Skip to main content

Hudson Rock

Hudson Rock is a cybersecurity intelligence platform specializing in compromised computer and credential data obtained from information-stealing malware (infostealers). The platform provides access to a vast repository of stolen credentials, session tokens, cookies, browser data, and system information extracted from computers infected by various infostealer malware families including Redline, Raccoon, Vidar, Mars, and other credential-harvesting trojans.

CategoryThreat intelligence
DirectionQuery source
Sign-inNo Authentication
Query languagesSQLite
Tables5
Websitehudsonrock.com

Before you start​

Hudson Rock needs no credentials — Huntbase queries it without signing in.

Connect Hudson Rock​

  1. Go to Connections and click New connection, or click New connection on the Hudson Rock product page.
  2. On Product, pick Hudson Rock and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Hudson Rock lives:

FieldRequiredNotes
Max RetriesNo
Min Delay (seconds)No

Credentials​

The only Method is No Authentication. Enter a Credential label (for example Production), then fill in:

No fields — choose this method to connect without credentials.

Query it​

Once connected, Hudson Rock can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
SQLiteSQL over the 5 tables listed below, alongside every other connected source.

Tables​

Hudson Rock adds 5 tables. Browse their columns from Schema in the query bar's ⋯ menu.

All 5 tables
TableContains
hudsonrock_search_by_domainSearch for domain-related cyber crime and infostealer intelligence using Hudson Rock's API.
hudsonrock_search_by_emailSearch for compromised credentials and infostealer data by email using Hudson Rock's API.
hudsonrock_search_by_ipSearch for info-stealer data by IP address using Hudson Rock's API.
hudsonrock_search_by_usernameSearch for compromised credentials and infostealer data by username using Hudson Rock's API.
hudsonrock_url_by_domainList URLs identified by infostealer infections for a given domain using Hudson Rock's API.

Next steps​