Your exposure on the dark web, fused into the graph you defend from.
NG-DWM is a licensed add-on under CTEM that watches for your domains, credentials, brand terms and executive names in dark-web feed data — matches every hit against your actual assets and identities, scores whether a leaked credential still works, and publishes findings into the knowledge graph, central alerts, TIP indicators, logs and compliance evidence. Feed-agnostic by design: bring the commercial feed of your choice, or evaluate with the built-in safe simulator.
What ships in the module
From feed to finding to every module that cares.
A finding, end to end
One leaked credential. Matched, liveness-checked, graphed, alerted.
A raw feed record is just text. NG-DWM turns it into an answer: is this ours, does it still work, what could it reach, and who needs to act? The finding carries its match evidence, its liveness verdict, its exposure score and its graph links — then flows into the same alert queue and case flow as every other detection.
- Matched against tenant assets and identities — not a keyword dump.
- Liveness checked safely against your identity provider — live credentials jump the queue.
- Graph edges connect the finding to the identity, its endpoints and its access.
- Publishes to alerts, TIP, logs and compliance evidence in one pass.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Feed ingest | Feed-agnostic intake — commercial providers or the built-in safe simulator (no live Tor in-product) | CTEM ▸ Dark Web Monitoring |
| Matching | Domains, credentials, brand terms, executive names vs tenant assets and identities | CTEM ▸ Dark Web Monitoring |
| Credential liveness | Safe check of leaked credentials against the tenant's identity provider | CTEM ▸ Dark Web Monitoring |
| Exposure scoring | Scored, prioritized findings — live privileged credentials first | CTEM ▸ Dark Web Monitoring |
| Graph fusion | Findings become nodes/edges on the AGE knowledge graph, linked to identities and assets | Knowledge graph — read platform-wide |
| Publication | Findings publish to central alerts, TIP indicators, logs and compliance evidence | Consumed by every module |
| License gate | Menu auto-hides, API gates, background loops skip unlicensed tenants — fully inert when off | Platform licensing |
See it live
Bring your feed — or run the simulator. See your exposure on the graph.
Works with everything on the graph
CTEM
The parent lifecycle — dark-web findings enter the same scoping, prioritization and mobilization loop as internal exposures.
Explore→Threat Intelligence
DWM findings publish as TIP indicators — ready for detection orchestration across your enabled integrations.
Explore→Compliance & Reporting
Every finding lands as compliance evidence — external-exposure monitoring you can show an auditor.
Explore→