Compromised Device Search
https://api.deepinfo.com/v1/cti/compromised-devicesSearches compromised (infostealer-infected) devices linked to your employees.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
page_ | Optional | Min 25, max 100. Default 100.Example 25 |
page | Optional | Min 1, max 800. Default 1.Example 1 |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "compromised_device.hardware_id",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "compromised_device.hardware_id",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith contains_ contains_ exists
| Field | Description |
|---|---|
compromised_ | The hardware ID the infostealer recorded for the infected device, which identifies one machine across logs. |
compromised_ | The operating-system user name on the infected device, as the stealer log recorded it. |
compromised_ | The computer name of the infected device; the platform shows it as MACHINE. |
compromised_ | The country the infected device was in when the log was made, as the stealer recorded it. |
compromised_ | The location the stealer log gives for the device, such as a city or region. |
compromised_ | The postal code the stealer log gives for the device's location. |
compromised_ | The system language of the infected device; the platform shows it as LANGUAGE. |
compromised_ | The time zone set on the infected device; the platform shows it as TIMEZONE. |
compromised_ | The operating system of the infected device, such as a Windows version; the platform shows it as OS. |
compromised_ | The screen resolution of the infected device, as the stealer recorded it. |
compromised_ | The IP address the infected device had when the data was stolen; the platform shows it as IP. |
compromised_ | The keyboard layouts installed on the infected device, a list of language codes. |
compromised_ | The amount of memory (RAM) of the infected device, as text. |
compromised_ | The processor (CPU) model of the infected device. |
compromised_ | The graphics cards (GPU) of the infected device, a list. |
compromised_ | The antivirus products found on the infected device, a list; the platform shows it as AV. |
compromised_ | The name of a program installed on the infected device. |
compromised_ | The version of a program installed on the infected device. |
compromised_ | The category of a program installed on the infected device. |
compromised_ | The name of a web browser installed on the infected device. |
compromised_ | The version of a web browser installed on the infected device. |
account. | The ID of the employee account the device is linked to, the id returned by Compromised Employee Account Search. |
account. | The e-mail address of the employee account the device is linked to. |
leaked_ | The names of the files the infostealer took from the device, a list. |
leaked_ | The address of the login page a stolen password was saved for. |
leaked_ | The full host name of the login page a stolen password was saved for, such as login.acme.example. |
leaked_ | The registered domain of the login page a stolen password was saved for, such as acme.example. |
leaked_ | The user name or e-mail address saved with a stolen password. Responses mask personal values. |
leaked_ | The stolen password itself. Responses show it masked. |
leaked_ | Where the stolen password came from, such as the kind of stealer log. |
leaked_ | The application the password was stolen from, such as a web browser. |
leaked_ | The stolen token itself, such as a session or API token. Responses show it masked. |
leaked_ | The kind of stolen token, such as a session token or an API key. |
leaked_ | The service that probably issued the stolen token; the platform shows it as ISSUER. |
leaked_ | The user the stolen token belongs to; the platform shows it as USER. |
leaked_ | The website the stolen token is used on. |
leaked_ | The category of the stolen token's service. |
leaked_ | Why the stolen token got its risk level, in words. |
leaked_ | The application the token was stolen from, such as a web browser. |
leaked_ | The name of a form field whose saved (autofill) value was stolen, such as email or phone. |
leaked_ | The stolen autofill value. Responses mask personal values. |
leaked_ | The kind of data in a stolen autofill value, such as an e-mail address or a phone number. |
leaked_ | The application the autofill value was stolen from, such as a web browser. |
leaked_ | The name of the browser profile or source the autofill value was read from. |
leaked_ | A domain the infected device had cookies for, such as acme.example. |
leaked_ | The subdomains of that domain the device had cookies for, a list. |
leaked_ | The domain a stolen sensitive cookie (one that can open a session) belongs to. |
leaked_ | The name of a stolen sensitive cookie. |
leaked_ | The value of a stolen sensitive cookie. Responses show it masked. |
leaked_ | The path a stolen sensitive cookie applies to, such as /. |
leaked_ | The kind of stolen cookie, such as a session or authentication cookie. |
leaked_ | Why the stolen cookie got its risk level, in words. |
leaked_ | The application the cookie was stolen from, such as a web browser. |
leaked_ | The file name of a document the infostealer took from the device. |
leaked_ | The author recorded in a stolen document's properties. Responses mask personal values. |
leaked_ | The last editor recorded in a stolen document's properties. Responses mask personal values. |
leaked_ | The text of a stolen document. Responses do not show it. |
leaked_ | The language of a stolen document's text. |
leaked_ | A score of how much sensitive data a stolen document holds. |
leaked_ | The kinds of sensitive data found in a stolen document, a list. |
compromise_ | Your organization's e-mail addresses found on the device, a list. |
compromise_ | The other e-mail addresses found on the device, a list. |
compromise_ | How often the same password is reused among the device's stolen passwords, as text. |
compromise_ | Internal resources of your organization the device had stolen access to, such as internal login pages, a list. |
compromise_ | A short assessment of the risk to your organization; the platform shows it as CORPORATE RISK. |
compromise_ | A short assessment of the financial risk; the platform shows it as FINANCIAL RISK. |
compromise_ | A short assessment of the identity theft risk; the platform shows it as IDENTITY THEFT. |
compromise_ | A short assessment of the corporate espionage risk. |
compromise_ | A short assessment of the ransomware threat; the platform shows it as RANSOMWARE THREAT. |
compromise_ | A short assessment of the phishing risk; the platform shows it as PHISHING RISK. |
compromise_ | A short assessment of the session hijacking risk, from the stolen cookies and tokens; the platform shows it as SESSION HIJACKING. |
Operators eq in gte lte exists
| Field | Description |
|---|---|
compromised_ | When the infostealer log of this device was created, that is, when the data was stolen. |
leaked_ | When the stolen cookie expires. A cookie that has not expired can still open a session. |
leaked_ | When a stolen document was created, from its properties. |
leaked_ | When a stolen document was last changed, from its properties. |
compromise_ | The number of passwords stolen from the device; the platform shows it as PASSWORDS. |
compromise_ | The number of tokens stolen from the device; the platform shows it as TOKEN. |
compromise_ | The number of autofill values stolen from the device; the platform shows it as AUTOFILL. |
compromise_ | The number of cookies stolen from the device. |
compromise_ | The number of sensitive cookies (ones that can open a session) stolen from the device; the platform shows it as COOKIE. |
Operators eq exists
| Field | Description |
|---|---|
leaked_ | true when the stolen password is for one of your organization's own services. |
leaked_ | true when the stolen cookie is sent over HTTPS only. |
leaked_ | true when the stolen cookie is hidden from page scripts (HttpOnly). |
leaked_ | true when the stolen cookie also applies to the domain's subdomains. |
Operators eq in exists
| Field | Description |
|---|---|
leaked_ | How risky the stolen token is: low, medium, high or critical. |
leaked_ | How risky the stolen cookie is: low, medium, high or critical. |
compromise_ | The device's overall risk level: low, medium, high or critical. |
Sortable Fields
| Field | Description |
|---|---|
compromised_ | The hardware ID the infostealer recorded for the infected device, which identifies one machine across logs. |
compromised_ | When the infostealer log of this device was created, that is, when the data was stolen. |
compromised_ | The operating-system user name on the infected device, as the stealer log recorded it. |
compromised_ | The computer name of the infected device; the platform shows it as MACHINE. |
compromised_ | The country the infected device was in when the log was made, as the stealer recorded it. |
compromised_ | The system language of the infected device; the platform shows it as LANGUAGE. |
compromised_ | The operating system of the infected device, such as a Windows version; the platform shows it as OS. |
compromised_ | The screen resolution of the infected device, as the stealer recorded it. |
compromised_ | The IP address the infected device had when the data was stolen; the platform shows it as IP. |
compromise_ | The number of passwords stolen from the device; the platform shows it as PASSWORDS. |
compromise_ | The number of tokens stolen from the device; the platform shows it as TOKEN. |
compromise_ | The number of autofill values stolen from the device; the platform shows it as AUTOFILL. |
compromise_ | The number of cookies stolen from the device. |
compromise_ | The number of sensitive cookies (ones that can open a session) stolen from the device; the platform shows it as COOKIE. |
compromise_ | How often the same password is reused among the device's stolen passwords, as text. |
compromise_ | The device's overall risk level: low, medium, high or critical. |
compromise_ | A short assessment of the risk to your organization; the platform shows it as CORPORATE RISK. |
compromise_ | A short assessment of the financial risk; the platform shows it as FINANCIAL RISK. |
compromise_ | A short assessment of the identity theft risk; the platform shows it as IDENTITY THEFT. |
compromise_ | A short assessment of the corporate espionage risk. |
compromise_ | A short assessment of the ransomware threat; the platform shows it as RANSOMWARE THREAT. |
compromise_ | A short assessment of the phishing risk; the platform shows it as PHISHING RISK. |
compromise_ | A short assessment of the session hijacking risk, from the stolen cookies and tokens; the platform shows it as SESSION HIJACKING. |
Response Fields
| Field | Type |
|---|---|
page | integer |
page_ | integer |
result_ | integer |
results | array of object |
results[]. | string |
results[]. | object |
results[]. | object |
results[]. | object |
results[]. | object |
Paginated. See Getting Started → Pagination.
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
page | number | 1 |
page_size | number | 25 |
result_count | number | 0 |
results | array |
Examples
Selecting one loads it into the request and response panels.