Structural AI
Analyzes URL structures, web relationships, JavaScript ASTs, and code behavior.
From the visible web to the invisible deep web, we detect malicious URLs and keep every click safe.
We protect what matters — our customers' data, privacy, and trust — through AI-native security.
The name OLPEMI evokes the owl — built to see clearly where others see only darkness.
PotatoNet reads the web differently. Real content forms connected, traceable link chains; malicious content forms disconnected, unreachable clusters — hidden in the invisible web, where conventional security cannot see. This principle, Digital Chain-Based Detection, is the foundation of everything we build: threats made visible, stopped before a single click.
Social-engineering attacks that exploit trust are surging, and in nearly every campaign the URL is the attacker's primary vector. In June 2025 alone, 16 billion Google, Apple, and Facebook account records were found exposed on the dark web — a reminder of how much rides on knowing which link is safe to click.
Conventional security relies heavily on known signatures, blocklists, and visible web resources and even that foundation is weaker than it looks.
A 2022 USENIX Security study* found that of VirusTotal's 84 scanning engines, 61 (72.6%) each detected fewer than 5% of domains already confirmed malicious. Even known threats routinely slip past most individual engines.
*Bouwman, X., Le Pochat, V., Foremski, P., Van Goethem, T., Gañán, C. H., Moura, G. C. M., Tajalizadehkhoob, S., Joosen, W., & van Eeten, M. (2022). Helping hands: Measuring the impact of a large threat intelligence sharing community. In 31st USENIX Security Symposium (pp. 1149–1165). USENIX Association. usenix.org/conference/usenixsecurity22/presentation/bouwman
"What does this URL match?"
"What does this URL connect to?"
By tracing relationships between URLs, domains, redirects, web content, code, and infrastructure, OLPEMI uncovers hidden threats that conventional security can miss.
Every link is structural evidence. OLPEMI reads it — not just where a URL points, but what it's really connected to.
Continuous, real-time inspection means newly registered malicious URLs are identified the moment they emerge — not after they've already been used in an attack.
Founded in 2022, with the establishment of our in-house R&D center — PotatoNet has since built a consistent track record of validated technology.
Seeing what hides in the dark, before the click lands.
Conventional security watches the visible web: known URLs, known patterns, known malware. But beneath it lies a far larger world. Our September 2024 analysis found that
74% of malicious URLs and 91% of malware reside in the deep web.
OLPEMI detects malicious URLs before anyone clicks — across the visible web, the invisible web, closed communities, and short-lived domains. Built on Digital Chain-Based Detection (patent-pending) and multidimensional AI analysis, it delivers a verdict in under 0.004 seconds at 99.0% accuracy. One engine, two directions: an administrator console streaming real-time threat intelligence for security operators, and a single interface for individuals — paste a link, know it's safe.
OLPEMI runs analysis across three layers — the URL itself, the content it leads to, and the infrastructure behind it.
URL structure and JavaScript AST (abstract syntax tree) analysis surface malicious patterns and evasion techniques.
Transformer-based HTML analysis, paired with Vision LLM, sLLM, and BERT models, identifies malicious content and behavior — including what a page shows a human versus what it serves as a scanner.
Correlating WHOIS, RDAP, certificate, ASN, and GeoIP data exposes hidden attack infrastructure and connected threats, linking a single malicious URL back to the network behind it.
Real-time intelligence for URLs, domains, web infrastructure, and emerging threats — including malicious deep web resources and C2 (command-and-control) server infrastructure. Specialized in identifying web shells on compromised servers, surfacing attacker footholds before they're used to launch further attacks. Behind every verdict: ten families of signals read through GraphCodeBERT-based code understanding, multimodal phishing detection, and RAG-based comparison against known attack patterns.
Detect and filter malicious URLs before users access harmful websites. Integrate preemptive URL intelligence into existing web security environments. Inspecting inbound and outbound traffic at the network gateway, OLPEMI SWG flags malicious content and internal data leakage before it ever leaves the network.
Discover hidden threats targeting web servers, including web shells planted on compromised servers and the malware distribution channels they enable. Built on zero-trust architecture and behavior-based analysis, centered on web-shell detection — shifting defense from post-incident cleanup to blocking before execution.
Protect users from malicious links distributed through messages, social platforms, QR codes, and other mobile channels. Delivered as an Android app that checks malicious URL access on smartphones, plus a browser extension for PC.
No installation. No complex configuration. No security expertise required.
OLPEMI is delivered as a fully SaaS-based platform, providing immediate access to AI-powered URL threat intelligence through a browser.
Built for:
The administrator console provides real-time visibility into:
When a suspicious link arrives, users do not need to understand cybersecurity. Just paste the link.
OLPEMI returns an instant verdict supported by evidence such as:
Know before you click.
OLPEMI turns complex threat intelligence into an intuitive, actionable console — every verdict backed by the evidence behind it: the redirect chain, a captured screenshot, what the link does.
Screenshots are surfaced prominently so operators can judge malicious or phishing content at a glance. Items sharing an identical screenshot hash are grouped together to reveal the same attack pattern.
A graph structure surfaces relationships within a single attribute and across different attributes, enabling fast, cross-cutting analysis.
From entry point to terminal payload, making the mechanism of an attack legible rather than abstract.
A built-in reporting function lets operators and users correct results, feeding manual verification back alongside AI judgments.
Dashboard, Platform, Detection Engine, Data Management, and Service Management, with convenient filtering and condition-setting for search.
OLPEMI can integrate with existing network equipment, email systems, and security appliances without requiring new infrastructure. Suspicious URLs reach OLPEMI TI from wherever they first surface — the network, email, or existing security tools — and come back verified through the TI API.
NDR, visibility appliances, and DPUs extract URLs and send them to OLPEMI TI for verification.
URLs pulled from SMTP mail servers are verified and analyzed.
Suspicious URLs collected from IPS, UTM, TMS, NGFW, EDR, and XDR are verified and analyzed.
Phishing URLs are built to disappear. Up to 70% vanish within five hours of going live — but conventional security only checks new URLs against a blacklist of previously seen threats.
By the time a URL is confirmed malicious and added to that list, it's often already gone, and a fresh one has taken its place. This structural gap is exactly what OLPEMI was built to close.*
*Sheng, S. et al. (2009), An empirical analysis of phishing blacklists, as cited in Mulder, C.J. (2020), Improving Early Phishing Detection using SSL & WHOIS data, Eindhoven University of Technology.
Conventional URL security asks: "Have we seen this threat before?"
OLPEMI asks: "What is this URL connected to?"
OLPEMI introduces a new detection principle based on the structure of web connections. Real web content forms connected digital chains. Abnormal or hidden content can form disconnected and unreachable clusters. By analyzing these link relationships, OLPEMI can discover malicious resources beyond the visibility of conventional search engines and standard web crawling.
The link itself becomes evidence.
An unreachable structure is exactly what makes a URL an ideal hiding place — often only the attacker and the intended target know the address. Because a URL is built from subdomains, ports, paths, and parameters, an attacker can place a payload where it can't be reached from the domain name alone; detection has to start from the exact URL the target actually opens.
Even with the address in hand, malicious behavior can be triggered for a single, specific visitor only — keyed to device, time of day, or the target's location. Detection has to work out those targeting rules, not just check whether a payload is visible right now.
Conventional threat intelligence stops at infrastructure — domains, IPs, certificates. It rarely looks at what a page actually shows a user, so visual impersonation slips through. OLPEMI closes that gap: multiple AI analysis layers work together, reading structure, visual content, infrastructure, and language as one signal, not four separate ones.
Analyzes URL structures, web relationships, JavaScript ASTs, and code behavior.
Analyzes images, screenshots, text, and brand characteristics to detect phishing and impersonation.
Correlates domains, certificates, WHOIS, RDAP, ASN, GeoIP, hosting, and related infrastructure — attacker infrastructure intelligence.
Transforms complex detection results and evidence into understandable threat analysis.
These layers don't run in isolation — they run together, in real time. So OLPEMI doesn't just match a URL, it understands threat context — including sites showing no active malicious behavior at the time of inspection, a common evasion tactic that lets threats slip past conventional, signature-based detection entirely. Conventional detection misses these; OLPEMI doesn't.
Watch how these AI layers work together in real time to trace a threat from a single URL to its full infrastructure.
Protection begins before a malicious website becomes active. OLPEMI continuously monitors domain and brand reputation signals to identify suspicious or infringing domains as they emerge. Detect the threat before the victim.
Every verdict becomes an opportunity to improve. Manual corrections and automated feedback continuously refine the detection model, allowing OLPEMI to adapt to evolving threats.
*Performance metrics based on OLPEMI testing and system conditions.
OLPEMI's technology is supported by a growing portfolio of patents, trademarks, testing, and international standardization activities.
The technology analyzes URL characteristics and web content behavior to identify abnormal and potentially malicious web activity. It provides the technological foundation for preemptive detection beyond conventional blacklist-based security.
In consulting with the Korean Intellectual Property Office (Sep–Nov 2024), we reviewed 114 related patents on deep web and malicious URL detection, in Korea and abroad. Three apparent "deep web" patents turned out to describe dark web content instead — confirming that our approach to detecting malicious deep web activity stands alone.
Independent research confirms the gap this technology addresses. A 2022 USENIX Security study found that of VirusTotal's 84 scanning engines — the industry-standard aggregator for signature-based detection — 61 (72.6%) each detected fewer than 5% of domains already confirmed malicious. Even the most widely used detection infrastructure in the industry misses the majority of known threats; OLPEMI's link-structure-based approach was built to close that gap.
OLPEMI is developed by a team focused on one fundamental challenge: how can we detect a cyber threat before it becomes visible?
Multimodal analysis, code intelligence, and generative AI.
URL, domain, infrastructure, and attacker behavior analysis.
Discovery of hidden and previously unreachable web resources.
Large-scale crawling, real-time processing, and security infrastructure integration.
Patents, technology verification, and international standardization.
We are building technology that moves cybersecurity from reactive defense to preemptive protection.
Key R&D projects and partner institutions, from 2022 to the present. Scroll to browse.
Ministry of SMEs and Startups
Ministry of SMEs and Startups
Ministry of the Interior and Safety
Korea Internet & Security Agency (KISA)
Ministry of SMEs and Startups
Seoul Business Agency (SBA)
Korea Internet & Security Agency (KISA)
Korea Internet & Security Agency (KISA)
Electronics and Telecommunications Research Institute (ETRI)
Yuanta Securities Korea
Explore our latest technology updates, demonstrations, certifications, patents, standardization activities, and industry recognition.
Get counseling about your secure digital world. It's the first step toward that.