The search box on the Fallout feed accepts a small query language. Tokens are separated by spaces; keys are case-insensitive. Press Enter to submit.
| Token | Effect |
|---|---|
sha256:<hex> |
Jump straight to the file page for that SHA-256.
Alias: sha:. A bare 64-character hex string works too — paste a hash, hit Enter.
|
crit:hostile · crit:suspicious · crit:benign · crit:any |
Filter by litmus criticality band. The feed defaults to crit:>=1 (suspicious + hostile); use crit:any for the unfiltered view.
Also accepts numeric comparators over the class number (0 = benign, 1 = suspicious, 2 = hostile): crit:>=1, crit:=2, crit:<1.
|
ecosystem:<name> |
Restrict to one package ecosystem (e.g. ecosystem:npm, ecosystem:pypi).
Alias: eco:. Maps to the /{ecosystem}/ URL.
|
domain:<host> |
Restrict to samples originating from one source domain (e.g. domain:pypi.org). |
m:<formula> |
Find samples sharing the same cleave malecule, e.g. m:C6H12O6.
Aliases: malecule:, molecule:, formula:. A bare formula-looking token (mixed capital letters and digits, no spaces) is treated as m:.
|
purl:<coord> |
Filter to one package identity by Package URL, e.g. purl:pkg:npm/lodash (every version) or purl:pkg:npm/[email protected] (one release).
The pkg: scheme is optional — purl:npm/lodash works and is normalized. A bare pkg:… paste is detected without the prefix.
Records are also linkable directly by URL path: /npm/lodash is the package's version index, and /npm/[email protected] lands on the sample page when the coordinate pins exactly one record.
|
name:<name> |
Every sample any identity claim says is this software — a registry's claim, or the file's own version resource / bundle manifest — e.g. name:7-Zip. Searches inside archives too: the exe inside each installer that ships it.
Consumes the rest of the query, so names with spaces need no quoting. Combine by signer with signer:.
|
signer:<org> |
Everything signed by one organization (code-signing certificate subject), e.g. signer:Igor Pavlov — the "who vouches for it" view.
Consumes the rest of the query; spaces are fine.
|
<free text> |
Anything else is matched against filename (substring, case-insensitive) and exact SHA-256.
Aliases: q:, filename:, file:.
|
crit:hostile ecosystem:npm
Hostile npm packages
ecosystem:pypi m:C6H12O6
PyPI samples sharing one malecule
crit:>2 domain:github.com
Hostile samples from github.com
purl:pkg:npm/[email protected]
One exact package release
requests-
Filename substring match
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
Jump to that SHA-256
Picking from the Crit / Ecosystem / Domain dropdowns updates only the matching token in the search box — anything else you typed is preserved.