API

Stealer data integrated in your security stack

The same marketplace intelligence as the platform, as JSON for your SIEM, SOAR or product. One REST API, thirteen endpoints per domain.

Mock server with synthetic data · No key needed to start · EU-hosted

curl https://api.passguard.dev/v2/infections/example.com

Hundreds of organisations are safer with Passguard

  • Tesorion logo
  • Vooruit logo
  • NEH logo
  • Topicus logo
  • AFAS Software logo
  • Hadrian logo
  • Damen Shipyards logo
  • Royal FloraHolland logo
  • Exonet logo
  • The S-Unit logo
  • NS logo
  • NFIR logo
  • SRM logo
  • Stratech logo
  • Vos Logistics logo
Inside the api

From your first request to production

/v2 · 13 data endpoints per domain
GET /v2/infections/{domain}   complete infection data
GET /v2/devices/{domain}      grouped per device
GET /v2/tokens/{domain}       exposed session tokens
GET /v2/traces/{domain}       verified ULP lists

Every endpoint, parameter and schema: read the docs

The data

Everything you need to investigate infections

See the affected device, exposed sessions, malware details, files, screenshots and timeline in one place.

Device details

Identify the compromised device and its environment.

  • Device type
  • OS version
  • Hostname
  • IP address
  • Device username
  • Processor
  • CPU cores
  • Graphics card
  • Memory
  • Language
  • Keyboard layout
  • Timezone

Session details

See which active sessions and credentials may be exposed.

  • Session tokens
  • Cookies
  • URLs
  • Usernames
  • Passwords
  • Browser version

Infection details

See what caused the infection and what malware was involved.

  • Stealer family
  • Subtype
  • Malware path

Collected data

See what additional data was captured from the infected device.

  • Screenshots
  • Local files

Timeline

See when the infection occurred and when the data surfaced.

  • Infection timestamp
  • Marketplace listing date
Rogier Fischer, CEO at Hadrian
“We benchmarked all major providers. Passguard delivered the clearest and most complete data.”
Rogier FischerCEO, HadrianRead the story
Resources

Developer resources

Everything you need to go from first request to production.

FAQ

Everything you need to know

The essentials, explained in plain language.

Not answered here? Contact us

How do I get API access?

Customers receive a production API key through the Passguard API Hub. A developer key is available for testing right away. Try the Demo API

Can I test the API before becoming a customer?

Yes. With the free developer key you can query endpoints, explore example data and build your integration without commitment.

What kind of data can I retrieve?

The API provides four data streams: infostealer infections, infostealer traces, threat indicators and breached accounts. Each returns structured JSON with rich context.

How is the data updated and validated?

Passguard continuously ingests from criminal marketplaces and underground sources. Data is normalised, validated and deduplicated before reaching your stack.

How is usage measured and billed?

Usage is based on the number of domains you monitor. Monitoring means you initiate a daily API request for each domain to fetch the latest data.

Is it just stealer data?

No. In addition to infostealer infections, Passguard provides traces, threat indicators and breached accounts for a complete view of exposure.

Can I test the API without a key?

Yes. The mock server at api.passguard.dev serves synthetic records in the production schema and needs no authentication. Use it to build and test your integration; real data is only served by api.passguard.com with a Bearer token.

Which domains may I query?

Only domains you have a legitimate interest in: domains you own, operate or are explicitly authorised to assess. Every request is validated and logged with the account, domain and time.

Start on the mock server today. When you are ready for real data, we scope your key with you.

See API pricing