On this page
Service Overview
DeepSeas' Dark Web Alerting service provides continuous monitoring of an organization's external digital footprint, alerting on emerging threats such as domain, IP, or VIP exposures, new CVEs related to external assets, and potential indicators of compromise discovered on the dark web. A monthly external scan report summarizes findings, risk areas, and recommended remediation actions.
Objectives
- Detect and alert on organizational exposures found on the dark web and related sources
- Identify and report new vulnerabilities (CVEs) affecting external hardware and software assets
- Highlight potential risks from open ports, misconfigured systems, and shadow IT
- Enhance overall situational awareness and proactive threat mitigation
Methodology
- Configure continuous dark web and open-source intelligence (OSINT) monitoring for specified domains, IP ranges, and VIP identitites.
- Collect and analyze data from dark web marketplaces, leak sites, and underground forums for any related exposure.
- Perform monthly external perimeter scans to identify new or changed network assets.
- Correlate scan data with vulnerability databases to identify relevant new CVEs impacting external systems.
- Detect and document open ports, exposed services, and unauthorized or unknown assets ("shadow IT").
- Prioritize findings based on severity, exploitability, and potential business impact.
- Validate alerts for accuracy and remove false positives prior to reporting.
- Generate a consolidated Monthly External Scan Report summarizing all findings and trends.
- Provide tailored remediation and risk-reduction recommendations.
- Review and adjust monitoring parameters quarterly to maintain optimal coverage.
Deliverables
- Monthly External Scan Report summarizing:
- Exposures and intelligence gathered from dark web sources
- Newly identified CVEs affecting monitored assets
- Open ports and shadow IT findings
- Risk ratings and prioritization
- Recommended remediation actions
- Alert Notifications (as applicable) for critical or high-severity findings between monthly reports.
- Quarterly Service Review Summary (optional, if included in engagement scope)
Service Assumptions
- Service is limited to non-intrusive, legally compliant dark web and OSINT data sources
- Reports are provided electronically (PDF or CSV) via a secure delivery method
- Client is responsible for implementing remediation actions and internal follow-ups
- Real-time alerting or integration with SIEM platforms may be available under a separate agreement
Client Responsibilities
- Client will provide an initial inventory of domains, IP ranges, and VIP names for monitoring
- Client will ensure necessary authorization for all external scanning and data collection activities

Back to Service Library