Infostealer Log Data API
Retrieve the parsed contents of infostealer logs, including credentials, cookies, autofills, and more."
SpyCloud's Infostealer Log Data API returns the parsed contents of infostealer malware logs that SpyCloud has recaptured from the criminal underground. Each log is organized into named collections: saved credentials, session cookies, autofill data, browsing history, file listings, running processes, installed software, and more.
The Investigations Breach Data API tells you that an identity appears in an infostealer log. The Infostealer Detail API shows you what else that log contains: which sessions were captured, which applications were exposed, what was on the device, and whether the same device was infected more than once.
Access
- Where it lives. The Infostealer Log Data API is part of the Investigations API license. Your SpyCloud account team enables it on your existing Investigations API key. You do not need a new key.
- What a call costs. Each call consumes one query from your Investigations API quota.
- What you need. Every request requires a
log_idor aninfected_machine_id. Both values appear on infostealer-sourced records returned by the Investigations API and the IDLink API.
Data coverageDetail is available for logs SpyCloud published starting in November 2024. Earlier log IDs return "not found" from this API, even when they remain valid in the Investigations API.
Collections reference
| Collection | What it contains | Why it matters |
|---|---|---|
credentials | Saved browser logins: URLs, usernames, and passwords | Shows every account the device could reach, often in plaintext |
cookies | Browser session cookies and tokens | Can let an attacker resume sessions without a password or MFA. Some tokens survive a password reset. |
autofills | Data saved in browser form fields | Can include names, addresses, phone numbers, payment details, and anything the user typed into web forms |
credit_cards | Payment cards stored in the browser | Direct financial fraud exposure |
history | Browsing history | Reveals behavior, services used, and potential targets |
bookmarks | Saved bookmarks | Can point to internal portals, admin consoles, and frequently used services |
downloads | Download history | Can point to how the malware reached the device |
clipboard | Clipboard contents at the time of infection | Can hold copied passwords, keys, or wallet addresses |
processes | Processes running at the time of infection | Can help identify security tools, remote access software, and the malware itself |
software | Installed software | Shows the device's application footprint, including VPN, remote access, and developer tools |
Response format
Responses return JSON by default. The collections endpoint also supports CSV.
Considerations
- Publish date is not infection date.
spycloud_publish_daterecords when SpyCloud acquired the data. For redistributed logs, that can be long after the malware ran. Useinfected_timeto date the infection. - Machine ID lookups can miss logs. If a log's
infected_machine_idis empty, Get logs by infected machine ID cannot return it. Recover thelog_idfrom the Investigations API and query the log directly. - One log often holds several collections. Credentials and cookies commonly arrive in the same log. Check metadata before treating them as separate exposures.
- Large cookie stores. Logs can contain thousands of cookies. Use
cookie_limit, and process large responses in code rather than loading them into memory at once. - Parsed data. The API returns SpyCloud's parsed, structured representation of each log, not the original raw archive.
- Limits. Standard Investigations API quotas, rate limits, and retry guidance apply. See API Guidelines.
Updated 1 day ago