grid lines

[ MISP API Service ]

One API. Complete exposure visibility.

Domain intelligence, email exposure and public breach records through a single integration. Built for Managed Intelligence Service Providers (MISPs), SOCs and security vendors who would rather ship monitoring than maintain feeds.

3

Intelligence services

1

Integration

REST · JSON

Over HTTPS

SOC · SIEM · XDR

Where it plugs in

[ The security challenge ]

The exposure you don't know about is the one that hurts

Stolen credentials, infected devices and breached accounts surface far from your perimeter. Most organisations learn about them from the attacker.

icon

Limited exposure visibility

Security teams rarely know when corporate email accounts, employee credentials or internal access details have been exposed.

01 · VISIBILITY

icon

Fragmented intelligence

Credential exposure records and breach reports live in separate datasets, each with its own format, access rules and gaps.

02 · FRAGMENTATION

icon

Delayed response

Without automated monitoring, a compromised account is discovered only after suspicious activity or unauthorised access has already happened.

03 · LATENCY

icon

Hard to integrate

Intelligence only matters inside the SIEM, the ticket queue and the incident workflow your team already runs.

04 · INTEGRATION

[ Our solution ]

Three intelligence services, one endpoint

A centralised interface for exposure intelligence tied to your domains and email addresses. Dark web records and public breach reports, combined and normalised, returned by one call.

exposure records with their sources

From manual searches to intelligence-driven operations

Through one integration your platform can identify potentially compromised corporate accounts, retrieve the exposed credential records behind them, investigate individual employee addresses, surface publicly reported breaches, and feed all of it into monitoring, alerting and incident response.

Domain Intelligence

Exposed corporate accounts, credentials and related indicators associated with an organisation's internet domains.

Email Exposure Intelligence

Every available exposure record tied to an individual address, for account compromise investigations.

Public Data Breach Intelligence

Publicly documented breach incidents that name your domains or addresses, with dates, descriptions and exposed data categories.

[ Core intelligence services ]

Built for the questions a SOC actually asks

Is this domain exposed? Is this employee's account in a stealer log? Has this address been in a reported breach? Three endpoints, one answer format.

[ What you can access ]

What was exposed, who is affected, what to do next

Exposure intelligence across domains, email addresses, compromised accounts and malware-infected devices. Indicators only: standard responses never expose a stolen password or a reusable session.

Accounts already in circulation

Corporate email addresses and usernames, the websites and login URLs they were captured with, password exposure indicators, exposure timestamps, and the corporate and third-party services involved.

The device behind the leak

Malware family or infection indicators, device identifiers and hostnames, operating system metadata, infection and collection timestamps, the accounts tied to the device, and network or location metadata where available.

Sessions that outlive a password reset

Cookie exposure indicators, potential authentication session exposure, the websites and services involved, and browser metadata. An exposure record alone does not prove a session is reusable or that access occurred.

VPNs, cloud consoles, admin portals

Internal and external application login URLs, VPN and remote access account indicators, cloud service accounts, business and administrative application accounts, and third-party service credentials.

One person's entire exposure

Addresses found in credential exposure records, the accounts and services tied to them, malware-related indicators, exposure dates and source information, and related compromised device details where available.

Incidents already on the record

Affected addresses and their incidents, breach names and descriptions, reported dates, categories of compromised information, the affected services, and exposure and publication dates.

[ Data categories ]

Nine categories, one response shape

What comes back depends on the search target, the underlying records, your access permissions and the fields each source supports. Not every search returns every category.

Intelligence category

Available information

Corporate domains

Domain-associated exposure records, affected accounts, related services

Email accounts

Email addresses, usernames, associated exposure records

Credential exposure

Password exposure indicators, compromised login URLs, affected services

Infostealer malware

Malware indicators, compromised device information, related accounts

Device intelligence

Hostnames, operating systems, device identifiers, available IP and location metadata

Browser exposure

Cookie and session exposure indicators, associated websites

Corporate applications

Exposed account indicators for business applications, cloud services, VPNs and administrative portals

Public data breaches

Breach names, dates, descriptions, affected accounts and compromised data categories

Exposure timeline

Available infection, collection, observation and breach dates

[ From data to action ]

Exposure records in, security actions out

The API is built so that a record becomes a decision: reset the password, revoke the session, pull the device, close the ticket.

icon

Identify exposure

Discover potentially compromised accounts, devices and corporate services tied to the domains and people you protect.

STEP 01

icon

Analyse intelligence

Read the affected accounts, the associated services, the available timestamps and the likely scope of the exposure.

STEP 02

icon

Investigate the risk

Decide whether the exposed credentials, devices or authentication sessions need deeper investigation.

STEP 03

icon

Take action

Password resets, session revocation, device investigation and the other protective measures your playbook calls for.

STEP 04

[ Integration ]

Plugs into the stack you already run

Security providers add exposure intelligence to their own products and workflows without building and maintaining several intelligence integrations themselves.

[ Who it is for ]

Teams that sell, run or build security monitoring

The same three services power an analyst's enrichment, an MISP's customer portal and a vendor's new product feature.

Security Operations Centers

Enrich investigations with credential exposure indicators and spot potentially compromised accounts before the alert fires.

Managed Intelligence Service Providers

Put domain and email exposure intelligence inside customer-facing monitoring, scoped per client workspace.

Enterprise security teams

Better visibility into corporate account exposure and a faster path through incident investigations.

Cybersecurity software vendors

Add dark web intelligence and breach exposure monitoring to an existing product without owning the data pipeline.

[ Key business benefits ]

Less integration work, more monitoring shipped

And a new line of business: security providers use the same API to launch credential exposure and breach monitoring services of their own.

icon

One unified API

Domain intelligence, email exposure and public breach records through a single integration and a single contract.

ONE INTEGRATION

icon

Improved visibility

Insight into exposed corporate accounts and potential credential compromise that perimeter tooling cannot see.

OUTSIDE-IN VIEW

icon

Faster investigations

No more separate manual searches across different intelligence services. One query, one normalised answer.

MINUTES, NOT DAYS

icon

Security automation

Exposure intelligence inside monitoring, alerting and incident response workflows, triggered by your rules.

RULES, NOT ANALYSTS

[ Our vision ]

Threat intelligence, accessible through one API

A unified, scalable, developer-friendly intelligence service that helps organisations find credential exposure early and strengthen the monitoring they already run. Domain intelligence, email exposure detection and public breach intelligence, brought together so external exposure becomes part of your own security service.

Service scope: specific fields, including device details, malware metadata and session indicators, are confirmed against licensed source capabilities before they are advertised as guaranteed. Access to sensitive exposure intelligence is subject to authorisation, legal and contractual restrictions.

[ Faq ]

Frequently asked questions

What integrators ask before the first request.

A JSON list of exposure records matched to the domain or email you queried: the affected account, the service or login URL it was captured from, the source category, and the timestamps available for that record.

No. Standard responses carry exposure indicators, never a usable secret. Passwords are hashed on ingest and session material is reported as an indicator only.

Domain and email lookups run against targets you are authorised for. Ownership verification and contractual scope apply, the same as in the AlienGate console.

Per workspace, with a request quota sized to your customer base. Every object belongs to exactly one workspace, so client data never crosses a boundary.

Account, service and source fields are always present. Device, malware and session metadata depend on the underlying record and are marked optional in the reference.

One API. Unified intelligence. Stronger security visibility.

Read the reference, try the endpoints against your own domain, and talk to us about workspace licensing for your customer base.