Skip to content

About

Local URL safety and phishing analysis with a Go API, Svelte UI, and multi-layer threat signals.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

ThreatLens

ThreatLens is a local URL safety and phishing analysis tool. It checks links for suspicious URL structure, redirects, TLS and SSL issues, DNS signals, domain age, typosquatting, brand mismatch indicators, content signals, and threat intelligence matches.

The packaged Windows build runs as a single executable:

  • UI: http://localhost:8080
  • API: http://localhost:8080/api/v1
  • Health check: http://localhost:8080/api/v1/health

Quick Start On A New Windows PC

No Docker, Go, or Node.js is required for normal use.

  1. Download or clone this repository.
  2. Open the project folder.
  3. Double-click start-all.bat.
  4. Wait for the command window to show that ThreatLens is listening.
  5. Open http://localhost:8080.

If port 8080 is already busy, the launcher automatically uses 8090 and prints the correct URL.

What To Run

Start Full App

Double-click:

start-all.bat

This starts the embedded UI and API from:

server/safesurf.exe

Start Backend/UI Manually

cd server
$env:PORT="8080"
$env:CACHE_DISABLED="1"
.\safesurf.exe

Then open:

http://localhost:8080

Verify Backend

curl http://localhost:8080/api/v1/health

Expected:

{"status":"ok"}

Note: http://localhost:8080/api/v1 by itself returns not found. Use /api/v1/health or /api/v1/analyze.

Scan API Example

curl "http://localhost:8080/api/v1/analyze?url=https%3A%2F%2Fexample.com"

Project Layout

server/                 Go backend and packaged executable
server/safesurf.exe     Single executable serving UI + API
web/website/            Svelte frontend source
docs/                   Documentation
start-all.bat           One-click app launcher
start-backend.bat       Backend/UI launcher
build-single-exe.bat    Rebuilds frontend and embeds it into safesurf.exe

Rebuilding The Single EXE

Only needed if you change source code.

Install:

  • Go 1.24 or newer
  • Node.js with npm

Then run:

build-single-exe.bat

That command:

  1. Builds the Svelte frontend.
  2. Writes static files into server/internal/web/dist.
  3. Rebuilds server/safesurf.exe with the frontend embedded.

Development Mode

Frontend dev server:

cd web/website
npm install
npm run dev -- --host 0.0.0.0

Backend from source:

cd server
$env:PORT="8080"
$env:CACHE_DISABLED="1"
go run ./cmd/safesurf

For normal users, prefer start-all.bat.

Features

  • URL structure and suspicious pattern checks
  • Redirect chain analysis
  • TLS and SSL certificate inspection
  • Domain age and registration information
  • Typosquatting and homoglyph checks
  • Page content and form analysis
  • Threat intelligence lookup
  • Clear verdict, trust score, and detailed evidence

Troubleshooting

If the page is blank:

  1. Close any old ThreatLens/SafeSurf command windows.
  2. Run start-all.bat again.
  3. Open the URL printed in the terminal.

If 8080 is busy:

  • The launcher will try 8090.
  • Open the URL shown in the command window.

If Windows blocks the executable:

  1. Right-click server/safesurf.exe.
  2. Open Properties.
  3. Click Unblock if shown.
  4. Run start-all.bat again.

About

Local URL safety and phishing analysis with a Go API, Svelte UI, and multi-layer threat signals.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages