Cyber Watch
Continuous monitoring of CVEs, attack surface, leaked credentials and threat intel
Continuously discover external and shadow assets, track new CVEs against your inventory, and catch leaked corporate credentials before attackers use them.
- External attack surface discovery and monitoring
- Leaked credential detection
- CVE extraction straight from primary sources
What this module does
Cyber Watch continuously identifies and assesses an organisation's IT assets to determine their security posture and potential attack vectors.
It detects and reports corporate account data that has leaked online, helping you secure compromised credentials before they are abused.
It tracks current CVE vulnerabilities and passively identifies affected systems within your network, and provides the latest updates on cybersecurity threats, incidents, and trends to keep you informed.
Cyber Watch in the console
Real screens from the PentestBX platform — swipe or use the arrows to look around.
Attack surface
Geographical distribution of every discovered asset, with an asset count per country.
Everything in Cyber Watch
Each capability is available on its own or combined with the other modules in a single subscription.
Basic Reporting
Consolidates cyber-watch findings into clear, exportable reports that include incident summaries, affected assets, severity ratings, indicators of compromise, and recommended mitigations. Available as PDF/HTML/XLS and pullable via API for SOC workflows.
Notification
Sends immediate alerts for high-risk intelligence — active exploits, public disclosures, targeted campaigns — through email, webhooks, and collaboration platforms. Rules and recipient groups can be tailored by asset, risk level, or playbook.
Scheduling Scanning
Orchestrates recurring intelligence collection and verification on an hourly, daily, weekly, or custom schedule. Schedules respect maintenance windows and retain execution metadata for audit and investigation.
Report Compare
Compares intelligence snapshots and alert runs to highlight emerging threats, resolved incidents, and regressions. Differences can be filtered by IOC type, CVE, affected asset group, and time window.
Cyber Intelligence
Aggregates and enriches threat intelligence from open feeds, commercial feeds, dark web, paste sites, and malware feeds to produce prioritised, contextual alerts. Enrichment includes IP/domain reputation, passive DNS, ASN mapping, and confidence scoring.
Attack Surface Management
Continuously monitors and inventories external and shadow assets — domains, subdomains, cloud services, exposed ports — to identify newly exposed or misconfigured resources, with risk scoring and automated remediation suggestions.
Cyber News
Curates relevant cybersecurity news, advisories, and vendor bulletins tailored to your environment and subscribed assets. News items are correlated with internal exposures and translated into actionable alerts.
Automatic IP Discovering
Automatically discovers public-facing IPs and associated services for monitored domains and cloud ranges using active and passive techniques. New IPs are fingerprinted, risk-scored, and added to the attack surface inventory.
Source-based CVE Extraction
Extracts CVE and vulnerability indicators directly from primary sources — vendor advisories, mailing lists, security blogs, GitHub commits — using source-aware parsers, then matches them to your inventory for prioritised, traceable alerts.
Bring Cyber Watch into your security programme
Size your estate in the configurator and request a tailored quote, or start a trial straight away.




