Disciplines

💥 Breach Intelligence (BREACHINT)

Exposed Credentials and Compromised Data
Cyber & Threat

Sources

0
0 no-auth

Mission domains

0
reach

Data points

0
covered

Related INT

0
disciplines

🔍 Lookup

📜 Playbook — Breach Intelligence collection

  1. Direction — frame the requirement for Breach Intelligence: what decision does this support, by when?
  2. Collection — collect from the 0 mapped sources (0 free) — filter the catalog by BREACHINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Mission

Breach Intelligence collects and analyzes leaked credentials, exposed databases, combolists, and infostealer logs to measure an organization's credential exposure. It answers which accounts and emails are compromised, whether plaintext or crackable passwords are circulating, and which employees or customers are infected by stealer malware.

📡 Collection methods

  • Ingesting and parsing breach dumps and combolists into normalized credential records
  • Parsing infostealer logs (RedLine, Raccoon, Lumma) for cookies, autofill, and corporate credentials
  • Querying breach-notification APIs by email, domain, and username
  • Scraping paste sites and public gists for freshly dumped credential blobs
  • Cross-referencing exposed hashes against wordlists and cracking dictionaries to assess plaintext risk
  • Monitoring dark-market and Telegram listings that advertise fresh logs and databases

🔧 Tools & frameworks

  • h8mail
  • WhatBreach
  • breach-parse
  • hashcat
  • Maltego
  • SpiderFoot
  • pwndb
  • CyberChef

📜 Breach Intelligence Tradecraft

  1. Collect breach records, stealer logs, and combolists keyed by the organization's email domains and known usernames
  2. Deduplicate and normalize entries into (identity, secret, source, first-seen) tuples and classify hash types
  3. Assess severity by distinguishing plaintext vs hashed secrets, corporate vs personal accounts, and password reuse across sources
  4. Attribute leaks to a specific breach event or a live stealer infection using artifact metadata and log structure
  5. Disseminate targeted exposure notices to affected account owners and the SOC with the source and freshness of each finding
  6. Trigger forced password resets, session revocation, and MFA enforcement, then verify the credential no longer appears in new drops

📊 Dashboard KPIs

Compromised accountsPlaintext credentialsStealer infectionsPassword-reuse rateNew breaches ingested
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php