LIVE_FEED
--:--:--[HIGH]shop-***-deals.comMagecart skimmer (Group 7)// US-EAST--:--:--[HIGH]wp-***-blog.netDrive-by iframe → exploit kit// EU-WEST--:--:--[MEDIUM]cdn-***-helper.ioObfuscated cryptominer (CoinIMP)// AP-SOUTH--:--:--[HIGH]auth-***-login.coCredential phishing kit (16shop)// EU-CENTRAL--:--:--[MEDIUM]media-***-files.orgMalicious redirect chain → ClickFix// US-WEST--:--:--[HIGH]support-***-desk.comFakeUpdates / SocGholish payload// US-EAST--:--:--[LOW]track-***-pixel.appUnauthorized 3rd-party tracker// EU-NORTH--:--:--[MEDIUM]img-***-host.ruDrive-by download (TLD reputation)// EU-EAST--:--:--[HIGH]api-***-stats.xyzC2 beacon (Cobalt Strike profile)// AP-EAST--:--:--[LOW]promo-***-coupon.shopAffiliate cloaking + cookie stuff// US-CENTRAL--:--:--[HIGH]shop-***-deals.comMagecart skimmer (Group 7)// US-EAST--:--:--[HIGH]wp-***-blog.netDrive-by iframe → exploit kit// EU-WEST--:--:--[MEDIUM]cdn-***-helper.ioObfuscated cryptominer (CoinIMP)// AP-SOUTH--:--:--[HIGH]auth-***-login.coCredential phishing kit (16shop)// EU-CENTRAL--:--:--[MEDIUM]media-***-files.orgMalicious redirect chain → ClickFix// US-WEST--:--:--[HIGH]support-***-desk.comFakeUpdates / SocGholish payload// US-EAST--:--:--[LOW]track-***-pixel.appUnauthorized 3rd-party tracker// EU-NORTH--:--:--[MEDIUM]img-***-host.ruDrive-by download (TLD reputation)// EU-EAST--:--:--[HIGH]api-***-stats.xyzC2 beacon (Cobalt Strike profile)// AP-EAST--:--:--[LOW]promo-***-coupon.shopAffiliate cloaking + cookie stuff// US-CENTRAL
CLIENT_PORTAL // SCREENSHOTS

Inside the client service portal

Eight annotated views of the live ExploitShield portal — the anonymized public rollup, the per-tenant operational dashboard, and the forensic drill-down tabs your analysts use during triage.

Portal Login

Sign-in & Anonymous Platform Snapshot

Tenant-isolated login to the client portal. The right-hand panel is the public, anonymized rollup of platform-wide coverage — tracked domains, crawl runs, threat deltas, browser files, proxy bodies, observed IPs, WHOIS, VirusTotal, AV, Snort and IsMalicious counts — with no domains, URLs, paths, hashes, or tenant identifiers exposed.

Coverage Telemetry

Temporal State, Risk & Script Indicators

Temporal Crawl State shows run counts, changed comparisons, and threat changes between scans. Risk Distribution surfaces Critical-severity findings. Script Indicators ranks the most-seen JS patterns (function_constructor, https_url, http_url, src_attr, unicode_escape, location_assignment, iframe, from_char_code, long_base64) parsed out of executed page bodies. Enrichment Coverage confirms WHOIS, domain-age, VirusTotal, AV and Snort enrichment depth.

Tenant Overview

Per-Tenant Operational Counters

Authenticated view: live operational counters for the tenant's monitored domain — profiles, crawl runs, threat deltas, malware-domain reputation flags, IP intelligence, WHOIS records, browser files, IsMalicious lookups, AV scans and detections, VirusTotal, Snort IDs and PCAPs, domain age, proxy flows, body indicators, browser findings, and total corpus size.

Forensic Breakdown

Risk Distribution, Indicators, Status & WHOIS

Top Indicators chart (function_constructor dominant at 253k+) alongside HTTP status code distribution across captured responses, threat-intel provider hits (urlhaus), domain-age buckets, and WHOIS registrar breakdown (MarkMonitor, NameCheap, Gandi, Cloudflare, etc.) — enough to spot a suspiciously young or recently re-registered third-party dependency at a glance.

Detection Signals

IsMalicious, AV, VirusTotal & Snort Signals

Side-by-side cards for IsMalicious signals, per-engine antivirus hits (clamav, defender, emsisoft), VirusTotal signals, and Snort signature matches. Empty cards stay visible so an analyst can confirm a clean signal source, not just see hits.

Drill-down

Investigation Tabs — WHOIS Timeline

Top-level investigation tabs: Overview, Crawls, Diffs, Temporal, Timeline, Relationships, Evidence, Browser, Network, Bodies, VirusTotal, AV, Snort, WHOIS, Raw Files. The WHOIS timeline orders every third-party domain by creation date — fresh registrations bubble to the top so newly-introduced supply-chain dependencies are obvious.

Triage

Priority Evidence Queue

Scored evidence rows ranked by severity. Threat-intel hits (AsyncRAT, RemcosRAT, stealer, malware_download) sit at the top with source attribution; crawl-change rows quantify diffs (content +34/-34, threat +4); body-indicator rows show exactly which obfuscation patterns (function_constructor counts, base64, fromCharCode, location_assignment) fired in each captured response file.

Raw Evidence

Browser Artifacts Inventory

Every artifact captured by the instrumented headless browser per crawl: DOM snapshots, HAR network logs, resource graphs, screenshots, AV detections, browser-policy analysis, canonical network flows, cookie artifacts, deobfuscated scripts, and more — with record, domain, IP, VirusTotal, and AV hit counts per file for fast pivoting.