Product
Breach credential and stealer-log monitoring across your client domains
Breach credential monitoring watches breach dumps, stealer logs, forums, paste sites, marketplaces and Telegram for usernames and passwords tied to the domains and email addresses you protect, then alerts you when a new exposure appears. DarkWebSonar lets an MSP monitor several client domains from one workspace, keeps stealer-log exposures separate from older breach data, and labels every alert with the client domain, so you know whose passwords to reset.
See what's already exposed on your own domain with a one-time breach and infostealer check.
northstar.example
Stealer logj.reed@northstar.example
•••••••• · 8 Oct 2026 · High risk · New alert
harborline.example
Breach dumpbilling@harborline.example
•••••••• · 7 Oct 2026 · Medium risk · Reviewed
millwright.example
Stealer logops@mail.millwright.example
•••••••• · 6 Oct 2026 · High risk · New alert
Slack notification
Credential exposure detected · northstar.example
of ransomware victims Verizon examined had their domains in infostealer logs or marketplace postings
had corporate email addresses in those credentials
of compromised systems with corporate logins were non-managed devices
For MSPs
What breach credential monitoring does for an MSP
The challenge is not running one scan. It is watching many client domains continuously, keeping findings separated, and giving a technician enough context to act without switching accounts.
- One workspace
- Monitor your client book from one account instead of maintaining separate workspaces.
- Client-level routing
- Every finding identifies the affected client domain for faster assignment and response.
- Continuous coverage
- Keep watching after the initial check so newly discovered exposures do not wait for the next manual scan.
Building the broader service around ransomware, executive exposure, and threat actors? Read the MSP dark web monitoring guide.
Coverage
Breach dumps vs stealer logs: why you need both
Treating every hit as urgent is how dark-web scans become noise. The source type tells you whether you are looking at an old dump or a freshly compromised machine.
Breach dumps and combolists
Credentials leaked from a third-party service, often months or years old, then aggregated into combolists. Useful for spotting password reuse. Noisy if every hit is treated as an incident.
Stealer logs
Browser-stored data stolen by malware on an infected device. These records are usually fresher than bulk dumps and point to a compromised machine that still needs cleaning after the password change.
Why freshness matters
A fresh stealer-log hit points to a compromised endpoint that needs cleaning. Older breach data is more useful for identifying password reuse. Keeping the two sources separate helps technicians choose the right first action.
How it works
How DarkWebSonar monitors your client domains
One workspace, every client
Add client domains and employee email addresses to one account. A monitored parent domain also matches email addresses on its subdomains — for example user@mail.client.com under client.com.
Where we look
Breach dumps, stealer logs, underground forums, paste sites, marketplaces, and Telegram channels are monitored for credentials tied to the domains and email addresses you protect.
Stealer-log detection, separate from breaches
Separate badges and filters keep older bulk breach records from obscuring fresh device-level compromises.
Filters that cut noise
Risk, password-exposure, and per-domain policy filters help sequence remediation. Every exposed credential still requires a response, regardless of whether it meets the client's complexity rules.
Event time and detection time
Alert emails show when the exposure occurred and when DarkWebSonar detected it. Discovery-time alerting ensures a newly ingested older post still reaches your team.
01
Detect
A match lands against a client domain in a breach dump or stealer log.
02
Alert
Email, dashboard, and integrations get the alert. Credential details stay in the platform.
03
Investigate
Open the record, see the client domain, and filter by stealer log, risk, or password policy.
04
Respond
Reset the password, revoke sessions, and clean the infected device when the hit is a stealer log.
Alert delivery
Getting alerts to the right client, in the tools you already use
Email and dashboard alerts identify the affected client. Slack, Microsoft Teams, PagerDuty, ServiceNow, and custom webhooks receive a privacy-safe notification without the exposed credential details.
Technicians open the protected record in DarkWebSonar, where Pro and Enterprise can show the exposed credentials. Custom webhooks can route the notification into a PSA or ticketing workflow.
Pro includes 1,000 monthly API requests for the intelligence feed and threat-actor data, plus MCP access. Enterprise includes 5,000 monthly requests and credential lookup endpoints. See the API reference or MCP setup.
Slack
Microsoft Teams
PagerDuty
ServiceNow
Custom Webhooks
Incident response
What to do when a client's credentials show up
Detection is the start. A password reset alone does not close a stealer-log hit.
- 1Confirm the user and the client domain on the alert.
- 2Reset the password.
- 3Revoke active sessions and tokens. Microsoft's token-theft playbook is the vendor-neutral reason: a reset does not kill a stolen session.
- 4Review MFA methods and inbox rules.
- 5For a stealer-log hit, find and clean the infected device.
Plans
Plans and domain limits for MSPs
Pro is the most popular MSP starting point: three domains, credentials shown in the platform, weekly account-level reports, and API access for the intelligence feed and threat-actor data.
| Plan | Price | Monitored domains | Credential monitoring | API / MCP |
|---|---|---|---|---|
| Starter | $49/mo | One-time domain snapshot | Email breach monitoring | No API access |
| Growth | $99/mo | 1 continuous domain | Stealer-log scanning, lookalike domains, CSV exports | No API access |
| ProMost popular | $199/mo | 3 continuous domains | Credentials shown in the platform, weekly account-level reports, Threat Intelligence Briefs | Intel feed and threat actors, 1,000 requests/mo |
| Enterprise | from $499/mo | 10 continuous domains | Credentials shown in the platform, Executive Threat Monitoring, priority support | All API data including credential lookups, 5,000 requests/mo |
Starter$49/moOne-time domain snapshot
- Credential features
- Email breach monitoring
- API / MCP
- No API access
Growth$99/mo1 continuous domain
- Credential features
- Stealer-log scanning, lookalike domains, CSV exports
- API / MCP
- No API access
ProMost popular$199/mo3 continuous domains
- Credential features
- Credentials shown in the platform, weekly account-level reports, Threat Intelligence Briefs
- API / MCP
- Intel feed and threat actors, 1,000 requests/mo
Enterprisefrom $499/mo10 continuous domains
- Credential features
- Credentials shown in the platform, Executive Threat Monitoring, priority support
- API / MCP
- All API data including credential lookups, 5,000 requests/mo
Add more client domains
Add or remove a monthly domain pack whenever your client book changes.
+5 domains
$50/mo
Available on Growth, Pro, or Enterprise
+10 domains
$90/mo
Available on Pro or Enterprise
+25 domains
$200/mo
Available on Enterprise
Choosing coverage
Continuous monitoring vs free checks and one-off scans
Free check: a useful baseline
Services such as Have I Been Pwned domain search help verified domain owners review known historical exposure at a point in time.
Continuous monitoring: an operating service
Ongoing collection, stealer-log separation, and client-level alerts surface new discoveries after the initial report and route them into your response workflow.
The 14-day trial includes a one-time breach and infostealer check on your own domain with passwords masked. Continuous domain monitoring starts on Growth.
Common questions
Frequently asked questions
What is breach credential monitoring?
Breach credential monitoring continuously checks breach dumps, stealer logs, underground forums, paste sites, marketplaces and Telegram channels for usernames and passwords tied to your domains and email addresses. When a new match appears, you get an alert, so you can reset the password and close the gap before someone uses it. Unlike a one-off scan, it keeps watching after the first report.
What's the difference between a breach dump and a stealer log?
A breach dump holds credentials leaked from a third-party service, often months or years old, and is frequently merged into combolists. A stealer log is created by malware on an infected device. It captures saved passwords, autofill data and often session cookies, and is usually much fresher. A stealer-log hit also points to a specific compromised machine that needs cleaning, not just a password that needs changing.
Can an MSP monitor every client's domain from one account?
Yes. Add each client's domains and email addresses to one workspace, then filter and label findings by client. A monitored parent domain also matches email addresses on its subdomains, such as user@mail.client.com under client.com. Alerts identify the affected client without requiring separate accounts.
How many client domains can I monitor on each plan?
Growth includes 1 breach-monitoring domain, Pro includes 3, and Enterprise includes 10. Starter includes a one-time domain check. Monthly add-ons are $50 for 5 domains on Growth and above, $90 for 10 domains on Pro and above, and $200 for 25 domains on Enterprise.
Does a password reset fix a stealer-log exposure?
Not on its own. Stealer logs often include session cookies, which can let an attacker stay signed in after a password change. Reset the password, revoke active sessions and tokens, review MFA methods and mailbox rules, and find and clean the infected device the log came from.
Can credential alerts go into my PSA or ticketing system?
DarkWebSonar sends alerts by email and to the dashboard, and integrates with Slack, Microsoft Teams, PagerDuty and ServiceNow. Custom webhooks can deliver alerts to any endpoint, including a PSA that accepts webhooks. Integrations receive the alert, not the credential details; those stay in the platform. There are no pre-built ConnectWise, Autotask or HaloPSA connectors today.
Can I see the exposed passwords?
Pro and Enterprise show exposed credentials in the platform. The 14-day free trial includes a one-time breach and infostealer check on your own domain with passwords masked. Slack, Teams and webhook alerts do not include the credential details.
Is there an API for credential monitoring data?
Credential lookups through the API are available on Enterprise. Pro includes 1,000 monthly API requests for the intelligence feed and threat-actor data, plus MCP access. Enterprise includes 5,000 monthly requests and credential lookup endpoints.
Can I test it on my own domain first?
Yes. The 14-day free trial includes a one-time breach and infostealer check on your own domain, with passwords masked. Continuous domain monitoring starts on the Growth plan.
See what is already exposed
Start a 14-day free trial and run a one-time breach and infostealer check on your own domain.