Pwned

Optional user and domain compromise monitoring

Watch identities and organisational domains against Have I Been Pwned (HIBP), and turn breaches into GLPI work.

Pwned is an optional Echo-9 plugin. It requires EchoDesk GLPI Advanced and cannot be taken as a shared service on its own.

What is Pwned?

Pwned integrates GLPI with Have I Been Pwned so service desk and security teams can see when users, VIP groups or organisational domains appear in known breaches — without making compromise monitoring a separate silo.

Password and email checks use HIBP’s k-Anonymity model. Domain and vendor monitoring can raise high-priority tickets automatically so response starts in the same platform as the rest of EchoDesk.

What It Covers

User security status

A Security Status tab on the GLPI user with clear breach state and detail

Password breach checks

HIBP k-Anonymity checks when users are created or updated

Domain monitoring

Polls HIBP for domain breaches and can auto-create high-priority GLPI tickets

VIP monitoring

Group-based scanning on a short cycle for high-value accounts

Vendor breaches

Fuzzy-matches GLPI manufacturers against known HIBP breaches

Users at Risk dashboard

Summary metrics and manual triggers for the team that owns identity risk