# Compromised Employee Credential Search

POST /cti/compromised-employee-credentials/search: Searches leaked employee credentials and their state.

Source: https://docs.deepinfo.com/reference/cti/compromised-employee-credential-search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/cti/compromised-employee-credentials/search`

Searches leaked employee credentials and their state.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `url` | The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`. |
| `account.id` | The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search. |
| `account.email` | The e-mail address of the employee account the credential belongs to (ACCOUNT column). |
| `account.domain` | The domain of the employee's e-mail address, one of your organization's domains. |
| `account.first_name` | The first name of the employee the credential belongs to, when known. |
| `account.last_name` | The last name of the employee the credential belongs to, when known. |
| `account.department` | The department of the employee the credential belongs to, when known. |
| `account.title` | The job title of the employee the credential belongs to, when known. |
| `account.linkedin_url` | The address of the LinkedIn profile of the employee the credential belongs to, when known. |
| `password` | The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them. |
| `password_analysis.strength.label` | The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column. |
| `password_analysis.composition.structure` | The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive. |
| `password_analysis.dictionary_match.dictionary_word_found` | The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password. |
| `target.url` | The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address. |
| `target.url_raw` | The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`. |
| `target.fqdn` | The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order. |
| `target.domain` | The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN). |
| `target.service` | The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list. |
| `target.platform` | Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host. |
| `target.main_category` | The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category. |
| `target.sub_category` | A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category. |
| `target.risk_tier` | The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `account.is_executive` | Whether the employee the credential belongs to is marked as an executive. |
| `password_analysis.composition.contains_uppercase` | Whether the password contains an uppercase letter (A–Z). |
| `password_analysis.composition.contains_lowercase` | Whether the password contains a lowercase letter (a–z). |
| `password_analysis.composition.contains_number` | Whether the password contains a digit (0–9). |
| `password_analysis.composition.contains_special` | Whether the password contains a special character, such as `!`, `@` or `#`. |
| `password_analysis.composition.starts_with_uppercase` | Whether the password starts with an uppercase letter (START WITH UPPERCASE). |
| `password_analysis.composition.ends_with_numbers` | Whether the password ends with a digit (END WITH NUMBERS). |
| `password_analysis.composition.ends_with_special` | Whether the password ends with a special character (END WITH SPECIAL CHARACTER). |
| `password_analysis.patterns.has_keyboard_pattern` | Whether the password contains a keyboard pattern (KEYBOARD PATTERN). |
| `password_analysis.patterns.has_date_pattern` | Whether the password contains a date pattern (DATE PATTERN). |
| `password_analysis.patterns.has_leet_speak` | Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK). |
| `password_analysis.patterns.has_sequential_chars` | Whether the password contains sequential characters (SEQUENTIAL CHARACTER). |
| `password_analysis.patterns.has_repeated_chars` | Whether the password contains repeated characters (REPEATED CHARACTER). |
| `password_analysis.dictionary_match.is_common_password` | Whether the password is a known common password (COMMON PASSWORD). |
| `password_analysis.dictionary_match.is_dictionary_word` | Whether the whole password, ignoring letter case, is a dictionary word. |
| `target.is_corporate` | Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list. |
| `target.requires_mfa_by_default` | Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category. |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `added_at` | When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
| `password_analysis.strength.level` | The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`. |
| `password_analysis.strength.score` | The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH). |
| `password_analysis.strength.entropy_bits` | An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess. |
| `password_analysis.composition.length` | The number of characters in the password (LENGTH). |
| `password_analysis.composition.character_classes_used` | How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES). |
| `password_analysis.dictionary_match.common_password_rank` | The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`. |

Operators: `eq`, `in`

| Field | Description |
|---|---|
| `id` | The exposed credential's unique ID, a 24-character hex string. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `state` | The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you). |

### Sortable Fields

| Field | Description |
|---|---|
| `id` | The exposed credential's unique ID, a 24-character hex string. |
| `url` | The address of the site or app the leaked login was used on; the SEARCH box of EXPOSED CREDENTIALS matches it. In the samples it is the same as `target.url`. |
| `account.id` | The ID of the employee account the credential belongs to, the `id` returned by Compromised Employee Account Search. |
| `account.email` | The e-mail address of the employee account the credential belongs to (ACCOUNT column). |
| `account.domain` | The domain of the employee's e-mail address, one of your organization's domains. |
| `account.is_executive` | Whether the employee the credential belongs to is marked as an executive. |
| `account.first_name` | The first name of the employee the credential belongs to, when known. |
| `account.last_name` | The last name of the employee the credential belongs to, when known. |
| `account.title` | The job title of the employee the credential belongs to, when known. |
| `account.linkedin_url` | The address of the LinkedIn profile of the employee the credential belongs to, when known. |
| `account.department` | The department of the employee the credential belongs to, when known. |
| `added_at` | When the credential was added to Deepinfo's data, shown as ADDED DATE (UTC date-time). |
| `password` | The leaked password in plain text. The platform masks it on screen, but API responses include it, so protect them. |
| `password_analysis.strength.level` | The password's strength level from 0 to 4: `0` Very Weak, `1` Weak, `2` Medium, `3` Strong, `4` Very Strong, matching `password_analysis.strength.label`. |
| `password_analysis.strength.score` | The password's strength score from 0 to 100; a higher score means a stronger password (STRENGTH). |
| `password_analysis.strength.label` | The password's strength rating: `Very Weak`, `Weak`, `Medium`, `Strong` or `Very Strong`, shown with a bar in the STRENGTH column. |
| `password_analysis.strength.entropy_bits` | An estimate of how hard the password is to guess, in bits of entropy (ENTROPY); a higher value means harder to guess. |
| `password_analysis.composition.length` | The number of characters in the password (LENGTH). |
| `password_analysis.composition.structure` | The shape of the password, one letter per character: `U` uppercase, `l` lowercase, `n` digit, `s` special character (STRUCTURE). It shows the password's shape while the password is masked, so treat it as sensitive. |
| `password_analysis.composition.character_classes_used` | How many of the four character types (uppercase letters, lowercase letters, digits, special characters) the password uses, from 1 to 4 (CHARACTER CLASSES). |
| `password_analysis.composition.contains_uppercase` | Whether the password contains an uppercase letter (A–Z). |
| `password_analysis.composition.contains_lowercase` | Whether the password contains a lowercase letter (a–z). |
| `password_analysis.composition.contains_number` | Whether the password contains a digit (0–9). |
| `password_analysis.composition.contains_special` | Whether the password contains a special character, such as `!`, `@` or `#`. |
| `password_analysis.composition.starts_with_uppercase` | Whether the password starts with an uppercase letter (START WITH UPPERCASE). |
| `password_analysis.composition.ends_with_numbers` | Whether the password ends with a digit (END WITH NUMBERS). |
| `password_analysis.composition.ends_with_special` | Whether the password ends with a special character (END WITH SPECIAL CHARACTER). |
| `password_analysis.patterns.has_keyboard_pattern` | Whether the password contains a keyboard pattern (KEYBOARD PATTERN). |
| `password_analysis.patterns.has_date_pattern` | Whether the password contains a date pattern (DATE PATTERN). |
| `password_analysis.patterns.has_leet_speak` | Whether the password uses leet speak, letters written as look-alike digits or symbols (LEET SPEAK). |
| `password_analysis.patterns.has_sequential_chars` | Whether the password contains sequential characters (SEQUENTIAL CHARACTER). |
| `password_analysis.patterns.has_repeated_chars` | Whether the password contains repeated characters (REPEATED CHARACTER). |
| `password_analysis.dictionary_match.is_common_password` | Whether the password is a known common password (COMMON PASSWORD). |
| `password_analysis.dictionary_match.common_password_rank` | The password's rank in the list of common passwords, where a lower number means a more common password; set only when `is_common_password` is `true`. |
| `password_analysis.dictionary_match.is_dictionary_word` | Whether the whole password, ignoring letter case, is a dictionary word. |
| `password_analysis.dictionary_match.dictionary_word_found` | The dictionary word found inside the password (DICT WORD), also when the password holds more than that word; empty when none is found. It reveals part of the password. |
| `target.url` | The address of the site or app the credential belongs to (Target URL). For an Android app (`target.platform` `ANDROID`) it is an `android://` app address instead of a web address. |
| `target.url_raw` | The raw form of the target URL, shown as URL RAW on the credential's TARGET tab; in the samples it is always the same as `target.url`. |
| `target.fqdn` | The host name of the target, such as `login.acme.example` (FQDN). For an Android app it is the app's package name in reverse order. |
| `target.domain` | The registered domain of the target, such as `acme.example` for `login.acme.example` (DOMAIN). |
| `target.service` | The name of the site or service the credential belongs to (SERVICE), shown first in the SOURCE/SERVICE column of the list. |
| `target.platform` | Where the credential was used: `WEB` for a website or `ANDROID` for an Android app (values seen), shown as the platform tag next to the host. |
| `target.main_category` | The category of the target service, such as `Social Media`, `Identity & Access` or `E-Commerce & Retail` (MAIN CATEGORY). Empty for a service without a category. |
| `target.sub_category` | A narrower category of the target service within `target.main_category`, such as `Email Provider` or `SSO / Identity Provider` (SUB CATEGORY). Empty for a service without a category. |
| `target.risk_tier` | The risk tier of the target service: `CRITICAL`, `HIGH`, `MEDIUM` or `LOW` (RISK TIER). Empty for a service without a category. |
| `target.is_corporate` | Whether the target is a corporate service (CORPORATE); such credentials show a corporate-building icon in the list. |
| `target.requires_mfa_by_default` | Whether the target service enforces multi-factor authentication by default, shown as MFA BY DEFAULT: ENFORCED or NOT ENFORCED. Empty for a service without a category. |
| `state` | The credential's state: `newly_detected` or `unresolved` while active; once inactive, `not_applicable` or `verified_resolved` (set by the platform) or `ignored`, `risk_accepted`, `marked_as_resolved` or `marked_as_false_positive` (set by you). |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].url` | string |  |
| `results[].state` | string | One of `newly_detected`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |
| `results[].account` | object |  |
| `results[].added_at` | string | date-time |
| `results[].password` | string |  |
| `results[].password_analysis` | object |  |
| `results[].target` | object |  |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].id` | string |
| `results[].url` | string |
| `results[].state` | string |
| `results[].account` | object |
| `results[].account.id` | string |
| `results[].account.email` | string |
| `results[].account.domain` | string |
| `results[].account.is_executive` | boolean |
| `results[].account.first_name` | null |
| `results[].account.last_name` | null |
| `results[].account.title` | null |
| `results[].account.linkedin_url` | null |
| `results[].account.department` | null |
| `results[].added_at` | string |
| `results[].password` | string |
| `results[].password_analysis` | object |
| `results[].password_analysis.strength` | object |
| `results[].password_analysis.strength.level` | number |
| `results[].password_analysis.strength.score` | number |
| `results[].password_analysis.strength.label` | string |
| `results[].password_analysis.strength.entropy_bits` | number |
| `results[].password_analysis.composition` | object |
| `results[].password_analysis.composition.length` | number |
| `results[].password_analysis.composition.structure` | string |
| `results[].password_analysis.composition.character_classes_used` | number |
| `results[].password_analysis.composition.contains_uppercase` | boolean |
| `results[].password_analysis.composition.contains_lowercase` | boolean |
| `results[].password_analysis.composition.contains_number` | boolean |
| `results[].password_analysis.composition.contains_special` | boolean |
| `results[].password_analysis.composition.starts_with_uppercase` | boolean |
| `results[].password_analysis.composition.ends_with_numbers` | boolean |
| `results[].password_analysis.composition.ends_with_special` | boolean |
| `results[].password_analysis.patterns` | object |
| `results[].password_analysis.patterns.has_keyboard_pattern` | boolean |
| `results[].password_analysis.patterns.has_date_pattern` | boolean |
| `results[].password_analysis.patterns.has_leet_speak` | boolean |
| `results[].password_analysis.patterns.has_sequential_chars` | boolean |
| `results[].password_analysis.patterns.has_repeated_chars` | boolean |
| `results[].password_analysis.dictionary_match` | object |
| `results[].password_analysis.dictionary_match.is_common_password` | boolean |
| `results[].password_analysis.dictionary_match.common_password_rank` | null |
| `results[].password_analysis.dictionary_match.is_dictionary_word` | boolean |
| `results[].password_analysis.dictionary_match.dictionary_word_found` | null |
| `results[].target` | object |
| `results[].target.url` | string |
| `results[].target.url_raw` | string |
| `results[].target.fqdn` | string |
| `results[].target.domain` | string |
| `results[].target.service` | string |
| `results[].target.platform` | string |
| `results[].target.main_category` | string \| null |
| `results[].target.sub_category` | string \| null |
| `results[].target.risk_tier` | string \| null |
| `results[].target.is_corporate` | boolean |
| `results[].target.requires_mfa_by_default` | boolean \| null |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-employee-credentials/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 21,
  "results": [
    {
      "id": "000000000000000e37e30001",
      "url": "https://www.fernhill.example/",
      "state": "unresolved",
      "account": {
        "id": "000000000000000ec9430001",
        "email": "user@acme.example",
        "domain": "acme.example",
        "is_executive": false,
        "first_name": null,
        "last_name": null,
        "title": null,
        "linkedin_url": null,
        "department": null
      },
      "added_at": "2025-06-01T08:00:00Z",
      "password": "********",
      "password_analysis": {
        "strength": {
          "level": 0,
          "score": 25,
          "label": "Very Weak",
          "entropy_bits": 20.5
        },
        "composition": {
          "length": 8,
          "structure": "********",
          "character_classes_used": 3,
          "contains_uppercase": true,
          "contains_lowercase": true,
          "contains_number": true,
          "contains_special": false,
          "starts_with_uppercase": false,
          "ends_with_numbers": false,
          "ends_with_special": false
        },
        "patterns": {
          "has_keyboard_pattern": false,
          "has_date_pattern": false,
          "has_leet_speak": false,
          "has_sequential_chars": false,
          "has_repeated_chars": false
        },
        "dictionary_match": {
          "is_common_password": false,
          "common_password_rank": null,
          "is_dictionary_word": false,
          "dictionary_word_found": null
        }
      },
      "target": {
        "url": "https://www.fernhill.example/",
        "url_raw": "https://www.fernhill.example/",
        "fqdn": "www.fernhill.example",
        "domain": "fernhill.example",
        "service": "Webmail",
        "platform": "Web",
        "main_category": null,
        "sub_category": null,
        "risk_tier": null,
        "is_corporate": false,
        "requires_mfa_by_default": null
      }
    },
    {
      "id": "000000000000000e37e30002",
      "url": "http://app.kestrel.example/",
      "state": "unresolved",
      "account": {
        "id": "000000000000000ec9430002",
        "email": "user@fernhill.example",
        "domain": "fernhill.example",
        "is_executive": false,
        "first_name": null,
        "last_name": null,
        "title": null,
        "linkedin_url": null,
        "department": null
      },
      "added_at": "2025-05-25T08:00:00Z",
      "password": "********",
      "password_analysis": {
        "strength": {
          "level": 1,
          "score": 45,
          "label": "Weak",
          "entropy_bits": 35.5
        },
        "composition": {
          "length": 8,
          "structure": "********",
          "character_classes_used": 3,
          "contains_uppercase": true,
          "contains_lowercase": true,
          "contains_number": true,
          "contains_special": false,
          "starts_with_uppercase": false,
          "ends_with_numbers": false,
          "ends_with_special": false
        },
        "patterns": {
          "has_keyboard_pattern": false,
          "has_date_pattern": false,
          "has_leet_speak": false,
          "has_sequential_chars": false,
          "has_repeated_chars": false
        },
        "dictionary_match": {
          "is_common_password": false,
          "common_password_rank": null,
          "is_dictionary_word": false,
          "dictionary_word_found": null
        }
      },
      "target": {
        "url": "http://app.kestrel.example/",
        "url_raw": "http://app.kestrel.example/",
        "fqdn": "app.kestrel.example",
        "domain": "kestrel.example",
        "service": "VPN",
        "platform": "Android",
        "main_category": "Email",
        "sub_category": "Email",
        "risk_tier": "LOW",
        "is_corporate": false,
        "requires_mfa_by_default": true
      }
    }
  ]
}
```

### 400 · Invalid Parameter (invalid page=0)

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-employee-credentials/search?page=0' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "page",
      "details": [
        "Ensure this value is greater than or equal to 1."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/compromised-employee-credentials/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.email",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.first_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.last_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.department",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.title",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.linkedin_url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "password",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "password_analysis.strength.label",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "password_analysis.composition.structure",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "password_analysis.dictionary_match.dictionary_word_found",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.url",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.url_raw",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.fqdn",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.domain",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.service",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.platform",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.main_category",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.sub_category",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "target.risk_tier",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "account.is_executive",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.contains_uppercase",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.contains_lowercase",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.contains_number",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.contains_special",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.starts_with_uppercase",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.ends_with_numbers",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.composition.ends_with_special",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.patterns.has_keyboard_pattern",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.patterns.has_date_pattern",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.patterns.has_leet_speak",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.patterns.has_sequential_chars",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.patterns.has_repeated_chars",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.dictionary_match.is_common_password",
        "type": "eq",
        "value": true
      },
      {
        "name": "password_analysis.dictionary_match.is_dictionary_word",
        "type": "eq",
        "value": true
      },
      {
        "name": "target.is_corporate",
        "type": "eq",
        "value": true
      },
      {
        "name": "target.requires_mfa_by_default",
        "type": "eq",
        "value": true
      },
      {
        "name": "added_at",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "password_analysis.strength.level",
        "type": "eq",
        "value": 0
      },
      {
        "name": "password_analysis.strength.score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "password_analysis.strength.entropy_bits",
        "type": "eq",
        "value": 0
      },
      {
        "name": "password_analysis.composition.length",
        "type": "eq",
        "value": 0
      },
      {
        "name": "password_analysis.composition.character_classes_used",
        "type": "eq",
        "value": 0
      },
      {
        "name": "password_analysis.dictionary_match.common_password_rank",
        "type": "eq",
        "value": 0
      },
      {
        "name": "id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "id",
      "order": "desc"
    }
  ]
}'
```
