External threat intel · DRP

External Threats & Digital Risk Protection

Watch the outside-in too — leaked credentials, dark-web & Telegram chatter, malware/C2 IOCs, ransomware victim posts and look-alike domains, all correlated to your assets and ranked by TALON.

Launch heimdallXAll capabilities

Scanning tells you what an attacker could reach on the assets you own. Digital Risk Protection tells you what's already happening outside your perimeter. heimdallX runs a fleet of pluggable providers — ransomware.live, abuse.ch, OpenPhish and HIBP alongside dark-web and Telegram monitors — normalizes every hit into one record, and correlates it back to your domains and identities. Everything is ranked by TALON, a composite score that fuses exposure, real-world exploitation, weaponization, recency and reach.

heimdallx.ai/appheimdallXPROUpgradeAI analystNew scanSign outAAcme Securityacme-prodCommand centerOverviewExecutive BriefFindings24Remediation7Assets18OperationsDiscoveryAttack Surface5Breach SimThreat IntelMonitoring3Compliance12IntegrationsActivityExternal ThreatsExternal Threats9Threat FeedAI BriefingExternal Threat IntelligenceDRP↻ Collect nowTotal31Matched9Critical5Takedowns2ransomware.liveabuse.chOpenPhishHIBPTelegramThreats · ranked by TALON● monitoringCRITMATCHEDLockBit 3.0 — victim: Acme Corpransomware.live · LockBitTALON 94HIGHMATCHED1,204 acme-corp.com creds in combolistHIBP · credential leakTALON 82HIGHMATCHEDacme-corp-support[.]com look-alikeOpenPhish · brand abuseTALON 74MEDC2 45.77.x.x contacted by an assetabuse.ch · malware IOCTALON 61

One inbox for every outside-in signal

Credential leaks, dark-web and Telegram mentions, malware/C2 indicators, ransomware victim posts and look-alike phishing domains funnel into a single normalized feed. Each record is deduplicated, attributed to a threat actor where known, and flagged the moment it matches an owned domain or identity.

TALON scoring & ATOM attack chains

TALON re-ranks external threats the way exploitability validation re-ranks vulnerabilities — a leaked credential that unlocks an exposed VPN outranks a generic brand mention. ATOM (Account-Takeover Monitoring) draws the line from a leaked identity to the surface it can unlock and produces a prioritized attack chain per correlation.

AI briefing, threat feed & knowledge graph

An AI briefing surfaces the few things to check right now — your worst findings and highest-TALON external threats, deep-linked. The threat feed ships block-ready IOCs and active ransomware-actor profiles, and a knowledge graph maps how actors, sources, identities and your assets connect. Available on Pro and Business.

How it works

1

Collect

Pluggable providers watch leaks, dark web, IOC feeds & ransomware sites.

2

Correlate

Match every hit to your owned domains and identities.

3

Score

Rank by TALON; draw ATOM account-takeover chains.

4

Brief

AI briefing + block-ready threat feed, alerting on what matters.

External intel example
$ drp collect --org acme-corp
→ ransomware.live: LockBit victim: Acme Corp · TALON 94
→ HIBP: 1,204 acme-corp.com creds leaked · TALON 82
→ abuse.ch: C2 45.77.31.9 contacted by asset · TALON 61
ATOM chain: leaked VPN cred → exposed portal → takeover

Put it to work

Run your first scan in under two minutes. Free, no credit card, real findings.

Launch heimdallX
External Threats & Digital Risk Protection — heimdallX