Watch Certificate Transparency in real time, hunt typosquats of Kuwaiti banks, telecoms and government services, and triage alerts — with the full detection engine running client-side. Nothing leaves your browser.
26brand profiles
—feed keywords
—known suffixes
STIX 2.1export
Direct CT tailing
The browser reads Certificate Transparency logs itself — no third-party feed — and scores every new certificate.
Typosquat Hunter
Generate look-alike domains and resolve them live over DNS-over-HTTPS.
Real enrichment
crt.sh history, RDAP registration data and URLhaus reputation, fetched directly.
Live overview — every number below is computed from real feed events, scans and alerts stored in this browser.
Certificates Seen
0
this session · live CT feed
Phishing Detected
0
score ≥ 50 in scans & feed
Open Alerts
0
0 critical
Brands Protected
26
Kuwait banking, telecom, government
Domains Analysed
0
0 live typosquats
🔴 Highest-risk Domainsfrom your scans and the live feed
Domain
Signal
Score
When
📊 Detection Categories
🔑 Keyword Hits in the Live Feedthis session
Certificate Transparency Live Feed
This browser reads public CT logs directly (get-sth / get-entries) and parses every certificate itself — no CertStream or other third-party feed. Each hostname is matched against your keywords and scored by the engine.
Feed Status
connecting
—
Certs / second
0
0 seen
Keyword Matches
0
stored locally
High Risk (≥60)
0
scored by the engine
Matched Certificates
Waiting for the first matching certificate…
🗂 CT logs being tailed
live —entries parsed 0coverage —0 errorsRelay feed: —
Log
State
Tree size
Read
Rate
Skipped
Not started
Logs are discovered from Google's public CT log list, falling back to built-in shards. A log that blocks cross-origin requests or is offline is skipped automatically. Independently, the relay feed carries matches found by the project's own tailer running on a schedule in GitHub Actions and published to this site, so Kuwait matches keep arriving even when a browser cannot read a log directly.
Domain Scanner
Phishing heuristics, brand impersonation and squatting analysis by the v2.4 engine, enriched live with DNS, Certificate Transparency and RDAP.
Paste a list of domains. Each one runs through the full engine; optionally each is resolved via DNS-over-HTTPS.
Input0 domains
Results—
Domain
Score
Level
Brands
Categories
DNS
📋
No scans yet
Paste domains above and click Scan All
🧬 Typosquat Hunter
Generates technique-tagged permutations of a brand (typos, homoglyphs, leetspeak, combo-squats, TLD swaps) and resolves them over DNS-over-HTTPS. Anything that resolves becomes a sighting.
Target Brand
Suffixes:max
Generated
0
Resolving (registered)
0
Not resolving
0
Unknown / errors
0
Permutations
🧠 Domain Intelligence
Real lookups from the browser: DNS-over-HTTPS resolution, Certificate Transparency history (crt.sh), RDAP registration age and URLhaus reputation. Feeds that require an API key (VirusTotal, Google Safe Browsing, PhishTank) run in the Python backend.
Recent investigations
Domain
Resolves
CT certs
Registered
Age
URLhaus
Verdict
When
🧠
No investigations yet
📜 CT Log Explorer
Query crt.sh for every certificate ever logged for a domain or wildcard pattern (e.g. %.nbk.com).
🌐 DNS Lookup
A, AAAA, MX, NS, TXT, CNAME and SOA records via Google DNS-over-HTTPS.
📇 RDAP / WHOIS
Registration data (registrar, dates, nameservers, status, abuse contact) via the IANA RDAP bootstrap.
📚 Scan History
Every scan is stored locally (IndexedDB). Click a row to re-run it.
Your Scans
Domain
Score
Level
Brands
Categories
Time
Brand Protection Monitor
Protected profiles with aliases and Arabic keywords. Alert counts come from your local alerts. Add your own profiles in Settings.
Brand
Protected Domains
Aliases / Arabic
Industry
Priority
Alerts
Security Alerts
Brand-impersonation alerts raised by scans and the live feed. Triage them here; false positives can be allowlisted in one click.
Critical
0
High
0
Medium
0
Resolved
0
🚨 Alerts
0 selected
ID
Severity
Brand
Domain
Type
Source
Detected
Status
Actions
🎯 Typosquat Sightings
Look-alike domains of protected brands that resolved when checked by the Typosquat Hunter or the automatic Watchtower sweep.
🗼 Watchtower
—
New
0
Monitoring
0
Total
0
Last check
—
Live sightings
Domain
Brand
Technique
IPs
First seen
Seen
Status
Actions
Analytics
Computed from the scans, alerts and feed matches stored in this browser.
Scans (7 days)
0
Alerts (7 days)
0
Feed matches (7 days)
0
False-positive rate
—
📈 Daily activity (scans + alerts)
🎯 Most-targeted brands
🕐 Feed matches by hour (UTC)
Notifications
Browser notifications work right here. Email, Slack, Teams, Telegram, webhook and Syslog/CEF delivery are performed by the Python backend (python main.py monitor), which cannot run inside a static page.
🔔 Browser notifications
Permission: unknown
🔗 Webhook payload preview
This is the exact JSON the backend posts to Slack/Teams/webhook targets for the most recent alert.
No alerts yet.
🖥️ Server-side channels
Configure in config.yaml → notifications:
• Email (SMTP) • Slack Block Kit • Microsoft Teams • Telegram • HMAC-signed webhook • Syslog / CEF
Then run python main.py test-notify to verify every channel.
Settings
Everything here is stored locally and applied immediately to the engine and the live feed.
🔑 CertStream Keywords
Keywords shorter than 3 characters only match whole tokens (so kw does not match hawkwind).
✅ Allowlist
🏦 Custom brand profile
🧪 Detection rulesregex · applied to the live feed and scans
Test:
Examples: civil-?id, (kw|kuwait).*(gov|fines|visa), ^(secure|login|verify)-.*\.(xyz|top|icu)$. Matches raise a custom_rule alert with the chosen severity.
⚙️ Engine & feed
Deep match — run the brand engine on every certificate, not only keyword hits (catches typos and homoglyphs such as nbк.com)
Auto-enrich new feed alerts with DNS and registration age (DoH + RDAP)
Watchtower brand sweeps every min
API: not configured
💾 Storage & retention—
Purge scans & feed matches older than days
ℹ️ About
esc
↑↓ navigate↵ runtab hunt instead
⌨️ Keyboard shortcuts
CtrlKSearch & commands
/Focus the domain scanner
?This help
EscClose panels
gdDashboard
gfCertStream feed
gsDomain scanner
gbBulk scanner
ghTyposquat hunter
gaAlerts
giDomain intel
gnAnalytics
gtSettings
Deep links: #scan=domain, #hunt=brand.com, #intel=domain, #alert=ID, #page=alerts.