For security teams

Brand phishing in the queue you already work.

Averrow finds lookalike domains and certificates aimed at your brand, triages the noise by rule, and sends alert and takedown events to your SIEM or ticketing tool.

Illustrative Fictional brand, example domains
acme-secure-login.example High Registered yesterday, serving a login page
acme-login.example New cert Certificate issued 2 hours ago
acme.example Set aside Your own domain, set aside with the reason recorded
In your console. On Business and Enterprise, also sent to your SIEM
registered lookalike domains found in the last 30 days
2,300+
threats tracked
1.2M+
hosting providers mapped
12,000+

How we count each number

How it works

Find, triage, route.

Each step produces something you can see in your console, and the last one lands where your team already works.

  1. Find

    We generate the lookalikes of every domain you protect and flag the ones that get registered. Certificate-transparency logs are checked every hour for certificates issued to names that look like your brands. Findings also draw on 40+ threat and intelligence sources.

    acme-secure-login.example High Serving a login page
    acme-login.example New cert Certificate issued 2 hours ago
  2. Triage

    Low-value noise is dismissed automatically, with the reason recorded, so your queue holds what needs a decision. Your own official domains are recognised and set aside.

    acme.example Set aside Your official domain. Reason recorded.
    acme-pay.example Low Parked, re-checked
  3. Route

    Alerts appear in your Averrow console. On Business and Enterprise, alert and takedown events also go to your webhook, SIEM or ticketing tool, set up with our team.

    Alert raised Routed Sent to your SIEM
    Takedown status changed Routed Sent to your ticketing tool

Find

We generate the lookalikes of every domain you protect and flag the ones that get registered. Certificate-transparency logs are checked every hour for certificates issued to names that look like your brands. Findings also draw on 40+ threat and intelligence sources.

acme-secure-login.example High Serving a login page
acme-login.example New cert Certificate issued 2 hours ago

Triage

Low-value noise is dismissed automatically, with the reason recorded, so your queue holds what needs a decision. Your own official domains are recognised and set aside.

acme.example Set aside Your official domain. Reason recorded.
acme-pay.example Low Parked, re-checked

Route

Alerts appear in your Averrow console. On Business and Enterprise, alert and takedown events also go to your webhook, SIEM or ticketing tool, set up with our team.

Alert raised Routed Sent to your SIEM
Takedown status changed Routed Sent to your ticketing tool
Your tools

Into the stack you already run.

Our team sets up each connection with you. Webhooks and the connectors belong to Business and Enterprise.

  • Webhooks Alert and takedown events to an endpoint you give us, set up with our team. Business and Enterprise
  • Splunk SIEM connector, set up with our team. Business and Enterprise
  • Microsoft Sentinel SIEM connector, set up with our team. Business and Enterprise
  • QRadar SIEM connector, set up with our team. Business and Enterprise
  • Jira and ServiceNow Ticketing connectors, set up with our team. Business and Enterprise
  • STIX 2.1 export A standard threat-intelligence format, delivered by our team. On request
Takedowns

Filed under your rules.

Your team decides how much runs on its own.

  • Domains and phishing URLs. Abuse reports go to registrars and hosting providers, with an evidence summary attached to each draft.
  • Three levels. Off (you approve each one), Semi-auto (approval for anything outside your rules) and Auto (within your signed scope).
  • Nothing without your say. A takedown is filed only with your approval or under rules you've signed. Removal is the provider's decision, and removed domains are re-checked.

See how takedowns work in full.

Scope

What's covered, and what isn't.

Every claim on this page has a limit. These are the limits.

Security teams: covered and not covered
Area Covered Not covered
Detection Lookalikes of the domains and brands on your account, flagged when registered and re-checked after, with hourly certificate-transparency checks for brand-like names. Every possible variation of your name, and brands you haven't added.
Triage Rule-based. Low-value noise is dismissed automatically with the reason recorded. Tell us your official domains, CDNs and partners and we set them aside for you. Rules you write yourself, and a published list of the rules.
Into your tools Alert and takedown events to webhooks and to Splunk, Microsoft Sentinel, QRadar, Jira and ServiceNow, on Business and Enterprise, set up with our team. Connectors you configure yourself in the console, and event types beyond alerts and takedowns.
Export STIX 2.1 export of your own findings, on request, delivered by our team. An API or feed you query yourself.
Takedowns Drafted for lookalike domains and phishing URLs, and filed with your approval or under your signed rules. Filing without your approval, and a promise that a provider will remove a domain.

Detection

Covered
Lookalikes of the domains and brands on your account, flagged when registered and re-checked after, with hourly certificate-transparency checks for brand-like names.
Not covered
Every possible variation of your name, and brands you haven't added.

Triage

Covered
Rule-based. Low-value noise is dismissed automatically with the reason recorded. Tell us your official domains, CDNs and partners and we set them aside for you.
Not covered
Rules you write yourself, and a published list of the rules.

Into your tools

Covered
Alert and takedown events to webhooks and to Splunk, Microsoft Sentinel, QRadar, Jira and ServiceNow, on Business and Enterprise, set up with our team.
Not covered
Connectors you configure yourself in the console, and event types beyond alerts and takedowns.

Export

Covered
STIX 2.1 export of your own findings, on request, delivered by our team.
Not covered
An API or feed you query yourself.

Takedowns

Covered
Drafted for lookalike domains and phishing URLs, and filed with your approval or under your signed rules.
Not covered
Filing without your approval, and a promise that a provider will remove a domain.
Related

The platform behind this role

Other roles

Where the work gets shared

See what's already aimed at your brand.

Run a free domain scan, no signup. Or book a demo and we'll set up monitoring and your SIEM routing with you.