Incident Investigation
Link suspicious account activity to external breach data during incident response.
Email breaches · 1 credit per lookup · no monthly fee
How it works
One call, structured answer
Incident Investigation runs on the email breaches lookup at 1 credit per lookup. Same API key, same JSON shape as every other Encrata lookup.
- Full breach history, names, dates and exposed data classes per breach
- 1 credit per check, so continuous monitoring stays affordable
- New-breach detection turns a public leak into a same-day security response
- Works for one address or your whole domain
Breach history in triage
Add the breach check to your triage runbook: for every account in an incident, pull breach history and note whether exposed credentials predate the suspicious activity. The timeline correlation, breach public on Monday, anomalous logins Wednesday, distinguishes credential stuffing from insider threats and targeted compromise in minutes.
Faster, surer classification
The classification speed matters because responses diverge: stuffing gets resets and rate limits; a compromise with no external breach trail gets forensics. Attach the breach evidence to the incident record, post-incident reviews and cyber-insurance claims both benefit from a documented 'how the credentials leaked' chain.