Integration: Kaseya SIEM and HaveIBeenPwned (Pwnd Monitor)

Overview

Kaseya SIEM integrates with HaveIBeenPwned (displayed in the connection wizard as "Pwnd Monitor") to check email addresses and domains against HaveIBeenPwned's database of known data breaches and credential compromises. This integration allows Kaseya SIEM to automatically flag compromised accounts, giving the security team visibility into exposed credentials across the organization.

NOTE  HaveIBeenPwned's own website displays its full name as "Pwned," but the Kaseya SIEM integration tile and connection wizard consistently label it Pwnd. This is a naming inconsistency between the two products, not a typo.

Prerequisites

  • Access to the email address you'll use to sign in to HaveIBeenPwned (sign-in is passwordless; a login link is emailed to you)

  • An active HaveIBeenPwned subscription (the free account shown in the Dashboard cannot provision an API key)

  • A HaveIBeenPwned API Key

  • Permission to manage integrations or organization applications in Kaseya SIEM

  • If using Domain mode: verified ownership of the domain in the HIBP domain dashboard

How to...

FAQ