The dataset, built from the source up.

We collect, on criminal sources, what feeds detection. No broker, no aggregated third-party feed.

Every source feeds a single dataset.

Channels, forums and marketplaces are followed continuously. What is published there is normalised, deduplicated and indexed, then matched against the monitored perimeters.

Ingestion feed live
  • telegram resale channel combo list
  • marketplace log batch infostealer
  • forum database leak ulp
  • paste dump excerpt combo list
  • discord log sharing infostealer
500M
credentials per day
14B+
unique credentials indexed
< 60 min
from publication to availability
9
source types followed
01

Near real time

Under 60 minutes between publication on a source and availability in the platform.

02

Proprietary, not aggregated

We buy no data. Adding a source is an engineering decision, not a negotiation with a supplier.

03

History kept

A credential keeps every occurrence: first and last seen, distinct sources, never overwritten.

Where stolen credentials circulate.

Clear web and darknet, indexed by us. Each source type delivers a different kind of leak.

  • 01

    Telegram channels

    Channels and bots reselling infostealer logs, fresh combo lists, free samples.

  • 02

    Underground forums

    Sale announcements, database leaks, accesses resold by initial access brokers.

  • 03

    Dark web marketplaces

    Infostealer logs sold individually, sorted by country, service or company.

  • 04

    Paste sites

    Combo lists and dump excerpts published in clear, often recycled.

  • 05

    Discord servers

    Logs and combo lists shared between actors, short-lived exchange rooms.

  • 06

    Threat actor communities

    Invitation-only private channels, where batches circulate before any publication.

  • 07

    File hosting services

    Log archives and full dumps dropped on sharing services.

  • 08

    Encrypted messaging

    Direct exchanges between sellers and buyers, outside any forum.

  • 09

    Restricted-access forums

    Closed markets where reputation gates access to the freshest batches.

Three kinds of leak, one format.

Depending on the source, the same e-mail address arrives with three very different levels of context.

Combo listlogin:password

Compilations of login and password pairs, aggregated from older breaches, phishing or password spraying. High volume, variable origin and freshness.

We know an account leaked, without knowing where or whether it is still alive.
ULPurl:login:password

Lines extracted from infostealer logs and mass-redistributed, with the login URL. The most common format on Telegram.

We know on which service the credential was typed, so which one is exposed.
Infostealer log40+ fields

The output of a machine infected by Lumma, RedLine, Vidar, Raccoon or StealC: credentials, cookies, tokens, files, system data.

We know which machine is infected and which sessions are still open.

What each leak type contains.

The password is readable in clear after your identity is validated. An active session is an access without password and without MFA.

Combo listULPInfostealer log
Login [✓] [✓] [✓]
Password [✓] [✓] [✓]
Login URL · [✓] [✓]
Source and detection date [✓] [✓] [✓]
Cookies and active sessions direct access without password · · [✓]
Cloud and mailbox tokens direct access without password · · [✓]
Autofill: address, phone, cards · · [✓]
Files: .env, private keys, exports · · [✓]
Infected machine: name, OS, IP, geolocation direct access without password · · [✓]
Malware and infection date · · [✓]
Browsing history, clipboard · · [✓]
[✓] present

A demo on your perimeter, not on a demo dataset.

Console tour, API integration, leaks detected on your domains, live.

  • [✓] No NDA
  • [✓] No commitment
  • [✓] No installation