Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Playbook for Typo Squatted Domain

This playbook provides systematic procedures for investigating misspelled domains and collaborating with the organization’s legal department for take-downs. Typo Squatted domains are intentionally misspelled domain names that closely resemble legitimate ones. Attackers take advantage of spelling errors to lead them to an ill-intended website for financial exploitation or other malicious activities.

The Typo Squatted Domains are reported to the Security Operations Team from different sources like Digital risk protection solutions (Digital Shadows) and Threat intelligence platforms (Anomali Threatstream). After a security incident is created, this solution helps identify whether the domain is indeed a Typo Squatted Domain. If it’s a Typo Squatted Domain, the analyst can report it to the legal team so that further actions can be taken.

The workflow is created based on an existing playbook, which provides a consistent and efficient approach for incident investigation. Each decision point in the playbook has been converted into an outcome-driven task and the flow changes direction based on the outcome of such tasks.

  • Set up the Typo Squatted Domain playbook
    Use the following steps to set up the Typo Squatted Domain playbook.
  • Use the Typo Squatted Domain playbook
    Use this playbook to investigate misspelled domains and collaborating with the organization’s legal department for take-downs. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Typo Squatted Domain playbook.

Parent Topic:Flow-based Playbooks