Skip to case study
All case studies

Case study IT Management

False positives fell by 95% as malicious sites came down faster

A global IT management provider used visual analysis and CDN honeytokens to cut false positives by 95% and bring average malicious-site takedown below four hours.

ThreatBrand impersonation and spoofed logins targeting an RMM provider with more than 10 million downstream endpoints
What Unit6 sawCloned login pages
Outcome95% fewer false positives

Impact summary

A global IT management provider used visual analysis and CDN honeytokens to cut false positives by 95% and bring average malicious-site takedown below four hours.

Illustrative translucent panes and small light suggesting detection of a cloned page

01 / Observation

What Unit6 saw

Unit6 deployed an active brand-protection workflow built around:

  1. 01

    A fine-tuned vision language model that distinguished legitimate sites from visual impersonations

  2. 02

    Hidden CDN honeytokens that alerted when attackers scraped the real site to build a spoof

  3. 03

    Infrastructure attribution linking several impersonation campaigns to known Chinese threat actors

  4. 04

    Automated detection, reporting, and takedown submissions

02 / Significance

Why it mattered

A global remote monitoring and management provider was averaging one malicious-site takedown per week.

Its Greek-nuanced brand name resembled legitimate company names, causing its legacy cyber threat intelligence tool to flag many harmless sites.

A senior security analyst spent about one day each week reviewing domains and submitting takedown requests. Spoofed login pages could capture administrative credentials and create a path to more than 10 million downstream endpoints.

03 / Confidence

How Unit6 established confidence

A purpose-built vision language model, CDN honeytokens, and infrastructure attribution

The honeytokens provided a high-confidence alert when a cloned page went live, while visual analysis filtered lookalike names that were not malicious.

04 / Response

What the customer could do

The operational workflow combined:

  • Visual filtering to remove the large volume of false positives
  • Active CDN honeytokens to surface newly cloned sites
  • Automated registrar and hosting-provider takedown submissions

05 / Documented outcome

Outcome

False positives fell by 95%, and average malicious-site takedown time dropped below four hours.

The automation returned eight analyst hours each week to the security team.

“A full automation of the takedown process reduced an analyst's work that was cumbersome, time-intensive, and led to bad brand reputation.”

— Chief Information Security Officer

See what happens when you know first.

You’ve seen their hands.
Now let’s look at yours.

Book a demo