Skip to main content

Umbra documentation

Know when your identities leak

Umbra is Identity Risk & Dark Web Monitoring. It watches your domains against breach dumps and infostealer data, scores the risk of every exposed identity, and alerts you the moment new exposures appear.

Sign in & activate    What is Umbra?

See your dark-web exposure

Credentials captured by infostealer malware and identities dumped in breaches and combolists, searched live for your monitored domains — every record dated, sourced, and safe to look at (passwords stay masked).

Pivot, never dead-end

The console is an entity graph: identity → infection → the infected device's dossier → every credential it stole → the password-reuse blast radius. Every id and name is a link, so an investigation flows instead of restarting.

Get alerted instantly

New detections are pushed to Umbra and land as alerts: the in-console bell, plus org-wide routing to email, Slack, and webhooks on the Pro plan — configured once, per event, per channel.

One Wazuh account

Sign in with Wazuh ID, the shared login of the Wazuh Labs ecosystem. Your organization is one tenant everywhere, billing rides one shared card managed in the Wazuh Hub, and the ecosystem rail moves you between services in the same tab.

WazuhPart of the Wazuh Labs ecosystem.