POSThttps://api.deepinfo.com/v1/cti/compromised-devices

Searches compromised (infostealer-infected) devices linked to your employees.

Authentication

Send your API key in the apikey request header.

Query Parameters

ParameterRequiredDescription
page_sizeOptional
Min 25, max 100. Default 100.
Example25
pageOptional
Min 1, max 800. Default 1.
Example1

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "compromised_device.hardware_id",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "compromised_device.hardware_id",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in startswith endswith contains_any contains_all exists

FieldDescription
compromised_device.hardware_idThe hardware ID the infostealer recorded for the infected device, which identifies one machine across logs.
compromised_device.user_info.usernameThe operating-system user name on the infected device, as the stealer log recorded it.
compromised_device.user_info.machine_nameThe computer name of the infected device; the platform shows it as MACHINE.
compromised_device.user_info.countryThe country the infected device was in when the log was made, as the stealer recorded it.
compromised_device.user_info.locationThe location the stealer log gives for the device, such as a city or region.
compromised_device.user_info.zip_codeThe postal code the stealer log gives for the device's location.
compromised_device.user_info.languageThe system language of the infected device; the platform shows it as LANGUAGE.
compromised_device.user_info.time_zoneThe time zone set on the infected device; the platform shows it as TIMEZONE.
compromised_device.user_info.operating_systemThe operating system of the infected device, such as a Windows version; the platform shows it as OS.
compromised_device.user_info.screen_resolutionThe screen resolution of the infected device, as the stealer recorded it.
compromised_device.user_info.ip_addressThe IP address the infected device had when the data was stolen; the platform shows it as IP.
compromised_device.user_info.keyboard_layoutsThe keyboard layouts installed on the infected device, a list of language codes.
compromised_device.system_info.ramThe amount of memory (RAM) of the infected device, as text.
compromised_device.system_info.cpuThe processor (CPU) model of the infected device.
compromised_device.system_info.gpuThe graphics cards (GPU) of the infected device, a list.
compromised_device.system_info.installed_antivirusThe antivirus products found on the infected device, a list; the platform shows it as AV.
compromised_device.installed_softwares.nameThe name of a program installed on the infected device.
compromised_device.installed_softwares.versionThe version of a program installed on the infected device.
compromised_device.installed_softwares.categoryThe category of a program installed on the infected device.
compromised_device.installed_browsers.nameThe name of a web browser installed on the infected device.
compromised_device.installed_browsers.versionThe version of a web browser installed on the infected device.
account.idThe ID of the employee account the device is linked to, the id returned by Compromised Employee Account Search.
account.emailThe e-mail address of the employee account the device is linked to.
leaked_data.stealer_docsThe names of the files the infostealer took from the device, a list.
leaked_data.passwords.urlThe address of the login page a stolen password was saved for.
leaked_data.passwords.fqdnThe full host name of the login page a stolen password was saved for, such as login.acme.example.
leaked_data.passwords.domainThe registered domain of the login page a stolen password was saved for, such as acme.example.
leaked_data.passwords.usernameThe user name or e-mail address saved with a stolen password. Responses mask personal values.
leaked_data.passwords.passwordThe stolen password itself. Responses show it masked.
leaked_data.passwords.leak_source_typeWhere the stolen password came from, such as the kind of stealer log.
leaked_data.passwords.source_applicationThe application the password was stolen from, such as a web browser.
leaked_data.tokens.raw_valueThe stolen token itself, such as a session or API token. Responses show it masked.
leaked_data.tokens.token_typeThe kind of stolen token, such as a session token or an API key.
leaked_data.tokens.possible_issuerThe service that probably issued the stolen token; the platform shows it as ISSUER.
leaked_data.tokens.associated_userThe user the stolen token belongs to; the platform shows it as USER.
leaked_data.tokens.websiteThe website the stolen token is used on.
leaked_data.tokens.categoryThe category of the stolen token's service.
leaked_data.tokens.risk_reasonWhy the stolen token got its risk level, in words.
leaked_data.tokens.source_applicationThe application the token was stolen from, such as a web browser.
leaked_data.auto_fills.field_nameThe name of a form field whose saved (autofill) value was stolen, such as email or phone.
leaked_data.auto_fills.field_valueThe stolen autofill value. Responses mask personal values.
leaked_data.auto_fills.data_typeThe kind of data in a stolen autofill value, such as an e-mail address or a phone number.
leaked_data.auto_fills.source_applicationThe application the autofill value was stolen from, such as a web browser.
leaked_data.auto_fills.source_nameThe name of the browser profile or source the autofill value was read from.
leaked_data.cookies.domainA domain the infected device had cookies for, such as acme.example.
leaked_data.cookies.subdomainsThe subdomains of that domain the device had cookies for, a list.
leaked_data.sensitive_cookies.domainThe domain a stolen sensitive cookie (one that can open a session) belongs to.
leaked_data.sensitive_cookies.nameThe name of a stolen sensitive cookie.
leaked_data.sensitive_cookies.valueThe value of a stolen sensitive cookie. Responses show it masked.
leaked_data.sensitive_cookies.pathThe path a stolen sensitive cookie applies to, such as /.
leaked_data.sensitive_cookies.cookie_typeThe kind of stolen cookie, such as a session or authentication cookie.
leaked_data.sensitive_cookies.risk_reasonWhy the stolen cookie got its risk level, in words.
leaked_data.sensitive_cookies.source_applicationThe application the cookie was stolen from, such as a web browser.
leaked_data.documents.nameThe file name of a document the infostealer took from the device.
leaked_data.documents.creatorThe author recorded in a stolen document's properties. Responses mask personal values.
leaked_data.documents.last_modified_byThe last editor recorded in a stolen document's properties. Responses mask personal values.
leaked_data.documents.contentThe text of a stolen document. Responses do not show it.
leaked_data.documents.languageThe language of a stolen document's text.
leaked_data.documents.sensitive_data_scoreA score of how much sensitive data a stolen document holds.
leaked_data.documents.sensitive_data_typeThe kinds of sensitive data found in a stolen document, a list.
compromise_summary.corporate_email_addressYour organization's e-mail addresses found on the device, a list.
compromise_summary.other_email_addressesThe other e-mail addresses found on the device, a list.
compromise_summary.same_password_rateHow often the same password is reused among the device's stolen passwords, as text.
compromise_summary.accessed_internal_resourcesInternal resources of your organization the device had stolen access to, such as internal login pages, a list.
compromise_summary.corporate_riskA short assessment of the risk to your organization; the platform shows it as CORPORATE RISK.
compromise_summary.financial_riskA short assessment of the financial risk; the platform shows it as FINANCIAL RISK.
compromise_summary.identity_theft_riskA short assessment of the identity theft risk; the platform shows it as IDENTITY THEFT.
compromise_summary.corporate_espionageA short assessment of the corporate espionage risk.
compromise_summary.ransomware_threatA short assessment of the ransomware threat; the platform shows it as RANSOMWARE THREAT.
compromise_summary.phishing_riskA short assessment of the phishing risk; the platform shows it as PHISHING RISK.
compromise_summary.session_hijacking_riskA short assessment of the session hijacking risk, from the stolen cookies and tokens; the platform shows it as SESSION HIJACKING.

Operators eq in gte lte exists

FieldDescription
compromised_device.log_dateWhen the infostealer log of this device was created, that is, when the data was stolen.
leaked_data.sensitive_cookies.expiration_timestampWhen the stolen cookie expires. A cookie that has not expired can still open a session.
leaked_data.documents.created_dateWhen a stolen document was created, from its properties.
leaked_data.documents.modified_dateWhen a stolen document was last changed, from its properties.
compromise_summary.password_countThe number of passwords stolen from the device; the platform shows it as PASSWORDS.
compromise_summary.token_countThe number of tokens stolen from the device; the platform shows it as TOKEN.
compromise_summary.autofill_countThe number of autofill values stolen from the device; the platform shows it as AUTOFILL.
compromise_summary.cookie_countThe number of cookies stolen from the device.
compromise_summary.sensitive_cookie_countThe number of sensitive cookies (ones that can open a session) stolen from the device; the platform shows it as COOKIE.

Operators eq exists

FieldDescription
leaked_data.passwords.is_corporatetrue when the stolen password is for one of your organization's own services.
leaked_data.sensitive_cookies.securetrue when the stolen cookie is sent over HTTPS only.
leaked_data.sensitive_cookies.http_onlytrue when the stolen cookie is hidden from page scripts (HttpOnly).
leaked_data.sensitive_cookies.include_subdomainstrue when the stolen cookie also applies to the domain's subdomains.

Operators eq in exists

FieldDescription
leaked_data.tokens.risk_levelHow risky the stolen token is: low, medium, high or critical.
leaked_data.sensitive_cookies.risk_levelHow risky the stolen cookie is: low, medium, high or critical.
compromise_summary.risk_levelThe device's overall risk level: low, medium, high or critical.

Sortable Fields

FieldDescription
compromised_device.hardware_idThe hardware ID the infostealer recorded for the infected device, which identifies one machine across logs.
compromised_device.log_dateWhen the infostealer log of this device was created, that is, when the data was stolen.
compromised_device.user_info.usernameThe operating-system user name on the infected device, as the stealer log recorded it.
compromised_device.user_info.machine_nameThe computer name of the infected device; the platform shows it as MACHINE.
compromised_device.user_info.countryThe country the infected device was in when the log was made, as the stealer recorded it.
compromised_device.user_info.languageThe system language of the infected device; the platform shows it as LANGUAGE.
compromised_device.user_info.operating_systemThe operating system of the infected device, such as a Windows version; the platform shows it as OS.
compromised_device.user_info.screen_resolutionThe screen resolution of the infected device, as the stealer recorded it.
compromised_device.user_info.ip_addressThe IP address the infected device had when the data was stolen; the platform shows it as IP.
compromise_summary.password_countThe number of passwords stolen from the device; the platform shows it as PASSWORDS.
compromise_summary.token_countThe number of tokens stolen from the device; the platform shows it as TOKEN.
compromise_summary.autofill_countThe number of autofill values stolen from the device; the platform shows it as AUTOFILL.
compromise_summary.cookie_countThe number of cookies stolen from the device.
compromise_summary.sensitive_cookie_countThe number of sensitive cookies (ones that can open a session) stolen from the device; the platform shows it as COOKIE.
compromise_summary.same_password_rateHow often the same password is reused among the device's stolen passwords, as text.
compromise_summary.risk_levelThe device's overall risk level: low, medium, high or critical.
compromise_summary.corporate_riskA short assessment of the risk to your organization; the platform shows it as CORPORATE RISK.
compromise_summary.financial_riskA short assessment of the financial risk; the platform shows it as FINANCIAL RISK.
compromise_summary.identity_theft_riskA short assessment of the identity theft risk; the platform shows it as IDENTITY THEFT.
compromise_summary.corporate_espionageA short assessment of the corporate espionage risk.
compromise_summary.ransomware_threatA short assessment of the ransomware threat; the platform shows it as RANSOMWARE THREAT.
compromise_summary.phishing_riskA short assessment of the phishing risk; the platform shows it as PHISHING RISK.
compromise_summary.session_hijacking_riskA short assessment of the session hijacking risk, from the stolen cookies and tokens; the platform shows it as SESSION HIJACKING.

Response Fields

FieldType
pageinteger
page_sizeinteger
result_countinteger
resultsarray of object
results[].idstring
results[].accountobject
results[].compromised_deviceobject
results[].leaked_dataobject
results[].compromise_summaryobject

Paginated. See Getting Started → Pagination.

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
pagenumber1
page_sizenumber25
result_countnumber0
resultsarray

Examples

Selecting one loads it into the request and response panels.

Reference updated