From report to takedown
What actually happens after you hit submit: how Blackwall screens, verifies, escalates and monitors a malicious website until it's gone.
The Blackwall pipeline
Six stages, each with a clear owner. Every report follows the same path: the speed and depth depend on your plan.
1. You submit a report
A guided wizard collects the domain, URLs, observed behaviour, evidence and your context. Reports can be private or shared with the community.
2. AI triage screens it
Free-tier reports are scored by a rule + LLM pipeline for description quality, evidence, domain reputation and anti-abuse signals. Junk is rejected instantly; the rest goes to a human. Priority and Company reports skip screening.
3. Human analyst investigates
The analyst verifies the abuse, enriches with WHOIS, IP/ASN, hoster and blocklist context, and captures a forensic snapshot into the evidence vault.
4. Coordinated escalation
Reports are forwarded to hosters, registrars and blocklists (Google Safe Browsing, Microsoft SmartScreen, APWG, URLhaus). Serious cases go to CERTs or law enforcement.
5. Monitored to resolution
We keep polling the URL until it 404s, is suspended, or no longer resolves. You get emails on the meaningful state changes: nothing else.
6. Added to the wall
Confirmed takedowns are added to the public Wall of Neutralized Threats (with public domains redacted per our privacy policy).
What makes a report pass screening
Free-tier submissions are auto-scored. Reports that clear the bar reach a human analyst within minutes; the rest are rejected on the spot.
Do
- • Describe the abuse in 2-3 specific sentences.
- • Attach at least one piece of evidence: screenshot, hash, log or URL.
- • Screenshot before the site disappears: evidence goes fast.
- • Use WHOIS to fill in registrar and hoster when you can.
- • Enable community sharing so others get warned.
Don't
- • Submit placeholder text, gibberish or test data.
- • Upload actual malware samples: screenshots and hashes only.
- • Report well-known legitimate domains without overwhelming proof.
- • Spam duplicate reports for the same URL.
- • Include PII of victims beyond what's necessary.
How your plan changes the pipeline
Everyone gets the same escalation channels. Paid tiers change how fast a report reaches a human and how many you can push through per hour.
Company checkout is currently in pilot: join the waitlist from the Companies page.
Report status guide
What each state means and what happens next.
Pending
Received and queued for automated screening. The system scores the report on description quality, evidence, domain reputation and anti-abuse signals.
Accepted
Passed screening and/or picked up by a human analyst for investigation.
Invalid
The report could not be processed: insufficient information, wrong format, or out of scope.
Abuse Confirmed
Investigation confirmed abusive activity. Evidence has been captured into the vault.
Abuse Not Found
No evidence of abuse at the time of analysis. The site may have been cleaned or the threat was not confirmed.
Forwarded
The report has been sent to one or more external parties for action.
Refused
After investigation, the report does not meet criteria for forwarding.
Solved
The abusive website has been taken down or otherwise neutralized.
Rejected
The report was rejected: false reporting, duplicate submission or policy violation.
Where reports get sent
Confirmed abuse is forwarded through legitimate channels: we do not run offensive operations.
Hosting Provider
Suspends the account behind the malicious site. Cooperative hosters typically act within hours to one business day.
Domain Registrar
Can suspend or seize the domain. Registrars usually respond in one to three business days.
Blocklists
Google Safe Browsing, Microsoft SmartScreen, APWG and URLhaus so browsers warn users even before the host acts.
CERTs / Law Enforcement
For serious criminal activity: fraud, illegal content, coordinated campaigns: we escalate to the appropriate authority.
Email: only when it matters
- • Submission confirmation with your Report ID.
- • Abuse confirmed or not found after investigation.
- • Forwarded to hoster, registrar or authority.
- • Final outcome: Solved, Refused or Rejected.
Intermediate transitions like Accepted or Pending don't email you: track them live in your dashboard.
In-app tracking
- • Notification centre for live status changes.
- • Investigation tab with enrichment output.
- • Full timeline per report: never gets deleted.
- • One-click GDPR data export from Settings.
Zodiac · OSINT investigation boards
For deeper cases, Pro and Enterprise teams get a collaborative graph workspace to map persons, domains, IPs and wallets, enrich them automatically, and submit verified indicators into a system-wide flag database.
Graph canvas
30+ entity types, smart paste from clipboard, floating edges with auto-avoidance, dark/light themes.
Realtime collaboration
Invite analysts, presence avatars, per-node comments, task assignment and read-only sharing.
Conflict-free editing
Soft node locks and append-only audit trail so two analysts can never overwrite each other.
Automated enrichment
One-click IP/ASN, WHOIS, crypto wallet, VirusTotal and AbuseIPDB lookups: each source recorded.
Global flag database
Verified indicators pulse red on any Blackwall board: across every workspace, in real time.
Strict verification
Only the host submits. Every entity is reviewed against strict criteria; decisions are explained and emailed.
Snapshots & audit
Versioned board snapshots and SHA-256 hash-chained audit trail: end-to-end verifiable.
Forensic PDF export
Graph screenshot, executive summary, entities, sources and chain-of-custody hash: ready for handover.
Ready to fire a report through the pipeline?
Free, no credit card, no follow-up spam. If you're here on behalf of a company, join the pilot for managed takedowns and brand monitoring.
