Stealer data integrated in your security stack
The same marketplace intelligence as the platform, as JSON for your SIEM, SOAR or product. One REST API, thirteen endpoints per domain.
Mock server with synthetic data · No key needed to start · EU-hosted
curl https://api.passguard.dev/v2/infections/example.com Hundreds of organisations are safer with Passguard
From your first request to production
GET /v2/infections/{domain} complete infection data
GET /v2/devices/{domain} grouped per device
GET /v2/tokens/{domain} exposed session tokens
GET /v2/traces/{domain} verified ULP lists GET /v2/breaches/{domain} verified breaches
GET /v2/leaks/{domain} leaked accounts GET /v2/cracks/{domain} cracked hashes
GET /v2/threats/{domain} target lists GET /v2/credentials/{domain} credentials across all sources
GET /v2/quickscan/{domain} summary per domain Every endpoint, parameter and schema: read the docs
Everything you need to investigate infections
See the affected device, exposed sessions, malware details, files, screenshots and timeline in one place.
Device details
Identify the compromised device and its environment.
- Device type
- OS version
- Hostname
- IP address
- Device username
- Processor
- CPU cores
- Graphics card
- Memory
- Language
- Keyboard layout
- Timezone
Session details
See which active sessions and credentials may be exposed.
- Session tokens
- Cookies
- URLs
- Usernames
- Passwords
- Browser version
Infection details
See what caused the infection and what malware was involved.
- Stealer family
- Subtype
- Malware path
Collected data
See what additional data was captured from the infected device.
- Screenshots
- Local files
Timeline
See when the infection occurred and when the data surfaced.
- Infection timestamp
- Marketplace listing date

“We benchmarked all major providers. Passguard delivered the clearest and most complete data.”
Developer resources
Everything you need to go from first request to production.
Everything you need to know
The essentials, explained in plain language.
Not answered here? Contact us
How do I get API access?
Customers receive a production API key through the Passguard API Hub. A developer key is available for testing right away. Try the Demo API
Can I test the API before becoming a customer?
Yes. With the free developer key you can query endpoints, explore example data and build your integration without commitment.
What kind of data can I retrieve?
The API provides four data streams: infostealer infections, infostealer traces, threat indicators and breached accounts. Each returns structured JSON with rich context.
How is the data updated and validated?
Passguard continuously ingests from criminal marketplaces and underground sources. Data is normalised, validated and deduplicated before reaching your stack.
How is usage measured and billed?
Usage is based on the number of domains you monitor. Monitoring means you initiate a daily API request for each domain to fetch the latest data.
Is it just stealer data?
No. In addition to infostealer infections, Passguard provides traces, threat indicators and breached accounts for a complete view of exposure.
Can I test the API without a key?
Yes. The mock server at api.passguard.dev serves synthetic records in the production schema and needs no authentication. Use it to build and test your integration; real data is only served by api.passguard.com with a Bearer token.
Which domains may I query?
Only domains you have a legitimate interest in: domains you own, operate or are explicitly authorised to assess. Every request is validated and logged with the account, domain and time.
