

Phishing is one of the major attack vectors. When your clients or employees get phished, they receive a link to a website looking like yours. Attackers collect accounts and passwords on the fake website and use those to get into your systems. ShadowTrackr scans the internet for website looking like yours and alerts you when things get phishy. This way you can warn your users in time.

The days when you could ask IT where your data was are over. Anyone can setup a website in a cloud somewhere. Larger organizations often have policies specifying which clouds you can use. We match all your assets against cloud providers and send you a weekly overview. So if you said “Azure West Europe only” and your site appears in Japan West too, you’ll know.

Attackers continuously scan the internet for vulnerable websites and servers, and that includes your assets. We look at your assets in the same way and warn you when we find a weak spot. Note that ShadowTrackr does only passive reconnaissance. We do not fire off any actual exploits (which would be illegal in most countries).

Your hosts can expose unintended information to the internet, like configuration information for Redis or MySQL. Or worse, they might have an unpatched vulnerability exposed to the internet. If so, our scanner nodes flag it as a problem. Not only will this appear as an event an in reports, so can also set custom alerts which sent warning emails or call webhooks.

The good guys on the internet publish many blacklists: hacked servers, spamming servers, C2 servers. If your assets appear on a blacklist, you’re in trouble. Visitors might no longer see your website, and clients no longer receive your emails. We check your assets against these blacklist and alert you when we find something.

Most websites list email addresses. You need to for your business. Attackers know this and gather them. Next, they search dataleaks for matching passwords and try to log in to your systems. ShadowTrackr does the first two steps too, but instead of trying to log in we warn you that you need to change the password.

Just like it is is hard to track your online assets, it is hard to track all suppliers of those assets. ShadowTrackr does that for you in the Supplier Dependency Report. For each supplier we also track where they are European companies or not. If you want to reduce your dependency on non-European countries, this is the report you need.

Mistakes happen. Due to a simple configuration error a database with client data can be exposed to the internet. Or a remote login that should have been behind a VPN is somehow accessible for the entire internet. We continuously scan your assets, track all changes and alert you when things go bad.