Investigations API
Start here to choose between the Investigations, IDLink, and Infostealer Log Data APIs.
SpyCloud's Investigations Breach Data API, IDLink API, and Infostealer Log Data API give you programmatic access to SpyCloud's recaptured breach and malware data. All three are REST APIs that work with your Investigations API key. Start with the question you need to answer, then continue to the guide for that API.
Which API answers which question?
| If you have | And want | Use |
|---|---|---|
| A selector: email, username, phone, IP, password, domain, and more | Every exposure record for it | Investigations Breach Data API |
| A selector | The other identities, accounts, and devices connected to it | IDLink API |
A log_id or infected_machine_id | What the infostealer log actually contains | Infostealer Log Data API |
A source_id | Details about the breach or source | Investigations API breach catalog endpoints |
The APIs at a glance
Investigations Breach Data API
Returns every exposure record for a selector, as JSON. It's built for SIEM and SOAR enrichment, batch jobs, and evidentiary pulls. Breach catalog endpoints return details about a breach or source by source_id.
IDLink API
Correlates identities at scale. Starting from a selector, it returns the other identities, accounts, and devices connected to it, as JSON records or JSON Graph Format.
Infostealer Log Data API
Returns the parsed contents of an infostealer log, organized into collections such as credentials, cookies, and autofills. Requests require a log_id or infected_machine_id, and responses are JSON or CSV by collection. Detail is available for logs published starting in November 2024.
Next steps
- Investigations Breach Data API guide: start here for selector-based exposure lookups and breach catalog details.
- IDLink API guide: continue here to pivot from a selector to connected identities.
- Infostealer Log Data API guide: continue here to retrieve the contents of a specific log.
Guidelines and sample configuration
All three APIs share the same authentication, IP allow-listing, pagination, and error handling. Read the API Guidelines before you build.
Updated about 5 hours ago