
Case study IT Management
False positives fell by 95% as malicious sites came down faster
A global IT management provider used visual analysis and CDN honeytokens to cut false positives by 95% and bring average malicious-site takedown below four hours.
Impact summary
A global IT management provider used visual analysis and CDN honeytokens to cut false positives by 95% and bring average malicious-site takedown below four hours.

01 / Observation
What Unit6 saw
Unit6 deployed an active brand-protection workflow built around:
- 01
A fine-tuned vision language model that distinguished legitimate sites from visual impersonations
- 02
Hidden CDN honeytokens that alerted when attackers scraped the real site to build a spoof
- 03
Infrastructure attribution linking several impersonation campaigns to known Chinese threat actors
- 04
Automated detection, reporting, and takedown submissions
02 / Significance
Why it mattered
A global remote monitoring and management provider was averaging one malicious-site takedown per week.
Its Greek-nuanced brand name resembled legitimate company names, causing its legacy cyber threat intelligence tool to flag many harmless sites.
A senior security analyst spent about one day each week reviewing domains and submitting takedown requests. Spoofed login pages could capture administrative credentials and create a path to more than 10 million downstream endpoints.
03 / Confidence
How Unit6 established confidence
A purpose-built vision language model, CDN honeytokens, and infrastructure attribution
The honeytokens provided a high-confidence alert when a cloned page went live, while visual analysis filtered lookalike names that were not malicious.
04 / Response
What the customer could do
The operational workflow combined:
- Visual filtering to remove the large volume of false positives
- Active CDN honeytokens to surface newly cloned sites
- Automated registrar and hosting-provider takedown submissions
05 / Documented outcome
Outcome
False positives fell by 95%, and average malicious-site takedown time dropped below four hours.
The automation returned eight analyst hours each week to the security team.
“A full automation of the takedown process reduced an analyst's work that was cumbersome, time-intensive, and led to bad brand reputation.”
— Chief Information Security Officer



