Skip to content

Oscuro exposure monitoring

Oscuro is a paid add-on. It watches domains you have proven you own for identities turning up in breach corpora, stealer logs, pastes and ransomware leak sites, and each finding ends in dated evidence once you close it.

It is set up with us rather than bought online. Pricing depends on the size of your user base, so it is quoted per workspace.

  1. Open Oscuro in the app and add the domain you want watched. Use the registrable domain, lowercased, with no scheme.
  2. Keel gives you a token. Publish it as a DNS TXT record at _oscuro-verify.<domain>, with the token as the value. For example.com the record name is _oscuro-verify.example.com. Some DNS panels want the host on its own, without the domain, in which case enter _oscuro-verify.
  3. Come back and verify. Nothing is queried for the domain until that record resolves. Propagation is usually minutes, and you can re-check as often as you like.

Keel reads that one name and nothing else on the domain. Verification is checked once, when you click verify, so removing the record afterwards does not switch monitoring off. Removing the domain in Keel is what does that.

Two workspaces can verify the same domain. A parent and a subsidiary, or an MSP and its client, both own it, so Keel does not treat that as a collision.

Removing a domain stops monitoring for it. Keel keeps a separate record of what was in scope and when, so a coverage statement about last quarter still checks out after the domain is gone.

Ransomware groups post victims by company name rather than by domain, so leak-site coverage matches on names you add. Add the trading names and subsidiaries you would want to hear about, and turn off the ones that generate noise.

Every finding carries the identity as the source reported it, the source, the breach or leak-site name, the date it happened and the categories the source says were exposed.

Work each one to a close:

  1. Acknowledge it, so the inbox reflects what has been looked at.
  2. Assign an owner. One person is accountable for the reset.
  3. Close it as remediated, with a note saying what was done, or as a false positive.

For a credential or stealer-log finding: force a password reset, revoke existing sessions and tokens, enforce MFA on the account, and reimage the endpoint if the source is a stealer log. Revoking the sessions matters because an attacker working from a stealer log may already hold a valid one, and a password reset on its own does not end it.

A leak-site finding is a criminal group’s claim that it holds your data. Confirm or dismiss it, and close it as a false positive if it turns out to be a name collision or an old post republished.

Closing a finding as remediated files dated evidence against the threat-intelligence controls in your frameworks. Closing it as a false positive files nothing, since nothing was remediated.

A passing monitoring check separately records that Oscuro ran for your workspace. It behaves like every other automated check in Keel and evidences the current state, so it is withdrawn if monitoring stops.

They are two separate artifacts because they go to different readers.

The monthly report is for your auditor. It gives coverage for the period, the findings register, and time to remediate per finding with its closing action. It carries no names: the data it is built from has no name in it, so there is no setting to get wrong.

The affected-user export is for whoever is doing the resets, and it does carry addresses. It has its own gate, and every run writes a row to your audit log recording how many rows were exported and never who was in them.

See Oscuro data handling, which covers what is stored, what is refused, how long it is kept, and what you owe your own staff. Read it before you turn monitoring on.