ShadowTrackr

Log in >
RSS feed

Updated GUI and phishy urls

05 May 2025
Two big items in this update. The first is the updated GUI. The goal was improved clarity and usability. Contrast has improved, icons and badges were added, asset pages have sticky headers, and things generally look smoother.

The second one are the phishy urls. There was a bug in there that kept detecting a phishy url as new if it was a permutation of two of your assets. Only one could be registered. That is fixed now, and the code had a major review. Phishy urls that redirect to the original url or one of your other assets are now clearly labeled. Babydomains are also clearly labeled if detected, as are reserved domains and redirects to marketing sites.

You can directly add a phishy_url to your assets if you bought it (from the action menu in the right top), and it's even possible to add your own phishy_urls that you want ShadowTrackr to monitor for you. Most should be detected by our algorithm, but some language specific urls (singulars/plurals) can be hard to generate.

Improved defacement detection

14 April 2025
The first version of defacement detection didn't detect everything it should. The next version was a bit to trigger happy, but the third one that is rolled out now is much better. Alerts will appear on your timeline.

I'll let it run for a while and then put proper alerts in the alert library. I'm also thinking of creating a defacement and changes report that shows all websites with major changes and possible indications of defacement.

Again, more software detection rules

07 April 2025
The current update fixes some bugs and adds more software detection rules. Some are additions to existing rules, but most are detection rules for software appearing as HTTP(S) on odd ports. Since the odd HTTP(S) ports were added we found quite some new stuff to detect.

A significant update is that phishy urls that redirect to one of your assets are now also scored as no risk (0). Previously this was only the case for redirects to the original domain.
Older posts >

Resources
API
Blog
Documentation
Integrations
Shodan
OpenCTI