What Active Focus monitors

Active Trace – Adding Deception to Aid Detection and Attack Surface Management

Most phishing starts with a copy of your website. Attackers clone a legitimate site to trick your users into entering credentials or completing fraudulent transactions — and the cleaner the copy, the more people fall for it. Active Trace turns that first step against them.

How website cloning works

The attacker’s goal is a convincing duplicate: your branding, your login form, your layout, hosted on a domain they control. When a victim lands on it and enters their details, the attacker captures them. It is devastating for the targeted organisation and for the users who trust the brand.

How Active Trace catches it

Active Trace plants hidden traps in your web pages — traps that stay dormant for normal visitors and only activate when the site is cloned and accessed by an attacker. The trap is a tiny piece of JavaScript or an SVG file embedded in your pages. When attackers clone your site, they copy your imagery and code wholesale to preserve its look and feel — so the trap comes along for the ride. The moment that cloned page loads somewhere it shouldn’t, the file quietly calls back to River Security infrastructure, telling us the site is running in an unauthorized setting. Active Trace identifies the clone and alerts your security team, giving you the chance to act while the fraudulent site is still being prepared.

Stopping phishing before it launches

The real value is timing. By surfacing a cloned site early — often before the phishing campaign goes out — Active Trace lets you respond while it still matters: block it, get it taken down, and cut the campaign off before it reaches your users. For organisations using Active Focus, it is one more way to stay a step ahead of the attackers, on the surface you can’t normally see.

Is it foolproof? No — nothing in this space is, and a determined attacker can strip the traps. But it doesn’t have to be foolproof. Raising the bar enough to catch and disrupt the majority of phishing infrastructure early is what changes the outcome.

See how Active Focus works Talk to an expert