Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This guide is part of the User Guides collection. It covers Dark Web in the left navigation, the Dark Web tab in a vendor’s Vendor Intelligence, and the settings under Configuration → Monitoring → Dark Web. For news, advisories and regulator filings about your vendors, see the Radar signals guide and the Breach notification monitoring guide. For the neighboring Vendor Intelligence tab that checks sanctions and watchlists, see the Sanctions screening guide.
Dark web monitoring is an optional module. If you do not see Dark Web in the left navigation, ask your Coverbase account team to turn it on.
Dark web monitoring checks your organization and your vendors against services that track what criminals publish and register: ransomware groups’ leak sites, published data breaches, logs from infostealer malware, and newly registered domains built to look like a real one. It runs once a day. Every hit becomes an exposure in one queue, and a person decides what it means. Each source is an outside service that already follows one kind of criminal activity and makes it searchable. Coverbase asks each source about the names and domains on your watchlist. It keeps the facts the source returns: who listed the company, when, how many records, which kinds of data. The leaked content itself, such as passwords or personal data, is never stored. The mistake people make most often is reading an empty queue, or a vendor tab marked Clear, as proof that nothing was found. Out of the box only the vendors Radar monitors are watched. A vendor tab shows Clear only when the vendor has watched values, a sweep has checked them, and nothing is open. Otherwise it shows Not watched or Not checked yet. See The vendor’s Dark Web tab.

Where it lives

Three places, for three jobs. The queue: Dark Web in the left navigation. Every exposure for your organization and every watched vendor, worst first, with the watchlist and the sweep history on tabs beside it. This is where triage happens. On a vendor: open a vendor, choose Vendor Intelligence, then Dark Web. The same exposures for that vendor only, with the values being watched for it. The settings: Configuration → Monitoring → Dark Web, or Configuration at the top right of the queue. An administrator switches monitoring on here and decides who is watched and which sources run.

What is watched

The sweep checks a watchlist. You do not type most of it: Coverbase builds it from records you already keep, and rebuilds it at the start of every sweep. Your organization. Its names, the domain of its website, and its email domains, all read from your organization record. Monitor our organization is on by default. Your vendors. For each vendor in scope, the vendor’s name and the domain of its website. When the vendor is linked to an entry in the Coverbase directory, that company’s name, website and other known names are added too. Every website domain is also watched as an email domain. Breach and infostealer data is organized by the address people sign in with, and a company’s web domain is usually its mail domain. If it is not, switch that row off. Values are normalized before they are stored, so different spellings of one value share a row. Case, accents, punctuation, a leading www. and a trailing company suffix such as Inc, Ltd or Co are ignored, which makes Orchard Insurance and Orchard Insurance Co. one row. Which vendors are in scope is a setting, and it is the one to check first. Archived vendors are never watched. A vendor that leaves the scope drops off the watchlist at the next sweep. The exposures already found for it stay in the queue.

What each source checks

A sweep consults five sources. Each one reads only some kinds of watchlist value, and each raises one category of exposure at a severity set by fixed rules. Lookalike checks cover your organization’s own domains. Vendor domains are added only when Lookalike domains for vendors is on.

Sources that need a license

ransomware.live does not allow commercial use without its written approval and a licensed key. Coverbase holds that key for the whole platform, not per organization, so there is no field for your own. Until the key is in place, the source’s switch stays off and shows Needs a platform key, and every sweep lists it as skipped in Sweep History. Once the key exists, the source runs without any change on your side. Have I Been Pwned is used for your organization’s own domains only. Vendor domains are not sent to it, so a vendor never has a Data breach exposure. For a vendor’s known breaches, read Breaches and exposed credentials on its Security tab. RansomLook and Have I Been Pwned publish under the CC BY 4.0 license, which requires credit. Every exposure from them names the source and links back to it.

Large portfolios

Each sweep searches the ransomware trackers’ older listings for at most 150 names and domains, and checks at most 25 domains for lookalikes. Your organization’s values go first in both. Recent leak-site listings are matched against the whole watchlist. Each source also has a few minutes per sweep, and one that runs out of time keeps what it found. Its badge in Sweep History turns amber, and the values it did not reach keep their earlier Last Checked time. Lookalike checks work through the vendors’ domains over the following days, 25 domains per sweep, your own first. With All vendors on a large portfolio, keep this in mind before you read a quiet queue as full coverage.

What no source reads yet

The sources read three types of value: Company name, Domain and Email domain, so those are the types Add asset offers. An older Person name, Email address, Card BIN or Keyword row stays on the watchlist and reads Not searched, as does a company name too short or generic to match on its own, such as “SAP”. The queue’s category filters list only the categories a current source raises.

Switching it on

Do this once, as an administrator. Open Configuration → Monitoring → Dark Web.
The Dark Web configuration page showing the Status card with the Monitoring badge, the enable switch, 117 assets on the watchlist across 28 vendors, Not swept yet, Open the queue and Sweep now, then the Your Organization card with company names, no domains, two email domains and a note on where they come from, and the Vendors card with Vendors monitored in Radar selected and 28 vendors matching that choice.

The settings page with monitoring switched on: the watchlist is built from the organization record and 28 Radar-monitored vendors, and no sweep has run yet.

  1. Under Your Organization, read the Company names, Domains and Email domains. They come from your organization record: its names, the domain of its Website, and its email domains. Change the name and website under Organization settings (the link on the card). Email domains are set when Coverbase creates your organization; to change them, ask your Coverbase account team, or switch an unwanted one off on the watchlist.
  2. If Domains reads None on the organization record., your organization has no website on file. Leak-site matching on your domain and lookalike checks then have nothing to work with for your organization, so add the website first.
  3. Under Vendors, choose who is watched. Read the count underneath, N vendors currently watched., before you rely on the queue.
  4. Leave Lookalike domains for vendors off unless you need it. It adds every watched vendor’s domain to the lookalike checks, and each sweep checks at most 25 domains.
  5. Under Sources, leave switched on the sources you want consulted. Every source that can run is on by default.
  6. Under Status, switch on Enable dark web monitoring.
The lower half of the Dark Web configuration page: the Vendors card with its three scope options, 28 vendors matching the choice and the Lookalike domains for vendors switch, and the Sources card with RansomLook, Have I Been Pwned, Hudson Rock and Lookalike domains switched on and ransomware.live switched off with a Needs a platform key badge.

Who is watched and which sources run. ransomware.live stays off until Coverbase has a licensed key for it.

Every change on this page saves as you make it and rebuilds the watchlist straight away, so the counts under Status and Vendors update. The first sweep happens at the next daily run, at 06:20 UTC. Sweep now runs it immediately. The Status card also reports trouble. The last sweep reported an error appears, with the error, when every source failed on the last sweep. It clears after the next sweep in which a source works.

How an exposure arrives

Every day at 06:20 UTC, Coverbase sweeps each organization that has monitoring on. A sweep does three things:
  1. It rebuilds the watchlist from your organization and vendor records, so a vendor that joined the scope yesterday is checked today.
  2. It asks every switched-on source about the watchlist values that source reads.
  3. It records what came back as exposures, stamps each watched value with the time, and adds a row to Sweep History.
Sweep now, on the queue or on the settings page, runs a sweep immediately. Only one sweep runs at a time for your organization, and a second click reports that one is already running. While a sweep runs, Last sweep reads Running, and the tables refresh when it finishes. Three rules keep the queue from filling with repeats and near misses:
  • One exposure per listing. The same listing found again on a later sweep does not create a new exposure. It moves Last Seen, adds to the seen N times count, and refreshes the evidence.
  • Your decision sticks. A new sighting never changes an exposure’s status. An exposure you resolved stays resolved even if the source keeps reporting it; its Last Seen keeps moving on the Resolved list.
  • Names match cautiously. On a leak-site listing, a domain is the strongest match. A company name matches only as a whole phrase. A name shorter than four characters, or one made only of generic words such as “Global Systems”, never matches on its own, so the domain has to appear in the listing.

The exposure queue

Open Dark Web in the left navigation.
The Dark Web page with five counters (Open exposures, Critical and high, Organization / Vendors, New in the last 7 days, and Last sweep reading Never with 117 assets and 28 vendors), the Exposures, Monitored Assets and Sweep History tabs, the Configuration and Sweep now buttons, the Open and Resolved buttons, severity and subject filters, four category filters, a search box, and an empty table reading No sweep has finished yet, so nothing has been checked.

The queue straight after monitoring was switched on: 117 values are watched, but no sweep has run, so the table is empty and Last sweep reads Never.

Five counters sit at the top. Below them are three tabs, Exposures, Monitored Assets and Sweep History, with Configuration and Sweep now at the right. You see those two buttons only if your role can change the settings and run sweeps. The Exposures table shows Severity, Exposure (the title, with the threat actor underneath when the source names one), Subject (Organization or the vendor), Category, Source, First Seen, Last Seen, Status and Assignee. It is sorted worst severity first, then most recently seen, 50 to a page by default.

Narrowing the queue

  • Open and Resolved switch between exposures still being worked (New, Acknowledged, Investigating) and closed ones (Resolved, False positive).
  • The severity buttons (Critical, High, Medium, Low, Info), Organization and Vendors, and the category buttons below them filter the list. Click a button to apply it and again to clear it. Buttons of the same kind widen the list; buttons of different kinds narrow it.
  • Search exposures matches the exposure title, the matched term, the threat actor and the vendor’s name.
The filters reset when you leave the page. The Open or Resolved choice and an open exposure are kept in the page address, so you can send a colleague a link to one exposure.

Reading an exposure

Click a row to open the exposure in a panel on the right. The header names the subject (your organization, or the vendor with a link to its page), the title, the severity, the status, and the category and source. What Matched holds the facts: Below it, Summary is the source’s description, with anything that looks like a credential, an email address, a card number or a key masked. Evidence lists what else the source returned: counts, malware families, dates and references. What to check first depends on the category:

Triaging an exposure

Decide what each exposure means and record it, so the next person does not check it again.
  1. Open the exposure from the queue or from the vendor’s tab.
  2. In Triage, set the Status, pick an Assignee if someone will follow it up, and write a Note: what was checked, and what was decided.
  3. Click Save review. The panel closes and the queue updates.
From then on the panel shows Last reviewed by, with the name and time of the last save. Any status can follow any other, which is how you reopen a closed exposure. Nothing moves an exposure between statuses on its own, and there is no delete: an exposure leaves the open list only through its status.

Escalating to a finding

When an exposure needs work tracked with an owner and a due date, click Escalate to finding. Coverbase opens a finding:
  • Titled with the exposure’s title, with the source type Dark web exposure.
  • With a description that lists the source, category, severity, matched term, threat actor and reference link, followed by the summary.
  • Assigned to the exposure’s saved assignee, if it has one.
  • On the vendor, for a vendor’s exposure. An exposure about your organization gives a finding with no vendor.
The button then reads Open finding. An exposure has at most one finding, and on the Findings list the finding’s Source column links back to the exposure. From there it is an ordinary finding; see Findings and remediation. Escalating does not change the exposure’s status, and it does not save what you changed under Triage. Save the assignee first if the finding should go to them, and set the status and click Save review afterwards.

Keeping the watchlist right

Make sure the sweep checks the right values, and nothing that belongs to someone else. Open Dark Web, then Monitored Assets.
The Monitored Assets tab listing rows with Subject, Type, Value, Source, Enabled, Open Exposures and Last Checked columns: the organization's company name and two email domains with gmail.com switched off, then company name, domain and email domain rows for vendors such as Honeywell and Zebra Technologies, all Derived, with gmail.com marked Not watched and the rest Not checked yet, with Search assets, Re-derive and Add asset controls.

The watchlist. Every row here was derived from a record, and the gmail.com email domain is switched off because a shared mail provider is not the organization's own.

Each row shows its Subject, Type, Value, Source (Derived from a record, or Manual when someone added it), Enabled, Open Exposures and Last Checked. Search assets matches values and vendor names.
  • Switch a row off with its Enabled switch to stop checking it. Use it for a value that is not really yours or the vendor’s, such as a shared mail provider on the organization record, or a company name that is also an ordinary word. A derived row cannot be removed, because the next rebuild would only add it back. Switched off, it stays off.
  • Derived rows look after themselves. When a record stops producing a value, because a vendor left the scope or was archived or a website changed, the row leaves the watchlist at the next rebuild. Exposures already found stay in the queue.
  • Re-derive rebuilds the derived rows now instead of at the next sweep, and reports how many were added, kept and retired. Use it after you change a vendor’s website or turn on Radar monitoring for more vendors. Changing a setting on the configuration page rebuilds the watchlist too.
  • Add asset watches a value no record provides, such as a second brand’s domain or the domain a vendor runs its customer portal on. Choose what it Belongs To (Organization, or Vendor and then the vendor), its Type and its Value. It is checked from the next sweep on.
  • Remove, the bin icon at the end of a manual row, stops watching that value. Exposures already found for it stay in the queue.
The Add Monitored Asset dialog with Belongs To set to Organization, Type set to Domain, an empty Value field with example.com as its placeholder, a note that spelling, case and punctuation are normalized, and the Cancel and Add asset buttons.

Adding a value by hand. Spelling, case and punctuation are normalized, so a value already on the watchlist is not added twice.

Last Checked is the time of the last sweep in which a source that reads that value finished checking it. A value whose only sources failed, or ran out of time, keeps its earlier time. Not searched means no current source can check the value.

Sweep history

Open Dark Web, then Sweep History. There is one row per sweep, scheduled or manual, including sweeps that found nothing. A source is skipped when it has no key, as ransomware.live does until Coverbase licenses it, or when the watchlist holds nothing it can read. A source switched off in the settings is not listed at all. A failed source reads as failed, never as clean. The other sources’ results still count, and the next sweep tries it again.

The vendor’s Dark Web tab

See one vendor’s exposures without the rest of the queue. Open a vendor, choose Vendor Intelligence, then Dark Web.
The Dark Web tab on a vendor page, under Vendor Intelligence, with Not checked yet at the top right, an Open Exposures section showing a Not checked yet badge and No open exposures, and a Monitored Assets section listing the vendor's company name, a company-name alias, its domain and its email domain, each Derived and Not checked yet.

A watched vendor before its first sweep: its name, a directory alias that happens to be its domain, and the domain as both a web and an email domain, none checked yet.

  • Last checked, at the top right, is the oldest check across the vendor’s watched values. It reads Not checked yet for a watched vendor before its first sweep, and Not watched when nothing a source can search is watched for the vendor.
  • Open Exposures lists everything open for the vendor, with a count per severity. With nothing open it shows Clear once a sweep has checked the vendor’s watched values, Not checked yet before that, and Not watched when nothing searchable is watched for the vendor.
  • Monitored Assets lists the values watched for this vendor, each with its type, Derived or Manual, Disabled when switched off, and when it was last checked. A value with open exposures shows how many are open.
  • Resolved lists closed exposures, and appears only when there are some.
Click an exposure to open the same panel as on the queue, with the same triage and escalation. The tab lists up to 50 open exposures, 50 resolved ones and 50 watched values; for more, search the vendor’s name on the Dark Web page. To add or switch off a vendor’s values, use Monitored Assets on the Dark Web page.
Clear means a sweep checked the vendor’s watched values and nothing is open. It is still only as wide as the sources: before you write “no dark web exposure” into an assessment, check what Monitored Assets lists and when Last checked ran.
The Dark Web tab on a vendor that is not in scope, showing Not watched at the top right and as the Open Exposures badge, No open exposures, and a Monitored Assets note that nothing is being watched for this vendor and how a vendor comes to be watched.

A vendor outside the watched scope. The header and the Open Exposures badge both read Not watched, because nothing a source can search is watched for this vendor.

If the tab reads Dark web monitoring is off, monitoring is switched off for your organization. The tab is part of the newer vendor page, where Vendor Intelligence lists its tabs down the left. If your vendor pages have tabs across the top instead, search the vendor’s name on the Dark Web page. Reviewers also find the tab under Vendor Intelligence when they open a questionnaire submission from the vendor.

Notifications

Dark web monitoring sends no email and no in-app notification. A new exposure appears in the queue and on the vendor’s tab and nowhere else, so someone has to look. The daily sweep runs at 06:20 UTC, so one check a day after that time catches each day’s new exposures. To route new exposures automatically:
  • Workflows. Dark Web Exposure is a trigger record with Created, Updated and Deleted events. See Building a workflow.
  • Webhooks. DarkWebExposure.Created, DarkWebExposure.Updated and DarkWebExposure.Deleted carry dark_web_exposure_id. See the event catalog.
An exposure you escalate becomes a finding, and from then on it follows the findings workflow, including its notifications.

Not the same as Radar or the Security tab

Three parts of Coverbase deal with breaches or the dark web. They do not share a queue, and nothing found by one appears in the others.

Who can do what

Dark web monitoring has its own permission, listed as Dark web exposure in the role editor. Like other vendor-backed permissions, it needs vendor read alongside it. Exposures follow vendor access. A role that can read only some vendors sees those vendors’ exposures, plus every exposure about your organization. The counters at the top of the queue still count the whole organization. Custom roles are built in Permissions and roles.

Troubleshooting

Sanctions screening guide

The neighboring Vendor Intelligence tab: sanctions and watchlist matches, re-checked on a schedule.

Working Radar signals

Which vendors Radar monitors, which is also who dark web monitoring watches by default.

Findings and remediation

What happens to an exposure once you escalate it to a finding.

Security intelligence guide

A vendor’s breaches and lookalike domains as part of its outside-in rating.