1) Define what matters
Add a domain, company name, threat actor, category, country, or industry. At least one criterion is required.
Monitor company names and domains with cyber threat intelligence. Review the source, actor, observed date, and category in one dashboard.
Free lookup. No credit card needed. Alert-profile matches are saved in the dashboard for review.
Use a company, domain, actor, category, country, or industry to define what the platform should match.
Add a domain, company name, threat actor, category, country, or industry. At least one criterion is required.
After creating a profile, search the available archive and inspect each matching threat record.
Review new matching records in the dashboard and Match history.
Start with direct identifiers such as the company name and domains. Add category, country, industry, or actor criteria only when they make the review set more useful. The account owner controls the criteria, and signed-in queries stay scoped to that user.
Use the company name and domains, then add the Financial Services industry or a relevant country to narrow review.
Use the organization name and domains, then add the Healthcare industry or a relevant threat category.
Use the company name, product domains, and any actor or category that the team already tracks.
These are setup examples, not preloaded templates. Read the cyber threat intelligence monitoring methodology, security controls, API documentation, or threat intelligence glossary.
Run the free scan and review the first result from the current production index. The product shows the source title, actor, observed date, and next review step. Create a trial account when you are ready to save a watchlist.
Explore an interactive cyber threat intelligence study covering records published from January through June. Compare categories, source networks, countries, industries, actor labels, and field completeness.
Each record reflects one collected source observation. It is not independent proof of a confirmed security incident.
The public preview omits organization names, raw post bodies, and internal identifiers. These snapshots show the fields used in the aggregate study.
The public method separates what the source records say from what the data can prove.
Start with source observations from Telegram, Tor, and the open web. Include records published from January 1 through June 30, 2026 in UTC, and reject publication dates that cannot be parsed into the same period.
Use the collected-record set as the denominator, match it to enriched metadata, and trim leading or trailing whitespace before comparing nine shared fields.
Separate records are not merged when they may describe the same real-world event across different sources. Counts describe records, not confirmed incidents.
Publish metadata completeness, cross-table consistency, three de-identified examples, aggregate CSV and JSON files, and SHA-256 checksums.
Read the full H1 2026 cyber threat data study. You can also download the aggregate JSON and integrity checksums.
Every plan is a product subscription. The site does not bundle penetration tests, vulnerability assessments, or incident response into these plans. View plans for cyber threat intelligence monitoring.
Annual billing. Trial limits are documented on the pricing page. Access the API for threat data feeds when your plan includes it. API use remains subject to authentication and abuse controls.
Review the controls that are implemented today and the commitments that are not published.
Passwords are hashed before storage. The application supports passkeys, signed-in sessions, server-side authorization, user-scoped queries, bearer API authentication, hashed API keys, expiration, and revocation.
Records are kept as reasonably needed to provide and secure the service, maintain required business records, resolve disputes, and meet legal obligations. Backups and logs may remain after active records are removed. No fixed deletion interval is promised.
Send suspected vulnerabilities to security@adversemonitor.com with the affected URL, reproduction steps, potential impact, and supporting evidence. AdverseMonitor does not bundle incident response into its monitoring plans.
Trial keys allow 5 requests per minute and 100 per day. Protection allows 10 per minute and 1,000 per day. Defend has unlimited plan-level requests, subject to authentication, availability, and abuse controls.
No public uptime SLA or service warranty is offered. The service and records are provided as is and as available under the Terms.
See API authentication and rate-limit examples or review the service terms.
Check what the product does, how matching works, which controls are public, and where coverage stops.
It checks the submitted domain against the available exposure data and presents the result on the site. It does not create an alert channel or send customer email.
The service receives third-party cyber-incident records from an upstream collection layer, makes the received records searchable, and checks newly received records against the criteria in a monitoring profile.
Public product documentation identifies ransomware and extortion leak sites, data-breach and data-leak listings, Telegram channels, Tor sites, and the open web. Source availability and coverage change, and the site does not claim complete collection or vendor-feed coverage.
A match is an investigation lead, not proof of compromise. Third-party source claims may be false, incomplete, out of date, misattributed, or duplicated. AdverseMonitor does not publish a universal precision or recall figure, so review the source evidence and internal logs before escalation.
When a newly received record meets an alert-profile criterion, the match is saved in the signed-in dashboard and Match history for review.
Trial access covers 30 days. Detection includes a one-year rolling feed, Protection includes a 365-day subscription window, and Defend includes full threat history. See the pricing page for the full comparison.
Documented data routes require a bearer token in the HTTPS Authorization header. Missing, invalid, expired, or unauthorized keys return a JSON error with an appropriate HTTP status.
Protection includes 10 requests per minute and 1,000 per day. Defend includes unlimited plan-level requests, subject to authentication, availability, and abuse controls. Trial keys allow 5 requests per minute and 100 per day.
The public pricing page lists annual prices, alert-profile limits, history windows, export access, API limits, and key limits for each plan.
The account owner chooses the monitoring criteria. Signed-in routes and data queries check the authenticated user before reading or changing profiles, keys, usage, or support records.
No. The plans shown here cover the monitoring platform and the listed data, export and API limits.
Read the monitoring methodology, pricing and plan limits, or API authentication guide.
Start with 1 domain. Run a free check, then save a watchlist when you are ready.