urlscan.io Threat Intelligence Scraper
Pricing
from $26.62 / 1,000 results
urlscan.io Threat Intelligence Scraper
Search the urlscan.io public scan database with Lucene queries (domain, page.url, hash, IP, ASN, tag) and export scan metadata: page URL, IP, ASN, server, TLS, screenshot, redirect chain, country, brand, verdict.
Pricing
from $26.62 / 1,000 results
Rating
0.0
(0)
Developer
ParseForge
Maintained by CommunityActor stats
0
Bookmarked
15
Total users
1
Monthly active users
14 hours ago
Last modified
Categories
Share

๐ก๏ธ urlscan.io Threat Intelligence Scraper
๐ Export urlscan.io scan results in seconds. Run Lucene-style queries across the public urlscan.io scan database and pull back domain, IP, ASN, TLS, brand, verdict, and screenshot metadata. No API key, no rate-limit dance, no manual JSON parsing.
The urlscan.io Threat Intelligence Scraper queries the urlscan.io public search API with full Lucene syntax (domain:, page.url:, task.tags:phishing, page.asn:, brand.name:, verdicts.overall.malicious:true, plus AND, OR, NOT, wildcards, and date ranges) and returns one row per scan. Each row carries the page URL, apex domain, IP, ASN, server software, TLS issuer, redirect chain, country, page title, request count, brand attribution, and the malicious verdict score, plus links to the rendered screenshot and the full urlscan report.
Coverage spans the entire urlscan.io public corpus, which adds millions of new scans every week across phishing kits, brand impersonation, malware C2s, fast-flux infrastructure, and regular web pages. Every field maps directly to the upstream API so you can join scans to your own SIEM, takedown queue, or brand-protection workflow.
| ๐ฏ Target Audience | ๐ก Primary Use Cases |
|---|---|
| Threat intel teams, SOC analysts, brand-protection engineers, takedown vendors, anti-phishing researchers, OSINT investigators | Phishing kit discovery, brand impersonation monitoring, IP / ASN attribution, malware infrastructure mapping, screenshot enrichment, indicator-of-compromise hunting |
๐ What the urlscan.io Scraper does
Five intel workflows in one Actor:
- ๐ฃ Phishing discovery. Pull every scan tagged
phishingfor a brand or apex domain. - ๐ข Brand impersonation monitoring. Watch
brand.name:<your-brand>across the global scan feed. - ๐ Infrastructure attribution. Pivot on
page.ip:,page.asn:, orpage.server:to map hosting clusters. - ๐ Redirect-chain analysis. Trace landing-page redirects and final URLs across recent scans.
- ๐ผ๏ธ Visual enrichment. Every record links to a public urlscan screenshot and the full result report.
Each scan record carries scan metadata (UUID, visibility, method, time, tags), page facts (URL, domain, apex, country, IP, ASN, server, status, title, MIME), TLS context (issuer, valid days), traffic stats (unique IPs, unique countries, request count, data length), brand attribution, and the urlscan verdict (score, malicious flag, categories), plus deep links to the screenshot and report page.
๐ก Why it matters: brand-protection and SOC teams burn hours stitching together phishing kit pivots from raw urlscan JSON. This Actor flattens the response into a spreadsheet-ready table so triage, takedown filings, and dashboards land in one query.
๐ Data fields
Each record includes: data_length, domain_age_days, page_apex_domain, page_asn, page_asn_name, page_country, page_domain, page_ip, page_language, page_mime_type, page_ptr, page_redirected, page_server, page_status, page_title, page_tlsIssuer, page_tlsValidDays, page_url, report_url, request_count, scrapedAt, screenshot, task_method, task_tags, task_time, task_url, task_visibility, unique_countries, unique_ips, uuid. All 30 field names come from a real production run, so what you see here is what lands in your dataset.
๐ How to use
- ๐ Sign up. Create a free account with $5 credit (takes 2 minutes).
- ๐ Open the Actor. Go to the urlscan.io Threat Intelligence Scraper page on the Apify Store.
- ๐ฏ Set the query. Try
domain:yourbrand.com AND task.tags:phishingand setmaxItems. - ๐ Run it. Click Start and let the Actor walk the search index.
- ๐ฅ Download. Grab results in the Dataset tab as CSV, Excel, JSON, or XML.
โฑ๏ธ Total time from signup to a phishing feed export: 3-5 minutes. No coding required.
๐ Recommended Actors
- ๐ RDAP Domain Lookup Scraper - Modern WHOIS replacement via the RDAP protocol
- ๐ข GSA eLibrary Scraper - U.S. federal contract vendor and price data
- ๐๏ธ Hubspot Marketplace Scraper - Marketplace app and integration catalog
- ๐ฐ PR Newswire Scraper - Press release feed with publish dates
- ๐ค Hugging Face Model Scraper - AI model registry metadata
๐ก Pro Tip: browse the complete ParseForge collection for more reference-data and intel scrapers.
โ ๏ธ Disclaimer: this Actor is an independent tool and is not affiliated with, endorsed by, or sponsored by urlscan.io GmbH or any of its partners. All trademarks mentioned are the property of their respective owners. Only publicly available scan data from the urlscan.io public search API is collected.
๐ Need Help?
If you hit a bug, have questions about setup, or need a scraper we haven't built yet, open our contact form or write to parseforge@protonmail.com. We also take on paid custom data projects.
For faster answers, join our Discord. It's the best place to get support and suggest new actors.