Assets Impersonation searches for domains that look like or target the assets you already track. You do not start from a blank query. You start from a domain or IP folder in My Assets. The feature then hunts for lookalikes of everything in that list.
Choose a domain (or IP) folder from My Assets. Assets Impersonation searches for domains that resemble or target the assets on that list. Select a list, then click Submit to run a preview.
That workflow matters. Instead of asking analysts to remember every brand domain, product subdomain, and campaign hostname, the search inherits the inventory you already maintain. One list becomes the source of truth for impersonation hunting.
How the query form is structured
The Query Form is compact, but each control changes the quality of the candidate set. The required starting point is the target assets list. From there, you narrow noise and decide how aggressive the lookalike logic should be.
Target Assets List: Required. Select the My Assets folder that contains the domains or IPs you want to protect.
Time Frame: Scope the search window, for example, Last Week, so results stay relevant to recent registrations and activity.
Excluded Domains: Remove known-good or already-reviewed domains to avoid cluttering the candidate list.
Excluded Keywords: Filter out terms that generate false positives in your environment.
Typosquat Mode: Set to Strict when you want higher-confidence lookalikes and fewer speculative matches.
Include Digit Homoglyphs: Turn on to catch substitutions such as
0foroor1forl.Search On Subdomains: Expand the hunt beyond apex domains when attackers hide impersonation one level down.
Submit / Reset: Run a preview immediately, or clear the form and start over without leaving the page.
The practical sequence is simple: select the assets list, set a time frame, apply exclusions, choose a typosquat mode, decide whether to include digit homoglyphs and subdomains, then submit. You can save the search later. You do not have to perfect monitoring settings before you see a preview.
How to read the results
After a search runs, the Results pane is not just a raw domain dump. It is organized so an analyst can decide what to investigate first.
Candidates
You see total matches, plus counts for the last 1 day, last 7 days, and IoFA. That split is the difference between “this lookalike has existed for years” and “this appeared in the last day and needs attention now.”
Impersonation Type Overview
Candidates are grouped by how they spoof you: typosquatting, homoglyphing, combosquatting, and more. That context tells you the attacker’s method, not just the string similarity. A combosquat that pairs your brand with login, secure, or support is a different problem than a single-character typo.
Typosquat: Misspelling of the brand domain, for example,
exampel.com.Homoglyph: Visually similar characters substituted, including lookalike Unicode.
Combosquat: Brand name combined with a suspicious or common word, for example,
example-login.com.TLD Concatenation: Brand and TLD combined so the full string spells the brand.
TLD Typosquat: Same brand label with a different or lookalike TLD, for example,
example.co.
Registration Date Overview
Freshly registered domains deserve a different response than aged infrastructure. Registration timing helps you separate opportunistic copycats from domains that may already be warmed up for use.
HTTP Response Overview
Not every lookalike is live. HTTP response context shows whether sites appear active. A parked or empty domain is still worth tracking.
Registrar Distribution and ASN Overview
Infrastructure context matters when you need to cluster related domains, identify a preferred registrar, or see whether candidates sit on the same network. One-off names are noise. Shared ASN and registrar patterns often point to a campaign.
Use these views to prioritize what to investigate first: recency, impersonation method, liveness, and infrastructure clustering, instead of working the list top to bottom.
Save once, monitor continuously
A one-off search finds what exists today. Impersonation does not stop after that snapshot. The Save action turns the query into an asset in its own right.
Click Save, give the search a name and optional description, then manage it from My Searches. Select the asset, click the three-dot icon ( ). From there, you can:
Set a schedule, every 5 minutes, hourly, or daily, so the search runs automatically.
Reopen the search with filters already filled in.
Share it with your organization, so brand protection isn't confined to a single analyst’s session.
A clock icon on a saved search means it is scheduled. New results appear in the Notification Center and, under that, in My Searches, with a distinction between manual and scheduled runs. To stop monitoring, open the search and remove or edit the schedule.