Umbra documentation
Know when your identities leak
Umbra is Identity Risk & Dark Web Monitoring. It watches your domains against breach dumps and infostealer data, scores the risk of every exposed identity, and alerts you as new exposures appear.
See your dark-web exposure
Credentials captured by infostealer malware and identities dumped in breaches and combolists, searched live for your monitored domains. Every record is dated, sourced, and safe to look at, because passwords stay masked.
Pivot, never dead-end
The console is an entity graph, running from an identity to an infection, to the infected device's dossier, to every credential it stole, to the password-reuse blast radius. Every id and name is a link, so an investigation flows instead of restarting.
Get alerted, not flooded
New detections are pushed to Umbra and land in the in-console bell the moment they arrive, plus org-wide routing to email, Slack, and webhooks on the Pro plan, configured once, per event, per channel. Email and Slack arrive as one grouped summary rather than one message per record.
One Wazuh account
Sign in with Wazuh ID, the shared login of the Wazuh ecosystem. Your organization is one tenant everywhere, and the ecosystem rail moves you between services in the same tab.
