Mandiant Digital Threat Monitoring provides visibility beyond your own network — across the open, deep, and dark web — to anticipate targeted attacks and detect data leaks early.
What Is Mandiant Digital Threat Monitoring?
Digital Threat Monitoring is a product from Mandiant, now part of Google, that monitors the open, deep, and dark web for malicious targeting. It covers underground marketplaces, paste sites, blogs, forums, malware repositories, and more, helping you anticipate attacks and detect previously unknown data and credential leaks.
Google Cloud notes that Digital Threat Monitoring is now exclusively offered as a feature within Google Threat Intelligence Enterprise and Enterprise+.
Core Features
- Visibility across the open, deep, and dark web: Monitoring of underground marketplaces, paste sites, blogs, forums, and malware repositories
- Compromised credential monitoring: Automatic alerts when accounts from your organization appear in leak data
- Templated monitors: Pre-configured templates simplify setup and tuning and are intended to reduce false positives and negatives
- Custom monitors: Alongside templates for card shops, domain protection, or code leaks, you can create custom monitors
- Managed Digital Threat Monitoring: Triage, prioritization, and contextual analysis by a designated Mandiant intelligence analyst
Typical Use Cases
Monitor Brand, VIPs, and Intellectual Property
Digital Threat Monitoring helps protect your brand, VIPs (such as CEO, CFO, evangelists), technical resources such as intellectual property, and trusted relationships with vendors and supply chain partners by monitoring the places where these items can be traded or sold.
Early Warning of Malicious Targeting
You gain visibility beyond the network and can see actors targeting your organization or individuals within it. Knowing when you are being targeted lets you better anticipate an attack and prepare defenses.
Detect Data and Credential Leaks
Identify data and credential leaks that existing security tools may have missed, including malicious and accidental insider data leaks.
Benefits
- Visibility beyond the perimeter: Observation of the places where attacks are prepared and data is traded
- Fast setup: Templates guide the creation of each monitor you need
- Reduced analysis effort: Optional managed service with a designated analyst
- Part of Google Threat Intelligence: Integrated with the broader threat intelligence offering
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you with Mandiant Digital Threat Monitoring: defining monitors, prioritizing alerts, and feeding results into your incident response processes.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Digital Threat Monitoring?
According to Google Cloud, Digital Threat Monitoring is a product offered by Mandiant, now part of Google, that monitors the open, deep, and dark web for malicious targeting.
Which parts of the web are monitored?
Google Cloud distinguishes three areas. The open web, also known as the surface or clear web, is easily accessible data indexed by search engines but makes up less than 10% of the internet. The deep web holds most online information; it is not indexed by search engines and includes academic networks and content requiring registration. The dark web requires special software such as TOR and specific configurations; criminal forums and marketplaces are typically hosted there.
How does credential monitoring work?
Mandiant Digital Threat Monitoring monitors the open, deep, and dark web for compromised credentials. If compromised credentials are discovered, it automatically alerts you if any accounts linked to your organization — both internal employees and customers — have appeared in compromised credential data.
What is Managed Digital Threat Monitoring?
Managed Digital Threat Monitoring is a managed service provided by Mandiant. A designated Mandiant intelligence analyst helps triage, prioritize, and provide contextual analysis of alerts, and alerts you when VIPs, partners, or your organization are being targeted.
How is Digital Threat Monitoring licensed?
Google Cloud states that Digital Threat Monitoring is included in Google Threat Intelligence and is now exclusively a feature within Google Threat Intelligence Enterprise and Enterprise+. For pricing, Google refers to sales.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
