General questions
What is the Typosquatting module?
What is the Typosquatting module?
Typosquatting is the exploitation of typing mistakes by attackers to mislead users, redirect traffic, or impersonate your organization. With the Typosquatting module, Patrowl helps you detect and manage domain permutations that could lead to security risks such as phishing or brand abuse.
What are permutations?
What are permutations?
Permutations are variations of your domains generated to simulate common typos or impersonation attempts (e.g., missing letters, swapped characters, or alternative extensions).
Where do the permutations come from?
Where do the permutations come from?
Patrowl automatically generates permutations from your top domains identified as part of your exposed attack surface and under protection (EASM or higher).
How the Typosquatting module works
Are permutations automatically classified?
Are permutations automatically classified?
No. All prioritization and categorization are fully manual. Your team decides how each permutation should be handled.
Are permutations updated over time?
Are permutations updated over time?
Yes. Permutations are continuously updated as new data is collected.
Risk & security
Why is typosquatting a risk?
Why is typosquatting a risk?
Your brand is the primary door to your attack surface. Typosquatting domains can be used for phishing, impersonation, malware distribution, or traffic redirection. All of these can directly impact your users and your brand reputation.
Can I trust the “Resolved” status?
Can I trust the “Resolved” status?
Yes. A permutation is marked as Resolved only when:
A vulnerability was created
A takedown request was executed
A retest confirmed the malicious site is no longer active
Access & permissions
Who can use the Typosquatting module?
Who can use the Typosquatting module?
The module is intended for security teams such as SOC, analysts, and attack surface management teams.
Who can modify permutations?
Who can modify permutations?
Only users with Standard access or higher can:
Modify permutation statuses
Create vulnerabilities
Manage and prioritize risks
Perform remediation-related actions
Users with lower access levels can view the module but cannot perform operational actions.
Lower-level users can view data but cannot make changes.
Data & scope
Which assets are monitored?
Which assets are monitored?
Only top domains that are part of your exposed attack surface and under protection (EASM or higher) are included.
Is the The Typosquatting module exhaustive?
Is the The Typosquatting module exhaustive?
The Typosquatting module focuses on relevant permutations based on your exposed attack surface. It is not an exhaustive scan of all possible domain variations on the internet.
