Back to SentryPage
SentryPage29 September 2026

Spotting injected scripts and redirects

Spotting injected scripts and redirects

The page looks completely normal, which is the point

The problem

Defacement that announces itself is the least of the problem. An attacker who wants to stay in place changes nothing a visitor would notice. A script is injected to skim what people type into a form. A redirect sends mobile traffic somewhere else. Hidden links are added to sell somebody else's search ranking. An image is loaded from a domain that has nothing to do with the organisation.

The usual answer

None of this shows up in a visual check, and it is not what an internal team is looking for. Someone opening the site on a desktop browser sees the site working correctly, because it is working correctly. The compromise lives in the source, and the traffic it affects goes somewhere the organisation cannot see. These are the incidents that run for months and get discovered by a card processor, a search engine warning, or a customer whose details were taken from a form on a page the organisation still considers healthy.

How we approach it

The External Resource Engine™ reads what the page is actually loading. Images, scripts and redirects that point at external domains are checked against the domains the organisation has declared, and anything reaching out to an unrecognised destination is flagged. The engine is looking at composition rather than appearance, so an injected component is visible even when the rendered page is unchanged.

What changes

You find out that something has been added to your page while it is a monitoring alert instead of a regulator's question. The check runs on the same interval as everything else, which means an injection that arrives on a Friday evening does not have the weekend to work.