JavaScript Required

BUI DarkWeb Intel Monitor requires JavaScript to run.

JavaScript is currently disabled in your browser.

Please enable JavaScript in your browser settings and reload the page to continue.

This application also requires a Microsoft account to access.

OFF
BETA v217
Ready
Threat Briefing
Loading…
— THREAT
Loading threat assessment…
Top Intelligence Stories — 24h
Loading…
Victims by Sector — 24h
Loading…
Most Active Groups — 24h
Loading…
Top Targeted Countries
Loading…
Critical CVEs — 24h
Loading…
Your Watchlist
Loading…
→ Open Alerts pane
Feed Status
Loading…
0 items
0 critical / high
0 countries
0 actors
Never refreshed
0 / 0 items
Never refreshed·No data yet
Total Victims
all time
Active Groups
ransomware groups
Countries Hit
recent 100
Last Updated
ransomware.live
Never refreshed·No data yet
— items
Loading ransomware intelligence…
— groups
Loading groups…
Loading stats…
Ransomware Incidents by Country
Last 7 days · Hover a country for details · Click to filter victims
0
— articles
Loading ransomware news…
Total Articles
0
combined feeds
Sources
11
active feeds
DarkWeb News
0
articles
Last Synced
Never
refreshed
Never refreshed·No data yet
— articles
Loading news…
Total Articles
0
loaded
Source
DailyDarkWeb
data-breaches feed
Last Synced
Never
refreshed
Latest
most recent
Never refreshed·No data yet
— articles
Loading data breaches…
Total Articles
0
loaded
Source
DailyDarkWeb
vulnerability feed
Last Synced
Never
refreshed
Latest
most recent
Never refreshed·No data yet
— articles
Loading vulnerabilities…
Total Articles
0
loaded
Source
DailyDarkWeb
unauthorized-accesses feed
Last Synced
Never
refreshed
Latest
most recent
Never refreshed·No data yet
— articles
Loading unauthorized accesses…
Total Articles
0
combined feeds
Sources
0
active feeds
Last Synced
Never
refreshed
Latest
most recent
— articles
Loading threat intelligence…
Never refreshed·No data yet
Known Breaches
in HIBP database
Accounts Pwned
total across all
Latest Breach
most recently added
Data Classes
types of data exposed
— breaches
Loading breach database…
Domain Breach Search
Search all email addresses on a domain that have appeared in known data breaches.
Only domains you have verified ownership of via HIBP can be searched.
Email Address Lookup
Check if an email address has appeared in any known data breach.
Results show which breaches the address was found in.
My Alerts — Watchlist Monitoring
— matches
Watchlist Items
0
being monitored
Total Matches
0
across all panes
Unread
0
new since last scan
Last Scan
Never
watchlist scan
No watchlist items yet
Add email addresses, domains, IP addresses, countries, threat actors, ransomware groups, or keywords to monitor. You'll see matching items from all panes here.
Tracked Intelligence
Track terms across all panes — matching cards glow with their category colour
Countries Sectors Actors Ransomware CVEs
Countries 0
Sectors 0
Actors 0
Ransomware 0
CVEs 0
Tracked countries glow red on Dark Web cards. Auto-scans when you switch to Dark Web Feed.
No countries tracked yet
QUICK ADD — COMMON REGIONS
Tracked sectors glow blue on Dark Web cards when posts mention matching industry sectors.
QUICK ADD
No sectors tracked yet
Tracked actors glow orange on cards when a matching threat actor or group is attributed.
QUICK ADD
No actors tracked yet
Tracked ransomware groups glow red (pulsing) on Ransomware victim cards and Dark Web posts.
QUICK ADD — ACTIVE GROUPS
No ransomware groups tracked yet
Tracked CVEs glow purple on any card mentioning that vulnerability across dark web, news, and threat intel feeds.
No CVEs tracked yet
IP Address Reputation
Continuous reputation checks on the addresses and ranges you own
Check looks an address up once — nothing is monitored. Watch daily adds it below, where it is checked every morning and you are emailed if its reputation worsens. Watch the addresses you own: being listed affects your mail delivery and partner access, and you want to know before a customer tells you.
paste a CSV export or a KQL array
Deep Web Search
Leaked credential & stealer-log intelligence
READY
Searches all sources at once. Narrow with a prefix: domain:example.com · email:name@example.com · user:jsmith · ip:1.2.3.4 · device:machine ID · password:secret
Credential Intelligence
Search our leaked-credential and stealer-log dataset by domain, email, username or password.
Discover exposed credentials and infostealer infections tied to your people and partners
before they're used in an attack.
Settings & Tools
Auto-Refresh Timer
Timer is off
Projection Mode
Cycle through panes in fullscreen — great for SOC wall displays.
Saved Views
Manual Post Import
Deep Web Search (Cavalier)
Enables the Deep Web Search pane — credential intelligence and dark web monitoring for our own assets.
Onboarding
Reports Report — Choose Style
Email Delivery
Email the selected report to yourself now as a PDF, or schedule a recurring HTML version. Sent to your signed-in email only.
Scheduled reports arrive at 07:00 UTC as an HTML email. The full PDF stays a one-click download here.
Tour Complete!
Ready to set up the dashboard for your organisation?
The setup wizard walks you through the 5 key configuration steps in under 2 minutes.
The wizard can be restarted anytime from ≡ Settings
Setup Wizard
Step 1 of 5 — Auto-Scan Interval
1. Timer
2. Watchlist
3. Notifications
4. Countries
5. Daily Digest
6. First Search
Auto-Scan Interval
How often should the dashboard automatically refresh all intelligence feeds? Choose a frequency that matches your monitoring needs.
The auto-scan timer is shown as a countdown ring in the header. You can change it anytime from ≡ Settings.
Add Your First Watchlist Item
The watchlist monitors all 9 intelligence panes for your specified terms and alerts you when matches are found. Add your organisation's domain, country, or a key term to start monitoring now.
Type
Value
Enter your organisation's primary domain — the dashboard will alert you when it appears in breach data, dark web posts, ransomware victims, and news.
Notification Channels
Get alerted when the dashboard finds new matches for your watchlist items. Enter your contact details and choose which channels to use for each alert type.
Phone (WhatsApp + Voice)
Include country code
Email Address
Minimum severity to trigger notifications
You can configure individual channel toggles per watchlist type in My Alerts → Notifications.
Track Countries
Tracked countries are highlighted in the Dark Web Feed whenever they appear. Choose the regions most relevant to your organisation's operations or threat exposure.
No countries added yet
Quick add — common regions:
Daily Intelligence Digest
Subscribe to a daily briefing email at 07:00 UTC every morning — built from live data with charts, your watchlist matches, top stories, critical CVEs, and a threat assessment.
Ransomware charts Critical CVEs Your watchlist matches Top stories Country breakdown
Delivered to the email address in your Notification Settings. Unsubscribe anytime.
Run Your First Search
Search all 9 intelligence panes simultaneously. Try your organisation's name, domain, country, or a threat actor relevant to your sector.
Enter a term above and click Search to preview results from all loaded panes.
After clicking Finish, the Search pane will open with your query and the full AI-powered search will run automatically.