RelayShield and Salesflare

How to connect RelayShield

About RelayShield

RelayShield is a security intelligence API for breach detection, SIM swap monitoring, infostealer exposure, and ransomware intelligence.

RelayShield operations on Zapier

Triggers (1)

Start a workflow when this happens

  • New Security Alert — Triggers when RelayShield detects a new finding — breach, infostealer hit, session hijack, ransomware victim listing, or other security event. Requires webhook delivery to be configured on your API key.

Actions (12)

Things Salesflare can make it do

  • Breach Check — Check if an email address appears in known data breaches. Returns breach count, breach names, dates, and exposed data classes.
  • Domain Lookalike Scan — Scan for typosquat and lookalike domains registered to impersonate a domain. Checks DNS resolution, certificate transparency logs, and Google Safe Browsing.
  • Identity Correlation — Link an email to associated phone numbers and domains seen alongside it in criminal channel dumps. Pivot from one compromised identifier to find all others exposed in the same breach or stealer log.
  • Infostealer Log Check — Check if credentials appear in criminal infostealer malware logs. A single infected device exposes every saved password across 50+ services simultaneously — banking, email, SaaS tools, and active session cookies that bypass 2FA.
  • NHI Exposure Check — Detect non-human identity (NHI) credentials — API keys, tokens, private keys — linked to a domain in stealer log corpus. Covers AWS IAM keys, GitHub PATs, Stripe secrets, Slack tokens, and more. Accepts own domain or vendor supply chain domains.
Show 7 more actions
  • OAuth & Token Exposure Check — Check breach history against 31 OAuth app watchlist plus live stealer log corpus. Detects stolen OAuth tokens across cloud consoles, CI/CD, identity providers, and SaaS tools with category-level severity scores.
  • Ransomware Risk Check — Check a domain against 100+ active ransomware group victim lists and pre-ransomware credential corpus. Returns victim list status, responsible group(s), and count of credentials found in stealer logs before the incident.
  • SIM Swap Detection — Detect active SIM swap or port-out fraud on a phone number via telco carrier lookup database. Returns carrier name, swap timestamp, and line type.
  • Session Hijack Detection — Detect stolen active session cookies linked to an email from criminal stealer log archives. Identifies AiTM attacks that bypass 2FA — attacker can access accounts right now without the password.
  • Supply Chain Risk Check — Check vendor domains for breach exposure and infostealer hits. Returns per-domain risk score (CRITICAL/HIGH/MEDIUM/LOW) and a 0–100 dark web composite score. Accepts up to 10 vendor domains per call.
  • Target Risk Score — Estimate the probability a domain is currently being targeted by threat actors. Combines 6 independent signals — ransomware victim listing, stealer log hits, breach exposure, criminal channel mentions, high-EPSS CVEs, and pre-ransomware credentials — into a 0–100 score with CRITICAL/HIGH/MEDIUM/LOW tier.
  • Threat Intelligence IOC Lookup — Query RelayShield's live IOC database (400,000+ indicators from 8 criminal Telegram channels and 15 authoritative threat feeds) for a domain, IP, email, phone, or wallet address. Returns confidence score, malware family, threat actor attribution, SIGMA rules, and ASN/geo context. Requires TI subscription.

Similar apps

Not using Salesflare yet?

Salesflare is a CRM for small and medium-sized B2B businesses — it fills itself in automatically so your team actually keeps it up to date.

Try it for free