Skip to content
BreachForecast

Platform

From one lookalike to the whole campaign.

Five capabilities that work together, using only public signals.

Lookalike detection

New domains imitating your brand, found as they're registered.

  • Typos and character swaps
  • Homoglyphs that look identical on screen
  • Added words: "-secure", "-login", "-verify"
  • New and unusual TLDs

Campaign mapping

One lookalike leads to the rest. Shared commodity infrastructure (big CDNs, parking, mainstream mail providers) is filtered out so links mean something.

  • Shared IPs, name servers and mail servers
  • SOA contacts and TLS certificates
  • Registrar and registration timing

Infrastructure watchlist

Once a campaign is mapped, anything new that appears on its infrastructure is flagged, even with no brand in the name.

  • Watches the campaign, not just the name
  • Catches domains that look nothing like you

Switch-on alerts

Delivered in the portal, and to email, Slack, Teams or webhook.

  • Mail server appears
  • Bulk-email service set up (SendGrid, Mailgun, Amazon SES and others)
  • Website goes live
  • Login form appears

Blocklists

Export a campaign's domains and infrastructure for your controls.

  • Email gateways
  • DNS filters
  • Web proxies

Find out what's being prepared against you.

Request a briefing