Skip to content

Threat intelligence

Catch the lookalike domain before it serves a page

Brand impersonation and phishing infrastructure are the same attack viewed from two desks. TracBrand runs a second pipeline alongside brand discovery that watches your own domains through six external feeds — and reports what it finds in the same graded queue.

The window

A typosquat announces itself long before it attacks

Registering a lookalike domain and standing up a convincing phishing page are separate jobs, usually days apart. The certificate is issued in between, and certificate transparency logs are public.

That gap is the only part of a phishing campaign where you are ahead. TracBrand monitors it continuously, so a lookalike certificate becomes a finding on your queue rather than something you learn about from a customer who lost money.

No AI in this pipeline

Severity is decided by explicit rules per finding type. Reproducible, auditable, and defensible in a security review.

Permanent deduplication

Findings are keyed by source and URL per brand, so a long-standing exposure does not re-alert on every cycle.

Runs on your cadence

Threat hunting can run alongside brand discovery, on its own, or not at all — configured per brand.

One queue, two pipelines

Domain findings and brand misuse cases share triage, ownership and audit, so nothing falls between two teams.

The feeds

Six sources, every one of your domains

Each domain you register is run against all six feeds on your monitoring cadence, with per-source result caps so a noisy feed cannot flood your queue.

crt.sh

Certificate transparency

A lookalike domain the moment someone issues an SSL certificate for it — usually days before the site goes live

PhishTank

Phishing feeds

Live phishing pages impersonating your brand to harvest customer logins

GitHub

Public code search

Your domains, configuration or secrets committed to public repositories

urlscan.io

URL scan corpus

Lookalike pages other researchers have already captured and published

Shodan

Internet-wide scan data

Exposed servers, open admin ports and forgotten infrastructure on your domains

LeakIX

Leak intelligence

Breached or leaked data tied to your hosts and credentials

Finding types

What lands on the queue, and how it is graded

Six finding types, each with a fixed severity rule. An exposed database and a newly issued certificate are never given the same weight.

Finding typeTypical severity
Certificate issuance

A certificate has been issued for a name resembling one of your domains. The strongest early signal you can get, because it usually precedes any content.

medium
Phishing imitation

A live page impersonating your brand, confirmed by a phishing feed and attributed to the domain it targets.

critical
Code leak

Your domains, configuration or credentials appearing in public source code repositories.

high
Public scan

A lookalike page another researcher has already captured and published, giving you a rendered snapshot without visiting it.

low
Exposed service

An open administrative port, forgotten host or misconfigured service reachable on one of your own domains.

high
Data leak

Breached or leaked data tied to your hosts, credentials or customer records.

critical

Severity shown is the typical grade for the type. The rule applied to a specific finding accounts for what the source actually reported.

Find out what is already registered against your domains

Give us your domains in a 30-minute session and we will run all six feeds live. Most teams are surprised by at least one certificate they did not know existed.