Cyber Intelligence Platform

See what attackers already know about you.

Real-time credential monitoring, stealer log investigation, and attack surface mapping. Built for security teams who refuse to be the last to know.

34B+
Leaked credentials indexed
4.5B+
Infections detected
24/7
Continuous monitoring
Trusted by
Government agencies Defense forces National banks Insurance corporations Fintechs Energy sector
The threat landscape
Your credentials are already out there.
The question is: do you know which ones?
We index billions of compromised records across stealer logs, dark web marketplaces, underground forums, and paste sites. This is the data attackers use. Now you can use it too.
34.000M+
Credentials indexed
4.000M+
Infections detected
195
Countries
17
API endpoints
How it works
From zero to cyber intelligence
in three steps.
No complex deployments. No infrastructure to manage. Start seeing results in minutes.
1

Register your assets

Add your organization's domains and email patterns. It takes less than 30 seconds. No agents, no sensors, no code.

2

We scan everything

Our engines continuously crawl stealer logs, dark web forums, paste sites, combo lists, and leak databases. 24×7, without you lifting a finger.

3

Act on cyber intelligence

Get instant alerts, investigate exposures in depth, generate executive reports, and push data to your SIEM via API. Remediate before attackers exploit.

Platform
Six intelligence modules.
One unified platform.
From credential leaks to stealer logs to ransomware victim lists — investigate the full spectrum without switching tools.

Cyber Intelligence

Search compromised credentials by organization, domain, or individual account. Automatic classification into employees, third parties, customers. Password strength scoring.

Core module

Stealer Log Investigation

Access raw infostealer logs with file-level browsing. Unlock individual entries to see session tokens, browser cookies, saved passwords, and device context.

Premium

Surface Exposure

Map your attack surface from leak data. Discover subdomains, exposed paths, and infrastructure that attackers have already found — without active scanning.

Intelligence

Domain Intelligence

WHOIS, DNS records, subdomain enumeration, port scanning, and technology stack detection. Complete domain reconnaissance in one click.

Intelligence

Continuous Monitoring

24×7 automated surveillance of your critical domains. Email alerts the moment new compromises appear. Full run history and delta tracking.

Always on

REST API & Automation

17 endpoints, 6 language SDKs, interactive Playground. Integrate with your SIEM, SOAR, or ticketing system. Bearer token auth with scoped permissions.

Developer
Product
Intelligence workspace
that speaks your language.
Clean, dark-first interface designed for security analysts. Every pixel serves a purpose.
app.cybersight.io
Tokens: 4,832
Org credentials
Account passwords
Domain credentials
Illicit networks
Surface exposure
Domain intel
Employees
Website and email domains both match the searched term.
ACCOUNTS342
45 Strong89 Medium134 Weak74 V.Weak
Third Parties
Email domain matches, website domain differs.
ACCOUNTS891
120 Strong245 Medium310 Weak216 V.Weak
Customers
Website domain matches, email domain differs.
ACCOUNTS1,247
187 Strong362 Medium423 Weak275 V.Weak
Others
No direct match with the searched domain.
ACCOUNTS467
78 Strong134 Medium156 Weak99 V.Weak
EmployeePassword • Weak2026-03-08
[email protected] — stealer-log
Username / Email[email protected]
Password••••••••
Websiteportal.acme-corp.com
Sourcestealer-log
Imported2026-03-08
Strength3/10
Third PartyPassword • Strong2026-03-07
[email protected] — combo-list
Username / Email[email protected]
Password••••••••••••
Websiteslack.com
Sourcecombo-list
Imported2026-03-07
Strength9/10
CustomerPassword • Very Weak2026-03-06
[email protected] — stealer-log
Username / Email[email protected]
Password•••••
Websitewebmail.acme-corp.com
Sourcestealer-log
Imported2026-03-06
Strength1/10

Public Search

Search for leaked credentials or infections by domain.
Org credentials
Illicit networks

Analytics dashboard snapshot

acme-corp.com
Compromised Accounts 2,947
Employees
Website and email domains both match the searched term.
ACCOUNTS342
45 Strong89 Medium134 Weak74 V.Weak
Third Parties
Email domain matches, website domain differs.
ACCOUNTS891
120 Strong245 Medium310 Weak216 V.Weak
Customers
Website domain matches, email domain differs.
ACCOUNTS1,247
187 Strong362 Medium423 Weak275 V.Weak
Others
No direct match with the searched domain.
ACCOUNTS467
78 Strong134 Medium156 Weak99 V.Weak
FilePathExtIngestedStatusAction
passwords.txt/ACME-PC_2026-03-05/Browsers/Chrome/txt2026-03-05 Unlocked View
autofill.json/ACME-PC_2026-03-05/Browsers/Chrome/json2026-03-05 Unlocked View
cookies.sqlite/ACME-PC_2026-03-05/Browsers/Firefox/sqlite2026-03-05 Locked View
system_info.txt/ACME-PC_2026-03-05/System/txt2026-03-05 Unlocked View
credit_cards.txt/ACME-PC_2026-03-05/Browsers/Chrome/txt2026-03-05 Locked View
File Browser — ACME-PC_2026-03-05
Browsers/
Chrome/
passwords.txt
autofill.json
cookies.sqlite
Firefox/
System/
Screenshots/
1https://portal.acme-corp.com/login
3S3cur3P@ss!2025
4
5https://mail.acme-corp.com
7S3cur3P@ss!2025
8
9https://slack.com/signin
11Sl@ckP@ss_2024
12
13https://github.com/login
14jmartinez-dev
15G1tHub!!2025
1,247,831
Total Posts
84
Sources
2h ago
Latest Post
2019-04
Oldest Post
Search
Simple Advanced
Results: 2,341 Page 1 of 47
Database dump — acme-corp.com users table (342k rows)
BreachForums Cached
Full SQL dump of users table including email, hashed passwords (bcrypt), full names, registration dates. 342,891 rows total. Sample: [email protected] | $2b$12$kX...
ACME Corp internal VPN credentials + RDP access for sale
XSS.is Cached Truncated
Selling initial access to ACME Corp network. Fortinet VPN + 3 RDP endpoints. Revenue $2.1B. Proof attached. Price: $15,000 for exclusive...
Stealer logs — acme-corp.com & acme-bank.com sessions
Russian Market
Fresh stealer logs from RedLine and Raccoon campaigns. Contains session cookies, saved passwords, and autofill data for acme-corp.com portal and acme-bank.com...
[LEAK] Employee PII — ACME Corp HR database
Exploit.in Cached
HR database export — 1,200 employees. Fields: full name, national ID, salary, personal email, phone, home address. Format: CSV. Verified sample included...
1 2 3 ... 47

Reports

Generate comprehensive intelligence reports for any asset.
PDF
Report Sections
Org credentialsInternal usernames and domains
Domain credentialsURLs referencing the asset
Account passwordsUsernames matching asset pattern
Illicit networksStealer logs and related sources
Domain intelligenceTop subdomains and paths
Surface exposureIPs, ports and services scanned
Queued reports will continue processing even if you navigate away.

Report Jobs

JobAssetFiltersDate RangeStatusCreatedActions
#RPT-00847acme-corp.comOrgDomainIllicitJan 1 – Mar 10 Completed2026-03-10 PDF
#RPT-00846acme-bank.comOrgSurfaceFeb 1 – Mar 10 Completed2026-03-09 PDF
#RPT-00845acme-corp.comAllDec 1 – Feb 28 Processing2026-03-09 Pending
#RPT-00844portal.acme.uyDomainIllicitJan 15 – Mar 1 Completed2026-03-08 PDF
API Explorer
Playground
API Keys
Base URL https://app.cybersight.io/api/v1
Account 2
GET /account/me
GET /account/quota
Credentials 4
POST /search/advanced
POST /search/domain
GET /search/stats
POST /search/bulk
Stealer 3
POST /stealer/search
GET /stealer/file/{id}
GET /stealer/browse/{id}
Monitoring 4
GET /monitor/list
POST /monitor/create
GET /monitor/activity
POST /monitor/toggle
Export 2
POST /export/csv
POST /export/json
POST /search/advanced 2 tokens/term

Search across all credential databases with advanced filters. Supports pagination, date ranges, and field-level filtering.

Parameters
NameTypeRequiredDescription
querystringREQUIREDDomain, email, or keyword
pageintPage number (default: 1)
page_sizeintResults per page (max: 100)
date_fromstringISO date filter start
email_tldarrayFilter by TLD (e.g. ["uy","br"])
Request Body
JSON
1  {
2    "query": "acme-corp.com",
3    "page": 1,
4    "page_size": 25,
5    "date_from": "2025-01-01",
6    "email_tld": ["com", "uy"]
7  }
Response 200 OK
JSON
1  {
2    "status": "success",
3    "data": {
4      "total": 2947,
5      "page": 1,
6      "results": [
7        {
8          "email": "[email protected]",
9          "password": "••••••••",
10         "source": "stealer-log",
11         "strength": 3
12        }
13      ]
14    },
15    "tokens_used": 2
16  }
Live API Playground
Requests consume real tokens
POST
https://app.cybersight.io/api/v1
nxk_a3f8...x9z2 (SIEM Integration)
{
  "query": "acme-corp.com",
  "page": 1,
  "page_size": 10
}
200 OK 142 ms
1  {
2    "status": "success",
3    "data": {
4      "total": 2947,
5      "page": 1,
6      "results": [ /* ... 10 items */ ]
7    },
8    "tokens_used": 2
9  }

API Keys

v1
KeyNameStatusRate LimitLast UsedExpiresActions
nxk_a3f8...x9z2SIEM Integration Active60/m2 min ago2026-06-10 Revoke
nxk_7b2e...m4k1Python Script Active120/m1 day ago2026-09-01 Revoke
nxk_9c4d...p8w3Monitoring Bot Revoked60/m2026-02-15 Delete
Generate New Key
60 req/min
90 days
Use cases
Built for every team
in the security operation.
Whether you're running a SOC, responding to incidents, or conducting offensive assessments — Nx CyberSight adapts to your mission.

Cyber Threat Intelligence

Continuous intelligence collection from stealer logs, underground forums, and dark web marketplaces.

Automated classification

Every credential auto-classified as Employee, Third-party, Customer, or Other based on domain matching.

6 search modalities

Org credentials, domain, account, illicit networks, surface exposure, and domain intelligence.

Strength distribution

See password strength breakdown across your entire exposure. Prioritize weak-password accounts.

24×7 monitoring

Continuous surveillance with email alerts when new compromises appear for your domains.

Incident Response & Forensics

When a leak hits, get answers in seconds. Search by domain, email, or keyword to understand scope.

Instant scope assessment

Search your domain and know within seconds how many credentials are exposed and where.

Stealer log forensics

Unlock raw stealer data: session tokens, cookies, browser history.

PDF evidence reports

Generate branded reports with full credential listings, strength analysis, and timeline.

CSV export for triage

Export up to 1,000 records for mass password resets or SIEM ingestion.

Brand & Executive Protection

Monitor executive credentials, detect impersonation infrastructure, and track your brand's exposure.

Executive credential watch

Know if C-suite emails appear in any leak or stealer log.

Domain impersonation

Reveal phishing infrastructure and lookalike domains.

Illicit network monitoring

Track if your brand appears in underground forums and marketplaces.

Continuous alerts

24×7 monitoring with immediate email notification.

Offensive Security & Red Team

Reconnaissance at scale using the same data sources that real attackers use.

Credential harvesting

Find real username:password pairs. Test password reuse and spray attacks.

OSINT reconnaissance

Subdomains, ports, technologies without active scanning.

Session hijacking data

Active session tokens and cookies from stealer logs.

API-driven automation

17 API endpoints. Bulk search up to 10 domains per request.

Compliance & Audit

Demonstrate security posture to auditors and regulators.

Executive PDF reports

Branded briefings for board presentations and regulatory submissions.

Complete audit trail

Every action logged with user, timestamp, IP, and result count.

RBAC governance

38 permissions, 13 roles, multi-org isolation.

Continuous evidence

24×7 monitoring history provides timestamped evidence.

MSSPs & Service Providers

Multi-tenant architecture for managed service providers.

Multi-tenant isolation

Unlimited orgs with separate assets, tokens, and permissions.

White-label ready

Deliver intelligence under your brand. Co-branded reports.

API at scale

300 req/min, bulk search, CSV export.

Partner economics

30-40% margin. IR hours, training, QBR included.

API & integration
Automate everything.
17 endpoints. Your language.

Developer-first design

Full REST API with Bearer token authentication, rate limiting, and scoped permissions. Integrate cyber intelligence into your SIEM, SOAR, ticketing system, or custom workflows.

17
Endpoints
300
Req/min max
6
Languages
cURLPythonJavaScriptPHPGoC#Java
search_credentials.py
# Search compromised credentials for your domain
import requests

response = requests.post(
    "https://api.cybersight.io/search/credentials",
    headers={
        "Authorization": "Bearer nxk_your_api_key",
        "Content-Type": "application/json"
    },
    json={
        "term": "acme.com",
        "page": 1,
        "per_page": 50
    }
)

data = response.json()
print(f"Found {data['stats']['total']} compromised credentials")

for cred in data["data"]["results"]:
    print(f"  {cred['username']} | {cred['strength_label']}")
Coverage
Deep intelligence across
21 Latin American countries.
The only CTI platform built from the ground up for LATAM. Localized threat feeds, regional pricing, and a team that speaks your language.
🇩🇴
Dominican Rep.
184.9M
infections
🇨🇴
Colombia
33.9M
infections
🇧🇷
Brazil
21.5M
infections
🇻🇪
Venezuela
20.5M
infections
🇨🇱
Chile
13.1M
infections
🇨🇷
Costa Rica
9.7M
infections
🇵🇪
Peru
7.6M
infections
🇲🇽
Mexico
6.9M
infections
🇦🇷
Argentina
6.6M
infections
🇬🇹
Guatemala
5.7M
infections
🇵🇦
Panama
3.5M
infections
🇳🇮
Nicaragua
3.3M
infections
🇪🇨
Ecuador
3.0M
infections
🇵🇷
Puerto Rico
2.8M
infections
🇧🇴
Bolivia
1.8M
infections
🇵🇾
Paraguay
1.8M
infections
🇨🇺
Cuba
1.3M
infections
🇸🇻
El Salvador
917K
infections
🇭🇳
Honduras
510K
infections
🇭🇹
Haiti
476K
infections
Why Nx CyberSight
Enterprise capabilities.
Accessible pricing.

3-10× more affordable than alternatives

SpyCloud starts at $30K/yr. Flare at $18K. Recorded Future at $120K+. Nx CyberSight Professional: $10,188/yr with more features than most competitors' entry tiers.

Managed services included

TAM, CTI consulting hours, incident response, and training included in upper tiers. No competitor includes human expertise in the subscription price.

The only LATAM-native CTI platform

21 countries. Spanish & Portuguese. Regional pricing. A team that understands the Latin American threat landscape.

Enterprise-grade from day one

38 RBAC permissions, 13 roles, multi-org architecture, 2FA, complete audit trails, and scoped API keys.

How we compare
See the difference.
Then decide.
Feature-by-feature comparison against leading cyber intelligence platforms. No spin. Just facts.
Feature Nx CyberSight SpyCloud Flare Hudson Rock
Starting price$4,188/yr~$30,000/yr~$18,000/yr~$20,000/yr
LATAM-native intelligence 21 countriesLimitedLimitedLimited
Spanish & Portuguese
Stealer log browser
Credential classification Auto (4 cat.)PartialPartial
24×7 monitoring & alerts
REST API included Pro+Add-onAdd-on
Multi-tenant MSSP NativeEnterpriseEnterprise
Managed services included TAM + IR + CTI
Regional pricing

Pricing and features based on publicly available information. Contact each vendor for current details.

Pricing
Transparent pricing.
No hidden fees. No surprises.
From startups to global MSSPs. Pick the tier that matches your operation.
Starter
USD349/mo
$3,770/yr billed annually
Cyber intelligence essentials for small teams.
  • 3 users
  • 1 organization
  • 5 assets
  • 500 tokens/mo
  • Org credentials
  • Domain credentials
  • Illicit networks
  • Public search
  • Surface exposure
  • Reporting
  • Monitoring
  • API access
Start free trial
Enterprise
USD1,799/mo
$17,910/yr billed annually
Full platform + investigation + managed services.
  • 10 users
  • 10 organizations
  • 50 assets
  • 5,000 tokens/mo
  • All Professional modules
  • Account passwords
  • Domain intelligence
  • Investigation (Stealer)
  • Monitoring & API
  • Onboarding walk-through
  • TAM assigned
  • 70h professional services
  • SaaS SLA 99.9%
  • Support 12h
Contact sales
MSSP Latam
USD2,499/mo
$25,490/yr billed annually
Multi-tenant for regional providers.
  • 30 users
  • 25 organizations
  • 100 assets
  • 12,000 tokens/mo
  • All Enterprise modules
  • Onboarding + TAM
  • Quarterly business review
  • 120h professional services
  • SaaS platform SLA
  • Dedicated support SLA
Contact sales
MSSP
USD4,999/mo
$50,990/yr billed annually
Unlimited scale. White-label. Full services.
  • 30 users
  • 25 organizations
  • 100 assets
  • 25,000+ tokens/mo
  • All modules included
  • All professional services
  • Monthly executive briefing
  • SaaS platform SLA
  • Custom support SLA
Contact sales
Compare all plans
Starter Professional Enterprise MSSP Latam MSSP
Platform
Users35103030
Organizations13102525
Assets51550100100
Nx Tokens / month5002,0005,00012,00025,000
Modules
Public search
Org credentials
Domain credentials
Illicit networks
Surface exposure
Account passwords
Domain intelligence
Investigation (Stealer)
Capabilities
Reporting
Monitoring & alerts50/mo
API60 req/min
Professional Services
Onboarding walk-through
Professional services40h70h120hCustom
TAM
Quarterly business review
Monthly executive briefing
SLA & Support
SaaS platform SLA99.9%
Support SLA24h12hSLASLA
Our story
We built the tool
we couldn't find.
Nx CyberSight wasn't born in a lab. It was born in the field — from years of red team operations, incident response, and threat intelligence work across Latin America.

We are the attackers (authorized ones)

Nexa runs red team and pentest engagements for banks, governments, and critical infrastructure. Every time we needed compromised credential data for LATAM, the available tools fell short: US-centric data, no Spanish UI, $30K+ price tags, and zero managed support.

We are the responders

When our IR team gets the call at 2 AM, we need instant scope assessment — not a vendor demo. We needed a platform that could tell us in seconds how many credentials were exposed, from what sources, and how critical each one was. So we built it.

We know LATAM like no one else

The threat landscape in Latin America is unique. The malware families, the attack patterns, the regulatory environments, the languages. Global platforms treat the region as an afterthought. We built Nx CyberSight from the ground up for this reality.

We include what others charge extra for

Because we use Nx CyberSight in our own operations, we know what teams actually need: a dedicated TAM who understands your business, IR hours when things go wrong, CTI consulting to interpret findings, and training so your team grows. All included — not as expensive add-ons.

We didn't start a CTI company. We are a cybersecurity company that built the intelligence platform we needed to do our job better — and then realized every security team in the region needed it too.

FAQ
Frequently asked
questions.

We aggregate data from multiple intelligence sources: stealer logs recovered from malware operations, dark web marketplaces, underground forums, paste sites, combo lists, and publicly disclosed leaks. We do not conduct hacking or illegal activities — we index data that is already circulating in criminal ecosystems so defenders can act on it.

Yes. All data is encrypted at rest and in transit. Access is controlled via RBAC with 38 granular permissions, 2FA enforcement, and complete audit trails. Multi-org architecture ensures zero cross-contamination between tenants.

Absolutely. We offer a free exposure report for any domain — no credit card, no sales call, just data. For qualified organizations, we also provide guided demos and limited trial access so your team can evaluate hands-on.

New stealer logs and leak data are typically indexed within 24-48 hours of acquisition. Our monitoring engines run 24×7 and trigger email alerts the moment new credentials matching your domains appear. Critical leaks are prioritized for immediate processing.

Our REST API (17 endpoints) enables integration with any SIEM, SOAR, or ticketing system. We provide SDKs for Python, JavaScript, PHP, Go, C#, and Java. Common integrations include Splunk, QRadar, Microsoft Sentinel, Elastic, XSOAR, TheHive, Jira, and ServiceNow.

Three things no competitor offers simultaneously: (1) LATAM-native intelligence — 21 countries with localized data, Spanish & Portuguese UI, and a team that understands the regional threat landscape. (2) Professional services included — dedicated TAM, IR hours, CTI consulting, and training bundled in the subscription. (3) Accessible pricing — starting at $399/mo, making enterprise-grade CTI available to organizations that were previously priced out.

Your domain. 30 seconds.
The truth.

Enter your corporate email and get a free, no-obligation exposure report showing exactly how many credentials are compromised. No credit card. No sales call. Just data.