Threat Intelligence / Anti-Phishing

Hunt phishing campaigns before they hunt your users.

Attackers register lookalike domains days before launching. Phishing Hunter watches CT logs at certificate issuance, runs OCR and logo detection against every flagged domain, and alerts your team while the infrastructure is still being assembled.

Request a Demo
phishing-hunter — CT monitor
▸ phishing-hunter monitor --domain example.com ✓ Watching 8 CT logs — Google, Cloudflare, Let's Encrypt... ✗ New cert issued: examp1e-secure-login.com (47 min ago) ✓ Running OCR + logo detection... ✗ Logo match: 94% — visual clone of example.com confirmed ✗ MX records active — ready to receive stolen credentials ✓ Alert dispatched — Slack, email, webhook Domain flagged 71h before first phishing email sent

From certificate issuance to alert, in four layers.

1. Certificate Transparency Monitoring

8+ CT logs (Google, Cloudflare, Let's Encrypt, Sectigo, and more) are watched continuously, with automatic failover if a log goes stale.

2. Similarity & Typosquat Detection

Every new domain is checked against your brand watchlist using lexical similarity and typosquatting heuristics.

3. Visual & Content Analysis

Playwright captures a real headless-Chrome screenshot of every flagged domain; Tesseract OCR (CLAHE-preprocessed) and OpenCV/ORB logo detection catch visual lookalikes that text-based scanners miss.

4. Threat Intel Enrichment & Scoring

Findings are enriched with VirusTotal, URLScan, WHOIS, and GeoIP data, then combined into a multi-layer severity score — CRITICAL, HIGH, or MEDIUM.

Signals an attacker can't dodge.

Beyond text similarity, four independent signals catch clones that evade lexical matching — each one hard for an attacker to avoid without giving up the impersonation.

IDN / Homoglyph Detection

Catches internationalized domains that swap in Unicode characters visually identical to Latin letters (a Cyrillic "а" for an "a"). Normalizes against the real ASCII form and adds a scoring bonus when confusables appear.

Visual Diff (Clone Detection)

Compares the suspect's screenshot against a legitimate reference re-captured from the real brand site every 12 hours, using perceptual image similarity. A strong visual match or a detected login form escalates severity a level.

Permutation Engine

Pre-generates known typosquatting variants (character swaps, omissions, duplications) for each protected brand and matches exactly — catching cases where general fuzzy similarity falls below threshold.

Favicon Matching

Compares the perceptual hash of the suspect's favicon against the known favicons of protected brands, flagging clones that copy the real site's assets without adapting the domain.

Detection that doesn't wait for a report.

Resilient Multi-Log Monitoring

8+ CT logs watched continuously, with automatic failover and hot-reload of the log inventory from Chrome's official list — coverage survives a log being deprecated, with no restart.

Pre-Activation Detection

Flags registered-but-unhosted domains in the 24–72h window before a phishing site goes live, re-checking DNS hourly and promoting to full analysis the moment it activates.

Web Dashboard with RBAC

Live WebSocket feed of processed certificates, watchlist/alert triage over thousands of entries, historical charts, and on-demand analysis of any single domain — with signed-cookie sessions, login rate limiting, and admin vs. read-only roles.

Watchlist Lifecycle

Promising-but-empty domains are re-checked with progressive backoff and auto-expire if they never show activity — so nothing gets forgotten and nothing lingers as noise.

Threat Intelligence Enrichment

VirusTotal, URLScan.io, WHOIS, and GeoIP context queried in parallel and attached to every finding automatically.

Multi-Channel Alerting

Telegram, Email, and Slack notifications, filtered by severity so your team isn't drowning in noise, with forensic evidence saved for CRITICAL and HIGH.

8+
CT Logs Monitored
10
Parallel Workers
8
Scoring Signals
24–72h
Pre-Activation Warning

Catch the next campaign before it launches.

Request a Demo