All Products
Search
Document Center

Security Center:DescribeExposedInstanceList

Last Updated:Jun 16, 2026

Queries information about assets exposed on the Internet.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:DescribeExposedInstanceList

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

PageSize

integer

No

The number of entries per page in a paged query. Default value: 20. If you leave this parameter empty, 20 entries are returned per page.

Note

Do not leave PageSize empty.

20

CurrentPage

integer

No

The page number of the current page in a paged query.

1

GroupId

integer

No

The ID of the server group that you want to query.

Note

You can call the DescribeAllGroups operation to query server group IDs.

9535356

VulStatus

boolean

No

Specifies whether the asset that you want to query has vulnerabilities. Valid values:

  • true: The asset has vulnerabilities.

  • false: The asset does not have vulnerabilities.

true

HealthStatus

boolean

No

Specifies whether the asset that you want to query has baseline weak password risks. Valid values:

  • true: The asset has baseline weak password risks.

  • false: The asset does not have baseline weak password risks.

true

ExposureComponent

string

No

The name of the system component exposed on the Internet that you want to query.

openssl

ExposurePort

string

No

The exposed port that you want to query.

22

ExposureIp

string

No

The public IP address of the server type or the public network connection address of the database type that you want to query.

116.12.XX.XX

InstanceId

string

No

The instance ID of the asset that you want to query.

i-bp1g6wxdwps7s9dz****

InstanceName

string

No

The name of the asset that you want to query.

abc_centos7.2_005

ResourceDirectoryAccountId

integer

No

The Alibaba Cloud account ID of the member accounts in the resource folder.

Note

You can invoke the DescribeMonitorAccounts operation to obtain this parameter.

16670360956*****

AssetType

string

No

The asset type. Valid values:

  • 0: ECS

  • 3: RDS

  • 4: MONGODB

  • 5: RDS-Redis.

0

CspmStatus

boolean

No

Specifies whether the asset that you want to query has Cloud Security Posture Management (CSPM) risks. Valid values:

  • true: The asset has CSPM risks.

  • false: The asset does not have CSPM risks.

true

ExposureComponentBizType

string

No

The type of the exposed component.

system_service

Response elements

Element

Type

Description

Example

object

RequestId

string

The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues.

598A4A61-ABA7-456B-8725-7378258276D9

PageInfo

object

The pagination information.

CurrentPage

integer

The page number of the current page in a paged query.

1

PageSize

integer

The maximum number of entries per page in a paged query.

20

TotalCount

integer

The total number of Internet-exposed assets.

2

Count

integer

The number of entries returned on the current page in a paged query.

2

ExposedInstances

array<object>

The list of asset exposure analysis results.

array<object>

ExposureIp

string

The public IP address exposed on the Internet.

116.12.XX.XX

TotalVulCount

integer

The total number of vulnerabilities exposed on the Internet that can be exploited by attackers.

0

InternetIp

string

The public IP address of the server.

116.12.XX.XX

NntfVulCount

integer

The number of low-severity vulnerabilities exposed on the Internet that can be exploited by attackers.

0

InstanceId

string

The instance ID of the asset.

i-bp1g6wxdwps7s9dz****

ExposureType

string

The expose type. Valid values:

  • INTERNET_IP: public IP addresses of Elastic Compute Service (ECS) instances

  • SLB: public IP address of a load balancing SLB instance

  • EIP: elastic IP address (EIP)

  • DNAT: NAT gateway that uses the DNAT feature to connect to the Internet

  • DB_CONNECTION: public network connection of a database.

INTERNET_IP

IntranetIp

string

The private IP address of the server.

192.168.XX.XX

RegionId

string

The ID of the region where the asset resides.

Note

For the mapping between region IDs and region names, see Regions and zones.

cn-hangzhou

ExposureTypeId

string

The instance ID that corresponds to the expose type. Different expose types correspond to different instance IDs. Valid values:

  • If ExposureType is INTERNET_IP: the value is empty.

  • If ExposureType is SLB: the value is the ID of the load balancing public instance.

  • If ExposureType is EIP: the value is the ID of the EIP instance.

  • If ExposureType is DNAT: the value is the ID of the NAT gateway instance.

  • If ExposureType is DB_CONNECTION: the value is the ID of the database instance.

i-ew11313a****

AsapVulCount

integer

The number of high-severity vulnerabilities exposed on the Internet that can be exploited by attackers.

0

ExposurePort

string

The port exposed on the Internet.

22

Uuid

string

The UUID of the server or the instance ID of the cloud service.

dd803d9e-a337-4add-9c5b-7d503e08****

GroupName

string

The name of the server group.

testGroup

GroupId

integer

The ID of the server group.

9469268

ExploitHealthCount

integer

The number of baseline weak password risks.

0

InstanceName

string

The name of the asset.

abc_centos7.2_005

ExposureComponent

string

The system component exposed on the Internet.

openssl,openssh

LaterVulCount

integer

The number of medium-severity vulnerabilities exposed on the Internet that can be exploited by attackers.

0

CspmAlarmCount

integer

The number of CSPM risks.

0

AssetType

integer

The asset type. Valid values:

  • 0: Elastic Computing Service (ECS) server

  • 1: load balancing (SLB)

  • 2: NAT gateway

  • 3: ApsaraDB RDS database

  • 4: MongoDB database

  • 5: Redis database

  • 6: container image (IMAGE)

  • 7: container (CONTAINER).

0

CloudAssetInfo

string

The JSON string of cloud service information for database-type assets. The fields include:

  • assetSubType: the asset subtype

  • assetSubTypeName: the name of the asset subtype

  • assetType: the asset type

  • assetTypeName: the name of the asset type

  • vendor: the asset vendor.

{assetSubTypeName":"INSTANCE","assetType":3,"assetTypeName":"RDS","vendor":0}

ExposureComponentList

array<object>

The list of exposed component information.

object

The exposed component information.

ListenPort

string

Exposed port.

22

ComponentName

string

Expose components.

openssh

ComponentVersion

string

Expose component version.

8.7p1

ComponentBizType

string

Expose component type.

system_service

Examples

Success response

JSON format

{
  "RequestId": "598A4A61-ABA7-456B-8725-7378258276D9",
  "PageInfo": {
    "CurrentPage": 1,
    "PageSize": 20,
    "TotalCount": 2,
    "Count": 2
  },
  "ExposedInstances": [
    {
      "ExposureIp": "116.12.XX.XX",
      "TotalVulCount": 0,
      "InternetIp": "116.12.XX.XX",
      "NntfVulCount": 0,
      "InstanceId": "i-bp1g6wxdwps7s9dz****",
      "ExposureType": "INTERNET_IP",
      "IntranetIp": "192.168.XX.XX",
      "RegionId": "cn-hangzhou",
      "ExposureTypeId": "i-ew11313a****",
      "AsapVulCount": 0,
      "ExposurePort": "22",
      "Uuid": "dd803d9e-a337-4add-9c5b-7d503e08****",
      "GroupName": "testGroup",
      "GroupId": 9469268,
      "ExploitHealthCount": 0,
      "InstanceName": "abc_centos7.2_005",
      "ExposureComponent": "openssl,openssh",
      "LaterVulCount": 0,
      "CspmAlarmCount": 0,
      "AssetType": 0,
      "CloudAssetInfo": "{assetSubTypeName\":\"INSTANCE\",\"assetType\":3,\"assetTypeName\":\"RDS\",\"vendor\":0}",
      "ExposureComponentList": [
        {
          "ListenPort": "22",
          "ComponentName": "openssh",
          "ComponentVersion": "8.7p1",
          "ComponentBizType": "system_service"
        }
      ]
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 NoPermission no permission
400 RdCheckNoPermission Resource directory account verification has no permission.
500 ServerError ServerError
500 RdCheckInnerError Resource directory account service internal error.
403 NoPermission caller has no permission

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.