Choosing the Right Deployment

For SpyCloud Investigations

SpyCloud Investigations helps security and fraud teams uncover identity-based risks using rich, recaptured data from the criminal underground. Whether you’re responding to alerts, investigating threats, or enriching internal data, there’s a deployment method that fits your needs.

This guide will help you choose the right way to access SpyCloud Investigations — from quick, manual research to automated, large-scale integrations.


Investigations Offerings


Overview of Each Offering

OfferingAccess TypeQuery StyleIdeal For
Investigations ModuleSaaS-based consoleManual via UIAnalysts and quick lookups
Investigations APIREST-based APIQuery-based (JSON)Automated SIEM/SOAR enrichment
IDLink APIJSON Graph-spec APICorrelation queriesHigh-volume identity risk correlation

🎯 Use Case Match-Up

Use CaseRecommended Option
Manually investigate an identityInvestigations Module
Enrich SIEM/SOAR alerts automaticallyInvestigations API
Investigate exposure from malware-infected devicesInvestigations Module
Correlate personal and corporate identitiesIDLink API
Review vendor/contractor/employee exposureIDLink API or Investigations Module
Upload a list of identities for quick reviewInvestigations Module

👥 Who's Using What?

TeamBest Fit Deployment
SOC / IRInvestigations Module or Investigations API
Threat IntelligenceInvestigations API or IDLink API
Security EngineeringInvestigations API
Fraud / RiskIDLink API
MSSPsInvestigations Module (analysts) + API (integrations)

📊 Volume-Based Guidance

Investigation VolumeRecommended Option
Low (manual, <100 queries/week)Investigations Module
Medium (~10K queries/week)Investigations API
High (10K+ lookups, correlations)Investigations API or IDLink API

🔌 Integration Style

How You Want to Use ItBest Option
No integration — just need quick resultsInvestigations Module
Feed exposure data into your SIEM (e.g. Splunk)Investigations API
Automate response in SOARInvestigations API
Score risk for employees/vendors/customersIDLink API
Enrich identities from a CSV — no codingInvestigations Module

💬 Need Other Options?


🙋 Need Help Choosing?

Not sure which deployment is right for your team?
We’re here to help.

Contact your SpyCloud representative to walk through your:

  • Use cases
  • Data volume
  • Integration preferences
  • Team structure

& find the best fit for your organization.