Webamon - Track the whole threat campaign, not one incident at a time

by
Most threat tools alert you one malicious incident at a time. Webamon clusters the infrastructure behind an attack into a tracked campaign and re-checks it 6× a day. New domains, liveness, infra rotation. Search it, monitor it, alert on it. Free tier, full API.

Add a comment

Replies

Best
Maker
📌
Hi Product Hunt 👋 I built Webamon because of a pattern that drove me up the wall: every tool in this space treats a phishing site as an incident. One domain, one alert, one ticket. But nobody runs one domain. They run a kit across hundreds of domains, rotating hosting and certificates, spinning up new ones the moment the old ones die. So the analyst gets a thousand alerts that are secretly the same problem and still misses the next domain, because it hadn't been registered yet when they closed the ticket. Webamon does two things differently: 1. It tracks campaigns, not incidents. We cluster related infrastructure into a campaign and keep it alive: re-checked six times a day for new domains, liveness (what got taken down, what came back), and infrastructure rotation. 84 are running in the console right now. A few real ones, with today's numbers: ClickFix Fake-Cloudflare Challenge; a pixel-clone of the "Just a moment…" gate that talks you into pasting a PowerShell command into your own terminal. 373 domains, tracked since April, re-checked 107 times. Telegram Phishing; Links Cluster - 8,543 DGA-style domains on .fit/.work/.bond, Cloudflare-fronted, pulling assets from Telegram's own infrastructure. ~60% are already NXDOMAIN. That's the whole argument for campaign-level tracking in one line: incident tooling would have opened 8,543 tickets, and 5,000 of them would now be pointing at nothing. Fake Telegram Web Credential Phishing; one kit, one asset path with the same cache-buster on every domain, sitting on .cfd/.sbs/.bond/.beauty. Telegram session theft, usually paired with a crypto-wallet drain. 370 domains. You don't start from an empty dashboard. 2. It doesn't detect on the domain name. Lookalike-domain matching only catches clones that bothered to look alike. Here's a real hunt that found a live campaign: dom:telegram on its own is meaningless. The Telegram Bot API shows up on roughly 2,800 legitimate small-business contact forms. page_title:webmail on its own is meaningless too; every genuine provider matches. But dom:telegram AND page_title:webmail is a credential kit cloning SaskTel, Videotron, OVH, Roundcube and cPanel logins and POSTing the stolen passwords straight into a Telegram chat - no attacker server, nothing to seize. It was sitting on domains like gutrimine.xyz and frigbollc.store. No lookalike-domain tool on earth finds that. On top of that: Lucene search over raw scan data, scan-any-URL-on-demand with screenshot + DOM, monitors that fire into Slack/email/webhook, and feeds (CT logs, newly registered domains, newly observed DNS, open directories). The free tier is a real product, not a demo. 100 scans/day, 10 monitors, 1,000 searches/day, every feed, and full API access. Go put a monitor on your own brand; it takes about two minutes. 🎁 And for Product Hunt: code PRODUCTHUNT gets you Researcher. the tier where the Campaigns console unlocks at $20/month instead of $45, locked for the life of your subscription. Not a first-year discount; that's your rate for as long as you stay subscribed. I'll be here all day. I'd genuinely love to hear: what would you want a campaign to do once you've found it? Auto-file a ticket? Push IOCs to your SIEM? That's the part I'm still designing, and I'd rather build what you'd actually use. Stephen, founder