Documentation
Everything you need to know about Knox Security
A practical, plain-English guide to finding exposed credentials, investigating compromised machines, and protecting your organization from breach data.
What is Knox Security?
Knox Security is a breach and leak intelligence platform built for security teams, incident responders, and organizations that need to know when their data — or their people — appear in compromised data from infostealer malware, public breaches, and leak sources.
Compromised machine records indexed
Login and password pairs searchable
Intelligence feeds monitored continuously
Who uses Knox Security?
Security Operations Centers
Monitor employee and executive exposure across breach data, get alerts when new leaks appear.
Incident Response Teams
Quickly assess what was stolen — credentials, cookies, sessions — and which machines were infected.
Threat Intelligence Analysts
Pivot from a single email to related identities, wallets, infrastructure, and threat actor profiles.
Compliance & Risk Teams
Generate exposure reports for audits, prove due diligence, and track remediation over time.
Authorized use only
Getting Started
You can start using Knox Security in under two minutes — no installation or setup required. Everything runs in your browser.
Create an account
Go to the registration pageand sign up with your work email. You'll get 50 free Exposure Checks per month — no credit card needed.
Run your first Exposure Check
Visit Exposure Checkand enter any email address. You'll see a verdict (Exposed or Clear), which sources mention it, and a severity score — all within seconds.
Upgrade for full search (optional)
To see actual credentials, passwords, infected machine details, and use advanced search, upgrade to a paid plan. Starter begins at $150/month.
Set up monitoring
Once on a paid plan, add the emails, domains, and usernames you want to watch. Knox Security will alert you automatically when new exposures appear.
Tip: Start with your own email
Credential Search
The Credential Search is the core of Knox Security. It lets you search across billions of leaked login and password records to find exposures for any email, username, domain, or website.
What you can search by
Email address
Enter any email (e.g. [email protected]) to find every login and password tied to it across all sources.
Username
Search by a username (e.g. jsmith) to find accounts across different websites that use the same handle.
Domain
Enter a domain (e.g. company.com) to find every leaked credential for any website on that domain.
Website URL
Search by a specific website (e.g. linkedin.com) to find all credentials leaked for that site.
Search tabs explained
Login Dumps
The largest source on the platform. Contains URL + username + password combinations collected from public breaches and leak compilations. When you search an email here, you see the website, the username, and (on paid plans) the plaintext password.
API Credentials (NAZ)
A specialized index of API keys, tokens, and application credentials that have been leaked in source code, config files, or breach data. Useful for finding exposed cloud keys, database connection strings, and third-party API tokens.
Compromised Machines
Records from computers infected by infostealer malware. Each record shows the victim's machine, the stolen credentials grouped by browser and profile, and the malware family responsible. This is the most actionable data for incident response.
Cookies
Session cookies stolen by malware. These can be used to bypass two-factor authentication and log into accounts without a password. Useful for understanding the full scope of a compromise.
Autofills
Browser autofill data — names, addresses, phone numbers, credit card numbers — that malware extracted from the victim's browser. Reveals personal and financial data beyond just logins.
Sessions
Active session tokens from browsers and apps. These represent logged-in sessions that were active at the time of infection and could allow an attacker to impersonate the victim without needing credentials.
What do I see on each plan?
Free: Verdict only (Exposed/Clear) + source categories. No passwords or details.
Starter: Full results with passwords, IPs, and export. Database + ULP sources.
Professional: Higher volume (10,000 searches/month) with export tooling.
Enterprise: All sources, Deep Search, domain reports, monitoring, and unlimited searches.
Compromised Machines
When malware infects a computer, it steals everything the browser has saved: logins, passwords, cookies, autofill data, crypto wallets, and active sessions. Knox Security indexes all of this so you can investigate the full scope of a compromise.
What each record contains
- Machine identifier and country (derived from the malware log filename)
- Hostname and operating system of the infected computer
- IP address at the time of infection
- Every stolen credential grouped by browser and profile
- Session cookies that could bypass two-factor authentication
- Browser autofill data (names, addresses, phone numbers, card numbers)
- Crypto wallet files detected on the machine
- The malware family responsible (RedLine, Raccoon, Vidar, etc.)
How to use this data
Incident Response
If an employee's machine appears here, treat it as a confirmed compromise. Reset all credentials found in the log, invalidate active sessions, and investigate whether the malware spread to other systems.
Executive Protection
Search for executives, board members, and high-risk employees. A compromised executive machine can lead to business email compromise, fraud, and data exfiltration.
Supply Chain Risk
Search for contractors, vendors, and partners who have access to your systems. Their compromised credentials can be used to breach your network.
Threat Hunting
Pivot from a compromised machine to related identities, wallets, and infrastructure. Identify patterns across multiple infections to map attacker campaigns.
Important
Exposure Check
Exposure Check is the free, fast way to see if an email address appears in any of our data sources. It gives you a verdict and severity score without revealing actual passwords or sensitive details.
What you get for free
- Exposed or Clear verdict across all sources
- Severity score (Critical, High, Medium, Low, None)
- Which source categories mention the email
- 50 checks per month, no credit card required
What requires a paid plan
- Actual passwords and credentials
- IP addresses and machine details
- Full result counts and evidence samples
- Export to CSV and report generation
Best practice for organizations
Data Sources
Knox Security aggregates and indexes data from multiple categories of sources. Here's what each one is and why it matters.
Infostealer Logs
Data stolen by malware like RedLine, Raccoon, Vidar, LummaC2, and others. When these trojans infect a computer, they grab saved passwords, cookies, autofill data, and crypto wallets, then send it back to the attacker. We index these logs so defenders can see what was stolen and act on it.
Public Breach Databases
Credential dumps from publicly known breaches (like the kind that appear on leak sites and forums). These contain email + password pairs that can be used for credential stuffing attacks.
ULP (URL/Login/Password) Compilations
Large collections of URL + username + password combinations assembled from multiple breach sources. These are the most common format for leaked credentials and represent the bulk of our searchable data.
Dark Web & Telegram Monitoring
We continuously monitor dark web forums, Telegram channels, and paste sites for new leak announcements, data sales, and threat actor activity. This gives early warning of new breaches before they hit mainstream news.
Threat Intelligence Feeds
Live feeds from CISA, Feodo Tracker, URLhaus, OpenPhish, and other public security organizations. These provide indicators of compromise (malicious IPs, domains, URLs, and file hashes) that you can use for threat hunting and blocking.
Vulnerability Intelligence
CVE data from the National Vulnerability Database and CISA's Known Exploited Vulnerabilities catalog. Helps you prioritize patching based on what's actually being exploited in the wild.
Where does the data come from?
Intelligence Tools
Beyond credential search, Knox Security includes a suite of tools for deeper investigation and broader threat awareness.
Domain Intelligence
Look up any domain to see DNS records, SSL certificate history, subdomains, WHOIS registration, and lookalike domains that could be used for phishing. Set up monitoring to get alerted when new subdomains appear.
Crypto Wallet Analysis
Enter a Bitcoin, Ethereum, TRON, or Monero wallet address to see its balance, transaction history, and counterparties. Check against OFAC sanctions lists for compliance screening.
Threat Actor Profiles
Browse profiles of known threat actors, including their aliases, Telegram channels, associated wallets, and categories of activity (credentials, access, data sales, services).
Ransomware Tracker
Real-time view of ransomware group activity, including victim announcements, attack dates, and group statistics. Filter by group, country, or time period.
CVE Explorer
Browse known vulnerabilities with severity scores, exploitability ratings, and patch status. Includes CISA's Known Exploited Vulnerabilities catalog so you can prioritize what to fix first.
Cyber News Feed
Real-time security news and advisories from CISA, BleepingComputer, Krebs on Security, and other top sources. Updated every 10 minutes.
Database OSINT
Search public records databases by phone, email, username, or Telegram ID. Currently covers India and USA databases, with more countries being added.
Data Statistics
See the real-time scale of our indexed data — how many records, which sources, and ingestion activity over time. Useful for understanding coverage before committing to a search.
VAPT Scanner
Run vulnerability assessment and penetration tests against your own external assets. Includes a scan wizard, findings triage by severity, and evidence export for reporting.
Dark Web Search
Search across dark web forums, Telegram channels, and onion sites for mentions of your organization, brand, or keywords. Available on Enterprise and above.
Monitoring & Alerts
Instead of searching manually every day, set up monitoring once and let Knox Security watch for new exposures automatically. When new data matching your criteria appears, you get an alert.
What you can monitor
- Email addresses (your employees, executives, contractors)
- Domains (your company domain, lookalike domains)
- Usernames (handles used by your team)
- IP addresses (your external infrastructure)
- Phone numbers
- Keywords (company name, product names, internal codenames)
- Crypto wallet addresses
- Specific websites or services
How alerts work
Alert delivery
Alerts appear in your dashboard inbox and can be delivered via email or Discord webhook. You can configure which severity levels trigger alerts and set quiet hours.
Correlation detection
When multiple monitored items appear in the same breach or malware log, Knox Security flags it as a correlated event. This helps you spot coordinated attacks or widespread compromises affecting multiple employees at once.
Website change monitoring (WatchWeb)
Monitor any URL for changes. Useful for tracking attacker infrastructure, leak sites, or your own web properties for unauthorized modifications.
Which plans include monitoring?
Plans & Access
Knox Security offers plans for individual researchers up to large security teams. Here's what each tier includes in plain terms.
Free — $0
For anyone who wants to check if they've been breached. 50 Exposure Checks per month. You get a verdict and severity score but no actual passwords or detailed data.
Starter — $150/month or $1,500/year
For individual researchers and small teams. 1,000 searches per month with full credential visibility (passwords, IPs), 200 results per search, and CSV export. Covers database and ULP sources.
Professional — $1,000/month or $10,000/year
For teams doing higher-volume investigations. 10,000 searches per month, 500 results per search, and export tooling. Same data scope as Starter but with much higher quotas.
Enterprise — Custom pricing
For security operations centers and large organizations. Unlimited searches, all data sources (including dark web and stealer logs), Deep Search mode, domain intelligence reports, continuous monitoring, and priority support.
API Access — Custom pricing
For teams that want to integrate Knox Security data into their own tools, SIEM, or automation. Includes everything in Enterprise plus REST API keys, full documentation, and higher rate limits.
Not sure which plan you need?
Security & Compliance
We take the security of your Knox Security account and the responsible handling of breach data seriously. Here's what we do.
Account security
- Two-factor authentication (TOTP and passkeys)
- Login activity audit trail
- Session management and remote sign-out
- Password requirements enforced
Audit logging
- Every search is logged with user, timestamp, and query
- Admins can view organization-wide search history
- Export logs for compliance and internal review
- Search logs retained per your data retention policy
Data handling
- Breach data is indexed for search but not redistributed
- Passwords are only visible to authorized, paid users
- Free tier sees verdicts only — no sensitive data exposure
- All access requires authentication and authorization
Acceptable use
- Defensive security, law enforcement, and authorized research only
- No harassment, doxxing, or unauthorized access
- No bulk redistribution of breach data
- Violations result in account termination
Compliance certifications
Legal & Regulatory Compliance
Knox Security is designed to operate lawfully in every jurisdiction where our users are based. Below is a detailed explanation of how we comply with the data protection, cybercrime, and privacy laws of major countries. This is not legal advice — it is a transparency statement about our legal position and compliance posture.
Our core legal principles
What we do
- Aggregate data that is already publicly available from breach dumps and threat actor releases
- Make that data searchable for authorized defenders to find and fix exposures
- Provide data subject rights (access, deletion, correction) in every jurisdiction
- Log every search and enforce acceptable use policies
- Support organizations in meeting their breach notification obligations
What we do NOT do
- Access, hack, or penetrate any computer system or network
- Commission, purchase, or facilitate the theft of any data
- Intercept communications or conduct surveillance
- Sell personal data to third parties
- Allow use of the platform for harassment, doxxing, or illegal purposes
Knox Security operates in compliance with the Budapest Convention on Cybercrime, the international treaty ratified by 70+ countries. Article 6(2) explicitly exempts authorized testing and protection of computer systems from criminal liability — which is exactly what Knox Security does.
Budapest Convention on Cybercrime (2001)
Article 6(2) states that criminal liability does not apply when tools or data are used for 'the authorised testing or protection of a computer system.' Knox Security aggregates already-public breach data for defensive security purposes, falling under this exemption. We do not create, commission, or facilitate cyberattacks.
Council of Europe Convention 185
The Explanatory Report (paragraph 72) clarifies that 'distribution' and 'making available' criminalize the active forwarding of tools designed to commit offenses. Knox Security does not distribute attack tools — we index breach data that is already publicly available for defensive use.
UN Cybercrime Convention (2024)
The newly adopted UN Cybercrime Convention, like the Budapest Convention, includes exemptions for legitimate security research and defensive cybersecurity activities. Knox Security's model — aggregating public breach data for authorized defenders — aligns with these exemptions.
The key legal distinction
How we help you comply with the law
Your data subject rights — in every country
Regardless of where you live, Knox Security honors the following rights for your personal data stored in our platform (your account data — not breach data, which is already public):
- Right to know what personal data we hold about you
- Right to access a copy of your personal data
- Right to correct inaccurate personal data
- Right to delete your account and personal data
- Right to restrict processing of your data
- Right to data portability (export your data)
- Right to object to processing
- Right to withdraw consent at any time
Law enforcement and government requests
Important disclaimer
Related legal documents
Frequently Asked Questions
Common questions about Knox Security, answered in plain English.
Still have questions?
Our team is happy to help. Reach out and we'll get back to you within one business day.