urlscan.io Threat Intelligence Scraper avatar

urlscan.io Threat Intelligence Scraper

Pricing

from $26.62 / 1,000 results

Go to Apify Store
urlscan.io Threat Intelligence Scraper

urlscan.io Threat Intelligence Scraper

Search the urlscan.io public scan database with Lucene queries (domain, page.url, hash, IP, ASN, tag) and export scan metadata: page URL, IP, ASN, server, TLS, screenshot, redirect chain, country, brand, verdict.

Pricing

from $26.62 / 1,000 results

Rating

0.0

(0)

Developer

ParseForge

ParseForge

Maintained by Community

Actor stats

0

Bookmarked

15

Total users

1

Monthly active users

14 hours ago

Last modified

Share

ParseForge Banner

๐Ÿ›ก๏ธ urlscan.io Threat Intelligence Scraper

๐Ÿš€ Export urlscan.io scan results in seconds. Run Lucene-style queries across the public urlscan.io scan database and pull back domain, IP, ASN, TLS, brand, verdict, and screenshot metadata. No API key, no rate-limit dance, no manual JSON parsing.

The urlscan.io Threat Intelligence Scraper queries the urlscan.io public search API with full Lucene syntax (domain:, page.url:, task.tags:phishing, page.asn:, brand.name:, verdicts.overall.malicious:true, plus AND, OR, NOT, wildcards, and date ranges) and returns one row per scan. Each row carries the page URL, apex domain, IP, ASN, server software, TLS issuer, redirect chain, country, page title, request count, brand attribution, and the malicious verdict score, plus links to the rendered screenshot and the full urlscan report.

Coverage spans the entire urlscan.io public corpus, which adds millions of new scans every week across phishing kits, brand impersonation, malware C2s, fast-flux infrastructure, and regular web pages. Every field maps directly to the upstream API so you can join scans to your own SIEM, takedown queue, or brand-protection workflow.

๐ŸŽฏ Target Audience๐Ÿ’ก Primary Use Cases
Threat intel teams, SOC analysts, brand-protection engineers, takedown vendors, anti-phishing researchers, OSINT investigatorsPhishing kit discovery, brand impersonation monitoring, IP / ASN attribution, malware infrastructure mapping, screenshot enrichment, indicator-of-compromise hunting

๐Ÿ“‹ What the urlscan.io Scraper does

Five intel workflows in one Actor:

  • ๐ŸŽฃ Phishing discovery. Pull every scan tagged phishing for a brand or apex domain.
  • ๐Ÿข Brand impersonation monitoring. Watch brand.name:<your-brand> across the global scan feed.
  • ๐ŸŒ Infrastructure attribution. Pivot on page.ip:, page.asn:, or page.server: to map hosting clusters.
  • ๐Ÿ” Redirect-chain analysis. Trace landing-page redirects and final URLs across recent scans.
  • ๐Ÿ–ผ๏ธ Visual enrichment. Every record links to a public urlscan screenshot and the full result report.

Each scan record carries scan metadata (UUID, visibility, method, time, tags), page facts (URL, domain, apex, country, IP, ASN, server, status, title, MIME), TLS context (issuer, valid days), traffic stats (unique IPs, unique countries, request count, data length), brand attribution, and the urlscan verdict (score, malicious flag, categories), plus deep links to the screenshot and report page.

๐Ÿ’ก Why it matters: brand-protection and SOC teams burn hours stitching together phishing kit pivots from raw urlscan JSON. This Actor flattens the response into a spreadsheet-ready table so triage, takedown filings, and dashboards land in one query.

๐Ÿ“Š Data fields

Each record includes: data_length, domain_age_days, page_apex_domain, page_asn, page_asn_name, page_country, page_domain, page_ip, page_language, page_mime_type, page_ptr, page_redirected, page_server, page_status, page_title, page_tlsIssuer, page_tlsValidDays, page_url, report_url, request_count, scrapedAt, screenshot, task_method, task_tags, task_time, task_url, task_visibility, unique_countries, unique_ips, uuid. All 30 field names come from a real production run, so what you see here is what lands in your dataset.

๐Ÿš€ How to use

  1. ๐Ÿ“ Sign up. Create a free account with $5 credit (takes 2 minutes).
  2. ๐ŸŒ Open the Actor. Go to the urlscan.io Threat Intelligence Scraper page on the Apify Store.
  3. ๐ŸŽฏ Set the query. Try domain:yourbrand.com AND task.tags:phishing and set maxItems.
  4. ๐Ÿš€ Run it. Click Start and let the Actor walk the search index.
  5. ๐Ÿ“ฅ Download. Grab results in the Dataset tab as CSV, Excel, JSON, or XML.

โฑ๏ธ Total time from signup to a phishing feed export: 3-5 minutes. No coding required.

๐Ÿ’ก Pro Tip: browse the complete ParseForge collection for more reference-data and intel scrapers.

โš ๏ธ Disclaimer: this Actor is an independent tool and is not affiliated with, endorsed by, or sponsored by urlscan.io GmbH or any of its partners. All trademarks mentioned are the property of their respective owners. Only publicly available scan data from the urlscan.io public search API is collected.

๐Ÿ†˜ Need Help?

If you hit a bug, have questions about setup, or need a scraper we haven't built yet, open our contact form or write to parseforge@protonmail.com. We also take on paid custom data projects.

For faster answers, join our Discord. It's the best place to get support and suggest new actors.