Console tour
The console is organized around entities you pivot between: every id and name is a link, each entity page has breadcrumbs and a "Related" rail, and the sidebar groups the screens by intent.
If Umbra cannot reach its exposure data source because of a problem on our side, the pages that show exposure data say Exposure data is temporarily unavailable, with a Contact us link. Our team has already been alerted, and your settings and alerts are safe; there is no Retry, because retrying cannot fix it. When the exposure data source is too busy to answer, the page says reputation feed busy, retry shortly and offers Try again where the page has one. Any other failed load offers Try again where asking again can help.
INVESTIGATE
Overview
Your exposure at a glance, entirely clickable. It opens with your own exposure: a hero card answering "what is my risk?" for the email you signed in with, giving the score ring and posture, how many different breaches your credentials come from, infostealer captures, and first and last seen. The hero covers all sources and is not filtered by the domain you select below it; Open your identity opens you in your own domain's workspace.
Below it:
- six exposure boxes, being total exposure, infostealer captures from botnet data, breach credentials, distinct breaches you appear in, and compromised services, each dated by the latest loaded record, and Resolved, how many of the domain's exposed credentials your team has marked resolved, as M of N beside the feed's total. The first three are exact counts for the whole domain; distinct breaches and compromised services are counted over the records loaded so far and say so ("in the loaded 450 of 400,005"), so they grow when you press Load more. On a domain you have verified a seventh box, Captured on your sites, counts the logins to your own sites that malware captured, whoever signed in; it is shown on its own and never added to total exposure, since the same capture can be in both. It appears a moment after the other boxes: the search of your sites runs once the rest of the page has loaded,
- the most recent breach and most recent capture cards. When the newest capture's victim signed in to your site with a username or an address outside your domains, the capture card shows Captured on your site instead of a detection date,
- the entity lists: top exposed identities, with yours pinned first when the domain shown is your own, and the risk badge on every row, compromised services, top breach sources, and the most-active infected devices. Every row is dated and every row is a pivot. Top exposed identities lists only people Umbra can score; the people captured on your sites are under Your sites in Identities. See Who gets a score.
Investigate
One search box for every entity. Paste:
| You paste | Umbra opens |
|---|---|
| an email | the identity's risk posture |
| a 32-character infection id | the infected device |
| a service host | that service's page |
| a monitored domain | Exposures for that domain |
ENTITIES
The entity directory pages, each covered in Core concepts: Identities, Exposures, Devices, Sources and Services, plus:
- Domains, the domains monitored for your tenant, the DNS-TXT add-domain wizard, and the "authorized domains ready to monitor" banner. See Monitored domains.
- Alerts, the feed of new-exposure notifications. See Alerts and notifications.
ACCOUNT
- Team, to invite teammates, change roles and remove members. See Team and roles.
- Billing, your plan and the Free against Pro comparison. See Plans and billing.
- Notifications, org-wide alert routing: the rules matrix and the channels. See Alerts and notifications.
- Settings, profile and organization, plus personal display preferences such as the theme.
SUPPORT
- Help, the in-console manual: a walkthrough of every screen.
- FAQ, accordion answers grouped into Platform, Monitoring & exposure data, and Pricing & billing.
- Contact us, a form that composes a pre-filled email in your own mail client, addressed to Umbra support with your topic and tenant context filled in. Nothing you type there transits Umbra's backend.
- Feedback, a form that sends a bug report, an improvement idea or general feedback, with an optional screenshot, straight to the product team through Umbra. A confirmation replaces the form once it is received; if it cannot be sent, your draft is kept so you can try again. Any member can send feedback, on every plan. Screenshots are kept for 30 days.