Fathom
FathomWatch watches infostealer logs for your organization's domains and staff email addresses, alerts your team when credentials turn up, and walks affected employees through recovery. Passwords are masked and never stored in the clear.
From CAD 9.99 per month
Features
- Infostealer log monitoring — Stolen-credential logs from infostealer malware are checked against your detectors as they arrive, so you hear about exposed staff accounts and sites quickly.
- Domain and custom detectors — Monitor your organization's verified domains, plus reviewed custom keyword or regex detectors such as a brand name or internal hostname.
- Personal email monitoring — Monitor up to five of your own email addresses, each confirmed with a code. If one turns up, you get an email with a step-by-step recovery guide.
- Passwords never stored — Only the first few characters of a stolen password are kept so its owner can recognise it; the full secret is never written to disk or shown.
- Recovery guide for employees — Affected employees get an email, sent on your organization's behalf, linking to a step-by-step guide to clean their device and secure their accounts.
- Team triage — Track each exposure from new to investigating to resolved or dismissed, with notes and a history everyone in the organization can see.
- Role-based visibility — Admins and security analysts see the whole organization; everyone else sees only their own exposures. Map your identity provider's groups to roles.
- Webhooks and digests — Push signed JSON to your SIEM or ticketing system, and email scheduled digests with a CSV attached to your security team.
- Single sign-on — Your people sign in with your organization's identity provider; there are no separate FathomWatch passwords to manage.
Know when malware has stolen your people's passwords Infostealer malware quietly copies everything saved in a browser — passwords, session cookies, card details — and the stolen logs are traded on the dark web. FathomWatch watches those logs for the domains your organization has verified and the email addresses you choose, and tells you when one of your people turns up. How it works Add detectors. An org admin picks one of the organization's verified domains to monitor. With a Personal plan, individuals can monitor up to five of their own email addresses, each confirmed with a code. Custom keyword or regex detectors (for example a brand or internal hostname) are reviewed by our team before they go live. We match the data. Each incoming log is checked against every active detector. Your organization receives only the lines its own detectors matched — never the rest of a log, which may belong to other victims. You get an exposure. Each exposure shows the affected account, the sites whose logins were stolen, and a masked password: only the first few characters are shown so the owner can recognise it. The full password is never stored, and a credential that resurfaces later isn't reported twice. Your team acts on it. Exposures move through new → investigating → resolved / dismissed, with notes everyone in the organization can see. Help for the person affected When an employee's work address is found in infostealer data, FathomWatch can email them a link to a step-by-step recovery guide, sent on behalf of your organization with your name and logo. It explains what happened, which sites were affected, how to find and clean the infected device, and — in the right order — how to secure their accounts. The email never contains a password, and the guide needs no sign-in. People who use FathomWatch are always told about their own addresses; org admins decide whether everyone else under your monitored domains is emailed too. Fits into your workflow Webhooks send a signed JSON payload to your SIEM, ticketing system or chat tool when a new exposure arrives, a status changes, or a known credential resurfaces. Scheduled digests email a list of new exposures, with a CSV attached, to the addresses you choose at the times you choose. CSV export of the filtered leak inbox, any time. Who sees what Org admins, and anyone in a group you map to the Security analyst role, see every exposure in the organization. Everyone else sees only exposures of their own address. Exposures of someone's personal addresses stay private to them. What FathomWatch monitors today FathomWatch currently monitors infostealer logs. Combolists, credential leaks, database dumps, social media and dark web pages are being moved over from our previous platform — see the roadmap below.
All products