MISP Integration
Optional modules look up captured indicators in MISP and push captures as events. Both are disabled by default and require a MISP API key; publish and lookup actions require an authenticated Lookyloo user.
An independent tool index
for incident response teams
Threat intelligence CSIRT-led
Capture websites and inspect the domains and requests involved in loading a page during web and phishing investigations.
By CIRCL and project contributors · Luxembourg
Primary sources connect this project to an EU CSIRT as developer or lead.
The software license credits CIRCL in Luxembourg alongside the project authors and Viper Framework. CIRCL operates the documented public instance.
Public-instance submissions follow CIRCL’s service conditions. Results support investigation and do not establish that a file or URL is safe.
identity / capabilities / deployment
Upstream documentation describes capture websites and inspect the domains and requests involved in loading a page during web and phishing investigations. It documents local installation.
Read sourceorigin / country
The software license credits CIRCL in Luxembourg alongside the project authors and Viper Framework. CIRCL operates the documented public instance.
Read sourcelicense
The upstream license file specifies BSD-3-Clause.
Read sourcemaintenance
Repository is not archived; its last recorded push was 2026-10-09. This is an activity signal, not a support guarantee.
Read sourcedeployment
CIRCL’s current service page explicitly offers public access and documents running a private instance.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Optional modules look up captured indicators in MISP and push captures as events. Both are disabled by default and require a MISP API key; publish and lookup actions require an authenticated Lookyloo user.
Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.
A threat intelligence workflow for CSIRTs