Financial Crime: Carding forums, credit-card shops, and blogs related to cryptocurrency crime.
Illicit Trafficking: Black markets and underground forums focused on illegal trade, including drugs, weapons, counterfeit goods, and intellectual-property violations.
Extremism & Misinformation: Radical forums, extremist news websites, and alternative social-media platforms that spread misinformation and hate speech.
Brand Monitoring: Illicit or illegal activity related to a brand on social media.
What types of illicit content are covered?
Hacking: Discussions and trade of tools for exploiting vulnerabilities, CVEs, hacking techniques, and planned or executed cyber attacks.
Data Breach: Data-leak sites, exposed personally identifiable information (PII), breach trading, account takeovers, and identity-theft discussions.
Carding: The sale and use of stolen credit-card details, bank-account information, financial-fraud schemes, and ATM fraud.
Crypto: Fraud and criminal activity involving cryptocurrencies, including money-laundering evasion, cryptojacking, and dark-web crypto exchanges.
Phishing: Phishing tools and kits, scam pages, phishing emails, and social-engineering discussions.
Malware: Malware trade and distribution discussions.
Ransomware: Ransomware-group sites, ransomware-as-a-service offerings, and affiliate discussions.
Stealer Logs: Trade, sharing, and discussions of stealer logs.
Counterfeit: Counterfeit goods, forged money or documents, intellectual-property theft, and piracy.
Gaming: Hacked gaming accounts, unauthorized game modifications, and leaked releases.
Sexual: Discussions and distribution of sexual media and content.
How far back can I search with the Cyber API?
Cyber repositories store up to two years of crawled content. Use Time Range to set the period for a request.
What sources does the Cyber API support?
The Cyber API crawls gated, password-protected, and CAPTCHA-protected sources across its supported networks: Tor, the open web, Telegram, public chat, and Discord.
My domain-threat-monitoring search returns no results. Is my company safe?
No. Threat actors may avoid naming a target directly. Supplement a company-name search with other identifiers, such as IP addresses, email domains, products and services, executive names, name variations, and—where relevant—credit-card BINs.
Why do searches for a specific Tor address return few results?
Filtering by one marketplace onion address returns posts from that address only. A marketplace may have multiple onion mirrors. Use site.domain to expand a known domain to its associated onion and clearnet aliases. site.name is also searchable when you know the marketplace name, but it does not expand mirrors.
What entities are supported?
Domains
Emails
Phone numbers
Credit cards
Social Security numbers
Wallet IDs
IP addresses
CVEs
Persons
Organizations
Locations
Why are not all keywords highlighted with highlight=true?
The highlight parameter enables title and text highlight snippets. When Elasticsearch produces a match, the API returns the snippets in highlightTitle and highlightText.
What does adversary-group classification include?
The API returns the adversary_group values associated with author data in indexed posts. It passes through those values; it does not classify groups or resolve aliases.