Investigations API

Start here to choose between the Investigations, IDLink, and Infostealer Log Data APIs.

SpyCloud's Investigations Breach Data API, IDLink API, and Infostealer Log Data API give you programmatic access to SpyCloud's recaptured breach and malware data. All three are REST APIs that work with your Investigations API key. Start with the question you need to answer, then continue to the guide for that API.

Which API answers which question?

If you haveAnd wantUse
A selector: email, username, phone, IP, password, domain, and moreEvery exposure record for itInvestigations Breach Data API
A selectorThe other identities, accounts, and devices connected to itIDLink API
A log_id or infected_machine_idWhat the infostealer log actually containsInfostealer Log Data API
A source_idDetails about the breach or sourceInvestigations API breach catalog endpoints

The APIs at a glance

Investigations Breach Data API

Returns every exposure record for a selector, as JSON. It's built for SIEM and SOAR enrichment, batch jobs, and evidentiary pulls. Breach catalog endpoints return details about a breach or source by source_id.

IDLink API

Correlates identities at scale. Starting from a selector, it returns the other identities, accounts, and devices connected to it, as JSON records or JSON Graph Format.

Infostealer Log Data API

Returns the parsed contents of an infostealer log, organized into collections such as credentials, cookies, and autofills. Requests require a log_id or infected_machine_id, and responses are JSON or CSV by collection. Detail is available for logs published starting in November 2024.

Next steps

Guidelines and sample configuration

All three APIs share the same authentication, IP allow-listing, pagination, and error handling. Read the API Guidelines before you build.


Did this page help you?