Skip to main content

BrandSafe Incidents

Each brand threat detected by BrandSafe is surfaced as an incident in the XTron Console with full context and recommended actions.

Viewing Incidents

Navigate to Incidents → BrandSafe in the XTron Console. Filter by:

  • Severity — Critical, High, Medium, Low
  • Status — Open, In Progress, Closed
  • Brand domain — The monitored domain that triggered the detection
  • Date range

Incident Types and Response Guidance

Phishing Site

A website actively impersonating your brand to steal user credentials, payment information, or personal data.

Response:

  1. Verify the site is live and actively phishing
  2. Identify the hosting provider and registrar (available in the incident fields)
  3. Submit abuse reports to the registrar, hosting provider, and browser safe browsing lists
  4. If customers may have been targeted, consider a customer notification
  5. Report to relevant law enforcement if significant fraud is involved

Quick takedown resources:

Typosquatting Domain

A domain registered with a variation of your brand name that could redirect traffic, host phishing content, or be used for spear-phishing emails.

Response:

  1. Assess the intent — is it parked, actively impersonating, or sending emails?
  2. If actively malicious: file a UDRP complaint or registrar abuse report
  3. If parked and not yet weaponized: monitor for escalation
  4. Consider defensive registration of high-risk typosquat variants

Fake Social Media Profile

An account falsely claiming to represent your brand or executives on LinkedIn, X (Twitter), Facebook, Instagram, or similar platforms.

Response:

  1. Report directly to the platform using their impersonation reporting tool
  2. Document the profile before reporting (screenshot, URL, username)
  3. Alert your social media team to monitor for user confusion

Fake App

An app in an official or third-party app store using your brand name, logo, or description.

Response:

  1. For official stores (Google Play, Apple App Store): submit a developer removal request
  2. For third-party stores: submit abuse reports directly
  3. Publish a security advisory on your website if the fake app is widespread

Incident Fields

FieldDescription
idUnique numeric ID
titleShort description of the threat
taskKeyTicket key (e.g., BSINC-789)
status_statusCdOpen, In Progress, Closed
severity_labelCritical, High, Medium, Low
category_nameThreat category
descriptionFull details
brand_nameMonitored brand name
brand_domainMonitored brand domain
urlURL of the infringing asset
ip_addressIP address of the infringing host
platformPlatform where the threat was detected
registrarDomain registrar
webhost_authorityHosting provider
webhost_countryCountry where the site is hosted
impactPotential impact
recommendationSuggested response action

Updating Incident Status

Track takedown progress and update incident status via the XTron Console under Incidents → BrandSafe → [incident] → Update Status. Add investigation notes to document abuse reports submitted and their outcomes.

API Access

BrandSafe Incidents API Reference