[{"data":1,"prerenderedAt":4602},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/2024-identity-breaches":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1297,"synopsis":1292,"hashTags":118,"publishedDate":1298,"slug":1299,"tagsCollection":1300,"relatedBlogPostsCollection":1306,"ogImage":3934,"authorsCollection":3936,"content":3944,"_id":4597,"_type":4598,"_source":4599,"_file":4600,"_stem":4601,"_extension":4598},"/blog/2024-identity-breaches","blog",{"id":1280,"publishedAt":1281},"1pJdOGN0dOd3BKVqO4CxHh","2026-01-30T09:10:57.289Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"Reviewing public breaches that stemmed from identity attacks in 2024. ","text","paragraph","document","Looking back on identity-based breaches in 2024","Public breaches from identity attacks in 2024","2025-01-10T00:00:00.000Z","2024-identity-breaches",{"items":1301},[1302],{"sys":1303,"name":1305},{"id":1304},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":1307},[1308,2055,2398],{"__typename":1309,"sys":1310,"content":1312,"title":2033,"synopsis":2034,"hashTags":118,"publishedDate":2035,"slug":2036,"tagsCollection":2037,"authorsCollection":2047},"BlogPosts",{"id":1311},"6vCr4d3R1XA1E8dU883l7N",{"json":1313},{"nodeType":1295,"data":1314,"content":1315},{},[1316,1325,1329,1345,1352,1359,1365,1372,1393,1413,1420,1426,1433,1436,1444,1451,1458,1466,1473,1480,1515,1521,1528,1531,1538,1545,1663,1670,1688,1695,1715,1722,1743,1750,1770,1773,1780,1787,1794,1827,1834,1841,1860,1866,1873,1880,1886,1893,1956,1963,1970,1977,1984,1991,1994,2001,2021,2027],{"nodeType":1317,"data":1318,"content":1324},"embedded-entry-block",{"target":1319},{"sys":1320},{"id":1321,"type":1322,"linkType":1323},"HcoxuG8EK0w5uFQlN0hbh","Link","Entry",[],{"nodeType":1326,"data":1327,"content":1328},"hr",{},[],{"nodeType":1294,"data":1330,"content":1331},{},[1332,1336,1341],{"nodeType":1293,"value":1333,"marks":1334,"data":1335},"While ",[],{},{"nodeType":1293,"value":1337,"marks":1338,"data":1340},"striking",[1339],{"type":312},{},{"nodeType":1293,"value":1342,"marks":1343,"data":1344}," gold sure feels good, mining for gold doesn’t. All that sifting for a few grains of value. ",[],{},{"nodeType":1294,"data":1346,"content":1347},{},[1348],{"nodeType":1293,"value":1349,"marks":1350,"data":1351},"If you’ve ever tried to make use of a TI feed on stolen credentials, you’ll know exactly how this feels. Yet the need to identify signal from noise is obvious. When it matters, it really matters. ",[],{},{"nodeType":1294,"data":1353,"content":1354},{},[1355],{"nodeType":1293,"value":1356,"marks":1357,"data":1358},"While there’s an enormous volume of TI data available on stolen creds, data trustworthiness is much harder to establish. Are these creds still in use? Are they in use on company applications? And without trust in the data, it’s harder to take action.",[],{},{"nodeType":1317,"data":1360,"content":1364},{"target":1361},{"sys":1362},{"id":1363,"type":1322,"linkType":1323},"4unFZadFrWEQsiHsD3YAEo",[],{"nodeType":1294,"data":1366,"content":1367},{},[1368],{"nodeType":1293,"value":1369,"marks":1370,"data":1371},"We set out to solve this problem at Push and ended up flipping the script on conventional approaches to evaluating TI on stolen credentials. (Lay down your shovel, friend.)",[],{},{"nodeType":1373,"data":1374,"content":1375},"blockquote",{},[1376],{"nodeType":1294,"data":1377,"content":1378},{},[1379,1383,1389],{"nodeType":1293,"value":1380,"marks":1381,"data":1382},"With our latest release, Push takes TI on stolen credentials sourced from criminal forums and compares it to the actual credentials still being used across customer environments, ",[],{},{"nodeType":1293,"value":1384,"marks":1385,"data":1388},"alerting on validated true positives only",[1386],{"type":1387},"bold",{},{"nodeType":1293,"value":1390,"marks":1391,"data":1392},". ",[],{},{"nodeType":1294,"data":1394,"content":1395},{},[1396,1400,1409],{"nodeType":1293,"value":1397,"marks":1398,"data":1399},"As of January 2025, you can also bring your own TI to the Push platform. Using the ",[],{},{"nodeType":1401,"data":1402,"content":1404},"hyperlink",{"uri":1403},"https://pushsecurity.redoc.ly/rest-v1#tag/Stolen-credential-detection",[1405],{"nodeType":1293,"value":1406,"marks":1407,"data":1408},"Push REST API",[],{},{"nodeType":1293,"value":1410,"marks":1411,"data":1412},", you can share stolen credential reports you receive from your existing vendors and task the Push browser agent with finding the ones still in use by employees.",[],{},{"nodeType":1294,"data":1414,"content":1415},{},[1416],{"nodeType":1293,"value":1417,"marks":1418,"data":1419},"Call it the “dirt in, gold out” model for TI feeds.",[],{},{"nodeType":1317,"data":1421,"content":1425},{"target":1422},{"sys":1423},{"id":1424,"type":1322,"linkType":1323},"5VtuerdMpP4U9yL7pjrb4P",[],{"nodeType":1294,"data":1427,"content":1428},{},[1429],{"nodeType":1293,"value":1430,"marks":1431,"data":1432},"In this article, we’ll cover some of the challenges with threat intel on stolen credentials, why the rise of infostealers has added urgency to determining the trustworthiness of this category of threat, and how Push’s approach of validating stolen credentials cuts through uncertainty. ",[],{},{"nodeType":1326,"data":1434,"content":1435},{},[],{"nodeType":1437,"data":1438,"content":1439},"heading-1",{},[1440],{"nodeType":1293,"value":1441,"marks":1442,"data":1443},"Why actionable intel on creds is hard",[],{},{"nodeType":1294,"data":1445,"content":1446},{},[1447],{"nodeType":1293,"value":1448,"marks":1449,"data":1450},"Both threat actors and security teams have ready access to information on stolen credentials, with obviously opposite goals. There is now a robust economy for this data, driven in part by both the success of attacks using stolen creds, and the SaaS-ification of business software. In the past, security teams could audit their Active Directory passwords. Today, many if not most corporate credentials are stored in apps that do not provide that level of visibility.",[],{},{"nodeType":1294,"data":1452,"content":1453},{},[1454],{"nodeType":1293,"value":1455,"marks":1456,"data":1457},"So when it comes to stolen credential TI, the challenge is not the availability of data — dozens of vendors already do the hard work of establishing presences in these forums in order to collect and disseminate information on credentials such as usernames, passwords, cookies, and API keys that have been stolen through data breaches, phishing attacks, infostealers, or other methods. ",[],{},{"nodeType":1459,"data":1460,"content":1461},"heading-2",{},[1462],{"nodeType":1293,"value":1463,"marks":1464,"data":1465},"Too much data, not enough context",[],{},{"nodeType":1294,"data":1467,"content":1468},{},[1469],{"nodeType":1293,"value":1470,"marks":1471,"data":1472},"Rather, the difficulty is determining which information to act on. Finding the gold, in other words.",[],{},{"nodeType":1294,"data":1474,"content":1475},{},[1476],{"nodeType":1293,"value":1477,"marks":1478,"data":1479},"TI on stolen credentials often suffers from:",[],{},{"nodeType":1481,"data":1482,"content":1483},"unordered-list",{},[1484,1500],{"nodeType":1485,"data":1486,"content":1487},"list-item",{},[1488],{"nodeType":1294,"data":1489,"content":1490},{},[1491,1496],{"nodeType":1293,"value":1492,"marks":1493,"data":1495},"Data overload:",[1494],{"type":1387},{},{"nodeType":1293,"value":1497,"marks":1498,"data":1499}," The double bind of TI is especially evident here — once you know about a potential true positive, you feel obligated to investigate, yet the scale of the information and the high incidence of outdated or incomplete information can pose a risk of desensitizing the SOC or wasting dozens of hours of time investigating what turn out to be false positives, especially when that time could have been better spent on in-depth threat hunting.",[],{},{"nodeType":1485,"data":1501,"content":1502},{},[1503],{"nodeType":1294,"data":1504,"content":1505},{},[1506,1511],{"nodeType":1293,"value":1507,"marks":1508,"data":1510},"Minimal context:",[1509],{"type":1387},{},{"nodeType":1293,"value":1512,"marks":1513,"data":1514}," Intelligence is often incomplete or out of date. TI feeds may present stolen passwords as new breaches, but the data is actually a recycled combolist (aggregated list of lists) rather than a new incident. In some situations, infostealer threat intel can stem from a personal device that was compromised and once accessed corporate assets, but is no longer active or using that password. Then there are the false negatives, where you get an alert for stolen credentials on a core app following a breach, and the creds are no longer in use there — but they are still being used on a different high-value app. ",[],{},{"nodeType":1317,"data":1516,"content":1520},{"target":1517},{"sys":1518},{"id":1519,"type":1322,"linkType":1323},"40ZWbzJFQLRjCAaFCA0YLS",[],{"nodeType":1294,"data":1522,"content":1523},{},[1524],{"nodeType":1293,"value":1525,"marks":1526,"data":1527},"Despite these challenges, there is still a strong case for incorporating TI on stolen creds into your cyber defense practice for one important reason: Attackers are increasingly using stolen credentials to compromise organizations.",[],{},{"nodeType":1326,"data":1529,"content":1530},{},[],{"nodeType":1437,"data":1532,"content":1533},{},[1534],{"nodeType":1293,"value":1535,"marks":1536,"data":1537},"The commodification of stolen creds in the age of infostealers",[],{},{"nodeType":1294,"data":1539,"content":1540},{},[1541],{"nodeType":1293,"value":1542,"marks":1543,"data":1544},"A few headline stats on how ubiquitous stolen credential exploitation has become:",[],{},{"nodeType":1481,"data":1546,"content":1547},{},[1548,1572,1594,1617,1653],{"nodeType":1485,"data":1549,"content":1550},{},[1551],{"nodeType":1294,"data":1552,"content":1553},{},[1554,1558,1568],{"nodeType":1293,"value":1555,"marks":1556,"data":1557},"The ",[],{},{"nodeType":1401,"data":1559,"content":1561},{"uri":1560},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[1562],{"nodeType":1293,"value":1563,"marks":1564,"data":1567},"2024 Verizon DBIR",[1565],{"type":1566},"underline",{},{"nodeType":1293,"value":1569,"marks":1570,"data":1571}," found that 79% of web application compromises were the result of breached credentials.",[],{},{"nodeType":1485,"data":1573,"content":1574},{},[1575],{"nodeType":1294,"data":1576,"content":1577},{},[1578,1581,1590],{"nodeType":1293,"value":37,"marks":1579,"data":1580},[],{},{"nodeType":1401,"data":1582,"content":1584},{"uri":1583},"https://www.ibm.com/reports/threat-intelligence",[1585],{"nodeType":1293,"value":1586,"marks":1587,"data":1589},"Researchers at IBM",[1588],{"type":1566},{},{"nodeType":1293,"value":1591,"marks":1592,"data":1593}," identified a 71% year-over-year increase in cyberattacks using stolen or compromised credentials. This jump made stolen creds the No. 1 source of initial access for cyberattacks in their study. They also found a 266% uptick in the last year in the use of infostealers — malware designed to capture passwords, cookies, and other credential data.",[],{},{"nodeType":1485,"data":1595,"content":1596},{},[1597],{"nodeType":1294,"data":1598,"content":1599},{},[1600,1604,1613],{"nodeType":1293,"value":1601,"marks":1602,"data":1603},"Researchers at threat intelligence provider ",[],{},{"nodeType":1401,"data":1605,"content":1607},{"uri":1606},"https://go.recordedfuture.com/hubfs/reports/ta-2024-0321.pdf",[1608],{"nodeType":1293,"value":1609,"marks":1610,"data":1612},"Recorded Future",[1611],{"type":1566},{},{"nodeType":1293,"value":1614,"marks":1615,"data":1616}," found a 135% increase last year in the number of harvested credentials among their data sources, and a 166% increase in credentials that included cookies, providing an easy way for attackers to bypass MFA protections.",[],{},{"nodeType":1485,"data":1618,"content":1619},{},[1620],{"nodeType":1294,"data":1621,"content":1622},{},[1623,1627,1636,1640,1649],{"nodeType":1293,"value":1624,"marks":1625,"data":1626},"Meanwhile, Mandiant’s last two ",[],{},{"nodeType":1401,"data":1628,"content":1630},{"uri":1629},"https://cloud.google.com/security/resources/m-trends",[1631],{"nodeType":1293,"value":1632,"marks":1633,"data":1635},"M-Trends reports",[1634],{"type":1566},{},{"nodeType":1293,"value":1637,"marks":1638,"data":1639}," found that stolen creds were the third and fourth most-used initial intrusion method of the last two years. Cisco Talos researchers found that the ",[],{},{"nodeType":1401,"data":1641,"content":1643},{"uri":1642},"https://blog.talosintelligence.com/cisco-talos-2023-year-in-review/",[1644],{"nodeType":1293,"value":1645,"marks":1646,"data":1648},"use of valid accounts",[1647],{"type":1566},{},{"nodeType":1293,"value":1650,"marks":1651,"data":1652}," was the second-most common attack technique they observed last year.",[],{},{"nodeType":1485,"data":1654,"content":1655},{},[1656],{"nodeType":1294,"data":1657,"content":1658},{},[1659],{"nodeType":1293,"value":1660,"marks":1661,"data":1662},"Push’s own review of the 25 most notable public identity-related breaches over the last year found that 23 were tied to stolen credentials.",[],{},{"nodeType":1294,"data":1664,"content":1665},{},[1666],{"nodeType":1293,"value":1667,"marks":1668,"data":1669},"What’s not immediately obvious from these statistics is that not only are credential-based attacks becoming more common, but they’re also becoming easier for attackers to execute.",[],{},{"nodeType":1294,"data":1671,"content":1672},{},[1673,1676,1684],{"nodeType":1293,"value":37,"marks":1674,"data":1675},[],{},{"nodeType":1401,"data":1677,"content":1678},{"uri":1583},[1679],{"nodeType":1293,"value":1680,"marks":1681,"data":1683},"IBM X-Force researchers",[1682],{"type":1566},{},{"nodeType":1293,"value":1685,"marks":1686,"data":1687}," have found that credentials for cloud accounts account for 90% of all cloud assets for sale on the dark web, making them readily accessible. Price tags can be as low as $10.",[],{},{"nodeType":1459,"data":1689,"content":1690},{},[1691],{"nodeType":1293,"value":1692,"marks":1693,"data":1694},"The rise of infostealers has supercharged the stolen credential marketplace",[],{},{"nodeType":1294,"data":1696,"content":1697},{},[1698,1702,1711],{"nodeType":1293,"value":1699,"marks":1700,"data":1701},"One category of threat — infostealer malware — has emerged as an especially successful avenue of compromise. While infostealers aren’t new, they have developed alongside what is now a robust economy for stolen credentials (think: dedicated Telegram channels advertising stolen data from the most popular infostealers), making them a fruitful option for attackers. For a deeper dive on the rise of infostealers, see our ",[],{},{"nodeType":1401,"data":1703,"content":1705},{"uri":1704},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/",[1706],{"nodeType":1293,"value":1707,"marks":1708,"data":1710},"previous article",[1709],{"type":1566},{},{"nodeType":1293,"value":1712,"marks":1713,"data":1714},".",[],{},{"nodeType":1294,"data":1716,"content":1717},{},[1718],{"nodeType":1293,"value":1719,"marks":1720,"data":1721},"Once attackers gain possession of stolen creds, they have plenty of soft targets. For organizations with a large amount of SaaS — a percentage of which will always be unmanaged shadow IT or freemium — the risk is heightened because all attackers need to do is log in to potentially hundreds of services, dump the data they find (including additional creds in some cases), and profit. ",[],{},{"nodeType":1294,"data":1723,"content":1724},{},[1725,1729,1739],{"nodeType":1293,"value":1726,"marks":1727,"data":1728},"In other words, the average attack path for SaaS is shorter and occurs in-app, often using legitimate workflows, making it therefore harder to detect than traditional network exploits. We discuss this phenomenon in our ",[],{},{"nodeType":1401,"data":1730,"content":1732},{"uri":1731},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[1733],{"nodeType":1293,"value":1734,"marks":1735,"data":1738},"shifting detection left",[1736,1737],{"type":1566},{"type":1387},{},{"nodeType":1293,"value":1740,"marks":1741,"data":1742}," article.",[],{},{"nodeType":1294,"data":1744,"content":1745},{},[1746],{"nodeType":1293,"value":1747,"marks":1748,"data":1749},"Our take: We haven’t yet seen the peak of identity attacks that leverage compromised credentials. The opportunities for attackers are too numerous, and front-line defenses like MFA are still not widely enough enforced, particularly on unmanaged apps used for work.",[],{},{"nodeType":1294,"data":1751,"content":1752},{},[1753,1757,1766],{"nodeType":1293,"value":1754,"marks":1755,"data":1756},"Push Security’s ",[],{},{"nodeType":1401,"data":1758,"content":1760},{"uri":1759},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[1761],{"nodeType":1293,"value":1762,"marks":1763,"data":1765},"own research",[1764],{"type":1566},{},{"nodeType":1293,"value":1767,"marks":1768,"data":1769}," has found that 37% of corporate identities are using passwords with no MFA. For attackers in possession of stolen creds, these are easy marks.",[],{},{"nodeType":1326,"data":1771,"content":1772},{},[],{"nodeType":1437,"data":1774,"content":1775},{},[1776],{"nodeType":1293,"value":1777,"marks":1778,"data":1779},"How Push detects stolen creds with high confidence",[],{},{"nodeType":1294,"data":1781,"content":1782},{},[1783],{"nodeType":1293,"value":1784,"marks":1785,"data":1786},"Now let’s take a look at how Push’s approach to this problem is different.",[],{},{"nodeType":1294,"data":1788,"content":1789},{},[1790],{"nodeType":1293,"value":1791,"marks":1792,"data":1793},"If you’re not familiar with the Push platform, a bit of context will be useful here: Push uses a browser agent deployed to employee browsers (we support all major browsers) to prevent, detect, and block identity attacks. ",[],{},{"nodeType":1294,"data":1795,"content":1796},{},[1797,1801,1810,1814,1823],{"nodeType":1293,"value":1798,"marks":1799,"data":1800},"In addition to enforcing ",[],{},{"nodeType":1401,"data":1802,"content":1804},{"uri":1803},"https://pushsecurity.com/blog/introducing-set-and-forget-controls-that-stop-real-world-identity-attacks/",[1805],{"nodeType":1293,"value":1806,"marks":1807,"data":1809},"security controls",[1808],{"type":1566},{},{"nodeType":1293,"value":1811,"marks":1812,"data":1813}," in the browser, Push also assesses the strength of end-user passwords by ",[],{},{"nodeType":1401,"data":1815,"content":1817},{"uri":1816},"https://pushsecurity.com/help/10065#start",[1818],{"nodeType":1293,"value":1819,"marks":1820,"data":1822},"creating and analyzing",[1821],{"type":1566},{},{"nodeType":1293,"value":1824,"marks":1825,"data":1826}," a truncated, salted SHA256 hash of the password for a given account. This is called a password fingerprint. These k-anonymized fingerprints are never seen by Push’s back-end and exist only in local browser extension storage.",[],{},{"nodeType":1294,"data":1828,"content":1829},{},[1830],{"nodeType":1293,"value":1831,"marks":1832,"data":1833},"This approach gives Push a directly observable source of truth for corporate credentials, and that data point turns out to be the key to flipping the script on how threat intelligence on stolen credentials is typically evaluated.",[],{},{"nodeType":1294,"data":1835,"content":1836},{},[1837],{"nodeType":1293,"value":1838,"marks":1839,"data":1840},"In the past, evaluating TI on stolen creds meant performing traditional intelligence assessments, such as confidence level based on factors like the intel source and whether the data was still current. Only after determining whether the information was high-confidence could you take action.",[],{},{"nodeType":1294,"data":1842,"content":1843},{},[1844,1848,1856],{"nodeType":1293,"value":1845,"marks":1846,"data":1847},"It’s worth noting, too, that the age of TI alone is not enough of an indicator to determine whether to take action. With the ",[],{},{"nodeType":1401,"data":1849,"content":1851},{"uri":1850},"https://pushsecurity.com/blog/snowflake-retro/",[1852],{"nodeType":1293,"value":1853,"marks":1854,"data":1855},"Snowflake breach earlier this year",[],{},{"nodeType":1293,"value":1857,"marks":1858,"data":1859},", we saw how even older credentials posed a threat of account takeover where these creds were still in use. In the case of Snowflake, the attacker used credentials sourced from historical infostealer campaigns, some dating as far back as 2020.",[],{},{"nodeType":1317,"data":1861,"content":1865},{"target":1862},{"sys":1863},{"id":1864,"type":1322,"linkType":1323},"2lSZ7HbZfLmSFXneCnVJzY",[],{"nodeType":1459,"data":1867,"content":1868},{},[1869],{"nodeType":1293,"value":1870,"marks":1871,"data":1872},"Forget about time-consuming manual TI validation and get straight to the true positives",[],{},{"nodeType":1294,"data":1874,"content":1875},{},[1876],{"nodeType":1293,"value":1877,"marks":1878,"data":1879},"With Push, the platform now can analyze threat intelligence on stolen credentials and alert when there’s a validated match among current credentials in use in your environment. This method works regardless of the source of the data or its age. This method also finds the needles in the haystack — situations where threat intel flags a stolen credential on one app, but that credential is also in use on several other apps. ",[],{},{"nodeType":1317,"data":1881,"content":1885},{"target":1882},{"sys":1883},{"id":1884,"type":1322,"linkType":1323},"7GSFasHfHb3UgpgF8pZ2N2",[],{"nodeType":1294,"data":1887,"content":1888},{},[1889],{"nodeType":1293,"value":1890,"marks":1891,"data":1892},"Here’s how it works:",[],{},{"nodeType":1481,"data":1894,"content":1895},{},[1896,1916,1926,1936,1946],{"nodeType":1485,"data":1897,"content":1898},{},[1899],{"nodeType":1294,"data":1900,"content":1901},{},[1902,1906,1913],{"nodeType":1293,"value":1903,"marks":1904,"data":1905},"Push receives TI on stolen credentials from vendor feeds. Use the feeds that Push supplies (at no additional cost for Push customers), or, additionally, bring your own TI by supplying stolen credential reports via the ",[],{},{"nodeType":1401,"data":1907,"content":1909},{"uri":1908},"https://pushsecurity.redoc.ly/rest-v1#operation/post-controls-stolenCredentials",[1910],{"nodeType":1293,"value":1406,"marks":1911,"data":1912},[],{},{"nodeType":1293,"value":1390,"marks":1914,"data":1915},[],{},{"nodeType":1485,"data":1917,"content":1918},{},[1919],{"nodeType":1294,"data":1920,"content":1921},{},[1922],{"nodeType":1293,"value":1923,"marks":1924,"data":1925},"For each customer environment, Push checks for customer domains in the data set.",[],{},{"nodeType":1485,"data":1927,"content":1928},{},[1929],{"nodeType":1294,"data":1930,"content":1931},{},[1932],{"nodeType":1293,"value":1933,"marks":1934,"data":1935},"When suspected stolen creds for a customer environment are present, Push hashes and salts the passwords and then sends those fingerprints to the relevant browser agents for comparison. ",[],{},{"nodeType":1485,"data":1937,"content":1938},{},[1939],{"nodeType":1294,"data":1940,"content":1941},{},[1942],{"nodeType":1293,"value":1943,"marks":1944,"data":1945},"If the stolen credential fingerprint matches a known credential fingerprint observed to be in use by the Push browser agent, the platform returns a validated true positive alert. Note that Push can alert on a validated true positive regardless of which platform the TI source indicated was the source of the stolen cred, allowing you to find those compromised credentials in use across any of your apps.",[],{},{"nodeType":1485,"data":1947,"content":1948},{},[1949],{"nodeType":1294,"data":1950,"content":1951},{},[1952],{"nodeType":1293,"value":1953,"marks":1954,"data":1955},"You can choose to receive alerts for this detection via webhook, ChatOps notification, or in the Push admin console.",[],{},{"nodeType":1294,"data":1957,"content":1958},{},[1959],{"nodeType":1293,"value":1960,"marks":1961,"data":1962},"From there, security teams can take action to reset passwords, identify potentially compromised devices, or perform other investigations.",[],{},{"nodeType":1294,"data":1964,"content":1965},{},[1966],{"nodeType":1293,"value":1967,"marks":1968,"data":1969},"By comparing all possible matches to only those credentials that are still in use, Push eliminates time-consuming validation exercises. In essence, the provenance of the intel no longer matters; only the true positives do.",[],{},{"nodeType":1459,"data":1971,"content":1972},{},[1973],{"nodeType":1293,"value":1974,"marks":1975,"data":1976},"Bring your own TI",[],{},{"nodeType":1294,"data":1978,"content":1979},{},[1980],{"nodeType":1293,"value":1981,"marks":1982,"data":1983},"With verified stolen credential detection, you can also extract a lot more value from your existing threat intelligence feeds by sharing stolen creds reports with the Push platform via API. ",[],{},{"nodeType":1294,"data":1985,"content":1986},{},[1987],{"nodeType":1293,"value":1988,"marks":1989,"data":1990},"This allows Push to perform the same checks to compare the reports to observed password fingerprints and flag only the true positives — eliminating the time-consuming work of manual triage, investigation, and end-user follow-up for your security team.",[],{},{"nodeType":1326,"data":1992,"content":1993},{},[],{"nodeType":1437,"data":1995,"content":1996},{},[1997],{"nodeType":1293,"value":1998,"marks":1999,"data":2000},"Try Push for yourself",[],{},{"nodeType":1294,"data":2002,"content":2003},{},[2004,2008,2017],{"nodeType":1293,"value":2005,"marks":2006,"data":2007},"The validated stolen credential detections feature is available at no additional cost for all Push customers. If you’d like to explore the platform yourself, ",[],{},{"nodeType":1401,"data":2009,"content":2011},{"uri":2010},"https://pushsecurity.com/demo/",[2012],{"nodeType":1293,"value":2013,"marks":2014,"data":2016},"request a demo",[2015],{"type":1566},{},{"nodeType":1293,"value":2018,"marks":2019,"data":2020},". ",[],{},{"nodeType":1317,"data":2022,"content":2026},{"target":2023},{"sys":2024},{"id":2025,"type":1322,"linkType":1323},"3tqVk7Vr7pYLOEVukIJM2g",[],{"nodeType":1294,"data":2028,"content":2029},{},[2030],{"nodeType":1293,"value":37,"marks":2031,"data":2032},[],{},"Eliminate false positives with verified stolen credential detections using Push","Push now compares user passwords with TI feeds to alert you when valid credentials are available on the clearweb and darkweb.","2024-12-03T00:00:00.000Z","verified-stolen-credential-detection",{"items":2038},[2039,2043],{"sys":2040,"name":2042},{"id":2041},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"sys":2044,"name":2046},{"id":2045},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":2048},[2049],{"fullName":2050,"firstName":2051,"jobTitle":2052,"profilePicture":2053},"Kelly Davenport","Kelly","Product Team",{"url":2054},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1309,"sys":2056,"content":2058,"title":2378,"synopsis":2379,"hashTags":118,"publishedDate":2380,"slug":2381,"tagsCollection":2382,"authorsCollection":2390},{"id":2057},"75wcCkoZEKwEMl7zBmDMtT",{"json":2059},{"data":2060,"content":2061,"nodeType":1295},{},[2062,2069,2076,2095,2114,2137,2144,2160,2167,2174,2181,2184,2191,2211,2230,2236,2256,2263,2270,2276,2283,2289,2322,2329,2349,2352,2359,2366,2372],{"data":2063,"content":2064,"nodeType":1437},{},[2065],{"data":2066,"marks":2067,"value":2068,"nodeType":1293},{},[],"Preventing credential attacks with automated password resets ",{"data":2070,"content":2071,"nodeType":1294},{},[2072],{"data":2073,"marks":2074,"value":2075,"nodeType":1293},{},[],"Preventing credential attacks is not an easy task, especially if you’re a member of the security team tasked with protecting some of your organization’s most valued assets: SSO identities.",{"data":2077,"content":2078,"nodeType":1294},{},[2079,2083,2092],{"data":2080,"marks":2081,"value":2082,"nodeType":1293},{},[],"IdP accounts such as a user’s Okta, Entra, or Google Workspace login are the most lucrative identities that an attacker can take over. By compromising an SSO identity, attackers not only gain access to the account itself, but also any downstream apps accessed via SSO – and the juicy data and functionality stored there. This was evidenced earlier this year when ",{"data":2084,"content":2086,"nodeType":1401},{"uri":2085},"https://www.bleepingcomputer.com/news/security/okta-warns-of-unprecedented-credential-stuffing-attacks-on-customers/",[2087],{"data":2088,"marks":2089,"value":2091,"nodeType":1293},{},[2090],{"type":1566},"Okta users experienced unprecedented levels of credential stuffing attacks",{"data":2093,"marks":2094,"value":2018,"nodeType":1293},{},[],{"data":2096,"content":2097,"nodeType":1294},{},[2098,2102,2110],{"data":2099,"marks":2100,"value":2101,"nodeType":1293},{},[],"You might also be surprised to learn that even these most critical accounts have serious security gaps. For example, ",{"data":2103,"content":2104,"nodeType":1401},{"uri":1759},[2105],{"data":2106,"marks":2107,"value":2109,"nodeType":1293},{},[2108],{"type":1566},"in a recent study we identified that",{"data":2111,"marks":2112,"value":2113,"nodeType":1293},{},[],":",{"data":2115,"content":2116,"nodeType":1481},{},[2117,2127],{"data":2118,"content":2119,"nodeType":1485},{},[2120],{"data":2121,"content":2122,"nodeType":1294},{},[2123],{"data":2124,"marks":2125,"value":2126,"nodeType":1293},{},[],"1 in 5 IdP accounts does not have an MFA method set, leaving them exposed to single-factor compromises using stolen credentials.",{"data":2128,"content":2129,"nodeType":1485},{},[2130],{"data":2131,"content":2132,"nodeType":1294},{},[2133],{"data":2134,"marks":2135,"value":2136,"nodeType":1293},{},[],"10% of IdP accounts share a password that is used to access other identities. (We’re not talking about the actual SSO process here – many users will use the same password as they do to log into their Okta or Entra as they do personal accounts such as shopping or food delivery. Yes, really.)  ",{"data":2138,"content":2139,"nodeType":1294},{},[2140],{"data":2141,"marks":2142,"value":2143,"nodeType":1293},{},[],"It’s a constant worry that your CFO’s Microsoft, Google, or Okta credentials are going to show up in the next big darkweb password dump. Ideally you’d want to prevent users from reusing passwords across multiple services. That’s why your information security policy is mandating password manager use, right?",{"data":2145,"content":2146,"nodeType":1294},{},[2147,2151,2156],{"data":2148,"marks":2149,"value":2150,"nodeType":1293},{},[],"No matter how many policies you have in place, ",{"data":2152,"marks":2153,"value":2155,"nodeType":1293},{},[2154],{"type":1566},"people will inevitably use the same passwords across multiple services",{"data":2157,"marks":2158,"value":2159,"nodeType":1293},{},[],". But who can blame them? Having to remember multiple passwords is a drag, especially when they find they can’t log into their company’s password manager from their home computers… The next best thing is to just reuse your Entra or Okta password across all services, right?!",{"data":2161,"content":2162,"nodeType":1294},{},[2163],{"data":2164,"marks":2165,"value":2166,"nodeType":1293},{},[],"At Push we realize that mistakes happen. That's why it's important to look out for when critical credentials are entered into a dodgy ecommerce platform, or the next entry lands on haveibeenpwnd.com.",{"data":2168,"content":2169,"nodeType":1294},{},[2170],{"data":2171,"marks":2172,"value":2173,"nodeType":1293},{},[],"By quickly forcing a password change when an SSO password is reused or breached, we can minimize the chance of it being abused by attackers. ",{"data":2175,"content":2176,"nodeType":1294},{},[2177],{"data":2178,"marks":2179,"value":2180,"nodeType":1293},{},[],"But how will you know when a password is reused or compromised? ",{"data":2182,"content":2183,"nodeType":1326},{},[],{"data":2185,"content":2186,"nodeType":1437},{},[2187],{"data":2188,"marks":2189,"value":2190,"nodeType":1293},{},[],"Using Push data to alert on password vulnerabilities ",{"data":2192,"content":2193,"nodeType":1294},{},[2194,2198,2207],{"data":2195,"marks":2196,"value":2197,"nodeType":1293},{},[],"Enter the Push browser extension. Push fingerprints passwords (",{"data":2199,"content":2201,"nodeType":1401},{"uri":2200},"https://pushsecurity.com/help/how-does-the-push-browser-extension-securely-track-reused-passwords",[2202],{"data":2203,"marks":2204,"value":2206,"nodeType":1293},{},[2205],{"type":1566},"in a safe way",{"data":2208,"marks":2209,"value":2210,"nodeType":1293},{},[],") as they are used by employees to access apps in their browsers. ",{"data":2212,"content":2213,"nodeType":1294},{},[2214,2218,2227],{"data":2215,"marks":2216,"value":2217,"nodeType":1293},{},[],"When a user logs into an app using credentials that they’ve previously used to login to another account, Push fires off an alert. ",{"data":2219,"content":2221,"nodeType":1401},{"uri":2220},"https://pushsecurity.com/blog/verified-stolen-credential-detection/",[2222],{"data":2223,"marks":2224,"value":2226,"nodeType":1293},{},[2225],{"type":1566},"We can also detect when an active password is stolen and appears on a criminal forum",{"data":2228,"marks":2229,"value":2018,"nodeType":1293},{},[],{"data":2231,"content":2235,"nodeType":1317},{"target":2232},{"sys":2233},{"id":2234,"type":1322,"linkType":1323},"5He3FB0NT3D3lcbwiVtn02",[],{"data":2237,"content":2238,"nodeType":1294},{},[2239,2243,2252],{"data":2240,"marks":2241,"value":2242,"nodeType":1293},{},[],"If you’ve ",{"data":2244,"content":2246,"nodeType":1401},{"uri":2245},"https://pushsecurity.com/help/audience/administrators/docs/connect-to-siem-or-soar/#start",[2247],{"data":2248,"marks":2249,"value":2251,"nodeType":1293},{},[2250],{"type":1566},"connected Push to your SIEM or SOAR",{"data":2253,"marks":2254,"value":2255,"nodeType":1293},{},[],", you’ll be able to create a workflow to respond automatically. ",{"data":2257,"content":2258,"nodeType":1459},{},[2259],{"data":2260,"marks":2261,"value":2262,"nodeType":1293},{},[],"Automating password resets in your SIEM using Push webhooks",{"data":2264,"content":2265,"nodeType":1294},{},[2266],{"data":2267,"marks":2268,"value":2269,"nodeType":1293},{},[],"You can automate password resets for accounts by ingesting this information via webhook into a SIEM, generating an alert. This in turn can fire off another webhook or workflow that sets the ‘force password change on next logon’ attribute on the user’s account.",{"data":2271,"content":2275,"nodeType":1317},{"target":2272},{"sys":2273},{"id":2274,"type":1322,"linkType":1323},"5WFLIVm4DWcuH7a6owQlR1",[],{"data":2277,"content":2278,"nodeType":1294},{},[2279],{"data":2280,"marks":2281,"value":2282,"nodeType":1293},{},[],"Below is some POC python code we use internally. This is specific to Google Workspace, but the general logic should apply to any IdP that allows you to perform these actions via API calls.",{"data":2284,"content":2288,"nodeType":1317},{"target":2285},{"sys":2286},{"id":2287,"type":1322,"linkType":1323},"4YNirRo8BlRrgGKwwzXE8R",[],{"data":2290,"content":2291,"nodeType":1294},{},[2292,2296,2305,2309,2318],{"data":2293,"marks":2294,"value":2295,"nodeType":1293},{},[],"You can perform similar functions in Microsoft Entra ID by modifying the user's ",{"data":2297,"content":2299,"nodeType":1401},{"uri":2298},"https://learn.microsoft.com/en-us/graph/api/user-update?view=graph-rest-1.0&tabs=http#:~:text=DisablePasswordExpiration%2C%20DisableStrongPassword.-,passwordProfile,-PasswordProfile",[2300],{"data":2301,"marks":2302,"value":2304,"nodeType":1293},{},[2303],{"type":1566},"passwordProfile",{"data":2306,"marks":2307,"value":2308,"nodeType":1293},{},[]," attribute via Microsoft Graph API, or in Okta via the ",{"data":2310,"content":2312,"nodeType":1401},{"uri":2311},"https://developer.okta.com/docs/api/openapi/okta-management/management/tag/UserCred/#tag/UserCred/operation/expirePassword",[2313],{"data":2314,"marks":2315,"value":2317,"nodeType":1293},{},[2316],{"type":1566},"expire_password",{"data":2319,"marks":2320,"value":2321,"nodeType":1293},{},[]," API endpoint.",{"data":2323,"content":2324,"nodeType":1294},{},[2325],{"data":2326,"marks":2327,"value":2328,"nodeType":1293},{},[],"You aren’t limited to just IdP accounts either – any app with an API that provides this functionality can be configured for automated password resets using Push data. ",{"data":2330,"content":2331,"nodeType":1294},{},[2332,2336,2345],{"data":2333,"marks":2334,"value":2335,"nodeType":1293},{},[],"We also use SSO password data to ",{"data":2337,"content":2339,"nodeType":1401},{"uri":2338},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[2340],{"data":2341,"marks":2342,"value":2344,"nodeType":1293},{},[2343],{"type":1566},"prevent users from entering their SSO credentials into phishing sites",{"data":2346,"marks":2347,"value":2348,"nodeType":1293},{},[],", providing strong anti-phishing protection that is extremely hard for attackers to bypass. ",{"data":2350,"content":2351,"nodeType":1326},{},[],{"data":2353,"content":2354,"nodeType":1437},{},[2355],{"data":2356,"marks":2357,"value":2358,"nodeType":1293},{},[],"Preventing attackers from exploiting vulnerable credentials has never been easier",{"data":2360,"content":2361,"nodeType":1294},{},[2362],{"data":2363,"marks":2364,"value":2365,"nodeType":1293},{},[],"This is just one of the possible SecOps use cases that Push streamlines and levels up for security teams. To find out more about Push’s browser-based ITDR platform and our other great features, book a demo. ",{"data":2367,"content":2371,"nodeType":1317},{"target":2368},{"sys":2369},{"id":2370,"type":1322,"linkType":1323},"11p9wnGrZHqp3XPpThHFk3",[],{"data":2373,"content":2374,"nodeType":1294},{},[2375],{"data":2376,"marks":2377,"value":37,"nodeType":1293},{},[],"Automating SSO password resets using Push","Using Push to automate password resets for your most critical identities when a password vulnerability is detected.","2024-12-13T00:00:00.000Z","automating-sso-password-resets-using-push",{"items":2383},[2384,2388],{"sys":2385,"name":2387},{"id":2386},"3pjES4THCIfSAwhGdNwBcy","Identity security",{"sys":2389,"name":2046},{"id":2045},{"items":2391},[2392],{"fullName":2393,"firstName":2394,"jobTitle":2395,"profilePicture":2396},"Johann Scheepers","Johann","Senior Security Engineer",{"url":2397},"https://images.ctfassets.net/y1cdw1ablpvd/75IEOH93vR0hbvxuqTu1m3/f6222745ee6892ea07bc18727a5a5ae7/T016S22KZ96-U02LU3SKC2D-e1e755770536-512.png",{"__typename":1309,"sys":2399,"content":2401,"title":3922,"synopsis":3923,"hashTags":118,"publishedDate":3924,"slug":3925,"tagsCollection":3926,"authorsCollection":3930},{"id":2400},"3lWfiuAMsVecxVyEKiwV0c",{"json":2402},{"nodeType":1295,"data":2403,"content":2404},{},[2405,2412,2419,2435,2441,2460,2467,2474,2477,2484,2491,2572,2579,2586,2593,2600,2607,2614,2629,2635,2721,2728,2735,2772,2779,2785,2792,2808,2919,2943,2949,2956,2972,2978,2981,2988,2995,3010,3017,3024,3031,3054,3075,3081,3088,3095,3102,3118,3124,3162,3168,3175,3208,3220,3227,3234,3241,3292,3299,3305,3312,3315,3322,3329,3336,3343,3397,3411,3462,3494,3501,3567,3573,3580,3633,3652,3659,3675,3713,3720,3727,3734,3761,3767,3770,3777,3784,3791,3903,3910,3916],{"nodeType":1437,"data":2406,"content":2407},{},[2408],{"nodeType":1293,"value":2409,"marks":2410,"data":2411},"The journey ahead",[],{},{"nodeType":1294,"data":2413,"content":2414},{},[2415],{"nodeType":1293,"value":2416,"marks":2417,"data":2418},"So you’ve chosen Push to accompany you on your identity security journey. Good choice! We’ve got (threat) hunting supplies and a sturdy raft. It’s risky to go alone, though, so take this map with you.",[],{},{"nodeType":1294,"data":2420,"content":2421},{},[2422,2426,2431],{"nodeType":1293,"value":2423,"marks":2424,"data":2425},"Inspired by the classic 1980s video game* ",[],{},{"nodeType":1293,"value":2427,"marks":2428,"data":2430},"Oregon Trail",[2429],{"type":312},{},{"nodeType":1293,"value":2432,"marks":2433,"data":2434},", we’ve put together the following guide for intrepid security teams who are traveling across potentially unknown territory as they uncover their identity attack surface, including shadow identities and apps, and secure it against modern identity attacks.",[],{},{"nodeType":1317,"data":2436,"content":2440},{"target":2437},{"sys":2438},{"id":2439,"type":1322,"linkType":1323},"3Ys8l6lqQcWOFX5O6QSulO",[],{"nodeType":1294,"data":2442,"content":2443},{},[2444,2448,2456],{"nodeType":1293,"value":2445,"marks":2446,"data":2447},"(*For Push fans outside the U.S., Oregon Trail followed a group of pioneers as they attempted to cross the continent in a covered wagon, avoiding wild animals and hunting for food along the way. The ",[],{},{"nodeType":1401,"data":2449,"content":2451},{"uri":2450},"https://knowyourmeme.com/memes/subcultures/the-oregon-trail",[2452],{"nodeType":1293,"value":2453,"marks":2454,"data":2455},"memes",[],{},{"nodeType":1293,"value":2457,"marks":2458,"data":2459}," now outlive the game, but we remember it fondly.)",[],{},{"nodeType":1294,"data":2461,"content":2462},{},[2463],{"nodeType":1293,"value":2464,"marks":2465,"data":2466},"In this guide, we’ll provide advice on what you can accomplish in your first three months after deploying Push to your workforce, transforming your employees’ browsers into a reliable control point to enforce a strong identity posture and stop account takeover.",[],{},{"nodeType":1294,"data":2468,"content":2469},{},[2470],{"nodeType":1293,"value":2471,"marks":2472,"data":2473},"In your first 90 days using Push, you can go far. Let’s take a look.",[],{},{"nodeType":1326,"data":2475,"content":2476},{},[],{"nodeType":1437,"data":2478,"content":2479},{},[2480],{"nodeType":1293,"value":2481,"marks":2482,"data":2483},"First 30 days: Get intel and secure against bears",[],{},{"nodeType":1294,"data":2485,"content":2486},{},[2487],{"nodeType":1293,"value":2488,"marks":2489,"data":2490},"This guide assumes you’ve identified a few identity security goals already. These probably include things like:",[],{},{"nodeType":1481,"data":2492,"content":2493},{},[2494,2518,2542,2552,2562],{"nodeType":1485,"data":2495,"content":2496},{},[2497],{"nodeType":1294,"data":2498,"content":2499},{},[2500,2504,2515],{"nodeType":1293,"value":2501,"marks":2502,"data":2503},"Closing gaps in existing security controls to protect against MFA bypass attacks like Adversary-in-the-Middle ",[],{},{"nodeType":2505,"data":2506,"content":2510},"entry-hyperlink",{"target":2507},{"sys":2508},{"id":2509,"type":1322,"linkType":1323},"11C3shj5SlkS8sAd3AlYDp",[2511],{"nodeType":1293,"value":2512,"marks":2513,"data":2514},"(AiTM) phishing toolkits",[],{},{"nodeType":1293,"value":1712,"marks":2516,"data":2517},[],{},{"nodeType":1485,"data":2519,"content":2520},{},[2521],{"nodeType":1294,"data":2522,"content":2523},{},[2524,2528,2538],{"nodeType":1293,"value":2525,"marks":2526,"data":2527},"Increasing ",[],{},{"nodeType":2505,"data":2529,"content":2533},{"target":2530},{"sys":2531},{"id":2532,"type":1322,"linkType":1323},"1qegIy4rMdm5XZXnIEoKpE",[2534],{"nodeType":1293,"value":2535,"marks":2536,"data":2537},"visibility of user activity",[],{},{"nodeType":1293,"value":2539,"marks":2540,"data":2541}," in the browser to identify and respond to threats.",[],{},{"nodeType":1485,"data":2543,"content":2544},{},[2545],{"nodeType":1294,"data":2546,"content":2547},{},[2548],{"nodeType":1293,"value":2549,"marks":2550,"data":2551},"Using federated SSO-based logins over password-based logins to limit the number of identities created, and removing unused login methods.",[],{},{"nodeType":1485,"data":2553,"content":2554},{},[2555],{"nodeType":1294,"data":2556,"content":2557},{},[2558],{"nodeType":1293,"value":2559,"marks":2560,"data":2561},"Implementing phishing-resistant authentication methods, and removing phishable ones.",[],{},{"nodeType":1485,"data":2563,"content":2564},{},[2565],{"nodeType":1294,"data":2566,"content":2567},{},[2568],{"nodeType":1293,"value":2569,"marks":2570,"data":2571},"Where password use cannot be avoided, ensuring good hygiene (no weak, reused, or breached passwords) and phishing-resistant MFA factors.",[],{},{"nodeType":1294,"data":2573,"content":2574},{},[2575],{"nodeType":1293,"value":2576,"marks":2577,"data":2578},"Then, once you’ve deployed the Push browser extension to your browser ecosystem, invited your security team to the Push admin console, and begun collecting behavioral and identity posture data from your employees’ login activity, you’re ready to embark.",[],{},{"nodeType":1294,"data":2580,"content":2581},{},[2582],{"nodeType":1293,"value":2583,"marks":2584,"data":2585},"Right away, you can set up your first out-of-the-box security control to provide novel and effective protection against adversary-in-the-middle (AiTM) phishing toolkits such as Evilginx, EvilNoVNC, and others.",[],{},{"nodeType":1294,"data":2587,"content":2588},{},[2589],{"nodeType":1293,"value":2590,"marks":2591,"data":2592},"It’s the identity security equivalent of bear deterrent (something sadly lacking on the Oregon Trail), and it takes just a couple of minutes.",[],{},{"nodeType":1294,"data":2594,"content":2595},{},[2596],{"nodeType":1293,"value":2597,"marks":2598,"data":2599},"You can also set additional security controls in Monitor mode and begin collecting valuable insights from your users’ account and app activity.",[],{},{"nodeType":1294,"data":2601,"content":2602},{},[2603],{"nodeType":1293,"value":2604,"marks":2605,"data":2606},"Here’s what we recommend for your first 30 days using Push:",[],{},{"nodeType":1459,"data":2608,"content":2609},{},[2610],{"nodeType":1293,"value":2611,"marks":2612,"data":2613},"Enable phishing tool detection in Warn or Block mode",[],{},{"nodeType":1294,"data":2615,"content":2616},{},[2617,2621,2626],{"nodeType":1293,"value":2618,"marks":2619,"data":2620},"Begin protecting employees from adversary-in-the-middle phishing from AitM tools by enabling ",[],{},{"nodeType":1293,"value":2622,"marks":2623,"data":2625},"Phishing tool detection",[2624],{"type":1387},{},{"nodeType":1293,"value":1712,"marks":2627,"data":2628},[],{},{"nodeType":1317,"data":2630,"content":2634},{"target":2631},{"sys":2632},{"id":2633,"type":1322,"linkType":1323},"2ylIkR0JXHkFStGuCFRjlN",[],{"nodeType":1481,"data":2636,"content":2637},{},[2638,2682,2692,2702],{"nodeType":1485,"data":2639,"content":2640},{},[2641],{"nodeType":1294,"data":2642,"content":2643},{},[2644,2648,2653,2657,2661,2665,2670,2674,2679],{"nodeType":1293,"value":2645,"marks":2646,"data":2647},"From the ",[],{},{"nodeType":1293,"value":2649,"marks":2650,"data":2652},"Controls",[2651],{"type":1387},{},{"nodeType":1293,"value":2654,"marks":2655,"data":2656}," page in the Push admin console, select ",[],{},{"nodeType":1293,"value":2622,"marks":2658,"data":2660},[2659],{"type":1387},{},{"nodeType":1293,"value":2662,"marks":2663,"data":2664}," and set the mode to ",[],{},{"nodeType":1293,"value":2666,"marks":2667,"data":2669},"Warn",[2668],{"type":1387},{},{"nodeType":1293,"value":2671,"marks":2672,"data":2673}," or ",[],{},{"nodeType":1293,"value":2675,"marks":2676,"data":2678},"Block",[2677],{"type":1387},{},{"nodeType":1293,"value":1712,"marks":2680,"data":2681},[],{},{"nodeType":1485,"data":2683,"content":2684},{},[2685],{"nodeType":1294,"data":2686,"content":2687},{},[2688],{"nodeType":1293,"value":2689,"marks":2690,"data":2691},"Customize the message that employees will see if they encounter a malicious site.",[],{},{"nodeType":1485,"data":2693,"content":2694},{},[2695],{"nodeType":1294,"data":2696,"content":2697},{},[2698],{"nodeType":1293,"value":2699,"marks":2700,"data":2701},"Add domains to the ignore list if you wish to ignore enforcing the control on specific domains or encounter any domains that trigger false positives.",[],{},{"nodeType":1485,"data":2703,"content":2704},{},[2705],{"nodeType":1294,"data":2706,"content":2707},{},[2708,2712,2717],{"nodeType":1293,"value":2709,"marks":2710,"data":2711},"You can monitor the ",[],{},{"nodeType":1293,"value":2713,"marks":2714,"data":2716},"Events",[2715],{"type":1387},{},{"nodeType":1293,"value":2718,"marks":2719,"data":2720}," page (or send Push events to an external SIEM or SOAR) to see when the control is triggered.",[],{},{"nodeType":1294,"data":2722,"content":2723},{},[2724],{"nodeType":1293,"value":2725,"marks":2726,"data":2727},"You may also wish to communicate with your end-users to let them know you’re enabling a new security protection to stop phishing attacks and that if they encounter a malicious site, they’ll see a warning.",[],{},{"nodeType":1459,"data":2729,"content":2730},{},[2731],{"nodeType":1293,"value":2732,"marks":2733,"data":2734},"Check for verified stolen credentials",[],{},{"nodeType":1294,"data":2736,"content":2737},{},[2738,2742,2751,2755,2760,2764,2769],{"nodeType":1293,"value":2739,"marks":2740,"data":2741},"Push uses threat intelligence sources to compare suspected ",[],{},{"nodeType":2505,"data":2743,"content":2746},{"target":2744},{"sys":2745},{"id":1311,"type":1322,"linkType":1323},[2747],{"nodeType":1293,"value":2748,"marks":2749,"data":2750},"stolen credentials",[],{},{"nodeType":1293,"value":2752,"marks":2753,"data":2754}," to those still actively in use across your workforce identities. You don’t need to configure anything for this feature, and you can check for any verified true positives by viewing the ",[],{},{"nodeType":1293,"value":2756,"marks":2757,"data":2759},"Vulnerable identities",[2758],{"type":1387},{},{"nodeType":1293,"value":2761,"marks":2762,"data":2763}," section of the ",[],{},{"nodeType":1293,"value":2765,"marks":2766,"data":2768},"Dashboard",[2767],{"type":1387},{},{"nodeType":1293,"value":1390,"marks":2770,"data":2771},[],{},{"nodeType":1294,"data":2773,"content":2774},{},[2775],{"nodeType":1293,"value":2776,"marks":2777,"data":2778},"We recommend investigating immediately and taking action to remediate any accounts with verified stolen credentials.",[],{},{"nodeType":1317,"data":2780,"content":2784},{"target":2781},{"sys":2782},{"id":2783,"type":1322,"linkType":1323},"150dE4aTzofOwFXJCtGkJF",[],{"nodeType":1459,"data":2786,"content":2787},{},[2788],{"nodeType":1293,"value":2789,"marks":2790,"data":2791},"Enable additional security controls in Monitor mode",[],{},{"nodeType":1294,"data":2793,"content":2794},{},[2795,2799,2804],{"nodeType":1293,"value":2796,"marks":2797,"data":2798},"Next, set up additional security controls in ",[],{},{"nodeType":1293,"value":2800,"marks":2801,"data":2803},"Monitor",[2802],{"type":1387},{},{"nodeType":1293,"value":2805,"marks":2806,"data":2807}," mode so you can begin finetuning your configuration or adding to ignore lists. A few details to keep in mind:",[],{},{"nodeType":1481,"data":2809,"content":2810},{},[2811,2850,2873,2896],{"nodeType":1485,"data":2812,"content":2813},{},[2814],{"nodeType":1294,"data":2815,"content":2816},{},[2817,2822,2826,2837,2841,2846],{"nodeType":1293,"value":2818,"marks":2819,"data":2821},"For all controls",[2820],{"type":1387},{},{"nodeType":1293,"value":2823,"marks":2824,"data":2825},", update your ",[],{},{"nodeType":2505,"data":2827,"content":2831},{"target":2828},{"sys":2829},{"id":2830,"type":1322,"linkType":1323},"2q4iZicL3D85XGTsYZ5mgK",[2832],{"nodeType":1293,"value":2833,"marks":2834,"data":2836},"Custom login URLs",[2835],{"type":1387},{},{"nodeType":1293,"value":2838,"marks":2839,"data":2840}," list on the ",[],{},{"nodeType":1293,"value":2842,"marks":2843,"data":2845},"Settings",[2844],{"type":1387},{},{"nodeType":1293,"value":2847,"marks":2848,"data":2849}," page to include any custom URLs you use for your identity provider or other important apps, so that Push can correctly identify those logins as belonging to your IdP (or other app).",[],{},{"nodeType":1485,"data":2851,"content":2852},{},[2853],{"nodeType":1294,"data":2854,"content":2855},{},[2856,2861,2865,2869],{"nodeType":1293,"value":2857,"marks":2858,"data":2860},"For SSO password protection",[2859],{"type":1387},{},{"nodeType":1293,"value":2862,"marks":2863,"data":2864},", we recommend starting in ",[],{},{"nodeType":1293,"value":2800,"marks":2866,"data":2868},[2867],{"type":1387},{},{"nodeType":1293,"value":2870,"marks":2871,"data":2872}," so you can identify any sites in your environment that cause false positives, such as sites that are configured to legitimately allow use of SSO credentials. Then add these sites to your ignore list. By running in monitor mode for a few weeks, you can also get a sense of how often employees are reusing their corporate IdP credentials on other sites where they shouldn’t, such as personal apps.",[],{},{"nodeType":1485,"data":2874,"content":2875},{},[2876],{"nodeType":1294,"data":2877,"content":2878},{},[2879,2884,2888,2892],{"nodeType":1293,"value":2880,"marks":2881,"data":2883},"For cloned login page detection",[2882],{"type":1387},{},{"nodeType":1293,"value":2885,"marks":2886,"data":2887},", set the mode to ",[],{},{"nodeType":1293,"value":2800,"marks":2889,"data":2891},[2890],{"type":1387},{},{"nodeType":1293,"value":2893,"marks":2894,"data":2895}," to receive events when employees visit a site using a cloned login screen for important apps including your identity provider.",[],{},{"nodeType":1485,"data":2897,"content":2898},{},[2899],{"nodeType":1294,"data":2900,"content":2901},{},[2902,2907,2911,2915],{"nodeType":1293,"value":2903,"marks":2904,"data":2906},"For URL blocking",[2905],{"type":1387},{},{"nodeType":1293,"value":2908,"marks":2909,"data":2910},", test a blocked URL or begin compiling a list of URLs you wish to block, such as AiTM sites discovered through phishing sites you find while using the ",[],{},{"nodeType":1293,"value":2622,"marks":2912,"data":2914},[2913],{"type":1387},{},{"nodeType":1293,"value":2916,"marks":2917,"data":2918}," feature.",[],{},{"nodeType":1294,"data":2920,"content":2921},{},[2922,2926,2930,2934,2939],{"nodeType":1293,"value":2923,"marks":2924,"data":2925},"To see events generated by these controls, filter the ",[],{},{"nodeType":1293,"value":2713,"marks":2927,"data":2929},[2928],{"type":1387},{},{"nodeType":1293,"value":2931,"marks":2932,"data":2933}," page. Go to the filters icon, then select ",[],{},{"nodeType":1293,"value":2935,"marks":2936,"data":2938},"Events > By type",[2937],{"type":1387},{},{"nodeType":1293,"value":2940,"marks":2941,"data":2942}," from the dropdown and choose the specific control to see associated events.",[],{},{"nodeType":1317,"data":2944,"content":2948},{"target":2945},{"sys":2946},{"id":2947,"type":1322,"linkType":1323},"2M0Cjc2Wo9L7c9rIQebx0S",[],{"nodeType":1459,"data":2950,"content":2951},{},[2952],{"nodeType":1293,"value":2953,"marks":2954,"data":2955},"Set up alerts for your security team",[],{},{"nodeType":1294,"data":2957,"content":2958},{},[2959,2963,2968],{"nodeType":1293,"value":2960,"marks":2961,"data":2962},"Push can send notifications of interesting employee activity to a Microsoft Teams or Slack channel so you can stay on top of new apps and account security findings. In the admin console, go to the ",[],{},{"nodeType":1293,"value":2964,"marks":2965,"data":2967},"ChatOps",[2966],{"type":1387},{},{"nodeType":1293,"value":2969,"marks":2970,"data":2971}," page and integrate your Teams or Slack instance, then enable topics you wish to get notified about.",[],{},{"nodeType":1317,"data":2973,"content":2977},{"target":2974},{"sys":2975},{"id":2976,"type":1322,"linkType":1323},"OObhJQA1HMcmwBvpWfmC7",[],{"nodeType":1326,"data":2979,"content":2980},{},[],{"nodeType":1437,"data":2982,"content":2983},{},[2984],{"nodeType":1293,"value":2985,"marks":2986,"data":2987},"First 60 days: Go (threat) hunting",[],{},{"nodeType":1294,"data":2989,"content":2990},{},[2991],{"nodeType":1293,"value":2992,"marks":2993,"data":2994},"Now you’re ready to survey the landscape and see where there are dangers hiding among your workforce identities such as missing MFA or SSO, unused accounts, compromised passwords, and unsanctioned or untrustworthy apps and integrations. ",[],{},{"nodeType":1294,"data":2996,"content":2997},{},[2998,3002,3006],{"nodeType":1293,"value":2999,"marks":3000,"data":3001},"Luckily, Push doesn’t make you forage for the important information. Use the ",[],{},{"nodeType":1293,"value":2765,"marks":3003,"data":3005},[3004],{"type":1387},{},{"nodeType":1293,"value":3007,"marks":3008,"data":3009}," in the Push admin console to pinpoint vulnerable identities and see SSO trends and other insights.",[],{},{"nodeType":1294,"data":3011,"content":3012},{},[3013],{"nodeType":1293,"value":3014,"marks":3015,"data":3016},"After getting a baseline understanding of your ecosystem, you can begin translating your security policies into actionable controls by preparing end-users and creating the foundation for control configuration rules.",[],{},{"nodeType":1294,"data":3018,"content":3019},{},[3020],{"nodeType":1293,"value":3021,"marks":3022,"data":3023},"Here’s what we recommend for your second month using Push:",[],{},{"nodeType":1459,"data":3025,"content":3026},{},[3027],{"nodeType":1293,"value":3028,"marks":3029,"data":3030},"Understand which identities are most vulnerable to account takeover",[],{},{"nodeType":1294,"data":3032,"content":3033},{},[3034,3038,3042,3046,3050],{"nodeType":1293,"value":3035,"marks":3036,"data":3037},"On the ",[],{},{"nodeType":1293,"value":2765,"marks":3039,"data":3041},[3040],{"type":1387},{},{"nodeType":1293,"value":3043,"marks":3044,"data":3045},", you can identify which identities are most at risk because they use a leaked, reused, or weak password and lack MFA by referencing the ",[],{},{"nodeType":1293,"value":2756,"marks":3047,"data":3049},[3048],{"type":1387},{},{"nodeType":1293,"value":3051,"marks":3052,"data":3053}," section.",[],{},{"nodeType":1294,"data":3055,"content":3056},{},[3057,3062,3066,3071],{"nodeType":1293,"value":3058,"marks":3059,"data":3061},"Tip: ",[3060],{"type":1387},{},{"nodeType":1293,"value":3063,"marks":3064,"data":3065},"Toggle the view to ",[],{},{"nodeType":1293,"value":3067,"marks":3068,"data":3070},"All identities",[3069],{"type":1387},{},{"nodeType":1293,"value":3072,"marks":3073,"data":3074}," if you are not yet using the sensitivity labels for apps to get a full picture of your data.",[],{},{"nodeType":1317,"data":3076,"content":3080},{"target":3077},{"sys":3078},{"id":3079,"type":1322,"linkType":1323},"4xPy4cr18jk7JV7TWqnmoy",[],{"nodeType":1294,"data":3082,"content":3083},{},[3084],{"nodeType":1293,"value":3085,"marks":3086,"data":3087},"Select each slice of the chart to go to a filtered list of the accounts with those security issues. You can then evaluate which accounts pose the biggest risk, whether they belong to high-sensitivity apps or high-value roles, such as admins or executives, or whether there are any data patterns, such as a cluster of account issues that belong to specific teams, that will help you decide on a remediation strategy.",[],{},{"nodeType":1294,"data":3089,"content":3090},{},[3091],{"nodeType":1293,"value":3092,"marks":3093,"data":3094},"As mentioned earlier, we recommend taking immediate action for any accounts with verified stolen credentials, especially those that also lack MFA protection.",[],{},{"nodeType":1459,"data":3096,"content":3097},{},[3098],{"nodeType":1293,"value":3099,"marks":3100,"data":3101},"Check your SSO coverage",[],{},{"nodeType":1294,"data":3103,"content":3104},{},[3105,3109,3114],{"nodeType":1293,"value":3106,"marks":3107,"data":3108},"On the Dashboard, you can also start to see your ",[],{},{"nodeType":1293,"value":3110,"marks":3111,"data":3113},"SSO trends",[3112],{"type":1387},{},{"nodeType":1293,"value":3115,"marks":3116,"data":3117},". Use this section of the dashboard to see a breakdown of login methods for your accounts (SAML, OIDC, or non-SSO).",[],{},{"nodeType":1317,"data":3119,"content":3123},{"target":3120},{"sys":3121},{"id":3122,"type":1322,"linkType":1323},"6GbX5cV4wOerwFeqKKAolC",[],{"nodeType":1294,"data":3125,"content":3126},{},[3127,3131,3136,3140,3145,3149,3159],{"nodeType":1293,"value":3128,"marks":3129,"data":3130},"You can look at more granular information on the ",[],{},{"nodeType":1293,"value":3132,"marks":3133,"data":3135},"Accounts",[3134],{"type":1387},{},{"nodeType":1293,"value":3137,"marks":3138,"data":3139}," page by filtering by ",[],{},{"nodeType":1293,"value":3141,"marks":3142,"data":3144},"Login method",[3143],{"type":1387},{},{"nodeType":1293,"value":3146,"marks":3147,"data":3148},". For example, you may wish to view accounts that have used both password and SAML login methods to identify local accounts on high-value apps that should be using SSO only — otherwise known as ",[],{},{"nodeType":2505,"data":3150,"content":3154},{"target":3151},{"sys":3152},{"id":3153,"type":1322,"linkType":1323},"174u87EYeKMKHzYYxBLlHO",[3155],{"nodeType":1293,"value":3156,"marks":3157,"data":3158},"ghost logins",[],{},{"nodeType":1293,"value":1712,"marks":3160,"data":3161},[],{},{"nodeType":1317,"data":3163,"content":3167},{"target":3164},{"sys":3165},{"id":3166,"type":1322,"linkType":1323},"68Sfs2MmpkdISb4rnoTCzW",[],{"nodeType":1459,"data":3169,"content":3170},{},[3171],{"nodeType":1293,"value":3172,"marks":3173,"data":3174},"Review patterns in employee activity",[],{},{"nodeType":1294,"data":3176,"content":3177},{},[3178,3182,3187,3191,3196,3200,3204],{"nodeType":1293,"value":3179,"marks":3180,"data":3181},"Using the ",[],{},{"nodeType":1293,"value":3183,"marks":3184,"data":3186},"Apps",[3185],{"type":1387},{},{"nodeType":1293,"value":3188,"marks":3189,"data":3190},", ",[],{},{"nodeType":1293,"value":3192,"marks":3193,"data":3195},"Employees",[3194],{"type":1387},{},{"nodeType":1293,"value":3197,"marks":3198,"data":3199},", and ",[],{},{"nodeType":1293,"value":3132,"marks":3201,"data":3203},[3202],{"type":1387},{},{"nodeType":1293,"value":3205,"marks":3206,"data":3207}," pages, you can then get a sense of which apps employees are accessing, using which login methods, whether they’re registered for MFA (and which MFA methods are registered on the account), whether they’re using a password manager, and where there are account security issues such as weak, reused, or shared passwords.",[],{},{"nodeType":1294,"data":3209,"content":3210},{},[3211,3216],{"nodeType":1293,"value":3212,"marks":3213,"data":3215},"Tip:",[3214],{"type":1387},{},{"nodeType":1293,"value":3217,"marks":3218,"data":3219}," Use the filters on these pages to zero in on issues of interest, such as password logins, account security findings, or weak MFA methods.",[],{},{"nodeType":1459,"data":3221,"content":3222},{},[3223],{"nodeType":1293,"value":3224,"marks":3225,"data":3226},"Put your security policies into practice",[],{},{"nodeType":1294,"data":3228,"content":3229},{},[3230],{"nodeType":1293,"value":3231,"marks":3232,"data":3233},"Equipped with this context, now you’re ready to lay the foundation for remediation and blocking controls, putting your security policies into practice.",[],{},{"nodeType":1294,"data":3235,"content":3236},{},[3237],{"nodeType":1293,"value":3238,"marks":3239,"data":3240},"At this stage, we recommend that you:",[],{},{"nodeType":1481,"data":3242,"content":3243},{},[3244,3272,3282],{"nodeType":1485,"data":3245,"content":3246},{},[3247],{"nodeType":1294,"data":3248,"content":3249},{},[3250,3254,3259,3263,3268],{"nodeType":1293,"value":3251,"marks":3252,"data":3253},"Set the ",[],{},{"nodeType":1293,"value":3255,"marks":3256,"data":3258},"Approval status",[3257],{"type":1387},{},{"nodeType":1293,"value":3260,"marks":3261,"data":3262}," and ",[],{},{"nodeType":1293,"value":3264,"marks":3265,"data":3267},"Sensitivity level",[3266],{"type":1387},{},{"nodeType":1293,"value":3269,"marks":3270,"data":3271}," of your apps using the provided categories in Push.",[],{},{"nodeType":1485,"data":3273,"content":3274},{},[3275],{"nodeType":1294,"data":3276,"content":3277},{},[3278],{"nodeType":1293,"value":3279,"marks":3280,"data":3281},"Create employee groups (which can be done manually or via API to match your existing directory groups) and assign employees to them based on department or job function.",[],{},{"nodeType":1485,"data":3283,"content":3284},{},[3285],{"nodeType":1294,"data":3286,"content":3287},{},[3288],{"nodeType":1293,"value":3289,"marks":3290,"data":3291},"Create custom labels for apps as needed.",[],{},{"nodeType":1294,"data":3293,"content":3294},{},[3295],{"nodeType":1293,"value":3296,"marks":3297,"data":3298},"By adding this metadata, you’ll be able to use these classifications when configuring rules for how to apply your desired security controls.",[],{},{"nodeType":1317,"data":3300,"content":3304},{"target":3301},{"sys":3302},{"id":3303,"type":1322,"linkType":1323},"pCIPMrpBAWlmqFoKxTL8P",[],{"nodeType":1294,"data":3306,"content":3307},{},[3308],{"nodeType":1293,"value":3309,"marks":3310,"data":3311},"Before enabling end-user remediation and blocking controls, which we cover in the next section, you may also wish to let your employees know what they should expect to see in terms of self-remediation workflows or other employee-facing guidance in their browser.",[],{},{"nodeType":1326,"data":3313,"content":3314},{},[],{"nodeType":1437,"data":3316,"content":3317},{},[3318],{"nodeType":1293,"value":3319,"marks":3320,"data":3321},"First 90 days: Remediate issues and arrive safely",[],{},{"nodeType":1294,"data":3323,"content":3324},{},[3325],{"nodeType":1293,"value":3326,"marks":3327,"data":3328},"With your team prepared and your rifle well-oiled, you’re ready to pick off security issues like SSO password phishing; missing MFA; and use of unsanctioned apps.",[],{},{"nodeType":1294,"data":3330,"content":3331},{},[3332],{"nodeType":1293,"value":3333,"marks":3334,"data":3335},"Here’s what we recommend for your third month using Push:",[],{},{"nodeType":1459,"data":3337,"content":3338},{},[3339],{"nodeType":1293,"value":3340,"marks":3341,"data":3342},"Move security controls out of Monitor mode to Warn or Block",[],{},{"nodeType":1294,"data":3344,"content":3345},{},[3346,3350,3355,3359,3363,3366,3370,3374,3378,3382,3386,3389,3393],{"nodeType":1293,"value":3347,"marks":3348,"data":3349},"Once you’ve informed your employees and curated your ignore list, you’re ready to move security controls such as ",[],{},{"nodeType":1293,"value":3351,"marks":3352,"data":3354},"SSO password protection",[3353],{"type":1387},{},{"nodeType":1293,"value":3356,"marks":3357,"data":3358}," into ",[],{},{"nodeType":1293,"value":2666,"marks":3360,"data":3362},[3361],{"type":1387},{},{"nodeType":1293,"value":2671,"marks":3364,"data":3365},[],{},{"nodeType":1293,"value":2675,"marks":3367,"data":3369},[3368],{"type":1387},{},{"nodeType":1293,"value":3371,"marks":3372,"data":3373}," mode. (If you have not already set the ",[],{},{"nodeType":1293,"value":2622,"marks":3375,"data":3377},[3376],{"type":1387},{},{"nodeType":1293,"value":3379,"marks":3380,"data":3381}," control to ",[],{},{"nodeType":1293,"value":2666,"marks":3383,"data":3385},[3384],{"type":1387},{},{"nodeType":1293,"value":2671,"marks":3387,"data":3388},[],{},{"nodeType":1293,"value":2675,"marks":3390,"data":3392},[3391],{"type":1387},{},{"nodeType":1293,"value":3394,"marks":3395,"data":3396},", now is also a good time to do that.)",[],{},{"nodeType":1294,"data":3398,"content":3399},{},[3400,3403,3407],{"nodeType":1293,"value":2645,"marks":3401,"data":3402},[],{},{"nodeType":1293,"value":2649,"marks":3404,"data":3406},[3405],{"type":1387},{},{"nodeType":1293,"value":3408,"marks":3409,"data":3410}," page of the admin console:",[],{},{"nodeType":1481,"data":3412,"content":3413},{},[3414,3432,3442,3452],{"nodeType":1485,"data":3415,"content":3416},{},[3417],{"nodeType":1294,"data":3418,"content":3419},{},[3420,3424,3429],{"nodeType":1293,"value":3421,"marks":3422,"data":3423},"Open the tile for the given control and update the ",[],{},{"nodeType":1293,"value":3425,"marks":3426,"data":3428},"Mode",[3427],{"type":1387},{},{"nodeType":1293,"value":1712,"marks":3430,"data":3431},[],{},{"nodeType":1485,"data":3433,"content":3434},{},[3435],{"nodeType":1294,"data":3436,"content":3437},{},[3438],{"nodeType":1293,"value":3439,"marks":3440,"data":3441},"Create a custom message that employees will see when the control is triggered.",[],{},{"nodeType":1485,"data":3443,"content":3444},{},[3445],{"nodeType":1294,"data":3446,"content":3447},{},[3448],{"nodeType":1293,"value":3449,"marks":3450,"data":3451},"Save the configuration.",[],{},{"nodeType":1485,"data":3453,"content":3454},{},[3455],{"nodeType":1294,"data":3456,"content":3457},{},[3458],{"nodeType":1293,"value":3459,"marks":3460,"data":3461},"If possible, we also recommend consuming the webhook events generated when these controls are triggered in your SIEM or other alerting platform so you have good visibility.",[],{},{"nodeType":1294,"data":3463,"content":3464},{},[3465,3469,3473,3476,3481,3485,3490],{"nodeType":1293,"value":3466,"marks":3467,"data":3468},"If you’ve found any malicious sites using the ",[],{},{"nodeType":1293,"value":2622,"marks":3470,"data":3472},[3471],{"type":1387},{},{"nodeType":1293,"value":2671,"marks":3474,"data":3475},[],{},{"nodeType":1293,"value":3477,"marks":3478,"data":3480},"Cloned login page detection",[3479],{"type":1387},{},{"nodeType":1293,"value":3482,"marks":3483,"data":3484}," control, you may also wish to update your blocklist using the ",[],{},{"nodeType":1293,"value":3486,"marks":3487,"data":3489},"URL blocking",[3488],{"type":1387},{},{"nodeType":1293,"value":3491,"marks":3492,"data":3493}," control. ",[],{},{"nodeType":1459,"data":3495,"content":3496},{},[3497],{"nodeType":1293,"value":3498,"marks":3499,"data":3500},"Implement banners to guide secure employee behavior",[],{},{"nodeType":1294,"data":3502,"content":3503},{},[3504,3508,3513,3517,3522,3525,3530,3533,3538,3542,3546,3550,3554,3558,3563],{"nodeType":1293,"value":3505,"marks":3506,"data":3507},"Depending on your security goals, you may want to implement in-browser guidance for employees in the form of ",[],{},{"nodeType":1293,"value":3509,"marks":3510,"data":3512},"App banners",[3511],{"type":1387},{},{"nodeType":1293,"value":3514,"marks":3515,"data":3516},". You can configure a banner in ",[],{},{"nodeType":1293,"value":3518,"marks":3519,"data":3521},"Inform",[3520],{"type":1387},{},{"nodeType":1293,"value":3188,"marks":3523,"data":3524},[],{},{"nodeType":1293,"value":3526,"marks":3527,"data":3529},"Acknowledge",[3528],{"type":1387},{},{"nodeType":1293,"value":3188,"marks":3531,"data":3532},[],{},{"nodeType":1293,"value":3534,"marks":3535,"data":3537},"Reason",[3536],{"type":1387},{},{"nodeType":1293,"value":3539,"marks":3540,"data":3541},", or ",[],{},{"nodeType":1293,"value":2675,"marks":3543,"data":3545},[3544],{"type":1387},{},{"nodeType":1293,"value":3547,"marks":3548,"data":3549}," modes from the ",[],{},{"nodeType":1293,"value":2649,"marks":3551,"data":3553},[3552],{"type":1387},{},{"nodeType":1293,"value":3555,"marks":3556,"data":3557}," page. Use the ",[],{},{"nodeType":1293,"value":3559,"marks":3560,"data":3562},"Rules",[3561],{"type":1387},{},{"nodeType":1293,"value":3564,"marks":3565,"data":3566}," feature to specify which employees or employee groups should see a banner, and which apps to apply it to.",[],{},{"nodeType":1317,"data":3568,"content":3572},{"target":3569},{"sys":3570},{"id":3571,"type":1322,"linkType":1323},"2rVWMTYrjShEdrswkzobJe",[],{"nodeType":1294,"data":3574,"content":3575},{},[3576],{"nodeType":1293,"value":3577,"marks":3578,"data":3579},"Common use cases include:",[],{},{"nodeType":1481,"data":3581,"content":3582},{},[3583,3593,3603,3613,3623],{"nodeType":1485,"data":3584,"content":3585},{},[3586],{"nodeType":1294,"data":3587,"content":3588},{},[3589],{"nodeType":1293,"value":3590,"marks":3591,"data":3592},"Blocking an app while you investigate a potential data breach.",[],{},{"nodeType":1485,"data":3594,"content":3595},{},[3596],{"nodeType":1294,"data":3597,"content":3598},{},[3599],{"nodeType":1293,"value":3600,"marks":3601,"data":3602},"Blocking unapproved apps, such as a file-sharing service that’s not approved for storing sensitive information.",[],{},{"nodeType":1485,"data":3604,"content":3605},{},[3606],{"nodeType":1294,"data":3607,"content":3608},{},[3609],{"nodeType":1293,"value":3610,"marks":3611,"data":3612},"Requiring employees to acknowledge your GenAI policy before using GenAI apps.",[],{},{"nodeType":1485,"data":3614,"content":3615},{},[3616],{"nodeType":1294,"data":3617,"content":3618},{},[3619],{"nodeType":1293,"value":3620,"marks":3621,"data":3622},"Reminding employees to use SSO for SAML-enabled apps rather than a local account password.",[],{},{"nodeType":1485,"data":3624,"content":3625},{},[3626],{"nodeType":1294,"data":3627,"content":3628},{},[3629],{"nodeType":1293,"value":3630,"marks":3631,"data":3632},"Asking employees not to use an app before it can be reviewed by the security team, for apps not yet in your inventory.",[],{},{"nodeType":1294,"data":3634,"content":3635},{},[3636,3640,3644,3648],{"nodeType":1293,"value":3212,"marks":3637,"data":3639},[3638],{"type":1387},{},{"nodeType":1293,"value":3641,"marks":3642,"data":3643}," You can monitor employee engagement with app banners on the ",[],{},{"nodeType":1293,"value":2713,"marks":3645,"data":3647},[3646],{"type":1387},{},{"nodeType":1293,"value":3649,"marks":3650,"data":3651}," page and send webhook events for when a banner is displayed or interacted with to your SIEM or SOAR.",[],{},{"nodeType":1459,"data":3653,"content":3654},{},[3655],{"nodeType":1293,"value":3656,"marks":3657,"data":3658},"Enforce MFA on high-value apps",[],{},{"nodeType":1294,"data":3660,"content":3661},{},[3662,3666,3671],{"nodeType":1293,"value":3663,"marks":3664,"data":3665},"If you’ve identified accounts on important apps that lack MFA, you can prompt employees to add an MFA method using ",[],{},{"nodeType":1293,"value":3667,"marks":3668,"data":3670},"MFA enforcement",[3669],{"type":1387},{},{"nodeType":1293,"value":3672,"marks":3673,"data":3674},". This control uses an in-browser message to direct employees to register for MFA on apps where they lack it. This control is enabled on a per-app basis, so you can decide where you want to prompt for MFA registration.",[],{},{"nodeType":1481,"data":3676,"content":3677},{},[3678,3703],{"nodeType":1485,"data":3679,"content":3680},{},[3681],{"nodeType":1294,"data":3682,"content":3683},{},[3684,3687,3691,3695,3699],{"nodeType":1293,"value":2645,"marks":3685,"data":3686},[],{},{"nodeType":1293,"value":2649,"marks":3688,"data":3690},[3689],{"type":1387},{},{"nodeType":1293,"value":3692,"marks":3693,"data":3694}," page, select the ",[],{},{"nodeType":1293,"value":3667,"marks":3696,"data":3698},[3697],{"type":1387},{},{"nodeType":1293,"value":3700,"marks":3701,"data":3702}," tile.",[],{},{"nodeType":1485,"data":3704,"content":3705},{},[3706],{"nodeType":1294,"data":3707,"content":3708},{},[3709],{"nodeType":1293,"value":3710,"marks":3711,"data":3712},"Customize the message to employees, if you like.",[],{},{"nodeType":1294,"data":3714,"content":3715},{},[3716],{"nodeType":1293,"value":3717,"marks":3718,"data":3719},"image",[],{},{"nodeType":1459,"data":3721,"content":3722},{},[3723],{"nodeType":1293,"value":3724,"marks":3725,"data":3726},"Send events to your SIEM or SOAR",[],{},{"nodeType":1294,"data":3728,"content":3729},{},[3730],{"nodeType":1293,"value":3731,"marks":3732,"data":3733},"To stay informed about end-user activity, findings, and controls on the Push platform, we recommend consuming events important to your security strategy in your SIEM, SOAR, or other similar alerting or automation platform.",[],{},{"nodeType":1294,"data":3735,"content":3736},{},[3737,3741,3745,3749,3757],{"nodeType":1293,"value":3738,"marks":3739,"data":3740},"Use the ",[],{},{"nodeType":1293,"value":2713,"marks":3742,"data":3744},[3743],{"type":1387},{},{"nodeType":1293,"value":3746,"marks":3747,"data":3748}," page in the admin console to get familiar with the data structure of events, as well as the volume of events, and then review our ",[],{},{"nodeType":1401,"data":3750,"content":3752},{"uri":3751},"/help/audience/administrators/docs/getting-started/#api-and-webhooks",[3753],{"nodeType":1293,"value":3754,"marks":3755,"data":3756},"REST API and webhooks documentation",[],{},{"nodeType":1293,"value":3758,"marks":3759,"data":3760}," for details on which entities, activities, control events, and audit logs you can consume.",[],{},{"nodeType":1317,"data":3762,"content":3766},{"target":3763},{"sys":3764},{"id":3765,"type":1322,"linkType":1323},"1oG13vQ3AGP5i6TD24dnjs",[],{"nodeType":1326,"data":3768,"content":3769},{},[],{"nodeType":1437,"data":3771,"content":3772},{},[3773],{"nodeType":1293,"value":3774,"marks":3775,"data":3776},"Next: Chart your own course",[],{},{"nodeType":1294,"data":3778,"content":3779},{},[3780],{"nodeType":1293,"value":3781,"marks":3782,"data":3783},"In your first 90 days and beyond, you can also begin creating custom workflows in your SIEM or SOAR platform to take Push’s browser and user activity telemetry and transform it into the triggers for solving specific problems in your environment.",[],{},{"nodeType":1294,"data":3785,"content":3786},{},[3787],{"nodeType":1293,"value":3788,"marks":3789,"data":3790},"Here are some ideas for what you can accomplish using Push’s REST API and webhooks:",[],{},{"nodeType":1481,"data":3792,"content":3793},{},[3794,3809,3824,3839,3854,3873,3888],{"nodeType":1485,"data":3795,"content":3796},{},[3797],{"nodeType":1294,"data":3798,"content":3799},{},[3800,3805],{"nodeType":1293,"value":3801,"marks":3802,"data":3804},"Harden identities and reduce account compromise",[3803],{"type":1387},{},{"nodeType":1293,"value":3806,"marks":3807,"data":3808},", such as alerting you when passwords are identified in public data breaches or when employees are using an unapproved app or when an SSO app is accessed via local account.",[],{},{"nodeType":1485,"data":3810,"content":3811},{},[3812],{"nodeType":1294,"data":3813,"content":3814},{},[3815,3820],{"nodeType":1293,"value":3816,"marks":3817,"data":3819},"Monitor for suspicious activity or high-risk changes",[3818],{"type":1387},{},{"nodeType":1293,"value":3821,"marks":3822,"data":3823},", such as checking for MFA method changes, or flagging when employees reuse corporate SSO passwords or visit sites running phishing malware.",[],{},{"nodeType":1485,"data":3825,"content":3826},{},[3827],{"nodeType":1294,"data":3828,"content":3829},{},[3830,3835],{"nodeType":1293,"value":3831,"marks":3832,"data":3834},"Investigate indicators of compromise",[3833],{"type":1387},{},{"nodeType":1293,"value":3836,"marks":3837,"data":3838},", such as correlating login events with platform logs, searching for recent signups to risky apps, or identifying post-compromise lateral movement opportunities.",[],{},{"nodeType":1485,"data":3840,"content":3841},{},[3842],{"nodeType":1294,"data":3843,"content":3844},{},[3845,3850],{"nodeType":1293,"value":3846,"marks":3847,"data":3849},"Force-reset an IdP password",[3848],{"type":1387},{},{"nodeType":1293,"value":3851,"marks":3852,"data":3853}," if Push finds a compromised password on an employee account.",[],{},{"nodeType":1485,"data":3855,"content":3856},{},[3857],{"nodeType":1294,"data":3858,"content":3859},{},[3860,3864,3869],{"nodeType":1293,"value":3861,"marks":3862,"data":3863},"Automate a workflow showing you all the",[],{},{"nodeType":1293,"value":3865,"marks":3866,"data":3868}," accounts and apps used by an employee you’re offboarding",[3867],{"type":1387},{},{"nodeType":1293,"value":3870,"marks":3871,"data":3872},", and their account login methods.",[],{},{"nodeType":1485,"data":3874,"content":3875},{},[3876],{"nodeType":1294,"data":3877,"content":3878},{},[3879,3884],{"nodeType":1293,"value":3880,"marks":3881,"data":3883},"Automate a workflow to revoke licenses",[3882],{"type":1387},{},{"nodeType":1293,"value":3885,"marks":3886,"data":3887}," on SaaS after a period of inactivity, saving money.",[],{},{"nodeType":1485,"data":3889,"content":3890},{},[3891],{"nodeType":1294,"data":3892,"content":3893},{},[3894,3899],{"nodeType":1293,"value":3895,"marks":3896,"data":3898},"Build an approved apps list",[3897],{"type":1387},{},{"nodeType":1293,"value":3900,"marks":3901,"data":3902}," in your company wiki, synced from Push’s source of truth.",[],{},{"nodeType":1294,"data":3904,"content":3905},{},[3906],{"nodeType":1293,"value":3907,"marks":3908,"data":3909},"If you’ve made it this far, congratulations! You did not die of identity attacks.",[],{},{"nodeType":1317,"data":3911,"content":3915},{"target":3912},{"sys":3913},{"id":3914,"type":1322,"linkType":1323},"4B7JIz8Iy7kp83vWLEVgOw",[],{"nodeType":1294,"data":3917,"content":3918},{},[3919],{"nodeType":1293,"value":37,"marks":3920,"data":3921},[],{},"River crossing: What you can accomplish in your first 90 days with Push Security","We’ve put together the following guide for intrepid security teams as they use Push to secure against modern identity attacks.","2024-12-09T00:00:00.000Z","navigating-your-first-90-days-with-push",{"items":3927},[3928],{"sys":3929,"name":2387},{"id":2386},{"items":3931},[3932],{"fullName":2050,"firstName":2051,"jobTitle":2052,"profilePicture":3933},{"url":2054},{"url":3935},"https://images.ctfassets.net/y1cdw1ablpvd/6AYqSpjNFFdEHnjviy5R7y/c1566a4f95e3c4d547abddba22ea2fd2/2024_identity_attacks__1_.png",{"items":3937},[3938],{"fullName":3939,"firstName":3940,"jobTitle":3941,"profilePicture":3942},"Dan Green","Dan","Threat Research",{"url":3943},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"json":3945,"links":4569},{"nodeType":1295,"data":3946,"content":3947},{},[3948,3955,3962,3969,3988,3995,4002,4005,4013,4020,4027,4034,4040,4047,4050,4058,4065,4072,4079,4086,4092,4099,4102,4110,4118,4125,4132,4139,4159,4167,4174,4181,4188,4195,4203,4210,4217,4223,4226,4234,4241,4248,4255,4262,4269,4272,4280,4287,4294,4301,4308,4315,4428,4444,4451,4457,4460,4468,4475,4544,4551],{"nodeType":1294,"data":3949,"content":3950},{},[3951],{"nodeType":1293,"value":3952,"marks":3953,"data":3954},"2024 was an unprecedented year in terms of the impact of identity-based attacks. Or that’s what it felt like anyway, so I decided to trawl through a year of news to see if reality stacked up. ",[],{},{"nodeType":1294,"data":3956,"content":3957},{},[3958],{"nodeType":1293,"value":3959,"marks":3960,"data":3961},"My main obstacles here were the ever-disappointing levels of public information disclosure for cyber breaches. Even where breaches are disclosed, it’s rare that any public information contains the nature of the initial access vector (though I can’t say I’m surprised — it’s hard to argue the ‘highly sophisticated’ nature of a breach that involved stolen credentials and no MFA). ",[],{},{"nodeType":1294,"data":3963,"content":3964},{},[3965],{"nodeType":1293,"value":3966,"marks":3967,"data":3968},"Publicly disclosed breaches are just the tip of the iceberg, and with the rise in data theft and extortion over more disruptive attacks (e.g. ransomware), there is often no obvious service interruption indicating that an incident has taken place. This makes it more likely that these situations can be settled quietly or smoothed over, without hitting the headlines. ",[],{},{"nodeType":1294,"data":3970,"content":3971},{},[3972,3976,3985],{"nodeType":1293,"value":3973,"marks":3974,"data":3975},"That said, the requirement that US companies submit a Form-8K for breaches of a material nature does appear to have increased the number of voluntary declarations (inside the US, at least) and the growing willingness of the SEC to prosecute negligent or misleading behavior is also a considerable motivator, such as ",[],{},{"nodeType":1401,"data":3977,"content":3979},{"uri":3978},"https://www.bleepingcomputer.com/news/security/sec-charges-tech-companies-for-downplaying-solarwinds-breaches/",[3980],{"nodeType":1293,"value":3981,"marks":3982,"data":3984},"the recent prosecution of companies for misleading investors about the impact of the 2020 SolarWinds Orion hack",[3983],{"type":1566},{},{"nodeType":1293,"value":1712,"marks":3986,"data":3987},[],{},{"nodeType":1294,"data":3989,"content":3990},{},[3991],{"nodeType":1293,"value":3992,"marks":3993,"data":3994},"Despite all this, I totalled 30 breaches that were the result of an identity-based initial access vector, such as phishing, credential stuffing, social engineering, session hijacking, etc. To make the list, it had to have appeared in the public domain, confirmed by the victim or an authoritative source, and the breach vector had to have been named. ",[],{},{"nodeType":1294,"data":3996,"content":3997},{},[3998],{"nodeType":1293,"value":3999,"marks":4000,"data":4001},"Public identity-related breaches in 2024 resulted in hundreds of millions of breached customer records (with the final impact of many still yet to appear in the public domain).",[],{},{"nodeType":1326,"data":4003,"content":4004},{},[],{"nodeType":1437,"data":4006,"content":4007},{},[4008],{"nodeType":1293,"value":4009,"marks":4010,"data":4012},"What is an identity attack?",[4011],{"type":1387},{},{"nodeType":1294,"data":4014,"content":4015},{},[4016],{"nodeType":1293,"value":4017,"marks":4018,"data":4019},"First, what do we mean by identity attack? ",[],{},{"nodeType":1294,"data":4021,"content":4022},{},[4023],{"nodeType":1293,"value":4024,"marks":4025,"data":4026},"An identity attack is any attack (regardless of the steps that follow) involving identity-based techniques, such as phishing, credential stuffing, and session hijacking, to log into an account/service. Basically, where identity is the initial breach vector.",[],{},{"nodeType":1294,"data":4028,"content":4029},{},[4030],{"nodeType":1293,"value":4031,"marks":4032,"data":4033},"The length and complexity of the overall attack chain will vary. For example, a SaaS-based account takeover where the attacker logs in and dumps the data from the app is naturally going to be more direct than a scenario in which an identity-based compromise leads to the takeover of an endpoint or device in a traditional networking environment. ",[],{},{"nodeType":1317,"data":4035,"content":4039},{"target":4036},{"sys":4037},{"id":4038,"type":1322,"linkType":1323},"SCbhb6dzXnaKUianhgLEL",[],{"nodeType":1294,"data":4041,"content":4042},{},[4043],{"nodeType":1293,"value":4044,"marks":4045,"data":4046},"In 2024, we’ve seen examples of both SaaS-based account takeover as well as identity attacks being used for initial access to more traditional networks, often resulting in ransomware deployment.",[],{},{"nodeType":1326,"data":4048,"content":4049},{},[],{"nodeType":1437,"data":4051,"content":4052},{},[4053],{"nodeType":1293,"value":4054,"marks":4055,"data":4057},"Breakdown of public identity breaches in 2024",[4056],{"type":1387},{},{"nodeType":1294,"data":4059,"content":4060},{},[4061],{"nodeType":1293,"value":4062,"marks":4063,"data":4064},"It’s always tricky to gauge the impact of a cyber breach, particularly when considering the limited information typically shared. Different types of breach are easier to assess than others — for example, any breach involving extortion/ransom payment has a clear cost associated. Regulator fines and penalties are also clear cut. But aside from these, you’re looking at the extent of any disruption/downtime, recovery costs, and the like. Long term, indirect impacts such as the loss of customer confidence are naturally tricky to estimate. ",[],{},{"nodeType":1294,"data":4066,"content":4067},{},[4068],{"nodeType":1293,"value":4069,"marks":4070,"data":4071},"However, many identity breaches don’t even have these metrics to go by. The general shift toward data theft only (as opposed to ransomware deployment) continued in 2024, and many of the public identity breaches reflect this. In these attacks, attackers steal data to extort a ransom payment, blackmail end-customers, and/or sell the data via underground criminal marketplaces. ",[],{},{"nodeType":1294,"data":4073,"content":4074},{},[4075],{"nodeType":1293,"value":4076,"marks":4077,"data":4078},"The one consistent metric we do have is the number of breached records, which is available in many (but not all) cases. Some organizations have attempted to calculate the financial impact per breached record. Most notably IBMs annual ‘Cost of a Data Breach’ report estimates the average data breach to cost $4.88m, and the cost per compromised record to be $169. But when applied to the sheer magnitude of 2024’s biggest attacks (in the region of hundreds of millions of breached records) the figures quickly reach unbelievable levels. ",[],{},{"nodeType":1294,"data":4080,"content":4081},{},[4082],{"nodeType":1293,"value":4083,"marks":4084,"data":4085},"All this is to say: It’s hard to pin down the relative impact of data breaches. But with the information available (profile of the victim organization, type of data impacted, number of customers impacted) it’s possible to provide a finger-in-the-air assessment — which is what I’ve attempted to do below. Here, we can see the overall month-by-month impact of public identity breaches, dated from when they were first reported (or using dates provided in said reports). ",[],{},{"nodeType":1317,"data":4087,"content":4091},{"target":4088},{"sys":4089},{"id":4090,"type":1322,"linkType":1323},"2XYuNqLuKhZbISb4II9IW4",[],{"nodeType":1294,"data":4093,"content":4094},{},[4095],{"nodeType":1293,"value":4096,"marks":4097,"data":4098},"Let’s take a closer look at the most notable breaches (and why they were especially significant). ",[],{},{"nodeType":1326,"data":4100,"content":4101},{},[],{"nodeType":1437,"data":4103,"content":4104},{},[4105],{"nodeType":1293,"value":4106,"marks":4107,"data":4109},"Top 3 public identity-related breaches in 2024",[4108],{"type":1387},{},{"nodeType":1459,"data":4111,"content":4112},{},[4113],{"nodeType":1293,"value":4114,"marks":4115,"data":4117},"#3: Microsoft — January 2024",[4116],{"type":1387},{},{"nodeType":1294,"data":4119,"content":4120},{},[4121],{"nodeType":1293,"value":4122,"marks":4123,"data":4124},"The threat group known as APT29, associated with the Russian SVR intelligence service, utilized password spray attacks that successfully compromised a non-production tenant account that did not have multi-factor authentication (MFA) enabled. They then leveraged this account to compromise a ‘test’ OAuth application that had elevated access to the Microsoft corporate environment. This was then used to access the email accounts of Microsoft employees. ",[],{},{"nodeType":1294,"data":4126,"content":4127},{},[4128],{"nodeType":1293,"value":4129,"marks":4130,"data":4131},"The attacks then continued throughout the year using information stolen from Microsoft mailboxes, with password spraying attacks increasing tenfold since the initial attack, resulting in the further compromise of source code repositories. ",[],{},{"nodeType":1294,"data":4133,"content":4134},{},[4135],{"nodeType":1293,"value":4136,"marks":4137,"data":4138},"Microsoft has shared limited information about the breach, but despite this it caused a significant stir. We can expect the number of email accounts compromised to be significant, given that it was later suggested that at least 100 external organizations had been contacted by Microsoft regarding their communications being breached (we only know this because 100-ish organizations reported the email as spam). The list of companies impacted included both public and private sector organizations, from major enterprises to government agencies in the US and other countries. ",[],{},{"nodeType":1294,"data":4140,"content":4141},{},[4142,4146,4155],{"nodeType":1293,"value":4143,"marks":4144,"data":4145},"Microsoft’s challenges with credential management didn’t end here either, ",[],{},{"nodeType":1401,"data":4147,"content":4149},{"uri":4148},"https://pushsecurity.com/blog/learning-from-the-servicenow-disclosure/",[4150],{"nodeType":1293,"value":4151,"marks":4152,"data":4154},"with bug bounty hunters able to use stolen credentials from a TI platform to breach Microsoft’s ServiceNow tenant",[4153],{"type":1566},{},{"nodeType":1293,"value":4156,"marks":4157,"data":4158},", accessing 1,000s of support ticket descriptions and attachments, and 250k+ employee emails.",[],{},{"nodeType":1459,"data":4160,"content":4161},{},[4162],{"nodeType":1293,"value":4163,"marks":4164,"data":4166},"#2: Change Healthcare — February 2024",[4165],{"type":1387},{},{"nodeType":1294,"data":4168,"content":4169},{},[4170],{"nodeType":1293,"value":4171,"marks":4172,"data":4173},"In February, attackers stole 6TB of data from UnitedHealth subsidiary Change Healthcare as part of a severe ransomware attack that caused massive disruption to the US healthcare industry. This impacted a wide range of critical services used by healthcare providers across the U.S., including payment processing, prescription writing, and insurance claims, and caused financial damages estimated at $872 million. The attack impacted the personal medical data of over 100M customers. ",[],{},{"nodeType":1294,"data":4175,"content":4176},{},[4177],{"nodeType":1293,"value":4178,"marks":4179,"data":4180},"The attacker used stolen credentials to breach the company's Citrix remote access service, which did not have multi-factor authentication enabled, as the initial breach vector for the attack. ",[],{},{"nodeType":1294,"data":4182,"content":4183},{},[4184],{"nodeType":1293,"value":4185,"marks":4186,"data":4187},"Following the attack, the organization's IT team replaced thousands of laptops, rotated credentials, and completely rebuilt Change Healthcare's data center network and core services.",[],{},{"nodeType":1294,"data":4189,"content":4190},{},[4191],{"nodeType":1293,"value":4192,"marks":4193,"data":4194},"The UnitedHealth Group admitted to paying a ransom demand to receive a decryptor and for the threat actors to delete the stolen data. The ransom payment was allegedly $22 million, according to the BlackCat ransomware affiliate who conducted the attack.",[],{},{"nodeType":1459,"data":4196,"content":4197},{},[4198],{"nodeType":1293,"value":4199,"marks":4200,"data":4202},"#1: Snowflake — April-June 2024",[4201],{"type":1387},{},{"nodeType":1294,"data":4204,"content":4205},{},[4206],{"nodeType":1293,"value":4207,"marks":4208,"data":4209},"165 organizations around the world were targeted using stolen credentials gathered from infostealer infections dating back to 2020. The impacted accounts lacked MFA, meaning successful authentication only required a valid username and password. As the Snowflake credentials found in infostealer malware credential dumps had not been rotated or updated, they remained valid and could be used to authenticate to user accounts on Snowflake tenants belonging to various customers. It has been touted by some news outlets as ‘one of the biggest breaches ever’. ",[],{},{"nodeType":1294,"data":4211,"content":4212},{},[4213],{"nodeType":1293,"value":4214,"marks":4215,"data":4216},"In total, nine public victims were named following the breach, collectively impacting hundreds of millions of their respective customers. Data was put up for sale on criminal forums for fees ranging from $150k to $2m per organization, while AT&T was also confirmed as paying an undisclosed ransom fee. ",[],{},{"nodeType":1317,"data":4218,"content":4222},{"target":4219},{"sys":4220},{"id":4221,"type":1322,"linkType":1323},"68txz4KkLmCX2hF9QySUZs",[],{"nodeType":1326,"data":4224,"content":4225},{},[],{"nodeType":1437,"data":4227,"content":4228},{},[4229],{"nodeType":1293,"value":4230,"marks":4231,"data":4233},"Identity attacks vs. other attacks in 2024",[4232],{"type":1387},{},{"nodeType":1294,"data":4235,"content":4236},{},[4237],{"nodeType":1293,"value":4238,"marks":4239,"data":4240},"In many ways, 2024 was a year of identity attacks. The attacks on Snowflake customers was unarguably one of (if not the most) significant cyber security event of the year (at least, if you exclude CrowdStrike causing a worldwide outage in July) — certainly, it was the largest perpetrated by a criminal group against commercial enterprises. ",[],{},{"nodeType":1294,"data":4242,"content":4243},{},[4244],{"nodeType":1293,"value":4245,"marks":4246,"data":4247},"Arguably the biggest non-identity story of the year was the Chinese state-sponsored “Salt Typhoon” campaign against global telecommunications firms, with at least nine major providers compromised — including AT&T, Verizon, and T-Mobile. The group reportedly focused on infiltrating telecommunications infrastructure to steal text messages, phone call information, and voicemails from targeted people. The threat actors also targeted the wiretapping platforms used by the US government, raising serious national security concerns.",[],{},{"nodeType":1294,"data":4249,"content":4250},{},[4251],{"nodeType":1293,"value":4252,"marks":4253,"data":4254},"Undoubtedly this was one of the biggest intelligence compromises in US history and is of major significance. But it’s also arguable that identity attacks had a more widespread commercial impact in 2024 when we look at the big picture.   ",[],{},{"nodeType":1294,"data":4256,"content":4257},{},[4258],{"nodeType":1293,"value":4259,"marks":4260,"data":4261},"Attacks on edge networking devices were also incredibly prominent, as were very much interlinked with the targeting of telecommunications infrastructure. A barrage of 0-days generated a huge amount of concern about the software security practices of many vendors. ",[],{},{"nodeType":1294,"data":4263,"content":4264},{},[4265],{"nodeType":1293,"value":4266,"marks":4267,"data":4268},"But despite these honorable mentions, the runaway threat of the year was an identity-based one… ",[],{},{"nodeType":1326,"data":4270,"content":4271},{},[],{"nodeType":1437,"data":4273,"content":4274},{},[4275],{"nodeType":1293,"value":4276,"marks":4277,"data":4279},"Threat of the year: Infostealers",[4278],{"type":1387},{},{"nodeType":1294,"data":4281,"content":4282},{},[4283],{"nodeType":1293,"value":4284,"marks":4285,"data":4286},"2024 saw an unprecedented rise in the role of infostealers. The played a huge role in the attacks on Snowflake customers, where 80% of the accounts were targeted using credentials found in infostealer infections. ",[],{},{"nodeType":1294,"data":4288,"content":4289},{},[4290],{"nodeType":1293,"value":4291,"marks":4292,"data":4293},"News relating to new infostealer variants and distributions campaigns came thick and fast in 2024, as attackers sought to harvest credentials from victims to use as part of their own malicious campaigns, or to sell on to other criminals on underground marketplaces for compromised credentials. Attackers leaned into alternative distribution channels, branching away from email-based campaigns to target victims via gaming forums, Facebook ads, and YouTube video descriptions. GitHub was also continuously targeted as a malware distribution mechanism throughout the year — and the majority of the time it was to push infostealers. ",[],{},{"nodeType":1294,"data":4295,"content":4296},{},[4297],{"nodeType":1293,"value":4298,"marks":4299,"data":4300},"Infostealers are the weapon of choice for attackers looking to harvest credentials at scale. Compared to credential harvesting phishing campaigns, infostealers target a much broader range of credentials, taking everything saved in the victim’s browser (and often also from local apps, including password managers).",[],{},{"nodeType":1294,"data":4302,"content":4303},{},[4304],{"nodeType":1293,"value":4305,"marks":4306,"data":4307},"Infostealers are nothing new, but have historically been seen as a problem affecting less secure personal devices and accounts. But 2024 has demonstrated that infostealers are finding ways to harvest business data — by finding ways around controls like EDR, and because of the ways that personal and business identities and accounts are converging in the modern workplace. For example, it’s not uncommon for employees to log into their personal Google account on their work device (and vice versa), inadvertently saving corporate credentials to their personal password store — which is later compromised through an infostealer infection on a personal device. ",[],{},{"nodeType":1294,"data":4309,"content":4310},{},[4311],{"nodeType":1293,"value":4312,"marks":4313,"data":4314},"The impact of infostealers (and the resulting stolen credentials and session cookies) is underlined by various figures:",[],{},{"nodeType":1481,"data":4316,"content":4317},{},[4318,4340,4362,4384,4406],{"nodeType":1485,"data":4319,"content":4320},{},[4321],{"nodeType":1294,"data":4322,"content":4323},{},[4324,4328,4336],{"nodeType":1293,"value":4325,"marks":4326,"data":4327},"79% of web application compromises were the result of breached credentials (",[],{},{"nodeType":1401,"data":4329,"content":4330},{"uri":1560},[4331],{"nodeType":1293,"value":4332,"marks":4333,"data":4335},"Verizon",[4334],{"type":1566},{},{"nodeType":1293,"value":4337,"marks":4338,"data":4339},").",[],{},{"nodeType":1485,"data":4341,"content":4342},{},[4343],{"nodeType":1294,"data":4344,"content":4345},{},[4346,4350,4359],{"nodeType":1293,"value":4347,"marks":4348,"data":4349},"Infostealer activity increased by 266% in 2023, while the number of attacks featuring valid credentials saw a 71% increase year-over-year (",[],{},{"nodeType":1401,"data":4351,"content":4353},{"uri":4352},"https://www.ibm.com/downloads/cas/L0GKXDWJ",[4354],{"nodeType":1293,"value":4355,"marks":4356,"data":4358},"IBM",[4357],{"type":1566},{},{"nodeType":1293,"value":4337,"marks":4360,"data":4361},[],{},{"nodeType":1485,"data":4363,"content":4364},{},[4365],{"nodeType":1294,"data":4366,"content":4367},{},[4368,4372,4381],{"nodeType":1293,"value":4369,"marks":4370,"data":4371},"Nearly half of the malware detected last year targeted victims’ data specifically, and the majority of that malware was classified as infostealers (",[],{},{"nodeType":1401,"data":4373,"content":4375},{"uri":4374},"https://news.sophos.com/en-us/2024/03/12/2024-sophos-threat-report/",[4376],{"nodeType":1293,"value":4377,"marks":4378,"data":4380},"Sophos",[4379],{"type":1566},{},{"nodeType":1293,"value":4337,"marks":4382,"data":4383},[],{},{"nodeType":1485,"data":4385,"content":4386},{},[4387],{"nodeType":1294,"data":4388,"content":4389},{},[4390,4394,4403],{"nodeType":1293,"value":4391,"marks":4392,"data":4393},"39,000 session token attacks are detected per day (",[],{},{"nodeType":1401,"data":4395,"content":4397},{"uri":4396},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf",[4398],{"nodeType":1293,"value":4399,"marks":4400,"data":4402},"Microsoft",[4401],{"type":1566},{},{"nodeType":1293,"value":4337,"marks":4404,"data":4405},[],{},{"nodeType":1485,"data":4407,"content":4408},{},[4409],{"nodeType":1294,"data":4410,"content":4411},{},[4412,4416,4425],{"nodeType":1293,"value":4413,"marks":4414,"data":4415},"Attacks on session cookies happen at the same rough order of magnitude as password-based attacks (",[],{},{"nodeType":1401,"data":4417,"content":4419},{"uri":4418},"https://github.com/WICG/dbsc/issues/13#issuecomment-1977657864",[4420],{"nodeType":1293,"value":4421,"marks":4422,"data":4424},"Google",[4423],{"type":1566},{},{"nodeType":1293,"value":4337,"marks":4426,"data":4427},[],{},{"nodeType":1294,"data":4429,"content":4430},{},[4431,4435,4440],{"nodeType":1293,"value":4432,"marks":4433,"data":4434},"And of the confirmed identity-based breaches in the public domain that we identified, ",[],{},{"nodeType":1293,"value":4436,"marks":4437,"data":4439},"a whopping 73% were the result of compromised credentials ",[4438],{"type":1387},{},{"nodeType":1293,"value":4441,"marks":4442,"data":4443},"(the rest were phishing attacks). ",[],{},{"nodeType":1294,"data":4445,"content":4446},{},[4447],{"nodeType":1293,"value":4448,"marks":4449,"data":4450},"As the primary source of compromised credentials, it’s fair to say that infostealers deserve the top spot for 2024.",[],{},{"nodeType":1317,"data":4452,"content":4456},{"target":4453},{"sys":4454},{"id":4455,"type":1322,"linkType":1323},"7mMQEYQTXKAajIGFviDJKt",[],{"nodeType":1326,"data":4458,"content":4459},{},[],{"nodeType":1437,"data":4461,"content":4462},{},[4463],{"nodeType":1293,"value":4464,"marks":4465,"data":4467},"Defend against infostealers with Push",[4466],{"type":1387},{},{"nodeType":1294,"data":4469,"content":4470},{},[4471],{"nodeType":1293,"value":4472,"marks":4473,"data":4474},"As a browser-based identity security platform designed to stop identity attacks, Push helps organizations to defend against the rise in infostealers by:",[],{},{"nodeType":1481,"data":4476,"content":4477},{},[4478,4512,4534],{"nodeType":1485,"data":4479,"content":4480},{},[4481],{"nodeType":1294,"data":4482,"content":4483},{},[4484,4487,4495,4499,4508],{"nodeType":1293,"value":37,"marks":4485,"data":4486},[],{},{"nodeType":1401,"data":4488,"content":4489},{"uri":2220},[4490],{"nodeType":1293,"value":4491,"marks":4492,"data":4494},"Alerting you whenever the valid credentials your employees are using appear in a compromised credential data feed",[4493],{"type":1566},{},{"nodeType":1293,"value":4496,"marks":4497,"data":4498},", which can be leveraged to ",[],{},{"nodeType":1401,"data":4500,"content":4502},{"uri":4501},"https://pushsecurity.com/blog/automating-sso-password-resets-using-push/",[4503],{"nodeType":1293,"value":4504,"marks":4505,"data":4507},"trigger automated password resets",[4506],{"type":1566},{},{"nodeType":1293,"value":4509,"marks":4510,"data":4511}," whenever an event fires and is received by your SIEM tool.",[],{},{"nodeType":1485,"data":4513,"content":4514},{},[4515],{"nodeType":1294,"data":4516,"content":4517},{},[4518,4521,4530],{"nodeType":1293,"value":37,"marks":4519,"data":4520},[],{},{"nodeType":1401,"data":4522,"content":4524},{"uri":4523},"https://pushsecurity.com/blog/introducing-session-token-theft-detection-why-browser-is-best/",[4525],{"nodeType":1293,"value":4526,"marks":4527,"data":4529},"Detecting session hijacking attacks using stolen cookies to identify when an attacker logs into an app",[4528],{"type":1566},{},{"nodeType":1293,"value":4531,"marks":4532,"data":4533}," from an unmanaged device without the Push browser extension — this can also be used to detect suspicious access in general!",[],{},{"nodeType":1485,"data":4535,"content":4536},{},[4537],{"nodeType":1294,"data":4538,"content":4539},{},[4540],{"nodeType":1293,"value":4541,"marks":4542,"data":4543},"Enabling you to enforce MFA the next time an employee logs into an app (even when the app itself doesn’t allow you to enforce mandatory MFA) — particularly handy if a weak, breached, or reused password is detected for their account!  ",[],{},{"nodeType":1294,"data":4545,"content":4546},{},[4547],{"nodeType":1293,"value":4548,"marks":4549,"data":4550},"And much, much more. ",[],{},{"nodeType":1294,"data":4552,"content":4553},{},[4554,4558,4566],{"nodeType":1293,"value":4555,"marks":4556,"data":4557},"If you’d like to explore the platform yourself and discover more of our great features, you can ",[],{},{"nodeType":1401,"data":4559,"content":4561},{"uri":4560},"https://pushsecurity.com/demo",[4562],{"nodeType":1293,"value":2013,"marks":4563,"data":4565},[4564],{"type":1566},{},{"nodeType":1293,"value":1712,"marks":4567,"data":4568},[],{},{"entries":4570},{"hyperlink":4571,"inline":4572,"block":4573},[],[],[4574,4581,4589,4593],{"sys":4575,"__typename":4576,"type":4577,"ctaText":4578,"buttonLabel":4579,"buttonColour":4580,"buttonUrl":1731},{"id":4038},"CtaWidget","Custom","Learn about how attack paths are changing with the shift to SaaS-based IT here","Read the blog","sunny orange",{"sys":4582,"__typename":4583,"title":4584,"caption":4585,"layoutMode":118,"file":4586},{"id":4090},"Image","Identity-related breaches in 2024","Bold names are particularly notable for their significance and impact. A snowflake symbol indicates that the victim was impacted as part of the wider campaign against Snowflake customers. Dollar sign indicates that a ransom payment was confirmed.",{"url":3935,"width":4587,"height":4588},1920,1150,{"sys":4590,"__typename":4576,"type":4577,"ctaText":4591,"buttonLabel":4579,"buttonColour":4592,"buttonUrl":1850},{"id":4221},"Read more about the Snowflake incident in our blog post","sea blue",{"sys":4594,"__typename":4576,"type":4577,"ctaText":4595,"buttonLabel":4579,"buttonColour":4596,"buttonUrl":1704},{"id":4455},"For more information on the rise of infostealers, check out our deep-dive here","orange","content:blog:2024-identity-breaches.json","json","content","blog/2024-identity-breaches.json","blog/2024-identity-breaches",1776359986252]