What URL forensics is
URL forensics examines a link itself and the infrastructure behind it: how the URL is constructed, where it leads, which domain really controls it and how old that domain is. It is used for phishing triage, scam investigations and incident response.
The workflow
1. Parse the URL and identify the real hostname and registrable domain. 2. Decode Punycode and encoded parameters. 3. Follow redirects in a controlled way and record each hop. 4. Run domain forensics on every domain in the chain, including the creation date. 5. Identify hosting and certificates. 6. Preserve the evidence with a hash.
Common traps
Brand names in subdomains or paths, user-info tricks with @, shortened links and open redirects on trusted sites all disguise the true destination. The controlling registrable domain and its registration date usually cut through the disguise.
- Identify the registrable domain.
- Record every redirect hop.
- Check the creation date of each domain.
- Never enter credentials or pay to test a link.
