Data Breach Intelligence
Security research, threat analysis, and breach intelligence from the xonPlus team.
Latest Insights
Free vs Paid Breach Monitoring: Exactly Where We Draw the Line
Your own domain and inbox are free on XposedOrNot, no card, no account. Other people's domains are xonThreatIntel+. Same breach index on both sides. The whole line, the edge cases, and what the money actually buys.
Employee Credential Monitoring: A Practical Setup Guide
The runbook we'd hand a security lead on day one. Verify every domain you own, route the alerts where your team already looks, work the backlog by password risk. An hour to switch on, on the free route or the paid console.
How to Read a Domain Breach-Health Report
Four tiles, a timeline, a breach table, three closing bullets. What each one counts, what it does not, and the sentence to say to the client for each, in the order that keeps the call calm.
Alert Routing That Doesn't Wake You at 3am
Slack, Teams, or your own webhook, per domain. Three routing patterns, the verification handshake, and the nightly since-poll that makes alerting self-checking.
Stealer Logs, Explained for MSSPs
What a stealer log is, how it differs from a breach dump, and what monitoring for one can honestly tell you. With our own catalog numbers.
Getting started with xonAPI+: from key to first breach check in 15 minutes
One endpoint, one header, JSON both ways. A 15-minute onboarding walkthrough with every command executed live, unhappy paths included.