# DarknetSearch ## Docs - [Monitoring assets](https://wiki.darknetsearch.com/api/guides/alerts.md): Watch your assets continuously — create monitoring rules, read and triage matches, suppress noise, and track the numbers. - [Assess and report on exposure](https://wiki.darknetsearch.com/api/guides/assess-overview.md): Turn raw findings into a security posture — a scored risk profile, leak statistics and trends, and shareable PDF reports. - [Authentication](https://wiki.darknetsearch.com/api/guides/authentication.md): How to authenticate with the DarknetSearch API — JWT bearer tokens, refresh, and 2FA. - [Find leaked credentials](https://wiki.darknetsearch.com/api/guides/credential-exposure.md): How DarknetSearch exposes leaked credentials — and which approach to reach for, by goal. - [Filtered credentials](https://wiki.darknetsearch.com/api/guides/credentials-filtered.md): Clean, deduplicated, domain-scoped credentials for the domains you own — scored and arranged by category. - [Raw Data](https://wiki.darknetsearch.com/api/guides/credentials-raw-sweep.md): The widest, unprocessed view of the entire leak corpus — raw records of every shape. - [Stealer logs](https://wiki.darknetsearch.com/api/guides/credentials-stealer-logs.md): Search the credential corpus by infected machine — each hit is a full stealer-log capture, with a bot record and screenshots you pull on demand. - [The ULP feed](https://wiki.darknetsearch.com/api/guides/credentials-ulp-feed.md): The URL / Login / Password feed — searchable leaked credential triples from combolists and stealer logs. - [Downloads and exports](https://wiki.darknetsearch.com/api/guides/downloads-exports.md): How to move API results into files, and when to use the export service instead of downloading original leak files. - [App Store Monitoring](https://wiki.darknetsearch.com/api/guides/expert-app-store.md): Find spoofed apps impersonating your brand on the iTunes and Google Play stores - [Open Cloud Storage](https://wiki.darknetsearch.com/api/guides/expert-cloud-storage.md): Search misconfigured S3 buckets and Azure containers for files exposing your data - [Credit Cards](https://wiki.darknetsearch.com/api/guides/expert-credit-cards.md): Search leaked and for-sale payment cards by BIN, last 4, owner, and bank across indexed leaks and deep-web marketplaces - [Data Brokers](https://wiki.darknetsearch.com/api/guides/expert-data-brokers.md): Search underground forums and data-broker marketplaces for posts that advertise, trade, or dump your organization's data - [Discord](https://wiki.darknetsearch.com/api/guides/expert-discord.md): Search Discord servers used by hacking communities with rich per-message context - [Data Pastes](https://wiki.darknetsearch.com/api/guides/expert-pastes.md): Search public paste sites for stolen data and credentials tied to your domain - [Phishing References](https://wiki.darknetsearch.com/api/guides/expert-phishing.md): Search the PhishTank community database for phishing sites impersonating your brand - [Search individual data sources](https://wiki.darknetsearch.com/api/guides/expert-search.md): Search one indexed data source at a time — 14 data sources, each with its own filters, result shape, and guide. - [SSL Transparency Logs](https://wiki.darknetsearch.com/api/guides/expert-ssl-logs.md): Search certificate transparency logs for certificates issued against your domains and surface unknown subdomains and stale hosts - [Telegram](https://wiki.darknetsearch.com/api/guides/expert-telegram.md): Search 2,200+ tracked cybercrime Telegram channels with Boolean queries and read message-level hits - [Threat Actor Publications](https://wiki.darknetsearch.com/api/guides/expert-threat-actors.md): Search ransomware leak-site victims to see which organizations a ransomware group has named and published - [URL Shorteners](https://wiki.darknetsearch.com/api/guides/expert-url-shorteners.md): Search indexed shortened links to unmask the phishing and malicious destinations they hide - [Export result sets](https://wiki.darknetsearch.com/api/guides/export-service.md): Use the general export service to turn supported API result sets into downloadable JSON, CSV, or XLSX files. - [Download leak files](https://wiki.darknetsearch.com/api/guides/leak-file-downloads.md): How to extract data from one leak, and when the original leak-file download flow applies. - [Live Data Broker Search](https://wiki.darknetsearch.com/api/guides/live-data-brokers.md): Scan Russian Market in real time for stealer-log listings that name your domain — see what's for sale, filter it, and request acquisition. - [Live search](https://wiki.darknetsearch.com/api/guides/live-search.md): Real-time searches that query external sources at request time. Three live searches: Live Data Broker Search (Russian Market), Tor & I2P, and Email References. - [Delivery: email and webhooks](https://wiki.darknetsearch.com/api/guides/monitoring-delivery.md): Send matches where they're needed — email senders, recipients, templates, and signed webhooks. - [Exclusion lists](https://wiki.darknetsearch.com/api/guides/monitoring-exclusions.md): Suppress known-good and false-positive hits per rule — by condition or by uploading a CSV. Forward-only. - [Read and triage matches](https://wiki.darknetsearch.com/api/guides/monitoring-matches.md): List incidents, open one, page its hits, set a triage status, and export — the hit shape mirrors the monitored source. - [Metrics](https://wiki.darknetsearch.com/api/guides/monitoring-metrics.md): Roll up your monitoring — per-source and per-day counts, a 12-month trend, and the org-wide default cadence. - [Create a monitoring rule](https://wiki.darknetsearch.com/api/guides/monitoring-rules.md): Create a monitoring rule — pick a data source, hand it your asset, set the cadence, and attach delivery. - [Rate limits](https://wiki.darknetsearch.com/api/guides/rate-limits.md): How the DarknetSearch API limits requests — how to read your usage and limits, and how to handle a 429. - [Rate limits by endpoint](https://wiki.darknetsearch.com/api/guides/rate-limits-reference.md): The request limit for every DarknetSearch API endpoint, grouped as in the API reference. - [Reports](https://wiki.darknetsearch.com/api/guides/reports.md): Generate PDF reports of your exposure — a premium research report or a credential comparison — on demand or on a schedule. - [Credential comparison report](https://wiki.darknetsearch.com/api/guides/reports-credential-comparison.md): Compare leaked credentials across a set of domains over a period — on demand or on a monthly schedule. - [Premium report](https://wiki.darknetsearch.com/api/guides/reports-premium.md): A full exposure report for one domain over a period — benchmarked against your industry, size, and country. - [Risk and exposure](https://wiki.darknetsearch.com/api/guides/risk-score.md): Your organization's risk score, leak statistics, trends, and peer benchmarks — and how to read them for threat intelligence. - [Searching DarknetSearch](https://wiki.darknetsearch.com/api/guides/search-overview.md): Three ways to search dark-web and breach intelligence — broad, source-by-source, or live — and which to reach for. - [Set up your organization](https://wiki.darknetsearch.com/api/guides/setup.md): Organizations are created in the dashboard — here's how to read and work with yours via the API. - [Search across all data sources](https://wiki.darknetsearch.com/api/guides/wide-search.md): Pick one search term and the platform searches it across every relevant data source at once. - [API changelog](https://wiki.darknetsearch.com/changelog.md): Changes to the public DarknetSearch API — breaking changes, new capabilities, and fixes. Tracks the API reference. - [API guides](https://wiki.darknetsearch.com/index.md): What the DarknetSearch API does, and which guide to use for your goal. ## OpenAPI Specs - [openapi](https://wiki.darknetsearch.com/api/openapi.json)