unphish
unphish unphish

What threat analysis looks like at unphish

Dejan Baker‑Petkovich from unphish

At unphish, identifying a potential threat is only the beginning.

Automation takes care of much of the repetitive work, including collecting evidence, enriching cases and progressing routine threats through established workflows. This allows the Threat Operations team to spend more time analysing complex campaigns, identifying attacker behaviour and making informed decisions about how threats should be disrupted.

That is where the Threat Operations team comes in.

Every day, the team reviews suspicious activity targeting clients’ brands, customers and reputation. They investigate high-risk threats, uncover links between campaigns, oversee enforcement activity and ensure malicious infrastructure is disrupted as quickly and effectively as possible.

One of the people doing that work is Dejan (or as we call him DJ), Digital Threat Analyst at unphish.

As a Threat Analyst, DJ investigates phishing campaigns, brand impersonation and other malicious activity targeting organisations. While automation streamlines much of the investigative process, his role is centred on the threats that require deeper analysis, critical thinking and human judgement.

Dejan Baker‑Petkovich from unphish

For DJ, the enforcement side is one of the most rewarding parts of the role.

“The enforcement side is where I get the biggest rush, actually taking down malicious domains and social media accounts belonging to bad actors.”


Every takedown has a real outcome. It can mean fewer people being deceived by scam pages, fewer customers being targeted through fake profiles, and fewer scammers using a trusted brand to steal money or personal data.

“There’s something deeply satisfying about knowing that every takedown we execute means real people are protected from scammers.”


“We’re not just identifying threats; we’re actively stopping them in their tracks and making the internet a safer place.”


That sense of impact has also shaped the way DJ thinks about his own growth. He is open about the fact that unphish gave him an opportunity, and that has stayed with him.

“What drives me in this work is straightforward. This company took a chance on me and gave me an incredible opportunity, so I want to do a good job and prove that faith was well-placed.”


That attitude carries through to the way he approaches investigations. Threat analysis requires patience, attention to detail, and a willingness to keep digging, even when something looks straightforward on the surface.

A lot of that approach has been shaped by working closely with Brendan Emmott, Head of Threat Operations at unphish.

“Honestly, Brendan has taught me everything I know in this role. From day one, he’s been instrumental in shaping how I approach investigations.”


The biggest lesson has stayed with him. Every detail matters.

“Being incredibly meticulous in my work, checking every detail, no matter how small. That thoroughness has become the foundation of everything I do, and it’s made all the difference in catching things others might miss. I owe a huge part of my growth in Threat Operations to his mentorship.”


In threat operations, small details can change how a case is understood. A slight variation in a domain name, a reused piece of infrastructure, a familiar account pattern, or a small inconsistency in a scam page can all affect how quickly action can be taken.

That level of detail becomes even more important in a role where scammer behaviour is constantly changing.

“What fascinates me most is the constant evolution of scammer behaviour.”


“You’ll catch onto a pattern, enforce against it, and watch them pivot their tactics almost immediately.”


“It’s this ongoing cat-and-mouse game. Just when you think you’ve figured out their playbook, they change it up entirely, and you’re back to hunting for their next move. Keeps the work interesting, that’s for sure.”


That is where curiosity becomes important. Analysts need to recognise patterns, question what they are seeing, and keep looking for the next shift in behaviour.

One part of the work that has made a big difference for DJ recently is automation within unphish.

“The automation features have become my favourite recently.”


For the Threat Operations team, automation has made a real difference. It helps analysts move faster, manage a higher volume of cases, and take action sooner without losing the detail that good investigations require.

“They’ve completely transformed how we work, allowing us to upscale our workflow significantly.”

“What used to take hours can now be streamlined, meaning we can protect more brands and take action faster, which ultimately means more bad actors shut down.”


As DJ has grown in the role, one of the biggest skills he has developed is understanding how the enforcement ecosystem actually works.

“My investigative skills have grown exponentially since I started.”


“I’ve developed a real understanding of the enforcement ecosystem, knowing exactly where to report specific violations, who to report to, and crucially, how to frame reports so registrars and hosting providers actually take action.”


That knowledge has become a practical part of the Threat Operations team’s success, helping cases move from investigation to disruption more effectively.

“That knowledge has been a game-changer in our success rate.”


There is a lot of technical work behind threat operations, but DJ is also known for bringing a very social energy to the office.

That was not always the case.

Dejan Baker‑Petkovich from unphish

“I used to be quite reserved. When I started here, I made a conscious decision to push myself out of my comfort zone and just talk to people in the building. Best decision I made.”


Around the office, he is also known for playing pool, backed by the best strategy.

“I believe. Confidence goes a long way. Believe you’ll make it, and more often than not, you will. Oh, and luck.”


Outside of work, DJ is all about balance. He spends time exercising, reading, socialising, working on his own projects, developing new skills and working on his fantasy novels.

“I write fantasy stories. How much space do you have? I can tell you about an entire world.”


And when it comes to karaoke, he is a simple man.

“Anything 2000s R&B, dance worthy or rap.”


In many ways, DJ’s role reflects the work happening inside unphish’s Threat Operations team. It is technical, detailed, fast-moving and deeply human.

Every case involves a real brand, real customers, and real people who could be harmed if the threat is not stopped quickly enough.

For DJ, the work comes back to following the details, understanding scammer behaviour, using the right enforcement pathways, and helping take threats offline before they can do more damage.

At the end of the day, threat operations at unphish comes down to stopping bad actors and protecting the people they are trying to reach.

About unphish

Protect Your Brand with unphish

unphish is a threat detection and disruption platform built to identify and take down phishingscams, and digital impersonation at scale. We combine intelligence-led detection with automated enforcement to help organisations protect their brand, customers, and digital ecosystem.

See unphish in Action

Detect, Validate, and Take Down Threats Automatically

unphish combines intelligence-led detection with automated enforcement so you can protect your brand, customers, and digital ecosystem without the manual effort.

Create your account