A typed terminal for security triage.
Paste an IP, a domain, a hash or an encoded command, then chain what you want to know about it. Every step is checked before a single API call is spent.
We're letting people in a few at a time. Leave your email and we'll let you know as soon as there's a spot for you.
You're on the list. We'll write to you as soon as your spot is ready.
We'll only email you about your invite, and we never share your address. Reply to any email from us and we'll delete it.
>>> "powershell -w hidden -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoA...".decode()[url]
>>> "cdn-telemetry.example".urlscan()[ip].abuseipdb()
>>> "203.0.113.47"{ geo()[country_name], asn(), rdap() }.cost()
>>>
- url:
- http://cdn-telemetry.example/win/update.ps1
- score:
- 100
- total_reports:
- 214
- usage_type:
- Data Center/Web Hosting/Transit
- is_tor:
- false
- cost:
- 3 API calls - projected, not executed
It knows what you pasted.
IPs, domains, URLs, hashes, email addresses and headers, shell and PowerShell commands. Defanged input such as 1[.]2[.]3[.]4 or hxxps:// is read as the real thing.
A dot offers what makes sense.
Registration, DNS, reputation, certificates, sandbox scans, sample lookups. Each step takes what the last one produced, so one line follows a URL to its host, its address and that address's history.
Lookups that can't answer don't run.
A chain is type-checked before anything leaves the machine, repeats come from a cache, and a block of checks can be priced before it runs.
Decoding stays local.
Base64 inside gzip inside hex is unwound on your machine, with the method and a confidence score. A sensitive blob is never sent anywhere to be read.
The investigation is kept.
Notes beside the terminal, saved expressions, exports to CSV and Excel, and an audit log of every action.