Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Behavioral Detection for Password-Phishing Websites

The SWG (Cloud) with GAM v8000 introduced BehavesLike.HTML.Phishinnk to detect phishing websites that attempt to steal user credentials. This behavioral detection helps protect users from phishing threats, including sites that do not yet have an established reputation or category. It evaluates webpage characteristics commonly associated with phishing activity, such as credential collection forms and other phishing indicators, and analyzes these signals to determine whether a page exhibits phishing-like behavior.

Temporary Exclusion for .jp Domains

Due to an elevated number of false positives on certain .jp domains, a DAT update released in June 2026 temporarily excluded this detection from .jp domains. The exclusion remains in place while the team investigates the issue.

Troubleshoot a Website Block

Perform the following steps to identify the cause of a website block by behavioral detection:

  • Verify the URL reputation and categorization.
  • If the site is legitimate and appears to be incorrectly detected, submit the URL for review.
  • If necessary, create a targeted policy exception for trusted business sites.
  • Open a Support case and provide the affected URL and detection details for investigation.

Recommendations

To help reduce false positives:

  • Ensure business-critical websites are properly categorized.
  • Regularly review uncategorized or unverified websites used within the organization.
  • Report suspected false positives to Support for analysis and resolution.
  • Was this article helpful?