Compromised Employee Account Export
https://api.deepinfo.com/v1/cti/compromised-employee-accounts/search:exportExports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. Large exports can time out: narrow them with filters.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
format | Optional | One of: json, csv.Example csv |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "id",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "id",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in gte lte exists
| Field | Description |
|---|---|
security_ | When the employee's earliest leaked credential was added, shown as FIRST SEEN in the security profile (UTC date-time). |
security_ | When the employee's most recent leaked credential was added, shown as LAST EXPOSURE in the list and LAST SEEN in the security profile (UTC date-time). The list is sorted by it, newest first. |
security_ | The number of days between the first and the last exposure date (EXPOSURE SPAN); 0 when all of the employee's credentials were added on the same day. |
security_ | The number of different passwords among the employee's leaked credentials, shown as UNIQUE PASSWORDS and in the PASSWORDS column. |
security_ | The average length, in characters, of the passwords in the employee's leaked credentials (AVG LENGTH). |
security_ | The average password strength score of the employee's leaked credentials, on the 0 to 100 scale of password_analysis.strength.score. The platform shows it divided by 10, as AVG STRENGTH SCORE out of 10. |
security_ | The lowest password strength score among the employee's leaked credentials, from 0 to 100 (the first number of MIN / MAX SCORE). |
security_ | The highest password strength score among the employee's leaked credentials, from 0 to 100 (the second number of MIN / MAX SCORE). |
security_ | The number of the employee's leaked credentials whose password is rated Very Weak. Credentials are counted, so a reused password counts once for each credential. |
security_ | The number of the employee's leaked credentials whose password is rated Weak. Credentials are counted, so a reused password counts once for each credential. |
security_ | The number of the employee's leaked credentials whose password is rated Medium. Credentials are counted, so a reused password counts once for each credential. |
security_ | The number of the employee's leaked credentials whose password is rated Strong. Credentials are counted, so a reused password counts once for each credential. |
security_ | The number of the employee's leaked credentials whose password is rated Very Strong. Credentials are counted, so a reused password counts once for each credential. |
security_ | The share of the employee's leaked credentials whose password is rated Very Weak or Weak, as a percentage from 0 to 100 (WEAK PASSWORDS). |
security_ | The number of the employee's passwords that appear in more than one leaked credential (REUSED PASSWORDS). |
security_ | The share of the employee's different passwords that appear in more than one leaked credential, as a percentage from 0 to 100 (REUSE RATE and the REUSE column). |
security_ | The number of the employee's leaked credentials whose password is a known common password (password_analysis.dictionary_match.is_common_password), shown as COMMON PASSWORDS. |
security_ | The number of the employee's leaked credentials whose password is a dictionary word (password_analysis.dictionary_match.is_dictionary_word), shown as DICTIONARY WORDS. |
security_ | The number of the employee's leaked credentials whose password contains a keyboard pattern (password_analysis.patterns.has_keyboard_pattern), shown as KEYBOARD PATTERNS. |
security_ | The number of the employee's leaked credentials whose password contains a date pattern (password_analysis.patterns.has_date_pattern), shown as DATE PATTERNS. |
security_ | The average number of character types (uppercase letters, lowercase letters, digits, special characters) per password across the employee's leaked credentials, from 1 to 4 (AVG CHAR CLASSES). |
security_ | The share of the employee's leaked credentials whose password uses all four character types, as a percentage from 0 to 100 (ALL CHAR CLASSES). |
security_ | The number of different password structures among the employee's leaked credentials (STRUCTURE VARIETY). |
security_ | The number of days since the employee's last exposure (security_profile.exposure.last_exposure_date), shown as DAYS SINCE LAST. |
security_ | How often new leaked credentials of the account appear, in credentials per month (VELOCITY, shown as cred/mo). |
state_ | The number of the employee's leaked credentials, in any state (Total Credentials in the STATE filter group). |
state_ | The number of the employee's credentials in an active state, newly_detected or unresolved (Active Credential Count). |
state_ | The number of the employee's credentials in an inactive state, such as ignored, risk accepted or marked as resolved (Inactive Credential Count). |
state_ | The number of the employee's credentials that are unresolved (Unresolved Credential Count). |
state_ | The number of the employee's credentials that are resolved (Resolved Credential Count). |
state_ | The number of the employee's credentials in the risk_accepted state (Risk Accepted Credential Count). |
state_ | The number of the employee's credentials in the ignored state (Ignored Credential Count). |
state_ | The number of the employee's credentials in the marked_as_false_positive state (False Positive Credential Count). |
risk_ | The employee account's numeric risk score, which goes with its risk_level; a higher score means a higher risk. |
Operators eq in startswith endswith wildcard fuzzy contains_ contains_ exists
| Field | Description |
|---|---|
email | The employee's e-mail address that was found in leaked credential data. It identifies the account and cannot be edited. |
domain | The domain of the employee's e-mail address, one of your organization's domains; the list has one tab per domain. |
first_ | The employee's first name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
last_ | The employee's last name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
title | The employee's job title (CURRENT TITLE when you edit it), when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
linkedin_ | The address of the employee's LinkedIn profile, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
department | The employee's department, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
security_ | The most common password structure among the employee's leaked credentials, one letter per character: U uppercase, l lowercase, n digit, s special character. It shows the passwords' shape while they are masked, so treat it as sensitive. |
Operators eq exists
| Field | Description |
|---|---|
is_ | Whether the employee is marked as an executive; executives show a VIP icon. You set it with EDIT DETAILS or the Compromised Employee Account Update endpoint. |
security_ | Whether new exposures of the account are becoming more frequent; the TREND figure shows true as ACCELERATING and false as STABLE. |
Operators eq in exists
| Field | Description |
|---|---|
computed_ | The employee account's computed state (State in the STATE filter group). It takes the same values as a credential's state, such as newly_detected or unresolved. |
risk_ | The employee's priority level: low, medium, high or critical. The platform describes it as a composite priority based on credential, role and recency. |
Operators eq in
| Field | Description |
|---|---|
id | The employee account's unique ID, a 24-character hex string. Exposed credentials refer to it as account.id. |
Sortable Fields
| Field | Description |
|---|---|
id | The employee account's unique ID, a 24-character hex string. Exposed credentials refer to it as account.id. |
email | The employee's e-mail address that was found in leaked credential data. It identifies the account and cannot be edited. |
domain | The domain of the employee's e-mail address, one of your organization's domains; the list has one tab per domain. |
is_ | Whether the employee is marked as an executive; executives show a VIP icon. You set it with EDIT DETAILS or the Compromised Employee Account Update endpoint. |
first_ | The employee's first name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
last_ | The employee's last name, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
title | The employee's job title (CURRENT TITLE when you edit it), when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
linkedin_ | The address of the employee's LinkedIn profile, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
department | The employee's department, when known. You can add or correct it with EDIT DETAILS in the platform or the Compromised Employee Account Update endpoint. |
security_ | When the employee's earliest leaked credential was added, shown as FIRST SEEN in the security profile (UTC date-time). |
security_ | When the employee's most recent leaked credential was added, shown as LAST EXPOSURE in the list and LAST SEEN in the security profile (UTC date-time). The list is sorted by it, newest first. |
security_ | The number of days between the first and the last exposure date (EXPOSURE SPAN); 0 when all of the employee's credentials were added on the same day. |
security_ | The number of different passwords among the employee's leaked credentials, shown as UNIQUE PASSWORDS and in the PASSWORDS column. |
security_ | The average length, in characters, of the passwords in the employee's leaked credentials (AVG LENGTH). |
security_ | The average password strength score of the employee's leaked credentials, on the 0 to 100 scale of password_analysis.strength.score. The platform shows it divided by 10, as AVG STRENGTH SCORE out of 10. |
security_ | The lowest password strength score among the employee's leaked credentials, from 0 to 100 (the first number of MIN / MAX SCORE). |
security_ | The highest password strength score among the employee's leaked credentials, from 0 to 100 (the second number of MIN / MAX SCORE). |
security_ | The number of the employee's leaked credentials whose password is rated Very Weak. Credentials are counted, so a reused password counts once for each credential. |
security_ | The number of the employee's leaked credentials whose password is rated Weak. Credentials are counted, so a reused password counts once for each credential. |
security_ | The number of the employee's leaked credentials whose password is rated Medium. Credentials are counted, so a reused password counts once for each credential. |
security_ | The number of the employee's leaked credentials whose password is rated Strong. Credentials are counted, so a reused password counts once for each credential. |
security_ | The number of the employee's leaked credentials whose password is rated Very Strong. Credentials are counted, so a reused password counts once for each credential. |
security_ | The share of the employee's leaked credentials whose password is rated Very Weak or Weak, as a percentage from 0 to 100 (WEAK PASSWORDS). |
security_ | The number of the employee's passwords that appear in more than one leaked credential (REUSED PASSWORDS). |
security_ | The share of the employee's different passwords that appear in more than one leaked credential, as a percentage from 0 to 100 (REUSE RATE and the REUSE column). |
security_ | The number of the employee's leaked credentials whose password is a known common password (password_analysis.dictionary_match.is_common_password), shown as COMMON PASSWORDS. |
security_ | The number of the employee's leaked credentials whose password is a dictionary word (password_analysis.dictionary_match.is_dictionary_word), shown as DICTIONARY WORDS. |
security_ | The number of the employee's leaked credentials whose password contains a keyboard pattern (password_analysis.patterns.has_keyboard_pattern), shown as KEYBOARD PATTERNS. |
security_ | The number of the employee's leaked credentials whose password contains a date pattern (password_analysis.patterns.has_date_pattern), shown as DATE PATTERNS. |
security_ | The average number of character types (uppercase letters, lowercase letters, digits, special characters) per password across the employee's leaked credentials, from 1 to 4 (AVG CHAR CLASSES). |
security_ | The share of the employee's leaked credentials whose password uses all four character types, as a percentage from 0 to 100 (ALL CHAR CLASSES). |
security_ | The most common password structure among the employee's leaked credentials, one letter per character: U uppercase, l lowercase, n digit, s special character. It shows the passwords' shape while they are masked, so treat it as sensitive. |
security_ | The number of different password structures among the employee's leaked credentials (STRUCTURE VARIETY). |
security_ | The number of days since the employee's last exposure (security_profile.exposure.last_exposure_date), shown as DAYS SINCE LAST. |
security_ | Whether new exposures of the account are becoming more frequent; the TREND figure shows true as ACCELERATING and false as STABLE. |
security_ | How often new leaked credentials of the account appear, in credentials per month (VELOCITY, shown as cred/mo). |
computed_ | The employee account's computed state (State in the STATE filter group). It takes the same values as a credential's state, such as newly_detected or unresolved. |
state_ | The number of the employee's leaked credentials, in any state (Total Credentials in the STATE filter group). |
state_ | The number of the employee's credentials in an active state, newly_detected or unresolved (Active Credential Count). |
state_ | The number of the employee's credentials in an inactive state, such as ignored, risk accepted or marked as resolved (Inactive Credential Count). |
state_ | The number of the employee's credentials that are unresolved (Unresolved Credential Count). |
state_ | The number of the employee's credentials that are resolved (Resolved Credential Count). |
state_ | The number of the employee's credentials in the risk_accepted state (Risk Accepted Credential Count). |
state_ | The number of the employee's credentials in the ignored state (Ignored Credential Count). |
state_ | The number of the employee's credentials in the marked_as_false_positive state (False Positive Credential Count). |
risk_ | The employee account's numeric risk score, which goes with its risk_level; a higher score means a higher risk. |
risk_ | The employee's priority level: low, medium, high or critical. The platform describes it as a composite priority based on credential, role and recency. |
Examples
Selecting one loads it into the request and response panels.