Skip to main content

Exposures

Exposures is the record-level view: every exposed credential the reputation feed holds for the selected monitored domain, searched live. Two kinds of record share the table:

  • Infostealer captures — logins pulled from an infected machine's browsers by malware.
  • Breach & combolist records — credentials from breach dumps and compiled lists.

The KPI cards at the top split the total between the two.

Reading a row

Each row shows the identity (the exposed email or username), the exact service the credential was for, the source, dates, and a masked password tail. Click any row for the detail drawer.

For an infostealer-sourced credential, the drawer grows two extra tabs:

  • Infected device — the machine the malware ran on: OS user, serial, country, IP, antivirus, and the rest of the device dossier.
  • Password reuse — the blast radius: other accounts sharing that password.

Search and facets

The search bar autocompletes across identities, services, and sources. Facets narrow by source and freshness. On the Free plan the facets are Pro-locked; text search and pagination stay live.

Masking — passwords are never fully shown

Umbra never displays a full password. Only the last characters of a password are ever exposed:

  • Free shows identities and emails in full (you always get to know who is exposed) but masks password fragments entirely.
  • Pro shows the real password tail — enough to recognize which password it was — and adds a client-side redact toggle (default off) so you can screen-share safely.

What Free sees here

On Free, the table lists only records older than 30 days. Fresh findings (the last 30 days) appear as a locked teaser strip — a count and an upgrade CTA, not the records. The delay is stated in a banner, not hidden.

Zero is a result

A monitored domain with nothing exposed settles into a positive "No exposed credentials found" state — distinct from the "first scan in progress" state that precedes it. See the first scan.

Switching domains

When more than one domain is authorized, the Domain switcher in the header changes which domain the view searches (default: your own email domain).