Run an investigation first.
Run an investigation first.
Run an investigation first.
What a run does
- Collect. Certificates naming the brand (crt.sh certificate transparency), lookalike domains generated from the brand domain (omission, swapped or adjacent keys, homoglyphs, hyphens, added words like "login" or "verify", other TLDs) and checked in DNS, and the public OpenPhish feed plus a Phishing.Database snapshot.
- Enrich. Live DNS (A, NS, MX) over HTTPS, the network owner of each IP (RIPEstat) and who the registry assigned the range to (IP RDAP, which also gives the hosting abuse contact and flags ranges held by security firms that run sinkholes), registration date and registrar (RDAP, for TLDs that publish it), and scans other people already submitted to urlscan.io.
- Connect. Domains are linked when they share an IP (CDN and sinkhole IPs excluded), non-generic name servers, or a registrar and registration week. A linked group is read as one operator.
- Score. Each factor is shown on the row: phishing-feed listing, malicious scan verdict, recent registration, live DNS, mail servers, lookalike pattern, shared infrastructure, brand name on free hosting.
- Triage and act. Each domain opens as a case: evidence, certificate history, the last public screenshot, a pivot to other sites on the same IP, registrar and hosting abuse contacts (RDAP, RIPEstat) and a defanged takedown notice. Triage states and notes are kept in this browser, the next run of the same brand lists what is new, and a re-check marks tracked domains offline once they stop resolving.
- Keyboard. j and k step through the flagged list and open each case; Esc closes it.
- Export. IOCs as CSV, or a STIX 2.1 bundle (domain and IP indicators, relationships, TLP:AMBER marking) for a TIP or SIEM.
- Report. A draft assessment with a bottom line, key judgements in estimative language, recommended actions, gaps, Admiralty source grades and an evidence list. The evidence log records every request with UTC time, status and SHA-256.
Boundaries
- No visit to any suspect site: page content comes only from scans others already made. This keeps the analyst's infrastructure out of the attacker's logs.
- No login, no scraping behind authentication, no purchase or download of leaked data. In Malaysia, unauthorised access is an offence under the Computer Crimes Act 1997 s.3, and compiling personal details to harass is an offence under the Penal Code amendments of 2025.
- Brand-owned domains are excluded by list; a domain not on the list is flagged, which is a lead and needs confirmation.
Limits
- Phishing sites without a certificate or a lookalike name are missed.
- crt.sh is slow and sometimes fails; the run says so when it does.
- .my domains publish no RDAP; their age falls back to the first certificate date.
- Up to 45 domains are enriched per run, highest evidence first.
Built by
Edward Tay. Homework page: forward-defense.edwardtay.com.