From report to takedown

    What actually happens after you hit submit: how Blackwall screens, verifies, escalates and monitors a malicious website until it's gone.

    The Blackwall pipeline

    Six stages, each with a clear owner. Every report follows the same path: the speed and depth depend on your plan.

    1. You submit a report

    A guided wizard collects the domain, URLs, observed behaviour, evidence and your context. Reports can be private or shared with the community.

    2. AI triage screens it

    Free-tier reports are scored by a rule + LLM pipeline for description quality, evidence, domain reputation and anti-abuse signals. Junk is rejected instantly; the rest goes to a human. Priority and Company reports skip screening.

    3. Human analyst investigates

    The analyst verifies the abuse, enriches with WHOIS, IP/ASN, hoster and blocklist context, and captures a forensic snapshot into the evidence vault.

    4. Coordinated escalation

    Reports are forwarded to hosters, registrars and blocklists (Google Safe Browsing, Microsoft SmartScreen, APWG, URLhaus). Serious cases go to CERTs or law enforcement.

    5. Monitored to resolution

    We keep polling the URL until it 404s, is suspended, or no longer resolves. You get emails on the meaningful state changes: nothing else.

    6. Added to the wall

    Confirmed takedowns are added to the public Wall of Neutralized Threats (with public domains redacted per our privacy policy).

    What makes a report pass screening

    Free-tier submissions are auto-scored. Reports that clear the bar reach a human analyst within minutes; the rest are rejected on the spot.

    Do

    • • Describe the abuse in 2-3 specific sentences.
    • • Attach at least one piece of evidence: screenshot, hash, log or URL.
    • • Screenshot before the site disappears: evidence goes fast.
    • • Use WHOIS to fill in registrar and hoster when you can.
    • • Enable community sharing so others get warned.

    Don't

    • • Submit placeholder text, gibberish or test data.
    • • Upload actual malware samples: screenshots and hashes only.
    • • Report well-known legitimate domains without overwhelming proof.
    • • Spam duplicate reports for the same URL.
    • • Include PII of victims beyond what's necessary.

    How your plan changes the pipeline

    Everyone gets the same escalation channels. Paid tiers change how fast a report reaches a human and how many you can push through per hour.

    Plan
    Review path
    SLA
    Rate limit
    Free
    AI triage
    Best effort
    10 reports/hour
    Starter
    AI triage + analyst
    48h
    50 reports/hour
    Pro
    Priority analyst
    24h
    25 reports/hour
    Enterprise
    Dedicated analyst
    Custom
    Custom

    Company checkout is currently in pilot: join the waitlist from the Companies page.

    Report status guide

    What each state means and what happens next.

    Pending

    Received and queued for automated screening. The system scores the report on description quality, evidence, domain reputation and anti-abuse signals.

    Screening typically completes within minutes: the report is either accepted for analyst review or auto-rejected.

    Accepted

    Passed screening and/or picked up by a human analyst for investigation.

    The analyst verifies whether the reported site is actually abusive.

    Invalid

    The report could not be processed: insufficient information, wrong format, or out of scope.

    Terminal state. You can submit a new report with corrected information.

    Abuse Confirmed

    Investigation confirmed abusive activity. Evidence has been captured into the vault.

    The report is forwarded to hosters, registrars and blocklists for takedown.

    Abuse Not Found

    No evidence of abuse at the time of analysis. The site may have been cleaned or the threat was not confirmed.

    You can add fresh evidence to reopen the case.

    Forwarded

    The report has been sent to one or more external parties for action.

    We poll the URL and wait for the provider response. Takedown SLAs vary.

    Refused

    After investigation, the report does not meet criteria for forwarding.

    You get an explanation. You may add evidence if you believe this was in error.

    Solved

    The abusive website has been taken down or otherwise neutralized.

    Terminal state. The URL is added to the Wall of Neutralized Threats.

    Rejected

    The report was rejected: false reporting, duplicate submission or policy violation.

    Terminal state. Review our guidelines before submitting future reports.

    Where reports get sent

    Confirmed abuse is forwarded through legitimate channels: we do not run offensive operations.

    Hosting Provider

    Suspends the account behind the malicious site. Cooperative hosters typically act within hours to one business day.

    Domain Registrar

    Can suspend or seize the domain. Registrars usually respond in one to three business days.

    Blocklists

    Google Safe Browsing, Microsoft SmartScreen, APWG and URLhaus so browsers warn users even before the host acts.

    CERTs / Law Enforcement

    For serious criminal activity: fraud, illegal content, coordinated campaigns: we escalate to the appropriate authority.

    Email: only when it matters

    • • Submission confirmation with your Report ID.
    • • Abuse confirmed or not found after investigation.
    • • Forwarded to hoster, registrar or authority.
    • • Final outcome: Solved, Refused or Rejected.

    Intermediate transitions like Accepted or Pending don't email you: track them live in your dashboard.

    In-app tracking

    • Notification centre for live status changes.
    • Investigation tab with enrichment output.
    • Full timeline per report: never gets deleted.
    • One-click GDPR data export from Settings.

    Zodiac · OSINT investigation boards

    For deeper cases, Pro and Enterprise teams get a collaborative graph workspace to map persons, domains, IPs and wallets, enrich them automatically, and submit verified indicators into a system-wide flag database.

    Graph canvas

    30+ entity types, smart paste from clipboard, floating edges with auto-avoidance, dark/light themes.

    Realtime collaboration

    Invite analysts, presence avatars, per-node comments, task assignment and read-only sharing.

    Conflict-free editing

    Soft node locks and append-only audit trail so two analysts can never overwrite each other.

    Automated enrichment

    One-click IP/ASN, WHOIS, crypto wallet, VirusTotal and AbuseIPDB lookups: each source recorded.

    Global flag database

    Verified indicators pulse red on any Blackwall board: across every workspace, in real time.

    Strict verification

    Only the host submits. Every entity is reviewed against strict criteria; decisions are explained and emailed.

    Snapshots & audit

    Versioned board snapshots and SHA-256 hash-chained audit trail: end-to-end verifiable.

    Forensic PDF export

    Graph screenshot, executive summary, entities, sources and chain-of-custody hash: ready for handover.

    Ready to fire a report through the pipeline?

    Free, no credit card, no follow-up spam. If you're here on behalf of a company, join the pilot for managed takedowns and brand monitoring.

    Cookie Notice

    We use cookies to ensure the functionality of our website. Necessary cookies are required for operation. Optional cookies help us improve our services. For more information, see our Privacy Policy.