# Domain Exploits Detector (ExploitShield) > Continuous detection of malware, skimmers, and exploit kits hosted on or injected into web domains. Real-browser scans every 5 minutes with email and webhook alerting. ExploitShield (Domain Exploits Detector) monitors domains for client-side threats — Magecart skimmers, drive-by downloads, fake-CAPTCHA / ClickFix lures, cryptominers, credential phishing kits, C2 beacons, and unauthorized third-party trackers. Detections come from a fully instrumented headless Chromium pipeline that survives anti-analysis checks, not from passive signature matching. ## Pages - [Home](/): Product overview and free domain scan. - [Features](/features): Detection capabilities and pipeline details. - [How it works](/how-it-works): Scan architecture, cadence, and alerting. - [Pricing](/pricing): Plans for individual domains, agencies, and enterprises. - [Security](/security): Data handling, isolation, and operational security. - [FAQ](/faq): Common questions about scans, coverage, and integration. - [Contact](/contact): Sales, demos, and support. - [Status](/status): Live service status. - [Sample alert](/sample-alert): Example of a real detection alert. - [Screenshots](/screenshots): Portal screenshots and telemetry views. - [Free Scan](/scan): Free real-browser malware scan for any domain. - [Compare](/compare): ExploitShield vs Sucuri, SiteLock, Quttera. - [Glossary](/glossary): Web threat glossary (Magecart, ClickFix, skimmers, exploit kits). - [Resources](/resources): Guides and reference material. ## Guides (pillar pages) - [Client-side security](/client-side-security): The browser-side attack surface WAFs can't see, and how to defend it. - [Malware domain blocklist](/malware-domain-blocklist): What a malware domain blocklist is and how 500+ sources are merged hourly. ## Blog - [Detecting Magecart skimmers in 2026](/blog/magecart-skimmer-detection-2026): What changed after Group 12 and how to catch service-worker skimmers. - [Anatomy of a fake CAPTCHA → ClickFix lure](/blog/fake-captcha-clickfix-anatomy): MITM transcript of a real social-engineering chain. - [Why we settled on a 5-minute scan interval](/blog/five-minute-scan-interval-why): The math behind detection latency vs crawler footprint. - [Formjacking explained](/blog/formjacking-explained): How attackers steal card data from checkout pages without breaching your server. - [Web skimming in 2026](/blog/web-skimming-2026-defenders-guide): A complete defender's guide to Magecart, formjacking, and service-worker skimmers. - [Client-side security: the attack surface your WAF can't see](/blog/client-side-security-attack-surface): Why client-side security is its own discipline. - [What is a malware domain blocklist](/blog/malware-domain-blocklist-explained): How 500+ threat-intel sources are merged at every scan. ## Optional - [Privacy](/privacy): Privacy policy.