# Compromised Device Search

POST /cti/compromised-devices: Searches compromised (infostealer-infected) devices linked to your employees.

Source: https://docs.deepinfo.com/reference/cti/compromised-device-search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/cti/compromised-devices`

Searches compromised (infostealer-infected) devices linked to your employees.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "compromised_device.hardware_id",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "compromised_device.hardware_id",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `compromised_device.hardware_id` | The hardware ID the infostealer recorded for the infected device, which identifies one machine across logs. |
| `compromised_device.user_info.username` | The operating-system user name on the infected device, as the stealer log recorded it. |
| `compromised_device.user_info.machine_name` | The computer name of the infected device; the platform shows it as MACHINE. |
| `compromised_device.user_info.country` | The country the infected device was in when the log was made, as the stealer recorded it. |
| `compromised_device.user_info.location` | The location the stealer log gives for the device, such as a city or region. |
| `compromised_device.user_info.zip_code` | The postal code the stealer log gives for the device's location. |
| `compromised_device.user_info.language` | The system language of the infected device; the platform shows it as LANGUAGE. |
| `compromised_device.user_info.time_zone` | The time zone set on the infected device; the platform shows it as TIMEZONE. |
| `compromised_device.user_info.operating_system` | The operating system of the infected device, such as a Windows version; the platform shows it as OS. |
| `compromised_device.user_info.screen_resolution` | The screen resolution of the infected device, as the stealer recorded it. |
| `compromised_device.user_info.ip_address` | The IP address the infected device had when the data was stolen; the platform shows it as IP. |
| `compromised_device.user_info.keyboard_layouts` | The keyboard layouts installed on the infected device, a list of language codes. |
| `compromised_device.system_info.ram` | The amount of memory (RAM) of the infected device, as text. |
| `compromised_device.system_info.cpu` | The processor (CPU) model of the infected device. |
| `compromised_device.system_info.gpu` | The graphics cards (GPU) of the infected device, a list. |
| `compromised_device.system_info.installed_antivirus` | The antivirus products found on the infected device, a list; the platform shows it as AV. |
| `compromised_device.installed_softwares.name` | The name of a program installed on the infected device. |
| `compromised_device.installed_softwares.version` | The version of a program installed on the infected device. |
| `compromised_device.installed_softwares.category` | The category of a program installed on the infected device. |
| `compromised_device.installed_browsers.name` | The name of a web browser installed on the infected device. |
| `compromised_device.installed_browsers.version` | The version of a web browser installed on the infected device. |
| `account.id` | The ID of the employee account the device is linked to, the `id` returned by Compromised Employee Account Search. |
| `account.email` | The e-mail address of the employee account the device is linked to. |
| `leaked_data.stealer_docs` | The names of the files the infostealer took from the device, a list. |
| `leaked_data.passwords.url` | The address of the login page a stolen password was saved for. |
| `leaked_data.passwords.fqdn` | The full host name of the login page a stolen password was saved for, such as `login.acme.example`. |
| `leaked_data.passwords.domain` | The registered domain of the login page a stolen password was saved for, such as `acme.example`. |
| `leaked_data.passwords.username` | The user name or e-mail address saved with a stolen password. Responses mask personal values. |
| `leaked_data.passwords.password` | The stolen password itself. Responses show it masked. |
| `leaked_data.passwords.leak_source_type` | Where the stolen password came from, such as the kind of stealer log. |
| `leaked_data.passwords.source_application` | The application the password was stolen from, such as a web browser. |
| `leaked_data.tokens.raw_value` | The stolen token itself, such as a session or API token. Responses show it masked. |
| `leaked_data.tokens.token_type` | The kind of stolen token, such as a session token or an API key. |
| `leaked_data.tokens.possible_issuer` | The service that probably issued the stolen token; the platform shows it as ISSUER. |
| `leaked_data.tokens.associated_user` | The user the stolen token belongs to; the platform shows it as USER. |
| `leaked_data.tokens.website` | The website the stolen token is used on. |
| `leaked_data.tokens.category` | The category of the stolen token's service. |
| `leaked_data.tokens.risk_reason` | Why the stolen token got its risk level, in words. |
| `leaked_data.tokens.source_application` | The application the token was stolen from, such as a web browser. |
| `leaked_data.auto_fills.field_name` | The name of a form field whose saved (autofill) value was stolen, such as `email` or `phone`. |
| `leaked_data.auto_fills.field_value` | The stolen autofill value. Responses mask personal values. |
| `leaked_data.auto_fills.data_type` | The kind of data in a stolen autofill value, such as an e-mail address or a phone number. |
| `leaked_data.auto_fills.source_application` | The application the autofill value was stolen from, such as a web browser. |
| `leaked_data.auto_fills.source_name` | The name of the browser profile or source the autofill value was read from. |
| `leaked_data.cookies.domain` | A domain the infected device had cookies for, such as `acme.example`. |
| `leaked_data.cookies.subdomains` | The subdomains of that domain the device had cookies for, a list. |
| `leaked_data.sensitive_cookies.domain` | The domain a stolen sensitive cookie (one that can open a session) belongs to. |
| `leaked_data.sensitive_cookies.name` | The name of a stolen sensitive cookie. |
| `leaked_data.sensitive_cookies.value` | The value of a stolen sensitive cookie. Responses show it masked. |
| `leaked_data.sensitive_cookies.path` | The path a stolen sensitive cookie applies to, such as `/`. |
| `leaked_data.sensitive_cookies.cookie_type` | The kind of stolen cookie, such as a session or authentication cookie. |
| `leaked_data.sensitive_cookies.risk_reason` | Why the stolen cookie got its risk level, in words. |
| `leaked_data.sensitive_cookies.source_application` | The application the cookie was stolen from, such as a web browser. |
| `leaked_data.documents.name` | The file name of a document the infostealer took from the device. |
| `leaked_data.documents.creator` | The author recorded in a stolen document's properties. Responses mask personal values. |
| `leaked_data.documents.last_modified_by` | The last editor recorded in a stolen document's properties. Responses mask personal values. |
| `leaked_data.documents.content` | The text of a stolen document. Responses do not show it. |
| `leaked_data.documents.language` | The language of a stolen document's text. |
| `leaked_data.documents.sensitive_data_score` | A score of how much sensitive data a stolen document holds. |
| `leaked_data.documents.sensitive_data_type` | The kinds of sensitive data found in a stolen document, a list. |
| `compromise_summary.corporate_email_address` | Your organization's e-mail addresses found on the device, a list. |
| `compromise_summary.other_email_addresses` | The other e-mail addresses found on the device, a list. |
| `compromise_summary.same_password_rate` | How often the same password is reused among the device's stolen passwords, as text. |
| `compromise_summary.accessed_internal_resources` | Internal resources of your organization the device had stolen access to, such as internal login pages, a list. |
| `compromise_summary.corporate_risk` | A short assessment of the risk to your organization; the platform shows it as CORPORATE RISK. |
| `compromise_summary.financial_risk` | A short assessment of the financial risk; the platform shows it as FINANCIAL RISK. |
| `compromise_summary.identity_theft_risk` | A short assessment of the identity theft risk; the platform shows it as IDENTITY THEFT. |
| `compromise_summary.corporate_espionage` | A short assessment of the corporate espionage risk. |
| `compromise_summary.ransomware_threat` | A short assessment of the ransomware threat; the platform shows it as RANSOMWARE THREAT. |
| `compromise_summary.phishing_risk` | A short assessment of the phishing risk; the platform shows it as PHISHING RISK. |
| `compromise_summary.session_hijacking_risk` | A short assessment of the session hijacking risk, from the stolen cookies and tokens; the platform shows it as SESSION HIJACKING. |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `compromised_device.log_date` | When the infostealer log of this device was created, that is, when the data was stolen. |
| `leaked_data.sensitive_cookies.expiration_timestamp` | When the stolen cookie expires. A cookie that has not expired can still open a session. |
| `leaked_data.documents.created_date` | When a stolen document was created, from its properties. |
| `leaked_data.documents.modified_date` | When a stolen document was last changed, from its properties. |
| `compromise_summary.password_count` | The number of passwords stolen from the device; the platform shows it as PASSWORDS. |
| `compromise_summary.token_count` | The number of tokens stolen from the device; the platform shows it as TOKEN. |
| `compromise_summary.autofill_count` | The number of autofill values stolen from the device; the platform shows it as AUTOFILL. |
| `compromise_summary.cookie_count` | The number of cookies stolen from the device. |
| `compromise_summary.sensitive_cookie_count` | The number of sensitive cookies (ones that can open a session) stolen from the device; the platform shows it as COOKIE. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `leaked_data.passwords.is_corporate` | `true` when the stolen password is for one of your organization's own services. |
| `leaked_data.sensitive_cookies.secure` | `true` when the stolen cookie is sent over HTTPS only. |
| `leaked_data.sensitive_cookies.http_only` | `true` when the stolen cookie is hidden from page scripts (HttpOnly). |
| `leaked_data.sensitive_cookies.include_subdomains` | `true` when the stolen cookie also applies to the domain's subdomains. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `leaked_data.tokens.risk_level` | How risky the stolen token is: `low`, `medium`, `high` or `critical`. |
| `leaked_data.sensitive_cookies.risk_level` | How risky the stolen cookie is: `low`, `medium`, `high` or `critical`. |
| `compromise_summary.risk_level` | The device's overall risk level: `low`, `medium`, `high` or `critical`. |

### Sortable Fields

| Field | Description |
|---|---|
| `compromised_device.hardware_id` | The hardware ID the infostealer recorded for the infected device, which identifies one machine across logs. |
| `compromised_device.log_date` | When the infostealer log of this device was created, that is, when the data was stolen. |
| `compromised_device.user_info.username` | The operating-system user name on the infected device, as the stealer log recorded it. |
| `compromised_device.user_info.machine_name` | The computer name of the infected device; the platform shows it as MACHINE. |
| `compromised_device.user_info.country` | The country the infected device was in when the log was made, as the stealer recorded it. |
| `compromised_device.user_info.language` | The system language of the infected device; the platform shows it as LANGUAGE. |
| `compromised_device.user_info.operating_system` | The operating system of the infected device, such as a Windows version; the platform shows it as OS. |
| `compromised_device.user_info.screen_resolution` | The screen resolution of the infected device, as the stealer recorded it. |
| `compromised_device.user_info.ip_address` | The IP address the infected device had when the data was stolen; the platform shows it as IP. |
| `compromise_summary.password_count` | The number of passwords stolen from the device; the platform shows it as PASSWORDS. |
| `compromise_summary.token_count` | The number of tokens stolen from the device; the platform shows it as TOKEN. |
| `compromise_summary.autofill_count` | The number of autofill values stolen from the device; the platform shows it as AUTOFILL. |
| `compromise_summary.cookie_count` | The number of cookies stolen from the device. |
| `compromise_summary.sensitive_cookie_count` | The number of sensitive cookies (ones that can open a session) stolen from the device; the platform shows it as COOKIE. |
| `compromise_summary.same_password_rate` | How often the same password is reused among the device's stolen passwords, as text. |
| `compromise_summary.risk_level` | The device's overall risk level: `low`, `medium`, `high` or `critical`. |
| `compromise_summary.corporate_risk` | A short assessment of the risk to your organization; the platform shows it as CORPORATE RISK. |
| `compromise_summary.financial_risk` | A short assessment of the financial risk; the platform shows it as FINANCIAL RISK. |
| `compromise_summary.identity_theft_risk` | A short assessment of the identity theft risk; the platform shows it as IDENTITY THEFT. |
| `compromise_summary.corporate_espionage` | A short assessment of the corporate espionage risk. |
| `compromise_summary.ransomware_threat` | A short assessment of the ransomware threat; the platform shows it as RANSOMWARE THREAT. |
| `compromise_summary.phishing_risk` | A short assessment of the phishing risk; the platform shows it as PHISHING RISK. |
| `compromise_summary.session_hijacking_risk` | A short assessment of the session hijacking risk, from the stolen cookies and tokens; the platform shows it as SESSION HIJACKING. |

## Response Fields

| Field | Type |
|---|---|
| `page` | integer |
| `page_size` | integer |
| `result_count` | integer |
| `results` | array of object |
| `results[].id` | string |
| `results[].account` | object |
| `results[].compromised_device` | object |
| `results[].leaked_data` | object |
| `results[].compromise_summary` | object |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-devices?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 0,
  "results": []
}
```

### 400 · Invalid Parameter (invalid page=0)

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-devices?page=0' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "page",
      "details": [
        "Ensure this value is greater than or equal to 1."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-devices?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "compromised_device.hardware_id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.username",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.machine_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.country",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.location",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.zip_code",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.language",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.time_zone",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.operating_system",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.screen_resolution",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.ip_address",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.user_info.keyboard_layouts",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.system_info.ram",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.system_info.cpu",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.system_info.gpu",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.system_info.installed_antivirus",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.installed_softwares.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.installed_softwares.version",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.installed_softwares.category",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.installed_browsers.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.installed_browsers.version",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.email",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.stealer_docs",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.passwords.url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.passwords.fqdn",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.passwords.domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.passwords.username",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.passwords.password",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.passwords.leak_source_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.passwords.source_application",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.tokens.raw_value",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.tokens.token_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.tokens.possible_issuer",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.tokens.associated_user",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.tokens.website",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.tokens.category",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.tokens.risk_reason",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.tokens.source_application",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.auto_fills.field_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.auto_fills.field_value",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.auto_fills.data_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.auto_fills.source_application",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.auto_fills.source_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.cookies.domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.cookies.subdomains",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.sensitive_cookies.domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.sensitive_cookies.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.sensitive_cookies.value",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.sensitive_cookies.path",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.sensitive_cookies.cookie_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.sensitive_cookies.risk_reason",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.sensitive_cookies.source_application",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.documents.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.documents.creator",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.documents.last_modified_by",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.documents.content",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.documents.language",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.documents.sensitive_data_score",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.documents.sensitive_data_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.corporate_email_address",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.other_email_addresses",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.same_password_rate",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.accessed_internal_resources",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.corporate_risk",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.financial_risk",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.identity_theft_risk",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.corporate_espionage",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.ransomware_threat",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.phishing_risk",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.session_hijacking_risk",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromised_device.log_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "leaked_data.sensitive_cookies.expiration_timestamp",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "leaked_data.documents.created_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "leaked_data.documents.modified_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "compromise_summary.password_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "compromise_summary.token_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "compromise_summary.autofill_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "compromise_summary.cookie_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "compromise_summary.sensitive_cookie_count",
        "type": "eq",
        "value": 0
      },
      {
        "name": "leaked_data.passwords.is_corporate",
        "type": "eq",
        "value": true
      },
      {
        "name": "leaked_data.sensitive_cookies.secure",
        "type": "eq",
        "value": true
      },
      {
        "name": "leaked_data.sensitive_cookies.http_only",
        "type": "eq",
        "value": true
      },
      {
        "name": "leaked_data.sensitive_cookies.include_subdomains",
        "type": "eq",
        "value": true
      },
      {
        "name": "leaked_data.tokens.risk_level",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "leaked_data.sensitive_cookies.risk_level",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "compromise_summary.risk_level",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "compromised_device.hardware_id",
      "order": "desc"
    }
  ]
}'
```
