The dataset, built from the source up.
We collect, on criminal sources, what feeds detection. No broker, no aggregated third-party feed.
Every source feeds a single dataset.
Channels, forums and marketplaces are followed continuously. What is published there is normalised, deduplicated and indexed, then matched against the monitored perimeters.
- telegram resale channel combo list normalised · deduplicated · indexed
- marketplace log batch infostealer normalised · deduplicated · indexed
- forum database leak ulp normalised · deduplicated · indexed
- paste dump excerpt combo list normalised · deduplicated · indexed
- discord log sharing infostealer normalised · deduplicated · indexed
- 500M
- credentials per day
- 14B+
- unique credentials indexed
- < 60 min
- from publication to availability
- 9
- source types followed
Near real time
Under 60 minutes between publication on a source and availability in the platform.
Proprietary, not aggregated
We buy no data. Adding a source is an engineering decision, not a negotiation with a supplier.
History kept
A credential keeps every occurrence: first and last seen, distinct sources, never overwritten.
Where stolen credentials circulate.
Clear web and darknet, indexed by us. Each source type delivers a different kind of leak.
- 01
Telegram channels
Channels and bots reselling infostealer logs, fresh combo lists, free samples.
- 02
Underground forums
Sale announcements, database leaks, accesses resold by initial access brokers.
- 03
Dark web marketplaces
Infostealer logs sold individually, sorted by country, service or company.
- 04
Paste sites
Combo lists and dump excerpts published in clear, often recycled.
- 05
Discord servers
Logs and combo lists shared between actors, short-lived exchange rooms.
- 06
Threat actor communities
Invitation-only private channels, where batches circulate before any publication.
- 07
File hosting services
Log archives and full dumps dropped on sharing services.
- 08
Encrypted messaging
Direct exchanges between sellers and buyers, outside any forum.
- 09
Restricted-access forums
Closed markets where reputation gates access to the freshest batches.
Three kinds of leak, one format.
Depending on the source, the same e-mail address arrives with three very different levels of context.
Compilations of login and password pairs, aggregated from older breaches, phishing or password spraying. High volume, variable origin and freshness.
Lines extracted from infostealer logs and mass-redistributed, with the login URL. The most common format on Telegram.
The output of a machine infected by Lumma, RedLine, Vidar, Raccoon or StealC: credentials, cookies, tokens, files, system data.
What each leak type contains.
The password is readable in clear after your identity is validated. An active session is an access without password and without MFA.
| Combo list | ULP | Infostealer log | |
|---|---|---|---|
| Login | [✓] | [✓] | [✓] |
| Password | [✓] | [✓] | [✓] |
| Login URL | · | [✓] | [✓] |
| Source and detection date | [✓] | [✓] | [✓] |
| Cookies and active sessions direct access without password | · | · | [✓] |
| Cloud and mailbox tokens direct access without password | · | · | [✓] |
| Autofill: address, phone, cards | · | · | [✓] |
| Files: .env, private keys, exports | · | · | [✓] |
| Infected machine: name, OS, IP, geolocation direct access without password | · | · | [✓] |
| Malware and infection date | · | · | [✓] |
| Browsing history, clipboard | · | · | [✓] |
A demo on your perimeter, not on a demo dataset.
Console tour, API integration, leaks detected on your domains, live.
- [✓] No NDA
- [✓] No commitment
- [✓] No installation