Auto-build takedown evidence packs for fake lookalike sites

By General Input

Every hour, new brand abuse tickets get scanned, screenshotted, and turned into a ready to send abuse report before an analyst even opens them.

Integrations

  • urlscan.io
  • Jira
  • Slack

Type

Agentic Task

Categories

  • Operations
  • Engineering

Every hour, build a complete takedown evidence pack for every new brand impersonation report sitting in our Jira brand protection project, so an analyst opens the ticket to a finished dossier instead of a blank investigation.

Start with Jira Search Issues (JQL) to find issues in our brand protection project that are still in the New status and carry the takedown label. For each issue that comes back, use Jira Get Issue to read the full ticket and pull out the reported domain or URL. Read the issue's existing comments at the same time and skip any ticket that already has an evidence dossier comment from a previous run, so an hourly schedule never scans the same domain twice. Cap the run at about ten tickets so we stay inside urlscan's free tier quotas.

For each reported domain, submit it with urlscan Submit URL Scan using unlisted visibility. Unlisted is the right default here: it keeps the scan out of urlscan's public search while still producing a link that vetted researchers and the hosting provider can open, and reported phishing URLs often carry victim specific parameters that should not be publicly indexed. Scanning is asynchronous and takes roughly ten to thirty seconds, so poll urlscan Get Scan Result until the finished result comes back rather than assuming it is ready immediately.

From the scan result, capture the hosting IP address, the ASN and the hosting provider or AS name, the page title, and the server details. Fetch urlscan Get Screenshot for a visual record and urlscan Get DOM Snapshot for the page source. Keep the scan permalink, because that is the citable evidence link the abuse report will point to.

Then pivot on the infrastructure: run urlscan Search Scans on that IP address to find other phishing pages sitting on the same host. Takedowns land much harder when you can show the provider a cluster of abusive pages rather than one isolated page, so collect the related domains along with their scan links and count them. Stick to Search Scans on the IP for this pivot. Do not use urlscan's structure or similar search, or file downloads by hash, because those are paid urlscan Pro features and this workflow needs to run on the free tier.

Degrade gracefully instead of failing the whole dossier. Get Screenshot and Get DOM Snapshot return a not found response when that asset was never stored for the scan, and Get Scan Result returns a gone response if the scan was deleted, so note the missing piece in the dossier and carry on with everything else. If the scan returns nothing useful because the site is already down, for example the submission is rejected because the domain no longer resolves or the rendered page comes back empty, flag that clearly and prominently at the top of the dossier so the analyst knows the page went offline before evidence could be captured rather than assuming the evidence is simply missing.

Compile everything into a structured evidence dossier with clear sections: the reported domain and ticket reference, the scan permalink as the citable evidence link, the hosting facts (IP address, ASN, hosting provider, country), the page facts (title, server details, whether a screenshot and page source were captured), and the related sites found on the same IP. Then draft a ready to send abuse report addressed to the hosting provider that quotes the specific evidence rather than speaking in generalities: name the impersonating domain, the IP it resolves to, the page title, what brand it is impersonating, the scan permalink, and the number and list of other abusive pages found on the same IP.

Post the dossier and the drafted abuse report back onto the ticket with Jira Add Comment, starting the comment with a consistent heading so later runs can recognize it and skip that ticket. Then send a short heads up to our brand protection channel with Slack Send a Message noting the impersonating domain, the hosting provider to contact, and how many related sites were found on the same IP, with a link back to the Jira issue. Keep the Slack message brief; the full detail lives on the ticket.

If no matching tickets are found in a given hour, do nothing and stay quiet.

Related prompts

Explore more prompts
Call overdue Xero customers with an AI collections agentWin back LiveChat visitors whose chats went unansweredChat quality review board for LiveChat support leadsWin back no-show and cancelled appointments every morningLive Loop returns analytics with product-level drill-downNewsletter pre-flight and approval board for Mailjet sendsTurn a prospect spreadsheet into personalized sequence enrollmentsMailjet email delivery lookup console for support teamsCatch feature flags that never got switched on in productionKajabi customer support console for member access fixes