{"client_id":"demo","count":5,"alerts":[{"id":"96a7d2c1-eb8c-4060-b117-893f3e326636","created_at":"2026-09-27T16:20:35.735878+00:00","client_id":"demo","findings":[{"id":"be26a883-1e83-425c-9670-b0ad3e7042e7","timestamp":"2026-09-27T10:44:13.081092+00:00","source":"paste_site","source_url":"https://pastebin.com/abc12345","title":"Credential dump on Pastebin mentions client domain","content":"A paste on pastebin.com contains what appears to be a list of email addresses and password hashes. Several entries use the democorp.example domain, suggesting a potential credential leak from the organization.","matched_keywords":["democorp.example"],"severity":"high","client_id":"demo","entity_type":"domain","entity_value":"democorp.example","raw_metadata":{"paste_id":"abc12345"},"false_positive":false,"reviewed":false}],"severity":"high","summary":"Credential dump on Pastebin mentions client domain","description":"Source: paste_site\nSeverity: HIGH\nEntity: domain - democorp.example\nMatched keywords: democorp.example\nURL: https://pastebin.com/abc12345\n\nContent:\nA paste on pastebin.com contains what appears to be a list of email addresses and password hashes. Several entries use the democorp.example domain, suggesting a potential credential leak from the organization.","recommended_actions":["IMMEDIATE: Triage this finding within 1 hour","Review the paste content for leaked credentials","Request paste removal if it contains sensitive data","Rotate any exposed credentials immediately"],"delivered":false,"delivered_at":null},{"id":"b3edea83-b3e1-498b-9b2d-a58c299fa1a8","created_at":"2026-09-27T16:20:35.735651+00:00","client_id":"demo","findings":[{"id":"8aac9bf8-c269-47c3-b896-d36516626adf","timestamp":"2026-09-27T13:44:13.081092+00:00","source":"github","source_url":"https://github.com/example/repo/blob/main/config.env","title":"Leaked .env file with database credentials on GitHub","content":"A public GitHub repository contains a .env file with what appears to be database credentials and API keys associated with the client domain. The repository appears to be a development fork that was made public by mistake.","matched_keywords":["democorp","democorp.example"],"severity":"critical","client_id":"demo","entity_type":"domain","entity_value":"democorp.example","raw_metadata":{"repo":"example/dev-fork","file_path":"config.env"},"false_positive":false,"reviewed":false}],"severity":"critical","summary":"Leaked .env file with database credentials on GitHub","description":"Source: github\nSeverity: CRITICAL\nEntity: domain - democorp.example\nMatched keywords: democorp, democorp.example\nURL: https://github.com/example/repo/blob/main/config.env\n\nContent:\nA public GitHub repository contains a .env file with what appears to be database credentials and API keys associated with the client domain. The repository appears to be a development fork that was made public by mistake.","recommended_actions":["IMMEDIATE: Triage this finding within 1 hour","Review the repository for leaked credentials or sensitive data","If credentials are found, rotate them immediately"],"delivered":false,"delivered_at":null},{"id":"f2e53dea-b9ec-4f47-9691-5bf65119a97c","created_at":"2026-09-27T16:20:35.736222+00:00","client_id":"demo","findings":[{"id":"11dae984-2945-4a2c-9469-bf1bd1a46562","timestamp":"2026-09-26T19:44:13.081092+00:00","source":"certificate_transparency","source_url":"https://crt.sh/?q=democorp.example","title":"New SSL certificate issued for api.democorp.example","content":"A new SSL certificate was issued for api.democorp.example via Let's Encrypt. This may be legitimate but should be verified as no corresponding deployment was announced.","matched_keywords":["democorp.example"],"severity":"medium","client_id":"demo","entity_type":"domain","entity_value":"democorp.example","raw_metadata":{"issuer":"Let's Encrypt","common_name":"api.democorp.example"},"false_positive":false,"reviewed":false}],"severity":"medium","summary":"New SSL certificate issued for api.democorp.example","description":"Source: certificate_transparency\nSeverity: MEDIUM\nEntity: domain - democorp.example\nMatched keywords: democorp.example\nURL: https://crt.sh/?q=democorp.example\n\nContent:\nA new SSL certificate was issued for api.democorp.example via Let's Encrypt. This may be legitimate but should be verified as no corresponding deployment was announced.","recommended_actions":["Review within 4 hours","Verify the certificate was issued legitimately","Check for unauthorized subdomain takeover"],"delivered":false,"delivered_at":null},{"id":"67965b7e-4b9a-464f-89d6-ee7b65deff6d","created_at":"2026-09-27T16:20:35.736063+00:00","client_id":"demo","findings":[{"id":"ac566faf-16aa-4dfc-96d5-81db714f425a","timestamp":"2026-09-27T03:44:13.081092+00:00","source":"reddit","source_url":"https://reddit.com/r/cybersecurity/comments/example","title":"Discussion on r/cybersecurity about Demo Corp security practices","content":"A thread on r/cybersecurity discusses Demo Corp's recent security practices. The thread includes some criticism of their incident response time and mentions potential vulnerabilities in their web infrastructure.","matched_keywords":["Demo Corp"],"severity":"medium","client_id":"demo","entity_type":"company","entity_value":"Demo Corp","raw_metadata":{"subreddit":"cybersecurity","score":42},"false_positive":false,"reviewed":false}],"severity":"medium","summary":"Discussion on r/cybersecurity about Demo Corp security practices","description":"Source: reddit\nSeverity: MEDIUM\nEntity: company - Demo Corp\nMatched keywords: Demo Corp\nURL: https://reddit.com/r/cybersecurity/comments/example\n\nContent:\nA thread on r/cybersecurity discusses Demo Corp's recent security practices. The thread includes some criticism of their incident response time and mentions potential vulnerabilities in their web infrastructure.","recommended_actions":["Review within 4 hours","Assess whether the mention indicates a real threat","Monitor for escalation or additional discussion"],"delivered":false,"delivered_at":null},{"id":"ae365eb2-b751-4b71-add5-1fc724b5af78","created_at":"2026-09-27T16:20:35.736403+00:00","client_id":"demo","findings":[{"id":"a5937dcb-ddd3-4114-8d67-320ddf7700c0","timestamp":"2026-09-24T15:44:13.081092+00:00","source":"domain_monitor","source_url":"DNS: democorp.example","title":"New subdomain detected: dev-democorp.example","content":"A new DNS record was detected for dev-democorp.example. This subdomain was not previously registered and resolves to an external IP address. Possible subdomain takeover risk.","matched_keywords":["democorp.example"],"severity":"medium","client_id":"demo","entity_type":"domain","entity_value":"democorp.example","raw_metadata":{},"false_positive":false,"reviewed":false}],"severity":"medium","summary":"New subdomain detected: dev-democorp.example","description":"Source: domain_monitor\nSeverity: MEDIUM\nEntity: domain - democorp.example\nMatched keywords: democorp.example\nURL: DNS: democorp.example\n\nContent:\nA new DNS record was detected for dev-democorp.example. This subdomain was not previously registered and resolves to an external IP address. Possible subdomain takeover risk.","recommended_actions":["Review within 4 hours","Verify DNS configuration is correct","Check for domain hijacking or unauthorized changes"],"delivered":false,"delivered_at":null}]}