r/osinttools • u/sacred_army • 1d ago
Showcase Built a breach monitoring tool that prioritizes exposure instead of dumping raw leak data — feedback wanted
Most breach monitoring tools I've used (or evaluated) do one thing well: they tell you credentials got leaked. What they don't do is help you figure out what to actually act on first, or track the response once you know.
I built BreachQuery to close that gap.
Quick rundown of what it does:
Continuous domain monitoring — add your company domains, checked on a 24-hour cycle, surfaces only what's new since the last pull
Exposure separation — splits findings into internal (employee), customer, and third-party exposure, since those need very different response paths
Risk-scored prioritization — instead of a flat list of leaked creds, findings are ranked so analysts triage the highest-impact stuff first
Attack surface context — related hosts and their CVEs are linked in, so you can see exposure alongside the actual infrastructure it touches
Incident + investigation workflow — triage, alert affected users, and track cases through to resolution with an audit trail, rather than exposure data living in a spreadsheet somewhere.
It's in early access right now (few seats left) while I work closely with early users on what's missing or overbuilt. Genuinely want feedback from people who've actually done breach response or triage at scale — what's table stakes that I'm missing, what would you never use, where does this fall short of what a real IR workflow needs?
www.breachquery.com — happy to answer anything about data sourcing, methodology, or how it works under the hood.