Threats
The Threats page in Rapid7 Digital Risk Protection (Threat Command) gives you visibility into potential threats across your organization’s digital footprint.
Use this page to monitor, investigate, and respond to threats across these categories:
- Mobile Applications - Mobile applications that use company-like branding or other similarities, which may carry malicious code or otherwise put users or your organization at risk.
- Exploitable Data - Hardware or software vulnerabilities, including open ports, SPF/DMARC records, SSL certificates, SSL issues, and exposed services. This information is primarily relevant to IT teams.
- Data Leakage - Ransomware data leaks or exposure of internal or confidential company documents.
- Dark Web - Company credit cards, bot-harvested credentials, or products offered for sale on dark web marketplaces.
Click a threat to see its details. Each threat area has a dedicated tab on the Threats page.
Using the Threats pages gives the following benefits:
- Better intelligence and transparency - For each monitored threat, you can see the criteria that are part of the Digital Risk Protection algorithm, for example, which developer uploaded a commit to GitHub, or values of different leaked information.
- Correlate between different threats - Use the filter and search features to show similar threats. For example, showing all domains created by the same registrant can lead to a fuller picture of what a specific registrant is doing with your brand name, a picture that cannot be seen by looking at a single domain. Or, perhaps the same developer is uploading apps to various stores. You can pivot on monitored threat based on over ten search criteria, so you can make more relevant decisions.
- Understand why alerts are triggere d - Any significant event in a monitored threat (like adding an MX record) will cause that threat to be elevated to an alert.
The tabs share similar functionality. To learn how to use the tab functions, see View threat details.