v1

latestOpenAPI 3.0.0Proprietary - Commercial Use Only2026-08-06172139621.6 KB
Findings

Get a credential management finding of a company.

There are 5+ billion hacked emails and passwords available on the internet and underground forums. This section shows the leaked or hacked emails and passwords that were discovered. This category has 9% effect on total scan score.<br/><br/> For storage optimization, the system <b>permanently</b> deletes all findings that haven't been detected by the Black Kite scanner for over a year. Findings with manually changed statuses or associated tickets are excluded.

get/api/v2/companies/{id}/findings/credentialmanagement/{findingId}

Path parameters

idinteger required

The id of the company that includes finding.

findingIdinteger required

The id of the target finding.

Response

Success

FindingIdinteger

The unique identifier of this finding.

Domainstring

The domain which this finding is related.

Severity'Info' | 'Low' | 'Medium' | 'High' | 'Critical'

The severity of a finding.

Status'Active' | 'FalsePositive' | 'Suppressed' | 'Acknowledged' | 'Deleted' | 'Remediated'

The status of this finding.

  • Active, means the finding is still active with no review as of yet.
  • FalsePositive, means the finding is considered to be false alarm.
  • Suppressed, means the finding is suppressed, similar to FalsePositive.
  • Acknowledged, means the finding is accepted, for example will not be fixed.
  • Deleted, means the finding is deleted, similar to FalsePositive.
  • Remediated, means the finding is mitigated.
EmailorUsernamestring

The username or email part of the credential pair; usually an email or a username.

Sourcestring

The source of the leak.

FindingDatestring date-time

The date that Black Kite first seen the finding.

LastCheckDatestring date-time

The date that Black Kite last checked the finding.

LeakDatestring date-time

The date that credentials are leaked or more likely published.

LeakIDnumber

The unique identifier of the data leak.

LeakNamestring

The descriptive name of the leak.

LeakInfostring

Leaked credential itself. This part is masked intentionally.

PasswordType'PLAIN' | 'HASH' | 'ENCRYPTED' | 'NULL'

The format of the leaked credential. Enum list is not complete.

ControlIdstring

The unique identifier of the control that this finding relates to.

ConfidenceLevel'Low' | 'Medium' | 'High' | 'VeryHigh' nullable

The confidence level of this finding.

UpdateDatestring date-time nullable

The date that the finding was last updated.

IsRsiFindingboolean

Indicates whether this finding contributes to the company's Ransomware Susceptibility Index (RSI) score.

Example response

{
  "FindingId": 2590965999,
  "Domain": "acmeinc.com",
  "Severity": "Medium",
  "Status": "Active",
  "EmailorUsername": "john.doe@acmeinc.com",
  "Source": "PASTEBIN LEAKS",
  "FindingDate": "2021-08-09T08:30:30.682Z",
  "LastCheckDate": "2021-08-09T08:30:30.682Z",
  "LeakDate": "2021-08-09T08:30:30.682Z",
  "LeakName": "COMBOLIST 767",
  "LeakInfo": "****",
  "PasswordType": "HASH",
  "ControlId": "FRADOM-001",
  "Ticket": {
    "Status": "Assigned",
    "Owner": "John Doe"
  },
  "ConfidenceLevel": "High",
  "UpdateDate": "2021-08-09T08:30:30.682Z",
  "IsRsiFinding": true
}