Part of the RST intelligence layer
RST Breach Alert
Compromised-credential intelligence over an API — scored, verifiable, and built so your stack can close the exposure, not just receive an email about it.
Checked against your own directory, inside your perimeter:
password still valid — P1The agent runs on your infrastructure. We send intelligence to you; we never reach in.
Credentials surface
Output from infostealer malware and the combolists circulating around it.
Matched and scored
Matched to the domains you own and scored on the same three dimensions as the rest of the layer — so age and source quality are visible, not assumed.
Notified, or pulled
Take a notification, or let your SOAR, SIEM or IAM tooling pull exposures on its own schedule.
Is the password still live?
Our on-prem agent pulls exposures from the API and tests them against your own directory.
→ confirmed live, or already rotated
The check happens inside your perimeter. The agent runs on your infrastructure and compares against your own directory — we send intelligence to you, we never reach into your environment. What comes back is the one thing that decides severity: whether the leaked credential still works.
Trusted exposure — what is already compromised.
Built for automation
Most breach monitoring sends an email. This closes the loop.
An alert in an inbox is a task for a human who may be asleep. Breach Alert is an API, so a finding can flow straight into the systems that can actually do something about it — and report back when the exposure is gone.
01
Configure your assets
The domains, email addresses and keywords you care about.
02
We monitor continuously
Stealer logs, ULP files, data dumps and leak channels.
03
Scored findings over the API
Every finding carries source confidence, context and relevancy.
04
Checked against your directory
An agent pulls findings and tests them against your identity store — for Active Directory, against password history: is it still active, or was it active recently?
05
Your actions fire
You define what happens on a match — force a reset, disable the account, raise a ticket, page the on-call.
06
Reported back as closed
Your stack confirms the exposure is resolved.
Collection
Where the data comes from
Stealer logs
Output from infostealer malware on infected endpoints — credentials, sessions and host context as harvested.
ULP files
URL-login-password combolists circulated in bulk across forums and channels.
Data dumps
Breached databases from third-party compromises, parsed and attributed back to identities.
Leaks & paste sites
Credential material published or traded in open and closed channels.
Scored, like everything else
Not every exposure deserves the same response
A credential from a dump three years old is not the same problem as one harvested last week. Every finding is scored on the same three dimensions as the rest of the layer — source confidence, context score and time relevance. See how we score →
Source confidence
How much we trust where the finding came from.
Context score
Which stealer malware produced it, and what else came with it.
Time relevance
Is this from last week, or a dump that has been circulating for years?
A breach is only a P1 if the password still works
For domains you own — and can prove you own — Breach Alert gives you access to the raw credential, so you can run your own authentication check in any system and confirm whether the exposure is real.
That is the difference between a ticket that says possible exposure and one that says this password works right now — and it is what lets you triage by fact instead of by assumption.
Where it fits in the pipeline
The rest of the RST layer tells you what is dangerous out there — the indicators, the actors, the reporting. Breach Alert tells you what is already yours: the exposure sitting inside your perimeter before any indicator fires.
Same scoring discipline, same machine-readable delivery, different question. Not “is this infrastructure malicious?” but “whose access is already for sale — and does it still work?”
See what is already exposed.
The fastest answer is a look at your own domains. Request a demo and we will walk through what Breach Alert surfaces — and how it plugs into what you already run.