Part of the RST intelligence layer

breach-alert-icon

RST Breach Alert

Compromised-credential intelligence over an API — scored, verifiable, and built so your stack can close the exposure, not just receive an email about it.

exposure record
identityj.doe@corp.com
sourcestealer log
malwareRedLine
first seen6 days ago
hostinfected endpoint

Checked against your own directory, inside your perimeter:

password still valid — P1

The agent runs on your infrastructure. We send intelligence to you; we never reach in.

01 · Collection

Credentials surface

stealer logsULP combolistsbreach dumps

Output from infostealer malware and the combolists circulating around it.

02 · RST Breach Alert

Matched and scored

your domainsscored

Matched to the domains you own and scored on the same three dimensions as the rest of the layer — so age and source quality are visible, not assumed.

03 · Delivery

Notified, or pulled

notificationsREST API

Take a notification, or let your SOAR, SIEM or IAM tooling pull exposures on its own schedule.

04 · Validation, your side

Is the password still live?

Active DirectoryEntra IDany LDAP

Our on-prem agent pulls exposures from the API and tests them against your own directory.

→ confirmed live, or already rotated

The check happens inside your perimeter. The agent runs on your infrastructure and compares against your own directory — we send intelligence to you, we never reach into your environment. What comes back is the one thing that decides severity: whether the leaked credential still works.

Trusted exposure — what is already compromised.

Built for automation

Most breach monitoring sends an email. This closes the loop.

An alert in an inbox is a task for a human who may be asleep. Breach Alert is an API, so a finding can flow straight into the systems that can actually do something about it — and report back when the exposure is gone.

01

Configure your assets

The domains, email addresses and keywords you care about.

02

We monitor continuously

Stealer logs, ULP files, data dumps and leak channels.

03

Scored findings over the API

Every finding carries source confidence, context and relevancy.

04

Checked against your directory

An agent pulls findings and tests them against your identity store — for Active Directory, against password history: is it still active, or was it active recently?

05

Your actions fire

You define what happens on a match — force a reset, disable the account, raise a ticket, page the on-call.

06

Reported back as closed

Your stack confirms the exposure is resolved.

You are not just told about a problem — the problem gets fixed, and you get told it is fixed.api-first · scored · verifiable

Collection

Where the data comes from

Stealer logs

Output from infostealer malware on infected endpoints — credentials, sessions and host context as harvested.

ULP files

URL-login-password combolists circulated in bulk across forums and channels.

Data dumps

Breached databases from third-party compromises, parsed and attributed back to identities.

Leaks & paste sites

Credential material published or traded in open and closed channels.

Scored, like everything else

Not every exposure deserves the same response

A credential from a dump three years old is not the same problem as one harvested last week. Every finding is scored on the same three dimensions as the rest of the layer — source confidence, context score and time relevance. See how we score →

Source confidence

How much we trust where the finding came from.

Context score

Which stealer malware produced it, and what else came with it.

Time relevance

Is this from last week, or a dump that has been circulating for years?

A breach is only a P1 if the password still works

For domains you own — and can prove you own — Breach Alert gives you access to the raw credential, so you can run your own authentication check in any system and confirm whether the exposure is real.

That is the difference between a ticket that says possible exposure and one that says this password works right now — and it is what lets you triage by fact instead of by assumption.

Where it fits in the pipeline

The rest of the RST layer tells you what is dangerous out there — the indicators, the actors, the reporting. Breach Alert tells you what is already yours: the exposure sitting inside your perimeter before any indicator fires.

Same scoring discipline, same machine-readable delivery, different question. Not “is this infrastructure malicious?” but “whose access is already for sale — and does it still work?”

See what is already exposed.

The fastest answer is a look at your own domains. Request a demo and we will walk through what Breach Alert surfaces — and how it plugs into what you already run.

Request a demo