
Domain exposures: breaches, infostealers, ULP heap, cookies. Counts and samples, free.
Listed on
First seen 2 Oct 2026. One server, whatever directories list it: each directory listing keeps its own page and history.
1
Directories
Collected by InvokeRank
2
Tools
From an anonymous probe
-
ToolBench grade
Not graded by Arcade
-
GitHub stars
No repository data
Tools
| Tool | Description | Behaviour |
|---|---|---|
| exposure_counts_for_domain | Credential-exposure counters for a domain. Counts only - no credential values or per-account detail. Sources: known breaches, infostealer infections, unattributed heap of ULP (Url,Login,Password) bundles, stolen cookies. All figures are INDEXATION dates, not incident dates: _month/_week mean 'newly indexed', never 'newly leaked' - the underlying leak may be years old. Windows nest (_total includes _month includes _week) - never sum them. Counters are rebuilt once daily, so figures are up to 24h old and never real-time. Repeated calls for the same input within a day return identical values - do not re-query to check for changes. Accepts a bare domain or a full URL; scheme, path, port, case and a leading www. are stripped and subdomains collapse to the registrable domain (multi-tenant hosting suffixes such as github.io are not collapsed). An IDN must already be in punycode (xn--) form. Invalid input (not a domain, an IP address) returns an error. If the domain is not in the index at all, every counter and both dates are null: that means NO DATA, not that the domain is clean - never report it as 'no exposure'. first_indexed_at and last_indexed_at give the date range of the domain's records; use last_indexed_at as the 'last updated' date for the domain. Free, no auth. | Read-only |
| exposure_samples_for_domain | A small RANDOM sample of individual exposure records for a domain - metadata only, capped in number: up to 20 records per type (stealers_users, stealers_staff, heap_users, heap_staff, breaches). Cookies are not sampled - see cookies_* in exposure_counts_for_domain. The sample is neither the newest nor the largest nor the most severe records, and it can differ between calls; identical-looking records can repeat and because of different logins/passwords. Each record says WHICH url was affected, WHICH domain the captured login belonged to, from WHICH source type, roughly when the incident was, and when the record was indexed. It carries NO credentials: no password, no username, and the login's local part is redacted. Use exposure_counts_for_domain first for the scale of the problem and for freshness (last_indexed_at); use this only when the user asks to see concrete examples. Calling again returns another random subset, never the full set - do not call it repeatedly to collect more records. | Read-only |
| Directory | Listing | Tier | First seen |
|---|---|---|---|
| Official MCP Registry | AlertsBar | - | 2 Oct 2026 |