Credential databases from historical breaches are not just an account takeover risk. Attackers use them as attack planning intelligence: which email domains are in use, which internal tools have employee accounts in leaked databases (implying the tool is internet-accessible), and which service accounts appear across multiple breach datasets (implying password reuse that enables authenticated API abuse). DDactic's Stage 4 assessment surfaces this intelligence so you can see what attackers see before they act on it.
The Stage 4 output does not report raw credential counts. It reports the attack surface implications of what is exposed: which endpoints become higher-risk given the credential exposure, which services should have their authentication hardened as a priority, and whether any leaked data suggests internal infrastructure is accessible from the internet.
What Stage 4 Queries
Stage 4 queries Have I Been Pwned (HIBP) for domain-level breach counts, DeHashed for domain-scoped credential exposure counts (without returning plaintext credentials), and LeakIX for service-level exposure indicators correlated with the organization's IP ranges and domain set. The stage does not attempt credential validation or any form of unauthorized access. It queries public breach intelligence APIs to understand exposure scope.
How Breach Data Becomes Attack Intelligence
An attacker with access to breach data targeting your organization follows a specific process. First, they identify all email addresses in the breach database matching your domain. Second, they look for patterns: internal tool domains (jira.company.com, gitlab.company.com, confluence.company.com) that suggest those services are internet-accessible. Third, they test whether leaked passwords work against your authentication endpoints, particularly OAuth SSO and legacy LDAP systems that pre-date modern password policies. Fourth, they use the breach data to identify employees with access to high-value systems and target those accounts specifically.
Stage 4 Findings and Their Remediation
Stage 4 findings fall into three categories. First: domain exposure count. Organizations with more than 500 employee credentials in public breach databases have a material credential stuffing risk and should implement phishing-resistant MFA across all internet-exposed authentication surfaces. Second: internal tool exposure. If breach data includes credentials for services on subdomains that DDactic found to be live and accessible, those services become high-priority hardening targets regardless of their current traffic or security posture. Third: service account patterns. Repeated appearance of service account email addresses (deploy@, ci@, monitoring@) in breach data suggests those accounts may be used for automated system access that is vulnerable to credential replay.
What Stage 4 Does Not Do
Stage 4 does not return individual credentials, plaintext passwords, or hashed passwords. It does not perform any form of credential validation or authentication attempt. It does not access non-public breach data. Every data source queried is a publicly available breach intelligence service that organizations are permitted to query for their own domains. The output is a risk assessment, not a credential list.
Using Stage 4 Output
The Stage 4 output feeds directly into the Stage 5 active reconnaissance: endpoints that appear high-risk given the credential exposure receive additional probing to verify whether their authentication hardening is adequate. An organization with 2,000 exposed employee credentials and an authentication endpoint with no rate limiting gets a critical finding combining both signals. An organization with the same credential exposure but strict auth rate limiting and phishing-resistant MFA gets a medium finding with no immediate action required.
See Your Breach Exposure
DDactic's Stage 4 assessment shows what breach data reveals about your attack surface -- without handling credentials.
Run a Free Scan