Protect

Protect your brand from phishing and impersonation

This is where you set up brand monitoring. Add the domains your team owns, then Threats.run checks new threat intelligence for lookalike domains, phishing URLs, and other abuse that may target your brand. Use Workspace separately as an investigation notepad when you need to review evidence.

What you can add

Company domains, login domains, product domains, and other domains your team is allowed to defend.

What we look for

Phishing pages, typo-squats, fake brand domains, suspicious URLs, and email abuse indicators.

What you can do next

Review evidence, decide if it is real abuse, and track takedown cases from one place.

How to use this page

  1. 1. Add Protected Domains. Add domains your team owns or is authorized to defend, then verify them with DNS when possible.
  2. 2. Watch for matches. Threat pages will show when an IOC looks related to your protected domains.
  3. 3. Investigate in Workspace. Use Workspace like a case notepad for URLs, headers, logs, decoded payloads, and analyst notes.
  4. 4. Open a takedown case. If the match is real abuse, collect the evidence and track the case in Takedown Cases.

Quick answers

Is this only for domains?

Not only domains, but domains are the starting point for this Protect flow because phishing and impersonation usually involve URLs, email domains, or lookalike domains. Workspace is for investigation notes, not asset management.

Why verify a domain?

Verification proves you own or control it, so matches and takedown evidence are tied to the right organization.

What happens after a match?

You review the source, confirm whether it is abuse, then create a takedown case to track the response.