NewKosmos Safe Browsing is now on Chrome

We monitor the entire web in real time.

We don't rely on aggregated sources: we generate our own data.

Products

From the web to the endpoint

Tesseract watches the web for what threatens your brand. Kosmos Safe Browsing already brings that protection to the browser, and the Antivirus comes next, to the computer.

Web platform

Tesseract

Threat intelligence on your brand: phishing, lookalike domains, exposed assets, and mentions, with evidence attached to every finding.

See the platform
Browser extensionNew

Kosmos Safe Browsing

Warns about and blocks malicious sites, such as phishing and scam pages, the moment someone tries to open them.

Meet the extension
Windows · LinuxComing soon

Kosmos Antivirus

Detects, blocks, and removes viruses and malware right on the computer.

Chrome extensionNew

KosmosSafe Browsing

Warns you before the phishing page opens.

Every domain you visit is checked against the Kosmos Intel threat database. If it is catalogued, navigation stops before the page loads — and you see the blocked address and the reason.

  • Free, no account
  • Version 1.5.0
  • PT · EN · ES

Chrome, Edge, Brave and other Chromium-based browsers.

Kosmos Safe Browsing warning page: this site is catalogued as a threat

Tesseract

A consolidated view: event volume, IP rotation, reputation, and the domains that share infrastructure with you.

Where the threats come from: the country, organization, and provider behind every event, on the map.

Domains tied together by the same server, DNS, or DMARC — the whole campaign, not the isolated alert.

Your own subdomains, panels, and services left open on the internet, found without touching your environment.

Pages impersonating your brand to steal credentials, with a screenshot, the domain, and a verdict on every finding.

Registrations that look like yours, tracked from DNS all the way to the live page.

Fraud against your brand — fake apps, payment links, and campaigns — collected and classified in one place.

Pages hijacking searches for your brand to push casinos, fraud, and adult content.

Accounts posing as your brand or your people, with the network they live on and the evidence attached.

Code, credentials, and secrets published in repositories, with the type of exposure classified.

Posts that mention your brand negatively, from complaints and forums to court rulings.

Tesseract · Event Dashboard

A consolidated view: event volume, IP rotation, reputation, and the domains that share infrastructure with you.

Datasheet

What you get

Ten panels over the same taxonomy, evidence attached to every finding, and nothing installed in your environment.

Monitoring panels
10, from the event dashboard to negative mentions
Collection
Passive, from observable external sources
Installation
No agent, no access to your environment
Analysis windows
24h · 48h · 7 days · 30 days · all
Evidence per finding
Page screenshot, domain, date, and context
Classification
Per-customer taxonomy and event severity
Correlation
Graph of IP, ASN, DNS, and DMARC across domains
Tools
Quarantine, source-code search, and reports
Integration
API to carry findings into your SOC
Data
Processed and stored in Brazil, under the LGPD

Who sees the phishing first

VirusTotal and Google answer about an address that already reached them. Tesseract starts from your brand.

Who sees the phishing firstTesseractVirusTotalGoogle Transparency
Watches your brand without being askeddoes itdoes notdoes not
Catches the lookalike domain at registrationdoes itdoes notdoes not
Does not wait for someone to submit the URLdoes itdoes notdoes it
Screenshot and context for the findingdoes itpartlydoes not
Ties the finding to the campaign (IP, ASN, DNS)does itpartlydoes not
Alerts you when it shows updoes itdoes notdoes not
Tracks it through takedowndoes itdoes notdoes not
Goes beyond phishingdoes itdoes notdoes not
Blocks the site in the visitor's browserdoes itdoes notdoes it

Comparison based on how each service publicly works. VirusTotal and Google are trademarks of their respective owners.

4,320
Correlated events / day
< 1h
From collection to alert
14
Intelligence modules
0
Agents installed
Modules

One platform, four risk fronts

Internal threats, external threats, shared infrastructure, and brand reputation — on the same dashboard, with the same taxonomy.

Internal threats

Exposed assets

Your external surface, inventoried on its own: forgotten subdomains, open admin panels, staging environments running in production.

Internal threats

Email server

SPF, DKIM, DMARC, and sending behavior audited — before someone signs messages in your name.

External threats

Active phishing

Pages published using your brand, detected as they go live and tracked through takedown.

External threats

Lookalike domains

Typosquatting and homoglyphs correlated with the IP, the ASN, and the registrant's history.

Code exposure

Repositories

Keys, tokens, and configs leaked in public repositories, with the commit and author identified.

Brand

Negative mentions

Fake profiles, SEO spam, and conversations about your company — prioritized by real reach, not volume.

How it works

From domain to
action plan

You provide the domain. Tesseract does the rest — nothing to install, nothing touching your environment.

Book a technical call
  1. 01
    You provide the domain
    No agent, no access to your environment, no upfront integration. Just the domain.
  2. 02
    Tesseract correlates
    Passive collection across open sources, the dark web, and infrastructure, normalized into a single taxonomy.
  3. 03
    You get your next steps
    Findings prioritized by risk, with evidence, a suggested owner, and a remediation path.
Watch cycle

The case does not close at takedown

Every finding enters a loop that never ends. Collection, enrichment, monitoring and reclassification repeat for as long as the asset exists — and keep running after it goes offline.

Asset under watchlogin-yourbrand.co Live
Page published, harvesting credentials.Re-checks · 18
  1. 01

    Collection

    The event lands in the panel with evidence: phishing, lookalike domain, fake app or a profile impersonating you.

    • Page screenshot
    • URL and redirects
    • WHOIS record
    • First seen
  2. 02

    Enrichment

    Everything the page carries is extracted and indexed — what the scam asks for and what it ships.

    • Identities and tax IDs
    • APKs and binaries
    • Phone numbers and emails
    • PDFs and documents
  3. 03

    Monitoring

    The asset keeps being checked from the outside: whether it is still live, where it points and who answers for it.

    • Availability
    • Passive DNS history
    • Associated emails
    • IP and domain reputation
  4. 04

    Reclassification

    Every lap rewrites the risk: severity rises, drops or reopens, and the campaign is correlated again.

    • Severity recalculated
    • Campaign correlated
    • Takedown tracked
    • Automatic reopening

Taken down is not closed. The domain stays under dormant watch, and if it resolves again, changes IP or is registered by someone else, the same case reopens — with the whole history attached.

Passive collection
No packet is ever sent to your infrastructure. Everything comes from observable external sources.
AES-256 encryption
Data encrypted at rest and in transit; per-customer segregation across the entire platform.
Data in Brazil
Processing and storage within Brazilian territory, aligned with the LGPD.
Audit trail
Every access and export is logged, with retention configurable by policy.

Find out what's already exposed

Initial report within 48 hours, with findings prioritized by risk and no commitment.