Behavioural detection
A rendered capture tells you what a page loaded. It does not tell you what the page does when somebody uses it — and that is where a large share of current phishing and malware-delivery kits keep the part worth seeing.
What a passive capture misses
Three shapes account for most of it, and all three survive a scan that only renders:
| Shape | Why rendering alone returns nothing |
|---|---|
| The command that does not exist yet | The page downloads nothing. It waits for a click, then writes a shell command to the visitor's clipboard and tells them to paste it. Network traffic during the visit is unremarkable, so the capture looks clean. |
| The screen one navigation away | The page that gets submitted is the lure. It holds a brand's name and imagery and nothing else; the credential form lives at a second address that only opens after a control is used. |
| The gate that is only a picture of a gate | A copied anti-bot interstitial stops a scanner exactly as well as a real one. The scan ends inconclusive, and everything behind the copy goes unexamined. |
What Urlyze does instead
Each of these is a separate mechanism with its own evidence on the scan record:
ClickFix and the clipboard
We use the control the page offers, on a discarded copy, and read what the page puts on the clipboard.
Following the funnel
When a page sends its whole clickable surface to one unrelated address, we open that address and examine what is waiting there.
Real gates and copies of them
We separate a challenge a provider actually served from a page that merely says it is one — and we stay away from the real ones.
Rules that apply to all of it
These constraints are part of the design, not caveats bolted on afterwards. They are worth reading before you evaluate the results:
- Interaction happens on a throwaway copy. The capture that becomes your scan record is not the page we clicked. Pressing a control cannot alter what was reported about the analysed page.
- We never execute what the page hands over. A clipboard command is read and classified, never run. A delivered file is not launched.
- We do not type credentials and we do not submit forms with invented identities.
- A genuine anti-bot challenge is left alone. We do not attempt to solve or bypass one; see Real gates and copies of them.
- Evidence stays attributed to the page that produced it. What we learn at a followed address is recorded as exactly that, and never merged into the observations about the page you submitted.
- One hop, not a graph. We follow a single address, once.