Dark Web and Credential Exposure Monitoring
Dark Web and Credential Exposure Monitoring is a monthly service that watches your corporate email domains for credentials and data that have leaked into breach corpora, infostealer logs, combolists, paste sites, and the underground forums and marketplaces that a commercial exposure data source can reach — and then does something about every hit. IT Partner correlates each exposure against your Microsoft Entra ID tenant and Entra ID Protection's leaked-credential detections, runs an agreed runbook when a hit involves a live account (forced password reset, session and token revocation, MFA and sign-in review), notifies owners of exposed non-Microsoft accounts, and delivers a monthly exposure report you can hand to an insurer, a board, or a customer who asks whether your credentials are circulating. The service costs $95 per monitored domain per month with no long-term contract. It is deliberately narrow — exposure monitoring and identity response, not a security operations center — and it never claims to see the whole dark web, because nobody can.
What this engagement is
Corporate credentials leak in ordinary ways. An employee registers for a supplier portal or a conference with a work address and reuses a password; that vendor is breached and the pair ends up in a dump. Infostealer malware on a home computer lifts every saved browser password and session cookie, including the ones for Microsoft 365, and the log is sold within days. Old dumps are recombined into combolists and replayed against your sign-in page by credential-stuffing bots. Insurers, boards, and enterprise customers now ask a specific question — are your credentials circulating? — and 'we do not know' is the wrong answer. What we will not do is dress the answer up. Nobody monitors 'the entire dark web'; the underground is fragmented, private, and constantly moving. What exists is a class of commercial exposure data sources that continuously collect breach corpora, infostealer logs, combolists, paste sites, and the criminal forums, marketplaces, and channels their collectors can reach, and match them against the domains you register. Coverage is inherently partial and sometimes lags the leak by weeks. This service uses that class of source, describes it that way, and puts its effort into what is fully within our control: what happens after a hit. Each month — and on alert between months — IT Partner triages every new exposure against your tenant. Does the account exist and is it enabled? Is the exposed password current, or one changed years ago? Has Microsoft Entra ID Protection independently raised a leaked-credential detection for the user? What do the sign-in logs show, and is MFA registered and healthy? Hits involving a live, current credential trigger the runbook you approved at onboarding: force a password reset, revoke refresh tokens and sessions so existing access does not survive the reset, review MFA methods and mailbox rules for signs of tampering, notify the user, and record every step. Exposures tied to non-Microsoft services — a SaaS account registered with a corporate address — get a notification to the account owner with instructions, because the reset there is theirs to do. An optional executive watchlist extends the watch to named individuals, including personal addresses with their written consent, since executives are targeted by name. Every month closes with an exposure report: new and aged hits, what was actioned, what was found to be stale, and the trend — written for the insurer, board, or customer who asked. The boundaries are deliberate. This service does not remove data from the underground — takedowns are rarely possible and never guaranteed, and we do not sell theatre. It is not detection and response: it watches one exposure surface, identities, and acts on it; Multi-Platform MDR is the upgrade path when you want the whole estate watched around the clock. And it is not incident recovery: if a hit reveals an attacker already inside — forwarding rules, fraudulent invoices, sessions from unfamiliar countries — that becomes Business Email Compromise Investigation and Recovery, with the monitoring findings handed over as its starting evidence. It pairs with the controls that make an exposed password much less dangerous in the first place: MFA for every user, and awareness training that keeps the reuse habit down.
Success criteria
What you receive
How the work unfolds
Access is established through GDAP roles you approve — least-privilege, time-bound, never standing global admin. Domains are verified and registered with the exposure data source, the historical lookback is triaged, Entra ID Protection's leaked-credential detection is confirmed to be working for your identities, MFA coverage is checked, and the runbook, its pre-approvals, the response window, and the monthly allowance are agreed in the service order. Historical hits are worked as the first cycle — or quoted as a cleanup if the lookback is large.
New exposures flow in as the data source finds them. Each is correlated against the tenant and classified. Hits on live accounts with current credentials move straight to the runbook; stale and non-existent-account hits are recorded for the report; non-Microsoft exposures generate owner notifications.
For a live hit: the password is reset, refresh tokens and sessions are revoked so already-issued access does not outlive the reset, MFA methods and mailbox rules are reviewed for tampering, the user is notified, and every step is logged. Signs of an attacker already inside are escalated immediately to your incident path — Business Email Compromise Investigation and Recovery, or your MDR provider — with the evidence attached.
Each month we review the leaked-credential detections Microsoft raised for your tenant against the third-party findings, so the two sources cover each other's gaps and no Microsoft-flagged user sits unactioned.
The month closes with the per-domain exposure report and a short review: what appeared, what was actioned, what was stale, what the trend says, and a plain recommendation when the pattern points at a control gap — MFA, password reuse, unmanaged devices — that is a project rather than a monitoring problem.
Prerequisites
Who does what
IT Partner
- Register and verify the domains with the exposure data source and operate the continuous watch.
- Triage and classify every hit against your tenant within the agreed intake window.
- Execute the approved runbook for live hits within the monthly allowance and log every step.
- Reconcile Microsoft Entra ID Protection leaked-credential detections with third-party findings monthly.
- Notify owners of exposed non-Microsoft accounts with clear instructions.
- Escalate signs of active compromise immediately to your incident path, with evidence attached.
- Deliver the monthly exposure report, and name honestly — and quote separately — anything that exceeds the monthly scope.
Your team
- Maintain MFA enforcement and the Microsoft licensing behind Entra ID Protection, and keep password hash synchronization enabled for hybrid identities.
- Pre-approve the runbook and keep the named contact current so response is not blocked on availability.
- Act on non-Microsoft account notifications — resets on third-party services are yours to perform.
- Obtain and maintain consent for any personal addresses on the executive watchlist.
- Engage the incident path — Business Email Compromise Investigation and Recovery or your MDR provider — when we escalate active compromise.
- Review the monthly report and decide on recommendations that require project work.
What's not included
Limitations & technical notes
Frequently asked questions
What is Dark Web and Credential Exposure Monitoring?
A monthly service that watches your corporate email domains for exposed credentials and data through a commercial exposure data source, correlates every hit against your Microsoft Entra ID tenant and Entra ID Protection's own leaked-credential detections, runs an approved runbook — password reset, session and token revocation, MFA and mailbox-rule review — when a hit involves a live account, notifies owners of exposed non-Microsoft accounts, and delivers a monthly exposure report. It costs $95 per monitored domain per month with no long-term commitment.
Who is this service for?
Small and mid-sized organizations that have been asked the question — by a cyber insurer at renewal, a board member after a headline, or an enterprise customer's security questionnaire — whether their credentials are circulating, and want a truthful, evidenced answer every month rather than a shrug. It suits organizations that have MFA in place and want the next layer without the cost of a full security operations center.
Do you monitor the entire dark web?
No, and neither does anyone else, whatever the brochure says. The underground is fragmented, private, and constantly moving. What exists is a class of commercial exposure data sources that continuously collect breach corpora, infostealer logs, combolists, paste sites, and the forums, marketplaces, and channels their collectors can reach, and match them against registered domains. That coverage is large, growing, and inherently partial — sometimes weeks behind a leak. We use that class of source, describe it exactly that way, and put our effort into the part that is entirely within our control: what happens after a hit.
What actually happens when you find one of our credentials?
Triage first: does the account exist and is it enabled; is the exposed password current or long since changed; has Entra ID Protection raised its own detection; what do the sign-in logs show; is MFA registered and healthy. If the account is live and the credential is current, the runbook you pre-approved runs: password reset, revocation of refresh tokens and sessions so existing access does not survive the reset, review of MFA methods and mailbox rules for tampering, notification to the user, and a written record. If the triage shows someone is already inside — forwarding rules, odd sign-ins, changed MFA methods — we escalate immediately to Business Email Compromise Investigation and Recovery or your MDR provider with the evidence attached.
Doesn't Microsoft Entra ID Protection already do this?
Partly, and we use it. Microsoft's leaked-credential detection matches credentials Microsoft's own collection finds against your users — it surfaces in every Entra tier, with full detail on Entra ID P2, and for hybrid identities only when password hash synchronization is enabled. It is a valuable second source, and reconciling it monthly with the commercial feed is part of the service. What it does not do is cover non-Microsoft exposures, monitor executives' personal addresses, run the response runbook, or write the report your insurer asked for. This service adds those, and makes sure a detection Microsoft raised never sits unactioned in the risky-users list.
How is this different from MDR?
Scope and price. Multi-Platform MDR watches your whole estate — endpoints, identities, email, cloud — around the clock, with threat hunting and containment. This service watches one exposure surface, identities, and acts on it, at a fraction of the cost. It is the honest entry point for organizations that are not ready for MDR and the natural upgrade path when they are; if you already have MDR with us, identity-exposure monitoring can be folded into that scope by agreement rather than bought twice.
What is the executive watchlist?
An optional extension that monitors named individuals — typically executives, finance leads, and administrators — as people rather than just as corporate addresses, including personal email addresses with their written consent. Executives are targeted by name, and a personal-account exposure often precedes a corporate one. Watchlist hits go through the same triage and are reported separately, with a discretion protocol agreed at onboarding.
Most of what you find will be old, won't it?
Frequently, yes — and we say so rather than dramatize it. Historical dumps recirculate constantly, and many hits are passwords changed years ago against accounts that no longer exist. Triage exists precisely to separate that noise from live risk, and the monthly report classifies every hit so a reader sees the difference. An old exposure is common and is not, by itself, evidence of compromise; a current one on a live account without MFA is a fire, and the runbook treats it as one.
Can you remove our data from the dark web?
No — and we would be wary of anyone who promises it. Leaked data is copied, resold, and recombined; a takedown of one listing changes nothing about the copies. What can be changed is whether the exposed credential still works: the reset and revocation runbook makes the leak worthless, which is the only reliable form of removal there is.
What is in the monthly exposure report?
Per monitored domain: new hits and aged hits by classification (live and current, live but stale, disabled or non-existent, non-Microsoft service), the actions taken for each with timestamps and approvals, Entra ID Protection detections reviewed, watchlist findings reported separately, the trend over time, and recommendations — plus an honest coverage statement so a reader knows what the sources do and do not see. It is written to drop into a cyber-insurance questionnaire, a board pack, or a customer's security assessment.
Do we need Entra ID P2?
No, but it helps. The commercial exposure feed and the runbook work with any Microsoft 365 licensing. Entra ID P2 — included in Microsoft 365 E5 and EMS E5, or licensed standalone — gives Entra ID Protection's leaked-credential detection its full detail and enables risk-based Conditional Access, which lets the tenant itself force a reset when Microsoft flags a user. We verify what your licensing provides at onboarding and quote any Microsoft costs before you buy anything.
Is the price fixed, and can we stop?
Billing is $95 per monitored domain per month for the domains in the agreed scope, with domains added or removed by service-order change. There is no long-term contract: stop any month, and all we ask is payment of previously approved invoices. The reports, the runbook records, and every reset already performed stay yours.
How quickly can the service start?
The first monthly cycle is the onboarding: GDAP access, domain verification with the data source, the historical lookback, the Entra ID Protection and MFA checks, and the service order with the runbook pre-approvals. If the lookback turns up a large backlog of live hits, that first cycle becomes the cleanup — or is quoted as one if it is unusually large. From the second cycle the service is in steady state, with alerts triaged as they arrive.
What access do you need?
Least-privilege GDAP that you approve — Microsoft's granular, time-bound partner access model. Our default request is Microsoft's standard starter relationship; the runbook's reset and revocation actions need the specific roles for them, requested and approved at onboarding, and nothing more. We never ask for standing Global Administrator, and our default access policy is published so you can compare it against what we actually request.