Is that file safe?

Drop any suspicious file onto ThreatLens and instantly know if it's ransomware, a credential stealer, cryptominer, or something worse. Free. No signup. No file uploads.

Download ThreatLens.exe How It Works

Windows 10/11 23 MB v1.0.0 100% Free

7
Analysis Engines
80+
Suspicious API Detections
50+
Threat Pattern Signatures
6
YARA Rules Built-in
70+
AV Engines via VirusTotal

What ThreatLens detects

Six categories of threats that put your data, money, and privacy at risk.

🔒

Ransomware

Detects file encryption APIs (CryptEncrypt, BCryptEncrypt), shadow copy deletion commands (vssadmin, wmic), ransom note text patterns, Bitcoin/Monero wallet addresses, and Windows recovery disabling. Catches it before it locks your files.

Critical Threat
🕵

Information Stealers

Identifies programs targeting Chrome, Firefox, and Edge saved passwords and cookies, Discord/Telegram tokens, SSH keys, crypto wallets, FileZilla credentials, and clipboard hijacking. Flags DPAPI decryption calls used to crack browser vaults.

Critical Threat
🖱

RATs & Backdoors

Spots remote access trojans via process injection APIs (WriteProcessMemory, CreateRemoteThread), reverse shell patterns, PowerShell download cradles, hidden window execution, and command-and-control channel indicators.

Critical Threat

Cryptominers & Resource Hogs

Flags mining pool connection strings (stratum+tcp://), known miner software names (XMRig, cgminer), hashrate references, and CPU affinity manipulation used to secretly mine cryptocurrency using your computer's resources.

High Threat
📦

Trojan Droppers

Detects download functions (URLDownloadToFile, DownloadString), embedded executables inside documents, packed/encrypted payloads via entropy analysis, and known packer signatures (UPX, Themida, VMProtect).

High Threat
🚫

Evasion & Anti-AV

Catches AMSI bypass attempts, Windows Defender disabling commands, AV process killing, firewall manipulation, debugger detection tricks, sandbox evasion via timing checks, and self-modifying code sections (RWX memory).

High Threat

How it works

Three steps. Under 5 seconds. No technical knowledge needed.

1

Download

Download ThreatLens.exe. It's a single file -- no installer, no setup, no account needed.

2

Drag & Drop

Drag any suspicious file onto ThreatLens.exe. Or double-click it to open a file picker.

3

Read the Verdict

Get a color-coded threat score (0-100) with detailed findings, severity levels, and recommendations.

7 analysis engines in one scan

Every file is run through multiple independent detection methods for maximum coverage.

Engine What It Analyzes File Types
PE Import Analyzer 80+ suspicious Windows API calls across 15 threat categories -- keylogging, injection, credential theft, encryption, privilege escalation, persistence, network exfil .exe, .dll, .scr, .sys
String Pattern Scanner 50+ regex signatures for ransomware notes, crypto wallets, browser data paths, C2 channels, PowerShell cradles, mining pools, AV evasion commands All files
YARA Rule Engine 6 compiled YARA rules detecting ransomware, browser stealers, cryptominers, process injection, anti-AV evasion, and shellcode patterns All files
Entropy Analyzer Shannon entropy calculation per-section and whole-file to detect packed, encrypted, or compressed payloads hiding malicious code All files
Office Macro Scanner VBA macro extraction, auto-execute trigger detection (AutoOpen, Document_Open), Shell calls, WScript objects, download commands, obfuscation .doc, .xls, .docm, .xlsm
File Identity Validator Magic byte detection, extension mismatch warnings (e.g., .jpg that's really .exe), double extension tricks, SHA256/MD5 hashing All files
VirusTotal Lookup Checks file hash against 70+ commercial antivirus engines. Shows detection names and count. No file upload -- hash only, fully private. All files

Why ThreatLens

Built for regular people who download files and want to stay safe.

+
100% Free, Forever No trial, no premium tier, no credit card. Every feature is free.
+
No Signup Required Download and use immediately. No account, no email, no registration.
+
Privacy First Your files are never uploaded. Analysis happens 100% on your computer. Only a hash (fingerprint) is checked online.
+
No Installation Single .exe file. No installer, no system changes, no admin rights needed. Delete it when you're done.
+
Drag-and-Drop Simple Drag any file onto the icon. That's it. Results in under 5 seconds. Anyone can use it.
+
Scans Any File Type EXE, DLL, Office documents, scripts (BAT, PS1, VBS, JS), PDFs, archives -- if it could be dangerous, ThreatLens checks it.
+
Plain English Verdicts Color-coded threat score from 0-100 with a clear verdict: CLEAN, LOW RISK, CAUTION, SUSPICIOUS, or DANGEROUS.
+
Detailed Forensic Report Every finding includes severity, category, description, and the exact string/API that triggered it. JSON export included.
+
Catches What AV Misses Static analysis catches threats that signature-based antivirus can miss -- packed files, zero-days, obfuscated scripts, and novel malware.
+
Combined Threat Detection Flags dangerous API combinations: credential theft + network = exfiltration. Keylogging + network = remote spy. Encryption + anti-debug = ransomware.
+
Works Alongside Your Antivirus Not a replacement for AV -- a second opinion. Run it on anything your antivirus doesn't flag but you still don't trust.
+
70+ AV Engine Cross-Check VirusTotal integration checks your file's fingerprint against 70+ antivirus engines worldwide -- without uploading the file.

Perfect for

Anyone who downloads files and wants peace of mind.

💻

Downloaded Software

Check any .exe you downloaded before running it. Especially from forums, torrents, or links someone sent you.

📧

Email Attachments

Got a Word doc, PDF, or zip file from an unexpected email? Scan it first. Catches macro viruses and embedded payloads.

💾

USB Drives

Someone gave you a USB stick? Scan every file on it before opening anything. Catches autorun exploits and disguised executables.

Don't open it until you scan it

One suspicious file can encrypt your entire hard drive, steal your passwords, or silently mine crypto in the background.

Download ThreatLens -- Free

Windows 10/11 · Single .exe · No install · No signup