What is Typosquatting?
Typosquatting is the exploitation of typing mistakes by attackers to mislead users, redirect traffic, or impersonate your organization.
Instead of using your legitimate domain, attackers register or use similar-looking domain names to mislead users, redirect traffic, or impersonate your organization.
How does it work?
Attackers rely on common human errors to exert typosquatting such as:
Missing or added characters
Swapped letters
Incorrect domain extensions (e.g. .com vs .co)
Slight variations of your brand or domain name
For example, a user trying to access example.com could accidentally land on:
exmaple.comexample.coexamp1e.com
These variations can be used maliciously to impersonate your brand and mislead users.
Why is it a security risk?
Your brand is the primary door to your attack surface, and attackers use typosquatted domains for:
Phishing attacks (stealing credentials or sensitive data)
Brand impersonation
Malware distribution
Traffic redirection to malicious websites
As compromised variations can be exploited at any given moment, a continuous detection and risk priorisation of typosquatted domains is essential to protect your brand reputation.
How does Patrowl detect typosquatting ?
Patrowl automatically generates and monitors permutations of the top domains identified as part of your external attack surface.
Within our dashboard, you can:
Identify suspicious domain variations
Assess associated risk using evidence
Monitor and categorize permutations
Track related vulnerabilities and actions



