Cyber threat intelligence for lean teams

Cyber threat intelligence: know when your company appears on ransomware sites.

Monitor company names and domains with cyber threat intelligence. Review the source, actor, observed date, and category in one dashboard.

Free lookup. No credit card needed. Alert-profile matches are saved in the dashboard for review.

Start with 1 domainRun a free check now without a sales call
Dark web and ransomware recordsSee the title, actor, date and source link
Review matched evidenceUse the dashboard, then query the API when needed
How it works

Turn a company name into a repeatable cyber threat watchlist

Use a company, domain, actor, category, country, or industry to define what the platform should match.

1

1) Define what matters

Add a domain, company name, threat actor, category, country, or industry. At least one criterion is required.

2

2) Review current matches

After creating a profile, search the available archive and inspect each matching threat record.

3

3) Monitor continuously

Review new matching records in the dashboard and Match history.

How to build a watchlist

Start with direct identifiers such as the company name and domains. Add category, country, industry, or actor criteria only when they make the review set more useful. The account owner controls the criteria, and signed-in queries stay scoped to that user.

Financial services example

Use the company name and domains, then add the Financial Services industry or a relevant country to narrow review.

Healthcare example

Use the organization name and domains, then add the Healthcare industry or a relevant threat category.

Technology and SaaS example

Use the company name, product domains, and any actor or category that the team already tracks.

What the production flow looks like

Production index results and quick start

Run the free scan and review the first result from the current production index. The product shows the source title, actor, observed date, and next review step. Create a trial account when you are ready to save a watchlist.

Exposure matchREVIEW
OrganizationMonitored company or domain
CategoryRansomware or dark web mention
EvidenceSource title, actor, observed date and source URL
StatusRequires analyst review
AccessDashboard and Match history
First-party dataset

Threat data highlights: 29,858 records from H1 2026

Explore an interactive cyber threat intelligence study covering records published from January through June. Compare categories, source networks, countries, industries, actor labels, and field completeness.

29,858period-matched threat records
29,853records matched across both sets
6 monthsJanuary 1 through June 30, 2026

Each record reflects one collected source observation. It is not independent proof of a confirmed security incident.

Three de-identified sample records

The public preview omits organization names, raw post bodies, and internal identifiers. These snapshots show the fields used in the aggregate study.

DDoS Attack

PublishedJune 6, 2026
SourceTelegram
ActorNXBB.SEC
CountryThailand
IndustryMental Health Care

Data Breach

PublishedFebruary 18, 2026
SourceOpen web
ActorkillaTheGoat
CountryUSA
IndustryAutomotive

Ransomware

PublishedApril 28, 2026
SourceTor
ActorCL0P
CountryCanada
IndustryBuilding and construction
Data methodology

How the H1 2026 threat data study was built

The public method separates what the source records say from what the data can prove.

1

Collect and select the records

Start with source observations from Telegram, Tor, and the open web. Include records published from January 1 through June 30, 2026 in UTC, and reject publication dates that cannot be parsed into the same period.

2

Match and clean shared fields

Use the collected-record set as the denominator, match it to enriched metadata, and trim leading or trailing whitespace before comparing nine shared fields.

3

State the de-duplication limit

Separate records are not merged when they may describe the same real-world event across different sources. Counts describe records, not confirmed incidents.

4

Run quality and integrity checks

Publish metadata completeness, cross-table consistency, three de-identified examples, aggregate CSV and JSON files, and SHA-256 checksums.

Simple annual plans

Cyber threat intelligence monitoring with API access for workflows

Every plan is a product subscription. The site does not bundle penetration tests, vulnerability assessments, or incident response into these plans. View plans for cyber threat intelligence monitoring.

Detection features

$388 / year
  • 5 alert profiles
  • 1-year rolling feed
  • Search and dashboard
  • Dashboard match history
  • Dashboard match alerts
Start Your Free 14-Day Trial

Defend features

$20,000 / year
  • Unlimited alert profiles
  • Full threat history and export
  • Unlimited API requests
  • Up to 100 API keys
Discuss Requirements
Security and governance

Security controls, data retention, and service limits

Review the controls that are implemented today and the commitments that are not published.

Account and API controls

Passwords are hashed before storage. The application supports passkeys, signed-in sessions, server-side authorization, user-scoped queries, bearer API authentication, hashed API keys, expiration, and revocation.

Data retention

Records are kept as reasonably needed to provide and secure the service, maintain required business records, resolve disputes, and meet legal obligations. Backups and logs may remain after active records are removed. No fixed deletion interval is promised.

Security issue handling

Send suspected vulnerabilities to security@adversemonitor.com with the affected URL, reproduction steps, potential impact, and supporting evidence. AdverseMonitor does not bundle incident response into its monitoring plans.

API limits, warranty, and SLA

Trial keys allow 5 requests per minute and 100 per day. Protection allows 10 per minute and 1,000 per day. Defend has unlimited plan-level requests, subject to authentication, availability, and abuse controls.

No public uptime SLA or service warranty is offered. The service and records are provided as is and as available under the Terms.

FAQ

Frequently asked questions about cyber threat intelligence

What does the free scan do?

It checks the submitted domain against the available exposure data and presents the result on the site. It does not create an alert channel or send customer email.

How is the cyber threat intelligence generated?

The service receives third-party cyber-incident records from an upstream collection layer, makes the received records searchable, and checks newly received records against the criteria in a monitoring profile.

Which data sources are included?

Public product documentation identifies ransomware and extortion leak sites, data-breach and data-leak listings, Telegram channels, Tor sites, and the open web. Source availability and coverage change, and the site does not claim complete collection or vendor-feed coverage.

How accurate are the matches?

A match is an investigation lead, not proof of compromise. Third-party source claims may be false, incomplete, out of date, misattributed, or duplicated. AdverseMonitor does not publish a universal precision or recall figure, so review the source evidence and internal logs before escalation.

How are alerts generated and reviewed?

When a newly received record meets an alert-profile criterion, the match is saved in the signed-in dashboard and Match history for review.

How much historical data can I access?

Trial access covers 30 days. Detection includes a one-year rolling feed, Protection includes a 365-day subscription window, and Defend includes full threat history. See the pricing page for the full comparison.

How does API authentication work?

Documented data routes require a bearer token in the HTTPS Authorization header. Missing, invalid, expired, or unauthorized keys return a JSON error with an appropriate HTTP status.

Which plan includes API access?

Protection includes 10 requests per minute and 1,000 per day. Defend includes unlimited plan-level requests, subject to authentication, availability, and abuse controls. Trial keys allow 5 requests per minute and 100 per day.

Where can I compare pricing and limits?

The public pricing page lists annual prices, alert-profile limits, history windows, export access, API limits, and key limits for each plan.

How are watchlists governed?

The account owner chooses the monitoring criteria. Signed-in routes and data queries check the authenticated user before reading or changing profiles, keys, usage, or support records.

Is this a penetration-testing or incident-response service?

No. The plans shown here cover the monitoring platform and the listed data, export and API limits.

Verify today: check your domain now

Start with 1 domain. Run a free check, then save a watchlist when you are ready.