# Have I Been Squatted
> The intelligence and response layer for adversary infrastructure. Detect typosquatting and attack infrastructure, investigate evidence, and manage takedowns.

## Pages
- [Have I Been Squatted: Domain Intelligence & Response](https://haveibeensquatted.com/): The intelligence and response layer for adversary infrastructure. Detect typosquatting and attack infrastructure, investigate evidence, and manage takedowns.
- [Platform](https://haveibeensquatted.com/platform): Detect adversary infrastructure, investigate with deep enrichment, and respond with coordinated takedowns. Domain monitoring, Site Canaries, Email Intelligence, and more.
- [Solutions](https://haveibeensquatted.com/solutions): One platform for end-to-end active defense across domain and DNS security, phishing and fraud response, and threat intelligence.
- [Brand Protection](https://haveibeensquatted.com/solutions/brand-protection): Detect and remove lookalike domains, cloned login pages, executive impersonation, and spoofed sender domains before they can harm customers or your brand.
- [Domain & DNS Security](https://haveibeensquatted.com/solutions/domain-security): Monitor lookalike registrations, certificate transparency, DNS changes, and mail infrastructure for adversary activity against your organization as it appears.
- [Phishing & Fraud Response](https://haveibeensquatted.com/solutions/phishing-fraud-response): Triage, cluster, and take down phishing and fraud infrastructure with live domain analysis, evidence capture, provider escalation, and campaign tracking.
- [Threat Intelligence](https://haveibeensquatted.com/solutions/threat-intelligence): Connect indicators into campaigns with certificate transparency, shared infrastructure, and content fingerprints, then deliver evidence to security teams.
- [Blog](https://haveibeensquatted.com/blog): Articles on typosquatting, domain security, brand protection, certificate transparency, DNS abuse, and how security teams detect and respond to malicious domains.
- [Learn](https://haveibeensquatted.com/learn): Guides on domain security, typosquatting, brand protection, threat intelligence, and email security for defenders investigating malicious domains.
- [Customers](https://haveibeensquatted.com/customers): Case studies from security teams using Have I Been Squatted to detect domain abuse faster, prioritize risk, and accelerate takedowns with clear evidence.
- [Partner Program](https://haveibeensquatted.com/partners): Add domain protection to managed services with recurring margins, a multi-tenant console, and original threat research from Have I Been Squatted.
- [Pricing](https://haveibeensquatted.com/pricing): Pro, Business, and Enterprise pricing for domain monitoring, typosquat detection, API access, team workflows, and managed threat response.
- [Contact us](https://haveibeensquatted.com/contact): Contact Have I Been Squatted about pricing, enterprise API access, managed threat intelligence, partnerships, research, press, or support.
- [Careers](https://haveibeensquatted.com/careers): Open roles in security research, backend engineering, and technical marketing at Have I Been Squatted. Remote work across UTC-adjacent time zones.
- [Community Research Program](https://haveibeensquatted.com/community-researchers): Leverage Have I Been Squatted data, publish the research, keep the credit. Community researchers get platform access, merch, and a private Discord.
- [Changelog](https://haveibeensquatted.com/changelog): Product updates, new features, improvements, and fixes for the Have I Been Squatted domain monitoring and typosquat detection platform.
- [About](https://haveibeensquatted.com/about): Have I Been Squatted helps organizations find, preempt, and disrupt attacker infrastructure before it affects their people or operations.
- [Privacy Policy](https://haveibeensquatted.com/about/privacy): Privacy policy for Have I Been Squatted: how personal information and domain monitoring data are collected, used, stored, and protected.
- [Terms of Service](https://haveibeensquatted.com/about/terms): Terms of service for the Have I Been Squatted domain monitoring platform, covering acceptable use, billing, data handling, and service agreements.
- [Security](https://haveibeensquatted.com/about/security): Security practices at Have I Been Squatted, including coordinated disclosure and incident notification. Compliance documentation lives in the Trust Center.
- [Report active abuse](https://haveibeensquatted.com/under-attack): Report active typosquatting, brand impersonation, executive impersonation, or phishing email abuse and route the case to the takedowns team.

## Blog
- [From fake interview to signed ClickOnce: inside a three-payload Windows chain](https://haveibeensquatted.com/blog/from-fake-interview-to-signed-clickonce-three-payload-windows-chain): A fake Web3 interview delivered a signed ClickOnce stager on Windows that unpacked two credential stealers and a persistent Go RAT.
- [Announcing Site Canaries](https://haveibeensquatted.com/blog/announcing-site-canaries): Site Canaries detect cloned and phishing copies of a production page with a small embedded script, then report flagged hostnames alongside domain findings.
- [From typosquatting to macOS backdoor via ClickFix and blockchain C2](https://haveibeensquatted.com/blog/from-typosquatting-to-macos-backdoor-clickfix-blockchain-c2/llms.txt): A macOS ClickFix campaign used typosquatting, clipboard-driven Terminal execution, persistent AppleScript, and a Polygon smart contract as a mutable C2 pointer for backdoor, stealer, RAT, and Ledger replacement modules.
- [When one RMM tool won't get the job done: inside a phishing operation's infrastructure](https://haveibeensquatted.com/blog/three-rmm-tools-one-vps-inside-carrier-phishing-operator-box/llms.txt): A packed carrier-onboarding dropper pulls NetSupport Manager from commodity VPS infrastructure. The same operator box also runs SimpleHelp and ScreenConnect, rotates fresh builds daily, and pivots lures from US carriers to European freight within 24 hours.
- [Announcing Email Intelligence for Microsoft 365](https://haveibeensquatted.com/blog/announcing-email-intelligence-microsoft-365): Email Intelligence ingests domain threat signals from Microsoft 365 mail into Have I Been Squatted lookups. Watchdog adds sender domain blocks in the tenant.
- [When a trusted trucking email delivers remote access](https://haveibeensquatted.com/blog/when-a-trusted-trucking-email-delivers-remote-access/llms.txt): Attackers used what appears to be a compromised Microsoft 365 account at a US freight carrier, sent Bill of Lading phishing to business contacts, and used a PDF link to an S3-hosted EXE that silently installed a pre-configured N-able RMM agent.
- [Have I Been Squatted now integrates with Tines](https://haveibeensquatted.com/blog/announcing-tines-integration): Have I Been Squatted now integrates with Tines, so typosquat permutations, domain analysis data can run directly inside investigation stories.
- [Typosquatted domains were early signals in the Trivy and LiteLLM attacks](https://haveibeensquatted.com/blog/typosquatted-domains-trivy-litellm-teampcp): In the TeamPCP supply chain campaign, lookalike domains were registered and certified days before malicious commits shipped—public signals defenders can monitor for.
- [Diesel Vortex: Inside the Russian cybercrime group targeting US & EU freight](https://haveibeensquatted.com/blog/diesel-vortex-inside-the-russian-cybercrime-group-targeting-us-eu-freight/llms.txt): Diesel Vortex is a Russian phishing-as-a-service group targeting freight and logistics companies across the US and Europe. This report details the group's infrastructure, tactics, and the 1,600+ credentials stolen from DAT Truckstop, Penske, EFS and Timocom.
- [Announcing certgrep](https://haveibeensquatted.com/blog/announcing-certgrep): Today we officially launch certgrep, our second free public tool for the security community.

## Customers
- [How Arena Group moved from reactive domain risk to proactive brand protection](https://haveibeensquatted.com/customers/arena-group/llms.txt): After a sophisticated attempted impersonation highlighted a gap that was difficult to close with existing controls alone, Arena Group turned to Have I Been Squatted to monitor threats across its brands, reduce noise, and build a more proactive approach to protection.
- [How BBI Logistics eliminated domain abuse with Have I Been Squatted](https://haveibeensquatted.com/customers/bbi-logistics/llms.txt): BBI Logistics shifted from reactive, manual abuse response to proactive domain monitoring and rapid takedowns, eliminating phishing incidents and weeks of back-and-forth.
