The platform

One panel.
Every clone, cornered.

Phish Plug brings detection, cloaking forensics, evidence and takedowns together. Watch for impersonation, prove the hidden redirect, capture the case, and file to the right desk — without leaving the panel.

live · cases

09:14DETECTEDaurora-bonus.net/login · lookalike
09:15CLOAKmobile trap ≠ crawler page · proven
09:51FILEDregistrar + host + Safe Browsing
14:02REMOVEDconfirmed offline · case archived
37 min to filing evidence attached

Capabilities

Everything the fight needs

Clone & lookalike monitoring

Round-the-clock watch over new registrations, lookalike patterns, backlinks and search results for anything wearing your brand.

Cloaking forensics

Dual-profile crawling through an in-country proxy pool resolves and proves the mobile redirect that hides the trap.

Evidence archive

Screenshots from both profiles, raw headers, the cloaking diff and the redirect chain — stored per case and exportable.

Human-approved takedowns

Route to registrars, hosts, CDNs and safe-browsing desks across six channels. Nothing sends without a click.

Detected → Removed status

A live timeline for every threat, from first sighting to confirmed removal, with time-to-filing tracked.

API, SSO & audit log

Pull cases and status into your stack, sign in with SSO, and keep a full audit trail of every action.

Cloaking forensics

We crawl as a bot and as a phone

The same link serves a clean page to crawlers and a credential trap to real mobile visitors. Phish Plug sees both — and diffs them to prove the redirect.

aurora-bonus.net/login
heritage-archiveARCHIVE · STORIES · ABOUT
What a search crawler sees
Canonical · clean
ACCOUNT SERVICES
Your session has expired

Re-enter your details to restore access.

EMAILPASSWORD• • • • • • • •VERIFY ACCOUNT CLOAKED REDIRECT · 181.20.AURORA.COM
What a mobile visitor sees
Cloaked · malicious
Phish Plug crawls as both a search bot and a real in-country phone, then diffs the two responses to prove the redirect.

Fits your stack

Built to plug in

Phish Plug is a panel your team can live in — and an API your systems can read. Pull cases, cloaking diffs and Detected → Removed status wherever you track risk.

REST API SSO Webhooks Audit log CSV / JSON export
6
Abuse channels
24+
Takedown desks
37min
Median time to filing
99%
Evidence accepted

FAQ

Product questions

Is Phish Plug a scanner or a takedown service?

Both, in one panel. It continuously detects clones and lookalikes, proves the cloaking with forensic crawling, builds the evidence case, and files the takedown — then tracks it to removal. You get detection, forensics and remediation without stitching three tools together.

How does the cloaking forensics work?

Each suspect URL is fetched twice: once as a search crawler and once as a real in-country mobile device through our proxy pool. Phish Plug diffs the two responses; when the mobile view is a credential trap and the crawler view is clean, the cloak is proven and attached to the case.

What does a case contain?

Screenshots from both crawl profiles, raw response headers, the cloaking diff, the resolved redirect chain and a Detected → Removed timeline. Everything is stored per case and exportable, so it stands up at any abuse desk.

Can my team use the API?

Yes. Cases, cloaking diffs and status are available over the API on Multi-brand and Enterprise plans, so you can pull them into your SIEM, ticketing or reporting stack. Enterprise adds SSO and an audit log.

Does anything get sent automatically?

No send happens without a human click. Phish Plug prepares the report and routes it to the correct desk, but a person approves it. That is how accuracy stays high and legitimate sites are never touched.

See the panel on your own domain

Run a free clone check — we detect, resolve the cloak and hand back an evidence sample.