Have I Been Pwned
- 14 Apr 2024
- 1 Minute to read
- Print
- DarkLight
- PDF
Have I Been Pwned
- Updated on 14 Apr 2024
- 1 Minute to read
- Print
- DarkLight
- PDF
Article summary
Did you find this summary helpful?
Thank you for your feedback
Have I Been Pwned is a website to check whether email accounts have been compromised in a data breach.
The Enrich User Data by Have I Been Pwned (HIBP) adapter uses the HIBP API to provide information on breaches, pastes and pwned password identified by the 'Have I Been Pwned' (HIBP) website for a given email account.
Note:
For details on the breaches, pastes and pwned password identified by 'Have I Been Pwned' (HIBP) API, see HIBP API.
Types of Assets Fetched
This adapter fetches the following types of assets:
- Users
Parameters
- Have I Been Pwned Domain - Specify the Have I Been Pwned (HIBP) domain or use the default configured HIBP public domain. This allows you to use the domain of a proxy instead of connecting directly to the server using the default domain of https://haveibeenpwned.com.
- API Key - Use the API key you purchased from 'Have I Been Pwned'.
- Account Domain (optional) - Specify the account domain.Note:
When Account Email is not supplied, Account Domain is required.
- Account Email (optional) - Specify a specific email account (e.g. axonius@axonius.com).Note:
When Account Domain is not supplied, Account Email is required.
To run the HIBP query against multiple Account Emails, you must use the Enrich User Data with Have I Been Pwned Enforcement Center action. - Verify SSL - Choose whether to verify the SSL certificate of the server against the CA database inside of Axonius. For more details, see SSL Trust & CA Settings.
- HTTPS Proxy (optional) - Connect the adapter to a proxy instead of directly connecting it to the domain.
- Rate Limit (requests per minute) (optional, default: 10) - Use this field to handle rate limit issues by HIBP documentation. It is possible to buy an account with a better rate limit.
Was this article helpful?