Cloud Asset Context

The Censys Attack Surface Management (ASM) Cloud Connectors for AWS, GCP, and Azure and Wiz integration retrieve various pieces of contextual cloud asset data to help you identify asset ownership for easier remediation.

Cloud asset context in the ASM web console

You can see the context data for an asset by clicking the linked text in the Source column in the Inventory table view in the ASM web console.

Cloud asset context data fields

All cloud asset context data fields are collected in objects prepended with cloud.. Use these fields to build search queries that target cloud context.

These fields can also be queried via the inventory search API endpoint.

AWS cloud context data fields

CategoryMetadataData field name
OrganizationARNcloud.aws.organization.arn
OrganizationIDcloud.aws.organization.id
OrganizationManagement Account ARNcloud.aws.organization.management_account_arn
OrganizationManagement Account IDcloud.aws.organization.management_account_id
OrganizationManagement Account Emailcloud.aws.organization.management_account_email
AccountIDcloud.aws.account.id
AccountNamecloud.aws.account.name
AccountEmailcloud.aws.account.email
AccountContact Type (Billing, Operations, or Security)cloud.aws.account.contacts.type
AccountContact Namecloud.aws.account.contacts.name
AccountContact Emailcloud.aws.account.contacts.email
AccountTagscloud.aws.account.tags
ResourceARNcloud.aws.arn
ResourceVPC IDcloud.aws.vpc_id
ResourceAvailability Zonescloud.aws.availability_zones
ResourceRegioncloud.aws.region
ResourcePrimary DNS Namecloud.aws.dns_name
ResourceDNS Namescloud.aws.dns_names
ResourcePublic IPscloud.aws.public_ips
ResourcePrivate IPscloud.aws.private_ips
ResourceRole Namecloud.aws.role_name
ResourceTagscloud.aws.tags

Azure cloud context data fields

CategoryMetadataData field name
Management GroupIDcloud.azure.management_group.id
Management GroupNamecloud.azure.management_group.name
SubscriptionIDcloud.azure.subscription.id
SubscriptionTenant IDcloud.azure.subscription.tenant_id
SubscriptionManaged by Tenantscloud.azure.subscription.managed_by_tenants
SubscriptionLocation Placement IDcloud.azure.subscription.location_placement_id
SubscriptionStatecloud.azure.subscription.state
SubscriptionTagscloud.azure.subscription.tags
SubscriptionNamecloud.azure.subscription.name
ResourceIDcloud.azure.id
ResourceLocationcloud.azure.location
ResourceTagscloud.azure.tags
ResourceResource Groupcloud.azure.resource_group
ResourceTypecloud.azure.type
ResourceKindcloud.azure.kind
ResourceZonescloud.azure.zones
ResourceNamecloud.azure.name

GCP cloud context data fields

CategoryMetadataData field name
OrganizationIDcloud.gcp.organization.id
ProjectIDcloud.gcp.project.id
ProjectNamecloud.gcp.project.name
ProjectNumbercloud.gcp.project.number
ResourceFull Resource Namecloud.gcp.name
ResourceDisplay Namecloud.gcp.display_name
ResourceLocationcloud.gcp.location
ResourcePrimary DNS Namecloud.gcp.dns_name
ResourceDNS Namescloud.gcp.dns_names
ResourcePublic IPscloud.gcp.public_ips
ResourcePrivate IPscloud.gcp.private_ips
ResourceKMS keyscloud.gcp.kms_keys
ResourceLabelscloud.gcp.labels
ResourceTagscloud.gcp.tags

Wiz cloud context data fields

CategoryMetadataData field name
Exposed EntityIDcloud.wiz.exposed_entity.id
Exposed EntityNamecloud.wiz.exposed_entity.name
Exposed EntityTypecloud.wiz.exposed_entity.type
Exposed EntityCloud Platformcloud.wiz.exposed_entity.cloud_platform
Exposed EntityCloud Providercloud.wiz.exposed_entity.cloud_provider_url
Exposed EntityExternal IDcloud.wiz.exposed_entity.external_id
Exposed EntityNative Typecloud.wiz.exposed_entity.native_type
Exposed EntityRegioncloud.wiz.exposed_entity.region
Exposed EntityRegion Locationcloud.wiz.exposed_entity.region_location
Exposed EntityRegion Typecloud.wiz.exposed_entity.region_type
Exposed EntityResource Groupcloud.wiz.exposed_entity.resource_group_external_id
Exposed EntityStatuscloud.wiz.exposed_entity.status
Exposed EntitySubscription IDcloud.wiz.exposed_entity.subscription_external_id
Application EndpointsIDcloud.wiz.application_endpoints.id
Application EndpointsNamecloud.wiz.application_endpoints.name
Application EndpointsTypecloud.wiz.application_endpoints.type
Application EndpointsPortcloud.wiz.application_endpoints.port
Application EndpointsHostcloud.wiz.application_endpoints.host