July 21st, 2026 — Agentic URL Scanning 2.0 Integration, Target Technology Watchlists, and Sharper Domain Reputation

🤖 Agentic URL Scanning 2.0 Integration

Agentic now leverages VirusTotal's sandboxed browser execution to analyze suspicious URLs dynamically.

Capabilities:

  • Runtime Telemetry: Captures dynamic DOM modifications, network requests, and global JavaScript variables.
  • Campaign Mapping: Fingerprints phishing kits (e.g. pivoting on __jwrAuth variables) to map related threat infrastructure.

URLs that are not in the public corpus of Google Threat Intelligence are analyzed privately using Private Scanning.

Example Prompt: "Investigate https://t-mobile.zyhqxp.top/pay/ and find other URLs from the same campaign using its JS footprint. Then create a campaign collection."
View this conversation in Agentic →

🛡️ Public Preview: Target Technology Watchlists

Target Technology Watchlists are now in Public Preview for GTI customers. This capability allows you to easily track relevant intelligence based on your specific technology stack, driving focus to the threats that truly matter most.

Key Benefits:

  • Flexible Inputs: Simply drop a list of technologies or CPEs into your threat scenario to immediately get vulnerability intelligence alerts through the alert section in the org profile.
  • Customizable Alerts:Receive notifications specifically for CVEs affecting the organization's tech stack.
  • Rich Vulnerability Details: Every alert is enriched with full exploit context, including assigned priority, vulnerability Risk Rating, real-world Exploitation State, and more.
  • Intelligence Context: Leverage direct integration with GTI vulnerability intelligence for full exploit context.
  • Unified View & API Access: Access a unified alerts stream, fully available via API for programmatic and agentic workflows.

For more information, please refer to the documentation on Threat Scenarios, Organization Profiles, and Alerts.

🌐 Sharper Domain Reputation (Mitigating Expired Domain Abuse)

Threat actors frequently purchase abandoned, previously popular domains to host malware C2 servers or DGA infrastructure, a tactic known as expired domain abuse. This is a known technique used to bypass security scanners by exploiting the domain's artificially high historical popularity.

To counter this, we have further enhanced our behavior-based detection for C2 and DGA domains to more strictly discount obsolete popularity metrics. This ensures that a domain's historical fame can no longer shield it from accurate threat scoring, effectively neutralizing this evasion tactic.