Skip to main content
Tutorial — Breach data analysis (defensive framing)
Skill: breach-data-analysis-specialist
Time: ~30 minutes
Goal
Use breach metadata to assess account takeover risk or corroborate a public email — not to weaponize private data.
Steps
- Define question: “Was this account in breach X?” vs “What password?” — reject the second for Patriot use.
- Use Have I Been Pwned-style APIs or org-approved tooling.
- Record breach name, date, and classes of data disclosed (e.g. hashes vs plaintext — often unknown at summary level).
- Recommend rotation and MFA in defensive reports.
- Redact all secrets in notes.
- If research touches non-public figures, obtain legal review before retention.
Pitfalls
- Paste dumps into chat tools — forbidden in most org policies.
- False negatives if email variants exist.
