Exposure discovery CSIRT-led
Typosquatting Finder
Generate and resolve look-alike domain names, inspect results and export findings for follow-up threat intelligence analysis.
By CIRCL and project contributors · Luxembourg
Primary sources connect this project to an EU CSIRT as developer or lead.
At a glance
Recorded facts- Response workflow
- Exposure discovery
- Developer or maintainer
- CIRCL and project contributors
- Recorded country
- Luxembourg
- Product model
- Open source
- Deployment
- Self-hosted / Public service
- Software license
- Apache-2.0 (web application)
- Upstream status
- Active
- Evidence class
- CSIRT-led
What the sources establish
Origin noteCIRCL lists Typosquatter among its own project organisations and provides the tool’s public project page in Luxembourg.
Reported capabilities
- Offers selectable domain-permutation algorithms and DNS results.
- Exports results as JSON and MISP events.
Scope and limits
The underlying permutation library uses a separate BSD-2-Clause license. A similar or registered domain is not evidence of malicious use.
Inspect the research evidence 7 source observations
identity / capabilities / deployment
Upstream documentation describes generate and resolve look-alike domain names, inspect results and export findings for follow-up threat intelligence analysis. It documents local installation.
Read sourceorigin / country
CIRCL lists Typosquatter among its own project organisations and provides the tool’s public project page in Luxembourg.
Read sourcelicense
The upstream license file specifies Apache-2.0 (web application).
Read sourcemaintenance
Repository is not archived; its last recorded push was 2026-02-25. This is an activity signal, not a support guarantee.
Read sourceorigin / country
CIRCL’s inventory connects the Typosquatter organisation and this tool to CIRCL.
Read sourcelicense / origin / country
The underlying permutation library is BSD-2-Clause and credits CIRCL, Luxembourg, the AIL project and David Cruciani.
Read sourcedeployment
CIRCL operates a free public search service for potentially typosquatted domains; the live form and project link are available.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Scope exposure discovery, validate vulnerability findings, prioritize affected assets and verify remediation. Practical guidance with documented European tools.
From vulnerability finding to verified remediation