# CTI Dashboard

Read the one-page Cyber Threat Intelligence summary of employee, client and payment card credentials found in leaked data, with exposure timelines, risk levels, credential states and the latest exposures.

Source: https://docs.deepinfo.com/guide/cti/dashboard/

Last updated: 2026-09-26

---
The Cyber Threat Intelligence (CTI) dashboard sums up, on one page, the credentials found in leaked data for your organization: those of
your employees, of your customers and of payment cards. Each section links to the full lists.

## Before You Start

- **Package:** CTI. Without it, the dashboard is replaced by a lock screen; see
  [What you can access](/guide/basics/packages-and-roles/).
- **Role:** Admin or Member.

## Where to Find It

**Sidebar:** **CYBER THREAT INTELLIGENCE** › **CTI DASHBOARD** · https://platform.deepinfo.com/app/cti/dashboard

From the [Global dashboard](/guide/global-dashboard/), the **CTI** card at the top and the
**GO TO CTI DASHBOARD** button open this page too.

## Read the Screen

The breadcrumb reads **CTI / CYBER THREAT INTELLIGENCE DASHBOARD** and the page title is
**Cyber Threat Intelligence Dashboard**. From top to bottom:

1. **Summary cards.** Four cards with the current totals:
   **COMPROMISED EMPLOYEE DATA**, **EXPOSED CREDENTIALS**, **COMPROMISED CLIENT CREDENTIALS** and
   **COMPROMISED PAYMENT CREDENTIALS**. A card shows **-** when there is nothing to count.
2. **COMPROMISED EMPLOYEE DATA** section.
3. **COMPROMISED CLIENT CREDENTIALS** section.
4. **COMPROMISED PAYMENT CREDENTIALS** section.

Each section has a **GO TO … PAGE** button that opens the section's page in a new browser tab.

![The four summary cards at the top of the CTI dashboard.](/img/guide/cti/dashboard-01.png)

### COMPROMISED EMPLOYEE DATA

**GO TO COMPROMISED EMPLOYEE DATA PAGE** opens the [overview](/guide/cti/compromised-employee-data/).

| Card | What it shows |
|---|---|
| **CREDENTIAL EXPOSURE TIMELINE** | A column chart of exposed employee credentials per period. Choose **DAILY** (the default), **WEEKLY** or **MONTHLY** in the card's interval list. |
| **RISK DISTRIBUTION** | A pie of compromised employees by risk level: **CRITICAL**, **HIGH**, **MEDIUM**, **LOW**. |
| **CREDENTIAL STATUS STATS** | A pie of employee credentials that are **ACTIVE** and **INACTIVE**. See [Change the state of exposed credentials](/guide/cti/change-credential-state/). |
| **RECENTLY EXPOSED CREDENTIALS** | The five most recent exposed credentials. Each row shows the service, a platform tag such as **WEB**, the host and the employee's e-mail address. The heading and its arrow open the [EXPOSED CREDENTIALS](/guide/cti/credential-exposures/) tab. |
| **RECENTLY EXPOSED EMPLOYEES** | The five most recently exposed employees. Each row shows the risk level, the e-mail address, **CREDS**, **PASSWORDS** and **AVG STRENGTH SCORE** (out of 10). The heading and its arrow open the [COMPROMISED EMPLOYEES](/guide/cti/compromised-employees/) tab; a row opens that employee's page. |

![The COMPROMISED EMPLOYEE DATA section of the CTI dashboard with the interval list of CREDENTIAL EXPOSURE TIMELINE open; e-mail addresses and organization names are blurred.](/img/guide/cti/dashboard-02.png)

### COMPROMISED CLIENT CREDENTIALS

**GO TO COMPROMISED CLIENT CREDENTIALS PAGE** opens
[Compromised Client Credentials](/guide/cti/compromised-client-credentials/).

- **CREDENTIAL EXPOSURE TIMELINE**: exposed client credentials per period.
- **RECENTLY EXPOSED CLIENTS**: the latest client credentials, each with the client's e-mail address and the
  date it was found.

### COMPROMISED PAYMENT CREDENTIALS

**GO TO COMPROMISED PAYMENT CREDENTIALS PAGE** opens
[Compromised Payment Credentials](/guide/cti/compromised-payment-credentials/).

- **CREDENTIAL EXPOSURE TIMELINE**: exposed payment credentials per period.
- **RECENTLY EXPOSED PAYMENTS**: the latest payment card records, or **No Result Found.** when there are none.

## Good to Know

- **Five bars at most.** The **CREDENTIAL EXPOSURE TIMELINE** of the employee section shows up to five
  periods. The same chart on the [overview](/guide/cti/compromised-employee-data/) shows up to twelve.
- **CREDS and PASSWORDS.** In **RECENTLY EXPOSED EMPLOYEES**, both columns can show the number of unique
  passwords. To see how many credentials an employee has, open the employee and read
  **CREDENTIAL LEAK**.
- **No score.** The CTI dashboard has no security score. Security scores belong to External Attack Surface Management (EASM).
- **No filters or export here.** To filter or export, open the lists. The **CTI REPORTS** tab of **REPORTS**
  has full exports of each credential type.

## Do This With the API

- [Compromised Employee Credential Stats](/reference/cti/compromised-employee-credential-stats/)
- [Compromised Employee Credential Exposure Timeline](/reference/cti/compromised-employee-credential-exposure-timeline/)
- [Compromised Employee Credential Status Stats](/reference/cti/compromised-employee-credential-status-stats/)
- [Compromised Employee Account Risk Distribution Stats](/reference/cti/compromised-employee-account-risk-distribution-stats/)
- [Compromised Client Credential Stats](/reference/cti/compromised-client-credential-stats/)
- [Compromised Payment Credential Stats](/reference/cti/compromised-payment-credential-stats/)
