{"uid":"cap_QLH7qzIca2OgSsQAHrQ6R","slug":"cyberpulse-dark-web-monitor-a075db20","name":"CyberPulse Dark Web Monitor","description":"Dark-web monitoring for any brand or domain — paste-site mentions, credential-dump signals, forum chatter, ransomware leak-site activity, brand impersonation, and initial-access-broker listings, for threat-intel and brand-protection agents. Ethical OSINT only.","url":"https://cyberpulse.theaslangroupllc.com/api/cyber/dark-web-monitor","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","properties":{"lang":{"type":"string","description":"en | es | fr | de | ja | zh | ko | pt | ar | hi (default: en)"},"brand":{"type":"string","description":"Brand name or domain to monitor — e.g. \"Acme Corporation\" | \"acme.com\" | \"MyBank\" | \"startupname.io\""}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"errors":{"type":"object","description":"Documented error responses, keyed by HTTP status code","additionalProperties":{"type":"object","required":["description"],"properties":{"example":{"type":"object"},"description":{"type":"string"}}}},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"target":"acme.com","signal_summary":{"paste_site_mentions":true,"data_for_sale_signals":false,"forum_chatter_detected":false,"credential_dump_mentions":false},"brand_impersonation":{"impersonation_examples":["acme-login.com","acmecorp-support.net"],"phishing_domains_registered":true},"credential_exposure":{"credential_freshness":"Stale (> 1 year)","combo_list_appearances":3,"estimated_exposed_accounts":2500},"recommended_actions":["Register defensive domain variations","Enable dark web monitoring alerts","Force password reset for accounts in known combo lists"],"overall_exposure_level":"MEDIUM"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.2","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.2/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_S8ziuA3Vm0XqB1bksEk4d","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.2","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans dark web sources — paste sites, credential dumps, hacker forums, ransomware leak sites, brand impersonation, and IAB listings — for mentions of a given brand or domain.","exampleAgentPrompt":"Run a dark web monitor scan on acmecorp.com — I want to know if it shows up on any paste sites, credential dump signals, ransomware leak sites, hacker forums, or initial-access-broker listings.","exampleUseCases":[{"title":"Ransomware incident response and victim verification","prompt":"Check the dark web right now for any mentions of our company on ransomware leak sites or in hacker forums — we just got a suspicious email claiming they have our data. I need to know if we're actually listed as a victim anywhere."},{"title":"Post-breach credential exposure monitoring","prompt":"We had a potential data breach last month. Scan the dark web for any signals that our employee credentials or customer data showed up in paste sites or credential dumps under our domain name."},{"title":"Brand impersonation and domain abuse detection","prompt":"Look across dark web forums and paste sites to see if anyone is impersonating our brand or using our domain name for phishing, selling fake access, or running any kind of scam operation."}],"resultDescription":"Returns dark web intelligence findings for the queried brand or domain, including paste-site mentions, signals of credential dumps, underground forum chatter, ransomware leak-site activity, brand impersonation indicators, and initial-access-broker listings — all scoped to ethical OSINT sources.","failureModes":["Invalid or malformed domain/brand input returns a 400 error","No dark web results found for the queried entity returns an empty or null findings payload","Payment not processed (x402 protocol failure) results in a 402 response","Rate limiting or quota exceeded returns a 429 error","Upstream OSINT source unavailability may result in partial or degraded results"],"whenToPreferThis":"Choose this endpoint when you need dark-web-specific threat intelligence for a brand or domain — particularly paste-site exposure, credential leak signals, ransomware victim listing checks, IAB activity, or brand impersonation on underground forums. Prefer this over surface-web OSINT or CVE/vulnerability endpoints when the threat vector is data exfiltration, credential theft, or underground marketplace activity rather than technical vulnerability scanning.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:31:16.558Z","isFirstParty":false}