A company domain can reveal far more than its website, email addresses, or public infrastructure. It can also provide a starting point for understanding how widely an organization’s credentials have appeared across infostealer logs, database breaches, combo lists, and other leaked data.
Webz.io has launched Lunar Domain Exposure, a free OSINT tool that turns this fragmented breach activity into a public, structured report.
Enter a company domain and the tool generates an immediate view of its external credential exposure. The report does not reveal passwords, personal information, or the underlying leaked records. Instead, it provides aggregated data that researchers, security teams, journalists, and developers can use to assess the scale and nature of an organization’s exposure.
What the Domain Exposure Report Shows
Each report brings together several indicators that would otherwise require searching across multiple breach and dark web data sources.
The report includes:
- An overall exposure risk score
- The volume of exposed employee and customer accounts
- A 12-month timeline of detected events
- A comparison of infostealer activity and traditional data breaches
- Malware families connected to infected endpoints
- Login services and critical infrastructure appearing in exposed data
- The geographic distribution of infected machines
Together, these indicators help answer more useful questions than simply asking whether a domain has appeared in a breach.
Researchers can see whether exposure is recent or historical, whether it comes mainly from stolen databases or infected endpoints, and whether activity appears isolated or persistent.
Why Infostealer Exposure Matters
Traditional breach monitoring often focuses on databases leaked after a company or third-party service is compromised.
Infostealer logs represent a different type of risk.
Infostealer malware infects individual computers and collects data directly from the device. This may include credentials, browser data, cookies, operating-system details, application information, and the services accessed from that machine.
As a result, a company may appear in infostealer data even when its own systems were not breached. An employee, contractor, customer, or partner may have accessed a corporate service from an infected personal or unmanaged device.
This makes infostealer activity useful for understanding exposure that may exist outside the organization’s normal security perimeter.
The Domain Exposure Report separates infostealer activity from database-breach activity, allowing researchers to distinguish between these two sources rather than treating every leaked credential as the same type of event.
A Starting Point for OSINT Investigations
The report is designed as an initial research layer, not as a replacement for a full security investigation.
For OSINT researchers, it can help establish context quickly.
A researcher examining a ransomware incident, fraud campaign, supply-chain compromise, or company breach can use the report to check whether the organization had a visible history of credential exposure.
It can also support comparisons between companies, sectors, subsidiaries, and regions. Researchers can examine whether one domain shows unusually high infostealer activity, whether exposure increased during a particular period, or whether infected endpoints are concentrated in specific countries.
The exposed services section can also help identify which parts of an organization may require closer attention. For example, the report may show activity linked to email systems, VPNs, cloud services, development platforms, remote-access tools, or other operational infrastructure.
The report does not prove that an exposed account is currently valid or that an organization has been compromised. It does, however, identify signals that may justify deeper investigation.
Public Insight Without Publishing Sensitive Data
Credential intelligence creates an obvious challenge for public OSINT tools: the data may be useful for research, but the underlying records can contain passwords, personal information, and other sensitive material.
Lunar Domain Exposure is built around aggregation rather than disclosure.
The public report shows volumes, categories, time patterns, malware families, services, and geographic indicators. It does not expose the actual credentials or personal data behind those findings.
This allows researchers to study corporate exposure while reducing the risk of turning a research tool into a source of additional harm.
Breach Visibility Should Not Depend on Budget
The idea behind the tool follows the same principle as Lunar: every organization should be able to understand whether its data has been exposed.
Large enterprises often have access to commercial threat-intelligence platforms, breach-monitoring systems, and dedicated security teams. Smaller companies, independent researchers, journalists, nonprofits, and academic teams may not.
A free public report lowers that barrier.
It gives users a way to assess a domain before committing to a deeper investigation, requesting internal access, or purchasing a commercial service. It can also help smaller organizations understand their external exposure using information that attackers may already have.
A Free Domain Exposure API
The data behind the reports is also available through a free Domain Exposure API.
Developers and researchers can use the API to integrate domain-exposure data into their own applications, investigation workflows, dashboards, and research projects.
Possible uses include:
- Adding breach context to company-research tools
- Enriching cyber-risk and third-party-risk assessments
- Comparing exposure across a list of domains
- Building alerts when exposure patterns change
- Supporting academic or industry research
- Adding credential-risk signals to OSINT platforms
- Prioritizing domains for further investigation
The API makes it possible to move beyond one-off reports and use the data at scale.

Turning Fragmented Breach Data Into Usable Context
Leaked credentials rarely exist as a single, clean dataset.
They appear across breach dumps, combo lists, malware logs, Telegram channels, underground forums, marketplaces, and repackaged collections. The same domain may appear repeatedly across different sources and time periods.
The difficult part is not simply finding a domain. It is organizing the findings into something that can be interpreted.
Lunar Domain Exposure turns those scattered signals into a report that shows what type of exposure exists, how much was found, when it occurred, and where deeper analysis may be needed.
For the OSINT community, that makes it a practical starting point: fast enough for initial research, structured enough for comparison, and public without exposing the sensitive records behind the results.