Monitor underground activity relevant to your organisation.
Selected forums, marketplaces, lawfully accessible messaging communities and ransomware leak sites are monitored for relevant references to authorised brands, domains, executives and third parties. Findings retain available source context for review.

Relevant underground sources
Access offers on forums and messaging channels
Offers may reference sector, geography, access type or an organisation’s infrastructure before related activity is visible through conventional controls.
Ransomware leak sites naming suppliers
A supplier listing may expose contracts, credentials or technical documents relevant to your own risk assessment.
Discussions about people and brands
Executive names, internal tools, leaked documents and access discussions require analyst context to distinguish relevant findings from noise.
How Vigil collects and contextualises relevant activity
Vigil monitors selected, lawfully accessible forums, marketplaces, messaging communities, paste services and leak sites, then correlates observed activity with the authorised customer watchlist.
- 01 · Collect
Forums, markets, messaging channels and leak sites
Selected source content is indexed from monitored forums, messaging channels, ransomware-related sources, paste services and exposed code repositories.
- 02 · Correlate
Your brand, domains, people, vendors
Mentions are matched against your watchlist — including suppliers and subsidiaries — and chained back to the channel, post and actor.
- 03 · Prioritise
Actor, intent, freshness
Known ransomware groups and access brokers score higher than repost bots. 806 tracked actor profiles and 500+ leak-site sources.
- 04 · Act
Alert with available source evidence
Where available, the alert includes a screenshot, channel, timestamp and actor profile, and can be routed to SIEM, SOAR or Teams for analyst review.

Observed underground-channel activity, leak signals and relevant references presented alongside forum and paste-service monitoring.
What changes for your team
Earlier visibility into relevant activity
Access offers and other relevant discussions can be reviewed alongside source context when they are observed.
Centralised analyst review
Vigil maintains monitored source coverage and presents correlated findings without requiring customer analysts to enter each source.
Current third-party signals
Supplier references on monitored leak sites can supplement periodic third-party assessments with more recent evidence.
Questions we get asked
How is source access governed?+
Source selection and collection methods are subject to legal, ethical and operational review. Customers receive correlated findings and available source context without requiring employees to access each monitored source.
Do you cover Turkish-language channels?+
Yes — Türkiye-focused channel and forum coverage is a core part of the collection, alongside international sources.
Can we add our own keywords and vendors?+
Yes. Domains, brands, executive names, product names and suppliers are all first-class watchlist items.
Review underground-monitoring coverage and evidence.
Review representative findings and monitoring coverage. Customer-specific checks are performed only after scope and authorisation are confirmed.
