Protect your brand from phishing and impersonation
This is where you set up brand monitoring. Add the domains your team owns, then Threats.run checks new threat intelligence for lookalike domains, phishing URLs, and other abuse that may target your brand. Use Workspace separately as an investigation notepad when you need to review evidence.
Company domains, login domains, product domains, and other domains your team is allowed to defend.
Phishing pages, typo-squats, fake brand domains, suspicious URLs, and email abuse indicators.
Review evidence, decide if it is real abuse, and track takedown cases from one place.
Add your protected domains
Add domains your team owns or is allowed to protect, such as your company website, login domains, and customer-facing product domains.
Investigate suspicious matches
Use Workspace as your investigation notepad. Paste URLs, headers, logs, decoded payloads, and notes while you decide whether a match is real abuse.
Track takedown cases
If a phishing page or impersonation domain is real, turn the evidence into a takedown case and track the response status.
How to use this page
- 1. Add Protected Domains. Add domains your team owns or is authorized to defend, then verify them with DNS when possible.
- 2. Watch for matches. Threat pages will show when an IOC looks related to your protected domains.
- 3. Investigate in Workspace. Use Workspace like a case notepad for URLs, headers, logs, decoded payloads, and analyst notes.
- 4. Open a takedown case. If the match is real abuse, collect the evidence and track the case in Takedown Cases.
Quick answers
Not only domains, but domains are the starting point for this Protect flow because phishing and impersonation usually involve URLs, email domains, or lookalike domains. Workspace is for investigation notes, not asset management.
Verification proves you own or control it, so matches and takedown evidence are tied to the right organization.
You review the source, confirm whether it is abuse, then create a takedown case to track the response.
