An interactive, terminal-based built with Python and the VirusTotal API to scan, analyze, and track URL security health metrics in real time.
Project Nexus Suite: LinkLookout is an official sub-project developed and maintained under the Project Nexus
# Clone the repository and navigate into it
cd link-lookout
# (Optional) Create a virtual environment
python -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
# Install dependencies
pip install -r requirements.txt
# Create your configuration environment file
# (On Windows, manually create a file named .env and add your API key in the same folder as Link_Lookout.py)
echo "API_Key=your_virustotal_api_key_here" > .env
# Run the scanner engine
python Link_Lookout.py-
Link_Lookout.py – Core application engine containing the custom terminal user interface (TUI), API orchestration, data parsing logic, and exception handlers.
-
requirements.txt – List of external Python package dependencies required to run the tool.
-
.env – Local security file storing the confidential VirusTotal API integration key (must be generated by the user).
-
LinkLookout (Operation: Scanning Horizon) is a lightweight open-source command-line utility designed to provide security analysts with instant forensic snapshots of suspicious URLs. By interacting natively with the VirusTotal V3 API backend via asynchronous client hooks, the utility automates multi-engine reputation auditing, redirection mapping, and domain tracking inside a sleek, color-coded ANSI terminal layer.
-
Multi-Engine Aggregation: Aggregates, parses, and formats real-time diagnostic results from over 70 security vendors into strict classification metrics (Malicious, Suspicious, Phishing, Spam, and Clean).
-
Deep Redirection Diagnostics: Traces network routing logic to track hidden path hops, calculating exact hop quantities while visually map-printing the ultimate target domain destination.
-
Infrastructure Attribution: Directly extracts metadata configurations tied to the requested URL, including hosting server location endpoints (last_serving_ip_address) and page document headers.
-
Historical Auditing & Tracking: Exposes long-term domain operational metadata by formatting Unix epoch intervals into legible database tracking history, revealing submission velocities and primary discovery flags.