SentriesAI
← SentriesAIDEEP SCAN
DEEP SCAN

Eight layers.
One verdict.

When a quick scan isn't enough. Deep scan renders the page in a real browser, catalogues its DOM, follows every redirect, and fingerprints its visual identity — all in under four seconds.

Try it freeSee the microscope ↓
THE MICROSCOPE

What you see. What we see.

A phishing page looks real to the human eye. Deep scan strips away the surface and examines six layers of structural evidence — simultaneously.

WHAT YOU SEE
brd-secure-verify.cc/login
BRD Bank
SECURE LOGIN
Verify your identity to continue
Username
Password
© 2026 BRD Bank. All rights reserved.
Looks legitimate · No obvious warning signs
WHAT WE SEESTANDBY
DEEP SCAN · brd-secure-verify.cc
01Threat intelligence
02Domain registration
03Visual rendering
04DOM structure
05Form destination
06Brand fingerprint
07Redirect chain
08Collective intelligence
LAYER 01
Threat intelligence
We cross-reference against 726,480+ known phishing URLs from URLhaus, OpenPhish, and Phishing.Database. Brand-new threats slip through blocklists — that's why we don't stop here.
LAYER 02
Domain registration
WHOIS age, email authentication records, and TLD risk scoring. Established domains earn trust; new domains pretending to be established ones do not.
LAYER 03
Visual rendering
We render the page in a headless Chromium browser with your user-agent. What the attacker wants you to see — we see too.
LAYER 04
DOM structure
We parse the page's DOM tree. Every form, input, hidden field, and external script is catalogued. Credential harvesting patterns leave structural fingerprints.
LAYER 05
Form destination
A legitimate login page submits credentials to its own domain. A phishing page ships them elsewhere. We follow the form action URL and flag mismatches immediately.
LAYER 06
Brand fingerprint
Favicon perceptual hash, color palette extraction, and layout pattern matched against our 66-brand database. We see the clone even when the text is different.
LAYER 07
Redirect chain
Every redirect is followed. Each hop is catalogued. The final URL is analyzed independently. Attackers hide the real target behind chains — we unwind them.
LAYER 08
Collective intelligence
Weighted community feedback aggregated across all SentriesAI users. Your scan strengthens everyone's protection — and theirs strengthens yours. Network effect built into the pipeline.
QUICK SCAN VS DEEP SCAN

Two tools. One pipeline.

Quick scan is instant — for everyday checks. Deep scan is thorough — for when it matters.

QUICK SCAN
Standard
DEEP SCAN
Full investigation
URLs in cached blocklist
726,480
726,480
Domain intelligence
Basic
Full WHOIS + DNS + auth
Content analysis
None
Full DOM + forms + scripts
Visual rendering
—
Headless Chromium
Brand fingerprint match
—
66 brands · pHash + palette
Redirect chain following
First hop only
Full chain (up to 10)
Scan time
< 200 ms
1-4 seconds
WHEN TO USE

When to go deep.

Four scenarios where a two-second wait pays off. Everything else — quick scan handles.

★
Anything involving money or credentials

Banking login, payment pages, crypto wallets, password resets, financial dashboards. When the stakes are high, deep scan is worth the extra two seconds.

◆
Never-seen-before domains

If the domain was registered recently or you've never visited it, the cached blocklist won't have caught it yet. Deep scan fills that gap with live structural analysis.

■
Suspicious messages from trusted contacts

A message from a friend with an unexpected link is a classic spear-phishing pattern. Deep scan on the link before clicking — even if you trust the sender.

▲
Whenever something feels off

Trust your instincts. If a page looks 'almost right' but something feels wrong, deep scan it. A two-second pause is a small price for peace of mind.

CAPABILITIES

Inside deep scan.

Full page rendering

We open the page in a real headless Chromium browser with your user-agent. JavaScript runs, dynamic content loads — we see everything.

Visual brand matching

66 brands pre-fingerprinted with favicon pHash, dominant color palette, and layout. PayPal clones on paypa1.com caught here with 95%+ confidence.

Redirect chain expansion

Short links, tracking redirects, intermediate hops — all followed up to 10 hops deep. The final destination is analyzed independently.

Form action analysis

Every form's action URL is checked. Credentials submitted to a different domain is one of the strongest phishing signals — invisible to content-only scanners.

Hidden input detection

Steganographic form fields, zero-width-space obfuscated labels, and visually hidden credential harvesters. We flag them all.

JavaScript behavior analysis

External scripts loaded, third-party domains contacted, cookie-setting behavior. Suspicious post-load behavior factored into the verdict.

Language-aware detection

Urgency patterns in Romanian, OTP harvesting phrases in Spanish, BEC keywords in German — 20+ languages, contextual rules.

Attack archetype classification

Not just 'is this phishing?' but 'what kind?' — credential harvest, crypto scam, CEO fraud, gift card, fake delivery. Context matters.

FREQUENTLY ASKED

Common questions.

Go deeper.

Pro plans include 10 deep scans per day. Max plans include 50. Free plans get unlimited quick scans.

Start freeView pricing →