SECOPS

Escalate Newly-Surfaced Impersonation Domains to PagerDuty

Hourly Brave Search for freshly indexed lookalike domains; high-confidence impersonation hits page the on-call secops engineer through PagerDuty instead of waiting for the daily…

CategorySecOps
Enginesim
Difficultyintermediate
Triggerschedule
Steps5
Setup~15 min

How it runs

The automated pipeline, trigger to output.

  • TriggerHourly schedule triggers the watch
  • ActionBrave Search for recently indexed lookalikesBraveBrave Search
  • LogicKeep only high-confidence, never-seen hits
  • ActionOpen a PagerDuty incident per qualifying domainPagerDutyPagerDuty
  • OutputMirror the alert to SlackSlack

What it does

This workflow watches for impersonation domains that have only just appeared in search results and escalates the highest-confidence ones to your on-call rotation. It separates the urgent "someone just stood up a phishing site" case from routine monitoring by paging immediately rather than filing a ticket.

When to use it

Use it during active campaigns or high-risk periods (a product launch, a breach, tax season) when a brand-new clone needs eyes within the hour. Pair it with the daily sweep, which handles everything below the paging bar.

How it works

  1. 1An hourly schedule triggers the watch.
  2. 2A Brave Search action queries lookalike permutations restricted to recently indexed results.
  3. 3A logic step scores each hit and keeps only those crossing a high-confidence threshold and not seen in prior runs.
  4. 4A branch routes anything that qualifies to escalation; everything else is dropped silently.
  5. 5A PagerDuty action opens an incident for each qualifying domain with the evidence inline.
  6. 6The output posts the same details to a Slack channel for shared visibility.

Set it up

What you configure once, before turning it on.

  1. 1
    Connect Brave SearchWeb, news, image, video search.
  2. 2
    Connect PagerDutyIncidents, on-call, escalations.
  3. 3
    Connect SlackChannels, DMs, threads, mentions.
  4. 4
    Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
  5. 5
    Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
  6. 6
    Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.

Run this workflow in your colony.

14-day trial. No DevOps. No Sales call. Provisioned in under a minute.