# Turn an indicator into a documented investigation.

[Turn an indicator into a documented investigation.](https://leakradar.io/en/use-cases/research)

Reviewed: 2026-09-09

Search leak data by email, domain or advanced criteria. Examine the available context, save useful searches and export findings for your analysis.

Create a free account to start investigating.

## You have an indicator. You need the surrounding evidence.

A domain or email address is a starting point, not a conclusion. Different search modes help you narrow the dataset, compare relevant records and retain the material that supports your analysis.

Build an investigation you can explain and revisit.

## Search, refine, retain

### Choose a search mode

Start from an email, domain or advanced filter. Select the dataset and mode that fit the question.

### Examine the context

Review available fields and sources. Distinguish what the record shows from what still needs confirmation.

### Keep useful results

Save the search for later or export the available results into your research workflow.

## What you can work with

### Searches with a purpose

Email, domain, advanced, raw and dark web searches serve different questions and have different plan requirements.

### Repeatable analysis

Saved searches help you return to a query. Exports let you work with the available results outside the interface.

### API and Python SDK

Use authenticated API requests in your own tools, subject to the endpoint permissions and usage limits described in the documentation.

## Access that fits your work

Start with a free account, then choose the plan that fits your datasets, monitoring, exports and team.

Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.

Illustration with fictional data.

## Before you get started

### Does every record have the same context?

No. Available fields depend on the source and dataset. Missing metadata should remain an explicit gap in your analysis.

### Can I automate my research?

The API and Python SDK support programmatic use. Check the documentation for endpoints, authentication, supported filters and applicable limits.

## Follow the evidence further.

Open the member area and choose the search mode your investigation needs.

## The data behind LeakRadar

Investigate exposed accounts across stealer logs, combolists, raw leak files and dark web forums. Inspect plaintext passwords when available in the source.

645,193,048,776 lines across indexed leak files. File lines, not a count of unique accounts.

Updated: 2026-09-14T23:24:37.940Z

## Explore the source behind a match

### Stealer logs

Connect a captured login to its service URL, username and password to understand which access is exposed.

[API documentation](https://docs.leakradar.io/#tag/Search-Email)

### Combolists

Find email/password and username/password pairs, including records without a service URL.

[API documentation](https://docs.leakradar.io/#tag/Search-Combolists)

### Raw leak files

Search the text of leaked files, database dumps and unstructured records beyond normalized credential fields.

[API documentation](https://docs.leakradar.io/#tag/Raw-Search)

### Dark web forums

Search indexed forum posts for mentions of your organization and examine the discussion's source context.

[API documentation](https://docs.leakradar.io/#tag/Dark-Web-Search)

## Plaintext passwords, with their account context

Inspect the exposed password alongside the account and, for stealer logs, its service URL. When the source includes plaintext, that detail helps your team scope password resets and investigate exposed access.

Compare plans for plaintext access and included unlock points.

## Access that fits your work

Start with a free account, then choose the plan that fits your datasets, monitoring, exports and team.

Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.

## Sources and access

- [How our data is organized](https://leakradar.io/en/methodology)
- [Trust center](https://leakradar.io/en/trust)
- [Alternatives](https://leakradar.io/en/alternatives)
- [Compare plans](https://leakradar.io/en/#pricing-plans)
