Breached credentials
Email addresses and passwords tied to your domain that appear in breach corpora, reported with where they surfaced and how recent the exposure is.
Dark web intelligence
Dark web intelligence is the practice of searching underground sources, leak sites and breach corpora for data belonging to an organisation. Most commonly that means credentials: email addresses and passwords exposed in a breach of some other service.
See.Tech checks those sources against your domain and, more usefully, relates what it finds to the rest of your external attack surface. A leaked credential is one fact. A leaked credential for a domain that also exposes a remote access service is a different fact entirely.
What is assessed
Email addresses and passwords tied to your domain that appear in breach corpora, reported with where they surfaced and how recent the exposure is.
Mentions of the organisation on monitored underground sources and leak sites, including company data listed by ransomware operators.
The Cyber News capability queries dark web sources by domain, so intelligence is filtered to the organisation being assessed rather than presented as a general feed.
Domains registered to resemble yours, which are how exposed credentials are most often converted into a successful phishing attempt.
Phishing infrastructure and cloned sites using your brand, assessed alongside the email authentication weaknesses that make impersonation easier.
SPF, DKIM and DMARC configuration, because credential theft and domain spoofing are the two halves of the same campaign.

Why isolation fails
A dark web monitoring product will tell you that eleven addresses at your domain appear in breach data. That is useful and incomplete.
What determines whether those eleven addresses matter is everything around them: whether the domain enforces DMARC, whether a lookalike domain is already registered, whether an internet-facing service accepts those credentials, and whether the accounts belong to people with privileged access.
Questions
Leaked credentials are usernames, email addresses and passwords that have been exposed in a data breach and published or traded. They usually come from a breach of a third-party service rather than of your own systems, which is why an organisation is often unaware of them.
Dark web intelligence is the collection and analysis of data about an organisation from underground forums, leak sites and breach corpora. For most organisations the practical output is exposed credentials and evidence that company data has been published.
No. Breached credential checks report that an exposure exists and where it surfaced. See.Tech is not a credential store.
Directly. An exposed credential is far more serious when the same organisation also exposes a remote access service, has weak DMARC enforcement, or has a lookalike domain registered against it. See.Tech scores these together rather than reporting them in isolation.
Checks run as part of an assessment, and assessments can be scheduled to rescan weekly or monthly. Change detection flags material changes between scheduled scans.
Reset it, check whether it was reused on any internet-facing service, and confirm multi-factor authentication is enforced on the account. If email authentication is also weak, fixing DMARC enforcement usually removes more risk than the password reset alone.
Start here
A See.Tech assessment starts from a domain name. Nothing is installed, no credentials change hands, and the first findings come back in hours.
Let's talk about protecting your brand, your customers, and your reputation. Our team is ready to show you exactly how See.Tech can help, starting today.