Skip to content

Query Data Reference

DRAFT — Internal Developer Use Only

This API reference is for internal development teams.

Overview

What it is: Each saved search query ID in Discovery returns a specific set of entity columns when executed through the Search & Query API. This reference documents exactly which fields come back for every built-in query, grouped by entity category.

Why it matters: Control developers building custom dashboards, KPI widgets, or data sync pipelines need to know the exact field paths and data types returned by each query. This reference eliminates guesswork when mapping Discovery response data to Control models.

How to use this reference: Find the query ID you are calling, then review its column table. Fields marked as hidden are available in the response but not shown by default in the UI — they are still accessible via the API. Fields with a subReport link to a drill-down query for related data. Dynamic fields (scores.*, attributes.*) expand based on tenant configuration.


Entity Field Prefixes

Every column field path starts with an entity prefix that indicates the data source:

PrefixEntity typeDescription
principal.*AccountCore account/principal identity fields
principalcollector.*Data sourceThe collector/data source that discovered this account
group.*GroupSecurity or distribution group fields
groupcollector.*Data sourceThe collector/data source for a group
identity.*OwnerIdentity owner (person) fields
identityfilter.*Owner (filtered)Owner fields used in filtered owner queries
scores.*ComputedComputed scores, mappings, classifications, and vault status
member.*Group memberAccount that is a member of a group
event.*Audit eventLogin and authentication event fields
loginevent.*Login eventAggregated login event data
vault.*VaultPAM vault/safe information
vaultprincipal.*Vault accountAccount representation within the vault
vaultcollector.*Vault data sourceThe vault integration data source
vaultsystem.*Vault platformPlatform info for the vault system
vaultobject.*Vault objectKey vault secrets, certificates, and keys
compromise.*CompromiseBreach/compromise detection data
compromisecollector.*Breach sourceData source that reported the compromise
threat.*Threat ruleIndividual threat rule/score metadata
threatscore.*Threat scorePer-rule score values
score.*Impact scoreAggregated impact scoring data
classification.*ClassificationAccount classification labels
classificationrule.*Classification ruleRules that assigned classifications
collectorstats.*Collector statsStatistical data per collector (averages, deviations)
MFA.*MFA detailMulti-factor authentication token details
sshkey.*SSH keySSH key metadata (algorithm, fingerprint, usage)
edge.*EdgeRelationship edge data (score edges, classification edges)
certification.*CertificationAttestation campaign/certification data
certentity.*Cert entityPer-entity certification progress
virtual.*VirtualVirtual/computed display fields for cross-entity views
updatedby.*Updated byUser who last modified the entity
role.*RoleAzure/cloud role definitions
rolemember.*Role memberMembers of a role
platformprincipal.*Linked accountLinked/platform account in vault integration
reconcileprincipal.*Reconcile accountReconciliation account for vault rotation
sourceprincipal.*Source accountSource account in SSH key trust relationships
targetprincipal.*Target accountTarget account in SSH key trust relationships
attributes.*AttributesDynamic extended attribute fields (tenant-configurable)

Common Account Fields

Most account-oriented queries share a core set of principal fields. The following table lists the common fields that appear across nearly all account searches. Individual query sections below only list additional fields beyond this common set.

FieldDisplay nameTypeHidden
principal.platformAccount Platformstring
principalcollector.collectornameCollector Namestring
principal.idstringyes
principalcollector.collectoridstringyes
principal.loginshellstringyes
principal.homedirstringyes
principal.shortdomainDomainstring
principal.providerProviderstring
principal.computernameComputer Namestringyes
principal.typeAccount Typestring
principal.nameAccount Namestring
principal.displaynameDisplay Namestring
principal.pathPathstringyes
principal.employeeidEmployee IDstringyes
principal.emailEmailstring
principal.userprincipalnameUPNstring
principal.mfastatusMFAstring
principal.statusStatusstring

Account & Principal Queries

General Account Query

Saved search ID0000CaOuQ1VIhqJGvtje3vbefsg
CategoryAccounts
Required entitiesvault, principal, principalcollector, scores, attributes, classification, updatedby

Includes all common account fields plus:

FieldDisplay nameTypeHidden
principalcollector.collectortypeData Source Platformstring
principal.titleTitlestringyes
principal.departmentDepartmentstringyes
principal.accountidVault Account Idstringyes
principal.secrettypeSecret Typestringyes
principal.samaccountnameSAM Account Namestringyes
principal.custom1principal.custom10Custom 1–10stringyes
scores.entitiesOwners Mappednumber
scores.mappingsMapped Tostring
scores.classesClassificationsstring
scores.actionsActionsstringyes
scores.igacountManaged by IGAnumber
scores.igasIGA Platformsstring
scores.pamstatusPAM Statusstring
scores.vaultsSafestring
scores.vaultaccountnamesVault Account Namestring
scores.vaultsecrettypesVault Secret Typesstring
updatedby.displaynameUpdated Bystringyes
principal.lastupdatedLast Updateddateyes
attributes.*(dynamic)variesyes

Account Status

Saved search IDDYhMbWB3zsTqwK6CvcSmobhAXEw
CategoryAccounts
Required entitiesscores, principal, principalcollector

Includes all common account fields plus:

FieldDisplay nameTypeHidden
scores.entitiesMapped Tonumber

Password Secret Age

Saved search IDRbhOuwKIQL4aJtFm1j8SVYQ29yL
CategoryAccounts
Required entitiesscores, principal, principalcollector

Includes all common account fields plus:

FieldDisplay nameTypeHidden
scores.entitiesMapped Tonumber
principal.passwordchangedPassword Changeddate
principal.passwordchangedagePassword Agenumber

Stale Accounts

Saved search IDN0Ta8FDwqzBURecu551neptjE7q
CategoryAccounts
Required entitiesscores, principal, principalcollector

Includes all common account fields plus:

FieldDisplay nameTypeHidden
scores.entitiesMapped Tonumber
principal.lastlogonLast Logondate
principal.lastlogonageLast Logon Agenumber
principal.createdCreateddate
principal.createdageCreated Agenumber

Password Secret Never Set

Saved search IDQo5kWAQD7nuQQQZeqIoMAsK7qyM
CategoryAccounts
Required entitiesscores, principal, principalcollector

Includes all common account fields plus:

FieldDisplay nameTypeHidden
scores.entitiesMapped Tonumber
principal.passwordchangedagePassword Agenumber

Account Changes By Date

Saved search IDGe30SKv50HEhUA5O448tDjCmgOM
CategoryAccounts
Required entitiesprincipal, principalcollector

Returns a subset of common account fields: collector name, platform, account type, name, UPN, display name, email, status. Does not include MFA, provider, or domain fields by default.


Accounts Created

Saved search IDAIlACtQBw19GgDHYH8qsrhbYnsY
CategoryAccounts
Required entitiesprincipal, principalcollector

Same structure as Account Changes By Date.


Login Activity

Saved search IDYsSAjcNRh6x8V0zGBlQp1BmlMzp
CategoryAccounts
Required entitiesevent, principal, principalcollector

Includes all common account fields plus:

FieldDisplay nameTypeHidden
event.eventtimeEvent Timedate
principal.lastlogonLast Logondate

Failed Logins

Saved search ID73L8y7WdXW63AA98rKYVSMl45p8
CategoryAccounts
Required entitiesloginevent, principal, principalcollector, eventcollector
FieldDisplay nameTypeHidden
principal.idstring
loginevent.countFailed Login Countnumber

Session Activity

Saved search IDa5k2RS1OHV0iwKq0BPxi9CErUMk
CategoryAccounts
Required entitiesevent, principal, principalcollector

Same event-based structure as Login Activity.


Login Audit

Saved search ID4LVYPMbrR6LSouqXafAU8tZp6kA
CategoryAccounts
Required entitiesevent, principal, principalcollector, eventcollector

Includes common account fields with virtual.* display fields plus:

FieldDisplay nameTypeHidden
virtual.collectornameCollector Namestring
virtual.collectoridCollector Idstringyes
virtual.displaynameDisplay Namestring
virtual.emailEmailstring
event.idEvent Idstringyes
event.eventtypeEvent Typestring
event.eventtimeEvent Timedate
event.eventageEvent Agenumber

Account Login Audit

Saved search IDMfNMq5Z7a3ftAO1IjOGpehoPoNN
CategoryAccounts
Required entitiesevent, principal, principalcollector, eventcollector

Same column structure as Login Audit. Accepts an account Id parameter to scope results to a single account.


Account Groups

Saved search IDAPa4DUQNWCiXqU6JMWLZaYxxzZG
CategoryAccounts
Required entitiesgroup, member, groupcollector, membercollector
FieldDisplay nameTypeHidden
groupcollector.collectornameCollector Namestring
group.idGroup Idstringyes
groupcollector.collectoridstringyes
group.platformGroup Platformstring
group.shortdomainDomainstring
group.providerProviderstring
group.nameGroup Namestring
group.displaynameDisplay Namestring
member.shortdomainMember Domainstring
member.computernameComputer Namestringyes
member.nameNamestring
member.displaynameDisplay Namestring
member.userprincipalnameUPNstring
member.emailEmailstring
member.loginshellLogin Shellstringyes
member.pathPathstring
member.objectsidSIDstringyes
member.statusStatusstring

Account Classification

Saved search IDEPFi08RwfU6yV1VrhZ4OsYfc3iz
CategoryAccounts
Required entitiesscores, principal, principalcollector, classification, classificationrule

Includes common account fields plus:

FieldDisplay nameTypeHidden
classification.nameClassificationstring
classificationrule.nameClassification Rulestring
scores.entitiesMapped Tonumber

Account Scores

Saved search IDMGiNLIsVvc2UQEdeBIyv4bSBGSN
CategoryAccounts
Required entitiesprincipal, threatscore, principalcollector

Includes common account fields (without MFA) plus:

FieldDisplay nameTypeHidden
threatscore.idThreat Rule Idstringyes
threatscore.nameThreat Rulestring
score.scoreScorenumber

Account Z-Score

Saved search IDE2SVTGeGpWjnxmj1Y5pYJlZE2YR
CategoryAccounts
Required entitiesscores, principal, group, principalcollector, collectorstats

Includes all common account fields plus:

FieldDisplay nameTypeHidden
scores.entitiesMapped Tonumber
collectorstats.groupcountdeviationStandard Deviationnumber
collectorstats.groupcountavgAverage Member Countnumber
principal.groupcountGroup Countnumber
principal.groupdifferenceGroup Differencenumber
principal.groupdeviationsGroup Membership Z-Scorenumber

Account Z-Score Threats

Saved search ID794IndeqvqzIqrjzy5CgCfBtwxx
CategoryAccounts
Required entitiesscores, principal, group, principalcollector, collectorstats
FieldDisplay nameTypeHidden
principal.idstring

Minimal column set — used as a sub-report for Z-Score threat drill-down.


Account Threat Scores

Saved search IDB5wzD0WU4ggdhAo7BNiXpLdZjBG
CategoryAccounts
Required entitiesscores, principal, principalcollector

Includes all common account fields plus:

FieldDisplay nameTypeHidden
scores.*(dynamic Score Set)varies

The scores.* field expands dynamically to include all configured threat score columns based on the tenant's Score Set configuration.


Compromised Accounts

Saved search IDAh5pa2KZuMZho0wnmLrLonor6mU
CategoryAccounts
Required entitiescompromise, principal, principalcollector, compromisecollector, scores
FieldDisplay nameTypeHidden
principal.typeAccount Typestring
compromise.idstringyes
principal.idstringyes
compromisecollector.collectornameBreach Sourcestring
compromise.nameBreach Namestring
compromise.breachdateBreach Datedate
compromise.breachdateageBreach Agenumber
principalcollector.collectornameCollector Namestring
principal.shortdomainDomainstring
principal.nameAccount Namestring
principal.employeeidEmployee IDstringyes
principal.emailEmailstring
principal.passwordchangedagePassword Agenumber
principal.passwordchangedPassword Changeddate
scores.*(dynamic Score Set)variesyes

Vault Queries

Vaulted Accounts

Saved search ID0000CZNzRfoREvBuaNZ9CwSAvws
CategoryAccounts
Required entitiesvault, vaultprincipal, vaultcollector, scores, principal, platformprincipal, reconcileprincipal, platformprincipalcollector, platformprincipalsystem, principalcollector, classification
FieldDisplay nameTypeHidden
principal.typeAccount Typestring
scores.classesClassificationsstring
scores.pamstatusPAM Statusstring
principal.platformAccount Platformstring
principalcollector.collectornameCollector Namestring
principal.displaynameDisplay Namestring
principal.nameAccount Namestring
vault.nameSafestring
platformprincipal.nameordisplaynameLinked Account Namestring
platformprincipal.platformLinked Account Platformstring
platformprincipalcollector.collectornameLinked Account Data Sourcestring
reconcileprincipal.nameordisplaynameReconcile Account Namestring
reconcileprincipal.displaynameReconcile Account Display Namestring
principal.secretreconciledLast Reconcileddate
principal.secretstatusReconcile Statusstring
principal.passwordchangedPassword Changeddate
scores.actionsActionsstring
scores.mappingsMapped Tostring
principal.mfastatusMFAstring
scores.F0001p8NopubZzx9n9u6AwF37YVLTotal Threatnumberyes
principal.statusStatusstring

Plus standard hidden fields: vaultcollector.credentialid, principal.id, principalcollector.collectorid, principal.accountid, principal.secrettype, etc.


Vaulted Account Management

Saved search ID0000CbuesIiBcSJlsPk6jzuIcrm
CategoryAccounts
Required entitiesvault, discoveredaccounts, scores, principal, vaultprincipal, platformprincipal, principalcollector, vaultcollector, vaultsystem, classification
FieldDisplay nameTypeHidden
principal.platformAccount Platformstring
principalcollector.collectornameCollector Namestring
principal.nameAccount Namestring
scores.actionsActionsstring
scores.pamstatusPAM Statusstring
vaultsystem.platformVault Platformstring
vaultcollector.collectornameVault Data Sourcestring
vault.nameSafestring
vaultprincipal.displaynameornameVault Account Namestring
platformprincipal.nameordisplaynamePlatform Accountstring
principal.displaynameDisplay Namestring
principal.typeAccount Typestring
scores.classesClassificationsstring
scores.mappingsMapped Tostring
principal.mfastatusMFAstring
scores.F0001p8NopubZzx9n9u6AwF37YVLTotal Threatnumber
principal.statusStatusstring

Account Vault Status

Saved search ID0000IrdpnFudkVXDaoLGubUBIbe
CategoryAccounts
Required entitiesvault, scores, principal, vaultprincipal, principalcollector, vaultcollector, vaultsystem, classification
FieldDisplay nameTypeHidden
principal.typeAccount Typestring
scores.classesClassificationsstring
scores.pamstatusPAM Statusstring
principal.platformAccount Platformstring
principalcollector.collectornameCollector Namestring
principal.displaynameDisplay Namestring
principal.nameAccount Namestring
vaultprincipal.displaynameornameVault Account Namestring
vaultsystem.platformVault Platformstring
vaultcollector.collectornameVault Data Sourcestring
vault.nameSafestring
scores.actionsActionsstring
scores.mappingsMapped Tostring
principal.mfastatusMFAstring
scores.F0001p8NopubZzx9n9u6AwF37YVLTotal Threatnumber
principal.statusStatusstring

Account Key Vault Objects

Saved search ID7J3TaqEtCgXB7sDwWhwZcT1YgM8
CategoryAccounts
Required entitiesprincipal, principalcollector, vaultobject
FieldDisplay nameTypeHidden
principal.platformPlatformstring
principal.providerProviderstring
principalcollector.collectornameCollector Namestring
principal.displaynameDisplay Namestring
principal.nameAccount Namestring
principal.typeAccount Typestring
principal.shortdomainDomainstring
vaultobject.VaultNameVault Namestring
vaultobject.ItemTypeObject Typestring
vaultobject.NameObject Namestring
vaultobject.ObjectEnabledObject Statusstring
vaultobject.PermissionObject Permissionstring
vaultobject.PathObject Pathstring
vaultobject.CreateDateObject Create Datedate
vaultobject.StartDateObject Start Datedate
vaultobject.ExpiryDateObject Expiry Datedate
vaultobject.AliasNamesObject Aliasesstring
vaultobject.PublicKeyObject Public Keystring
vaultobject.HSMPlatformObject HSM Platformstring

Group Key Vault Objects

Saved search ID7Dt6XcnjJOzpexYxZlz7kIN1zCF
CategoryGroups
Required entitiesgroup, groupcollector, vaultobject

Same vault object fields as Account Key Vault Objects but with group entity fields (group.platform, group.provider, group.name, group.shortdomain) instead of principal fields.


Group User Key Vault Objects

Saved search IDa62mQQOqiTzBN8F2sFMNJyiY0F0
CategoryGroups
Required entitiesgroup, groupcollector, member, vaultobject

Combines group fields, member account fields, and vault object fields.


Account Role Membership

Saved search ID1gbrYrq61lu5dymofZGYu8ACOTT
CategoryAccounts
Report query ID6jZNu3bAmCBJ5rZtN6V1FDQN6ms
Required argsactorid (Account ID)

Returns role assignments for a specific account. Used by the Role Membership tab on Account Details.

FieldDisplay nameTypeHidden
role.nameRole Namestring
role.displaynameDisplay Namestring
principalsystem.datasourceData Sourcestring
principalsystem.platformPlatformstring
role.typeRole Typestring

Owner Role Membership

Saved search IDGcN0B8yAZVqXi3SvOjLVeL581I8
CategoryOwners
Report query IDXxQ9DzWCqtCIUNduJ8AmOsf6oVR
Required argsactorid (Identity ID)

Returns aggregated role assignments across all accounts mapped to a specific owner. Used by the Role Membership tab on Owner Details.

FieldDisplay nameTypeHidden
role.nameRole Namestring
role.displaynameDisplay Namestring
principal.nameAccount Namestring
principalsystem.datasourceData Sourcestring
principalsystem.platformPlatformstring
role.typeRole Typestring

Group Queries

General Group Query

Saved search IDOd1oCfsGRnV77zCWNvi6YFg9E2d
CategoryGroups
Required entitiesgroup, attributes, groupcollector
FieldDisplay nameTypeHidden
group.idGroup Idstringyes
group.platformGroup Platformstring
groupcollector.collectoridData Source Idstring
groupcollector.collectornameData Source Namestring
group.shortdomainDomainstring
group.providerProviderstring
group.nameGroup Namestring
group.displaynameDisplay Namestring
group.pathPathstringyes
group.objectsidSIDstringyes
directmember.countDirect Member Countnumber
member.countMember Countnumber
attributes.*(dynamic)variesyes

Groups By Date

Saved search IDTUdfgfRUd5ZFVDlgi5Ix5tf1Lmb
CategoryGroups
Required entitiesgroup, groupcollector
FieldDisplay nameTypeHidden
groupcollector.collectornameCollector Namestring
group.platformGroup Platformstring
group.shortdomainDomainstring
group.providerProviderstring
group.nameGroup Namestring
group.displaynameDisplay Namestring
group.pathPathstringyes

Group Changes By Date

Saved search IDDa90sRZm6VkElZh5tpwhPm7Ihtd
CategoryGroups
Required entitiesgroup, groupcollector

Same column structure as Groups By Date.


Groups By Member Count

Saved search IDAKXH3V3MPiHZD5xfmqaveYlZUnx
CategoryGroups
Required entitiesgroup, groupcollector
FieldDisplay nameTypeHidden
groupcollector.collectornameCollector Namestring
group.idstringyes
groupcollector.collectoridstringyes
group.platformGroup Platformstring
group.shortdomainDomainstring
group.providerProviderstring
group.nameGroup Namestring
group.displaynameDisplay Namestring

Privileged Groups

Saved search ID2rkv9qq7HWNwiEuk97chCdnAO8B
CategoryGroups
Required entitiesgroup, groupcollector

Same column structure as General Group Query with privilege-level filtering.


Expanded Group Membership

Saved search IDUS6oSTzOLxZ9LyK2shh5nMysTk5
CategoryGroups
Required entitiesgroup, member, groupcollector, membercollector

Same column structure as Account Groups — returns group + member fields with full recursive expansion.


Direct Group Membership

Saved search ID6dIqKgxTygmSilzBx4kNSNzJR5Q
CategoryGroups
Required entitiesgroup, member, groupcollector, membercollector

Same column structure as Account Groups — returns only direct (non-recursive) memberships.


Group Membership

Saved search ID0qwQBiyYucYSQbvfkdSQi4U84m7
CategoryGroups
Required entitiesgroup, member, membercollector, groupcollector
FieldDisplay nameTypeHidden
membercollector.collectornameData Source Namestring
group.idGroup Idstringyes
membercollector.collectoridData Source Idstringyes
group.platformGroup Platformstring
group.shortdomainGroup Domainstring
group.providerGroup Providerstring
group.nameGroup Namestring
group.displaynameGroup Display Namestring
member.shortdomainDomain Namestring
member.computernameComputer Namestringyes
member.nameNamestring
member.displaynameDisplay Namestring
member.userprincipalnameUPNstring
member.emailEmailstring
member.loginshellLogin Shellstringyes
member.pathPathstring
member.objectsidSIDstringyes
member.statusStatusstring

Group Login Audit

Saved search IDWkjkxGR0LE99gvzmTcYdQt9VJyF
CategoryGroups
Required entitiesgroup, member, groupcollector, event, membercollector

Combines group + member fields from Group Membership plus event fields:

FieldDisplay nameTypeHidden
event.idEvent Idstringyes
event.eventtypeEvent Typestring
event.eventtimeEvent Timedate
event.eventageEvent Agenumber

Owner & Identity Queries

Global Search Owner

Saved search IDNFZg0Ss2HDfKd8VIsY0RMJwTDzF
CategoryOwners
Required entitiesidentity, scores
FieldDisplay nameTypeHidden
identity.postalCodePostal Codestringyes
identity.countryCodeCountrystringyes
identity.idstringyes
identity.nameNamestring
identity.emailEmailstring
identity.alternativeemailAlternative Emailstringyes
identity.statusStatusstringyes
identity.ownertypeOwner Typestringyes
identity.startdateStart Datedateyes
identity.enddateEnd Datedateyes
identity.titleTitlestringyes
identity.deptDepartmentstringyes
identity.managerManagerstringyes
identity.locationLocationstringyes
identity.phonePhonestringyes
identity.mobileMobile Phonestringyes
scores.entitiesMapped Accountsnumber
scores.*(dynamic Score Set)variesyes
scores.F0001p8NopubZzx9n9u6AwF37YVLTotal Threatnumber

Owner Threat Scores

Saved search IDVkAGnFi7Yjdy14x9x4WZT0DtcS2
CategoryOwners
Required entitiesidentity, scores
FieldDisplay nameTypeHidden
identity.idstringyes
identity.nameNamestring
identity.emailEmailstring
scores.entitiesMapped Accountsnumber
scores.*(dynamic Score Set)varies

Owner Account Data

Saved search IDK5Wb75il7Or3lxfFdmr4gfwsbkn
CategoryOwners
Required entitiesidentity, scores
FieldDisplay nameTypeHidden
identity.idOwner Identifierstringyes (also shown visible)
identity.postalCodePostal Codestring
identity.countryCodeCountrystring
identity.nameNamestring
identity.emailEmailstring
identity.alternativeemailAlternative Emailstring
identity.alternativenameAlternative Display Namestring
identity.statusStatusstring
identity.ownertypeOwner Typestring
identity.startdateStart Datedate
identity.enddateEnd Datedate
identity.titleTitlestring
identity.deptDepartmentstring
identity.managerManagerstring
identity.locationLocationstring
identity.phonePhonestring
identity.mobileMobilestring
scores.F0001p8NopubZzx9n9u6AwF37YVLTotal Threatnumber

Owner Login Audit

Saved search ID4rAqYWwpS7R7ev4qvomlzaxW8b4
CategoryOwners
Required entitiesevent, identity, principal, principalcollector, eventcollector

Same column structure as Login Audit. Scoped to accounts mapped to a specific owner via Identity Id parameter.


Owner Account MFA

Saved search IDQe2RsFtZUMDkIRkpnky8xxHe5UY
CategoryOwners
Required entitiesidentity, principal, principalcollector

Includes common account fields. Scoped to accounts mapped to a specific owner.


Owner Account Risk

Saved search ID4W3yZV5j7Joi0lFvuwz48I5kT0t
CategoryOwners
Required entitiesidentity, principal, principalcollector, scores

Includes common account fields plus:

FieldDisplay nameTypeHidden
scores.*(dynamic Score Set)varies

Owner Group Membership

Saved search IDXheILctS3gRnDWLhbRBnSCmVZpa
CategoryOwners
Required entitiesidentityfilter, principal, group, groupcollector
FieldDisplay nameTypeHidden
identityfilter.nameOwner Namestring
groupcollector.collectornameCollector Namestring
group.idGroup Idstringyes
groupcollector.collectoridstringyes
group.platformGroup Platformstring
group.shortdomainDomainstring
group.providerProviderstring
group.nameGroup Namestring
group.displaynameDisplay Namestring
principal.shortdomainDomainstring
principal.computernameComputer Namestringyes
principal.nameAccount Namestring
principal.displaynameDisplay Namestring
principal.userprincipalnameUPNstring
principal.employeeidEmployee IDstringyes
principal.emailEmailstring
principal.loginshellLogin Shellstringyes
principal.pathPathstring
principal.statusStatusstring

Owner Group Membership (Bulk)

Saved search IDVixlNXPx92So7lQ8b6nwpDlT7vg
CategoryOwners
Required entitiesidentityfilter, principal, group, groupcollector

Combines full owner identity fields (identityfilter.*) with group and principal member fields. Returns all owner-group-account relationships in a single flat result set for bulk export.


Mapped Owners

Saved search IDT2MBuk8ZhWZ2zSAJMvwf8dR1GRg
CategoryOwners
Required entitiesprincipal, identity
FieldDisplay nameTypeHidden
identity.nameNamestring
identity.emailEmailstring

Sub-report used for drill-down from account queries to see which owners are mapped.


Mapped Accounts

Saved search IDWJk4TU9UZ7fNmIWZtvHaSjyxZkL
CategoryOwners
Required entitiesidentity, principal, principalcollector, scores

Includes common account fields plus:

FieldDisplay nameTypeHidden
principal.lastlogonLast Logondate
scores.pamstatusPAM Statusstring
scores.F0001p8NopubZzx9n9u6AwF37YVLTotal Threatnumber

Sub-report used for drill-down from owner queries to see mapped accounts.


Global Search (Cross-Entity)

Global Search — Accounts

Saved search IDGjJXh07y2K3xrTOwohZjde4SkLU
CategoryGlobal Search
Required entitiesscores, attributes, principal, principalcollector

Returns an extensive account dataset with most fields hidden by default for use in cross-entity search:

FieldDisplay nameTypeHidden
principalcollector.collectortypeData Source Platformstring
principalcollector.collectornameCollector Namestring
principal.platformAccount Platformstring
principal.displaynameDisplay Namestring
principal.nameAccount Namestring
principal.emailEmailstring
scores.F0001p8NopubZzx9n9u6AwF37YVLTotal Threatnumber
principal.statusStatusstring
principal.typeAccount Typestring
principal.samaccountnameSAM Account Namestringyes
principal.custom1principal.custom10Custom 1–10stringyes
principal.titleTitlestringyes
principal.departmentDepartmentstringyes
scores.classesClassificationsstringyes
scores.actionsActionsstringyes
scores.pamstatusPAM Statusstringyes
scores.vaultsSafestringyes
scores.vaultaccountnamesVault Account Namesstringyes
scores.vaultsecrettypesVault Secret Typesstringyes
scores.entitiesMapped Ownersnumberyes
scores.mappingsMapped Tostringyes
principal.userprincipalnameUPNstringyes
principal.lastlogonageLast Logon Agenumberyes
principal.lastlogonLast Logondateyes
principal.createdCreateddateyes
principal.passwordchangedPassword Changeddateyes
principal.passwordchangedagePassword Agenumberyes
principal.mfastatusMFAstringyes
scores.*(dynamic Score Set)variesyes
attributes.*(dynamic Attributes)variesyes
scores.breachnameCompromise Namestringyes
scores.breachdateCompromise Datedateyes
scores.breachdateageCompromise Agenumberyes

Global Search — Groups

Saved search ID3QJOML6Yg7Hem6MtAsar9lleE6A
CategoryGlobal Search
Required entitiesgroup, member, scores, attributes, groupcollector
FieldDisplay nameTypeHidden
group.idstringyes
group.platformGroup Platformstring
groupcollector.collectornameCollector Namestring
groupcollector.collectortypeData Source Platformstringyes
group.shortdomainDomainstringyes
group.providerProviderstringyes
group.nameGroup Namestring
group.displaynameDisplay Namestring
group.pathPathstringyes
group.objectsidSIDstringyes
directmember.countDirect Member Countnumber
member.countMember Countnumber
scores.*(dynamic Score Set)variesyes
attributes.*(dynamic Attributes)variesyes

Compliance & Insights

Insights And Recommendations — NIST CSF V2.0

Saved search IDEUo14Qdnd04fogoYMKGv8JjOTFj

Insights And Recommendations — CIS V8

Saved search IDLC9DrZsZWuAtK2VbcvQwsElgodt

Insights And Recommendations — CRITIER4 V2

Saved search ID7CPLbSf0cZHim76HO8j2a7HJNWE

All three compliance frameworks share the same column structure — they return framework-specific assessment data against the configured Score Sets.


Permissions

Saved search IDO2IMv9WseU6NVITC3gPw8Vto4wE
Required entitiesprincipal, principalcollector
FieldDisplay nameTypeHidden
principalcollector.collectornameCollector Namestring
principal.idstringyes
principalcollector.collectoridstringyes
principal.platformAccount Platformstring
principal.nameAccount Namestring
principal.userprincipalnameUPNstring
principal.displaynameDisplay Namestring
principal.pathPathstringyes
principal.employeeidEmployee IDstringyes
principal.emailEmailstring
principal.statusStatusstring

Entitlements

Saved search IDCs9H6go9QfNKGuNuUaiUuGbmnQY
Required entitiesprincipal, principalcollector

Same column structure as Permissions.


Privileged Roles

Saved search IDLEtIh62OjUxex7u2iJU9cQQAD0M
Required entitiesrole, rolemember, rolemembercollector, rolecollector

Returns role and member fields similar to group membership queries.


Scores

Saved search IDHz0YvM5S8FCRjXmnoKSkYtSsEyp
Required entitiesscores, virtualprincipal, virtualgroup, virtualidentity, collector
FieldDisplay nameTypeHidden
scores.idScore IDstring
scores.groupingGroupingstring
scores.*(dynamic Score Set)varies

Scoring & Classification

Score Edges

Saved search IDSh8AOdOMlTD4SyzmLbzgEOVJUlL
Required entitiesedge
FieldDisplay nameTypeHidden
edge.edgetypeEdge Typestring
edge.parentidParent IDstring
edge.childidChild IDstring
edge.directDirectbool

Classification Edges

Saved search IDZaWWoHqOrOBPZU6v3kwQINT2KWm
Required entitiesedge

Same column structure as Score Edges. Filters to edge.classification and edge.classificationrule edge types.


Flyout Queries

Flyout queries power the risk flyout panel in the Discovery UI. They are called internally by the flyout endpoint and return aggregated threat data grouped by different dimensions.

Flyout Data

Saved search IDJ4sUtdVNIXJZBgEtHZqYpfFQXXy
Required entitiesscores, principal, principalcollector, threat
FieldDisplay nameTypeHidden
principal.idstring
principalcollector.collectornameCollector Namestring
principal.platformAccount Platformstring
principal.nameAccount Namestring
scores.F0001p8NopubZzx9n9u6AwF37YVLTotal Threatnumber
threat.nameThreat Namestring

Grouped by principal.id — returns top risky accounts.


Flyout Data Threat

Saved search IDUGWfuXAU0s77MuWYbxVwtQKh2JI
Required entitiesscores, principal, principalcollector, threat

Same fields as Flyout Data plus principal.idcount. Grouped by threat.name — returns account counts per threat rule.


Flyout Data Platform

Saved search IDUYxpUZMKDRTazl2CPsTlVfWMD3U
Required entitiesscores, principal, principalcollector, threat

Same fields as Flyout Data plus principal.idcount. Grouped by principal.platform — returns risk distribution per platform.


Flyout Data Service

Saved search IDQLzXWkDyPj1fydf3fBRnCIkYBr1
Required entitiesscores, principal, principalcollector, threat

Same fields as Flyout Data plus principal.idcount. Filtered to principal.type = "service account" — returns service account risk data.


Flyout Distribution

Saved search IDEDYoMksgyE4CYlFs0cphqM7pYQA
Required entitiesscores, principal, principalcollector, threat

Same fields as Flyout Data plus principal.idcount (displayed as percentage). Grouped by threat.name — returns percentage distribution of threat rules.


Mapping & Export Queries

Mapped Accounts Bulk

Saved search ID6opzOoSgU9NYwW9WLR9uuLLGiVE
Required entitiesidentity, principal, principalcollector, scores

Full owner identity fields plus full account fields. Used by Control for bulk data synchronization:

FieldDisplay nameTypeHidden
identity.idIDstring
identity.postalCodePostal Codestring
identity.countryCodeCountrystring
identity.nameNamestring
identity.emailEmailstring
identity.alternativeemailAlternative Emailstring
identity.statusStatusstring
principal.statusAccount Statusstring
identity.ownertypeOwner Typestring
identity.startdateStart Datedate
identity.enddateEnd Datedate
identity.titleTitlestring
identity.deptDepartmentstring
identity.managerManagerstring
identity.locationLocationstring
identity.phonePhonestring
identity.mobileMobile Phonestring
scores.entitiesMapped Accountsnumber
scores.mappingsMapped Tostring
+ all common account fields
principal.lastlogonLast Logondate
scores.pamstatusPAM Statusstring
scores.F0001p8NopubZzx9n9u6AwF37YVLTotal Threatnumber

Users Export

Saved search IDYOmamp53l581Tw6YJAAHP55qJVd

Full account data export with all principal fields for CSV download.


Groups Export

Saved search ID2duji0UlFRUKO3iGjfPrCtkJOvp

Full group data export with all group and member fields for CSV download.


General Resource Query

Saved search IDFHddWu8ylCTNmncivqiThqriqF1
Required entitiesprincipal, attributes, principalcollector

Includes common account fields plus:

FieldDisplay nameTypeHidden
attributes.*(dynamic)variesyes

CyberArk Onboarding

Saved search IDOBXNfYIw71ZiwfwQ297xZAkMfxE
Required entitiesvault, discoveredaccounts, scores, principal, principalcollector, classification

Returns accounts eligible for CyberArk onboarding (not yet managed by PAM):

FieldDisplay nameTypeHidden
principal.platformAccount Platformstring
principalcollector.collectornameCollector Namestring
scores.actionsActionsstring
scores.pamstatusPAM Statusstring
scores.vaultsSafestring
scores.vaultaccountnamesVault Account Namestring
scores.vaultsecrettypesVault Secret Typesstring
principal.nameAccount Namestring
principal.displaynameDisplay Namestring
principal.typeAccount Typestring
scores.classesClassificationsstring
scores.mappingsMapped Tostring
principal.mfastatusMFAstring
scores.F0001p8NopubZzx9n9u6AwF37YVLTotal Threatnumber
principal.statusStatusstring

Approvals

Saved search IDHxM4qza1UFtGdLpVFEQWRljN746

Returns pending workflow approval events for review.


Stub Report

Saved search IDWG2mnQ36yVa30jAeWJ0jwEPC5bR

Empty placeholder report used for testing and UI scaffolding.


Control Integration — Sync Query Fields

Control uses specific query IDs for data synchronization (documented in Search & Query API — Control Integration). The key fields Control maps from each sync query:

Sync purposeQuery IDKey fields consumed
All accountsASpnJ4bLpFRGBZxEwAEPullOFx5principal.name, principal.type, principal.platform, principal.status, principal.mfastatus, scores.F0001p8NopubZzx9n9u6AwF37YVL, scores.classes, scores.pamstatus
Account ownersUVYaMSAx8evNujhC75QELLRej2Tidentity.name, identity.email, scores.entities, scores.F0001p8NopubZzx9n9u6AwF37YVL
Bulk owner accountsDUrG0M5i1MYn0H99KwSpezBqLttFull identity + principal + scores fields (see Mapped Accounts Bulk)
Bulk group membershipsW8fSFbTri7TqbXWgdZVpBjLZMNnFull identity + group + principal fields (see Owner Group Membership Bulk)
List groups5giWu96fvwE0N3LVgm60eKfI6X6group.name, group.platform, group.displayname, directmember.count, member.count
List owner accountsMG4VCGoPBLa1aHtSHRziTeHvb34Full account fields + scores.pamstatus, scores.F0001p8NopubZzx9n9u6AwF37YVL
List owner groupsGlLjXWQNzXixQCqikR3K9mJMoTaOwner + group + principal membership fields
Get group members8XYzi8x3XmVmA47OehS6q1K8Jiagroup.name, member.name, member.email, member.status

Hydden Documentation and Training Hub