Once the agent finishes, the structured report appears here.
Cloud URLs (Azure tenants, S3 buckets, SharePoint, Workers, Vercel, Heroku, etc.) are auto-detected and correlated — traditional reputation feeds miss these.
Example IOCs
Paste the raw email (use "Show Original" in Gmail or "View Source" in Outlook). ThreatLens extracts every IP, domain, URL, and sender identity, then runs the full agent investigation on each.
Starting…
Agent Activity
idleEnter an IOC to begin. The agent's reasoning will appear here in real time.
Investigation Report
Next Actions
Recent Investigations
- No investigations yet.