POSThttps://api.deepinfo.com/v1/cti/compromised-employee-credentials/search:mark-false-positive

Marks the compromised employee credentials that match filters as false positive (marked_as_false_positive).

The action applies to every record matching filters. Always send a filter (for example by id); an empty filter matches all records.

State changes are applied asynchronously: the new state is visible a few seconds after the response. The response body only reports how many records matched.

Authentication

Send your API key in the apikey request header.

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{
  "filters": {
    "must": [
      {
        "name": "id",
        "type": "eq",
        "value": "000000000000000e37e30001"
      }
    ]
  }
}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in startswith endswith wildcard fuzzy contains_any contains_all exists

FieldDescription
urlThe address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as target.url.
account.idThe ID of the employee account the credential belongs to, the id returned by Compromised Employee Account Search.
account.emailThe e-mail address of the employee account the credential belongs to (ACCOUNT column).
account.domainThe domain of the employee's e-mail address, one of your organization's domains.
account.first_nameThe first name of the employee the credential belongs to, when known.
account.last_nameThe last name of the employee the credential belongs to, when known.
account.departmentThe department of the employee the credential belongs to, when known.
account.titleThe job title of the employee the credential belongs to, when known.
account.linkedin_urlThe address of the LinkedIn profile of the employee the credential belongs to, when known.
passwordThe leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.
password_analysis.strength.labelThe password's strength rating: Very Weak, Weak, Medium, Strong or Very Strong, shown with a bar in the STRENGTH column.
password_analysis.composition.structureThe shape of the password, one letter per character: U uppercase, l lowercase, n digit, s special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.
password_analysis.dictionary_match.dictionary_word_foundThe dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.
target.urlThe address of the site or app the credential belongs to (Target URL). For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address.
target.url_rawThe raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as target.url.
target.fqdnThe host name of the target, such as login.acme.example (FQDN). For an Android app it is the app's package name in reverse order.
target.domainThe registered domain of the target, such as acme.example for login.acme.example (DOMAIN).
target.serviceThe name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.
target.platformWhere the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown as the platform tag next to the host.
target.main_categoryThe category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail (MAIN CATEGORY). Empty for a service without a category.
target.sub_categoryA narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider (SUB CATEGORY). Empty for a service without a category.
target.risk_tierThe risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW (RISK TIER). Empty for a service without a category.

Operators eq exists

FieldDescription
account.is_executiveWhether the employee the credential belongs to is marked as an executive.
password_analysis.composition.contains_uppercaseWhether the password contains an uppercase letter (A–Z).
password_analysis.composition.contains_lowercaseWhether the password contains a lowercase letter (a–z).
password_analysis.composition.contains_numberWhether the password contains a digit (0–9).
password_analysis.composition.contains_specialWhether the password contains a special character, such as !, @ or #.
password_analysis.composition.starts_with_uppercaseWhether the password starts with an uppercase letter (START WITH UPPERCASE).
password_analysis.composition.ends_with_numbersWhether the password ends with a digit (END WITH NUMBERS).
password_analysis.composition.ends_with_specialWhether the password ends with a special character (END WITH SPECIAL CHARACTER).
password_analysis.patterns.has_keyboard_patternWhether the password contains a keyboard pattern (KEYBOARD PATTERN).
password_analysis.patterns.has_date_patternWhether the password contains a date pattern (DATE PATTERN).
password_analysis.patterns.has_leet_speakWhether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).
password_analysis.patterns.has_sequential_charsWhether the password contains sequential characters (SEQUENTIAL CHARACTER).
password_analysis.patterns.has_repeated_charsWhether the password contains repeated characters (REPEATED CHARACTER).
password_analysis.dictionary_match.is_common_passwordWhether the password is a known common password (COMMON PASSWORD).
password_analysis.dictionary_match.is_dictionary_wordWhether the whole password, ignoring letter case, is a dictionary word.
target.is_corporateWhether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.
target.requires_mfa_by_defaultWhether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.

Operators eq in gte lte exists

FieldDescription
added_atWhen the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).
password_analysis.strength.levelThe password's strength level from 0 to 4: 0 Very Weak, 1 Weak, 2 Medium, 3 Strong, 4 Very Strong, matching password_analysis.strength.label.
password_analysis.strength.scoreThe password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).
password_analysis.strength.entropy_bitsAn estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.
password_analysis.composition.lengthThe number of characters in the password (LENGTH).
password_analysis.composition.character_classes_usedHow many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).
password_analysis.dictionary_match.common_password_rankThe password's rank in the list of common passwords, where a lower number means a more common password; set only when is_common_password is true.

Operators eq in

FieldDescription
idThe exposed credential's unique ID, a 24-character hex string.

Operators eq in exists

FieldDescription
stateThe credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you).

Sortable Fields

FieldDescription
idThe exposed credential's unique ID, a 24-character hex string.
urlThe address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as target.url.
account.idThe ID of the employee account the credential belongs to, the id returned by Compromised Employee Account Search.
account.emailThe e-mail address of the employee account the credential belongs to (ACCOUNT column).
account.domainThe domain of the employee's e-mail address, one of your organization's domains.
account.is_executiveWhether the employee the credential belongs to is marked as an executive.
account.first_nameThe first name of the employee the credential belongs to, when known.
account.last_nameThe last name of the employee the credential belongs to, when known.
account.titleThe job title of the employee the credential belongs to, when known.
account.linkedin_urlThe address of the LinkedIn profile of the employee the credential belongs to, when known.
account.departmentThe department of the employee the credential belongs to, when known.
added_atWhen the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time).
passwordThe leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them.
password_analysis.strength.levelThe password's strength level from 0 to 4: 0 Very Weak, 1 Weak, 2 Medium, 3 Strong, 4 Very Strong, matching password_analysis.strength.label.
password_analysis.strength.scoreThe password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH).
password_analysis.strength.labelThe password's strength rating: Very Weak, Weak, Medium, Strong or Very Strong, shown with a bar in the STRENGTH column.
password_analysis.strength.entropy_bitsAn estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess.
password_analysis.composition.lengthThe number of characters in the password (LENGTH).
password_analysis.composition.structureThe shape of the password, one letter per character: U uppercase, l lowercase, n digit, s special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive.
password_analysis.composition.character_classes_usedHow many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES).
password_analysis.composition.contains_uppercaseWhether the password contains an uppercase letter (A–Z).
password_analysis.composition.contains_lowercaseWhether the password contains a lowercase letter (a–z).
password_analysis.composition.contains_numberWhether the password contains a digit (0–9).
password_analysis.composition.contains_specialWhether the password contains a special character, such as !, @ or #.
password_analysis.composition.starts_with_uppercaseWhether the password starts with an uppercase letter (START WITH UPPERCASE).
password_analysis.composition.ends_with_numbersWhether the password ends with a digit (END WITH NUMBERS).
password_analysis.composition.ends_with_specialWhether the password ends with a special character (END WITH SPECIAL CHARACTER).
password_analysis.patterns.has_keyboard_patternWhether the password contains a keyboard pattern (KEYBOARD PATTERN).
password_analysis.patterns.has_date_patternWhether the password contains a date pattern (DATE PATTERN).
password_analysis.patterns.has_leet_speakWhether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK).
password_analysis.patterns.has_sequential_charsWhether the password contains sequential characters (SEQUENTIAL CHARACTER).
password_analysis.patterns.has_repeated_charsWhether the password contains repeated characters (REPEATED CHARACTER).
password_analysis.dictionary_match.is_common_passwordWhether the password is a known common password (COMMON PASSWORD).
password_analysis.dictionary_match.common_password_rankThe password's rank in the list of common passwords, where a lower number means a more common password; set only when is_common_password is true.
password_analysis.dictionary_match.is_dictionary_wordWhether the whole password, ignoring letter case, is a dictionary word.
password_analysis.dictionary_match.dictionary_word_foundThe dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password.
target.urlThe address of the site or app the credential belongs to (Target URL). For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address.
target.url_rawThe raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as target.url.
target.fqdnThe host name of the target, such as login.acme.example (FQDN). For an Android app it is the app's package name in reverse order.
target.domainThe registered domain of the target, such as acme.example for login.acme.example (DOMAIN).
target.serviceThe name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list.
target.platformWhere the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown as the platform tag next to the host.
target.main_categoryThe category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail (MAIN CATEGORY). Empty for a service without a category.
target.sub_categoryA narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider (SUB CATEGORY). Empty for a service without a category.
target.risk_tierThe risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW (RISK TIER). Empty for a service without a category.
target.is_corporateWhether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list.
target.requires_mfa_by_defaultWhether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category.
stateThe credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you).

Response Fields

FieldType
countinteger

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
countnumber1

Examples

Selecting one loads it into the request and response panels.

Reference updated