Skip to content
Service

Website and app forensics

Fraudulent platforms are rarely built once. We examine a site or application to determine who operates it, where it is hosted, what it is built from, and which other properties share the same fingerprints.
Open a caseReport in 4 to 7 business days

What the work involves

  1. 01

    Reconstruct domain registration and DNS history, including records that have since been changed.

  2. 02

    Analyse hosting, TLS certificate issuance history and content delivery configuration.

  3. 03

    Fingerprint the application: templates, analytics identifiers, third-party integrations and payment endpoints.

  4. 04

    Pivot on shared identifiers to surface related properties run by the same operator.

  5. 05

    Document intellectual property misuse where a legitimate brand has been cloned.

What this cannot do

Privacy services, offshore registrars and bulletproof hosting exist precisely to frustrate this work. Sometimes the honest finding is that attribution stops at a service provider, and the useful output is a takedown rather than a name.

Typical matters

Identifying the operator of a fraudulent platform
Brand and trademark misuse
Phishing infrastructure targeting your customers
Establishing the scale of an operation before deciding whether to act
Website and app forensics — CoinSentry