🎭 Fraud & Identity theater
Covers consumer and enterprise fraud — phishing, account takeover, synthetic identity, BEC, OTP-bot, and card fraud — powered by stealer logs, breach corpora, and phishing kits. Protects identities and brands by mapping fraud infrastructure and the crews that run it.
Live indicators
182.9K
in this theater
High severity
0
score ≥ 0.75 (top 60)
Actors tracked
4
documented
Mapped sources
8
in catalog
🏹 Threat Actors
📚 Priority sources & datasets
🔄 Live Datasets & APIs (5 key-free · ingestible)
📜 Fraud & Identity Playbook
- Collect phishing kits, stealer logs, spam feeds, and breach corpora from APWG, PhishTank, and abuse.ch.
- Normalize and correlate compromised identities, domains, and ATO infrastructure across campaigns.
- Analyze fraud typologies (phishing, synthetic identity, BEC, OTP-bot, card fraud) and phishing-kit lineage.
- Attribute operations to fraud crews (Scattered Spider, Black Axe, FIN7) via TTPs and shared infrastructure.
- Disseminate takedown packages and victim alerts to registrars, brands, and financial institutions.
- Execute domain takedowns, credential resets, and account-takeover blocks.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
🔗 Cross-domain pivots
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron