Built for Nigerian banking & fintech realities β BVN/NIN lures, bank-clone domains, OTP/USSD scams β with explainable, SOC-ready outcomes.
Speed for analysts, autonomy for discovery. Minimal clicks, maximum clarity. Everything else is here β but secondary.
AI-powered phishing detection tuned to Nigeriaβs banking & fintech landscape.
We analyze domain, content, link-graph, and live behavior signals with localized feature engineering for Nigeria β including BVN/NIN prompts, bank-clone lexicons, .ng/domain tricks, USSD/OTP baits, and local payment/wallet flows.
Hunter uses safe headless browsing to discover, test, and score live suspect links from Nigerian-tuned seeds and learned patterns.
| Time | URL | Source | Risk | Verdict |
|---|---|---|---|---|
| No data loaded yet. | ||||
GET /hunter/status, POST /hunter/start, POST /hunter/stop, GET /hunter/discoveries?limit=50.Threat actors adapt to Nigerian banks, telcos, and wallets. Our features reflect those patterns.
Verdicts grouped across domain, content, links, and behavior β analysts can audit the βwhyβ.
Zero URL storage by default, in-memory processing, self-hostable enterprise mode.
Heuristics + ML + LLM rationale + live browser simulation.
Forward outcomes and evidence to SIEM; export redirect chains & interactions.
Built to align with Nigerian financial-sector realities and oversight needs.
1) Signal Collection
Domain (.ng nuances), content (BVN/NIN/OTP/USSD), link graph (bank variants), and live behavior signals.
2) Behavioral Simulation
Headless browser follows redirects, detects timers/popups/consent, records OTP/USSD prompts.
3) Hybrid Fusion
Heuristics + ML + LLM-assisted rationale tuned to Nigerian patterns.
4) Explainable Output
Verdict + grouped reasons + evidence, ready for SOC review.
Redirects, timers, popups, consent, OTP/USSD prompts β captured and analyzed.
Grouped reasons across domain, content, links, and behavior β SOC-friendly.
BVN/NIN lure detection, bank-clone signatures, .ng TLD misuse, local spellings & wallets.
Heuristics + ML + LLM rationale to boost accuracy and reduce false positives.
Zero URL storage by default. In-memory processing. Enterprise retention controls.
Deploy across your environment β and centralize visibility.
Export redirect chains, OTP/USSD prompts, consent clicks, and grouped reasons.
Ephemeral by default. Configurable retention in enterprise/self-hosted deployments.
Evaluation, drift checks, safe defaults, and change control β designed for SOC workflows in regulated environments.
Send a URL for analysis. Optional quick=1 for faster heuristics.
POST https://checkthaturl.com/check?ui=redacted
Content-Type: application/json
{"url":"https://bankname.ng/secure-login"}
Response (truncated):
{
"verdict": "Phishing",
"risk": 0.86,
"explanation": "BVN/OTP lure + suspicious .ng subdomain + redirect maze",
"domain_risks": [...],
"behavior": { "redirect_chain": [...], "clicks": 2 }
}
$0
$49 / seat / mo
Custom
Final pricing depends on usage, deployment model, and compliance needs.
Free POV for banks/fintechs/telcos: Email Scanner, Browser Extensions, API, SIEM integrations.