Report an Incident Become a Partner Careers Contact
Book a Demo
Detection & response · dark web monitoring

Stolen today,
not in a 2019 breach list.

Most dark web monitoring tells you an old password appeared in an old dump. The credentials that matter were taken this week by malware on somebody’s laptop, and they came with the session cookies.

Exposure · this weeklive
STEALERFinance laptop, personal deviceinfected
COOKIEM365 session token, still validlive
ACTPassword reset, sessions revokedcontained
HUNTSign-in logs checked for prior useno access
CLOSEDDevice rebuilt, user briefedresolved
What it is

Watching the places
your data gets sold.

Continuous monitoring of criminal forums, marketplaces, Telegram channels and infostealer logs for your domains, your people and your brand — with our SOC acting on what turns up.

Credentials reach criminals by two routes. The slow one is a breach: a company is compromised, a database is dumped, and it circulates for years. That is what most monitoring services check, and by the time you hear about it the password has usually been changed twice.

The fast one is infostealer malware. Somebody installs a cracked application or a fake browser update, usually on a personal machine, and everything the browser holds is sent to a criminal server within minutes — saved passwords, autofill, and the session cookies that keep them logged in. Those logs are bought and used in days, not years. That is the half worth watching, and it is the half we are built around.

  • Infostealer logs, including credentials taken from unmanaged personal devices.
  • Session cookies and access tokens — the ones that walk past multi-factor authentication.
  • Criminal forums, marketplaces and Telegram channels for data-for-sale posts.
  • Initial access broker listings naming your organisation or your sector.
  • Ransomware leak sites, so you know before the negotiation does.
  • Phishing domains and look-alike domains registered against your brand.
  • Named executives, for impersonation and for credentials tied to them personally.
  • Your key suppliers, because their breach becomes your incident.
  • API keys and tokens exposed in public code repositories.
Three different things wearing one name

Most of it
is a breach database lookup.

"Dark web monitoring" covers three very different activities, and the cheap version is the one with the least to say about your actual risk.

Historic

Breach database lookups

Your domain checked against dumps from past breaches. Cheap, widely sold, and usually what a free tool means. It tells you about passwords that were changed years ago.

  • Old breaches, already public
  • Little that is currently exploitable
  • Often the whole of a cheap service

Useful once, at onboarding. Not a monitoring service.

Current

Infostealer and stealer logs

Credentials and live session cookies exfiltrated by malware in the last days or weeks — frequently from a personal device your controls never touched. This is what is actually being used to get in.

  • Plaintext passwords, current
  • Session cookies that bypass MFA
  • Unmanaged and personal devices
  • Days old, not years

What we build the service around.

Context

Forums, brokers and leak sites

Data-for-sale posts, initial access broker listings, ransomware leak sites, phishing domains and the actors behind them. The early signal that somebody has taken an interest in you or in your sector.

  • Access being advertised for sale
  • Brand and executive impersonation
  • Ransomware disclosure before the call
  • Payment card data tied to your business
  • Who is currently targeting your sector

Early warning, and often the most uncomfortable.

If a service cannot tell you which of these three it does, it is the first one. Ask before you buy — and ask what happens after a hit, because that is the part that decides whether any of it was worth paying for.

Why the alert is the easy part

An email saying you are exposed
is not a security service.

Finding a leaked credential is close to trivial. Deciding what it means at two in the morning, and doing something about it before it is used, is the work.

The standard product emails a PDF to a shared mailbox. Someone reads it on Monday. It lists an address and a password, and nobody knows whether the password is current, whether the account has MFA, whether the session is still live, or whether anyone has already signed in with it. So it gets forwarded to IT, and the honest answer is that most of the time nothing happens.

A hit reaches analysts who already watch your estate. They can see whether that account signed in from somewhere it should not have, whether the token was used, and what it touched. The password gets reset, the sessions get revoked, and the question of whether it was used is answered rather than left open — which is the only version of this that changes your risk rather than your mood.

How the 24/7 SOC works

Triaged, not forwarded
Is this credential current, does the account still exist, is MFA on it, and is the session still valid. Answered before you are told, not asked of you.
Revoked, not just reset
A password reset leaves a stolen session cookie working. Sessions and refresh tokens are revoked too, which is the step most people miss.
Checked for prior use
Sign-in logs and identity signals reviewed for whether it was already used, and what it reached. A leak you found late is an incident, not a notification.
Personal devices, handled carefully
Most stealer infections are on machines you do not own and cannot rebuild. The response has to work anyway, and it is mostly a conversation rather than a console.

If you already have monitoring and nobody acts on it, the gap is not the feed. Bring the feed and we will run the response half.

How it runs

Watched continuously,
worked when it hits.

Set up in a day, then it sits in the background until it has something worth telling you — which, on the first run, it usually does.

  1. 01

    Tell us what is yours

    Domains, brands, executive names, key suppliers and the applications that matter. No agents, no access to your estate, nothing to deploy.

  2. 02

    The first look back

    A baseline across everything already circulating. This is the uncomfortable one — most organisations have exposure they did not know about, and some of it is still live.

  3. 03

    Continuous monitoring

    New infostealer logs, forum posts, broker listings, leak sites and lookalike domains checked against your assets as they appear.

  4. 04

    Triage before you hear

    A hit is verified and assessed against your estate first, so what reaches you is a finding with a recommendation, not a raw record.

  5. 05

    Contain and confirm

    Reset, revoke, and check whether it was used. Where we run your detection and response, that happens without waiting for a ticket to be picked up.

Questions

Dark web monitoring, answered.

What is dark web monitoring?

Continuous searching of criminal forums, marketplaces, Telegram channels and malware exfiltration logs for your credentials, domains and brand. The useful version watches what is being stolen now, not only what leaked years ago.

What does a dark web monitoring service include?

Monitoring of your domains, people and brand, verification of anything found, and the response that follows — password reset, session revocation and a check of whether it was already used. A service that only emails you a list is a feed, not a service.

Is dark web monitoring worth it for a business?

It is worth it if somebody acts on the findings. On its own a feed produces alerts nobody closes. Attached to a SOC it closes a genuine route in, because stolen session cookies bypass multi-factor authentication entirely.

How is this different from a free breach checker?

A free checker tells you an address appeared in a historic breach. That password has usually been changed. We focus on infostealer logs — credentials and live session cookies taken in the last days, often from personal devices your controls never see.

Our staff use personal devices. Does that matter?

It is the most common source of a live credential. Infostealers land on home machines through cracked software and fake updates, then take everything the browser saved — including sessions for your corporate applications. You cannot manage those devices, which is exactly why you want to know.

Does MFA protect us from this?

Not on its own. A stolen session cookie is an already-authenticated session, so it does not prompt for a second factor. That is why the response includes revoking sessions rather than only resetting the password.

What happens when something is found?

It is verified, assessed against your estate, and brought to you with a recommendation. Where we run your detection and response we reset, revoke and check for prior use directly. Where we do not, you get everything needed to do it quickly.

Can you monitor our executives specifically?

Yes. Named individuals are monitored for credential exposure and for impersonation — look-alike domains and fraudulent profiles set up in their name. Senior people are targeted personally and often use personal devices for work, which is where the exposure usually appears.

Can you monitor our suppliers too?

Yes, and it is worth doing. A supplier with your data and stolen credentials is your incident in practice, whatever the contract says. It sits naturally alongside third-party risk management, where the same suppliers are already being assessed.

Do we need to install anything?

No. Monitoring runs entirely outside your estate against assets you nominate, so there is nothing to deploy and no access required. It works alongside whatever else you run.

Where to start

The first look back
is the one that lands.

Onboarding starts with a baseline across everything already circulating against your domains, your people and your suppliers. Most organisations find something, and some of it is still usable today.