AlertsBar
Domain exposures: breaches, infostealers, ULP heap, cookies. Counts and samples, free.
- 0.1.1
- Version
- remote
- Transport
- 2
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 2 tools scanned
- metadata: scanned
No findings.
Tools (2)
exposure_counts_for_domain
Credential-exposure counters for a domain. Counts only - no credential values or per-account detail. Sources: known breaches, infostealer infections, unattributed heap of ULP (Url,Login,Password) bundles, stolen cookies. All figures are INDEXATION dates, not incident dates: _month/_week mean 'newly indexed', never 'newly leaked' - the underlying leak may be years old. Windows nest (_total includes _month includes _week) - never sum them. Counters are rebuilt once daily, so figures are up to 24h old and never real-time. Repeated calls for the same input within a day return identical values - do not re-query to check for changes. Accepts a bare domain or a full URL; scheme, path, port, case and a leading www. are stripped and subdomains collapse to the registrable domain (multi-tenant hosting suffixes such as github.io are not collapsed). An IDN must already be in punycode (xn--) form. Invalid input (not a domain, an IP address) returns an error. If the domain is not in the index at all,
exposure_samples_for_domain
A small RANDOM sample of individual exposure records for a domain - metadata only, capped in number: up to 20 records per type (stealers_users, stealers_staff, heap_users, heap_staff, breaches). Cookies are not sampled - see cookies_* in exposure_counts_for_domain. The sample is neither the newest nor the largest nor the most severe records, and it can differ between calls; identical-looking records can repeat and because of different logins/passwords. Each record says WHICH url was affected, WHICH domain the captured login belonged to, from WHICH source type, roughly when the incident was, and when the record was indexed. It carries NO credentials: no password, no username, and the login's local part is redacted. Use exposure_counts_for_domain first for the scale of the problem and for freshness (last_indexed_at); use this only when the user asks to see concrete examples. Calling again returns another random subset, never the full set - do not call it repeatedly to collect more record