Cross analyses

Exposed staff

Every identity of your domains is aggregated, scored and placed in a cohort, with a single recommendation: to train, device to protect, access to harden, to watch or clean.

Requires the service Compromised credentials

Territory: Identities and access Enterprises

The problem

After a breach, the list of affected addresses does not say what to do for each person. An employee who reuses a password does not call for the same answer as an infected personal device or a privileged account with no proof of a second factor. Training everyone is expensive and does not protect those who matter; training nobody leaves the exposure in place. What is needed is a short, named list, with one measure per person.

Client area preview

What you see

Fictional data, for illustration only: no client, no real data.

What you get: the list of employees per cohort in your client area, with the score, the recommendation, the recorded actions and the CSV export for HR and IT.

  1. 01

    The five cohorts and their headcounts: to train, device to protect, access to harden, to watch, clean

  2. 02

    For every person: the probable role (executive, privileged, standard), the risk score, its reasons and the single recommendation

  3. 03

    The recorded actions (trained, device reinstalled, access hardened, sessions revoked) and the CSV export, cohort by cohort

A limit stated plainly · Our data does not say whether MFA is on: “access to harden” means a usable password is circulating for a sensitive target with no proof of a second factor.

How it works

Our answer in three steps

For every address of your domains, VesperID aggregates what breaches, stealer logs and live sessions reveal, including consumer sites used with the work address, exposed personal data and suspected password reuse. Out of it come a probable role, a score and a single recommendation per person, and the list exports to CSV for HR and IT.

  1. 01

    The analysis starts from the compromised credentials of your verified domains; infected devices, stolen sessions and executive protection enrich every record when they are active.

  2. 02

    The platform aggregates per person: leaks, usable passwords, stealer logs, live sessions, distinct sources, consumer sites, personal data, suspected reuse. It derives the probable role, the score and the recommendation: phishing awareness training, password hygiene, device reinstall and rotation, access hardening, session revocation, executive protection or plain monitoring.

  3. 03

    You record the actions taken; the risk drops, and a new exposure flags the person again. A notification tells you when someone enters a cohort to protect.

The records draw on the leaks and stealer logs our partners acquire (passwords, sessions, consumer sites used with the work address), on the mentions their analysts follow and on the personal data collected on the open web; VesperID aggregates per person without keeping any secret.

Our sources in detail

Cross analyses

What the platform computes on top

This service’s data is crossed with the others’: here are the analyses that come out of it, all visible in the client area.

Discover the platform
  1. 01

    Risk score and takeover class

    Each person’s score builds on the risk computed per identity and its takeover class: possible, likely or immediate depending on usable passwords, infected devices and still-valid cookies.

  2. 02

    Exposure chains

    A person present in an exposure chain shows it on their record, with the probable origin and the playbook; an action recorded on the person has the chain recomputed within minutes.

  3. 03

    Notification when a cohort is entered

    When someone enters “device to protect” or “access to harden”, a notification tells you and the person moves to the top of the list.

What you receive

Exposed staff

  1. 01

    The named list per cohort in the client area, with the score and the recommendation

  2. 02

    CSV export per cohort to organise training sessions and device interventions

  3. 03

    Recorded actions that lower the risk, and a new flag at the next exposure

  4. 04

    A notification when a person enters a cohort to protect

Frequently asked questions

  • Is this a ranking of employees?

    No. A cohort reads as a list of actions to organise, not as a league table. The score measures the exposure observed on the outside, never behaviour at work, and the recommendation is the same for the whole cohort. The probable role (executive, privileged, standard) comes from your declared perimeter and the services touched, not from a judgement.

  • What does “access to harden” mean if you cannot see MFA?

    Exactly what our data allows us to say: a usable password is circulating for a sensitive target (SSO, VPN, mailbox, administration tool) and nothing proves a second factor. If MFA is already in place, the “access hardened” action records it and lowers the risk.

  • Do other services need to be active?

    The analysis requires the Compromised credentials service, which provides the raw material. Infected devices, stolen sessions and executive protection are not mandatory but complete the records: without them, the “device to protect” cohort stays empty and the “executive” role is only set from your perimeter. The service is for organisations; an executive’s own profile belongs to executive protection.

Request an exposure assessment.

One hour with an analyst, not a demo: what already circulates about your organisation, what to monitor, what is better left alone. Reply within 24 h.

No public price list: bespoke offering, written proposal after scoping.