Impersonation

Prev Next

Brand impersonation rarely starts with a polished phishing kit. It starts with a domain that looks close enough to yours: a swapped letter, a digit that resembles a character, a brand-plus-keyword combo. Silent Push Impersonation tools are built to find those candidates early, explain how they spoof you, and keep watching after the first search.

All impersonation tools live under Reconnaissance > Impersonation. Two redesigned queries, Domain Impersonation and Assets Impersonation, are the primary workflows for lookalike domains. Email, Favicon, and HTML Title Impersonation remain available for adjacent signals: spoofed mail infrastructure, stolen icons, and copied page titles.

What Impersonation does

Use Domain Impersonation when you have a specific brand or hostname to protect. Use Assets Impersonation when you already maintain that inventory in My Assets and want one list to drive monitoring. The other modules answer narrower questions: who is standing up mail for a lookalike, who is reusing your favicon, and who is copying your HTML title.

Domain Impersonation and Assets Impersonation share the same form pattern: a required starting point, a time frame, exclusions, typosquat mode, digit-homoglyph and subdomain toggles, then Submit. Save the search to monitor new candidates over time. Results land in the Notification Center and in My Searches.

How the modules differ

The starting input is the difference that matters.

  • Domain Impersonation asks for a target domain. Use it for a named brand, a campaign hostname, or a domain you do not already keep in My Assets.

  • Assets Impersonation asks for a My Assets folder. Use it when the inventory already exists and should stay the source of truth for scheduled hunts.

Do not treat Domain Impersonation as the asset-list workflow. That path belongs to Assets Impersonation.

Note

Domain Impersonation is the primary module and has been redesigned for simpler use with asset lists, scheduled monitoring, and background processing. The previous version is marked Legacy.

Shared monitoring pattern

Run a preview first. When the candidate set looks right, click Save, name the search, and schedule it from My Searches. New findings appear in the Notification Center and under My Searches, with manual and scheduled runs kept distinct. A clock icon means the search is scheduled. Open the saved search to edit or remove the schedule without deleting history.