Skip to content
Back to scanner

Method

How a scan becomes a verdict.

A scan combines high-confidence reputation checks with resilient local signals so the output stays useful even when one provider is degraded. Each signal resolves independently, and verdict confidence explains how much clean or risky coverage actually supported the final score.

Scoring approach

High-confidence evidence moves the verdict most.

Safe Browsing matches, community feed hits, and stronger multi-engine detections outweigh softer context. DNS posture, TLS quality, WHOIS age, and redirect behavior still matter, but they are supporting evidence rather than the primary driver.

Risk-moving signals

  • Google Safe Browsing
  • Threat feeds: URLhaus and OpenPhish — matches use the exact listed URL string, not directory or hub pages.
  • VirusTotal multi-engine detections
  • Local ensemble consensus

Resilience signals

  • TLS validation and certificate metadata
  • WHOIS age, registrar, and country
  • DNS anomalies and passive observations
  • Redirect-chain hops and terminal reachability

Using the console

How to read lanes, batches, and feeds.

Summary vs full
Summary prioritizes the highest-impact lanes; full shows every outcome, including caveats.
Batch stays isolated
Queue short lists, then open any finished row in single-scan mode from the scan console.
Browser-only history
Saved scans stay on-device unless you export or share them. See privacy for what the server still processes.
Feed hits need the full URL
URLhaus and OpenPhish match the exact IOC string you paste — not browse pages like urlhaus.abuse.ch/browse/.
Scrutinix

Hash-only logs · Browser-only history · No share database