Notifications
When a copycat finding notifies your channels, how repeats are suppressed, and what the changelog records.
Brand Protection raises two events. Both go to every configured notification channel — email, Slack, Microsoft Teams, custom webhook and SIEM — and both are recorded in the changelog.
Copycat domain detected
Sent when a finding's risk classification rises to Medium risk or High risk — a new domain that assesses at medium risk or above, or an existing one that escalates. Low-risk and benign findings never notify, and neither do findings that are hidden below the risk floor or carry only the fallback assessment.
Each finding notifies at most once per classification. A domain that arrives at Medium risk notifies once and then stays quiet through every re-check until it becomes High risk, when it notifies once more. Changes in the score within a band do not notify.
Copycat domain changed
Sent for a finding you are watching whenever its page content changes — the daily re-check found a different page fingerprint. This is the signal that a parked or placeholder domain has gone live, or that a copycat page has been reworked. Watching a finding is the only way to be told about changes that do not move its classification.
What a notification carries
The domain, the brands it trades on, its risk score and classification, the
threat types the assessment attached, and a link to the finding. In the
changelog the events appear as Copycat Domain Detected and Copycat
Domain Changed, and in webhook and SIEM payloads as the change types
brand_finding_detected and brand_finding_changed, so they can be routed
or filtered like any other change.
What does not notify
- Triage: setting a status, ignoring with a reason, or raising a Jira ticket
- Re-checks that find nothing new
- Findings below the risk floor, and findings you have ignored