GNSAC
Solutions
Solution — Phishing & brand protection

Detect phishing infrastructure and brand impersonation earlier.

Vigil monitors certificate-transparency records, phishing sources and relevant underground activity for look-alike domains, fake login pages and other forms of brand abuse, retaining evidence for investigation and response.

On-prem OVF/OVAIsolated per-customer DBSaaS managed cloud option
vigil — phishing brand LIVE
Phishing & brand — finding view
3.1Mphishing URLs indexed
CT-logcertificate watch for your brand
7.5Mindicators indexed (IP, domain, hash)
Live production environmentcontinuous collection
01

Common brand-abuse patterns

01

Look-alike domains

Domains such as example-corp-login.com or examp1e-corp.com may be registered and configured to resemble a legitimate customer or employee service.

02

Phishing kits imitating customer portals

Kits may reuse logos, page styling and interaction flows. Relevant references and infrastructure can appear across monitored sources.

03

Brand abuse across multiple channels

Fake applications, social accounts and messaging groups may impersonate support or other trusted functions.

02

How Vigil identifies and prioritises it

Certificate-transparency records, phishing URL intelligence and underground collection are correlated to the authorised brand context rather than treated as isolated keyword matches.

  1. 01 · Collect

    CT logs, phishing intelligence, kits and source references

    Phishing URLs are monitored; new certificates are evaluated against your brand tokens; relevant kit and fake-page references are collected with source context.

  2. 02 · Correlate

    Brand tokens, visual similarity, intent

    Domains are scored for brand similarity, live content (payment page? login form?), hosting and registration patterns.

  3. 03 · Prioritise

    Live and credential-collecting infrastructure first

    A live look-alike domain containing a login or payment form can be prioritised above a parked domain, with the scoring factors available for review.

  4. 04 · Act

    Evidence for response

    Where available, findings include screenshots, registration, hosting, certificate and timeline data to support internal response and external abuse reports.

Phishing & brand — finding view LIVE
Phishing & brand — finding view

Look-alike domain with live login page, certificate issuance and hosting details — the finding as your analyst sees it.

03

What changes for your team

Earlier review of look-alike infrastructure

Certificate and source monitoring can surface look-alike domains at issuance or first observation, enabling earlier investigation.

Shared evidence for fraud and security teams

A common finding record gives both teams source, timeline, infrastructure and available screenshot evidence.

Continuous monitoring to supplement manual review

Automated monitoring reduces reliance on periodic manual domain searches while keeping analysts in control of validation and response.

FAQ

Questions we get asked

Do you manage removal requests?+

Where available, Vigil prepares an evidence package containing screenshot, WHOIS, hosting, certificate and timeline data, and can export a blocking list. Your team or legal counsel submits and manages the removal request.

How many brands can we monitor?+

Brand names, product names and subsidiaries can be added as watchlist items. Applicable limits depend on the selected licence and agreed scope.

Does it cover phishing aimed at employees too?+

Yes — phishing domains and kits targeting your staff are scored and delivered the same way; pair it with GNSAC Phishing for awareness.

Get started

Review brand-monitoring and response workflows.

Review representative findings and brand-monitoring workflows. Customer-specific checks are performed only after scope and authorisation are confirmed.

Phishing & Brand Protection — Typosquat and Phishing Kit Detection | GNSAC Vigil