fields and matching rules. Use this reference when searching Open Directories. The Advanced Search VQL reference describes queries for services, registration, and DNS.

Open Directories supports:

  • Fully qualified conditions, such as open_dir.file.ext = "zip", without a surrounding group.
  • AND, OR, and parentheses to control how conditions combine.
  • Multiple groups and nested groups.
  • A special open_dir.file:(...) group that requires conditions to match the same fetched file.
  • Regular expressions on text fields.

Use the open_dir fields listed below. Cross-source joins with services:, dns:, or registration: and Advanced Search WITH filters are not supported here. Open Directories does not require a primary-key condition in each group.

Query structure

A condition contains a field, an operator, and a value:

open_dir.file.ext = "zip"

Group fields under a shared prefix to avoid repeating it:

open_dir:(host = "files.example.com" AND file.ext = "zip")

The same query can be written with fully qualified fields:

open_dir.host = "files.example.com" AND open_dir.file.ext = "zip"

Quote text, dates, addresses, and hashes. Write numbers without quotes. Regex patterns use /.../ with the =~ operator.

You can also enter a domain or IP address directly in the search box. Validin converts it to an open_dir.host or open_dir.ip condition.

Combine conditions

Use AND when all conditions must match and OR when either side can match.

open_dir.file.ext = "zip" OR open_dir.file.ext = "7z"

AND takes precedence over OR. Use parentheses to make the intended grouping clear:

open_dir.host = "files.example.com" AND (open_dir.file.ext = "zip" OR open_dir.file.ext = "7z")

Match a crawl or match one file

This distinction matters whenever you combine file attributes.

Top-level conditions match at the crawl level. Different files in the same crawl can satisfy different conditions:

open_dir.file.ext = "zip" AND open_dir.file.ext = "py"

This finds crawls containing both a fetched ZIP file and a fetched Python file.

A file group matches one fetched file. Use open_dir.file:(...) when one file must satisfy the combined conditions:

open_dir.file:(ext = "zip" AND size > 1000000)

This finds crawls containing a fetched ZIP file larger than 1,000,000 bytes. Without the group, a small ZIP file and a separate large file could satisfy those conditions.

You can combine a file group with other conditions:

open_dir.host = "files.example.com" AND open_dir.file:(ext = "zip" AND size > 1000000)

Operators

OperatorMeaningSupported fields
=Equality, with the field-specific matching described belowAll fields
=~Regular expression matchText fields
>Greater thanInteger and date fields
>=Greater than or equal toInteger and date fields
<Less thanInteger and date fields
<=Less than or equal toInteger and date fields

Host and network matching

Use a CIDR block to search a network range:

open_dir.ip = "192.0.2.0/24"

Use a *. prefix for a domain-zone search:

open_dir.host = "*.example.com"

Filename wildcards

The file.name and file.listed.name fields support a single leading or trailing * in a quoted value:

QueryMeaning
open_dir.file.name = "config.json"Exact filename
open_dir.file.name = "backup*"Filename starts with backup; case-sensitive
open_dir.file.name = "*.json"Filename ends with .json; case-insensitive

These are limited filename patterns, not general glob syntax. Use a regular expression for more complex patterns. Extensions use suffix matching and are case-insensitive; write file.ext = "zip" without a leading dot.

Regular expressions

Use =~ followed by a slash-delimited pattern:

open_dir.server =~ /nginx/

Anchor a pattern with ^ and $ when you want to match the entire value:

open_dir.file.name =~ /^backup[0-9]+[.]zip$/

Regex matching is case-sensitive. Flags such as /pattern/i and inline modifiers such as (?i) are not supported. An explicit character class can cover selected case variants:

open_dir.server =~ /[Nn]ginx/

Use =~ /pattern/ for regex matching. = "/pattern/" searches for the literal text, including the slashes.

Sizes and dates

Sizes are integers in bytes:

open_dir.file:(ext = "zip" AND size >= 1000000 AND size < 10000000)

Use date comparisons for file modification times:

open_dir.file:(ext = "py" AND mtime >= "2026-01-01T00:00:00Z" AND mtime < "2026-02-01T00:00:00Z")

Supported fields

Crawl and infrastructure fields

FieldTypeDescription
open_dir.ipIP address or CIDRAddress or network serving the directory; supports IPv4 and IPv6.
open_dir.hostDomainDomain or virtual host; supports a *. zone prefix.
open_dir.portIntegerTCP port.
open_dir.serverTextHTTP Server header.
open_dir.titleTextDirectory index page title.
open_dir.total_bytesIntegerTotal bytes across fetched files in the crawl.
open_dir.file_countIntegerNumber of fetched files in the crawl.
open_dir.listing_countIntegerNumber of fetched directory listings in the crawl.

File fields

Outside a same-file group, each field finds crawls containing a matching file. Inside open_dir.file:(...), omit the open_dir.file. prefix.

FieldTypeDescription
open_dir.file.nameTextFetched filename, without its parent path. Supports exact, prefix, suffix, and regex matching.
open_dir.file.pathTextFull fetched file path within the directory hierarchy.
open_dir.file.extTextFetched filename extension, such as zip or env.
open_dir.file.sizeIntegerFetched file size in bytes.
open_dir.file.mtimeDateFile last-modified time.
open_dir.file.mimeTextServer-reported Content-Type.
open_dir.file.magika_mimeTextMIME type detected by Magika from the content.
open_dir.file.magika_labelTextMagika content label, such as pebin, elf, macho, javascript, or eml.
open_dir.file.detected_typeTextContent description detected by libmagic.
open_dir.file.sha256HashFile SHA-256 hash.
open_dir.file.sha1HashFile SHA-1 hash.
open_dir.file.md5HashFile MD5 hash.

Detected types describe the collected content. A filename extension or server-reported MIME type may disagree with that detection.

Include files advertised in listings

By default, file.name, file.path, and file.ext search fetched files. These fields broaden the search to include entries advertised in a directory listing even when their content was not fetched:

FieldTypeDescription
open_dir.file.listed.nameTextFetched or advertised filename; supports the same filename patterns as file.name.
open_dir.file.listed.pathTextFetched or advertised file path.
open_dir.file.listed.extTextFetched or advertised filename extension.
open_dir.file.listed.name = "backup*"

A listing-only match does not imply that a preview, hash, or downloadable capture exists. It may qualify a crawl without producing a fetched matching-file entry.

Note: The same-file group open_dir.file:(...) evaluates fetched files. Using listed.name, listed.path, or listed.ext inside that group does not extend it to unfetched entries. Use listing fields outside a same-file group to discover advertised-but-unfetched files.

Directory fields

FieldTypeDescription
open_dir.dir.pathTextA fetched directory path in the crawl.
open_dir.dir.titleTextA directory index page title.
open_dir.dir.path =~ /backup/

Examples

Find captured executables by detected type

open_dir.file:(magika_label = "pebin" OR magika_label = "elf" OR magika_label = "macho")

Find JavaScript content saved with a text extension

open_dir.file:(ext = "txt" AND magika_label = "javascript")

Search for a known file hash

Replace the sample hash with the SHA-256 value from your investigation:

open_dir.file.sha256 = "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"

See Open Directories for exploring matches, viewing captures, and comparing changes.


Did this page help you?