For the complete documentation index, see llms.txt. This page is also available as Markdown.

Watchlist Events

Watchlist Events is the continuous alert feed for the assets you monitor. Every detection against a watchlist identifier appears here as an event, ready for review and triage.

Availability: All plans, for the identifiers your subscription permits.

Event-type tabs

A tab strip below the page header filters the feed by event type:

  • All — every event.

  • Leaks — credential leaks from stealer and combolist sources.

  • Mentions — dark web mentions.

  • Exposed Secrets — exposed repository secrets.

The selected tab and sub-tab are reflected in the page URL, so a view can be bookmarked or refreshed in place.

Filters

The toolbar refines the feed by:

  • Identifier — a specific monitored domain, keyword, or watchlist group.

  • Date range — a quick range such as the last 7, 30, or 90 days.

  • Status — open, resolved, or unresolved.

A time-series card alongside the list summarizes event volume over the selected range, with a day, week, or month bucket selector.

Reading an event

Each event is presented as a card with a generated title that states the audience, the action, and the subject, along with the credential count, the entry, tags for type and status, and the affected log-date window. While the feed loads, skeleton placeholders preserve the layout.

Selecting an event opens its detail sidebar, where the full record is available subject to your entitlements.

Status and resolution

Events carry a status so they can be triaged. You can change an event's status as you work through the feed, and filter by status to focus on what remains open.

Exporting

The feed can be exported to CSV under the current filters for offline reporting.

Last updated