Mayfield Intelligence Operations Start a pilot

01 Monitoring & detection

Dark & Deep Web Monitoring

Your security stack watches your perimeter. It cannot watch the closed forums, darknet markets and paste sites where your data is traded — which is where an incident usually starts.

Start a pilot

Most organisations learn that their data is circulating when someone uses it. By then the window for cheap intervention has closed: credentials have been sold on, an access broker has advertised a route in, or a ransomware group has already listed you on a leak site. The information was available for weeks beforehand. Nobody was looking.

We monitor those sources continuously against your domains, your executives, your brands and your infrastructure. When your name appears, you hear from us with the source, the date, what was posted and an assessment of what it means — not an automated alert you have to triage yourself.

01 What you receive

Deliverables.

Every engagement produces a written, sourced deliverable — not a dashboard login you will never open.

01
Standing monitoring
Continuous collection against an agreed watch list of domains, people and assets.
02
Alerts with assessment
Every alert arrives with the source, the date, what was found and what we think it means.
03
Monthly reporting
A written summary of activity, trend and change in your exposure.
04
Evidence packs
Where a finding needs to support legal or regulatory action, documented to that standard.

02 Method

How it runs.

  1. 01

    Scope

    We agree the watch list: domains, executive names, brands, supplier names, infrastructure.

  2. 02

    Collect

    Monitoring goes live across darknet markets, closed forums, paste sites and leak sites.

  3. 03

    Assess

    An analyst reviews every hit. Noise is discarded; real findings are researched and contextualised.

  4. 04

    Report

    You receive alerts on material findings and a written monthly summary.

04 Common questions

Is dark web monitoring legal?

Yes. Observing and recording material that is published on criminal forums and marketplaces is lawful intelligence collection. We do not purchase stolen data, we do not gain unauthorised access to systems, and we do not engage with threat actors on a client’s behalf. Where a finding requires interaction we say so and refer it appropriately.

What happens if you find our data?

You are alerted with the source, the date, what was exposed and our assessment of the risk. We set out practical remediation — usually credential rotation, control changes and, where relevant, a notification decision for your compliance team. If the finding may support legal action, we document it to evidential standard.

How is this different from a threat intelligence feed?

A feed gives you indicators; you still have to work out whether any of them concern you. We monitor specifically against your organisation and an analyst reviews every hit before it reaches you. You get findings, not a queue.

Tell us what you would want watched. We will scope a pilot on it, in writing, before anything is agreed.