🛡️ GuardFox Security Systems Documentation

Dark Web Monitoring

Continuous monitoring of dark web forums, paste sites, breach databases, ransomware blogs, and Telegram channels for mentions of your organisation.

Route: /darkweb
darkweb screenshot

How dark web monitoring works

Overview

How Dark Web Monitoring Works

GuardFox Security Systems continuously scans 47+ dark web and surface web sources for mentions of your monitored assets:

Source typeExamples
Dark web forumsRussian/English cybercrime forums
Paste sitesPastebin, Rentry, paste.ee
Breach databasesHave I Been Pwned, dehashed
Ransomware blogsRansomware group .onion blogs
Telegram channelsThreat actor channels
Code repositoriesGitHub public repos (secrets scanning)

Finding types detected

credential · email · credit_card · api_key · source_code · database_dump · ransomware_mention · executive_mention · pii · domain · ip

Risk scoring

Each finding gets a 0–100 risk score based on: severity of data exposed, source credibility, record count, and whether active exploitation is confirmed.

Adding monitored assets

Setup

Adding Assets to Monitor

Go to Dark Web Monitor → 🎯 Monitored Assets.

Asset types

TypeExampleWhat it finds
Domaincompany.comMentions, credential leaks, source code
Email Domain@company.comCredential dumps, breach records
Keywordcompany ransomwareRansomware group mentions
Executive NameJohn Smith CEOTargeted phishing prep, forum mentions
IP Range192.168.0.0/16IP-based threat actor references
Brand NameGuardFoxBrand impersonation, piracy

Recommended starting set

  1. Your primary domain (company.com)
  2. Your corporate email domain (@company.com)
  3. Names of C-suite executives
  4. Your most critical product/brand names
  5. The word "ransomware" combined with your company name

The more specific your keywords, the fewer false positives.

Generating and scheduling reports

Usage

Generating Dark Web Reports

On-demand report

  1. Click Generate Report (top right)
  2. Choose report type: Executive Summary, Technical Report, Credential Leak, Ransomware Intel, or Full Intelligence
  3. Choose date range (24h / 7d / 30d / 90d)
  4. Select all export formats you need (can select multiple)
  5. Optionally enter email recipients
  6. Click Generate Reports

Export formats

FormatBest for
PDFExecutive briefings, board reports
CSVData analysis, import into Excel
JSONSIEM/SOAR webhook integration
HTMLWeb-viewable interactive report
Word (DOCX)Board reporting, editable
STIX 2.1Threat sharing with partners, Splunk
MISPMISP threat intel platform import

Scheduling recurring reports

Go to 📅 Schedules → Add Schedule: Daily (credential monitoring, executive summaries), Weekly (SOC team technical report), Monthly (board report in DOCX), or Real-time (instant JSON webhook to SIEM on each new finding).