Attackers register lookalike domains days before launching. Phishing Hunter watches CT logs at certificate issuance, runs OCR and logo detection against every flagged domain, and alerts your team while the infrastructure is still being assembled.
Request a Demo8+ CT logs (Google, Cloudflare, Let's Encrypt, Sectigo, and more) are watched continuously, with automatic failover if a log goes stale.
Every new domain is checked against your brand watchlist using lexical similarity and typosquatting heuristics.
Playwright captures a real headless-Chrome screenshot of every flagged domain; Tesseract OCR (CLAHE-preprocessed) and OpenCV/ORB logo detection catch visual lookalikes that text-based scanners miss.
Findings are enriched with VirusTotal, URLScan, WHOIS, and GeoIP data, then combined into a multi-layer severity score — CRITICAL, HIGH, or MEDIUM.
Beyond text similarity, four independent signals catch clones that evade lexical matching — each one hard for an attacker to avoid without giving up the impersonation.
Catches internationalized domains that swap in Unicode characters visually identical to Latin letters (a Cyrillic "а" for an "a"). Normalizes against the real ASCII form and adds a scoring bonus when confusables appear.
Compares the suspect's screenshot against a legitimate reference re-captured from the real brand site every 12 hours, using perceptual image similarity. A strong visual match or a detected login form escalates severity a level.
Pre-generates known typosquatting variants (character swaps, omissions, duplications) for each protected brand and matches exactly — catching cases where general fuzzy similarity falls below threshold.
Compares the perceptual hash of the suspect's favicon against the known favicons of protected brands, flagging clones that copy the real site's assets without adapting the domain.
8+ CT logs watched continuously, with automatic failover and hot-reload of the log inventory from Chrome's official list — coverage survives a log being deprecated, with no restart.
Flags registered-but-unhosted domains in the 24–72h window before a phishing site goes live, re-checking DNS hourly and promoting to full analysis the moment it activates.
Live WebSocket feed of processed certificates, watchlist/alert triage over thousands of entries, historical charts, and on-demand analysis of any single domain — with signed-cookie sessions, login rate limiting, and admin vs. read-only roles.
Promising-but-empty domains are re-checked with progressive backoff and auto-expire if they never show activity — so nothing gets forgotten and nothing lingers as noise.
VirusTotal, URLScan.io, WHOIS, and GeoIP context queried in parallel and attached to every finding automatically.
Telegram, Email, and Slack notifications, filtered by severity so your team isn't drowning in noise, with forensic evidence saved for CRITICAL and HIGH.