Threat intelligence CSIRT-led

Lookyloo

Capture websites and inspect the domains and requests involved in loading a page during web and phishing investigations.

By CIRCL and project contributors · Luxembourg

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
CIRCL and project contributors
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted / Public service
Software license
BSD-3-Clause
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

The software license credits CIRCL in Luxembourg alongside the project authors and Viper Framework. CIRCL operates the documented public instance.

Reported capabilities

  • Visualises relationships between domains involved in a capture.
  • Provides a REST API for capture workflows.

Scope and limits

Public-instance submissions follow CIRCL’s service conditions. Results support investigation and do not establish that a file or URL is safe.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    Upstream documentation describes capture websites and inspect the domains and requests involved in loading a page during web and phishing investigations. It documents local installation.

    Read source
  2. origin / country

    The software license credits CIRCL in Luxembourg alongside the project authors and Viper Framework. CIRCL operates the documented public instance.

    Read source
  3. license

    The upstream license file specifies BSD-3-Clause.

    Read source
  4. maintenance

    Repository is not archived; its last recorded push was 2026-10-09. This is an activity signal, not a support guarantee.

    Read source
  5. deployment

    CIRCL’s current service page explicitly offers public access and documents running a private instance.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

MISP Integration

Optional modules look up captured indicators in MISP and push captures as events. Both are disabled by default and require a MISP API key; publish and lookup actions require an authenticated Lookyloo user.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs