Platform

Turn infections into action

Quickly see which devices are compromised, which access was stolen, and what to do next.

Free scan · No signup · Plans from €250 per month

Hundreds of organisations are safer with Passguard

  • Vooruit logo
  • NEH logo
  • Topicus logo
  • AFAS Software logo
  • Damen Shipyards logo
  • Royal FloraHolland logo
  • Exonet logo
  • The S-Unit logo
  • NS logo
  • NFIR logo
  • SRM logo
  • Stratech logo
  • Vos Logistics logo
Inside the platform

From first domain to a closed investigation

The data

Everything you need to investigate infections

See the affected device, exposed sessions, malware details, files, screenshots and timeline in one place.

Device details

Identify the compromised device and its environment.

  • Device type
  • OS version
  • Hostname
  • IP address
  • Device username
  • Processor
  • CPU cores
  • Graphics card
  • Memory
  • Language
  • Keyboard layout
  • Timezone

Session details

See which active sessions and credentials may be exposed.

  • Session tokens
  • Cookies
  • URLs
  • Usernames
  • Passwords
  • Browser version

Infection details

See what caused the infection and what malware was involved.

  • Stealer family
  • Subtype
  • Malware path

Collected data

See what additional data was captured from the infected device.

  • Screenshots
  • Local files

Timeline

See when the infection occurred and when the data surfaced.

  • Infection timestamp
  • Marketplace listing date
Six data streams

Intelligence from across criminal markets.

See different types of exposure side by side, so an account or identity is never viewed in isolation. Need to integrate the data into your own workflows? All data streams are also available through the API.

Explore the API
  • Infostealer infectionsInfected devices, exposed sessions and infection context.
  • Infostealer tracesCredentials found in ULP lists tied to infostealer activity, with source context.
  • Target listsAccounts and identities found on target lists used in attack campaigns.
  • Password cracksDehashed passwords found on password crack lists.
  • Leaked accountsAccounts and credentials exposed in compilations, paste lists and other leaked datasets.
  • Breached accountsAccounts and profiles exposed in third-party data breaches.
Jeroen van de Pol, Manager ICT at Stratech
“By using Passguard, we meet the ISO 27001 requirement around threat intelligence.”
Jeroen van de PolManager ICT, StratechRead the story
Resources

Infostealer detection resources

Understand the threat and how Passguard monitors criminal marketplaces.

FAQ

Everything you need to know

The essentials, explained in plain language.

Not answered here? Contact us

How fast can we start?

Add your assets (domains, portals or email accounts), verify them by email, DNS or a request to us, and monitoring starts immediately. Most teams are live within minutes. There is no agent to install and no access to your systems required.

How do notifications work?

Every new listing that touches your domains triggers a notification in the platform and by email. If you want the data in your own tools, use the API.

Can I add colleagues?

Yes. Invite team members, assign infections, label them and comment, so investigations stay transparent and progress is shared.

Which data do I see per infection?

Device details (OS, hostname, IP, username), the exposed sessions and services, the stealer family and malware path, and a timeline with the infection date and the date it was listed.

Does the platform show more than infostealer infections?

Yes. Next to infections you see infostealer traces, threat indicators such as target list mentions, and breached accounts from third-party leaks and compilations.

Where is the data hosted?

In the European Union, on European infrastructure. Passguard is a Dutch company and GDPR compliance is part of how the platform is built.

Start with a free scan of your domain, or book a demo and we walk you through the platform using your results.

See pricing