The monitored domain this secret was matched to - the domain you queried.
infected_emails
array
Employee account email(s) found in the same infostealer log.
crawled_date
string
When Webz.io collected the record.
Secret
Field
Type
Description
token_type
string
Kind of credential, e.g. ApiKey, OauthPAT, RefreshToken, PrivateKey.
service_type
string
Detector / issuing service that matched the secret, e.g. googleoauth2.
matched_string
string
The secret as found. Masked (e.g. AI****Xk) unless your account has the view-password permission.
secret_parts
object
The secret split into its named parts (e.g. key, or client_id + client_secret). Masked under the same rule.
verified
boolean
true when the secret was confirmed live against its issuer.
verification_status
string
verified, unverified, or unknown.
enrichment
What the issuing service told us when the secret was verified. Keys vary by service_type; the object is omitted when there is nothing to report (typically unverified secrets).
Field
Description
rotation_guide
Link to a step-by-step guide for rotating this kind of secret.
scopes
Permissions the secret grants, e.g. repo, read:org.
account_type, username, url, account
The account the secret belongs to, as reported by the issuer.
version, key_id, …
Other issuer-specific details.
evidence
Where the secret was found.
Field
Description
file_name
Name of the file the secret was found in, e.g. .env.
file_extension
File extension.
file_path
Path of the file inside the stealer log.
context
The raw log lines around the secret; find it with matched_string. Returned only when your account has the view-password permission, since the lines may hold other credentials.
device_info
The infected machine the secret was taken from.
Field
Description
infection_uuid
Id of the infection. Records from the same machine share it - across cookies, secrets, and Data Breaches API credentials.
exfiltration_date
When the data was exfiltrated from the device.
log_file_name
Source log file.
hwid
Device hardware id.
ip_address
Device IP address.
location
country, city, zip_code.
computer_username
Username on the infected machine.
os
Operating system.
antivirus_software
Detected antivirus.
malware_family
Malware family.
malware_path
Path of the malware on the device.
publication_source_info
Field
Description
file_name, file_link
Source file name and link (when your plan includes file info).