urlscan.io
Tool Description : A web scanning tool that safely visits a URL on your behalf and records everything that happens.
urlscan.io
Quick Overview
What it does
It loads a website in a safe environment capturing page screenshots, domains contacted, IP addresses, scripts and resources loaded, and technologies used.
How to use it
Drop in a suspicious URL, review the screenshot first, then dive into network requests to see hidden connections.
Cost
Free for basic use. Paid for higher volume, API access, and private scans.
Account required
No for basic scans. Yes for advanced features.
Cookies
Basic tracking and session cookies (but none recorded in our session).
Ownership
German cybersecurity company urlscan GmbH, founded by Johannes Gilger.
Use in Reporting
Strong for evidence-based reporting. Screenshots help explain findings to non-technical audiences and technical logs support deeper analysis.
What does urlscan.io do?
urlscan.io acts like a digital investigator, visiting a website so you don’t have to and recording everything it sees and does. It loads a website in a controlled environment and captures page screenshots, domains contacted, IP addresses, scripts and resources loaded, and technologies used.
The lowdown: urlscan.io is a must-have OSINT tool for safely analysing websites. Think of it as a safe remote browser ideal for safely analysing suspicious or unknown links.
How to Use:
Paste a URL into the search bar and click “Scan”.

Wait for the scan to complete (usually seconds) and explore the results via tabs (Summary, Links, DOM, etc.)

Top tip: Use filters and search to pivot into related domains or infrastructure.
You can also view our full guide in the OSINT Newsletter here.
Cost
Free for basic use. Paid for higher volume, API access, and private scans.
Data Processing
Account Required:
No for basic scans. Yes for advanced features like private scans and API use.
Cookies:
When we visited the webpage on 26.03.26, no cookies were recorded.
Use in Reporting
Urlscan.io can be useful for:
Providing visual evidence (screenshots).
Capturing technical indicators (IPs, domains, requests).
Malware analysis, phishing investigations, and attribution.
Accessing easily shareable scan links.
In real-world terms, a Reuters investigation revealed a for-hire hacking group (Bahamut) targeting individuals across regions using phishing, fake apps, and surveillance tools.
“Reuters was able to identify new targets by cross-referencing data published in BlackBerry's report with boobytrapped webpages preserved by urlscan.io.”
Capabilities
Limitations
Safe URL detonation (no direct exposure).
Some sites block automated scanners.
Full page rendering and screenshots.
Limited scans per day on the free tier.
Network traffic analysis.
Advanced features require paid access.
Domain and IP extraction.
Not fully anonymous (target site may detect scan activity).
Technology fingerprinting.
Historical scan database.
Summary
urlscan.io combines visual insight with deep technical data, making it perfect for both quick checks and detailed investigations. It’s best used in the analysis and pivoting stages of the OSINT workflow to safely inspect a URL and uncover related infrastructure and activity.
Ownership
The tool is owned by urlscan GmbH, a German cybersecurity company that provides web analysis and threat intelligence services. It was founded in 2017 by Johannes Gilger.
Ethical Considerations
Only scan URLs you are authorised to investigate.
Be aware scans may alert the target website.
Avoid scanning sensitive or personal links without justification.
Follow organisational and legal guidelines.
Related Tools:
VirusTotal
Hybrid Analysis
Sources
https://www.linkedin.com/in/johannesgilger/
https://www.crunchbase.com/person/johannes-gilger
https://www.backblaze.com/cloud-storage/case-studies/urlscan-io
Last updated
Was this helpful?