Brand impersonation · detection & takedown

Are your customers on a fake site?

Perseus Defend protects banks and consumer brands from impersonation. It finds the fake sites and lookalike domains opened in their name, documents each one with evidence captured at detection, and gets it taken down.

87,141Takedowns in the last 3 months

Category
Brand impersonation detection & takedown
Built for
Banks, fintech, e-commerce, gaming and telecom brands, worldwide
Evidence
Screenshot and registration record, captured at detection
Filed with
Registrars, hosting providers, blocklists and authorities
Export
PDF · Excel · CSV · JSON

Trusted infrastructure

  • AbuseIPDB
  • Spamhaus
  • Google
  • Cloudflare

Why lookalikes

Most fakes aren’t hacked.They’re registered.

Phishing runs on domains bought for the job. Perseus Defend finds them early and gets them taken down.

A takedown request “could take anything between hours to days or even weeks”, says the UK’s National Cyber Security Centre. That is why the evidence has to exist before anyone files.

NCSC · Takedown: removing malicious content to protect your brand(opens in a new tab)

Exhibit 01 · Lookalike check

Type your domain.See it spelled wrong.

Type your domain and see the variants an attacker would try first. Computed in your browser; nothing is sent or stored.

Or try ours:

12 variants generated for perseusdefend.com

  1. perseu5defend.comhomoglyph · digit
  2. perseusdefendofficial.comkeyword
  3. perseusdefend.liveextension swap
  4. preseusdefend.comletter swap
  5. prseusdefend.comomission
  6. perseusd-efend.comhyphenation
  7. pers3u5defend.comdouble homoglyph
  8. perseusdsefend.comkeyboard slip
  9. perrseusdefend.comdoubled letter
  10. persousdefend.comvowel swap
  11. pers3usdefend.comhomoglyph · digit
  12. perseusdefendsecure.comkeyword

Candidates, not findings: none of these was looked up.

12 of 174 variants for perseusdefend.com.

The full scan our analysts run in the panel is much larger: it tries more domain extensions and checks which variants are already registered.

Talk to an analyst about perseusdefend.com

Exhibit 02 · One case, start to finish

Watch one fake gofrom found to gone.

One lookalike of our demo brand, followed from the moment it is found until it can no longer be reached. The screens are your team’s view of the panel, rebuilt with its own labels.

Every domain sits in one of four states

  • Threat

    A live phishing site. It needs a takedown.

  • Monitoring

    Found and watched: parked, empty or still being checked.

  • Temporary Takedown

    Blocked for now, not yet permanent; we keep at it.

  • Takedown

    Unreachable: blocked, suspended or offline.

“Takedown” means the site can no longer be reached. It does not mean the domain was deleted.

  1. 02.1Found

    A lookalike turns up.

    A new lookalike, perseusdefend-giris.com, lands in your panel’s Auto Detection tab, marked Detected By: AI. It sits in Monitoring while it is checked.

    Who acts
    Perseus Defend, automatically
    When
    As soon as it is found
    Where you see it
    Your panel: Auto Detection
  2. 02.2Documented

    Evidence comes first.

    Before any verdict, the page is captured. The screenshot is kept as evidence together with the domain’s registrar and hosting details, and your team can open it in Screenshot Preview.

    Who acts
    Perseus Defend, automatically
    When
    At detection, before any verdict
    Where you see it
    Your panel: Screenshot Preview
  3. 02.3Classified

    A verdict, with its confidence.

    AI reads the captured page and labels it Phishing, with a confidence score (96% here, an illustrative value). The row turns Threat, and your team can check the call against the screenshot.

    Who acts
    AI, open to review by your team and ours
    When
    Once the evidence is in
    Where you see it
    Your panel: Threat status
  4. 02.4Requested

    One request, from the row.

    Your team, or our analysts for you, sends a takedown request from the row, with an optional note. A request can wait for approval first: the record shows Takedown Approval Pending until it clears, then the case opens as Case Active.

    Who acts
    Your team, or our analysts for you
    When
    When you decide
    Where you see it
    Your panel: Send Takedown Request
  5. 02.5Taken down

    Checked until it stays down.

    We file with every party that can act on it: the domain’s registrar, the hosting provider, security and blocklist providers, and the relevant authorities. Then we keep checking until the site stays down. The row turns Takedown and the case closes as Case Succeeded.

    Who acts
    Perseus Defend and our analysts
    When
    Depends on the party hosting it
    Where you see it
    Your panel: Takedown · Case Succeeded

Exhibit 03 · Where a takedown goes

One request.Every party that can act.

Taking a fake down depends on who controls it. You send one request; we file it with each party that can act on it, then keep checking until the fake stays down.

Your takedown request

03.1

Registrar

Can suspend the domain name, so the address stops working.

Typical pace

Hours to days

Takes it down

03.2

Hosting provider

Can take the site’s pages offline.

Typical pace

Hours to days

Takes it down

03.3

Security & network providers

Can put a warning in front of the site and pass the report on to its host.

Typical pace

Their own queue

Blocks or warns

03.4

Browser & search blocklists

Can warn visitors before the page opens or drop it from search results. They don’t delete the site.

Typical pace

Their own queue

Blocks or warns

03.5

Authorities

Where the law allows, can have access blocked on their country’s networks.

Typical pace

Their own procedure

Blocks or warns

03.6

Social platforms

Can remove an account that impersonates your brand.

Typical pace

Each platform’s own queue

Takes it down
Closed · the fake is unreachable

Two clocks.Only one is ours.

Finding, documenting and classifying a fake runs on our clock. Taking it down runs on the clock of whoever hosts or lists it, and nobody can promise their pace.

Our part

Find, document, classify

As soon as it is found

Your decision

The takedown request

Whenever you send it

Their part

The parties that host or list it

Hours to days, sometimes weeks

Time after the fake is found · log scale

An illustration of typical pace, not a measurement.
Covered
  • Lookalike domains
  • Cloned sites
  • Redirect chains
  • Fake social accounts you point us to

Timings describe typical behaviour, not guarantees: every party works to its own rules and pace. The UK’s NCSC puts takedown at anywhere from hours to days, or even weeks. NCSC

Exhibit 04 · The panel, uncropped

This is the product.Not a mockup.

app.perseusdefend.com / overview
Perseus Defend Overview in the demo tenant: a pulse line, four status-group cards, a status distribution chart and recent detections. Figures are an anonymised replay.
Exhibit 04.1 · Overview · demo tenant, anonymised replay · numbers are not company statistics
  • A pulse line at the top says whether anything needs attention right now.
  • One card per status group (Threat, Monitoring, Temporary Takedown, Takedown), each opening the filtered list.
  • Recent detections show each domain’s status and whether AI or a person found it.

Exhibit 05 · The film

All data in the film is an anonymised replay.

Music: “Inspired” by Kevin MacLeod (incompetech.com), licensed under CC BY 4.0

Watch a clone get found, documented and filed.

73 seconds in the panel, with anonymised data: the daily overview, the threat list, the screenshot kept as evidence, the takedown request and the case that follows it.

Chapters

Read the transcript
  1. 00:00

    OpeningYour customers may be transacting on a fake copy of your site right now. And before you notice, your brand’s reputation is at risk.

  2. 00:14

    Overview: what is happening today?Perseus Defend finds fake sites opened in your brand’s name, documents them and gets them taken down. The panel is the daily summary: is a threat live, how many domains are in which state. Let’s follow this domain from recent detections.

  3. 00:29

    The threat listEvery record the AI finds sits on one row with brand, detection date and status. Here is the domain we are following.

  4. 00:38

    Evidence: the screenshotThe screenshot taken at detection time is kept as evidence: is it really a copy of your site, at a glance.

  5. 00:46

    The takedown requestThe takedown request comes from a single menu: confirm the domain, add a note, send. Bulk sending is possible too.

  6. 00:56

    Case trackingThe request becomes a case; which channel, when, and what came back, all here in order.

  7. 01:06

    ClosingDetect faster. Take down sooner. Perseus Defend.

Objections

Questions a CISOshould ask us.

Straight answers, including what we don’t do.

Ask an analyst

Lookalike domains and cloned websites that use your brand, plus the fake social media accounts you point us to, which are added to your panel by URL.

Our part runs as soon as a domain is found: the site is documented with evidence and classified. Once a takedown is filed, the parties that register and host the fake set the pace, usually hours to days.

Every AI verdict is stored with its confidence score and the screenshot taken at detection, so a person can check it. Your own and partner domains go on the Whitelist and are not flagged again. Nothing is filed without a takedown request, and a request can wait for approval before it goes out.

Finding, documenting and classifying are automatic. The takedown request is raised in the panel by your team or by our analysts, and in some setups it is raised automatically. We then file the case with every party that can act on it.

The case doesn’t rest on one party. Where it qualifies, it also goes to the other parties that can block access to the site: security and blocklist providers and the relevant authorities. We keep checking the site until it stays down.

That the site can no longer be reached. It doesn’t necessarily mean the domain was deleted, and we don’t report it that way. If a closed site comes back, it is picked up again.

In your panel, each record keeps the screenshot captured at detection, the registrar, the IP owner, the detection date and the status. Lists export as PDF, CSV, Excel or JSON.

Each client works in its own tenant: your records are visible to your team and to our analysts, not to other clients. Personal data is processed in line with KVKK and GDPR; see our privacy policy for the details.

You talk with one of our analysts. We walk you through the panel and look at your domain together, so you can see how a case would run for your brand.

Next case

perseusdefend-giris.com · Takedown

Find the fake. Take it down.

Tell us which brand you need to protect. We’ll walk you through the panel and follow one case from detection to takedown.