Platform
One platform, four pillars
From the first suspicious URL to the takedown request — every step backed by a full forensic scan.
Pillar 01
URL Scanning & Analysis
Headless browser scans with a clear verdict — Clean, Suspicious, or Malicious — plus a plain-language explanation and analyst hint.
Clear verdicts
Every scan ends in Clean, Suspicious, or Malicious — with a plain-language explanation and an analyst hint that justify it.
Multi-engine reputation
Reputation lookups across multiple engines feed into the verdict.
File & document analysis
In-depth analysis of files and documents encountered during scans.
Redirect-chain & DOM forensics
Follow the full redirect chain with multi-stage screenshots and DOM forensics.
Cloaked redirector detection
Detects CAPTCHA-gated cloaked redirectors that hide the real payload from scanners.
Egress region selection
Pick the egress region per scan to see what a target serves in a specific geography.
Clipboard-attack (ClickFix) detection
Fake “verify you are human” gates are pressed on a throwaway copy of the page, and whatever they write to the clipboard is captured as evidence — command included.
Blockchain-hosted C2 detection
Pages that fetch their command-and-control address from a public blockchain node while presenting themselves as something unrelated to crypto.
Executable delivery & remote-management abuse
Pages that hand over installers or push remote management tooling under a document or update pretext — the file the page actually delivers is the file analysed.
- reputation · engine Aflagged
- reputation · engine Bno match
Explanation
Credential form posts captured input to an unrelated third-party host.
Analyst hint
Kit fingerprint matches a known phishing-kit family — pivot on the second hop of the redirect chain.
Pillar 02
Brand & Domain Protection
Lookalike and typosquat discovery over newly registered domains — ~70,000 NRDs screened daily.
Lookalike discovery
Lookalike/typosquat discovery over newly registered domains, with ~70,000 NRDs screened daily.
Impersonation detection
Visual fingerprints and phishing-kit fingerprints catch impersonation even when the domain looks unrelated.
BEC-capable lookalike alerts
Domains armed with MX+SPF but hosting no website — invisible to site-only scanners — flagged the day they're registered.
Classified inventory
Your lookalike inventory classified live / parked / mail-armed, so you know what to act on first.
Takedown evidence packs
Export takedown-ready evidence packs backed by full forensic scan reports.
- ur1yze.iolive
- urlzye.ioparked
- urly2e.ioBEC-capablemail-armed
- urlyze-io.comparked
Pillar 03
Email Security Posture
Grade and monitor the email security posture of your owned domains.
SPF / DKIM / DMARC grading
Core email authentication records graded on your owned domains.
BIMI, MTA-STS, TLS-RPT
Extended posture checks beyond the basics.
Downgrade alerts
Continuous monitoring with alerts when a domain's posture degrades.
- SPF-all
- DKIMaligned
- DMARCp=reject
Pillar 04
SOC Workflow
Built for how analysts actually work — API-first, with the exports and integrations your stack expects.
Case management
Track investigations from first alert to closure, in one place.
IOC / STIX export
Export indicators in the formats your tooling consumes.
SIEM integration
Feed alerts and scan results into your SIEM.
API-first design
Everything in the UI is available over the API.
Scheduled monitoring & saved searches
Re-run what matters on a schedule and keep your queries at hand.
Telegram brand-mention monitoring
Watch Telegram channels for mentions of your brand.
Report intake
Your people forward a suspicious email and it lands in your workspace already scanned — links and attachments extracted, analysed and triaged into a report.
Case · lookalike takedown
- Alert
- Triaged
- Evidence pack
- Takedown requested
Pipeline
How a scan runs
Every submitted URL moves through the same forensic pipeline — each step can raise the verdict's severity, never lower it.
- fail fast
Preflight
DNS resolution + TCP reachability, so dead domains fail fast instead of burning a scan.
- real browser
Headless render
A real browser loads the page: redirect chain, DOM, multi-stage screenshots.
- throwaway copy
Interaction & clipboard evidence
Gates and prompts are pressed on a throwaway copy of the page — never the analysed document — capturing what the page writes to the clipboard and the instruction screen that only appears afterwards.
- parallel
Reputation engines
Multiple reputation engines queried in parallel.
- deep inspection
Content & document analysis
In-depth inspection of files and documents encountered during a scan.
- kit match
Fingerprint & correlation
Phishing-kit fingerprints, brand-baseline matching, correlation rules.
- upward-only
Verdict
Signals aggregate upward-only — a step can raise severity, never lower it — ending in a verdict plus its explanation and analyst hint.
- handoff
Evidence
Full report, IOC/STIX export, takedown evidence pack, case handoff.
API
Built API-first
Submit scans and poll verdicts, pivot across fingerprint dimensions, fetch scan screenshots, export IOC feeds as JSON, STIX 2.1, or firewall-ready EDL lists, and read live usage — everything the platform does is available over the API. Authenticate with an API key from your dashboard.