urlyze.

Platform

One platform, four pillars

From the first suspicious URL to the takedown request — every step backed by a full forensic scan.

Pillar 01

URL Scanning & Analysis

Headless browser scans with a clear verdict — Clean, Suspicious, or Malicious — plus a plain-language explanation and analyst hint.

Clear verdicts

Every scan ends in Clean, Suspicious, or Malicious — with a plain-language explanation and an analyst hint that justify it.

Multi-engine reputation

Reputation lookups across multiple engines feed into the verdict.

File & document analysis

In-depth analysis of files and documents encountered during scans.

Redirect-chain & DOM forensics

Follow the full redirect chain with multi-stage screenshots and DOM forensics.

Cloaked redirector detection

Detects CAPTCHA-gated cloaked redirectors that hide the real payload from scanners.

Egress region selection

Pick the egress region per scan to see what a target serves in a specific geography.

Clipboard-attack (ClickFix) detection

Fake “verify you are human” gates are pressed on a throwaway copy of the page, and whatever they write to the clipboard is captured as evidence — command included.

Blockchain-hosted C2 detection

Pages that fetch their command-and-control address from a public blockchain node while presenting themselves as something unrelated to crypto.

Executable delivery & remote-management abuse

Pages that hand over installers or push remote management tooling under a document or update pretext — the file the page actually delivers is the file analysed.

secure-login-portal.exampleMalicious
  • reputation · engine Aflagged
  • reputation · engine Bno match

Explanation

Credential form posts captured input to an unrelated third-party host.

Analyst hint

Kit fingerprint matches a known phishing-kit family — pivot on the second hop of the redirect chain.

Pillar 02

Brand & Domain Protection

Lookalike and typosquat discovery over newly registered domains — ~70,000 NRDs screened daily.

Lookalike discovery

Lookalike/typosquat discovery over newly registered domains, with ~70,000 NRDs screened daily.

Impersonation detection

Visual fingerprints and phishing-kit fingerprints catch impersonation even when the domain looks unrelated.

BEC-capable lookalike alerts

Domains armed with MX+SPF but hosting no website — invisible to site-only scanners — flagged the day they're registered.

Classified inventory

Your lookalike inventory classified live / parked / mail-armed, so you know what to act on first.

Takedown evidence packs

Export takedown-ready evidence packs backed by full forensic scan reports.

Lookalike inventory · urlyze.io
  • ur1yze.iolive
  • urlzye.ioparked
  • urly2e.ioBEC-capablemail-armed
  • urlyze-io.comparked

Pillar 03

Email Security Posture

Grade and monitor the email security posture of your owned domains.

SPF / DKIM / DMARC grading

Core email authentication records graded on your owned domains.

BIMI, MTA-STS, TLS-RPT

Extended posture checks beyond the basics.

Downgrade alerts

Continuous monitoring with alerts when a domain's posture degrades.

example.comStrong
  • SPF-all
  • DKIMaligned
  • DMARCp=reject
StrongModerateWeakExposed

Pillar 04

SOC Workflow

Built for how analysts actually work — API-first, with the exports and integrations your stack expects.

Case management

Track investigations from first alert to closure, in one place.

IOC / STIX export

Export indicators in the formats your tooling consumes.

SIEM integration

Feed alerts and scan results into your SIEM.

API-first design

Everything in the UI is available over the API.

Scheduled monitoring & saved searches

Re-run what matters on a schedule and keep your queries at hand.

Telegram brand-mention monitoring

Watch Telegram channels for mentions of your brand.

Report intake

Your people forward a suspicious email and it lands in your workspace already scanned — links and attachments extracted, analysed and triaged into a report.

Case · lookalike takedown

  1. Alert
  2. Triaged
  3. Evidence pack
  4. Takedown requested
ExportIOCSTIXSIEM

Pipeline

How a scan runs

Every submitted URL moves through the same forensic pipeline — each step can raise the verdict's severity, never lower it.

  1. fail fast

    Preflight

    DNS resolution + TCP reachability, so dead domains fail fast instead of burning a scan.

  2. real browser

    Headless render

    A real browser loads the page: redirect chain, DOM, multi-stage screenshots.

  3. throwaway copy

    Interaction & clipboard evidence

    Gates and prompts are pressed on a throwaway copy of the page — never the analysed document — capturing what the page writes to the clipboard and the instruction screen that only appears afterwards.

  4. parallel

    Reputation engines

    Multiple reputation engines queried in parallel.

  5. deep inspection

    Content & document analysis

    In-depth inspection of files and documents encountered during a scan.

  6. kit match

    Fingerprint & correlation

    Phishing-kit fingerprints, brand-baseline matching, correlation rules.

  7. upward-only

    Verdict

    Signals aggregate upward-only — a step can raise severity, never lower it — ending in a verdict plus its explanation and analyst hint.

  8. handoff

    Evidence

    Full report, IOC/STIX export, takedown evidence pack, case handoff.

API

Built API-first

Submit scans and poll verdicts, pivot across fingerprint dimensions, fetch scan screenshots, export IOC feeds as JSON, STIX 2.1, or firewall-ready EDL lists, and read live usage — everything the platform does is available over the API. Authenticate with an API key from your dashboard.

Read the API docs — docs.urlyze.io →

See the platform on your own brand.