Using SAQL (SAFE Query Language) for Advanced Filtering

Prev Next

What is SAQL?

SAQL (SAFE Query Language) is a SQL-like text query language for filtering Assets and Findings in the SAFE platform.

SAQL is available in the filter bar on the Assets and Findings views. Switch to SAQL mode in the filter panel's drop-down, type your query, and apply it to filter the table in real time.

Notes

  • You can start a query in Basic mode and then switch to SAQL mode to see the equivalent query as text, a helpful way to learn the syntax.

  • SAQL queries support a maximum of 4,000 characters, including spaces and operators.

Query Syntax Basics

Building a Condition

A single condition follows the pattern: attributeId  operator  value

Example: criticality = 'Critical'

Attribute Identifiers

Use the Attribute ID from the tables in Sections 4 and 5 (e.g., name, criticality, status). These identifiers are case-sensitive and must be typed exactly as shown.

Values

Type

Format

Example

String

Single or double quotes

'Critical' or "Critical"

Number

Bare decimal or integer

7.5, 100

Boolean

true or false

true

Date

ISO string or a date function

'2024-01-01' or daysAgo(30)

Combining Conditions

Keyword

Meaning

Example

AND

Both conditions must be true

criticality = 'High' AND status = 'Open'

OR

Either condition must be true

criticality = 'Critical' OR criticality = 'High'

NOT

Negates the following expression

NOT status = 'Closed'

( ... )

Groups sub-expressions

(criticality = 'High' OR criticality = 'Critical') AND status = 'Open'

Precedence: AND binds more tightly than OR. Use parentheses to make the intended grouping explicit when mixing both.

Operators

SAQL supports three categories of operators.

Comparison Operators

Used for exact equality, inequality, and numeric/date ordering.

Operator

Syntax

Applies To

Example

Equals

=

String, Number, Boolean, Date

isFixAvailable = true

Not Equals

!=

String, Number

severity != 'Low'

Greater Than

>

Number, Date

cvssV3Score > 7.0

Greater Than or Equal

>=

Number, Date

exposureScoreInherent >= 4.0

Less Than

<

Number, Date

epss < 0.05

Less Than or Equal

<=

Number, Date

cvssV2Score <= 3.9

Set & Range Operators

Used for membership checks and numeric/date ranges.

Operator

Syntax

Example

In a set

IN ('val1', 'val2', ...)

criticality IN ('Critical', 'High')

Not in a set

NOT IN ('val1', 'val2', ...)

status NOT IN ('Closed', 'Resolved')

Between two values (inclusive)

BETWEEN low AND high

cvssV3Score BETWEEN 4.0 AND 8.9

Not between

NOT BETWEEN low AND high

epss NOT BETWEEN 0.0 AND 0.1

Text & Pattern Operators

Used for substring matching and wildcard patterns on text fields.

Operator

Syntax

Notes

Example

Contains substring

CONTAINS 'text'

Case-insensitive substring match

findingName CONTAINS 'SQL Injection'

Does not contain

NOT CONTAINS 'text'


name NOT CONTAINS 'test-'

Like (wildcard)

LIKE 'pattern'

% = any sequence; _ = single character

cveIds LIKE 'CVE-2024-%'

Not Like

NOT LIKE 'pattern'


name NOT LIKE '%deprecated%'

IP CIDR range

CIDR 'x.x.x.x/n'

Matches IPs within the given CIDR block

ipAddress CIDR '10.0.0.0/8'

Date Functions

On date attributes, you can use dynamic date functions instead of hard-coded dates. The function resolves to the actual date at query execution time, so saved filters stay current automatically.

Function

Resolves To

today()

Start of the current day

yesterday()

Start of the previous day

tomorrow()

Start of the next day

startOfWeek()

First day of the current week

endOfWeek()

Last day of the current week

startOfMonth()

First day of the current month

endOfMonth()

Last day of the current month

startOfQuarter()

First day of the current quarter

endOfQuarter()

Last day of the current quarter

startOfYear()

First day of the current year

endOfYear()

Last day of the current year

daysAgo(N)

N days before today (e.g., daysAgo(7))

weeksAgo(N)

N weeks before today (e.g., weeksAgo(4))

monthsAgo(N)

N months before today (e.g., monthsAgo(3))

yearsAgo(N)

N years before today (e.g., yearsAgo(1))

Examples:

  • firstSeen > daysAgo(30)

  • lastSeen BETWEEN monthsAgo(6) AND today()

  • cisaAddedDate >= startOfYear()

Filterable Attributes - Findings

The following attributes can be used in SAQL queries on the Findings view. The Attribute ID column shows the exact identifier to use in your query.

Finding Properties

Display Name

Attribute ID

Type

Supported Operators

Finding Name

findingName

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Finding Type

findingType

Enum

IN · NOT IN

Finding Score

exposureScoreInherent

Number (0–10)

= · != · > · >= · < · <= · BETWEEN · NOT BETWEEN

Finding Severity

severity

Enum

= · IN · NOT IN

Status

status

Enum

IN · NOT IN

First Seen

firstSeen

Date

> · < · BETWEEN · NOT BETWEEN

Last Seen

lastSeen

Date

> · < · BETWEEN · NOT BETWEEN

Age of Finding (days)

ageOfFinding

Number

= · != · > · >= · < · <= · BETWEEN · NOT BETWEEN

Fix Available

isFixAvailable

Boolean

=

Onboarding Source

onboardingSource

Enum

IN · NOT IN

Sources

contributingSources

Enum

IN · NOT IN

Source

sourceName

Enum

IN · NOT IN

Compliance Framework

complianceFramework

Enum

= · IN · NOT IN

Threat Tags

threatTags

Enum

IN · NOT IN

CVE / Vulnerability Data

Display Name

Attribute ID

Type

Supported Operators

CVE IDs

cveIds

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

CWE IDs

cweIds

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

CVE Publish Date

cvePublishDate

Date

> · < · BETWEEN · NOT BETWEEN

Age of CVE (days)

ageOfCVE

Number

= · != · > · >= · < · <= · BETWEEN · NOT BETWEEN

EPSS Score

epss

Number (0–1)

= · != · > · >= · < · <= · BETWEEN · NOT BETWEEN

CVSS V2 Score

cvssV2Score

Number (0–10)

= · != · > · >= · < · <= · BETWEEN · NOT BETWEEN

CVSS V3 Score

cvssV3Score

Number (0–10)

= · != · > · >= · < · <= · BETWEEN · NOT BETWEEN

CVSS V4 Score

cvssV4Score

Number (0–10)

= · != · > · >= · < · <= · BETWEEN · NOT BETWEEN

CVSS V2 Severity

cvssV2Severity

Enum

= · IN · NOT IN

CVSS V3 Severity

cvssV3Severity

Enum

= · IN · NOT IN

CVSS V4 Severity

cvssV4Severity

Enum

= · IN · NOT IN

CISA Known Exploited Vulnerabilities (KEV)

Display Name

Attribute ID

Type

Supported Operators

CISA KEV

cisaKev

Boolean

=

CISA KEV Added Date

cisaAddedDate

Date

> · < · BETWEEN · NOT BETWEEN

CISA KEV Due Date

cisaDueDate

Date

> · < · BETWEEN · NOT BETWEEN

Affected Asset Properties

Display Name

Attribute ID

Type

Supported Operators

Asset Name

assetName

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Asset Type

assetTypes

Enum

IN · NOT IN

Attack Surface

attackSurface

Enum

= · IN · NOT IN

Zone

zone

Enum

= · IN · NOT IN

Asset Criticality

criticality

Enum

= · IN · NOT IN

Asset Score

assetExposureScore

Number (0–10)

= · != · > · >= · < · <= · BETWEEN · NOT BETWEEN

Asset Tags

assetTags

Multi-value

CONTAINS · NOT CONTAINS · IN · NOT IN

Business Owner

assetBusinessOwner

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

IT Owner

assetITOwner

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

VM Owner

assetVMOwner

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Device Owner

assetDeviceOwner

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Ticket & Remediation

Display Name

Attribute ID

Type

Supported Operators

Ticketed

ticketed

Boolean

=

External Ticket ID

externalTicketId

Text

CONTAINS

Ticket ID

internalTicketId

Text

CONTAINS

Filterable Attributes- Assets

The following attributes can be used in SAQL queries on the Assets view.

Asset Identity

Display Name

Attribute ID

Type

Supported Operators

Asset Name

name

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Asset Types

assetTypes

Enum

= · IN · NOT IN

Asset Subtype

assetSubtype

Enum

= · IN · NOT IN

Asset Criticality

criticality

Enum

= · IN · NOT IN

Asset Score

assetExposureScore

Number (0–10)

= · != · > · >= · < · <= · BETWEEN · NOT BETWEEN

Cloud Asset

isCloudAsset

Boolean

=

Findings Count

findingsCount

Number

= · > · < · BETWEEN · NOT BETWEEN

Attack Surface

attackSurface

Enum

= · IN · NOT IN

Zone

zone

Enum

= · IN · NOT IN

Platform

platform

Enum

= · IN · NOT IN

Patch State

patchState

Enum

IN · NOT IN

Tags

tags

Multi-value

CONTAINS · NOT CONTAINS · IN · NOT IN

Network & Location

Display Name

Attribute ID

Type

Supported Operators

IP Address

ipAddress

IP / Text

= · CONTAINS · NOT CONTAINS · CIDR

Location

location

Enum

LIKE · NOT LIKE · IN · NOT IN

Designation

designation

Enum

LIKE · NOT LIKE · IN · NOT IN

Cloud Properties

Display Name

Attribute ID

Type

Supported Operators

Cloud Provider

cloudProvider

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE

Cloud Region

region

Enum / Text

= · LIKE · NOT LIKE · IN · NOT IN

Cloud Account ID

cloudAccountId

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Cloud Unique ID

cloudResourceId

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Cloud Instance ID

cloudInstanceId

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

VPC / VNet ID

cloudVpcId

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Cloud Resource Group

cloudResourceGroupName

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Source & Onboarding

Display Name

Attribute ID

Type

Supported Operators

Onboarding Source

onboardingSource

Enum

IN · NOT IN

Sources

contributingSources

Enum

IN · NOT IN

Source

sourceName

Enum

IN · NOT IN

Onboarding Time

onboardingTime

Date

= · > · < · BETWEEN · NOT BETWEEN

Last Seen

lastSeen

Date

> · < · BETWEEN · NOT BETWEEN

Last Analysed

updatedAt

Date

> · < · BETWEEN · NOT BETWEEN

Ownership

Display Name

Attribute ID

Type

Supported Operators

Business Owner

businessOwner

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

IT Owner

itOwner

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

VM Owner

vmOwner

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Device Owner

deviceOwner

Text

= · CONTAINS · NOT CONTAINS · LIKE · NOT LIKE · IN · NOT IN

Example Queries

  1. Filters assets that belong to Cloud Infrastructure or Cloud Account types, have Critical or High criticality, and were last seen within the specified date range.

    "Asset Types" IN ('Cloud Infrastructure', 'Cloud Account') AND "Asset Criticality" IN ('Critical', 'High') AND lastSeen BETWEEN '2026-03-15T18:30:00.000Z' AND '2026-04-15T18:29:59.999Z'

  2. Exploited vulnerabilities added to CISA KEV in the last 90 days

    cisaKev = true AND cisaAddedDate > daysAgo(90)

  3. Findings linked to a specific CVE pattern, not yet closed
    cveIds LIKE 'CVE-2024-%' AND status NOT IN ('Closed', 'Resolved', 'Accepted Risk')

  4. Assets in the cloud with no owner assigned, onboarded this year

    isCloudAsset = true AND businessOwner NOT CONTAINS '@' AND onboardingTime >= startOfYear()

  5. High-score findings on assets owned by a specific team, first seen this quarter

    exposureScoreInherent >= 7.0 AND assetBusinessOwner CONTAINS 'platform-team' AND firstSeen >= startOfQuarter()

  6. Assets with many findings, seen recently, not in a test environment

    findingsCount > 50 AND lastSeen > daysAgo(7) AND name NOT LIKE '%-test-%' AND name NOT LIKE '%-dev-%'

Quick-Reference - Operator Applicability by Type

Operator

String/Text

Number

Date

Enum

Boolean

IP Address

Multi-value Tag

=

✓

✓

✓

✓

✓

✓


!=

✓

✓






> / >=


✓

✓





< / <=


✓

✓





IN / NOT IN

✓



✓



✓

BETWEEN / NOT BETWEEN


✓

✓





CONTAINS / NOT CONTAINS

✓





✓

✓

LIKE / NOT LIKE

✓



✓




CIDR






✓