Monitoring assets
A search answers a question *now*. **Monitoring** keeps asking it for you: you hand the platform an asset to watch — a domain, a brand, a query — and it re-runs the search on a schedule, recording every new hit and notifying you. (In the dashboard this is the **Alerts** section.)How it works
Monitoring is built from a few pieces that fit into a loop:- A monitoring rule ties one data source to one asset. The data source is an alert service — Telegram, leaked credentials, phishing, certificates, ransomware, and the rest of the catalog. The asset is the rule’s
args— the domain, brand, or query you want watched. - The platform runs the rule on its schedule. Each run searches that source for hits new since the rule last ran — so you only ever see fresh exposures.
- New hits are recorded as a match (an incident in the dashboard) and delivered to your email recipients and/or a webhook.
- You read and triage matches, export them, and suppress the false positives with an exclusion list.
- Metrics roll it all up — how much is hitting, on which sources, over time.