Umbra documentation
Know when your identities leak
Umbra is Identity Risk & Dark Web Monitoring. It watches your domains against breach dumps and infostealer data, scores the risk of every exposed identity, and alerts you the moment new exposures appear.
See your dark-web exposure
Credentials captured by infostealer malware and identities dumped in breaches and combolists, searched live for your monitored domains — every record dated, sourced, and safe to look at (passwords stay masked).
Pivot, never dead-end
The console is an entity graph: identity → infection → the infected device's dossier → every credential it stole → the password-reuse blast radius. Every id and name is a link, so an investigation flows instead of restarting.
Get alerted instantly
New detections are pushed to Umbra and land as alerts: the in-console bell, plus org-wide routing to email, Slack, and webhooks on the Pro plan — configured once, per event, per channel.
One Wazuh account
Sign in with Wazuh ID, the shared login of the Wazuh Labs ecosystem. Your organization is one tenant everywhere, billing rides one shared card managed in the Wazuh Hub, and the ecosystem rail moves you between services in the same tab.
Part of the Wazuh Labs ecosystem.