Stillhook Labs

How it works

A process, not a favor

Security testing and scam takedowns each follow a set of clear steps. Nothing starts without your written sign-off.

Security testing

Penetration tests & phishing simulations

  1. 1

    Get in touch

    Tell us about your site, your team, and what you're worried about. A short form is all it takes to start the conversation.

  2. 2

    Sign authorization & scope agreement

    We define exactly what's in scope, what's out of scope, and the testing window before anything starts. Nothing is tested without this signed off.

  3. 3

    We test

    Hands-on testing of your app or your staff within the agreed window, carried out by us, not outsourced.

  4. 4

    You get a report

    Clear findings, severity ratings, proof of concept, and business impact. No fix implementation, just what your dev team needs to act.

  5. 5

    Retest (optional)

    Once your team ships fixes, we can verify they actually worked with a short-form before/after report.

No testing without authorization. We only test what's explicitly agreed and signed off in advance, no exceptions. Read more on our Legal & Trust page.

Scam site takedowns

How we research and remove scam websites

Scammers copy trusted brands to steal logins, payments, and personal details from customers. Before launch we took down 98 scam websites targeting logistics companies using this process.

  1. 1

    Report & triage

    Send us anything suspicious: links, emails, SMS messages, ads, or fake social profiles. We also hunt for sites impersonating your brand ourselves. Sites actively taking money or data from your customers go to the front of the queue.

  2. 2

    Investigate the site

    We work through the scam the way a victim would, from a safe, isolated setup. We find out exactly what it's after, how it tricks people, and what happens to the information victims hand over.

  3. 3

    Trace the operation

    One scam site is rarely alone. We look past the page in front of us to the setup behind it and link related sites and campaigns, so we can go after the whole operation, not just one URL.

  4. 4

    Build the case & take it down

    We put together a case file built to get action and escalate it through the channels that actually pull scam sites offline, while warnings go up for would-be victims. Formal claims on your brand's behalf are only filed with your written go-ahead.

  5. 5

    Follow up & report back

    We stay on it until the site is gone and watch for it coming back under a new name. You get a clear write-up of what the scam targeted, how far it reached, and what was taken down.

Why we keep the details close. Scammers read security websites too, so we don't publish our exact methods. Everything we do stays within the law, and sites come down through the providers responsible for them, not by hacking them.

Ready for step one?

Get Started Free