> For the complete documentation index, see [llms.txt](https://knowledge.whiteintel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://knowledge.whiteintel.io/search-and-investigation/global-search.md).

# Global Search

Global Search queries the Whiteintel corpus directly for a specific identity, asset, or indicator and returns matching records. It is the fastest way to investigate a single value without configuring continuous monitoring.

**Availability:** All plans. Certain search types and result detail are tier-gated, as noted below.

<figure><img src="/files/biOcNHQxBsfR363be4XV" alt=""><figcaption></figcaption></figure>

### Running a search

1. Select a **search type** that matches the value you are looking up.
2. Enter the value in the search bar and run the search.
3. Review the results in the table on desktop, or as stacked cards on mobile.

The search type and query are reflected in the page URL, so a search can be bookmarked, shared, or reopened in a new tab with the same parameters.

### Search types

* **Consumer records** — leaked accounts associated with a domain where the account holder is an external consumer (for example, a personal email used on the site).
* **Corporate records** — leaked accounts where the username belongs to the searched domain itself.
* **Email address** — records tied to a specific mailbox.
* **IP address** — records observed in connection with an address. Requires a Threat Intelligence tier.
* **Computer name** — records tied to a device hostname. Requires a Threat Intelligence tier.
* **Country** — records filtered by country. Country values use the ISO two-letter code.
* **Password** — lookups by password. Password queries require a minimum length.
* **APK package** — records tied to a mobile application package.
* **Attack surface** — exposed assets and services associated with a domain.

<figure><img src="/files/yCQ2X7WoUhVCOBa5brlj" alt=""><figcaption></figcaption></figure>

### Filters

The Filters panel refines the active result set without starting a new query. Common filters include:

* **Subdomain** and **Domain** scoping.
* **Date range** or a specific event date.
* **Log type**, where applicable: stealer, combolist, or database.

On all viewport sizes the Filters panel opens as an overlay so it does not reflow the results behind it.

<figure><img src="/files/9CGVmy8eGYjMSOWQON3z" alt=""><figcaption></figcaption></figure>

### Results

Each result row summarizes the leaked account, the application or URL it was captured on, the record class, the source type, and when it was last seen. Selecting a row opens the detail view; see Viewing logs and record detail.

On mobile, results render as cards that present the same fields in a stacked layout.

### Saved and recent searches

Frequently used queries can be saved for reuse, and recent searches are retained so you can return to them quickly.
