Current Doc

URL Threat Analyzer

Use Browse Docs to switch sections and search the full docs list.

Documentation

Blue Lantern Security Docs

Learn how to use the marketplace, run security tools, and integrate via the API.

URL Threat Analyzer

Render a URL in a controlled environment and surface phishing, redirect abuse, and suspicious page behavior.

The URL Threat Analyzer loads a URL in an isolated browser, captures a screenshot of the rendered page, and runs a series of safety checks against the request, response, and DOM. Use it to triage suspicious links before clicking, or to enrich phishing investigations with the actual landing page behavior.

What It Analyzes

  • Page Rendering - Loads the target URL in a controlled environment and captures a screenshot of the final landing page so you can see what a victim would see.
  • Phishing Signals - Detects login forms, credential prompts, and other deceptive page patterns commonly used in credential harvesting.
  • Redirect Chain - Records the full navigation history from the submitted URL to the final landing URL, including intermediate hops.
  • Domain Analysis - Pulls registration details (age, registrar, creation/expiration dates) and flags suspicious patterns such as recently registered domains or typosquats.
  • SSL & Final URL Validation - Checks that the certificate is valid and that the final URL is well-formed and reachable.
  • Suspicious Network Requests - Filters out the target domain and common benign third parties, then flags requests for known credential-harvesting hosts, POSTs to external hosts, obfuscated payloads, bare-IP endpoints, and possible data stuffing.
  • Suspicious Links - Reviews links on the rendered page for javascript: hrefs, data URIs, encoded hrefs, direct downloads, and credential or billing patterns.
  • Cookie Security - Inspects cookies set during the visit for missing HttpOnly, Secure, and SameSite attributes, plus cookies with embedded JWTs or other unexpected payloads.
  • Page Behavior - Watches for popups, automatic downloads, and back-button hijack attempts.

Input Requirements - URL must use http:// or https://. If you submit a bare hostname, the engine will normalize it to https://. Only submit URLs you are authorized to analyze.

How to Use - UI

  1. Navigate to the URL Threat Analyzer page.
  2. Paste the URL you want to analyze into the input field.
  3. Click Submit for Analysis. You will receive a job ID and the analysis will run in roughly 30 seconds.
  4. Once processing completes, open your Monitoring Hub and click into the run to see the screenshot, check results, redirect chain, and any flagged network requests, links, and cookies.
  5. The full result set, including the noisier network log and cookie data, is available via the Download CSV button on the report page.

Tip - The QR URL Extractor can hand a decoded URL directly to the URL Threat Analyzer with one click, so you do not have to retype links from a phone screen.

How to Use - API

This API is designed to be plugged into automation tools so you can detonate URLs from SOAR playbooks, ticket triage, or email enrichment pipelines. Please note, there is a limit of 600 requests in a 10 minute period for your account.

  1. Ensure you have provisioned an API key.
  2. Submit the URL via the /runs endpoint. Unlike the file-based tools, this is a JSON request, not multipart form data. If you only want to check the cost without running the analysis, set checkCost to true.

curl --location 'https://api.bluelanternsecurity.io/runs' \
--header 'Authorization: [YOUR API KEY]' \
--header 'Content-Type: application/json' \
--data '{
    "tool": "URLDETONATOR",
    "checkCost": false,
    "url": "https://example.com/login"
}'

  1. After submission you will be provided a job ID that you will use in the subsequent call to fetch the results data. The jobID response will look as follows:
{
    "message": "Requested Analysis Job Created",
    "result": {
        "jobId": "[JOB ID HERE]"
    }
}
  1. The following curl request (after analysis is completed in approx. 30 seconds) will fetch the report:
curl --location 'https://api.bluelanternsecurity.io/results' \
--header 'Content-Type: application/json' \
--header 'Authorization: [YOUR API KEY]' \
--data '{
    "jobId":"[YOUR JOB ID]"
}'
  1. The screenshot is fetched separately by passing fetchScreenshot: true on the same /results endpoint. The response will be a PNG (or a JSON wrapper containing a base64 image, depending on transport):
curl --location 'https://api.bluelanternsecurity.io/results' \
--header 'Content-Type: application/json' \
--header 'Accept: image/png' \
--header 'Authorization: [YOUR API KEY]' \
--data '{
    "jobId":"[YOUR JOB ID]",
    "fetchScreenshot": true
}' --output detonation.png
  1. The results payload will look as follows (network log and cookie sections truncated for brevity):

{
    "message": "results retrieved",
    "result": {
        "job_id": "[JOB ID]",
        "url": "https://example.com/login",
        "analyzed_at": "2026-04-28T15:51:51.002669+00:00",
        "status": "Completed",
        "Status": 200,
        "checks": {
            "valid_ssl_certificate": true,
            "login_screen_detected": true,
            "is_valid_final_url": true,
            "back_button_possible_hijack": false,
            "download_exists": false,
            "has_popups": false,
            "domain_findings": [],
            "cookie_checks": {
                "session_id": {
                    "httpOnly": "Pass",
                    "secure": "Pass",
                    "sameSite": "Fail"
                }
            }
        },
        "details": {
            "initial_url": "https://example.com/login",
            "final_url": "https://example.com/login",
            "history_length": 1,
            "page_history": [
                "https://example.com/login"
            ],
            "suspicious_network_log": [
                {
                    "url": "https://[SUSPICIOUS HOST]/collect",
                    "method": "POST",
                    "status": 200,
                    "headers": { "content-type": "application/json" },
                    "suspicion_reasons": [
                        "POST to external host",
                        "Possible data stuffing"
                    ]
                }
            ],
            "suspicious_cookies": [
                {
                    "name": "tracking_id",
                    "domain": "[SUSPICIOUS DOMAIN]",
                    "path": "/",
                    "httpOnly": false,
                    "secure": false,
                    "sameSite": "None"
                }
            ],
            "suspicious_links": [
                {
                    "url": "javascript:void(0)",
                    "suspicion_reasons": ["JavaScript in href"]
                }
            ],
            "domain": {
                "domain_info": {
                    "domain": "example.com",
                    "root_domain": "example.com",
                    "age_days": 9876,
                    "creation_date": "1999-01-15",
                    "expiration_date": "2027-01-15",
                    "registrar": "[REGISTRAR]",
                    "available": false,
                    "suspicious_patterns": []
                },
                "findings": []
            },
            "technologies": ["React", "Cloudflare"]
        }
    }
}

Need Help?

Can't find what you're looking for? Reach out and we'll get back to you.

Contact Support