> For the complete documentation index, see [llms.txt](https://knowledge.whiteintel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://knowledge.whiteintel.io/basics/markdown.md).

# Combolist Logs

Combo lists, a.k.a ULPs, are compilations of URL, username, and password information shared on dark web related resources. Due to the nature of these files, they do not include any additional information such as the date of the breach or details about the compromised device. They are simply lists of credentials in URL:USERNAME:PASSWORD format.

The following image contains part of a combo list detected on dark web related resources.

<figure><img src="/files/qo4cpKQz5TFE2xl8OLSY" alt=""><figcaption></figcaption></figure>

### Difference Between Information Stealer Logs and Combo lists

Information stealer logs include additional data such as IP addresses, host-names, usernames, operating systems, malware paths, files, the date of compromise, and saved credentials from the browsers. In contrast, combo lists are merely lists of credentials without any supplementary information, making them less reliable compared to comprehensive information stealer logs.

### Whiteintel Approach

Whiteintel offers a filter differentiate between information stealer logs and combo lists.

<figure><img src="/files/jMDHItgcaGV1ZHsY690g" alt=""><figcaption></figcaption></figure>
