What is SAQL?
SAQL (SAFE Query Language) is a SQL-like text query language for filtering Assets and Findings in the SAFE platform.
SAQL is available in the filter bar on the Assets and Findings views. Switch to SAQL mode in the filter panel's drop-down, type your query, and apply it to filter the table in real time.
Notes
You can start a query in Basic mode and then switch to SAQL mode to see the equivalent query as text, a helpful way to learn the syntax.
SAQL queries support a maximum of 4,000 characters, including spaces and operators.
Query Syntax Basics
Building a Condition
A single condition follows the pattern: attributeId operator value
Example: criticality = 'Critical'
Attribute Identifiers
Use the Attribute ID from the tables in Sections 4 and 5 (e.g., name, criticality, status). These identifiers are case-sensitive and must be typed exactly as shown.
Values
Type |
Combining Conditions
Keyword |
Precedence: AND binds more tightly than OR. Use parentheses to make the intended grouping explicit when mixing both.
Operators
SAQL supports three categories of operators.
Comparison Operators
Used for exact equality, inequality, and numeric/date ordering.
Operator | Syntax | Applies To | Example |
Equals | = | String, Number, Boolean, Date | isFixAvailable = true |
Not Equals | != | String, Number | severity != 'Low' |
Greater Than | > | Number, Date | cvssV3Score > 7.0 |
Greater Than or Equal | >= | Number, Date | exposureScoreInherent >= 4.0 |
Less Than | < | Number, Date | epss < 0.05 |
Less Than or Equal | <= | Number, Date | cvssV2Score <= 3.9 |
Set & Range Operators
Used for membership checks and numeric/date ranges.
Operator | Syntax | Example |
In a set | IN ('val1', 'val2', ...) | criticality IN ('Critical', 'High') |
Not in a set | NOT IN ('val1', 'val2', ...) | status NOT IN ('Closed', 'Resolved') |
Between two values (inclusive) | BETWEEN low AND high | cvssV3Score BETWEEN 4.0 AND 8.9 |
Not between | NOT BETWEEN low AND high | epss NOT BETWEEN 0.0 AND 0.1 |
Text & Pattern Operators
Used for substring matching and wildcard patterns on text fields.
Operator | Syntax | Notes | Example |
Contains substring | CONTAINS 'text' | Case-insensitive substring match | findingName CONTAINS 'SQL Injection' |
Does not contain | NOT CONTAINS 'text' | name NOT CONTAINS 'test-' | |
Like (wildcard) | LIKE 'pattern' | % = any sequence; _ = single character | cveIds LIKE 'CVE-2024-%' |
Not Like | NOT LIKE 'pattern' | name NOT LIKE '%deprecated%' | |
IP CIDR range | CIDR 'x.x.x.x/n' | Matches IPs within the given CIDR block | ipAddress CIDR '10.0.0.0/8' |
Date Functions
On date attributes, you can use dynamic date functions instead of hard-coded dates. The function resolves to the actual date at query execution time, so saved filters stay current automatically.
Function | Resolves To |
today() | Start of the current day |
yesterday() | Start of the previous day |
tomorrow() | Start of the next day |
startOfWeek() | First day of the current week |
endOfWeek() | Last day of the current week |
startOfMonth() | First day of the current month |
endOfMonth() | Last day of the current month |
startOfQuarter() | First day of the current quarter |
endOfQuarter() | Last day of the current quarter |
startOfYear() | First day of the current year |
endOfYear() | Last day of the current year |
daysAgo(N) | N days before today (e.g., daysAgo(7)) |
weeksAgo(N) | N weeks before today (e.g., weeksAgo(4)) |
monthsAgo(N) | N months before today (e.g., monthsAgo(3)) |
yearsAgo(N) | N years before today (e.g., yearsAgo(1)) |
Examples:
firstSeen > daysAgo(30)
lastSeen BETWEEN monthsAgo(6) AND today()
cisaAddedDate >= startOfYear()
Filterable Attributes - Findings
The following attributes can be used in SAQL queries on the Findings view. The Attribute ID column shows the exact identifier to use in your query.
Finding Properties
Display Name | Attribute ID | Type | Supported Operators |
Finding Name | findingName | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Finding Type | findingType | Enum | IN · NOT IN |
Finding Score | exposureScoreInherent | Number (0–10) | = · != · > · >= · < · <= · BETWEEN · NOT BETWEEN |
Finding Severity | severity | Enum | = · IN · NOT IN |
Status | status | Enum | IN · NOT IN |
First Seen | firstSeen | Date | > · < · BETWEEN · NOT BETWEEN |
Last Seen | lastSeen | Date | > · < · BETWEEN · NOT BETWEEN |
Age of Finding (days) | ageOfFinding | Number | = · != · > · >= · < · <= · BETWEEN · NOT BETWEEN |
Fix Available | isFixAvailable | Boolean | = |
Onboarding Source | onboardingSource | Enum | IN · NOT IN |
Sources | contributingSources | Enum | IN · NOT IN |
Source | sourceName | Enum | IN · NOT IN |
Compliance Framework | complianceFramework | Enum | = · IN · NOT IN |
Threat Tags | threatTags | Enum | IN · NOT IN |
CVE / Vulnerability Data
Display Name | Attribute ID | Type | Supported Operators |
CVE IDs | cveIds | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
CWE IDs | cweIds | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
CVE Publish Date | cvePublishDate | Date | > · < · BETWEEN · NOT BETWEEN |
Age of CVE (days) | ageOfCVE | Number | = · != · > · >= · < · <= · BETWEEN · NOT BETWEEN |
EPSS Score | epss | Number (0–1) | = · != · > · >= · < · <= · BETWEEN · NOT BETWEEN |
CVSS V2 Score | cvssV2Score | Number (0–10) | = · != · > · >= · < · <= · BETWEEN · NOT BETWEEN |
CVSS V3 Score | cvssV3Score | Number (0–10) | = · != · > · >= · < · <= · BETWEEN · NOT BETWEEN |
CVSS V4 Score | cvssV4Score | Number (0–10) | = · != · > · >= · < · <= · BETWEEN · NOT BETWEEN |
CVSS V2 Severity | cvssV2Severity | Enum | = · IN · NOT IN |
CVSS V3 Severity | cvssV3Severity | Enum | = · IN · NOT IN |
CVSS V4 Severity | cvssV4Severity | Enum | = · IN · NOT IN |
CISA Known Exploited Vulnerabilities (KEV)
Display Name | Attribute ID | Type | Supported Operators |
CISA KEV | cisaKev | Boolean | = |
CISA KEV Added Date | cisaAddedDate | Date | > · < · BETWEEN · NOT BETWEEN |
CISA KEV Due Date | cisaDueDate | Date | > · < · BETWEEN · NOT BETWEEN |
Affected Asset Properties
Display Name | Attribute ID | Type | Supported Operators |
Asset Name | assetName | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Asset Type | assetTypes | Enum | IN · NOT IN |
Attack Surface | attackSurface | Enum | = · IN · NOT IN |
Zone | zone | Enum | = · IN · NOT IN |
Asset Criticality | criticality | Enum | = · IN · NOT IN |
Asset Score | assetExposureScore | Number (0–10) | = · != · > · >= · < · <= · BETWEEN · NOT BETWEEN |
Asset Tags | assetTags | Multi-value | CONTAINS · NOT CONTAINS · IN · NOT IN |
Business Owner | assetBusinessOwner | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
IT Owner | assetITOwner | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
VM Owner | assetVMOwner | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Device Owner | assetDeviceOwner | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Ticket & Remediation
Display Name | Attribute ID | Type | Supported Operators |
Ticketed | ticketed | Boolean | = |
External Ticket ID | externalTicketId | Text | CONTAINS |
Ticket ID | internalTicketId | Text | CONTAINS |
Filterable Attributes- Assets
The following attributes can be used in SAQL queries on the Assets view.
Asset Identity
Display Name | Attribute ID | Type | Supported Operators |
Asset Name | name | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Asset Types | assetTypes | Enum | = · IN · NOT IN |
Asset Subtype | assetSubtype | Enum | = · IN · NOT IN |
Asset Criticality | criticality | Enum | = · IN · NOT IN |
Asset Score | assetExposureScore | Number (0–10) | = · != · > · >= · < · <= · BETWEEN · NOT BETWEEN |
Cloud Asset | isCloudAsset | Boolean | = |
Findings Count | findingsCount | Number | = · > · < · BETWEEN · NOT BETWEEN |
Attack Surface | attackSurface | Enum | = · IN · NOT IN |
Zone | zone | Enum | = · IN · NOT IN |
Platform | platform | Enum | = · IN · NOT IN |
Patch State | patchState | Enum | IN · NOT IN |
Tags | tags | Multi-value | CONTAINS · NOT CONTAINS · IN · NOT IN |
Network & Location
Display Name | Attribute ID | Type | Supported Operators |
IP Address | ipAddress | IP / Text | = · CONTAINS · NOT CONTAINS · CIDR |
Location | location | Enum | LIKE · NOT LIKE · IN · NOT IN |
Designation | designation | Enum | LIKE · NOT LIKE · IN · NOT IN |
Cloud Properties
Display Name | Attribute ID | Type | Supported Operators |
Cloud Provider | cloudProvider | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE |
Cloud Region | region | Enum / Text | = · LIKE · NOT LIKE · IN · NOT IN |
Cloud Account ID | cloudAccountId | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Cloud Unique ID | cloudResourceId | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Cloud Instance ID | cloudInstanceId | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
VPC / VNet ID | cloudVpcId | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Cloud Resource Group | cloudResourceGroupName | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Source & Onboarding
Display Name | Attribute ID | Type | Supported Operators |
Onboarding Source | onboardingSource | Enum | IN · NOT IN |
Sources | contributingSources | Enum | IN · NOT IN |
Source | sourceName | Enum | IN · NOT IN |
Onboarding Time | onboardingTime | Date | = · > · < · BETWEEN · NOT BETWEEN |
Last Seen | lastSeen | Date | > · < · BETWEEN · NOT BETWEEN |
Last Analysed | updatedAt | Date | > · < · BETWEEN · NOT BETWEEN |
Ownership
Display Name | Attribute ID | Type | Supported Operators |
Business Owner | businessOwner | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
IT Owner | itOwner | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
VM Owner | vmOwner | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Device Owner | deviceOwner | Text | = · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN |
Example Queries
Filters assets that belong to Cloud Infrastructure or Cloud Account types, have Critical or High criticality, and were last seen within the specified date range.
"Asset Types" IN ('Cloud Infrastructure', 'Cloud Account') AND "Asset Criticality" IN ('Critical', 'High') AND lastSeen BETWEEN '2026-03-15T18:30:00.000Z' AND '2026-04-15T18:29:59.999Z'
Exploited vulnerabilities added to CISA KEV in the last 90 days
cisaKev = true AND cisaAddedDate > daysAgo(90)
Findings linked to a specific CVE pattern, not yet closed
cveIds LIKE 'CVE-2024-%' AND status NOT IN ('Closed', 'Resolved', 'Accepted Risk')Assets in the cloud with no owner assigned, onboarded this year
isCloudAsset = true AND businessOwner NOT CONTAINS '@' AND onboardingTime >= startOfYear()
High-score findings on assets owned by a specific team, first seen this quarter
exposureScoreInherent >= 7.0 AND assetBusinessOwner CONTAINS 'platform-team' AND firstSeen >= startOfQuarter()
Assets with many findings, seen recently, not in a test environment
findingsCount > 50 AND lastSeen > daysAgo(7) AND name NOT LIKE '%-test-%' AND name NOT LIKE '%-dev-%'
Quick-Reference - Operator Applicability by Type
Operator | String/Text | Number | Date | Enum | Boolean | IP Address | Multi-value Tag |
= | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |
!= | ✓ | ✓ | |||||
> / >= | ✓ | ✓ | |||||
< / <= | ✓ | ✓ | |||||
IN / NOT IN | ✓ | ✓ | ✓ | ||||
BETWEEN / NOT BETWEEN | ✓ | ✓ | |||||
CONTAINS / NOT CONTAINS | ✓ | ✓ | ✓ | ||||
LIKE / NOT LIKE | ✓ | ✓ | |||||
CIDR | ✓ |