New attack infrastructure leaves traces the moment it's created: a certificate, a registration, a first DNS resolution. Webamon watches all of it, continuously.
Newly issued SSL certificates in near real time. Phishing sites need certificates too, and CT is often the very first trace of brand abuse and new campaign infrastructure.
Fresh registrations as they appear. Spot typosquats, lookalikes, and suspicious naming patterns on day zero, before the domain has ever served a page.
Domains at their first DNS resolution, often the earliest signal that dormant infrastructure is going live, including domains registered long ago and held in reserve.
Exposed directory listings across the web: phishing kits, stealer logs, and staging servers left open. A goldmine for attribution and early kit analysis.
Curated intelligence from open-source feeds, enriched with Webamon scan context and pivot-ready indicators. Signal, not noise.
Feeds are wired into the rest of the platform. Every event is a pivot point, not just a line in a stream.
Every feed event is indexed and searchable alongside Webamon's full scan corpus. Query feeds with the same syntax you use everywhere else.
Send any suspicious domain from a feed straight into the Sandbox for a full analysis: screenshot, certificates, technologies, and risk score in one click.
Turn any feed query into a monitor and get alerted by email, webhook, or Slack every time new infrastructure matches your patterns.
All five feeds are included on every plan, including free Starter
Search them, scan from them, and build monitors on top of them
No sales call required