Data Points

📋 Paste / Leak Post

Text posted to a paste site or leak forum — a frequent first appearance of stolen data.
Dark & Leak

Sources

8
5 no-auth

Disciplines

2
that use it

Mission domains

5
reach

Workbench

native tool

🔌 Sources that yield Paste / Leak Post (8)

SourceCategoryAuthFormat
AIL Framework (CIRCL)
Open-source framework to crawl and analyse pastes, leaks and onion sites for leaked inform
Paste MonitoringNONEhtmlhome↗
Lyzem
Free search engine indexing public Telegram channels, groups, bots and messages.
Telegram OSINTNONEhtmlhome↗
Pastebin Dump Monitor (PSBDMP)
Paste-site leak monitoring.
PASTINTNONEjsonhome↗ api↗
PhoneBook.cz
IntelX-powered lookup listing all domains, email addresses and URLs found for a given sele
Leak AggregatorNONEhtmlhome↗
psbdmp (Paste Dump)
Searchable archive of 28M+ removed/expired Pastebin dumps by email, domain, keyword or dat
Paste MonitoringNONEresthome↗ api↗
Have I Been Pwned
Canonical breach index; breach-catalog endpoints are free/no-auth, account lookups need a
Breach SearchKEYresthome↗ api↗
Pastebin Scraping API
Primary public paste host; real-time scraping API requires paid PRO account and IP whiteli
Paste MonitoringKEYresthome↗ api↗
TGStat
Telegram channel/group analytics and search with a free API tier (post search, channel sta
Telegram OSINTKEYresthome↗ api↗

🔍 Lookup

📜 Playbook — Paste / Leak Post exploitation

  1. Direction — frame the requirement for Paste / Leak Post: what decision does this support, by when?
  2. Collection — pull the 8 mapped sources (5 free) and the native workbench; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎫 Paste / Leak Post

A paste / leak post is content published to a paste site, leak forum, ransomware blog, or Telegram channel, frequently containing credentials, source code, PII, or database dumps. It matters for early breach detection, credential-exposure monitoring, and tracking threat actors who broker or dump stolen data.

Format: Paste URL or id (e.g. pastebin.com/<8-char id>), forum thread/post id, or .onion URL; free-text body often embedding structured dumps (email:password combolists, SQL, JSON)

📡 How it is collected

  • Paste-site scraping / APIs
  • Leak-forum and marketplace monitoring
  • Telegram leak-channel ingestion
  • Tor / hidden-service crawling
  • Ransomware leak-site mirroring
  • Combolist and stealer-log feeds

🧩 Analysis &amp; hunting techniques

  • Credential extraction and parsing
  • Regex / entropy secret detection (API keys, tokens)
  • PII detection and classification
  • Actor-handle correlation across sources
  • Breach clustering and de-duplication
  • Combolist validation / stuffing-risk scoring
  • Onion-to-clearnet operator linkage

🔧 Tools

  • trufflehog
  • gitleaks
  • PSBDMP
  • Intelligence X
  • SpiderFoot
  • Recon-ng
  • Have I Been Pwned API

⚡ Workbench actions

  • Extract credentials
  • Scan for secrets
  • Screen emails against HIBP
  • Detect and redact PII
  • Attribute actor handle
  • Archive / snapshot paste
  • Hash and de-duplicate
  • Alert affected domains

📊 Dashboard KPIs

Credentials foundUnique emails exposedSecret / key hitsImpacted victim orgsPaste freshness (age)
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php