Q-TIP (QR Code Threat Inspection Platform)

By Rushikesh D Nandedkar on 07 Aug 2025 @ Blackhat : Arsenal
πŸ”— Link
We need help to complete this entry! Missing: Source Code
I can help!
#incident-management #web-security #architecture #security-training
Focus Areas: πŸ” Application Security , 🚨 Incident Response , πŸ—οΈ Security Architecture , πŸ“š Security Awareness , 🌐 Web Application Security
This tool demo covers following tools where the speaker has contributed or authored
Q-TIP

Abstract

Q-TIP – QR Threat Inspection Protocol is an innovative, multi-layered cybersecurity tool designed to combat the emerging threat of QR code-based phishing attacks. By combining robust QR code decoding, comprehensive static URL analysis (including redirection chain tracking, WHOIS lookups, and SSL certificate validation), and advanced visual forensics using OpenCV, Q-TIP offers a granular, data-driven assessment of phishing risks. Additionally, the tool integrates threat intelligence from a continuously updated phishing artifacts database and implements suspicious file detection by securely downloading and analyzing files with malicious extensions. Its modular, scalable design supports both single-image and batch processing, generating detailed forensic reports in TXT and HTML formats that explicitly enumerate the reasons behind each phishing verdict.

Takeaways:

This abstract encapsulates Q-TIP’s promise to revolutionize QR code phishing detection through technical rigor, innovative methodologies, and forward-thinking designβ€”making it a compelling solution for Black Hat USA Arsenal 2025.