What is Umbra?
Umbra tells your organization whether its credentials and identities have leaked — in breach dumps, combolists, or the logs of infostealer malware traded on the dark web — and alerts you when new exposures appear.
You sign in with your work email, your domain becomes monitored, and you get:
- an Overview of your exposure posture, opening with your own identity's risk,
- a searchable, paginated table of exposure records for your domains,
- per-identity risk scoring with the breaches and infections behind it,
- device dossiers for the infected machines that captured your credentials,
- alerts the moment a new detection lands (in-console bell, plus email / Slack / webhook routing on Pro).
The exposure data comes from a third-party reputation feed (never named in-product), proxied server-side — your browser never sees vendor credentials, and Umbra never stores more than the findings themselves.
Two kinds of exposure
| Where it comes from | What it tells you | |
|---|---|---|
| Infostealer captures | Malware on an infected machine stole credentials from its browsers | Which device, which browser, when it happened — and every other credential taken from that machine |
| Breach & combolist records | A service was breached, or credentials were compiled and dumped | Which breach or list, which identities of yours appear in it |
Both land in the same Exposures table; each row names the identity, the exact service the credential was for, and a masked password tail.
An entity graph, not a report
Umbra's console is organized around entities you pivot between — Identity, Device, Credential, Source, Service, Domain. Every id and name renders as a link; each entity page carries a "Related" rail so you never dead-end. The canonical flow mirrors an analyst pivot:
identity → risk posture → infection → the infected device's dossier → every credential it stole → the password-reuse blast radius.
See the console tour for each screen, and the Core concepts section for how exposures, identity risk, devices and sources and services fit together.
Part of the Wazuh Labs ecosystem
Umbra is a Wazuh Labs service. It shares the ecosystem's building blocks:
- Wazuh ID — one account for every Labs service; Umbra's sign-in is "Continue with Wazuh ID". See Sign in and activation.
- The Wazuh Hub — where your organization activates services and manages the one shared payment card that all Labs subscriptions bill to. See Plans and billing.
- The ecosystem rail — the icon bar on the far left of the console that moves you between Wazuh services in the same tab.
Plans at a glance
Two plans, no trial: every account starts on Free (historic data only, masked password fragments, no alerts) and upgrades to Pro ($49/mo: real-time data, full records, instant alerts). Entitlements are enforced server-side. Full details in Plans and billing.