Whose name and face is being worn to phish your people, and which profile is the trap?
Baitback searches the professional networks where impersonation gets staged. Give it a name and it returns everyone who shares it; add your company and it pulls out the ones claiming to work there, so the lookalike account built to pass as your CFO stops hiding in the crowd of genuine namesakes.
What Baitback sees
Two lists, and only one is the threat
A search returns name_matches, everyone who shares the name, and, when you give a company, company_matches: the same name claiming to work at yours. The first list is genuine namesakes and harmless; the second is the shortlist an impersonator, or a fake-employee phishing account, hides in. Grouped so you weigh the real person against the fakes at a glance.
Enough to judge, screenshot and report
Every match carries the display name, the stated company, the profile link and the profile photo: the evidence a takedown needs, and enough to open the account and weigh it against the people you actually employ. The grouping is what narrows the field; Baitback ranks nothing and accuses nobody.
A search that runs itself
A thorough sweep works through page after page, so a search does not block: you submit a name, get a job, and poll it for the live stage and, when it finishes, the grouped result. Set the depth, a quick pass or a complete crawl, to trade speed against completeness.
On the record, like every search
Each search lands in your organization's activity log with the caller, the name queried and whether it arrived over an API key, the same audit model that covers the rest of the platform. Baitback reads public profiles; it never signs in to anyone's private account or touches your own systems.
The crowd is not the threat. The shortlist at your company is.
A name-search returns two lists: a crowd of genuine namesakes, and the short set claiming to work at your company. Put side by side, the 18-day-old account nobody there recognises has nowhere to stand.
NAME_MATCHES
44Everyone who shares the name.
GENUINE NAMESAKES · NOT YOUR PROBLEM
COMPANY_MATCHES
3The same name, claiming your company.
Chief Financial Officer
6-yr tenure
Finance Manager, EMEA
3-yr tenure
- FLAGGED
Chief Financial Officer
18-day account · not in your directory
ONE OF THREE IS 18 DAYS OLD
Same data, same permissions, over HTTP
Everything the console shows, the API serves. Real endpoint, sample response, masked values.
GET /api/baitback/v1/jobs/{job_id}
REQUEST
curl -H "X-API-Key: sk_••••••••" \ "https://console.generalintels.com/api/baitback/v1/jobs/bbk_9f3c••••"
RESPONSE · 200
{
"job_id": "bbk_9f3c••••",
"status": "done",
"name": "••••••",
"company": "••••••",
"elapsed_sec": 41,
"error": null,
"result": {
"total_captured": 47,
"name_matches_count": 44,
"company_matches_count": 3,
"company_matches": [
{ "name": "••••••", "company": "••••••",
"profile_url": "https://••••••", "photo_url": "https://••••••" }
],
"name_matches": [
{ "name": "••••••", "company": "••••••",
"profile_url": "https://••••••", "photo_url": "https://••••••" }
]
}
}Two-step and asynchronous: POST /api/baitback/v1/search?name=…&company=…&depth=25 returns a job_id immediately, then poll this endpoint. While it runs the job reports its progress and result is null; once status is done, result carries the two groups. company_matches is the same-name-at-your-company shortlist. Names, companies and URLs are redacted in this sample.
Full API reference ships with your workspace: every endpoint, versioned.
The connection request that was a wire fraud
Finance flags a new connection request from a profile using your CFO's name and title.
You run Baitback on the name with your company set; the job returns in under a minute.
name_matches lists forty-odd genuine namesakes. company_matches has three: your real CFO, a finance manager, and a third account claiming the same title that nobody in the company recognises.
Your team opens the third profile, files the link, the photo and a screenshot with the network's abuse desk, and warns staff in the same hour. The invoice the fake would have requested is never sent.
Baitback, honestly answered
The other windows
- SherlogCredential & Cookie Intelligence
- DragnetUnderground Content Intelligence
- CvekitVulnerability Intelligence
- MalveineThreat Intel Console & Feeds
- JabbernautMessaging Intelligence · XMPP
- TelepathyMessaging Intelligence · Telegram
- GuildwireMessaging Intelligence · Discord
- SoursOperator Surveillance · Closed briefing
Your competitors will learn about the leak from the invoice.
Learn about it from the log batch.
NDA-friendly briefings · global coverage · no slideware