A typed terminal for security triage.

Paste an IP, a domain, a hash or an encoded command, then chain what you want to know about it. Every step is checked before a single API call is spent.

We're letting people in a few at a time. Leave your email and we'll let you know as soon as there's a spot for you.

We'll only email you about your invite, and we never share your address. Reply to any email from us and we'll delete it.

TERMINAL

>>> "powershell -w hidden -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoA...".decode()[url]

>>> "cdn-telemetry.example".urlscan()[ip].abuseipdb()

>>> "203.0.113.47"{ geo()[country_name], asn(), rdap() }.cost()

>>>

OUTPUT
[OK] Decode on powershell -w hidden -enc SQBFAFgA... via base64, utf-16le
url:
http://cdn-telemetry.example/win/update.ps1
[OK] IP reputation on 203.0.113.47 via AbuseIPDB
score:
100
total_reports:
214
usage_type:
Data Center/Web Hosting/Transit
is_tor:
false
[OK] { geo(), asn(), rdap() }.cost() on 203.0.113.47
cost:
3 API calls - projected, not executed
NOTES

It knows what you pasted.

IPs, domains, URLs, hashes, email addresses and headers, shell and PowerShell commands. Defanged input such as 1[.]2[.]3[.]4 or hxxps:// is read as the real thing.

A dot offers what makes sense.

Registration, DNS, reputation, certificates, sandbox scans, sample lookups. Each step takes what the last one produced, so one line follows a URL to its host, its address and that address's history.

Lookups that can't answer don't run.

A chain is type-checked before anything leaves the machine, repeats come from a cache, and a block of checks can be priced before it runs.

Decoding stays local.

Base64 inside gzip inside hex is unwound on your machine, with the method and a confidence score. A sensitive blob is never sent anywhere to be read.

The investigation is kept.

Notes beside the terminal, saved expressions, exports to CSV and Excel, and an audit log of every action.