Pivot map
Pivot from here
Outputs from URL Risk Analysis can become inputs for the next tool. These are the most relevant follow-on pivots in the library.
A global, open, stable, and secure Internet that serves the entire Asia Pacific community
ARIN is a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the Internet.
AbuseIPDB provides IP reputation data and community abuse reports for identifying malicious hosts in network and threat investigations.
AccountKiller provides direct deletion links and step-by-step instructions for removing accounts on hundreds of websites and social platforms.
Investigator Use
Zulu URL Risk Analyzer (zulu.zscaler.com) is a free URL analysis and risk scoring service operated by Zscaler, a leading cloud security company. For security analysts, threat intelligence researchers, and OSINT investigators evaluating the safety and reputation of URLs, Zulu provides automated risk assessment backed by Zscaler's extensive threat intelligence infrastructure.
Zulu analyzes submitted URLs across multiple dimensions: the hosting domain's reputation history, content category (what type of site it is), security policy violations detected in page content, associated IP address reputation, SSL certificate validity, and whether the URL or domain appears in Zscaler's threat intelligence feeds. The result is a risk score from 0 to 100 with detailed breakdowns by risk factor.
The content categorization is particularly useful for OSINT: Zulu classifies pages into categories (news, social media, adult content, gambling, phishing, malware, command-and-control, etc.), providing immediate context about a URL's purpose even before examining the page directly. A URL categorized as "command-and-control" or "phishing" by Zscaler's systems has almost certainly been confirmed malicious by prior investigation.
For incident responders triaging suspicious URLs from phishing reports or SIEM alerts, Zulu provides a rapid first-pass assessment. A high risk score indicates immediate follow-up is warranted, while a low score with a legitimate category may deprioritize the URL in a queue of events awaiting analysis.
Zscaler's threat intelligence reflects real-world telemetry from millions of enterprise users passing traffic through Zscaler's cloud proxy — giving the risk scoring substantial data backing compared to smaller intelligence providers. This breadth of telemetry makes Zulu particularly reliable for identifying known bad infrastructure.
Limitations include time lag for new threats — domains registered recently for a specific phishing campaign may not yet have accumulated sufficient reputation data for accurate scoring. Always supplement Zulu analysis with URLScan.io, VirusTotal, and manual page inspection for complete assessment.
Document the analyzed URL, risk score, category classification, and scan date in security incident records.
Before You Pivot
Capture the target, search terms, and why this source is relevant before you leave the page.
Archive volatile pages, save screenshots, and keep timestamps for anything that may change.
Treat one tool as a lead source. Confirm important findings with independent sources.
Related tools
ArchiveBox is self-hosted open-source web archiving for preserving websites, social posts, and online evidence for investigations.
Web technology information profiler tool. Find out what a website is built with.
CheckShortURL expands shortened URLs to reveal the final destination before clicking, supporting safe analysis of potentially malicious links.
Cutestat provides website analytics including traffic estimates, Alexa rank, server details, WHOIS data, and SEO metrics for any domain.
Down For Everyone Or Just Me confirms whether a website is globally offline or unavailable locally during OSINT investigations.
Photon is a fast OSINT crawler extracting URLs, emails, files, subdomains, and metadata from any target website for investigators.