Book a demo call with us
Cross icon
Threat-intel

Urlscan

A free web scanning service that browses submitted URLs in a sandboxed environment and records all page activity, resources, and behavior. Used by SOC teams to safely investigate suspicious links and detect phishing infrastructure.

Urlscan

What is Urlscan?

Urlscan.io is a free web analysis service that safely browses submitted URLs in an isolated sandboxed environment and records everything that happens during the page load: all HTTP requests made, JavaScript executed, cookies set, redirects followed, and the final rendered DOM. The result is a detailed report showing the full behavior of a web page, including any malicious content loading, drive-by download attempts, phishing form submissions, or redirect chains designed to obscure the final destination. Urlscan also captures a screenshot of the rendered page and extracts all observed domains, IP addresses, and file hashes as indicators of compromise. Because it accesses URLs in an isolated environment, analysts can safely investigate suspicious links from phishing emails or threat intelligence feeds without risking their own browser or network.

How does Urlscan work with Qevlar?

Qevlar uses Urlscan to safely analyze suspicious URLs encountered during automated phishing and threat intelligence investigations. When an alert involves a URL of unknown safety, Qevlar can submit it to Urlscan and use the resulting behavioral report and extracted IOCs to determine whether the link is malicious and to identify related infrastructure.

Want to help your analysts focus on the most critical alerts?

Frequently asked questions

What does Urlscan do?

bar
bar

Urlscan.io is a web scanning service that safely browses submitted URLs in an isolated sandbox, recording every request, redirect and rendered page — along with a screenshot and extracted IOCs — so analysts can investigate suspicious links without risk.

What can you do with Urlscan in Qevlar?

bar
bar

Qevlar can submit suspicious URLs to Urlscan during phishing and threat-intelligence investigations, using the behavioral report and extracted IOCs to determine whether a link is malicious and to identify related infrastructure.

Does Qevlar scan suspicious links automatically?

bar
bar

Yes. When an alert involves a URL of unknown safety, Qevlar handles the scan and folds the result into the investigation without manual effort.

Can Urlscan results uncover related infrastructure?

bar
bar

Yes. The domains and IPs captured during a scan are pivoted across your connected tools to find related activity and map the attacker's infrastructure.

Other integrations