Resources
A working glossary, and the research we are writing next.
There is no back catalogue here, because we have not written one yet and filling the page with recycled explainers would waste your time. What is here is the vocabulary: 14 terms you will meet in any dark web, attack surface or brand protection evaluation, defined without the sales gloss.
In progress
The pieces we are writing first
None of these are published yet, so none of them are links. It is the running order of what we think is worth writing down: how the detections actually work, and what to do with a finding once you have one.
- Field guide
What one domain name reveals
A discovery run traced end to end: apex domain in, full asset inventory out, with every attribution decision shown.
Upcoming
- Field guide
How to read a stealer log
What is actually inside an infostealer dump, which fields matter, and how to tell a live session cookie from a dead password.
Upcoming
- Playbook
A takedown, start to finish
Every step from first sighting of a phishing page to registrar suspension, including the evidence each party insists on.
Upcoming
- Explainer
Dangling DNS and subdomain takeover
Why abandoned CNAMEs keep appearing in cloud estates, how they are claimed, and the record hygiene that closes them off.
Upcoming
- Playbook
Triage rules that survive a real SOC
Routing external findings so analysts receive context and an owner, rather than one more queue nobody has time for.
Upcoming
- Explainer
Certificate transparency as an early-warning feed
What public certificate logs tell you about your own estate — and about someone building a login page in your name.
Upcoming
- Buyer's guide
Buying external threat intelligence
The questions that separate original collection from a reskinned data feed, and what a fair proof of value looks like.
Upcoming
- Product note
What onboarding actually involves
What we ask for at kickoff, what the console shows once the first discovery run completes, and which tuning decisions come next.
Upcoming
Glossary
The vocabulary, without the sales gloss
14 terms that come up in every evaluation of tooling like this. If a vendor uses one of them to mean something else, that is worth asking about.
Tags show where a term applies
- Dark webDark Web Monitoring
- Attack surfaceAttack Surface Management
- BrandBrand Protection
- Attack surface
Every point at which an outsider could interact with your systems: domains, IP ranges, exposed services, cloud storage, APIs, SaaS tenants and the credentials that open them. The external attack surface is the portion an attacker can enumerate with no access at all, which is why it is the part worth mapping first.
Applies to: Attack surface
- External attack surface managementEASM
The practice of discovering that external estate from the outside in, attributing each asset to an owner, and watching it for change. It answers “what do we have facing the internet” rather than “is this host we already know about patched”.
Applies to: Attack surface
- Digital risk protectionDRP
The category term for monitoring threats that sit outside your perimeter — leaked data, impersonation, exposed assets, targeted executives. It spans dark web monitoring, attack surface management and brand protection, which is why those three are usually bought together.
Applies to: Dark webAttack surfaceBrand
- Dark web
Sites reachable only through an anonymising network such as Tor or I2P, where stolen corporate data is traded with little fear of removal. In practice the useful intelligence also sits on the clear web next door: paste sites, breach forums, closed Telegram channels and ransomware leak pages.
Applies to: Dark web
- Initial access brokerIAB
A criminal specialist who breaks into an organisation and then sells that access on rather than using it. An advert naming your company — or describing your sector, revenue and VPN vendor closely enough to identify you — is often the last warning before ransomware arrives.
Applies to: Dark web
- Infostealerstealer log
Malware that harvests saved browser passwords, session cookies, autofill data and wallet files from an infected machine and uploads the lot; the resulting file is the stealer log. Because infection usually happens on a personal or unmanaged device, one employee can expose a live corporate SSO session without anything touching your network.
Applies to: Dark web
- Combolist
A plain-text file of email-and-password pairs compiled from many different breaches and stealer logs, then recirculated. Because it is a compilation, an appearance tells you a credential is in circulation but not where it came from — so provenance matters far more than a raw hit count.
Applies to: Dark web
- Credential stuffing
Replaying stolen username-and-password pairs against your login pages at scale, on the assumption that people reuse passwords. It exploits reuse rather than any flaw in your code, so the defences are MFA, detection of anomalous login patterns, and resetting exposed credentials before anyone tries them.
Applies to: Dark webAttack surface
- Typosquatting
Registering a domain one keystroke or one word away from yours: a dropped letter, a swapped top-level domain, an added hyphen, or an appended word such as “login” or “payroll”. The registration itself is cheap and often legal; what follows it is usually phishing, invoice fraud or a fake support page.
Applies to: Brand
- Homoglyph domain
A lookalike domain built from characters that render almost identically to yours, frequently Unicode letters from another script encoded as punycode (xn--…). To someone reading the address bar it can be indistinguishable, so detection has to compare rendered glyphs rather than raw strings.
Applies to: Brand
- Subdomain takeover
What happens when a DNS record still points at a cloud service that no longer hosts anything — a deleted bucket, a decommissioned app, a retired CDN endpoint. Anyone can register the abandoned name at that provider and serve their own content from your subdomain, with a valid certificate to match.
Applies to: Attack surfaceBrand
- Certificate transparencyCT logs
A set of public, append-only logs that publicly trusted certificate authorities write to whenever they issue a certificate. Because the logs are open, they double as an early-warning feed: new hostnames of your own appear there, and so do certificates issued for domains built to impersonate you.
Applies to: Attack surfaceBrand
- Takedown
Getting malicious content removed by whoever has authority over it: the registrar, the hosting provider, an app store, a social platform or a national CERT. Success depends on filing with the right party in the format that party accepts and then chasing it, and how long that takes is decided by the provider rather than by the person filing.
Applies to: Brand
- Shadow IT
Systems that teams stand up without going through IT or security: a campaign microsite, a departmental SaaS trial, a developer's personal cloud account holding production data. It is rarely malicious, but it is unmonitored and unpatched, and it is almost always found from the outside rather than in an asset register.
Applies to: Attack surface
Want these when they land?
We have not built a newsletter and we are not going to pretend otherwise. Use the contact form, write “add me to the research list” in the message box, and you will get one email when a piece publishes. Reply once to stop them.
See your own exposure first.
A demo on your domains, not a canned dataset. Thirty minutes, and you keep the findings either way.
- Scoped to your real estate
- No agent to install
- Findings are yours to keep