Threat Intelligence · Detect & respond
Your company's leaked credentials, with follow-up and response.
We analyze your domain and tell you how many of your accounts are already circulating in stealer logs, public lists and known breaches. With the module on, every affected email address becomes a task with an owner, a playbook and evidence inside your remediation plan.
The count of exposed accounts is already in the free plan, no credit card needed.
What it is
Corporate credential exposure monitoring.
Leaked credentials are exposed usernames and passwords of your company that are already in third-party hands, almost always without anyone inside having done anything wrong. They get there by three paths that do not go through your network: a laptop with an infostealer inside, the breach of a service someone on your team used years ago, or a combo list recycled on a forum.
The problem arrives weeks after the theft, when someone uses those credentials and walks in with a correct username and password, with no exploit and no alert going off. Nobody inside the company checks every week which addresses of the domain have shown up on a new list, and the exposure stays open until someone looks.
The cost shows up when someone warns you from outside: an invoice diverted to another bank account, a customer who received an email from you that you never wrote, or a supplier whose payment details were changed in the middle of a thread. By then the credential has been circulating for a while and, if it came out of an infected machine, the session cookies are circulating with it.
3
published severity rules
6
fields stored per credential
30
days that mark critical severity
12
months of evidence validity
- What it is
- Monitoring of your domain's credential exposure in stealer logs, public lists and known breaches, with a rotation task for every affected account inside your remediation plan.
- Who it is for
- Companies of 10 to 250 employees with their own email domain and nobody inside who checks every week which addresses have shown up on a new list.
- Where it fits
- In the Pro and Max plans. In Free, leaked credentials are shown only as a count, without detail: you see the number of exposed accounts, and each account's record is unlocked with the module.
- What we need
- The company's email domain. Nothing else: no agents, no access to your email, no credentials of yours. The query runs from our infrastructure against an external index.
- Cadence
- Check the date of the last sweep in the portal and your account's schedule. Each account's history lets you tell new records from earlier appearances.
What each sweep looks at
Three sources of exposure and six fields per credential.
Each run takes your company's main domain and searches by email domain against a commercial index of exposed credentials.
- Stealer logs
- The dump from an infected machine: passwords saved in the browser and session cookies.
- Third-party breaches
- The SaaS someone on your team used with their work email and that suffered a breach.
- Public lists
- Aggregated username/password pairs from old breaches that get recompiled and recirculated on forums.
- The affected identity
- Which address of your domain appears and who has to rotate the password.
- Plain text or hash
- The factor that weighs most in severity: in plain text the password appears unhashed; its current validity is not checked.
- The source type
- Telling malware on an endpoint from an old breach changes the response completely.
- The entry date
- How long the credential has been exposed and whether the originating infection is recent.
- Breach dates
- When the source provides them, they place the origin of the exposure in time.
- Associated services
- Where the credential has been seen in use, to know where else to sign out.
The query covers anyone with an address on your domain, even if their account is not published anywhere on your website. The call goes out from our infrastructure and your browser never talks to the source.
Severity
Three rules decide the urgency of each finding.
All three are published so you can challenge them: urgency depends on whether the password is usable as is and on when it entered the feed.
Critical
Plain text and recent stealer log
Applies when the password travels in plain text, comes from a stealer log and entered the feed 30 days ago or less. The combination deserves priority review. The feed entry date does not by itself prove when the machine was infected.
High
Plain text or stealer log
Applies to plain text from any source and to any stealer log, regardless of age. The origin and the format of the record justify reviewing the account and the machine, even if the dump is years old. The rotation task opens all the same, with its owner and its playbook.
Medium
Old exposure without either condition
Applies to exposure older than three years that meets neither of the two conditions above. It is residual risk, usually from old breaches with the password hashed. It stays on the list because a reused password opens the door on another service.
What a single address reaches
A corporate credential rarely stays in the mailbox. From a single address with the password in plain text you reach the invoice history and suppliers' bank details, whatever hangs off that identity through single sign-on, the apps that person authorized with one click and the open sessions. That is why the playbook adds closing sessions and reviewing the machine of origin.
What each sweep leaves behind
The record, the rotation task and the aggregates.
The account record
Severity, main source, first detection, the services where the credential has been seen in use and the event history with its source and date. New appearances accumulate here and the worst severity seen is kept.
The rotation task
One action per affected account, inside the same remediation plan where the scanner's findings already live, with its owner and its playbook: rotate the password, close the active sessions and review the services where it has been seen in use.
Dashboard and aggregates
Four counters in the header, the table ordered by severity and date, and the aggregates for management: infected endpoints, exposure window in days, affected services and the split of appearances by source. It is the material to explain the exposure to the board or to the insurer.
Sample exposed account · Sample data
- Account
- c•••@company.example
- Severity
- Critical in the example
- Why
- Plain-text record · stealer log origin · imported 9 days ago
- Current validity
- Not checked
- Action
- Rotate the password, close active sessions and review the machine of origin
- Evidence
- Source and dates available in the record
Where it fits in the platform
Every closed rotation counts as evidence.
A leaked credential and a weakness in your public surface are the two ways in without breaking anything, and both live in the same file. The finding is mapped to ISO 27001:2022 A.5.17 and A.5.7 and to Article 21(d) of NIS2. Every closure records actor, IP and the state before and after, and leaves associated evidence valid for twelve months.
External Scanner
The other way in: what your public surface exposes today, classified and prioritized.
Learn moreEDR & MDR
If the credential came out of an infected machine, the endpoint is where the origin gets cut off.
Learn moreCyber Insurance
The exposure aggregates go into the picture the insurer asks for before quoting.
Learn moreLimits
What this module does not do.
Check the scope before turning on the module and coordinate with your team the actions that fall to them.
An empty result is not a guarantee
It means you do not appear in the indexed sources. No credential monitoring covers everything that circulates through private forums and markets.
It rotates nothing on its own
It opens the task with an owner and a playbook. The password change and the closing of sessions are carried out by your team or your identity provider.
It does not check whether the credential is still valid
Access is not tested with the leaked password. The exposure is reported, and attempting to use it is out of scope.
Only accounts on the corporate domain
The query is by email domain. Your team's personal accounts are out of scope, even if they appear in the same breach.
It does not read your email
There is no agent, no connected mailbox and no access to your systems. The search runs by domain against an external index of exposed credentials.
The information has a date
The date of the last sweep is visible in the portal. New exposure can appear between reviews.
In Free you only see the count
The free plan counts the exposed accounts. The details (which account, whose it is, since when and what to do about it) are unlocked in Pro.
Sized for companies of 10 to 250
With exposure volumes far above what is usual at that size, it is worth talking about a custom scope.
Plans
Threat Intelligence comes with Pro and Max.
The count of exposed accounts is in the free plan. The details (which account, whose it is, since when and what to do about it) are unlocked in Pro and stay in Max.
Free
To see your real risk before deciding anything.
No cost · No card.
Everything to get looking:
- Continuous scan External surface, 24/7
- Posture and risk map Real-time CyberScore
- Leaked credentials Counted, no detail
Base
For companies that want the whole platform without a security team of their own.
Self-serve · No commitment.
Everything in Free, plus:
- Integrations Microsoft 365, Google Workspace and cloud
- AI risk Apps with permissions over your data
- Prioritized backlog Monthly remediation
- 1 domain Continuously scanned
Pro
For teams that need every sensor active and an expert behind it.
Advisor on escalation · No commitment.
Everything in Base, plus:
- Security advisor On escalation, with SLA
- Threat Intelligence Exposed credentials, under watch
- Recurring pentesting Authenticated, report reviewed by Axyom
- MDR 24/7 Up to 20 managed devices
- Up to 5 domains All continuously scanned
Max
For high exposure or compliance demands.
Dedicated advisor · No commitment.
Everything in Pro, plus:
- Dedicated security advisor A fixed person, monthly session
- Priority response Incidents
- Compliance by framework Downloadable evidence and attestation
- Audit support Customer questionnaires and due diligence
FAQs.
What is a stealer log and why does it matter so much?
It is the dump of data an infostealer steals from an infected machine: passwords saved in the browser, session cookies and form data, sold in batches. When a corporate credential shows up inside one, that person's machine was infected, without any breach at the company.
Is changing the password enough?
Not when the credential came out of an infected machine: session cookies usually travel with the password and allow someone in without authenticating again. That is why the playbook adds closing the active sessions and reviewing the machine of origin, on top of rotating the password.
Do you monitor the team's personal accounts?
The query is run on the company's email domain, so it covers any corporate address even if it is not published on your website. Employees' personal accounts are out of scope, even if they show up in the same breach.
Do you have access to our email?
We only need the domain, and the query is made against an external index of exposed credentials. Nothing is installed and nobody reads your email. The call goes out from our infrastructure, so your browser never talks to the source.
Does it count as compliance evidence?
The finding is mapped to ISO 27001:2022 A.5.17 and A.5.7 and to Article 21(d) of NIS2, and it counts in the same file as the rest of your security. Every closure records actor, IP and the state before and after, and leaves associated evidence valid for twelve months.
Choose how to start.
On your own
Analyze your domain and start with your security posture. Then connect your systems and turn on the capabilities you need.
With our team
Tell us what you need to protect and which requirements you have. We will review the scope and the right plan with you.