Skip to main content

FAQ about the new Typosquatting module

Find answers to the most common questions about the Typosquatting module and how it works.

Written by Hugo

General questions

What is the Typosquatting module?

Typosquatting is the exploitation of typing mistakes by attackers to mislead users, redirect traffic, or impersonate your organization. With the Typosquatting module, Patrowl helps you detect and manage domain permutations that could lead to security risks such as phishing or brand abuse.

What are permutations?

Permutations are variations of your domains generated to simulate common typos or impersonation attempts (e.g., missing letters, swapped characters, or alternative extensions).

Where do the permutations come from?

Patrowl automatically generates permutations from your top domains identified as part of your exposed attack surface and under protection (EASM or higher).


How the Typosquatting module works

Are permutations automatically classified?

No. All prioritization and categorization are fully manual. Your team decides how each permutation should be handled.

Are permutations updated over time?

Yes. Permutations are continuously updated as new data is collected.


Risk & security

Why is typosquatting a risk?

Your brand is the primary door to your attack surface. Typosquatting domains can be used for phishing, impersonation, malware distribution, or traffic redirection. All of these can directly impact your users and your brand reputation.

Can I trust the “Resolved” status?

Yes. A permutation is marked as Resolved only when:

  • A vulnerability was created

  • A takedown request was executed

  • A retest confirmed the malicious site is no longer active


Access & permissions

Who can use the Typosquatting module?

The module is intended for security teams such as SOC, analysts, and attack surface management teams.

Who can modify permutations?

Only users with Standard access or higher can:

  • Modify permutation statuses

  • Create vulnerabilities

  • Manage and prioritize risks

  • Perform remediation-related actions

  • Users with lower access levels can view the module but cannot perform operational actions.

Lower-level users can view data but cannot make changes.


Data & scope

Which assets are monitored?

Only top domains that are part of your exposed attack surface and under protection (EASM or higher) are included.

Is the The Typosquatting module exhaustive?

The Typosquatting module focuses on relevant permutations based on your exposed attack surface. It is not an exhaustive scan of all possible domain variations on the internet.

Did this answer your question?