LúminaKite
Impersonation risk

Brand protection monitoring

Brand abuse often starts with a lookalike domain or a certificate that gives a phishing site credibility. LuminaKite turns brand keywords, official domains and CT evidence into a prioritized review queue.

Operational outcomes

Brand

  • Generate candidate domains from brand names, aliases, products and official domains.
  • Detect typosquatting, homograph and suspicious term patterns.
  • Score findings with evidence, detection type, similarity and enrichment context.
  • Deduplicate findings so repeated CT or generated signals do not flood analysts.

Core capabilities

Brand profiles
Define brand names, aliases, primary domains, official domains and monitored TLDs that shape detection scope.
Candidate generation
Generate likely abuse variants, including typo, TLD and homoglyph patterns.
CT-backed findings
Use Certificate Transparency signals to identify certificates and domains connected to brand keywords.
Risk scoring
Score findings with similarity, suspicious terms, risky TLDs, detection types and enrichment evidence.
Disposition workflow
Track review status so analysts can mark false positives, monitor suspicious assets or escalate likely phishing.

How the module works

1

Define monitored brands

Add brand keywords, official domains, aliases and TLDs that matter to the organization.

2

Generate and ingest findings

LuminaKite combines CT adapters with generated candidates for a broader view of impersonation risk.

3

Deduplicate and score

Findings are normalized, keyed and scored so analysts see stable records with evidence.

4

Review and act

Use risk, score breakdown and source evidence to decide whether to monitor, dismiss or escalate.

Signals and evidence

matched brand keyword or alias
domain similarity score
homograph and IDN evidence
suspicious terms and risky TLDs
certificate serial, issuer and not_after where available

Common use cases

Find phishing infrastructure early

Review newly observed or generated lookalike domains before they are used in campaigns.

Protect product launches

Monitor new product names and campaign terms for fast-moving imitation domains.

Support takedown evidence

Collect structured evidence that can support legal, abuse desk or registrar workflows.

Frequently asked questions

Does the module only watch exact brand names?

No. It also evaluates aliases, official domains, generated variants, homograph patterns and suspicious terms.

How are findings prioritized?

Findings receive risk and score evidence based on similarity, detection type, suspicious terms, TLD context and enrichment data.

Can I monitor multiple brands?

Yes. Brand profiles let teams define multiple brand or product scopes inside a workspace.

Does it automatically take down domains?

No. The module produces evidence and workflow context. Takedown action remains a human or legal process.

Related modules