← All Netgraph solutions
Dark Web MonitoringExposure & Validation

Your exposure on the dark web, fused into the graph you defend from.

NG-DWM is a licensed add-on under CTEM that watches for your domains, credentials, brand terms and executive names in dark-web feed data — matches every hit against your actual assets and identities, scores whether a leaked credential still works, and publishes findings into the knowledge graph, central alerts, TIP indicators, logs and compliance evidence. Feed-agnostic by design: bring the commercial feed of your choice, or evaluate with the built-in safe simulator.

Licensed add-on under CTEMFeed-agnostic ingestCredential-liveness scoringGraph-fused findingsPublishes to alertsTIPcompliance

What ships in the module

From feed to finding to every module that cares.

01

Licensed, and honest about it

Fully inert unless licensed — the menu auto-hides, the API gates, and background loops skip unlicensed tenants. No half-enabled features, no phantom data collection.

02

Feed-agnostic ingest

Works with commercial dark-web feed providers of your choice — or the built-in safe simulator for evaluation. No live Tor requirement in-product, ever.

03

Matching engine

Domains, credentials, brand terms and executive names matched against your tenant's registered assets and identities — so a hit means your exposure, not internet noise.

04

Credential liveness

Does the leaked credential still work against your identity provider? Checked safely — a still-valid credential is an incident; a long-rotated one is a record.

05

Exposure scoring

Findings are scored and prioritized so a live credential for a privileged identity rises above a stale mention of a marketing domain.

06

Graph fusion

Every finding lands as nodes and edges on the AGE knowledge graph — linked to the identity, the asset, the case — where blast-radius and attack-path analysis can reason over it.

07

Published everywhere

Findings publish into central alerts, TIP indicators, logs and compliance evidence — consumed by the L1 autopilot, detections, hunting and reporting like any other signal.

A finding, end to end

One leaked credential. Matched, liveness-checked, graphed, alerted.

A raw feed record is just text. NG-DWM turns it into an answer: is this ours, does it still work, what could it reach, and who needs to act? The finding carries its match evidence, its liveness verdict, its exposure score and its graph links — then flows into the same alert queue and case flow as every other detection.

  • Matched against tenant assets and identities — not a keyword dump.
  • Liveness checked safely against your identity provider — live credentials jump the queue.
  • Graph edges connect the finding to the identity, its endpoints and its access.
  • Publishes to alerts, TIP, logs and compliance evidence in one pass.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Feed ingestFeed-agnostic intake — commercial providers or the built-in safe simulator (no live Tor in-product)CTEM ▸ Dark Web Monitoring
MatchingDomains, credentials, brand terms, executive names vs tenant assets and identitiesCTEM ▸ Dark Web Monitoring
Credential livenessSafe check of leaked credentials against the tenant's identity providerCTEM ▸ Dark Web Monitoring
Exposure scoringScored, prioritized findings — live privileged credentials firstCTEM ▸ Dark Web Monitoring
Graph fusionFindings become nodes/edges on the AGE knowledge graph, linked to identities and assetsKnowledge graph — read platform-wide
PublicationFindings publish to central alerts, TIP indicators, logs and compliance evidenceConsumed by every module
License gateMenu auto-hides, API gates, background loops skip unlicensed tenants — fully inert when offPlatform licensing

See it live

Bring your feed — or run the simulator. See your exposure on the graph.