cerbia.core.scanners.MaliciousUrlScanner applies local URL heuristics to extracted links. It is designed to identify suspicious structures such as risky domains, shorteners, and lookalike patterns before a user or downstream system uses the URL.
| Parameter | Default | Meaning |
|---|---|---|
|
built-in set |
Optional replacement list of top-level domains to flag. |
|
built-in set |
Optional replacement list of URL shorteners. |
|
built-in set |
Optional replacement domains used for lookalike detection. |
|
|
Finding severity. |
|
|
Finding action. |
|
|
Accepted content types. |
The scanner extracts supported URL forms, evaluates its heuristics, and returns the highest observed risk with a rationale describing the detected signals. It returns risk 0.0 when no URL is found or no heuristic is triggered.
The replacement lists are complete replacements for the corresponding built-in heuristic data. Use them when the deployment has a known set of trusted popular domains, approved shorteners, or organization-specific risky top-level domains; do not assume an omitted default list is added automatically.
scanners:
- scanner: cerbia.core.scanners.MaliciousUrlScanner
init_args:
suspicious_tlds: ["top", "loan", "win"]
Use URL allowlist when known destinations should be explicitly approved rather than scored heuristically.