Use cases · Information security
For information security teams
How long have these credentials been circulating, and through which hops? You already have a platform: we do not replace it, we plug into it.
What the archive adds
The same credential, four times
Knowing a credential is circulating does not tell you what to do. Knowing since when, and through how many hands, does.
One credential, its dated reappearances
11/2023
Combolist, 3rd release
02/2024
Initial-access marketplace
07/2024
Leak aggregator
12/2024
Back on sale, another marketplace
The same credential, four times. Knowing which of those hops preceded the incident changes the response: a thirteen-month-old leak is not handled like yesterday's.
Goes back into your tools, not into one more console
- OpenCTI
- MISP
- Sekoia
- STIX 2.1
Schematic. The dates are illustrative and describe no real case.
Plugging in
In your tools, not alongside them
Connectors
OpenCTI, MISP, Sekoia: elements land in the tool your analysts already work in.
Standard format
STIX 2.1 output and API access, so the data enters your correlation rules without manual rework.
What comes through
Exposed credentials, access offered for sale, extortion claims naming your organisation or your third parties.
What we are not trying to be
Neither your SOC nor your platform
You have a platform, feeds and correlation rules. We do not add a console: we add an archive depth that current feeds do not have, in the format your tools already read.
If what you already receive covers the anteriority you need, we will say so — a duplicate costs analyst time before it costs anything else.
Plug the archive into your platform
One connector, a set of dated elements, and you judge it in your own environment.