Cyber Threat Intelligence (CTI) shows data found in leaks: your employees' passwords, your customers' logins, payment card data and posts from dark web sources. This page lists what the platform masks on screen and what it shows as found, so you can decide what to reveal, export or share.

Before You Start

This applies to everyone who can open CTI; see What you can access.

Passwords Are Masked

Leaked passwords are masked on screen until you choose to show them:

Where How the password appears How to show it
EXPOSED CREDENTIALS tab, list view •••••• in the PASSWORD column Tick SHOW PASSWORD
Credential drawer, OVERVIEW tab ●●●●●●●● next to PASSWORD Select the eye icon
Quick view and the credential's own page •••••• in the PASSWORD figure Use the list view or the drawer
Employee's page, CREDENTIALS tab •••••• in the PASSWORD column Tick SHOW PASSWORD

These screens show no passwords at all:

SHOW PASSWORD is not available in quick view. Switch to list view to use it.

What Showing a Password Does

Ticking SHOW PASSWORD, or selecting the eye icon, shows the password in plain text in your browser. Anyone who can see your screen can read it. Untick SHOW PASSWORD to mask the list again.

Show a password only when you need it, and mask it again as soon as you are done. Before you share your screen or take a screenshot, check that no password is shown.

What Stays Visible While Passwords Are Masked

  • Password analysis. STRUCTURE on the PASSWORD ANALYSIS tab, and DOMINANT STRUCTURE in an employee's security profile, show the pattern of character types in a password. LENGTH, CONTAINS and the YES / NO checks describe it further. Together they reveal the shape of a password without its characters. Keep this in mind before you share a screenshot.
  • The Password filter. On the EXPOSED CREDENTIALS tab, CREDENTIAL › Password filters the list by password value, whether or not passwords are shown. Anyone who can use the filters can look for a given password in the leaked data.
  • Account details. Employees' e-mail addresses and details such as department and title, and the usernames and e-mail addresses of your customers, are shown as they are.

Card Data and Dark Web Results

  • Payment cards. The COMPROMISED PAYMENTS list has a PAN column for the card number; see Review compromised payment credentials. Handle everything on that page under your organization's rules for card data.
  • Dark web results. Results of Dark Web Search can contain e-mail addresses, IP addresses, card numbers, social security numbers and the full text of the source. Handle them under the same rules as card data.

Data Kept in Your Browser

Dark Web Search keeps your search tabs, with their searches and results, in this browser for your user, so they are still there after a reload. They are not shared with other browsers or computers. On a shared computer, close the search tabs you no longer need, or clear the browser's site data for the platform when you finish.

Exports and Reports

EXPORT on the CTI lists and the exports on the CTI REPORTS tab of REPORTS create files on your computer. The platform does not describe what each EXPORT SCOPE includes, so check an exported file for passwords and other leaked values before you pass it on. Store exported files securely, share them only with people who need them, and delete them when you no longer need them.

Act on Leaked Data Responsibly

  • Use it only to protect the accounts concerned. For example, have the leaked password changed on every service where it was used, and turn on multi-factor authentication where the service offers it. For your customers' accounts, follow your own process, such as asking the customer to reset the password.
  • Do not sign in with a leaked credential to check whether it still works.
  • Do not copy passwords or card numbers into tickets, e-mail or chat. Refer to a credential by its service and account instead, or share the address of its page in the platform.
  • Follow your organization's policies for personal data and incident response.
  • Record what you did by changing the credential's state; see Change the state of exposed credentials.

Good to Know

  • Screenshots. Take screenshots of CTI screens with passwords masked, and check the password analysis fields and e-mail addresses before you share them.

Do This With the API

The search responses include the password field of each employee and client credential, and the card number fields (pan, pan_masked, pan_last_four) of each payment record. Protect the responses, and any files or logs your scripts write, as you would the platform's screens:

Last updated