Cross analyses
Exposure chains
A graph links infected devices, credentials, sessions, lookalike domains, hosts, executives and suppliers; every chain carries its probable origin, its impacts and the playbook that cuts it. Exposure chains link, in one graph, the infected devices, leaked credentials, valid sessions, lookalike domains, exposed hosts, executives, suppliers and breach sources of your perimeter, and give every chain its probable origin, its confidence, its possible impacts and the playbook that cuts it.
The problem
A credential leak, an infected device, a still-valid session and a lookalike domain arrive as four alerts, on four screens, and nobody sees that they are one attack in preparation. The question that matters, where the exposure comes from and what it enables if nobody acts, stays unanswered until the incident. The data to answer it already sits in your client area; what is missing is the links between the pieces.
Client area preview
What you see
Fictional data, for illustration only: no client, no real data.
What you get: the graph of every chain in your client area, recomputed every fifteen minutes, with its probable origin, its impacts and the playbook that cuts it.
- 01
The graph of every chain: devices, credentials, sessions, lookalike domains, hosts, executives, suppliers and breach sources, joined by their relations
- 02
The probable origin and its confidence: infected workstation, third-party breach, password reuse, phishing campaign, supplier compromise or exposed service
- 03
The possible impacts, the recommended playbook and, on every finding, the “linked to” mention pointing at its chains
How it works
Our answer in three steps
Every fifteen minutes, VesperID recomputes from the findings of your perimeter the chains that link causes to consequences: an infected device to the credentials it leaked, to the still-valid session and to the SSO it opens. Every chain is deterministic, capped at twelve nodes, and delivered with its probable origin, its confidence, its impacts and the recommended playbook.
- 01
Chains are built on the services you have activated; the more identities, devices, domains and suppliers the perimeter connects, the more complete the chains.
- 02
Every fifteen minutes, the platform links findings through their relations (same identity, same device, same source, same domain) and computes for every chain an origin, a confidence and impacts. The computation is deterministic: same facts, same chain.
- 03
An analyst reviews the critical chains, confirms or corrects the origin and writes the expected action with the playbook that cuts the chain.
Where this data comes from
A chain has no source of its own: its nodes come from the leaks and stealer logs our partners acquire, from the forums and channels their analysts follow, from certificate logs and from the surface observed continuously; VesperID adds the links, the origin and the confidence.
Our sources in detailCross analyses
What the platform computes on top
This service’s data is crossed with the others’: here are the analyses that come out of it, all visible in the client area.
Discover the platform- 01
The link on every finding
Every finding shows the chains it belongs to, and every chain the findings it links: the graph reads from the inbox as well as from the chain.
- 02
Recommended playbook
Every chain names one of the thirteen playbooks, with its steps in the order in which they cut the exposure: isolate the device, reset, revoke, document.
- 03
Employees involved
The identities in a chain also appear in the exposed-staff analysis, with the recommendation that matches the chain’s origin: device to protect for an infected workstation, access to harden for a reused password.
What you receive
Exposure chains
- 01
The chains of your perimeter in the client area, recomputed every fifteen minutes and kept for ninety days
- 02
One record per chain: graph, probable origin, confidence, possible impacts, playbook, linked findings
- 03
The “linked to” mention on every finding of the inbox, with its chains
- 04
Critical chains reviewed by an analyst, with the expected action
Frequently asked questions
Is a chain proof of an intrusion?
No. A chain links observed exposures and says what they enable if nobody acts; it does not say an attacker walked it. The confidence measures how solid the links are, not the certainty of an incident. That is exactly what makes acting first possible.
Why cap a chain at twelve nodes?
Because past that, a chain stops being readable and stops pointing at one action. When an incident touches more elements, the platform produces several chains, each with its origin and its playbook, rather than one graph nobody reads.
Which services must be active to get chains?
Chains are built on what your services see. Compromised credentials, infected devices and stolen sessions provide the most decisive links; lookalike domains, external surface, suppliers and executives add their own origins and impacts. For an executive profile, chains link their accounts, their devices and the impersonation aimed at them.
Request an exposure assessment.
One hour with an analyst, not a demo: what already circulates about your organisation, what to monitor, what is better left alone. Reply within 24 h.
No public price list: bespoke offering, written proposal after scoping.