KWTCyberWatch
Live · runs entirely in your browser

Phishing detection & brand protection for Kuwait

Watch Certificate Transparency in real time, hunt typosquats of Kuwaiti banks, telecoms and government services, and triage alerts — with the full detection engine running client-side. Nothing leaves your browser.

26brand profiles
—feed keywords
—known suffixes
STIX 2.1export

Direct CT tailing

The browser reads Certificate Transparency logs itself — no third-party feed — and scores every new certificate.

Typosquat Hunter

Generate look-alike domains and resolve them live over DNS-over-HTTPS.

Real enrichment

crt.sh history, RDAP registration data and URLhaus reputation, fetched directly.

Alert triage

Lifecycle, one-click allowlisting, CSV and STIX 2.1 export — stored locally.

KWTCyberWatch

v2.4.0
CertStream: connecting…
Analyst — LOCAL ENGINE

Dashboard

Live overview — every number below is computed from real feed events, scans and alerts stored in this browser.

Certificates Seen
0
this session · live CT feed
Phishing Detected
0
score ≥ 50 in scans & feed
Open Alerts
0
0 critical
Brands Protected
26
Kuwait banking, telecom, government
Domains Analysed
0
0 live typosquats
🔴 Highest-risk Domainsfrom your scans and the live feed
DomainSignalScoreWhen
📊 Detection Categories
🔑 Keyword Hits in the Live Feedthis session

Certificate Transparency Live Feed

This browser reads public CT logs directly (get-sth / get-entries) and parses every certificate itself — no CertStream or other third-party feed. Each hostname is matched against your keywords and scored by the engine.

Feed Status
connecting
—
Certs / second
0
0 seen
Keyword Matches
0
stored locally
High Risk (≥60)
0
scored by the engine
Matched Certificates
Waiting for the first matching certificate…
🗂 CT logs being tailed
live — entries parsed 0 coverage — 0 errors Relay feed: —
LogStateTree sizeReadRateSkipped
Not started

Logs are discovered from Google's public CT log list, falling back to built-in shards. A log that blocks cross-origin requests or is offline is skipped automatically. Independently, the relay feed carries matches found by the project's own tailer running on a schedule in GitHub Actions and published to this site, so Kuwait matches keep arriving even when a browser cannot read a log directly.

Domain Scanner

Phishing heuristics, brand impersonation and squatting analysis by the v2.4 engine, enriched live with DNS, Certificate Transparency and RDAP.

Try: nbk-secure-login.xyz · nbк.com · بيتك-تحديث.com · knetpay.info · login.nbk.com
📋 Recent Scans
DomainRisk ScoreLevelCategoriesScanned

📋 Bulk Domain Scanner

Paste a list of domains. Each one runs through the full engine; optionally each is resolved via DNS-over-HTTPS.

Input0 domains
Results—
DomainScoreLevelBrandsCategoriesDNS
📋
No scans yet
Paste domains above and click Scan All

🧬 Typosquat Hunter

Generates technique-tagged permutations of a brand (typos, homoglyphs, leetspeak, combo-squats, TLD swaps) and resolves them over DNS-over-HTTPS. Anything that resolves becomes a sighting.

Target Brand
Suffixes: max

🧠 Domain Intelligence

Real lookups from the browser: DNS-over-HTTPS resolution, Certificate Transparency history (crt.sh), RDAP registration age and URLhaus reputation. Feeds that require an API key (VirusTotal, Google Safe Browsing, PhishTank) run in the Python backend.

Recent investigations
DomainResolvesCT certsRegisteredAgeURLhausVerdictWhen
🧠
No investigations yet

📜 CT Log Explorer

Query crt.sh for every certificate ever logged for a domain or wildcard pattern (e.g. %.nbk.com).

🌐 DNS Lookup

A, AAAA, MX, NS, TXT, CNAME and SOA records via Google DNS-over-HTTPS.

📇 RDAP / WHOIS

Registration data (registrar, dates, nameservers, status, abuse contact) via the IANA RDAP bootstrap.

📚 Scan History

Every scan is stored locally (IndexedDB). Click a row to re-run it.

Your Scans
DomainScoreLevelBrandsCategoriesTime

Brand Protection Monitor

Protected profiles with aliases and Arabic keywords. Alert counts come from your local alerts. Add your own profiles in Settings.

BrandProtected DomainsAliases / ArabicIndustryPriorityAlerts

Security Alerts

Brand-impersonation alerts raised by scans and the live feed. Triage them here; false positives can be allowlisted in one click.

Critical
0
High
0
Medium
0
Resolved
0
🚨 Alerts
0 selected
IDSeverityBrandDomainTypeSourceDetectedStatusActions

🎯 Typosquat Sightings

Look-alike domains of protected brands that resolved when checked by the Typosquat Hunter or the automatic Watchtower sweep.

🗼 Watchtower
—
New
0
Monitoring
0
Total
0
Last check
—
Live sightings
DomainBrandTechniqueIPsFirst seenSeenStatusActions

Analytics

Computed from the scans, alerts and feed matches stored in this browser.

Scans (7 days)
0
Alerts (7 days)
0
Feed matches (7 days)
0
False-positive rate
—
📈 Daily activity (scans + alerts)
🎯 Most-targeted brands
🕐 Feed matches by hour (UTC)

Notifications

Browser notifications work right here. Email, Slack, Teams, Telegram, webhook and Syslog/CEF delivery are performed by the Python backend (python main.py monitor), which cannot run inside a static page.

🔔 Browser notifications
Permission: unknown
🔗 Webhook payload preview

This is the exact JSON the backend posts to Slack/Teams/webhook targets for the most recent alert.

No alerts yet.
🖥️ Server-side channels

Configure in config.yaml → notifications:
• Email (SMTP)  • Slack Block Kit  • Microsoft Teams
• Telegram  • HMAC-signed webhook  • Syslog / CEF

Then run python main.py test-notify to verify every channel.

Settings

Everything here is stored locally and applied immediately to the engine and the live feed.

🔑 CertStream Keywords

Keywords shorter than 3 characters only match whole tokens (so kw does not match hawkwind).

✅ Allowlist
🏦 Custom brand profile
🧪 Detection rulesregex · applied to the live feed and scans
Test:

Examples: civil-?id, (kw|kuwait).*(gov|fines|visa), ^(secure|login|verify)-.*\.(xyz|top|icu)$. Matches raise a custom_rule alert with the chosen severity.

⚙️ Engine & feed
Deep match — run the brand engine on every certificate, not only keyword hits (catches typos and homoglyphs such as nbк.com)
Auto-enrich new feed alerts with DNS and registration age (DoH + RDAP)
Watchtower brand sweeps every min
API: not configured
💾 Storage & retention—
Purge scans & feed matches older than days
ℹ️ About