Skip to main content

Infected devices

Devices are the infected machines whose infostealer logs captured your identities. The device page is the heart of the pivot model: it connects one physical machine to every credential it leaked and every victim it affected.

Finding a device

  • From an identity's risk posture — each infostealer infection links to its device.
  • From an exposure row — the detail drawer's Infected device tab.
  • By infection id — paste the 32-character id into Investigate or the Devices search.

The device dossier

The dossier comes first: everything the feed's device index holds for the machine —

  • device user and serial,
  • country, IP, language, timezone,
  • antivirus, screen, root / developer-build state,
  • last login, and when the machine was first registered in the feed,
  • the feed's own correlation ids — quote those when you ask the feed's operators about the machine,
  • the browsers the malware pulled credentials from.

Below the dossier:

  • Every credential the machine leaked — each one pivoting to the victim identity and to the service it was for.
  • The victims list — which of your identities this machine affected.

The fastest incident answer it supports: one machine, all of its stolen credentials, all of its victims — the reset list writes itself.

"Infection — metadata only" is not an error

The reputation feed serves infections from separate indices with independent coverage, so an infection reported by an identity's risk profile can have no stealer log (and no device dossier) in the searchable corpus. The page then shows what the feed does report — infection and detection dates, the infostealer id — and links back to the identity.

Likewise, a device with captured credentials but no machine fingerprint says so in place of the dossier. Feeds are ingested continuously, so an infection can gain its stealer log later — check back.

Umbra keeps empty and unknown apart: a lookup that failed or timed out is shown as not checked, never as "nothing here".