Threat intelligence
Reputation feeds disagree more often than a single-score interface admits. This module queries each source separately and presents every verdict, so an analyst can see when a target is clean according to one reliable feed and malicious according to another.
Example: https://example.com/path
What this module collects
- Spamhaus ZEN listings, with the specific listing type decoded
- SURBL domain listings
- abuse.ch URLhaus malware distribution records, online and historical
- AbuseIPDB confidence scores where an API key is configured
- An explicit disagreement finding when sources conflict
- Certificate validation failures on the live host
- Missing security headers and weak TLS parameters
- Recently registered domain flags
What this module will not do
These limits are deliberate. Each one is a place where a tool could produce a confident-looking answer that is not supported by public evidence.
Disagreement is never resolved for you
If two sources conflict, both verdicts are shown side by side with the confidence marked low. Picking a winner would discard the signal that the answer is genuinely uncertain.
Not listed is not the same as safe
An absence of listings means no queried feed has recorded this target. New infrastructure is routinely clean in every feed on the day it is used.
No malware execution or sandbox detonation
The platform retrieves and inspects public responses. It does not download, execute or analyse samples.