Oscuro by Keel GRC
Exposure monitoring that ends in evidence
Oscuro watches the domains you have proven you own and turns what it finds into work with an owner and a date. A finding arrives in a triage inbox, somebody takes it, and closing it files dated evidence against the threat-intelligence controls you already report on. The alert and the proof you acted on it end up in the same place.
Oscuro is priced per workspace by the size of your user base, and is set up with us rather than bought online. Tell us how many people you cover and we will quote it.
What Oscuro does
From the alert to the closed finding
Everything Oscuro monitors is a domain you have proven you control, and a finding moves through these five steps.
-
Domains you proved you own
Add a domain, publish the DNS TXT record Keel gives you, and monitoring starts. Nothing is queried for a domain that has not been verified, so Oscuro cannot be pointed at somebody else.
-
Findings, deduplicated
Each finding carries the identity, the source, the breach or leak-site name, the date it happened and the categories the source says were exposed. The same breach does not re-alert every morning.
-
Leak-site claims stay claims
When a ransomware group posts a company on its leak site, you see the group, the post date and the claim. It is an assertion by a criminal group, and triage is where you confirm or dismiss it.
-
Triage with an owner and a note
Acknowledge a finding, assign who is fixing it, and close it as remediated or as a false positive with what was done. For stolen credentials that means a password reset, revoked sessions and tokens, enforced MFA, and a reimage where the source was a stealer log.
-
Evidence when it closes
Closing a finding as remediated files dated evidence against the threat-intelligence controls in your framework. What an auditor asks about is what you did with the alerts you got.
What Oscuro does not keep
What Keel holds on your behalf
Exposure monitoring means letting a vendor hold records about your staff that came out of criminal breaches. This is how much of that Keel actually holds.
-
Oscuro records that an exposure happened. The database has no column for a password, a password hash, a session token or a raw breach record.
-
Password checking is anonymised. A five-character hash prefix is all that leaves your workspace, and the comparison happens locally, so the password and its full hash never travel.
-
Keel never tests a discovered credential against a live system, including yours, and never opens accounts on leak sites or forums, messages anyone there, or buys data.
If the findings database were stolen in full, it would disclose that an address appeared in a named public breach, and no credential, because there is none in it.
Why it sits inside Keel
The control is already in your framework
-
Closing a finding is the evidence
Your framework already asks you to collect threat intelligence and act on it. Oscuro closes a finding against that control, and the closure is what the auditor reads.
-
A monthly report for the auditor
Coverage for the period, the findings register, and time to remediate per finding with the closing action. It carries no names, because the data it is built from has no name in it.
-
A separate export when a name is needed
Resetting accounts needs the addresses, so that export is a separate action with its own gate. Every run writes a row to your audit log with the number of rows exported.
Put your exposures on the record
Oscuro is an add-on to any Keel workspace. Start the platform free, and talk to us when you want monitoring turned on.
Ransomware leak-site coverage uses data published by RansomLook, licensed under CC BY 4.0.