O2 Intel builds O2 Radar — continuous credential-exposure monitoring that scores every leak by how much it actually matters, catches stolen credentials on employee machines before they leak, and pages you only on what's new.
A provider tells you a credential exists. It doesn't tell you whether it matters. Radar scores every finding multiplicatively and shows the breakdown — so an analyst can challenge the number instead of trusting it.
leaked@acme.com · gmail · 3 years ago and admin@acme.com · vpn.acme.com · last Tuesday land worlds apart on the graph. Radar weighs each one on the factors that decide an incident.
Every part of Radar is built to cut false urgency and surface the one thing that matters.
A batch probe opens every scan. If nothing new landed, the whole estate costs a single request — steady state is nearly free.
Multiplicative factors with a visible breakdown. Two hundred stale customer leaks can't outrank two live VPN credentials.
Slack, HMAC-signed webhook, or email — each with its own threshold. A 200-finding backlog is one message, identities masked.
Pivot from a finding to the same identity elsewhere. One identity across five hosts usually means an infected endpoint.
Who owns a host and what it's for — registration facts plus a grounded, cited web summary. Queried about the domain, never fetched from it.
Catch a credential on the employee's machine before it leaks — and nudge anyone about to save one into the browser.
Finding exposure is the easy part — knowing what to do about it is the job. O2 Radar uses AI to turn every signal into something a person can act on, and quietly falls back to written-in templates whenever AI isn't available. Every answer is labeled with what produced it.
Domain monitoring catches a credential after it leaks. The O2 Radar agent catches it before — counting the local stores an infostealer harvests: browser vaults, cleartext files, notes apps, .env files, SSH keys, cloud credentials.
It reports where and how much — never the contents. And when someone saves a password into their browser, it reacts within seconds.
Comment on every save, in real time. Try saving a password →
Attackers register lookalikes of your domain to phish your staff and customers. O2 Radar hunts typosquats, homoglyphs and cloned login pages — and flags the ones actually armed to attack: mail configured, a fresh cert, your login page copied.
The whole product is built on one rule: it reports where credentials sit, never what they are.
Point O2 Radar at the domains you own and watch what surfaces. No agent to deploy for the first scan; endpoint coverage whenever you're ready.