Takedown (brand protection)
Was ist Takedown (brand protection)?
Dieser Eintrag liegt derzeit nur auf Englisch vor.
A takedown is the process of getting an impersonating asset — a lookalike domain, a spoofed SMS sender ID, or a fake brand display name — removed from the infrastructure an attacker is abusing. The request goes to the abuse desk best positioned to act: the domain registrar, the hosting provider, the carrier SMS abuse desk, or the messaging platform. Detection and case tracking happen on your platform; the actual report is filed with the recipient off platform.
More detail
Devotel Orbit's brand-impersonation module assembles the evidence pack an abuse desk expects: the matched brand token from your watchlist, the impersonation score and band, the individual findings that fired, a recommended recipient class for the candidate type, and a ready-to-send notice summary. That pack is what it means for a case to be filing-ready.
The platform's role splits cleanly. Detection and case tracking — the watchlist, the scan, the evidence pack, the case record — live in Orbit. The submission itself, to a registrar or carrier abuse desk, is your action outside the product, and no case status advances on its own.
A takedown case moves through open (assembled, awaiting review), evidence_ready (reviewed and ready to file), reported (submitted to the abuse desk), and resolved (the impersonating asset is down or the desk confirmed action), with dismissed as the exit for a false positive or accepted risk. An impossible jump — open straight to resolved — is rejected.
Häufige Fragen
- What is a takedown in brand protection?
- A takedown is getting an impersonating asset removed from the infrastructure it abuses — a lookalike domain via the registrar, a spoofed sender ID via the carrier SMS abuse desk, or a fake display name via the messaging platform. Orbit detects the impersonation and assembles the evidence pack; you file the report with the abuse desk.
- Does the platform submit the takedown for me?
- No. Orbit detects the candidate, scores it against your watchlist, and assembles a filing-ready evidence pack with a recommended recipient class. Actually submitting the notice to the registrar, carrier, hosting provider, or platform abuse desk is your action, done outside the product — the reported and resolved case statuses record what you did, not anything the product sent.
- What do the takedown case statuses mean?
- Open means the evidence pack is assembled and awaiting review; evidence_ready means you reviewed it and it is ready to file; reported means you submitted it to the abuse desk; resolved means the impersonating asset is down or the desk confirmed action; dismissed covers a false positive or accepted risk, and a dismissed case can be reopened.
See also
Build it on Orbit
Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.