Decentralized identity and verifiable credentials, Identity

Too many credential leaks, too little context? SOCRadar connects the dots

Credential leaks, infostealer logs, and exposed personal data do not show up in one place. Analysts often have to pull those pieces together before they can understand how exposed a person really is. SOCRadar has added Human Identity Exposure to its Extended Threat Intelligence platform, giving security teams and analysts a central view of leaked credentials, exposed personal data, and other external signals tied to an individual.

The new identity and access layer pulls information from breach databases, infostealer logs, and threat intelligence feeds into a single record. That gives analysts a faster way to investigate employees, executives, and other high-risk identities without jumping between separate data sources.

A broader identity intelligence approach

The main interface is the Human Identity Exposure Card, which gives analysts a consolidated view of an individual’s exposure. It assigns a risk score based on leaked credentials, sensitive personal data, infostealer activity, and the number of sources in which the identity appears.

Several security vendors already collect and correlate compromised credentials and infostealer records. SOCRadar is positioning the breadth of its identity data as a point of difference.

Brian Costello, vice president of global partnerships at SOCRadar, told MSSP Alert, “Most vendors in this category focus on a relatively narrow problem. They match an email address with a password found in a breach or an infostealer log. While that is valuable, it only tells part of the story."

“SOCRadar takes a much broader identity intelligence approach. Instead of looking at credentials in isolation, we correlate more than 30 different identity attributes associated with an individual across multiple independent data sources. These can include email addresses, passwords, phone numbers, physical addresses, government identifiers where legally available, usernames, crypto wallets, social profiles, and other exposed identity elements.”

The platform connects identity details that may come up across different incidents, like an email address appearing in one breach, a phone number, a home address or a government identifier showing up in another. Bringing those records together helps analysts see whether the problem calls for a password reset or points to a wider risk, such as fraud, impersonation, or account recovery abuse.

“Individually, these pieces of information may not seem critical. However, when correlated across different leaks, they reveal the true level of exposure and the actual risk to an organization,” Costello said. “For example, an email address may appear in one breach, while an SSN or national identifier appears in another, and a home address or phone number in a third. Bringing these together provides a far more complete picture of identity compromise than credentials alone.”

“This enables security teams and MSSPs to prioritize the identities that represent the highest real-world risk, rather than simply generating another list of compromised passwords. The result is more accurate investigations, better prioritization, and faster remediation of identity-based threats.”

External intelligence has limits

Human Identity Exposure can flag potential risks without connecting to a customer’s IAM or HR systems. That makes it easier to deploy, though external data alone cannot confirm whether an account is still active, privileged, or already remediated.

“External-only data cannot, by itself, definitively confirm that an identity is still active, privileged, or remediated. That ground truth lives in your IAM, directory, and HR systems,” Costello said.

“What external data can do is provide strong prioritization signals based on how recent the exposure is, whether it recurs across multiple recent sources, the associated domain and email pattern, and whether the same host shows other active compromise indicators.”

SOCRadar shows the source and age of each exposure so analysts can judge whether a record still requires action. Customers who need internal confirmation can also connect the service to existing security and identity tools.

“We address this gap in two ways. First, we are explicit about recency and source so analysts can make informed judgments. Second, for customers who want a full confirmation loop, we offer integrations into their stack to turn ‘possibly exposed’ into ‘confirmed active and privileged’ or ‘already rotated,’” Costello said.

The platform can also generate a Compromised Data Exposure Report that summarizes leaked credentials, password hashes and exposed personal information. Security teams can use those reports for incident tracking, remediation and communication with business stakeholders.

Pricing aimed at MSSP scale

For MSSPs, identity exposure monitoring could fit into managed detection, digital risk protection or executive protection services. Pricing will be a key factor, especially for providers managing customers with very different employee counts and investigation volumes.

“If cost scales linearly with every monitored identity or investigation, a provider’s margin erodes as they grow,” Costello said. “Our pricing design avoids per-identity or per-lookup metering to ensure it does not penalize your success.”

That pricing model gives MSSPs more flexibility to build the capability into recurring services without costs rising every time they add an identity or run a search. Providers will still need to decide who they monitor, how often analysts review the results, and which remediation steps are included.

Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds