ArgusLeaf

Origin

A problem that's obvious once you see it.

Every time a certificate authority issues a TLS certificate, that event is public. The certificate is logged to a transparency tree maintained by Google, Cloudflare, DigiCert, and others — permanently, tamper-evident, and free to read. Millions of certificates are issued per day.

Within that stream, attackers register imitation domains — slightly misspelled, with added keywords like "login" or "secure" — and obtain certificates for them, often within hours of registration. Those certificates appear in the public log.

ArgusLeaf was built on the premise that the data needed to detect these domains is already public — the missing piece was the tooling to read it at scale and match it against a watched brand.

The name · Argus

A hundred eyes, never all closed.

Argus Panoptes was the watchman of Greek mythology. He had a hundred eyes, and only some of them slept at any given moment — so he was never fully asleep, never fully blind. When Hermes eventually lulled Argus to sleep with music and killed him, Hera commemorated his eyes by placing them on the tail of the peacock — the ocelli, the "eye-spots" still visible today.

The animation on our homepage is those ocelli. The name is chosen deliberately: a monitoring service that never closes every eye is the point.

The name · Leaf

One entry at a time.

A Certificate Transparency log is a Merkle tree — a data structure where every piece of data is a "leaf" and every leaf is connected to the others through a chain of cryptographic hashes. The root hash of the tree proves, mathematically, that the tree hasn't been tampered with.

When we say we watch the leaves, we mean it literally: we stream the leaf entries from CT logs one at a time, hash-by-hash, as they're added.

What this is

An independent monitoring project.

ArgusLeaf is built and maintained by an independent security researcher. It is not a product of any security company. The monitoring service (Watch) is free for the first 50 organisations during early access.

The Observatory research arm — sector-wide phishing intelligence — is published openly for anyone to read. There is no investor, no sales team, no "enterprise tier." If this scales to the point where server costs become significant, donations and sponsorships will cover them.

Support the project →

Contact

Get in touch.

Monitoring applications
[email protected]
Alert configuration & account questions
[email protected]
Scanner opt-out & complaints
[email protected]
Report a suspicious domain
[email protected]
Press & partnerships
[email protected]