Skip to content
Product in development

Resources

A working glossary, and the research we are writing next.

There is no back catalogue here, because we have not written one yet and filling the page with recycled explainers would waste your time. What is here is the vocabulary: 14 terms you will meet in any dark web, attack surface or brand protection evaluation, defined without the sales gloss.

In progress

The pieces we are writing first

None of these are published yet, so none of them are links. It is the running order of what we think is worth writing down: how the detections actually work, and what to do with a finding once you have one.

  • Field guide

    What one domain name reveals

    A discovery run traced end to end: apex domain in, full asset inventory out, with every attribution decision shown.

    Upcoming

  • Field guide

    How to read a stealer log

    What is actually inside an infostealer dump, which fields matter, and how to tell a live session cookie from a dead password.

    Upcoming

  • Playbook

    A takedown, start to finish

    Every step from first sighting of a phishing page to registrar suspension, including the evidence each party insists on.

    Upcoming

  • Explainer

    Dangling DNS and subdomain takeover

    Why abandoned CNAMEs keep appearing in cloud estates, how they are claimed, and the record hygiene that closes them off.

    Upcoming

  • Playbook

    Triage rules that survive a real SOC

    Routing external findings so analysts receive context and an owner, rather than one more queue nobody has time for.

    Upcoming

  • Explainer

    Certificate transparency as an early-warning feed

    What public certificate logs tell you about your own estate — and about someone building a login page in your name.

    Upcoming

  • Buyer's guide

    Buying external threat intelligence

    The questions that separate original collection from a reskinned data feed, and what a fair proof of value looks like.

    Upcoming

  • Product note

    What onboarding actually involves

    What we ask for at kickoff, what the console shows once the first discovery run completes, and which tuning decisions come next.

    Upcoming

Glossary

The vocabulary, without the sales gloss

14 terms that come up in every evaluation of tooling like this. If a vendor uses one of them to mean something else, that is worth asking about.

Tags show where a term applies

Attack surface

Every point at which an outsider could interact with your systems: domains, IP ranges, exposed services, cloud storage, APIs, SaaS tenants and the credentials that open them. The external attack surface is the portion an attacker can enumerate with no access at all, which is why it is the part worth mapping first.

Applies to: Attack surface

External attack surface managementEASM

The practice of discovering that external estate from the outside in, attributing each asset to an owner, and watching it for change. It answers “what do we have facing the internet” rather than “is this host we already know about patched”.

Applies to: Attack surface

Digital risk protectionDRP

The category term for monitoring threats that sit outside your perimeter — leaked data, impersonation, exposed assets, targeted executives. It spans dark web monitoring, attack surface management and brand protection, which is why those three are usually bought together.

Applies to: Dark webAttack surfaceBrand

Dark web

Sites reachable only through an anonymising network such as Tor or I2P, where stolen corporate data is traded with little fear of removal. In practice the useful intelligence also sits on the clear web next door: paste sites, breach forums, closed Telegram channels and ransomware leak pages.

Applies to: Dark web

Initial access brokerIAB

A criminal specialist who breaks into an organisation and then sells that access on rather than using it. An advert naming your company — or describing your sector, revenue and VPN vendor closely enough to identify you — is often the last warning before ransomware arrives.

Applies to: Dark web

Infostealerstealer log

Malware that harvests saved browser passwords, session cookies, autofill data and wallet files from an infected machine and uploads the lot; the resulting file is the stealer log. Because infection usually happens on a personal or unmanaged device, one employee can expose a live corporate SSO session without anything touching your network.

Applies to: Dark web

Combolist

A plain-text file of email-and-password pairs compiled from many different breaches and stealer logs, then recirculated. Because it is a compilation, an appearance tells you a credential is in circulation but not where it came from — so provenance matters far more than a raw hit count.

Applies to: Dark web

Credential stuffing

Replaying stolen username-and-password pairs against your login pages at scale, on the assumption that people reuse passwords. It exploits reuse rather than any flaw in your code, so the defences are MFA, detection of anomalous login patterns, and resetting exposed credentials before anyone tries them.

Applies to: Dark webAttack surface

Typosquatting

Registering a domain one keystroke or one word away from yours: a dropped letter, a swapped top-level domain, an added hyphen, or an appended word such as “login” or “payroll”. The registration itself is cheap and often legal; what follows it is usually phishing, invoice fraud or a fake support page.

Applies to: Brand

Homoglyph domain

A lookalike domain built from characters that render almost identically to yours, frequently Unicode letters from another script encoded as punycode (xn--…). To someone reading the address bar it can be indistinguishable, so detection has to compare rendered glyphs rather than raw strings.

Applies to: Brand

Subdomain takeover

What happens when a DNS record still points at a cloud service that no longer hosts anything — a deleted bucket, a decommissioned app, a retired CDN endpoint. Anyone can register the abandoned name at that provider and serve their own content from your subdomain, with a valid certificate to match.

Applies to: Attack surfaceBrand

Certificate transparencyCT logs

A set of public, append-only logs that publicly trusted certificate authorities write to whenever they issue a certificate. Because the logs are open, they double as an early-warning feed: new hostnames of your own appear there, and so do certificates issued for domains built to impersonate you.

Applies to: Attack surfaceBrand

Takedown

Getting malicious content removed by whoever has authority over it: the registrar, the hosting provider, an app store, a social platform or a national CERT. Success depends on filing with the right party in the format that party accepts and then chasing it, and how long that takes is decided by the provider rather than by the person filing.

Applies to: Brand

Shadow IT

Systems that teams stand up without going through IT or security: a campaign microsite, a departmental SaaS trial, a developer's personal cloud account holding production data. It is rarely malicious, but it is unmonitored and unpatched, and it is almost always found from the outside rather than in an asset register.

Applies to: Attack surface

Want these when they land?

We have not built a newsletter and we are not going to pretend otherwise. Use the contact form, write “add me to the research list” in the message box, and you will get one email when a piece publishes. Reply once to stop them.

Go to the contact form

See your own exposure first.

A demo on your domains, not a canned dataset. Thirty minutes, and you keep the findings either way.

  • Scoped to your real estate
  • No agent to install
  • Findings are yours to keep