Estimated reading time: 8 minutes
The Domain That Waited
A carrier writes three mid-market manufacturers in the same quarter. Different brokers, different states, no shared vendors. Eleven months later, all three report wire fraud losses inside six weeks of each other.
The domains used against them were registered on the same afternoon, at the same registrar, on the same hosting. Nobody connected them until the claims arrived.
That sequence is invented. The timeline is not.
What Silent Push 6.1 Changes
Silent Push released version 6.1 of its preemptive cyber defense platform today, rebuilding the engine that hunts for domains impersonating a customer’s brand.
The pitch is lead time. Configure your brands and assets once, and the platform keeps finding look-alike domains, scoring them, clustering them by threat actor and delivering takedown-ready evidence. The company’s argument is that it finds attacker infrastructure while it is being built rather than after it is used.
For cyber insurers, the interesting question is whether that capability belongs on an application form. Silent Push thinks it does. The evidence that would let a carrier act on that is not yet public.
What The Lead Time Claim Actually Rests On
The company’s headline evidence comes from a published case study with a Fortune 500 media and entertainment customer.
That customer ran every SIEM-flagged domain and IP through Silent Push ThreatCheck, then compared when each indicator first appeared in the Silent Push dataset against when it surfaced in their own logs. The gap averaged 104 days, with a median of 117. Some indicators appeared more than 200 days ahead. The longest documented gap was a FIN7 domain detected 305 days before it reached the customer’s SIEM.
The published examples span FIN7, Lazarus, PoisonSeed, FakeUpdate, Keitaro C2, and SecTopRAT. The customer separately reported early detection of Sapphire Sleet, ClickFix, and Amos Infostealer activity.
Read the methodology carefully. This measures Silent Push against one customer’s own detection, not against competing threat intelligence vendors. It answers how much earlier the data existed, not how much better it is than the alternative.
For a vendor comparison, Silent Push points at Revolut. The bank’s threat intelligence lead reported that the platform surfaced more than 25 impersonation domains that two of its existing brand protection vendors had missed.
“Silent Push helps isolate impersonated domains, delivering a detection that is months ahead of other tools,” Vladimir Krupnov, threat intelligence lead at Revolut, said in the announcement.
The mechanism, as Jonathan Peyster, director of product management at Silent Push, describes it, is fingerprinting rather than reporting. “We map attacker infrastructure as it’s being set up, using the DNS, hosting, and content fingerprints adversaries reuse across campaigns, rather than waiting for a domain to be used and reported,” he said. “That’s what produces the months of lead time, whether the target is a corporate network or a brand.” That is the same dataset behind the dangling subdomain research the company published in July, and behind its work on residential proxy networks.
The Number Nobody Will Give You
Ask about false positives and the answer gets honest in a way that matters.
Peyster declines to state a rate.
“It’s quite hard to assess what a false-positive rate would be, as different customers will have a different threshold a domain will need to cross to be worth taking action on,” Peyster told Cyber Insurance News. “It’s not a purely objective measure.”
Instead of a score, the platform gives analysts context. “Rather than just show potential imposter domains, we enrich them with context from our context graph to help users understand whether or not they are active threats,” he said. Analysts can see the HTML title and logo of whatever is hosted on a look-alike domain, then monitor how its configuration changes over time before deciding it is worth pursuing.
That is a reasonable answer for a security team. It is a problem for an underwriter.
The company’s own dashboard illustrates the gap. A single asset impersonation run in the product returns 176 candidate domains. Four of them carry the Indicators of Future Attack designation. The breakdown splits into 123 typosquats, 23 top-level domain typosquats, 23 combosquats, and a handful of homoglyphs, spread across Cloudflare, GoDaddy, NameCheap, and NameSilo registrations.
Somewhere between 176 and four sits the judgment a carrier would have to price. Without a stated accuracy rate, a control credit rests on the insured’s threshold rather than on the tool’s performance.
Source: Silent Push.
Could Brand Impersonation Monitoring Become An Underwriting Control?
Silent Push argues it should, and the logic is sound on its face.
“Continuous domain impersonation monitoring is a natural candidate for the next generation of cyber insurance underwriting and renewal controls,” Peyster said.
He added, “A vast percentage of social engineering, business email compromise, and credential harvesting attacks leverage lookalike or typo-squatted domains, tracking these external threats serves as a powerful indicator of an organization’s overall cyber hygiene and threat landscape.”
The supporting evidence sits in other people’s data. Yooz found business email compromise and phishing aimed at finance teams was the most common attack type among organizations reporting payment fraud, at 50%, with vendor impersonation and unauthorized banking changes at 37%. Chao Cheng-Shorland put email at the origin of 91% of attacks on the Cyber Insurance News podcast this week.
Cyber Insurance News also asked what loss data insurers would need before extending a control credit. Peyster did not address that part of the question.
That absence is the story. It is not unique to Silent Push, and it is not evidence the argument is wrong.
Five Vendors, One Missing Number
This publication has covered five separate pitches for continuous monitoring as an underwriting input this year.
Sophos and Spektrum Labs launched Insurability FastTrack in March, converting control status into verifiable tokens. Jessica Newman argued on this publication’s podcast that the market must move from asking whether a control exists to demanding evidence of how it performs. Marsh and Resilience bundled continuous external scanning into cyber placements across Asia this month. CyberCube argued days later that point-in-time attestation cannot capture how fast an insured’s posture changes.
Every one of those proposals is coherent. None comes with data linking the control to reduced claims frequency or severity.
That is what a carrier needs before a credit appears on a quote. Multi-factor authentication earned its place on application forms because claims experience eventually supported it. Impersonation monitoring has the argument and not yet the experience.
What Else Is In 6.1
The rest of the release is platform work, and one item is worth noting for anyone tracking where threat intelligence is heading.
Silent Push has added an MCP server, exposing its data to AI assistants and agentic workflows over the Model Context Protocol. Threat intelligence feeding autonomous agents is a small line in a product announcement and a large question about who acts on the output.
The remainder: a Palo Alto Cortex XSOAR integration for automated playbooks, a Chrome extension for investigating indicators without leaving the page, bidirectional STIX and TAXII sharing, and TLP AMBER+STRICT support so subscription intelligence reaches only its intended recipients. A My Assets feature lets teams build a reusable list of owned domains, IP ranges, ASNs and TLDs. The interface now ships in Korean and Spanish, with Japanese to follow.
“Disrupting impersonation before it scales means finding it before it is used,” said Ken Bagnall, co-founder and chief executive of Silent Push.
Asked whether the platform can identify infrastructure targeting several policyholders before separate claims emerge, Peyster pointed to existing carrier relationships.
“We have several customers in the insurance industry, and impersonation consistently comes up as an important use case for them,” he said. “Our technology not only allows insurers to protect their policyholders from campaigns impersonating their brand but also allows them to better understand emerging risks directly targeting these policyholders as well.”
The multi-policyholder early warning question went unaddressed.
For carriers thinking about accumulation, that remains the interesting one.
WHILE YOU ARE HERE, TAKE THE CYBER INSURANCE NEWS SURVEY
FAQ – Brand Impersonation Monitoring
What is brand impersonation monitoring?
Continuous searching for domains built to imitate an organization’s brand or infrastructure, such as typosquats, combosquats and homoglyph domains. Platforms score candidates by risk, add registrar and hosting context, and cluster them by threat actor so security teams can pursue takedowns.
How far ahead can attacker infrastructure be detected?
Silent Push cites a Fortune 500 case study in which indicators appeared in its dataset an average of 104 days before reaching the customer’s SIEM, with a median of 117 days. The longest documented gap was 305 days on a FIN7 domain.
What false positive rate should organizations expect?
Silent Push director of product management Jonathan Peyster declines to state one, arguing that customers set different thresholds for what warrants action. A single platform run illustrated in company materials returns 176 candidate domains, four of which carry an Indicators of Future Attack designation.
Could impersonation monitoring earn a cyber insurance credit?
Peyster calls it a natural candidate for the next generation of underwriting and renewal controls, since a large share of business email compromise and credential harvesting runs through look-alike domains. No published loss data yet links the control to reduced claims frequency or severity.
What is new in Silent Push 6.1?
A rebuilt brand and infrastructure impersonation engine, a My Assets feature for reusable infrastructure lists, and integrations including Palo Alto Cortex XSOAR, a Chrome extension, bidirectional STIX and TAXII sharing, and an MCP server exposing data to AI assistants.
Related Cyber Insurance Posts
- Defense Just Lost Its Head Start. Ask A Hospital What That Costs.
- Cyber Insurance Policy Insights: Measuring Breach Risk with The SecurityScorecard BSI(Opens in a new browser tab)
- Silent Push 6.0 Gives Cyber Underwriters Sharper Threat Intelligence(Opens in a new browser tab)
- Scammers Supercharge Senior Scam Tactics with AI, Impersonations, and Urgent Deceptions(Opens in a new browser tab)
- Domain Security Meets Cyber Insurance: CSC Joins NetDiligence’s eRiskHub®(Opens in a new browser tab)