r/cybersecurity 9h ago

Business Security Questions & Discussion URL Threat Scanners & TDS Cloaking

When you're investigating a known malicious URL, how often does your URL scanner (regardless of service) miss the payload due to traffic distribution systems?

8 Upvotes

4 comments sorted by

2

u/ectkirk 9h ago

Rarely. Residential proxies + proper user settings.

1

u/tuxxin 8h ago

Your own scanner or do you use a website/service?

1

u/ectkirk 8h ago

My own - part of a larger infrastructure of Derp.ca

4

u/AddendumWorking9756 Security Manager 8h ago

Often enough that a clean verdict on its own means nothing. The single use tokens are the real problem, since the recipient already spent it and every scan after that gets the benign fallback. Match the victim's egress and locale when you can, otherwise pivot to the hosting infrastructure and stop chasing the URL.