SentinelPhish

Real-time heuristic zero-day phishing detection, optical QR shield inspection, and community threat intelligence.

Engine v1.0 Production Release

Platform & Intelligence

  • URL Threat Scanner
  • Community Threat Feed
  • QR Shield Inspection
  • Plans & Pricing

Legal & Support

  • Privacy Policy
  • Terms of Service
  • Contact Intelligence

© 2026 SentinelPhish AI. All rights reserved.

Commercial licensing available for MSPs, SOCs & Fintech.
Instant URL Inspection • No Account Required

AI-Powered Phishing Protection
for the Modern Web

Analyze suspicious links with layered threat intelligence, URL heuristics, headless sandbox analysis, and AI-assisted visual inspection before they reach your team.

https://
2 Free Guest Scans Included•Layered Threat Intelligence•Zero Software Installation
[ Example Analysis ]Demonstration Sample
2026-09-12 09:42 UTC
High Risk — 88/100
Target:hxxps://auth-verification-portal[.]net/loginDefanged
Brand Impersonation Detected
Suspicious Redirect Hop
Obfuscated DOM Inputs
Detection Summary
  • High-fidelity credential harvesting form impersonating corporate Single Sign-On (SSO).
  • Double HTTP 302 redirect hop through intermediate dynamic DNS host (hop-02.dyndns[.]org).
  • Headless DOM analysis captured hidden Base64 JavaScript listeners capturing input keystrokes.
Recommended Action
Immediate containment & perimeter blocking recommended
  • Blacklist domain and resolve destination IP in boundary firewalls & DNS sinkholes.
  • Invalidate active SSO sessions for any user who accessed this URL within the past 4 hours.
  • Quarantine inbound email messages containing matching domain or redirect signatures.
Security Engine: Sentinel Hybrid Heuristics + Vision LLM SandboxStatus: Quarantine Enforced
Platform Demo

Automated Headless Sandbox In Action

Observe our headless browser navigate intermediate redirect hops and extract DOM heuristics without executing malicious payloads locally.

Your browser does not support the video tag.
ANALYSIS ARCHITECTURE

How Sentinel Investigates a Suspicious Link

Every submitted URL traverses a multi-layered inspection engine to expose deceptive behavior before any human clicks.

[ STAGE 01 ]

Pre-Flight & Network Routing

Resolving destination status codes, inspecting multi-hop redirect chains, and detecting immediate cloaking techniques or IP circuit-breakers.

Verified Execution
  • URL Normalization
  • 5-Hop Redirect Trace
  • Threat Intel (URLhaus)
  • Circuit Breaker Tripping
[ STAGE 02 ]

Heuristics & Static Inspection

Evaluating suspicious domain patterns, misleading subdomains, obfuscated paths, and embedded form fields before browser execution.

Verified Execution
  • Brand Typosquatting
  • Shady TLD Matching
  • Form Action Hijacks
  • WHOIS/RDAP Age Verification
[ STAGE 03 ]

Headless Sandbox & AI Vision

Rendering the page in an isolated headless environment to capture DOM behavior and AI visual brand impersonation checks.

Verified Execution
  • Isolated Chromium Runtime
  • Full-Viewport Screenshot
  • Multimodal Vision AI
  • Deceptive MFA & Urgency Audit
[ STAGE 04 ]

Evidence Synthesis & Verdict

Correlating findings into a categorized threat verdict with concrete forensic evidence and defanged URLs.

Verified Execution
  • 0–100 Unified Risk Score
  • SOC Quarantine Protocol
  • Defanged Telemetry (hxxps://)
  • Convex Threat Persistence
[ FORENSIC EVIDENCE VS. BLACK-BOX SCORES ]

Don’t Just Get a Score. Understand Why.

Most scanners leave you guessing with an opaque risk rating. Sentinel dissects the entire delivery chain, revealing the exact heuristics and behavioral signals behind every verdict.

Tier Preview:
Legacy Security ScannerBlack Box
82%Suspicious

Arbitrary threat weight without forensic evidence.

Unanswered Questions
Why is this score 82% instead of 20%?
Which intermediate redirect hops were traversed?
Was a credential form hidden in an iframe?
What immediate action should SOC take?

The Old Way: High friction, zero context, and no actionable proof.

[ Example Analysis Preview ]Target: hxxps://security-update-microsoft[.]cc/verify
Phishing Confirmed — 92/100
Redirect Path Forensics (3 Hops)
Dynamic Gateway Cloaking
1. Initial:bit[.]ly/m365-verify
301 Redirect
2. Intermediate:tracking.cloudgateway[.]org/hop?id=9a2b
302 Gateway
3. Terminal:security-update-microsoft[.]cc/verify
200 Payload
DOM Forensics & Hidden Form Elements
Cross-Origin Iframe Hijack:

Password input injected within sandboxed iframe to evade static crawlers.

Form Action Exfiltration:

Credentials POST directly to unmapped IP destination 198.51.100.27.

AI Threat Assessment (Grounded Narrative)

“Credential harvesting workflow intentionally impersonating Microsoft 365 login portal. Attackers utilize an obfuscated 3-hop redirect chain and dynamic DOM injection to bypass standard email gateway filters.”

Deep Autonomous System & SSL Analysis
PRO TELEMETRY UNLOCKED
Registrar / Age:NameSilo (3 days old)
Origin ASN:AS208608 (Bulletproof)
SSL Certificate:Let's Encrypt (Untrusted CA)

Deep Network ASN & Autonomous System Forensics

PRO

Inspect newly registered bulletproof ASN infrastructure, upstream peering anomalies, and automated SOC blocking playbooks.

Unlock with 14-Day Free Trial
Recommended Action: Immediate perimeter DNS sinkhole and SSO session revocation.

Defensive De-Fanging

Automatically neutralize URLs (hxxps://, [.]) and embedded payloads prior to evaluation, preventing accidental execution across SOC teams.

Zero Hallucination Grounding

AI assessments are anchored directly to real DOM nodes, redirect hops, and viewport pixel buffers—eliminating synthetic guesswork and false positives.

Exportable Forensics

Generate clean, concise technical threat summaries with defanged IOCs ready to paste directly into Jira tickets, Slack security channels, or SIEM rules.

Real-time Heuristics

Analyze URLs with lightning speed. Our engine breaks down threats and obfuscations as they emerge.

Deep Vision Analysis

Leverage vision AI to detect brand impersonation, visual trickery, and deceptive DOM elements.

Layered Intelligence

Cross-reference against real-time threat intelligence data feeds, DNS anomalies, and redirect chains.

[ TRANSPARENT SECURITY PRICING ]

Investigate with Confidence. Upgrade for Full Forensics.

Start analyzing suspicious links immediately on the Free tier, or unlock multi-hop redirects and deep AI heuristics with a 14-day Pro trial.

MonthlyAnnualSave 20%

Community Free

For individuals & ad-hoc verification

Active Tier
$0/ month

Free forever · No credit card required

Included Capabilities:
  • 9 Daily URL Scans (resets midnight UTC)
  • Standard risk scoring (0–100) & status verdicts
  • Automatic URL defanging (hxxps://)
  • Full access to Community Threat Feed (/reports)
  • Domain age & baseline reputation heuristics
14-Day Free Trial · No CC Required

SecOps Pro

For security engineers & teams

$15/ month$29

50% early access rate locked in for life

Advanced Forensics Unlocked:
  • 300 Scans / Day (Fair Use SecOps allocation)
  • Multi-Hop Redirect Tracing & dynamic gateway unmasking
  • Headless DOM Analysis & cross-origin iframe detection
  • AI Multimodal Vision (brand logo & MFA spoof checks)
  • Exportable IOC Forensics ready for SIEM & ticketing
Activate 14-Day Free Trial
ZERO CLICK EXPOSURE

Got a suspicious link?

Let SentinelPhish investigate it before anyone clicks.

2 free guest scans · Instant heuristic verdict · No account required

[ LIVE THREAT TELEMETRY ]

Recently Investigated Threats

Real-time URLs analyzed and defanged across the Sentinel platform. Backed exclusively by genuine inspection telemetry.

View Complete Threat Archive