Each campaign is a living investigation object, curated and updated by Webamon as the actor's infrastructure changes. No stale IOC lists. You see what's live right now.
Every domain attributed to the campaign, from first observation onward, with new infrastructure added as it's discovered.
Which domains are serving content right now versus parked, sinkholed, or taken down, so you can prioritise blocking what's active.
Hosting, certificates, technologies, and kit artifacts behind the campaign: the patterns that connect today's domains to tomorrow's.
How the campaign has evolved over time: growth waves, hosting moves, and takedown responses, all recorded as they happen.
Most intel tells you about campaigns after they've done damage. Webamon surfaces new infrastructure clusters automatically: groups of related domains, certificates, and kit fingerprints forming into something coordinated, before they're promoted to full tracked campaigns.
You see attacks forming, not just confirmed. When a cluster matures into a campaign, the full history comes with it.
Related infrastructure is grouped by shared fingerprints across scans, certificates, and feeds. No manual pivoting required.
Analysts review and promote clusters into named, tracked campaigns, so every campaign starts with its full pre-history already mapped.
Browse and pivot through campaigns in the console, or pull every campaign programmatically: domains, liveness, and infrastructure, straight into your SIEM, blocklists, and tooling.
Explore every tracked campaign interactively: filter domains by liveness, pivot into scans and screenshots, and follow infrastructure changes as they land.
Available from the Researcher plan
Available from the Research Lab plan up
80+ live tracked campaigns, updated continuously
Console access from Researcher, full API from Research Lab
From first cluster to final takedown