What Is Unfurl and What Can It Do for URL Analysis?
Unfurl is an open-source URL analysis tool from Hindsight Foundry, aimed at DFIR and OSINT analysts who need to pull as much intelligence as possible out of a URL. It does two things: it breaks URLs into their component parts, and it visualizes the extracted data as a directed graph. If your work involves triaging suspicious links, tracing phishing infrastructure, or enriching indicators during an investigation, Unfurl is built for that task. It is not a general-purpose link shortener or a consumer "is this safe?" checker.
How Unfurl fits into the Hindsight Foundry toolset
Hindsight Foundry is a site dedicated to browser forensics research, open-source tools, and related resources. It hosts two main tools:
| Tool | Purpose | Primary audience |
|---|---|---|
| Hindsight | Extracts and correlates many browser artifact types into a unified timeline; supports Mozilla Firefox and Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, and more) | Browser forensics / DFIR |
| Unfurl | Breaks URLs into components and visualizes extracted data as a directed graph | DFIR and OSINT analysts |
The two tools cover different ends of a web investigation. Hindsight works on what a browser left behind on a system; Unfurl works on the URLs themselves, whether they came from a browser artifact, an email, or an intelligence feed.
What Unfurl actually does
URL decomposition
Unfurl parses a URL into its constituent pieces rather than treating it as a single opaque string. That matters because a URL often carries more than a destination: embedded parameters, encoded values, identifiers, and timestamps can all be extracted and examined separately.
Directed-graph visualization
The extracted data is rendered as a directed graph. This lets an analyst see relationships between components — for example, how parameters, identifiers, or decoded values connect to one another — instead of reading through a flat list.
Parser-based enrichment
Unfurl's capabilities expand through parsers. The v2026.09 release added parsers for:
- Gmail
- Outlook Safe Links
- GitHub
That same release decodes more timestamps found in tokens and IDs, and adds new Tree and Text views to the web UI. For an analyst, this means a URL wrapped in a known service's format can be unwrapped automatically, and time-related values buried in tokens become readable.
Who should use it
Unfurl is a fit if you are:
- A DFIR analyst who needs to understand a URL recovered from an investigation
- An OSINT analyst working with links from social media, email, or public sources
- Someone doing phishing or infrastructure triage who wants structured output rather than manual string inspection
It is likely not the right tool if you just want a quick reputation verdict on a link, or if you need a browser extension for everyday safe-browsing.
Practical starting points
- Tool access: Unfurl is listed on the Hindsight Foundry site alongside Hindsight, with the site describing both as open source.
- Staying current: The site offers a subscribe option for notifications when new Hindsight and Unfurl releases drop, plus occasional browser forensics deep-dives. The site's pricing signals mention "subscribe," but no pricing or payment details are provided in the available material, so treat the subscription as a release-notification channel rather than a stated paid product.
- Learning context: Hindsight Foundry also lists hands-on browser forensics training for security analysts, structured around practical investigative questions, described as a new course launching soon.
A concrete example of the workflow
Suppose an investigation surfaces a link that appears to route through a mail provider's redirect wrapper. Rather than manually stripping the wrapper and guessing at the remaining parameters, you would feed the URL to Unfurl. The relevant parser handles the wrapper format, the tool decomposes what remains, and the directed graph shows how the decoded components relate. If the URL contains a token with an embedded timestamp, the expanded timestamp decoding in v2026.09 lets you read that value directly. The output is a structured view you can document or pivot from, not a hand-decoded string.
What to check before relying on it
- Browser coverage is a Hindsight feature, not Unfurl's. Firefox support and Chromium-based browser support apply to Hindsight. Unfurl's scope is URLs.
- Parser coverage determines what gets decoded automatically. The Gmail, Outlook Safe Links, Facebook, Instagram, and GitHub parsers were added in v2026.09; URLs outside supported formats still get decomposed, but service-specific unwrapping depends on parser availability.
- Version matters. If you need the newer parsers, timestamp decoding, or the Tree and Text views, confirm you are on v2026.09 or later.