Skip to main content
Intelligence · Module DRK-01 · PDF

Dark Web datasheet

Stealer logs, leaked credentials, ransomware victim posts, and threat-actor marketplaces — monitored continuously and matched to your assets.

One page, no preamble

The credentials, sessions, and access already up for sale.

Stealer logs, combo lists, ransomware leak sites, and access-broker marketplaces — ShadowMap watches them continuously and surfaces the moment your domain, your customer, or your employee shows up. By the time the attacker uses what they bought, you've already rotated.

Everything in the datasheet is on this page and on the Dark Web capability page. The PDF exists because procurement asks for one, not because it says anything the site does not.

Dark Web datasheet (PDF)

We'll email you a confirmation link. Click it and the PDF downloads — no waiting on a sales call.

By downloading, you agree to receive relevant communications. We respect your privacy.

Prefer to skip the form? Everything here is on the capability page, ungated.

The capability list

What Dark Web monitors

Every capability in the Dark Web module, as printed in the datasheet
CapabilityWhat it does
Stealer-log credential matching 12B+ records across major stealer families (RedLine, Vidar, Raccoon, LummaC2). Matches by email, domain, application URL.
Compromised cards Customer payment-card exposure surfaced from carding marketplaces with BIN-level scoping for fraud teams.
Ransomware leak monitoring Continuous scraping of 290+ ransomware leak sites (LockBit, BlackCat/ALPHV, Akira, etc.). Your name appearing = page-the-CISO.
Initial-access broker watch XSS, Exploit, and underground forums monitored for offers selling network access to your assets.
Session cookie / token harvesting Stealer logs often contain active session cookies. Matched and surfaced with token-revocation guidance.
Customer-side exposures Your B2C customers showing up in stealer logs that reference your domain — useful for fraud teams and account-takeover prevention.
Exec + HVT monitoring Targeted dark-web watch for named executives, IT admins, and other high-value-target accounts.
Source attribution Each match annotated with stealer family, infection date, exfil URL, and confidence — so you can plan account, device, and domain-wide responses.

Every capability in the Dark Web module, as printed in the datasheet

Stealer-log credential matching

What it does
12B+ records across major stealer families (RedLine, Vidar, Raccoon, LummaC2). Matches by email, domain, application URL.

Compromised cards

What it does
Customer payment-card exposure surfaced from carding marketplaces with BIN-level scoping for fraud teams.

Ransomware leak monitoring

What it does
Continuous scraping of 290+ ransomware leak sites (LockBit, BlackCat/ALPHV, Akira, etc.). Your name appearing = page-the-CISO.

Initial-access broker watch

What it does
XSS, Exploit, and underground forums monitored for offers selling network access to your assets.

Session cookie / token harvesting

What it does
Stealer logs often contain active session cookies. Matched and surfaced with token-revocation guidance.

Customer-side exposures

What it does
Your B2C customers showing up in stealer logs that reference your domain — useful for fraud teams and account-takeover prevention.

Exec + HVT monitoring

What it does
Targeted dark-web watch for named executives, IT admins, and other high-value-target accounts.

Source attribution

What it does
Each match annotated with stealer family, infection date, exfil URL, and confidence — so you can plan account, device, and domain-wide responses.

How it works

Ingest → Index → Match → Respond

1

Ingest

Continuous ingestion from telegram dump channels, dedicated-leak forums, ransomware sites, and stealer-log feeds.

2

Index

Normalised + searchable index keyed on email, domain, subdomain, and application URL.

3

Match

Your attributed inventory + employee identifiers used as standing queries. New matches alerted in near-real-time.

4

Respond

Auto-ticket for password rotation; session revocation guidance; scope-of-impact reporting for breach notification decisions.

200-800

What changes

Stealer-log credentials surfaced per customer

Average enterprise customer has 200–800 employee credentials surfaced in stealer logs in the first scan — the median exposure age is over 6 months.