Skip to main content

Infected devices

Devices are the infected machines whose infostealer logs captured your identities. The device page is the heart of the pivot model: it connects one physical machine to every credential it leaked and every victim it affected.

Finding a device​

  • From an identity's risk posture, where each infostealer infection links to its device.
  • From an exposure row, in the record page's Infected device section.
  • By infection id. Paste the 32-character id into Investigate or the Devices search.

The device dossier​

The dossier comes first. It holds everything the feed's device index has for the machine:

  • device user and serial,
  • country, IP, language, timezone,
  • antivirus and screen,
  • last login, and when the machine was first registered in the feed,
  • the feed's own correlation ids, to quote when you ask the feed's operators about the machine,
  • the browsers the malware pulled credentials from.

When the feed has them, two more blocks follow:

  • Malware: the malware family, the executable path it ran from, its permissions, and whether it ran as admin. The path is a file you can look for elsewhere: hunt for it across your fleet with Wazuh file integrity monitoring.
  • Machine: the operating system, hardware specs, keyboard layout, and the city and ZIP the machine was in.

The feed's coverage of these fields is sparse, so a field it did not send is not shown at all. On the Free plan, and until your domain is verified, the city and ZIP are masked, the same way the IP is.

Below the dossier:

  • Every credential the machine leaked, each one pivoting to the victim identity and to the service it was for.
  • The victims list, which of your identities this machine affected.

The fastest incident answer it supports is one machine, all of its stolen credentials, all of its victims. The reset list writes itself.

The dossier usually arrives within a second, while the machine's credentials can take several seconds to come back from the feed, so the page shows each part as soon as it has it. Until the full list arrives, the credentials of this machine that are already in your loaded exposures show under a Partial label, and the counts above them read so far. You don't need to reload: the full list replaces them when it comes in.

Infection — metadata only is not an error​

The reputation feed serves infections from separate indices with independent coverage, so an infection reported by an identity's risk profile can have no stealer log and no device dossier in the searchable corpus. The page then shows what the feed does report, which is the infection and detection dates and the infostealer id, and links back to the identity.

Likewise, a device with captured credentials but no machine fingerprint says so in place of the dossier. Feeds are ingested continuously, so an infection can gain its stealer log later. Check back.

Umbra keeps empty and unknown apart: a lookup that failed or timed out is shown as not checked yet, never as "nothing here". And when Umbra cannot reach its exposure data source because of a problem on our side, the device says Exposure data is temporarily unavailable instead of metadata only or no machine fingerprint, and so does a service opened from that machine.