Compromised Employee Credential Mark Resolved
https://api.deepinfo.com/v1/cti/compromised-employee-credentials/search:mark-resolvedMarks the compromised employee credentials that match filters as resolved (marked_as_resolved).
The action applies to every record matching filters. Always send a filter (for example by id); an empty filter matches all records.
State changes are applied asynchronously: the new state is visible a few seconds after the response. The response body only reports how many records matched.
Authentication
Send your API key in the apikey request header.
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{
"filters": {
"must": [
{
"name": "id",
"type": "eq",
"value": "000000000000000e37e30001"
}
]
}
}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "state",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "id",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith wildcard fuzzy contains_ contains_ exists
| Field | Description |
|---|---|
url | The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as target.url. |
account. | The ID of the employee account the credential belongs to, the id returned by Compromised Employee Account Search. |
account. | The e-mail address of the employee account the credential belongs to (ACCOUNT column). |
account. | The domain of the employee's e-mail address, one of your organization's domains. |
account. | The first name of the employee the credential belongs to, when known. |
account. | The last name of the employee the credential belongs to, when known. |
account. | The department of the employee the credential belongs to, when known. |
account. | The job title of the employee the credential belongs to, when known. |
account. | The address of the LinkedIn profile of the employee the credential belongs to, when known. |
password | The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them. |
password_ | The password's strength rating: Very Weak, Weak, Medium, Strong or Very Strong, shown with a bar in the STRENGTH column. |
password_ | The shape of the password, one letter per character: U uppercase, l lowercase, n digit, s special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive. |
password_ | The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password. |
target. | The address of the site or app the credential belongs to (Target URL). For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address. |
target. | The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as target.url. |
target. | The host name of the target, such as login.acme.example (FQDN). For an Android app it is the app's package name in reverse order. |
target. | The registered domain of the target, such as acme.example for login.acme.example (DOMAIN). |
target. | The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list. |
target. | Where the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown as the platform tag next to the host. |
target. | The category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail (MAIN CATEGORY). Empty for a service without a category. |
target. | A narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider (SUB CATEGORY). Empty for a service without a category. |
target. | The risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW (RISK TIER). Empty for a service without a category. |
Operators eq exists
| Field | Description |
|---|---|
account. | Whether the employee the credential belongs to is marked as an executive. |
password_ | Whether the password contains an uppercase letter (A–Z). |
password_ | Whether the password contains a lowercase letter (a–z). |
password_ | Whether the password contains a digit (0–9). |
password_ | Whether the password contains a special character, such as !, @ or #. |
password_ | Whether the password starts with an uppercase letter (START WITH UPPERCASE). |
password_ | Whether the password ends with a digit (END WITH NUMBERS). |
password_ | Whether the password ends with a special character (END WITH SPECIAL CHARACTER). |
password_ | Whether the password contains a keyboard pattern (KEYBOARD PATTERN). |
password_ | Whether the password contains a date pattern (DATE PATTERN). |
password_ | Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK). |
password_ | Whether the password contains sequential characters (SEQUENTIAL CHARACTER). |
password_ | Whether the password contains repeated characters (REPEATED CHARACTER). |
password_ | Whether the password is a known common password (COMMON PASSWORD). |
password_ | Whether the whole password, ignoring letter case, is a dictionary word. |
target. | Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list. |
target. | Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category. |
Operators eq in gte lte exists
| Field | Description |
|---|---|
added_ | When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
password_ | The password's strength level from 0 to 4: 0 Very Weak, 1 Weak, 2 Medium, 3 Strong, 4 Very Strong, matching password_analysis.strength.label. |
password_ | The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH). |
password_ | An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess. |
password_ | The number of characters in the password (LENGTH). |
password_ | How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES). |
password_ | The password's rank in the list of common passwords, where a lower number means a more common password; set only when is_common_password is true. |
Operators eq in
| Field | Description |
|---|---|
id | The exposed credential's unique ID, a 24-character hex string. |
Operators eq in exists
| Field | Description |
|---|---|
state | The credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you). |
Sortable Fields
| Field | Description |
|---|---|
id | The exposed credential's unique ID, a 24-character hex string. |
url | The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as target.url. |
account. | The ID of the employee account the credential belongs to, the id returned by Compromised Employee Account Search. |
account. | The e-mail address of the employee account the credential belongs to (ACCOUNT column). |
account. | The domain of the employee's e-mail address, one of your organization's domains. |
account. | Whether the employee the credential belongs to is marked as an executive. |
account. | The first name of the employee the credential belongs to, when known. |
account. | The last name of the employee the credential belongs to, when known. |
account. | The job title of the employee the credential belongs to, when known. |
account. | The address of the LinkedIn profile of the employee the credential belongs to, when known. |
account. | The department of the employee the credential belongs to, when known. |
added_ | When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
password | The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them. |
password_ | The password's strength level from 0 to 4: 0 Very Weak, 1 Weak, 2 Medium, 3 Strong, 4 Very Strong, matching password_analysis.strength.label. |
password_ | The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH). |
password_ | The password's strength rating: Very Weak, Weak, Medium, Strong or Very Strong, shown with a bar in the STRENGTH column. |
password_ | An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess. |
password_ | The number of characters in the password (LENGTH). |
password_ | The shape of the password, one letter per character: U uppercase, l lowercase, n digit, s special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive. |
password_ | How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES). |
password_ | Whether the password contains an uppercase letter (A–Z). |
password_ | Whether the password contains a lowercase letter (a–z). |
password_ | Whether the password contains a digit (0–9). |
password_ | Whether the password contains a special character, such as !, @ or #. |
password_ | Whether the password starts with an uppercase letter (START WITH UPPERCASE). |
password_ | Whether the password ends with a digit (END WITH NUMBERS). |
password_ | Whether the password ends with a special character (END WITH SPECIAL CHARACTER). |
password_ | Whether the password contains a keyboard pattern (KEYBOARD PATTERN). |
password_ | Whether the password contains a date pattern (DATE PATTERN). |
password_ | Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK). |
password_ | Whether the password contains sequential characters (SEQUENTIAL CHARACTER). |
password_ | Whether the password contains repeated characters (REPEATED CHARACTER). |
password_ | Whether the password is a known common password (COMMON PASSWORD). |
password_ | The password's rank in the list of common passwords, where a lower number means a more common password; set only when is_common_password is true. |
password_ | Whether the whole password, ignoring letter case, is a dictionary word. |
password_ | The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password. |
target. | The address of the site or app the credential belongs to (Target URL). For an Android app (target.platform ANDROID) it is an android:// app address instead of a web address. |
target. | The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as target.url. |
target. | The host name of the target, such as login.acme.example (FQDN). For an Android app it is the app's package name in reverse order. |
target. | The registered domain of the target, such as acme.example for login.acme.example (DOMAIN). |
target. | The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list. |
target. | Where the credential was used: WEB for a website or ANDROID for an Android app (values seen), shown as the platform tag next to the host. |
target. | The category of the target service, such as Social Media, Identity & Access or E-Commerce & Retail (MAIN CATEGORY). Empty for a service without a category. |
target. | A narrower category of the target service within target.main_category, such as Email Provider or SSO / Identity Provider (SUB CATEGORY). Empty for a service without a category. |
target. | The risk tier of the target service: CRITICAL, HIGH, MEDIUM or LOW (RISK TIER). Empty for a service without a category. |
target. | Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list. |
target. | Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category. |
state | The credential's state: newly_detected or unresolved while active; once inactive, not_applicable or verified_resolved (set by the platform) or ignored, risk_accepted, marked_as_resolved or marked_as_false_positive (set by you). |
Response Fields
| Field | Type |
|---|---|
count | integer |
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
count | number | 1 |
Examples
Selecting one loads it into the request and response panels.