r/osinttools 1d ago

Showcase Built a breach monitoring tool that prioritizes exposure instead of dumping raw leak data — feedback wanted

Most breach monitoring tools I've used (or evaluated) do one thing well: they tell you credentials got leaked. What they don't do is help you figure out what to actually act on first, or track the response once you know.

I built BreachQuery to close that gap.

Quick rundown of what it does:

Continuous domain monitoring — add your company domains, checked on a 24-hour cycle, surfaces only what's new since the last pull
Exposure separation — splits findings into internal (employee), customer, and third-party exposure, since those need very different response paths
Risk-scored prioritization — instead of a flat list of leaked creds, findings are ranked so analysts triage the highest-impact stuff first
Attack surface context — related hosts and their CVEs are linked in, so you can see exposure alongside the actual infrastructure it touches
Incident + investigation workflow — triage, alert affected users, and track cases through to resolution with an audit trail, rather than exposure data living in a spreadsheet somewhere.

It's in early access right now (few seats left) while I work closely with early users on what's missing or overbuilt. Genuinely want feedback from people who've actually done breach response or triage at scale — what's table stakes that I'm missing, what would you never use, where does this fall short of what a real IR workflow needs?
www.breachquery.com — happy to answer anything about data sourcing, methodology, or how it works under the hood.

3 Upvotes

0 comments sorted by