Threat Modeling

We analyze the risk of each individual to determine the unique human attack surface.

Exposure Monitoring
Risk Mitigation
Incident Response and Recovery
Threat Modeling

We analyze the risk of each individual to determine the unique human attack surface.

Exposure Monitoring
Risk Mitigation
Incident Response and Recovery

THE HUMAN ATTACK SURFACE

THE HUMAN ATTACK SURFACE

THE HUMAN ATTACK SURFACE

How We Mitigate Personal Attacks

How We Mitigate Personal Attacks

How We Mitigate Personal Attacks

Built on industry standards

Built on industry standards

Built on industry standards

79% of attacks use malware-free methods

79% of attacks use malware-free methods

79% of attacks use malware-free methods

Source: Crowdstrike '24 DRP Report

Source: Crowdstrike '24 DRP Report

Every Kanary capability counters real MITRE ATT&CK techniques that adversaries use to target individuals. Our team of researchers validate capabilities against thousands of reported personal incidents as vectors evolve.

Every Kanary capability counters real MITRE ATT&CK techniques that adversaries use to target individuals. Our team of researchers validate capabilities against thousands of reported personal incidents as vectors evolve.

MITRE ATT&CK FRAMEWORK

Scroll

Scroll

Threat actor technique

Kanary capability

T1591

T1591.001

T1591.004

Gather Victim Org Info

Scraping org charts, job titles, conference appearances, and org relationships from LinkedIn

LinkedIn Profile Scanning

Flags exposed PII and job roles visible to adversaries

T1589

T1591

T1593

T1593.001

T1593.002

Search Open Websites / Data Brokers

Aggregating personal data across people-search sites, Whitepages, Intelius, and Google results

Data Broker Removal

Opt-outs across a broad range of sites with managed Google cache suppression and monthly re-scans

T1589

T1591

T1593

T1593.001

Search Victim-Owned Social Media

AI-assisted OSINT on public posts to build target profiles and identify physical locations

X & LinkedIn Post Scanning

Detects PII, doxxing content, and weaponizable information across public social media posts

T1589

T1591

T1593

T1593.001

T1593.002

Gather Victim Identity Info

Harvesting home addresses, phone numbers, emails, and family relationships from data brokers

PII Exposure Monitoring

Tracks unlimited address, name, phone, and email variants with configurable scan frequency

Reconnaissance

Reconnaissance

Threat actor technique

Kanary capability

T1591

T1591.001

T1591.004

Gather Victim Org Info

Scraping org charts, job titles, conference appearances, and org relationships from LinkedIn

LinkedIn Profile Scanning

Flags exposed PII and job roles visible to adversaries

T1589

T1591

T1593

T1593.001

T1593.002

Search Open Websites / Data Brokers

Aggregating personal data across people-search sites, Whitepages, Intelius, and Google results

Data Broker Removal

Opt-outs across a broad range of sites with managed Google cache suppression and monthly re-scans

T1589

T1591

T1593

T1593.001

Search Victim-Owned Social Media

AI-assisted OSINT on public posts to build target profiles and identify physical locations

X & LinkedIn Post Scanning

Detects PII, doxxing content, and weaponizable information across public social media posts

T1589

T1591

T1593

T1593.001

T1593.002

Gather Victim Identity Info

Harvesting home addresses, phone numbers, emails, and family relationships from data brokers

PII Exposure Monitoring

Tracks unlimited address, name, phone, and email variants with configurable scan frequency

Threat actor technique

Kanary capability

T1591

T1591.001

T1591.004

Gather Victim Org Info

Scraping org charts, job titles, conference appearances, and org relationships from LinkedIn

LinkedIn Profile Scanning

Flags exposed PII and job roles visible to adversaries

T1589

T1591

T1593

T1593.001

T1593.002

Search Open Websites / Data Brokers

Aggregating personal data across people-search sites, Whitepages, Intelius, and Google results

Data Broker Removal

Opt-outs across a broad range of sites with managed Google cache suppression and monthly re-scans

T1589

T1591

T1593

T1593.001

Search Victim-Owned Social Media

AI-assisted OSINT on public posts to build target profiles and identify physical locations

X & LinkedIn Post Scanning

Detects PII, doxxing content, and weaponizable information across public social media posts

T1589

T1591

T1593

T1593.001

T1593.002

Gather Victim Identity Info

Harvesting home addresses, phone numbers, emails, and family relationships from data brokers

PII Exposure Monitoring

Tracks unlimited address, name, phone, and email variants with configurable scan frequency

Resource development

Resource development

Threat actor technique

Kanary capability

T1585.001

Establish Fake Social Media Accounts

Creating lookalike profiles on X and LinkedIn to impersonate executives and conduct social engineering

Impersonation Detection

Scans X and LinkedIn for profiles and posts matching protected individual information

Compromise Social Media Accounts

Exploiting weak MFA settings or lax default privacy configurations to hijack legitimate accounts

T1585.001

Account Settings Hardening

Enforces strong privacy settings, and assists with setup across social platforms

T1588

Obtain Capabilities via OSINT

Using scraped photos, audio, and video to fuel AI deepfake tools for impersonation campaigns

Exposure Minimization

Removes photos and PII from public-facing sources before they can be used to generate synthetic media

Threat actor technique

Kanary capability

T1585.001

Establish Fake Social Media Accounts

Creating lookalike profiles on X and LinkedIn to impersonate executives and conduct social engineering

Impersonation Detection

Scans X and LinkedIn for profiles and posts matching protected individual information

Compromise Social Media Accounts

Exploiting weak MFA settings or lax default privacy configurations to hijack legitimate accounts

T1585.001

Account Settings Hardening

Enforces strong privacy settings, and assists with setup across social platforms

T1588

Obtain Capabilities via OSINT

Using scraped photos, audio, and video to fuel AI deepfake tools for impersonation campaigns

Exposure Minimization

Removes photos and PII from public-facing sources before they can be used to generate synthetic media

Defense evasion

Defense evasion

Threat actor technique

Kanary capability

T1036

Masquerading

Fake profiles crafted to look identical to executive accounts — same photo, similar handle, copied bio — evading platform detection for months

Lookalike Profile Detection

Continuously scans for profiles matching name, handle patterns, and bio attributes; flags subtle variations designed to evade casual review

T1036.009

Blend into Platform Norms

Adversaries operate fake personas within normal platform behavior — liking posts, commenting, building followers — to appear legitimate before striking

Behavioral Pattern Monitoring

Frequent scans track emerging profiles over time, not just point-in-time snapshots, catching personas as they mature

Threat actor technique

Kanary capability

T1036

Masquerading

Fake profiles crafted to look identical to executive accounts — same photo, similar handle, copied bio — evading platform detection for months

Lookalike Profile Detection

Continuously scans for profiles matching name, handle patterns, and bio attributes; flags subtle variations designed to evade casual review

T1036.009

Blend into Platform Norms

Adversaries operate fake personas within normal platform behavior — liking posts, commenting, building followers — to appear legitimate before striking

Behavioral Pattern Monitoring

Frequent scans track emerging profiles over time, not just point-in-time snapshots, catching personas as they mature

Initial access

Initial access

Threat actor technique

Kanary capability

T1566

Spear-Phishing via Social Media

Attacks built entirely from LinkedIn data — job title, direct number, recent events — requiring no system breach

Attack Surface Reduction

Threat-model-based removal prioritizes the data points most commonly weaponized in social engineering campaigns

T1589

T1591

T1591.001

T1591.004

T1593

T1593.001

Trusted Relationship Abuse

Using inferred org relationships and professional or family connections to pivot laterally into target organizations

Family and Professional Network Protection

All-in-one coverage of trusted relationships from the central control of your core profile: for team members and family. No limits on family members or team members.

Threat actor technique

Kanary capability

T1566

Spear-Phishing via Social Media

Attacks built entirely from LinkedIn data — job title, direct number, recent events — requiring no system breach

Attack Surface Reduction

Threat-model-based removal prioritizes the data points most commonly weaponized in social engineering campaigns

T1589

T1591

T1591.001

T1591.004

T1593

T1593.001

Trusted Relationship Abuse

Using inferred org relationships and professional or family connections to pivot laterally into target organizations

Family and Professional Network Protection

All-in-one coverage of trusted relationships from the central control of your core profile: for team members and family. No limits on family members or team members.

Impact & response

Impact & response

Threat actor technique

Kanary capability

T1491

Defacement, Doxxing & Harassment

Publishing home addresses, threats, and personal information to intimidate targets and disrupt operations

Incident Response & Legal Escalation

Recovery support with legal documentation, escalation pathways, and legal partner access

T1657

Financial Fraud & Identity Theft

Using harvested PII to commit fraud, impersonate targets to financial institutions, or extort victims

Data Sharing & API

Threat models provide early-warning triggers for banks and identity teams so they can block or slow transactions

Threat actor technique

Kanary capability

T1491

Defacement, Doxxing & Harassment

Publishing home addresses, threats, and personal information to intimidate targets and disrupt operations

Incident Response & Legal Escalation

Recovery support with legal documentation, escalation pathways, and legal partner access

T1657

Financial Fraud & Identity Theft

Using harvested PII to commit fraud, impersonate targets to financial institutions, or extort victims

Data Sharing & API

Threat models provide early-warning triggers for banks and identity teams so they can block or slow transactions

Prioritization across thousands of sources and platforms where threats surface

Prioritization across thousands of sources and platforms where threats surface

Prioritization across thousands of sources and platforms where threats surface

Physical intimidation, scams and fraud, and account take overs stem from AI-powered tactics.

Physical intimidation, scams and fraud, and account take overs stem from AI-powered tactics.

Doxxing

Recover from attacks across social platforms like X, LinkedIn, and Twitch. Clean-up posts and profiles drawing attention to addresses or doctored images.

Impersonation

Monitor profiles on LinkedIn for instances of person of interest, executive, or VIP impersonation. Escalate take downs following ToS.

Physical Arrivals

Connect physical security teams with intelligence to prevent unwanted arrivals at residences, offices, and events. Retain a traceable log of threat exposures.

Phishing

Disrupt multi-billion dollar scam operations at the source. Reduce scammer access to high-confidence signal tracking.

Doxxing

Recover from attacks across social platforms like X, LinkedIn, and Twitch. Clean-up posts and profiles drawing attention to addresses or doctored images.

Impersonation

Monitor profiles on LinkedIn for instances of person of interest, executive, or VIP impersonation. Escalate take downs following ToS.

Physical Arrivals

Connect physical security teams with intelligence to prevent unwanted arrivals at residences, offices, and events. Retain a traceable log of threat exposures.

Phishing

Disrupt multi-billion dollar scam operations at the source. Reduce scammer access to high-confidence signal tracking.

Doxxing

Recover from attacks across social platforms like X, LinkedIn, and Twitch. Clean-up posts and profiles drawing attention to addresses or doctored images.

Impersonation

Monitor profiles on LinkedIn for instances of person of interest, executive, or VIP impersonation. Escalate take downs following ToS.

Physical Arrivals

Connect physical security teams with intelligence to prevent unwanted arrivals at residences, offices, and events. Retain a traceable log of threat exposures.

Phishing

Disrupt multi-billion dollar scam operations at the source. Reduce scammer access to high-confidence signal tracking.

MONITORED AND MITIGATED ACROSS
Monitored and Mitigated Across
MONITORED AND MITIGATED ACROSS

Data Brokers

Data Brokers

AI/LLMs

AI/LLMs

Social Media

Social Media

Search Engines

Search Engines

How Does Kanary Compare?

How Does Kanary Compare?

How Does Kanary Compare?

Compare key capabilities, coverage, and workflows to see how Kanary stacks up.

Compare key capabilities, coverage, and workflows to see how Kanary stacks up.


Check out our site on a larger screen for a more comprehensive breakdown.

Compare key capabilities, coverage, and workflows to see how Kanary stacks up.

Capability

Threat Model Based

Kanary

Kanary

Bulk data broker removal

DeleteMe, Optery, Incogni

DeleteMe, Optery, Incogni

Privacy Multi-Tool

Privacy Multi-Tool

Cloaked, Aura, Privacy Bee

Cloaked, Aura, Privacy Bee

Approach

Approach

Precise risk reduction

Precise risk reduction

Bulk data removal

Bulk data removal

Identity-theft and credit repair

Identity-theft and credit repair

Threat model

Threat model

Risk scoring

Risk scoring

(some competitors)

(some competitors)

Privacy risk only

Privacy risk only

Prioritization

Prioritization

Mitigates highest risks first

Mitigates highest risks first

Treats most risk the same

Treats most risk the same

Treats all risk the same

Treats all risk the same

Data handling

Data handling

In house

In house

Outsourced

Outsourced

Mixed approach

Mixed approach

Sources

Sources

Built for targeted attacks

Built for targeted attacks

Built for data broker lists

Built for data broker lists

Built for identity management

Built for identity management

Public Brokers

Public Brokers

300+

300+

85 - 950

85 - 950

85 - 250

85 - 250

Private Brokers

Private Brokers

125

125

Home Image Mapping

Home Image Mapping

Limited

Limited

Dark Web

Dark Web

Limited

Limited

Social media

Social media

X, Linkedin

X, Linkedin

Monitoring only

Monitoring only

Search engines

Google, Bing

Some removal

Some removal

AI/LLMs

ChatGPT

Coverage

Configurable

Basic

Bundled

Free tier

Limited

Fully-managed service tier

Limited

Scanning frequency options

Monthly, Weekly, Daily

Monthly, Quarterly

Monthly, Quarterly

Mobile app

Limited

API

Some competitors

VPN

Custom removals

CSV exports

Limited

Limited

Family member coverage

Add to any account

Requires onboarding

Requires onboarding

Self-service onboarding

Mitigation Techniques

Comprehensive

Sporadic

Fragmented

Data removal

Search de-indexing

Limited

Some competitors

Masking

Limited

Some competitors

Incident response

Limited

Power of Attorney

Some competitors

Some competitors

Attorney General Escalation

Limited

Limited

Capability

Threat Model Based

Kanary

Bulk data broker removal

DeleteMe, Optery, Incogni

Privacy Multi-Tool

Cloaked, Aura, Privacy Bee

Approach

Precise

Bulk

Credit/Identity

Threat model

Risk scoring

(some competitors)

Privacy risk only

Prioritization

Mitigates highest risks first

Treats most risk the same

Treats all risk the same

Data handling

In house

Outsourced

Mixed approach

Sources

Built for targeted attacks

Built for data broker lists

Built for identity management

Public Brokers

300+

85 - 950

85 - 250

Private Brokers

125

Home Image Mapping

Limited

Dark Web

Limited

Social media

X, Linkedin

Monitoring only

Search engines

Google, Bing

Some removal

Some removal

AI/LLMs

ChatGPT

Coverage

Configurable

Basic

Bundled

Free tier

Limited

Fully-managed service tier

Limited

Scanning frequency options

Monthly, Weekly, Daily

Monthly, Quarterly

Monthly, Quarterly

Mobile app

Limited

API

Some competitors

VPN

Custom removals

CSV exports

Limited

Limited

Family member coverage

Add to any account

Requires onboarding

Requires onboarding

Self-service onboarding

Mitigation Techniques

Comprehensive

Sporadic

Fragmented

Data removal

Search de-indexing

Limited

Some competitors

Masking

Limited

Some competitors

Incident response

Limited

Power of Attorney

Some competitors

Some competitors

Attorney General Escalation

Limited

Limited