Amuneth Guard

Browser protection at the exact moment risk appears.

Amuneth Guard is the browser layer for Chrome and Edge that helps users before damage occurs: when clicking, signing in, downloading, uploading and entering sensitive information. The add-on checks URL signals, brand impersonation, suspicious login forms, OAuth consent risks, downloads and data leak indicators locally.

When a page looks malicious, Guard blocks the route and shows a clear warning with score, reasons and choice: return to safety or continue deliberately. Users can report a suspicious URL themselves; optional automatic reporting for high-risk URLs can be enabled.

Protection layers

Not just phishing links, but browser behavior with context.

Guard combines multiple signals into one score, so users do not need to understand whether punycode, OAuth scopes, redirect parameters or suspicious form actions together form an attack.

URL & brand

Typosquatting, shorteners and lookalikes

Checks suspicious domains, IP URLs, @ deception, unusual ports, punycode, long parameters, shorteners and known brand impersonation.

Login & OAuth

Credential theft and consent phishing

Detects password fields, MFA code fields, cross-domain form posts, unsafe form actions and high-risk OAuth scopes such as Mail.Read and offline_access.

Data & downloads

Data leaks and malware moments

Warnings for secrets/API keys in forms, risky downloads, double extensions, HTML attachments and command snippets in clipboard flows.

How it works

From browser event to CTI overview.

1User sees risk

Guard shows a warning or block page with clear reason and score.

2Reporting

The user reports from the extension popup, or chooses automatic reporting for high-risk URLs.

3Database

The live endpoint validates JSON and writes the event to the CTI Guard table.

4Analysis

CTI shows top domains, critical reports and recent URLs for follow-up.