Sources and services
Two entity types complete the pivot graph: where a credential leaked from, the source, and what it opens, the service. Both have directory pages and detail views, and both are reachable from any exposure row.
Sources, where it leaked
Sources lists the breaches, combolists, and stealer compilations seen in your exposed credentials. Open one to see which of your identities it exposed.
Source names are always shown, on every plan. A breach's existence is public knowledge, and knowing which breach touched you is the minimum actionable fact.
A loaded record the feed sent without a source name belongs to no source, so the page counts those separately ("N loaded records without a source name") rather than leaving them out.
Typical uses:
- A new breach makes the news. Open its source page and know in seconds whether it touched you, and who exactly.
- An identity's risk posture lists its breach sources. Pivot into one to see who else from your organization is in the same dump.
Services, what it opens
Services lists the hosts your credentials were captured for, which covers your own applications, a SaaS tool, a consumer site. Open one to see:
- which of your identities are exposed on it,
- from which machines the credentials were captured,
- how fresh each capture is.
This is the fastest way to answer "who needs a reset on this app?". One service page is a complete, dated reset list.
A service only comes from an infostealer capture, because only the malware records the site a login was stolen from. A breach or combolist record names the breach instead of a site, so it never appears as a service, even when the breach's name looks like a domain. Those records are on Sources. If the loaded records for your domain hold no infostealer captures, Services is empty and says so: look at Sources for the breaches, and at Identities for the per-person infections from each identity's risk profile.
The count on each service card is the number of your identities exposed on that service, not a domain-wide total.
A login captured from an Android app is listed under the app's package
name, such as test.example.chatapp, and its card and service page carry an
Android app tag. The package name is how Android identifies the app, not
a website. The vendor's website, if it was captured too, is its own service:
Umbra does not merge the two, because a package name does not reliably tell
which site belongs to the same vendor.
Password reuse, the blast radius
From a credential that carries a record id, whether an infostealer capture, a breach or a combo list, the password reuse pivot lists the other accounts sharing that password. One capture on one machine can compromise every service where the password was reused. The blast-radius view turns "we reset the leaked account" into "we reset every account that password opens".
Rollups are computed over your exposures
The Sources and Services directories, like Identities and the Overview rollups, are derived from the exposure records loaded for your domain. That is the same slice the Exposures table shows, framed as "seen in your exposures". They are a lens over your findings, not an index of the entire dark web.