For the complete documentation index, see llms.txt. This page is also available as Markdown.

Endpoints

The Endpoints tab of the Dashboard lists infected corporate machines that carry at least one corporate credential record for the selected domain or watchlist group. It is the device-centric counterpart to the Credentials view.

Availability: All plans for viewing. CSV export requires an organization account and, per platform policy, an Enterprise or Threat Intelligence subscription.

Reading the table

Each row represents one infected machine and shows:

  • the source domain (in group views),

  • the hostname,

  • the IP address,

  • the operating system, with a brand icon,

  • the country, with a flag,

  • the count of corporate credential records on the machine,

  • and the date it was last seen.

A trailing action opens the endpoint detail. On mobile, machines render as cards that present the same fields stacked.

Sorting

A Sort by control orders the list by last seen or by latest added. In group views, restricted domains are skipped and reported as a count.

Endpoint detail

Selecting an endpoint opens a detail sidebar scoped to that machine, presenting:

  • a description of the infection,

  • a metadata grid for the device, and

  • the exposed corporate credentials, with passwords masked by default and revealable, plus remediation guidance.

The detail sidebar also offers a client-side export of the metadata and the credentials currently loaded on the sidebar, for quick capture of a single machine.

Exporting

The Export button opens a slide-over that exports the full endpoint set server-side as a CSV file, billed against your organization's export credits. In group views you can scope the export to all domains or to a single member. See CSV exports and export credits.

Last updated