DEV Community

Yuhe He
Yuhe He

Posted on

A Free Public-Web Layer for Breach Monitoring (Watchlist, Not Dump Downloading)

Most breach-monitoring setups watchHaveIBeenPwned. That's a consumer database: delayed, curated, and blind to the incidents that matter to targeted work - a SaaS panel leaked yesterday, an admin panel exposed on an ISP network, a Telegram bot token pasted to a public gist.

Here is the free, public-web layer for breach-adjacent signal, and it runs on a laptop.

1. Exposure endpoints, not dumps. The useful public sources are indexed query APIs: leaked-domain and leaked-site lookups, paste-site indexes, and public code-search for secret patterns. Query them on a schedule for the target's domains. You are building a watchlist poller, not downloading 30GB.

2. Public code search is the live one. Secrets land in public repos within minutes of a developer's bad day: AIza (Google keys), glpat- (GitLab), xoxb- (Slack), ghp_/gho_ (GitHub tokens), Telegram bot token format \d+:A[\w-]{33}, AWS AKIA prefixes. Poll code search for your target strings, diff the result set daily. The diff is the alert: new hit = fresh exposure.

3. The dedup that prevents screaming wolf. A key exposed in 200 forks is one incident. Dedupe by (repo owner, secret hash), not by hit count. Alert once per (secret, first-seen repo). Forks are distribution, not new exposure - same lesson as mirror channels.

4. Time-to-remediation is your quality metric. For each unique exposure, track first-seen to removal (commit deleted, repo made private). Median remediation time across an org is a security-posture measurement you can trend monthly, from public data only, with no engagement with the target.

5. Attribution from the exposure itself. Commit author emails (when not noreply), co-authored-by trailers, and the org's commit-email domain convention identify which team leaked, for free. One paste can map an internal team name to a product nobody had linked before.

Scope discipline (the professional part): in bug-bounty scope, an exposed key is a finding, not a conquest. Report it through the program; don't log into anything the secret opens. The monitoring product is the watching, not the touching.

The full pattern list, polling cadence, dedup keys, and alert templates are in the Telegram & Web OSINT Bundle ($5); the free sample brief shows the output format.

Runs free on GitHub Actions - no server, no paid APIs.

Top comments (1)

Collapse
 
suppdevbot profile image
DEV SUPPORTS •

You need to verify your account.

Enter fullscreen mode Exit fullscreen mode

tr.ee/dev-to