urlyze docs

Behavioural detection

A rendered capture tells you what a page loaded. It does not tell you what the page does when somebody uses it — and that is where a large share of current phishing and malware-delivery kits keep the part worth seeing.

What a passive capture misses

Three shapes account for most of it, and all three survive a scan that only renders:

ShapeWhy rendering alone returns nothing
The command that does not exist yet The page downloads nothing. It waits for a click, then writes a shell command to the visitor's clipboard and tells them to paste it. Network traffic during the visit is unremarkable, so the capture looks clean.
The screen one navigation away The page that gets submitted is the lure. It holds a brand's name and imagery and nothing else; the credential form lives at a second address that only opens after a control is used.
The gate that is only a picture of a gate A copied anti-bot interstitial stops a scanner exactly as well as a real one. The scan ends inconclusive, and everything behind the copy goes unexamined.

What Urlyze does instead

Each of these is a separate mechanism with its own evidence on the scan record:

ClickFix and the clipboard

We use the control the page offers, on a discarded copy, and read what the page puts on the clipboard.

Following the funnel

When a page sends its whole clickable surface to one unrelated address, we open that address and examine what is waiting there.

Real gates and copies of them

We separate a challenge a provider actually served from a page that merely says it is one — and we stay away from the real ones.

Rules that apply to all of it

These constraints are part of the design, not caveats bolted on afterwards. They are worth reading before you evaluate the results:

Everything on these pages describes behaviour that is live in production today. Where a mechanism has a limit that matters to how you read a result, that limit is stated on the page — including the cases we deliberately refuse.