Selected work

Chapter 03 / Threat intelligence

SentinelScope.

URL reputation checks through a familiar interface.

Status

Prototype

My role

Personal security tool

View source on GitHub

The idea

A Python Telegram bot that brings VirusTotal reputation signals into a simple chat workflow.

Python / Telegram / VirusTotal / FastAPI

Animated architecture

The journey of a URL check

External boundaries are explicit: Telegram transports messages and VirusTotal receives submitted URLs.

01 / Ask in chat

02 / Admit the request

03 / Record and submit

04 / Retrieve reputation

05 / Explain the result

Control flow / Decisions & data

From a chat message to reputation evidence

The command and phrase handlers converge on one URL scan path. Telegram carries the request; VirusTotal supplies the reputation data.

Decision branchesSolid arrows show routing and return paths.

Scroll across the diagram to follow each branch

From a chat message to reputation evidenceThe command and phrase handlers converge on one URL scan path. Telegram carries the request; VirusTotal supplies the reputation data. A text explanation follows the diagram.NoYesInvalidValid/scan_url commandTelegram message + user IDScan / check phraseText handler → same scan functionWithin user rate limit?In-memory request allowanceAsk the user to waitStop this requestNormalize and validate URLBasic format, not a safety verdictExplain invalid inputRequest a usable URLSubmit to VirusTotalAPI v3 URL submissionRetrieve reputation reportRead available detection statisticsExternal service boundaryAvailability, quota, report readinessFormat the Telegram replyReputation signals for human reviewActivity recordLocal audit log

Reading the flow

  1. Both entry points use the same scan handler; inline queries are not a separate working scan engine.
  2. The per-user rate limit is stored in memory. Restarting the process loses that state, and multiple instances would need a shared limit store.
  3. URL submission and report retrieval cross into VirusTotal. A report may be unavailable or incomplete; error handling and synchronous requests remain hardening work.
  4. A low detection count is not a guarantee of safety. The reply supports a triage decision, while local activity records can contain submitted URLs and user identifiers.

The starting point

Why this project?

A suspicious link often arrives in a conversation. SentinelScope explores making a first reputation check accessible through a messaging interface, with enough detail to support a human triage decision.

My contribution

The work I brought to it.

I built a Telegram-based security helper around URL reputation checks. The repository brings together command handling, simple natural-language scan triggers, VirusTotal requests, per-user rate limiting, and activity logging.

How it works

From input to output.

The /scan_url command normalizes a submitted URL, checks basic input structure, and calls VirusTotal API v3. It retrieves reputation statistics and returns the result to Telegram. Simple scan/check phrases reach the same handler. Requests are rate limited in memory and written to a local audit log. A separate FastAPI entry point configures a Telegram webhook.

  1. URL in Telegram
  2. Validate + rate limit
  3. VirusTotal lookup
  4. Reputation response

A design decision

Put a useful signal where the conversation happens.

Telegram reduces the steps needed to request a reputation lookup. The tradeoff is dependency on Telegram and VirusTotal, including their availability and quotas. A reputation result is one input to investigation: no detections does not make a URL safe, especially when a threat is new.

The evidence

Look under the surface.

These links point to the reviewed source revision, so the implementation behind this story stays inspectable.

Current boundaries

Useful work. Honest limits.

  • The source implements scanning; a currently running public bot has not been verified.
  • The inline-query path only prepares a message. It does not perform a full reputation scan.
  • Synchronous HTTP calls, an in-memory rate limit, and incomplete error handling need hardening.
  • Submitted URLs reach external services, and logs can contain user identifiers and URLs. Use only authorized, non-sensitive inputs.

Source reviewed October 3, 2026.

Keep exploring / Chapter 04

SSH Honeypot

Observe an SSH session without exposing the host shell.

Let’s build something
worth protecting.

“A thoughtful conversation can be the beginning of something worth building.”
Connect on LinkedIn