Home / Services / Web Security / Defacement detection
Web Security / DefaceMonitorBe the first to know
when your website is defaced.
Defacement detection (DefaceMonitor) regularly crawls your public websites from the outside, inspecting them in progressively deeper layers (page content, rendered screen and AI analysis) and alerting you only to changes that are actually dangerous. It also catches embedded skimming scripts that show nothing on screen, by detecting changes in where scripts are loaded from.
Challenges
Sound familiar?
You hear about defacement from your users
With no internal way to notice, defacement comes to light only when someone outside points it out. Meanwhile the damage spreads.
Attacks that change nothing visible
Malicious scripts injected into payment pages (web skimming) leave the screen unchanged and cannot be found by visual checks.
False alarms with every update
Simple diff monitoring raises an alert every time an article is updated or a banner is swapped, burying real defacement.
Features
Defacement detection key features
01Three-layer inspection
First it quickly checks for changes in page content. Only when something changes does it capture and compare the screen, and then AI compares the before and after to make a judgment. Because inspection deepens step by step from the lightest check, monitoring stays efficient even at short intervals.
02Screen diffs and diff images
Compares visual similarity with the previous screen and flags a detection when it falls below 95%. A diff image marking the changed areas is saved, and you can view the before and after screens side by side in the console.
03AI second-stage review
Image-recognition AI compares cropped before-and-after views of the changed areas and decides whether the change is defacement, such as a takeover message, injected spam or a fake login form, or an article update or banner swap. Alerts are suppressed for changes it can identify as normal updates.
04Fail-safe design
If the AI cannot decide or does not respond, an alert is always sent. The AI's judgment never causes a missed detection. The AI runs on your Amazon Bedrock.
05Script source monitoring
Records the domains that serve the JavaScript each page loads on every check, and detects loading from domains that have not been used before. This lets you notice skimming scripts that steal card data without changing how the page looks.
06URL lists and crawling
Register individual URLs to monitor, or let the crawler collect up to 2,000 pages on your site automatically. Configure form login to monitor pages behind login as well.
07Flexible monitoring schedules
Set an interval or a cron expression, as short as every 5 minutes. High-sensitivity mode captures and compares the screen on every check.
08Notifications with reasons
Notifies via email, Slack and webhooks, including why the change was judged to be defacement: screen similarity, new script sources, the AI's verdict and more.
Three-layer inspection
Three layers of inspection,
alerts only for real defacement
What makes defacement detection hard is that most changes are legitimate updates. DefaceMonitor uses three layers that deepen step by step from the lightest check, delivering both short monitoring intervals and few false alarms.
Page content changes
Compares a fingerprint of the fetched page content with the previous one to quickly tell whether anything changed. If nothing changed, the check ends here, so short monitoring intervals stay low in load and cost.
Screen comparison
Renders and captures only the pages that changed, in a browser, and compares visual similarity with the previous screen. Changes below 95% are recorded as defacement candidates, together with a diff image.
AI review
Image-recognition AI compares the changed areas before and after and classifies the change as “defacement”, “normal update” or “undetermined”. Alerts are suppressed only for changes it identifies as normal updates.
Please note: Script source monitoring runs on every check, independently of the three layers. When a new source is found, you are always notified, regardless of the AI's verdict.
Web skimming
Attacks that change nothing visible,
caught by their script sources
Skimming scripts embedded in payment pages and similar places show nothing on screen. Screen comparison still reports 100% similarity while card data is sent to an outside party. DefaceMonitor records where the JavaScript each page loads comes from on every check, and alerts you as soon as a domain never before used on that page appears.
Compared by domain, not URL
CDNs change file names with every deployment, so comparing URLs produces constant false alarms. Source domains are stable, so a “never-seen-before domain” is a strong signal.
Never suppressed by AI
The AI judges by looking at the screen, so it is not used to judge scripts that never appear on screen. New sources are always reported, regardless of the AI's verdict.
Please note: Inspection covers scripts included in the HTML served by the server. Scripts added dynamically by other JavaScript after the page is displayed are not covered.
Specifications
Scope and delivery
| Scope |
|
|---|---|
| Inspection |
|
| Deployment |
|
| Monitoring interval |
|
| Notifications |
|
| Pricing |
|
Please note: Monitoring is limited to sites published on the internet. Detection works by comparison with the previous crawl, and there is no feature to restore defaced pages. AI review requires Amazon Bedrock to be set up in your account.
Getting started
Getting started
Register URLs
Register the URLs of the pages to monitor, or a starting point for crawling. Add login credentials if needed.
Set the schedule
Set the monitoring interval and notification destinations. The first crawl records the baseline screens and script lists used for comparison.
Start monitoring
From then on, crawling runs automatically, and you are notified with reasons whenever defacement is suspected.
FAQ
FAQ
Will I get an alert every time I update an article?
The AI compares the before and after and suppresses alerts for changes it can identify as normal updates. However, you are always notified when the AI cannot decide and when script sources change.
Do I still need this if I have a WAF?
A WAF stops attacks at the point of entry. It cannot detect changes made through paths that bypass the WAF, such as misuse of an admin panel or defacement via a contractor. Combined with WAAP, you cover both stopping attacks and noticing changes.
Works well with
Defacement detection — details and demo requests
Our team will explain deployment options and pricing for your environment.