Keep up with account exposure across your institution.
Review institutional domains, staff identities and accounts associated with teaching or research services. Give each finding an appropriate owner.
Create a free account to start investigating.
Staff and administration
staff.example.comLearning platforms
learning.example.netResearch collaboration
research.example.org
See which accounts and services are exposed in your sector.
File lines, not a count of unique accounts.
UpdatedPlaintext passwords, with their account context
Inspect the exposed password alongside the account and, for stealer logs, its service URL. When the source includes plaintext, that detail helps your team scope password resets and investigate exposed access.
Compare plans for plaintext access and included unlock points.
Stealer logs
Connect a captured login to its service URL, username and password to understand which access is exposed.
url:user:passCombolists
Find email/password and username/password pairs, including records without a service URL.
email:passuser:passRaw leak files
Search the text of leaked files, database dumps and unstructured records beyond normalized credential fields.
Dark web forums
Search indexed forum posts for mentions of your organization and examine the discussion's source context.
Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.
An academic address can outlast a role.
A university address appears in a leak, but the person may have changed department or left. Compare the record with your account lifecycle before deciding how to respond.
Where to focus your review
Staff and administration
Start with institutional addresses for administrators, teaching staff and other roles covered by your authorization.
Learning platforms
Review records linked to your teaching service domains, with account ownership checked in your own systems.
Research collaboration
Examine institutional addresses used on external research services and involve the relevant project owner.
From exposure to an assigned follow-up
Search your domain
Sign in and review the employee, third-party and customer categories. Compare matches with the accounts and services you actually use.
Set up monitoring
Get notified via Email, Slack, Discord, Telegram or Webhook when new exposed credentials match your monitored domains or email addresses.
Document and follow up
Use the domain PDF report for an overview and available exports for relevant records. Your team handles account checks and remediation in its own systems.
Before you get started
Do the categories identify students and staff?
No. Domain categories reflect the relationship between email and service domains. Your own directory establishes a person's role.
Can multiple campuses be covered?
Yes. Add authorized campus and institution domains within the monitoring limits of your plan.