Back to blog

Blog Post

Reduce false positives with Email Format Validation

Share on social

Sep 22, 2026

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Reduce false positives with Email Format Validation

What’s New

With this enhancement, Searchlight Threat – Monitor customers can drastically reduce the number of false-positive credential results by excluding invalid email formats from their Credential Actions – including the following pre-attack indicators.

  • Leaked credentials: Compromised credentials related to your organization that have been exposed. Stolen username and password combinations remain a significant initial access vector for cyberattacks (HelpNet).
  • Stealers: The output of information‑stealing malware that runs on a victim’s device and harvests data, including email addresses, usernames, passwords, and cookies that can be used to launch an attack.  

Fewer false positives means less time spent chasing irrelevant results and more confidence that the credentials surfaced in your Credential Actions are worth acting on.

How it works

Users can now define their organization’s email syntax within the new Scan Rules area. For example, if your organization uses the initial.surname[@]company.com format, you can save this format and automatically exclude future discovered results that don’t follow this structure.

For organizations with different email conventions across domains, you can also create customised rules using the custom rule builder. Specific domains can be assigned their own validation rule, while other active domains continue to use the main organization-wide rule. All domains used in these rules must already exist within your active attributes.

These changes are applied at the company level, so MSSPs managing multiple client environments within Searchlight can set different rules for each customer.

Alex Blackman

Author

Alex Blackman

Head of Product Marketing at Searchlight Cyber

Alex Blackman leads product marketing at Searchlight Cyber, where he's responsible for taking the company's Preemptive Threat Exposure Management platform to market. Before joining Searchlight, Alex worked with global brands including Unilever and Allianz. He runs Searchlight's webinar programme and spends most of his time helping security teams understand why preemptive beats reactive and how that works in the Searchlight platform.

Related Blog Posts

September 22, 2026

New Company Dashboard in Searchlight Threat – Monitor

September 17, 2026

Beacon: AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers

September 16, 2026

How AI Is Collapsing Exploitation Timelines

September 15, 2026

Faster Leaked Credential Search with a rebuilt experience

September 10, 2026

Beacon: Searchlight Researchers Uncover JavaScript Sandbox Flaw Enabling RCE in Zendesk and Nuclei

September 3, 2026

Beacon: FulcrumSec Claims Responsibility for Manchester Airport Group Breach

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient