Ross ROSS = Recommend OSS · open-source software intelligence for agents

UndeadSec/EvilURL

Generate unicode domains for IDN Homograph Attack and detect them. observed · 2026-08-28

github.com/UndeadSec/EvilURL · homepage · Python · BSD-3-Clause (permissive) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 83
  • Release rhythm 8
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3227
  • days_rel: n/a
  • days_push: 107
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1267 stars · 301 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

EvilURL is a Python CLI tool that generates Unicode (IDN) domain permutations used in homograph attacks, where look-alike characters trick users into visiting spoofed domains. It can also detect potential homograph domains, check their registration availability, test connectivity, and process domain lists in bulk.

Use cases

  • generate IDN homograph attack domains for a pentest
  • detect lookalike unicode domains impersonating my brand
  • check if spoofed versions of my domain are registered or available
  • find domain permutations using confusable unicode characters
  • test which homograph domains actually resolve and connect
  • audit a list of domains for homograph spoofing risk

When to choose

  • you need to generate realistic homograph domain candidates during an authorized penetration test or red-team engagement
  • you are doing brand protection and want to find registered or available look-alike domains
  • you want a lightweight offline CLI that also checks domain availability and connectivity

When to avoid

  • you need continuous large-scale phishing detection or email gateway filtering rather than on-demand domain generation
  • you require alerting, dashboards, or integration into a defensive monitoring pipeline
  • you want a general-purpose domain name generator unrelated to spoofing or security testing

Facets

cli-tool · maturity active

security penetration-testing security penetration-testing cli python cross-platform windows idn-homograph-attack phishing unicode-domains domain-spoofing pentest brand-protection url-security domain-monitoring linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
UndeadSec/EvilURLmain10

For agents

markdown · JSON · MCP: product_card(name="UndeadSec/EvilURL")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem