In today's digital threat landscape, protecting your brand and your customers is essential. Axur’s Intelligent Monitoring of Similar Domains enables the detection and takedown of fraudulent domains that attempt to impersonate your company. But how can you perform even more effective and targeted searches to protect your brand?
This article will guide you through four levels of detection, from the most restrictive to the most comprehensive, so you can search like a true professional in Threat Hunting for fraudulent similar domains.
Level 1: Exact Brand Match Domains (Multiple TLDs)
This is the most restrictive level, detecting only domains that exactly match your brand name but use different Top-Level Domains (TLDs). It's ideal for companies looking to catch the most obvious impersonations.
Examples of detection:
netflix.cn
netflix.co
netflix.com.mx
netflix.online
Query example:
domainLabel=netflix AND referenceType=DOMAIN
Level 2: Exact Match in Domain Names and Hosts
At this level, the search expands to include exact matches in both domain names and hostnames. This helps identify subdomains or services trying to mimic your brand.
Examples of detection:
netflix.com
netflix.github.io
netflix.co
netflix.com.br
Query example:
(domainLabel=netflix OR subdomain=netflix) AND referenceType=DOMAIN
Level 3: Domain and Host Match with Typos and Homoglyphs
Moving up a level, this search includes detection of domains and hosts that use typosquatting (misspellings) and homoglyphs (visually similar characters that deceive users). This is critical for capturing more sophisticated fraud attempts.
Examples of detection:
netflíx.com
nettflix.github.io
netfllx.co
online.netflīx.com
Query example:
(domainLabel=netflix~1 OR sanitizedDomainLabel=netflix~1 OR subdomain=netflix~1 OR sanitizedSubdomain=netflix~1) AND referenceType=DOMAIN
Level 4: Comprehensive Match with Typos and Homoglyphs in Any Position
The most comprehensive level. Here, the search combines typosquatting and homoglyph detection with the ability to find your brand at the beginning, middle, or end of any word used in the domain or host name. Ideal for maximum fraud protection.
Examples of detection:
newnetflix.github.io
netflis.co
ѕuрроrt-netflix.com
nētflixlogin.com
Query example:
(domainLabel=*netflix* OR subdomain=*netflix* OR domainLabel=netflix~1 OR subdomain=netflix~1 OR sanitizedDomainLabel=*netflix* OR sanitizedSubdomain=*netflix* OR sanitizedDomainLabel=netflix~1 OR sanitizedSubdomain=netflix~1) AND referenceType=DOMAIN
Need to adjust your rules?
Keep in mind that the ideal detection level depends on your risk profile and available resources. Start with a more conservative level and broaden your scope as needed, monitoring the results and refining your queries to optimize cost-effectiveness and reduce false positives.
If you have any questions, feel free to reach out at [email protected] 😊