New

Infostealer-compromised machine analysis

Every infostealer leak tied to the machine that produced it: timeline, still-active sessions and impacted domains, in the cockpit, the list and the API.

Full view of a compromised machine in Stealed, with demo data: identity, indicators, timeline, sessions, domains and log content

A credential stolen by an infostealer never travels alone. The infected machine usually leaked dozens of other accounts, session cookies that still work and a trace of everything installed on it. Until now Stealed showed you those credentials one by one. Infostealer-compromised machine analysis ties them to the machine that produced them.

In your cockpit

A new indicator counts the distinct compromised machines linked to your domains: your employees’ and those of your customers or visitors, the new ones over 30 days, the ones joined to a corporate domain and the ones with a session still active. Copies of the same log, resold or collected again, are grouped: a machine is counted once.

A client's cockpit with the Compromised machines block: distinct machines, internal and external, new over 30 days, domain-joined and with active sessions

The machine list

All your compromised machines on one page, internal first, sortable by infection or publication date, filterable by scope, infostealer family, country, publication date and unexpired sessions. A row opens the machine sheet.

List of a client's compromised machines: infection date, machine name, account, scope, family, country, credentials, cookies and publication date

The machine sheet

Every machine has its sheet: its identity (Windows account, administrator rights, Active Directory domain, hardware identifiers), then everything its log holds, section by section.

Top of a machine sheet: machine identity, credentials, cookies, other secrets and circulation

Timeline of an infection, from the machine being infected to its first release
The whole story of the infection. From the machine being infected to its release on criminal sources: the delay before the first publication, the re-releases and what each one added.
Validity of the stolen sessions, sorted by expiry date
Sessions still usable. Stolen cookies sorted by expiry date, with the ones still valid on your domains brought forward: those open an account without a password.
Root domains hit by a machine, with the number of stolen credentials for each
The real extent of the exposure. Every domain hit by the machine, yours first, with the number of stolen credentials for each.

Everything the log holds

Below the sheet, every section of the log has its table: credentials, cookies and sessions, Windows credentials, installed software, machine environment and releases. Passwords and cookie values stay masked, and for accounts outside your domains the password is never disclosed.

Credentials tab of a machine: your domains first, then other domains, password masked or not disclosed

Cookies and sessions tab of a machine: host, name, masked value, browser, session and expiry date

One click on a row opens the leak detail without leaving the machine.

Leak detail opened from the Credentials tab of a machine

The graph view

The same sheet, drawn: the machine in the centre, its identities around it, then the sites where each one is used. An orange ring flags a session that is still valid. Hover a point to light up its links, click it for its detail.

Graph view of a compromised machine: the machine in the centre, its identities and the sites where each one is used

From a leak to the machine, and back

In your leak lists, the detail of a credential stolen by an infostealer now shows the infected machine: “View the machine” opens its sheet, “Filter on this machine” keeps only its leaks. From the sheet, “View this machine’s leaks” goes the other way.

A client's infostealer leak list and the detail of a credential, with the infected machine and its two buttons

Through the API

Compromised machines and their sheets are available through the API to feed your tools (SIEM, ticketing, reports), for instance to open a ticket for each machine holding an employee credential. Every view shows the matching call, ready to copy in Bash, Python or JavaScript. Secrets never leave through the API.

API call window of the compromised machine list, with the Bash example

Your data stays protected

Passwords and cookies are masked by default. They are revealed on demand only, one at a time, and every reveal is logged. No password is ever shown for an account outside your domains.

Availability

The module is already enabled in your workspace, nothing to request: open your cockpit, the Compromised machines block is waiting for you there.

The screenshots on this page come from a demo workspace: companies, domains, machines and accounts are fictional.