Query Examples

Post Filters

Use caseQuery
Search for posts written by a threat actorauthor:lockbitsupp
Search for content in a specific languagelanguage:russian
Search for content that was published in a certain time frame(published:>1596240000000 published:<1599550000000)

Site Filters

Use caseQuery
Filter by site domainsite.domain:xss.is
Filter by site namesite.name:"xss"
Searching for websites related to financial crimesite.category:financial_crime
Searching for hacking forumssite.category:cyber_threat_intelligence AND site.type:discussions
Searching for radical chat channelssite.type:chat AND enriched.category:extremism
Searching for gaming chat channelssite.type:chat AND enriched.category:gaming
Searching for drug traffickingsite.type:(market OR chat OR discussions) AND enriched.category:drugs

Thread Filters

Use caseQuery
Searching for a Telegram channelthread.url:"https://t.me/Fullz"
Searching for posts from a specific section in the sitethread.site_section:"https://raidforums.com/Forum-Databases"
Searching for a thread with a specific topic and a minimum count of participants and commentsthread.title:"openbullet" AND thread.participants_count:>5 AND thread.replies_count:>10

Extended Filters

Use caseQuery
Searching for mentioned external links with specific suffixesextended.external_link:*.onion
Searching for login-protected websitesextended.required_login:true
Filter by networkextended.network:telegram

Enriched Filters

Use caseQuery
Filter by categoryenriched.category:hacking
Searching for high-risk indicators of exposed PII and data breachesenriched.category:data_breach AND enriched.cyber_risk.value:>6
Searching for leaked data published online by ransomware gangsenriched.category:(data_breach AND ransomware)
Searching for mentions of emails from a specific domainenriched.email.value:*@acme.com
Searching for specific phone valuesenriched.phone.value:*15159992896
Searching for credit card leaksenriched.credit_card.count:>0
Searching for posts that include routers' default gateway IP (might indicate a cyber risk )enriched.ip.value:(127.0.0.1 OR 192.168.0.1 OR 10.0.0.1)