Skip to main content

What Umbra does

Umbra answers one question about an organization: which of its identities have had credentials leaked, and where those credentials turned up. It watches the domains an organization owns and reports every record that names an identity on one of them, as something to follow rather than a line in a report.

Two kinds of exposure​

Every record comes from one of two situations, and the difference decides how far an investigation can go.

Where it comes fromWhat the record carries
Infostealer captureMalware running on a machine copied credentials out of the browsers on itThe identity, the web address the credential was captured on, the machine it was taken from, and the date of the capture
Breach or combolist recordA service was breached, or credentials were compiled into a list and dumpedThe identity, the service the credential was for, and the source that carried it

An infostealer capture names a machine, so everything else that machine leaked is one step away. A breach record names a source, so every other identity in that same breach is one step away. Both kinds land in the same Exposures table, and each row says which kind it is.

The console is built to be walked, not read. An identity, a machine identifier, a service host, a breach source and a domain each open their own view, and the canonical walk runs through all of them: an identity's risk posture names an infection, the infection opens the dossier of the infected machine, the dossier lists every credential that machine took, and one of those credentials opens every other place the same password was seen.

That is why one exposed password is rarely the whole answer. The record names one account. The walk finds the other accounts the same machine, or the same password, also opens.

Where an investigation starts​

The Overview opens with the exposure of the address that signed in, above every organization-wide total. It carries a risk score out of 100, the posture band that score falls into, how many distinct breach sources the address appears in, and how many infostealer captures name it. The tiles and lists below it count the findings loaded for the domain in view.

What the two plans change​

Umbra has two plans. Free reports records older than 30 days, masks password fragments, withholds the identifiers that lead to an infected machine, and raises no alerts on any channel, while Pro removes the delay, returns the full record and turns alerts on. Who is exposed is named on both plans, so the identities are never the part that is held back. See Plans and billing.

Where Umbra sits in the Wazuh ecosystem​

Umbra is one of several Wazuh services that share one account and one organization.

  • Wazuh ID is the account. One Wazuh ID signs in to every Wazuh service, and Umbra has no password of its own. See Sign in and start your workspace.
  • The Wazuh Hub is the front door to the ecosystem. An organization is defined there, and its plan for each Wazuh service is managed from there. See Plans and billing.
  • A workspace is what an organization gets inside Umbra. Everyone from the same organization shares one, so they see the same monitored domains, the same exposures and the same alerts.
  • The rail is the icon bar down the left of the console. Each icon is another Wazuh service, the top one is the Wazuh Hub, and every one of them opens in the same tab.