Silent Push announced enhancements to its preemptive cyber defense platform with the launch of Silent Push 6.1. The latest release delivers a fully rebuilt and automated Brand and Infrastructure Impersonation capability that continuously searches for impersonators and alerts customers to its findings. It also expands platform extensibility, allowing security analysts to seamlessly connect with security telemetry and AI tools for faster investigations and controlled intelligence sharing.
Brand and infrastructure impersonation is now a formal intelligence requirement, not just a marketing concern. In its April 2026 research note, Align Cyberthreat Intelligence to Business Priorities for Stronger SecOps, Gartner® identifies “Brand Abuse and Phishing Infrastructure” as an example intelligence requirement and frames the question security operations teams must answer as: “What malicious domains, phishing assets, or impersonation campaigns are leveraging our brand, and what actions are needed to disrupt them before they scale?”
Silent Push 6.1 is built to answer that question before the first phishing email is sent. Set it once, and the platform keeps finding new look-alike domains and reporting them to your team on an ongoing basis.
“Signal is essential for weeding out noise against today’s attack environment and time is the biggest disadvantage defenders have,” said Vladimir Krupnov, Threat Intelligence Lead, Revolut. “Silent Push helps isolate impersonated domains, delivering a detection that is months ahead of other tools. This provides the early-action intelligence to inform critical workflows to protect the business.”
“Disrupting impersonation before it scales means finding it before it is used,” said Ken Bagnall, Co-Founder & CEO, Silent Push. “The new Brand and Infrastructure Impersonation engine turns our data on attackers’ own infrastructure against them. We find the imposters targeting our customers before look-alike domains are ever used against them.”
Silent Push 6.1 centers on protecting what matters to organizations and accelerating everything analysts do next. The platform meets analysts where they already work: SOAR platforms, browsers, AI tools, and threat-intel feeds, further shortening the distance between finding threats and acting on them.
New capabilities include:
- Next-Gen Brand and Infrastructure Impersonation: Gartner describes the brand-abuse requirement as: “Continuously discover and score look-alike domains, subdomains, and mobile app listings using brand and keyword monitoring, and provide registrar and hosting details for takedown.” The rebuilt 6.1 engine does exactly that for the infrastructure you own: look-alike domains scored by risk, enriched with registrar and hosting context, clustered by threat actor, and exported as takedown evidence.
- Advanced Pivot Control: Displays existing Silent Push data and lets you move into WHOIS or open-directory lookups without losing your place in the investigation. Insight Search now understands domains, IPs, ASNs, subnets, and HTML titles in a single query. Total View adds a PADNS timeline, IP certificates, one-click PDF export, and date filtering for screenshots.
- Ecosystem Reach: With 6.1, the My Assets feature lets you build a reusable list of the infrastructure you own (domains, IP ranges, ASNs, and TLDs), tag it, and reuse it as a one-click input everywhere in the platform.
- Integrations:
- Palo Alto Cortex XSOAR: Silent Push intelligence is available inside XSOAR for automated playbooks and response workflows.
- Chrome Extension: Investigate domains and indicators directly from the browser, without leaving the page you are on.
- MCP Server: Exposes Silent Push data to AI assistants and agentic workflows over the Model Context Protocol (MCP).
- Updated TAXII Server: Now supports bidirectional sharing, enabling two-way threat-intelligence exchange over STIX/TAXII.
- TLP Amber Reports: Custom Silent Push analyst reports now support TLP: AMBER+STRICT, so exclusive, subscription-based intelligence reaches only the organizations and individuals meant to receive them.
- Internationalization: The interface is now available in Korean and Spanish alongside English, with navigation and guidance fully localized per user, while the underlying data stays the same. Japanese will be available shortly, with additional languages available on customer request.
Related News: