Threat intelligence
Catch the lookalike domain before it serves a page
Brand impersonation and phishing infrastructure are the same attack viewed from two desks. TracBrand runs a second pipeline alongside brand discovery that watches your own domains through six external feeds — and reports what it finds in the same graded queue.
The window
A typosquat announces itself long before it attacks
Registering a lookalike domain and standing up a convincing phishing page are separate jobs, usually days apart. The certificate is issued in between, and certificate transparency logs are public.
That gap is the only part of a phishing campaign where you are ahead. TracBrand monitors it continuously, so a lookalike certificate becomes a finding on your queue rather than something you learn about from a customer who lost money.
No AI in this pipeline
Severity is decided by explicit rules per finding type. Reproducible, auditable, and defensible in a security review.
Permanent deduplication
Findings are keyed by source and URL per brand, so a long-standing exposure does not re-alert on every cycle.
Runs on your cadence
Threat hunting can run alongside brand discovery, on its own, or not at all — configured per brand.
One queue, two pipelines
Domain findings and brand misuse cases share triage, ownership and audit, so nothing falls between two teams.
The feeds
Six sources, every one of your domains
Each domain you register is run against all six feeds on your monitoring cadence, with per-source result caps so a noisy feed cannot flood your queue.
Certificate transparency
A lookalike domain the moment someone issues an SSL certificate for it — usually days before the site goes live
Phishing feeds
Live phishing pages impersonating your brand to harvest customer logins
Public code search
Your domains, configuration or secrets committed to public repositories
URL scan corpus
Lookalike pages other researchers have already captured and published
Internet-wide scan data
Exposed servers, open admin ports and forgotten infrastructure on your domains
Leak intelligence
Breached or leaked data tied to your hosts and credentials
Finding types
What lands on the queue, and how it is graded
Six finding types, each with a fixed severity rule. An exposed database and a newly issued certificate are never given the same weight.
| Finding type | Typical severity | What it means |
|---|---|---|
| Certificate issuance A certificate has been issued for a name resembling one of your domains. The strongest early signal you can get, because it usually precedes any content. | medium | A certificate has been issued for a name resembling one of your domains. The strongest early signal you can get, because it usually precedes any content. |
| Phishing imitation A live page impersonating your brand, confirmed by a phishing feed and attributed to the domain it targets. | critical | A live page impersonating your brand, confirmed by a phishing feed and attributed to the domain it targets. |
| Code leak Your domains, configuration or credentials appearing in public source code repositories. | high | Your domains, configuration or credentials appearing in public source code repositories. |
| Public scan A lookalike page another researcher has already captured and published, giving you a rendered snapshot without visiting it. | low | A lookalike page another researcher has already captured and published, giving you a rendered snapshot without visiting it. |
| Exposed service An open administrative port, forgotten host or misconfigured service reachable on one of your own domains. | high | An open administrative port, forgotten host or misconfigured service reachable on one of your own domains. |
| Data leak Breached or leaked data tied to your hosts, credentials or customer records. | critical | Breached or leaked data tied to your hosts, credentials or customer records. |
Severity shown is the typical grade for the type. The rule applied to a specific finding accounts for what the source actually reported.
Find out what is already registered against your domains
Give us your domains in a 30-minute session and we will run all six feeds live. Most teams are surprised by at least one certificate they did not know existed.