Cybercrime investigation platform

DeXpose cybercrime investigation platform: Unmask the operator. Map their network.

DeXpose pivots through stealer logs, breaches, hacking forums, onion sites, Telegram and more than 800 OSINT sources, with an AI agent that proposes the next move, until the operator's devices, accounts and associates sit on a single graph, every node with its source and date.

Start from a Telegram handle

Offered to law enforcement, government agencies, qualified organisations and vetted cybercrime investigators.

Investigations workspace

Every pivot becomes a node. The agent finds the next one.

Emails, phones, usernames, passwords, device IDs, Telegram IDs, names and images become nodes, each edge coloured by how the link was made. The investigator drives the case; the agent proposes, runs and summarises, and nothing it adds counts until it has been reviewed.

A section of a live investigation graph: typed nodes for emails, phones, usernames, passwords and devices linked by colour-coded edges, personal values blurred
AI agent

Proposes the next pivot, with the evidence.

Reads the graph and suggests the moves most likely to connect an alias to a person, a device or a channel. You choose what to run.

Autopilot mode

Runs the expansions end to end.

Give it one identifier and the correlations and cross-source lookups execute in sequence while the graph fills in. Every addition is listed for review before it counts.

Pivot

From any node to everything it touches.

Emails and phones, usernames and names, passwords and devices, Telegram IDs and groups, images.

Timeline, groups and isolate

Order what happened. Keep leads apart.

Every node and edge in sequence, separate lines of inquiry in groups, and the canvas stripped to the part you are working on.

Export and import

The graph leaves with its evidence.

Graph export with the source and date of every node, device log export, CSV credentials, and import of existing material.

AI analysis

One click summarises a device log.

What the stealer took, which credentials still matter and which identities share the infection, ready for the case file.

Infostealer intelligence

From a jurisdiction to a machine to a person.

Compromised devices are searchable by country, category, infrastructure and credential. Open one and you get the machine, the infection, every artefact the stealer took and the identities it links to.

Device search filtered by country with the device category list: government devices, corporate devices, military devices, extremist content, hacking forums, cryptocurrency platforms, privacy tools and online gambling
01
Find infected devicesMore than thirteen thousand machines in this view, filtered by country, then by category: government and military devices, corporate fleets, hacking forums, cryptocurrency platforms, privacy tools, extremist content and more. Narrow by stealer family, compromise date range, ASN number or name.
One compromised machine in DeXpose: 82 credentials across 70 services, 9 emails, 24 usernames, 5 phones, 38 percent password reuse and strength, the device and infection details, top services, identities and passwords, the stealer's info file, exfiltrated files and identity correlations. Personal values are blurred
02
Open one deviceCountry, OS, IP, hostname, user and antivirus, the stealer family, the compromise date and the path it ran from. Then 82 credentials across 70 services, identities, passwords with reuse and strength, cookies, autofill, history and the raw info file. AI analysis summarises it in one click; export hands it to the case file.
Identity correlations for one device: 37 linked identities, shared password 19 times, same infection 485 times, rated high; below it the credentials table with identity, service, password and flags such as too short, no special characters, year pattern, sequential and PII-derived. Personal values are blurred
03
Correlate identitiesThe emails, phones and usernames found on the same infected device and sharing passwords across services are clustered: here 37 identities, 19 shared passwords, 485 same-infection matches, rated high. Below, every credential with its service, password and weakness flags, filterable and exportable as CSV.
Query by field
device.countrydevice_categorydevice.ipdevice.hostnamedevice.hostname.rawhostshosts.rawhostslistemaildomainsemaildomains_listautofill.valuescookies.hostscookies.hostslisthistory.hostsstealer.familyasn.numberasn.namedate.compromise.fromdate.compromise.toand moredevice.countrydevice_categorydevice.ipdevice.hostnamedevice.hostname.rawhostshosts.rawhostslistemaildomainsemaildomains_listautofill.valuescookies.hostscookies.hostslisthistory.hostsstealer.familyasn.numberasn.namedate.compromise.fromdate.compromise.toand more
More modules

Search everything. Resolve anyone. Watch where the trade happens.

Three more modules share the same corpus and the same graph. Every result they return can become a node in the workspace.

Deep identity scan: map the digital footprint from a phone number, an email address or a username, with an optional OSINT scan
Identity intelligence

A phone, an email or a username. The person behind it.

Deep identity scan resolves one identifier into the accounts, platforms, locations and linked contacts behind it, drawing on more than 800 OSINT sources alongside the DeXpose corpus. Sensitive values stay masked until you open them.

800+OSINT sources behind every deep identity scan, on top of stealer logs, breaches, forums, onion sites and Telegram.
Telegram intelligence

Where the trade happens now. And who is behind the handle.

Stealer logs, combo lists and access are sold in Telegram channels before they ever reach a forum. DeXpose indexes messages, channels and groups so an investigator can search them by keyword, username or ID, profile a channel and its members, and de-anonymise the users behind a handle: the phones, emails, usernames and devices that connect a Telegram account to a person or a threat actor.

Millionsof channels and groups monitored
Billionsof messages indexed and searchable
  • Messages and channels, searchableKeyword, username or Telegram ID across indexed channels and groups, with member counts and activity.
  • De-anonymise Telegram usersResolve a handle or ID to the phones, emails, usernames and infected devices behind it.
  • Threat actors and their infrastructureFollow an alias from a channel to the developer, the operator and the infrastructure they run.

The platform ships with further modules, from intel feeds to infrastructure and brand monitoring, and new ones are added as investigations demand them. Ask about the full module list

31BPublic Breachesrecords
58MCompromised Machinesdevices
2.2BInfostealer Recordsrecords
4.8BULPs & Combo Listsrecords
2BDarkweb Entriesentries
52KASNsnetworks
31BPublic Breachesrecords
58MCompromised Machinesdevices
2.2BInfostealer Recordsrecords
4.8BULPs & Combo Listsrecords
2BDarkweb Entriesentries
52KASNsnetworks
How an investigation runs

Search, pivot, build, report.

Four stages, one workspace. Every record you touch carries its source and collection date from the first query to the exported case file.

  1. Global search

    Search

    Enter an email, domain, IP, phone or username. One query returns matches from every source, grouped by where they were found.

  2. Infostealer and identity

    Pivot

    Open the compromised device, the identity or the Telegram channel behind a match, and follow the correlations it exposes.

  3. Investigations workspace

    Build

    Send findings to the workspace as nodes, order them on the timeline, group leads, and let the AI agent propose the next moves or run them on autopilot.

  4. Export

    Report

    Export the graph and the device logs with the source and date of each record, ready for the case file.

Access

Built for authorised investigations.

The platform is offered to law enforcement agencies and qualified organisations with a lawful mandate to investigate, and to individual cybercrime investigators through beta access. Access is reviewed, usage is metered, and every record keeps its provenance.

Request access
Who it is for
Law enforcement agencies, government bodies and qualified organisations such as national CERTs, regulators and vetted investigative firms, as well as individual investigators and researchers who work cybercrime cases, who can apply for beta access.
How access is granted
Every request is reviewed for professional use before an account is created. Tell us about your organisation or your practice, and a recent investigation where the platform would have helped.
How usage is metered
Searches, scans and expansions draw on a credit balance shown in the header, so the cost of an investigation is visible before you run it.
What every record carries
Its source and collection date, from the first search result to the exported graph, device log or CSV.
FAQ

Common questions.

Coverage, access and evidence, in plain terms.

Who can get access to the platform?

Law enforcement agencies, government bodies and qualified organisations with a lawful mandate to investigate, and individual investigators or researchers who work cybercrime cases, through beta access. Requests are submitted through the access form and reviewed for professional use before an account is created.

What does a global search cover?

Infostealer logs, ULP dumps, combo lists, public breaches, compromised machines, malware log files, hacking forums, intel feeds, onion sites, Telegram messages and Telegram channels. A single query returns matches from every source, grouped by where they were found.

Can I start from a single phone number or username?

Yes. Deep identity scan takes a phone number, an email address or a username and resolves it into the accounts, platforms and locations behind it, with an optional OSINT scan over more than 800 sources. Global search accepts emails, domains, IPs and usernames.

Where does the data come from?

From stealer logs and combo lists traded on dark web markets, forums and Telegram, from public breach corpora, and from onion sites and hacking forums that DeXpose indexes continuously. Each record carries its source and collection date.

Can the graph and the logs be exported?

Yes. The investigation graph exports with its evidence, each compromised device has an export for its full log, and credential tables export as CSV, so findings can be attached to the case file.

Request access to the investigation platform.

Tell us about your agency, organisation or practice and the investigations you run. We review every request and set up access for approved teams and investigators.