How Saber Works
Saber combines static analysis, JavaScript rendering, reputation databases, and AI to deliver a confident risk verdict on any URL — in seconds
The Scanning Process
Every scan follows the same multi-layer pipeline. Each stage builds on the previous one, so the final verdict is grounded in evidence from multiple independent sources.
Submit
Paste a URL or IP address — or scan a QR code with your camera or by uploading an image. Saber extracts the link and runs the appropriate scan automatically.
Reputation Check
Multiple community threat-intelligence feeds and domain blocklists are checked simultaneously. Highly-trusted domains receive an instant safe verdict based on global traffic rankings. Domain registration age and registrar reputation are also evaluated.
Page Fetch
Saber retrieves the live page using a stealth browser with realistic fingerprints that bypass bot-detection. Scroll and mouse simulation reveals forms that only appear after user interaction. For image-locked pages, OCR extracts visible text in 18 languages. JavaScript hooks capture credential exfiltration attempts, keylogger behavior, and clipboard reads at the browser level.
Signal Analysis
Dozens of signals are evaluated across domain structure, TLS certificate, page content, redirect behavior, and brand patterns. Every scan is matched against a cross-scan database of confirmed phishing kit structural fingerprints and favicon hashes — when any new domain deploys the same page template as a known phishing kit, it is flagged instantly without an AI call. ICO/presale fraud vocabulary, raw crypto payment addresses, and behavioral exfiltration hooks are also evaluated.
AI Verdict
A frontier AI model reviews the complete evidence chain — domain signals, content patterns, behavioral hooks, redirect behavior, and reputation data — and reasons from first principles to a structured verdict and threat classification. Automatic cross-provider failover ensures every scan receives an AI verdict.
What We Analyze
Saber evaluates signals across six categories. No single signal is conclusive — the risk verdict reflects the weight of evidence across all of them.
Domain & Infrastructure
- Domain registration age and history
- TLS certificate validity and issuer
- DNS configuration and nameservers
- Hosting provider reputation (abused ASN detection)
- Subdomain structure and impersonation patterns
- Top-level domain risk classification
Content & Brand Analysis
- Credential harvesting form detection
- Brand impersonation and trust-borrowing indicators
- Deceptive language, urgency, and prize-scam patterns
- Wallet drainer and seed phrase harvesting detection
- Government ID collection and fake KYC detection
- Banking brand impersonation on free hosting platforms
Redirect & Network Behavior
- Redirect chain length and destinations
- Final landing URL verification
- Cross-domain navigation patterns
- Network-level evasion techniques
- Bot-challenge and CAPTCHA interception detection
Reputation Databases
- Multiple community-maintained phishing and malware feed databases
- Google Web Risk (MALWARE, SOCIAL_ENGINEERING, UNWANTED_SOFTWARE)
- WHOIS / RDAP registrant and domain age data
- Certificate Transparency log history (domain establishment signals)
- Tranco top-1M global domain trust ranking
- Cross-scan phishing kit structural fingerprints and favicon hash database
JavaScript Rendering
- Full browser-level page execution with stealth fingerprint randomisation
- Scroll and mouse simulation to reveal interaction-gated forms
- OCR text extraction for image-locked content in 18 languages
- XHR and fetch hook monitoring for credential exfiltration to Telegram, Discord, and webhooks
- Keylogger and clipboard read behavioral hook detection
TLS & Certificate Signals
- Certificate authority and trust level classification
- Common name and subject validation
- Certificate Transparency log history (domain establishment signals)
- Wildcard and SAN coverage analysis
- Certificate mismatch detection
Built Where the Threats Are
Purpose-BuiltPhishing intelligence engineered for the modern threat landscape — both in the message you submit and in the page content it analyzes.
Reads the Message, Not Just the Link
Paste any SMS, WhatsApp message, or email and Saber reads it natively — detecting urgency language, impersonation patterns, and scam phrasing written in Arabic, not inferred through translation.
Goes Beyond the URL
Saber analyzes the full content of the destination page — headings, form labels, call-to-action buttons — identifying brand impersonation and deceptive language directly, without a translation step.
Verdicts Delivered in Your Language
The AI verdict and threat explanation are delivered in the same language as the content you scan. Clear, actionable context — never a machine-translated afterthought.
Multi-Model AI Verdict Layer
After all signals are collected, a frontier AI model reasons over the complete evidence chain and issues a structured verdict with threat classification and a plain-language explanation — available in English and Arabic. Saber runs a fleet of models with automatic cross-provider failover, so every scan receives an AI verdict.
Evidence-based chain-of-thought
The AI reads every collected signal — domain behavior, content structure, brand claims, redirect chain, and JavaScript hooks — and reasons from the evidence to a verdict and threat classification. No hardcoded pattern lists: the model builds its case from the actual evidence, catching zero-day campaigns that don't yet appear in any blocklist.
Multi-model fleet with automatic failover
Saber runs on a configurable fleet of frontier AI models. If the primary provider is unavailable, automatic cross-provider failover kicks in so every scan receives an AI verdict — no manual intervention required.
Bilingual explanations
AI explanations are available in both English and Arabic. When the scanned page or submitted message is in Arabic, the verdict context is delivered in Arabic — not a machine-translated afterthought.
Risk Levels
Every scan produces one of four verdicts. When the evidence is ambiguous, Saber errs on the side of caution.
No significant threat indicators were found. The domain, content, and behavior all appear consistent with a legitimate site.
One or more signals warrant caution. The site may be legitimate, but we recommend not submitting credentials or sensitive information.
The page was bot-blocked or too obfuscated to evaluate clearly. There is not enough observable evidence to confirm safety — treat the link with caution.
The scanner could not reach the page at all — it may be offline, blocking all automated access, or restricted to a specific network or region.
Strong evidence of an active attack. Saber identifies five specific threat types: phishing, wallet drainers, malware downloads, fake KYC identity theft, and banking SPA impersonation. Do not proceed.
Built for Trust
Every scan generates a shareable public report with a permanent URL. Security researchers, IT teams, and individuals can document and share threat findings — no account required to view a report.
Shareable public reports
Every scan generates a permanent public report URL you can share with anyone — no account needed to view it.
Independent signal sources
Saber cross-references multiple independent data sources so no single compromised or outdated feed can skew the verdict.
Community-reinforced detection
Once a phishing kit is confirmed, its structural fingerprint and favicon hash are stored. Every future deployment of the same template — on any domain — is flagged instantly without an AI call.