[{"data":1,"prerenderedAt":7395},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/5-reasons-why-push-security-shouldnt-exist":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"ogImage":118,"summary":1282,"title":1303,"subtitle":118,"metaTitle":1303,"synopsis":1304,"hashTags":118,"publishedDate":1305,"slug":1306,"tagsCollection":1307,"relatedBlogPostsCollection":1317,"authorsCollection":5984,"content":5988,"_id":7390,"_type":7391,"_source":7392,"_file":7393,"_stem":7394,"_extension":7391},"/blog/5-reasons-why-push-security-shouldnt-exist","blog",{"id":1280,"publishedAt":1281},"1fp5aOCIcGHDbdQ0amCYOf","2026-01-30T12:09:50.005Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1302},{},[1286,1295],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"If current security controls worked perfectly, Push wouldn't need to exist – unfortunately, they don't, so here we are!","text","paragraph",{"data":1296,"content":1297,"nodeType":1294},{},[1298],{"data":1299,"marks":1300,"value":1301,"nodeType":1293},{},[],"In this article, we break down common misconceptions about identity controls like MFA, SSO, passkeys, and password managers, exploring some of the gaps they leave and how to fill them to achieve defense in depth.","document","5 reasons why Push Security shouldn’t exist","Breaking down common misconceptions about identity threats and controls like MFA, SSO, passkeys, password managers, and more.","2024-07-11T00:00:00.000Z","5-reasons-why-push-security-shouldnt-exist",{"items":1308},[1309,1313],{"sys":1310,"name":1312},{"id":1311},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"sys":1314,"name":1316},{"id":1315},"3pjES4THCIfSAwhGdNwBcy","Identity security",{"items":1318},[1319,4315,5134],{"__typename":1320,"sys":1321,"content":1323,"title":4295,"synopsis":4296,"hashTags":118,"publishedDate":4297,"slug":4298,"tagsCollection":4299,"authorsCollection":4307},"BlogPosts",{"id":1322},"6XIts2UEnrsJDki8gKDXyI",{"json":1324},{"nodeType":1302,"data":1325,"content":1326},{},[1327,1335,1370,1377,1386,1393,1413,1438,1445,1453,1479,1495,1502,1514,1521,1525,1532,1539,1555,1567,1574,1607,1610,1617,1637,1644,1652,1748,1755,1894,1901,2024,2031,2038,2215,2222,2229,2312,2315,2322,2329,2336,2399,2406,2439,2446,2489,2496,2502,2737,2743,2751,2758,2761,2768,2775,2782,2835,2842,2885,2892,2925,2931,2937,3102,3108,3116,3123,3131,3138,3146,3153,3156,3163,3170,3177,3240,3247,3280,3287,3320,3326,3332,3438,3441,3448,3455,3462,3525,3532,3565,3572,3605,3611,3617,3790,3793,3800,3807,3814,3887,3894,3927,3934,3967,3973,3979,4209,4212,4219,4226,4233,4240,4243,4250,4257,4264,4267,4274,4281,4288],{"nodeType":1328,"data":1329,"content":1330},"heading-1",{},[1331],{"nodeType":1293,"value":1332,"marks":1333,"data":1334},"Identity attacks on the rise?",[],{},{"nodeType":1294,"data":1336,"content":1337},{},[1338,1342,1353,1357,1366],{"nodeType":1293,"value":1339,"marks":1340,"data":1341},"Identity has been recorded as the #1 cyber attack vector since forever. You don’t have to look particularly hard to find statistics to support this. In 2023, one source reports that ",[],{},{"nodeType":1343,"data":1344,"content":1346},"hyperlink",{"uri":1345},"https://www.csoonline.com/article/648894/identity-based-security-threats-are-growing-rapidly-report.html",[1347],{"nodeType":1293,"value":1348,"marks":1349,"data":1352},"4/5 breaches involved identity and compromised credentials",[1350],{"type":1351},"underline",{},{"nodeType":1293,"value":1354,"marks":1355,"data":1356},", while another suggests that ",[],{},{"nodeType":1343,"data":1358,"content":1360},{"uri":1359},"https://rakgarg.substack.com/p/identity-crisis-the-biggest-prize",[1361],{"nodeType":1293,"value":1362,"marks":1363,"data":1365},"75% of breaches are caused by mismanaged identity, access, or privileges",[1364],{"type":1351},{},{"nodeType":1293,"value":1367,"marks":1368,"data":1369},".",[],{},{"nodeType":1294,"data":1371,"content":1372},{},[1373],{"nodeType":1293,"value":1374,"marks":1375,"data":1376},"Phishing, social engineering, credential stuffing, and business email compromise have morphed into a homogenous understanding of identity threats that are generally tackled through a combination of email security tooling, content access controls, and user awareness. ",[],{},{"nodeType":1378,"data":1379,"content":1385},"embedded-entry-block",{"target":1380},{"sys":1381},{"id":1382,"type":1383,"linkType":1384},"5NRWvCl0xsoWcpgHbcQIkf","Link","Entry",[],{"nodeType":1294,"data":1387,"content":1388},{},[1389],{"nodeType":1293,"value":1390,"marks":1391,"data":1392},"The fact that such attacks have been reported as the top security threat for so long probably means that people pay less attention to identity threats. Ransomware grabs the headlines, and rightly so in many cases, but phishing feels like a “known known” that we have a plan for (even if the plan often fails). ",[],{},{"nodeType":1294,"data":1394,"content":1395},{},[1396,1400,1409],{"nodeType":1293,"value":1397,"marks":1398,"data":1399},"In fact, there’s a problem with messaging generally. The ",[],{},{"nodeType":1343,"data":1401,"content":1403},{"uri":1402},"https://www.verizon.com/business/resources/T78/reports/data-breach-investigation-report_2015.pdf",[1404],{"nodeType":1293,"value":1405,"marks":1406,"data":1408},"2015 Verizon DBIR",[1407],{"type":1351},{},{"nodeType":1293,"value":1410,"marks":1411,"data":1412}," contains plenty of stats that still ring largely true today. For example:",[],{},{"nodeType":1414,"data":1415,"content":1416},"unordered-list",{},[1417,1428],{"nodeType":1418,"data":1419,"content":1420},"list-item",{},[1421],{"nodeType":1294,"data":1422,"content":1423},{},[1424],{"nodeType":1293,"value":1425,"marks":1426,"data":1427},"In the 2013 DBIR, phishing was associated with over 95% of incidents attributed to state sponsored actors, and for two years running, more than two-thirds of incidents have featured phishing",[],{},{"nodeType":1418,"data":1429,"content":1430},{},[1431],{"nodeType":1294,"data":1432,"content":1433},{},[1434],{"nodeType":1293,"value":1435,"marks":1436,"data":1437},"In 60% of cases, attackers are able to compromise an organization within minutes",[],{},{"nodeType":1294,"data":1439,"content":1440},{},[1441],{"nodeType":1293,"value":1442,"marks":1443,"data":1444},"Remove the dates and a lot of the report still stands up. ",[],{},{"nodeType":1446,"data":1447,"content":1448},"heading-2",{},[1449],{"nodeType":1293,"value":1450,"marks":1451,"data":1452},"Bad then, worse now",[],{},{"nodeType":1294,"data":1454,"content":1455},{},[1456,1460,1466,1470,1475],{"nodeType":1293,"value":1457,"marks":1458,"data":1459},"But identity attacks ",[],{},{"nodeType":1293,"value":1461,"marks":1462,"data":1465},"are",[1463],{"type":1464},"bold",{},{"nodeType":1293,"value":1467,"marks":1468,"data":1469}," worse than they used to be. Yes, credential stuffing, phishing, and SIM swapping may not be the most sophisticated attacks, but they remain as effective as ever. ",[],{},{"nodeType":1293,"value":1471,"marks":1472,"data":1474},"As the saying goes, if it ain’t broke — don’t fix it.",[1473],{"type":312},{},{"nodeType":1293,"value":1476,"marks":1477,"data":1478}," ",[],{},{"nodeType":1294,"data":1480,"content":1481},{},[1482,1486,1491],{"nodeType":1293,"value":1483,"marks":1484,"data":1485},"Recent attacks have moved toward a broader targeting of the ",[],{},{"nodeType":1293,"value":1487,"marks":1488,"data":1490},"identity infrastructure",[1489],{"type":1464},{},{"nodeType":1293,"value":1492,"marks":1493,"data":1494},". While phishing and social engineering was once primarily a delivery mechanism for malicious payloads to be executed on endpoint, it is now used to harvest credentials and secrets for identity-based attacks against cloud apps and services. ",[],{},{"nodeType":1294,"data":1496,"content":1497},{},[1498],{"nodeType":1293,"value":1499,"marks":1500,"data":1501},"And because businesses have migrated to more cloud-based services and infrastructure, the compromise of an identity now has different consequences.",[],{},{"nodeType":1294,"data":1503,"content":1504},{},[1505,1509],{"nodeType":1293,"value":1506,"marks":1507,"data":1508},"The data and functionality that attackers seek has moved off endpoints and internal networks and onto cloud systems and SaaS applications, which organizations are using in large numbers (tens to hundreds). The modern way of working means that applications are more often than not directly exposed to the internet — and the only thing needed to access these apps are identities. ",[],{},{"nodeType":1293,"value":1510,"marks":1511,"data":1513},"Naturally, it's much harder to stop credential stuffing attacks against 100 SaaS apps than the single centralized external VPN/webmail endpoint of yesteryear. ",[1512],{"type":1464},{},{"nodeType":1294,"data":1515,"content":1516},{},[1517],{"nodeType":1293,"value":1518,"marks":1519,"data":1520},"It’s clear that stats alone don’t adequately capture the identity threat. So we have to look beyond the numbers to find out why. ",[],{},{"nodeType":1522,"data":1523,"content":1524},"hr",{},[],{"nodeType":1328,"data":1526,"content":1527},{},[1528],{"nodeType":1293,"value":1529,"marks":1530,"data":1531},"Using this resource",[],{},{"nodeType":1294,"data":1533,"content":1534},{},[1535],{"nodeType":1293,"value":1536,"marks":1537,"data":1538},"To cut through some of the noise, we’ve compiled this list of reported attacks and explored what they mean for the identity threat landscape. ",[],{},{"nodeType":1294,"data":1540,"content":1541},{},[1542,1546,1551],{"nodeType":1293,"value":1543,"marks":1544,"data":1545},"This is not intended to be an exhaustive list of all attacks involving the compromise of digital identities (the list would be endless!). Nor is it something you should read all in one go (unless you ",[],{},{"nodeType":1293,"value":1547,"marks":1548,"data":1550},"really",[1549],{"type":312},{},{"nodeType":1293,"value":1552,"marks":1553,"data":1554}," want to, we won’t stop you). We want it to be a resource that you can refer back to, that we will continue to update as new attacks are recorded. ",[],{},{"nodeType":1294,"data":1556,"content":1557},{},[1558,1562],{"nodeType":1293,"value":1559,"marks":1560,"data":1561},"In this context we define identity attacks as ",[],{},{"nodeType":1293,"value":1563,"marks":1564,"data":1566},"attacks targeting cloud identities and their associated identity management systems, protocols, applications, and infrastructure. ",[1565],{"type":1464},{},{"nodeType":1294,"data":1568,"content":1569},{},[1570],{"nodeType":1293,"value":1571,"marks":1572,"data":1573},"The attacks recorded below are high profile examples of identity attacks that demonstrate how threat actors are leveraging the cloud identity plane to evade established cyber defenses and traverse new attack paths to achieve their goals. We’ve focused on attacks targeting identity infrastructure itself that are notable for their bypassing of traditional environments and established controls (e.g. Networkless or SaaS-to-SaaS attack paths). ",[],{},{"nodeType":1294,"data":1575,"content":1576},{},[1577,1581,1590,1594,1603],{"nodeType":1293,"value":1578,"marks":1579,"data":1580},"As with all publicly disclosed breaches, the level of detail and transparency we see varies. Where possible, we’ve mapped the threat actor Tactics, Techniques and Procedures to our ",[],{},{"nodeType":1343,"data":1582,"content":1584},{"uri":1583},"https://github.com/pushsecurity/saas-attacks",[1585],{"nodeType":1293,"value":1586,"marks":1587,"data":1589},"SaaS Attack Matrix.",[1588],{"type":1351},{},{"nodeType":1293,"value":1591,"marks":1592,"data":1593}," To learn more about SaaS attack techniques ",[],{},{"nodeType":1343,"data":1595,"content":1597},{"uri":1596},"https://pushsecurity.com/blog/saas-attack-techniques/#id-problems-with-observing-saas-attacks",[1598],{"nodeType":1293,"value":1599,"marks":1600,"data":1602},"read the blog",[1601],{"type":1351},{},{"nodeType":1293,"value":1604,"marks":1605,"data":1606},". ",[],{},{"nodeType":1522,"data":1608,"content":1609},{},[],{"nodeType":1328,"data":1611,"content":1612},{},[1613],{"nodeType":1293,"value":1614,"marks":1615,"data":1616},"Snowflake – June 2024",[],{},{"nodeType":1294,"data":1618,"content":1619},{},[1620,1624,1633],{"nodeType":1293,"value":1621,"marks":1622,"data":1623},"The threat group known as ShinyHunters (also tracked as UNC5537) has claimed responsibility for breaching multiple organizations using Snowflake, a cloud-based data warehousing and analytics platform. The breach stems from the historical compromise of credentials used to access customer-specific Snowflake tenants, via infostealer infections. These credentials were used as part of a targeted campaign against Snowflake customers, which was exacerbated by the widespread absence of MFA due to the lack of MFA enforcement by default. At the time of writing, approximately 165 customers have been impacted globally ",[],{},{"nodeType":1343,"data":1625,"content":1627},{"uri":1626},"https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",[1628],{"nodeType":1293,"value":1629,"marks":1630,"data":1632},"according to a report by Mandiant",[1631],{"type":1351},{},{"nodeType":1293,"value":1634,"marks":1635,"data":1636},". ",[],{},{"nodeType":1446,"data":1638,"content":1639},{},[1640],{"nodeType":1293,"value":1641,"marks":1642,"data":1643},"How did Snowflake get breached?",[],{},{"nodeType":1294,"data":1645,"content":1646},{},[1647],{"nodeType":1293,"value":1648,"marks":1649,"data":1651},"It’s worth noting that customers/users of Snowflake were breached via their Snowflake tenants, and no central breach of Snowflake's own systems occurred.",[1650],{"type":312},{},{"nodeType":1414,"data":1653,"content":1654},{},[1655,1665,1688,1698,1708,1718,1728,1738],{"nodeType":1418,"data":1656,"content":1657},{},[1658],{"nodeType":1294,"data":1659,"content":1660},{},[1661],{"nodeType":1293,"value":1662,"marks":1663,"data":1664},"Snowflake users were infected with infostealer malware that harvested credentials from user devices over an extended period. The threat actor used Snowflake customer credentials that were previously exposed via several infostealer malware variants, including; VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER.",[],{},{"nodeType":1418,"data":1666,"content":1667},{},[1668],{"nodeType":1294,"data":1669,"content":1670},{},[1671,1675,1684],{"nodeType":1293,"value":1672,"marks":1673,"data":1674},"Credentials appeared on criminal marketplaces e.g. dark web forums and ",[],{},{"nodeType":1343,"data":1676,"content":1678},{"uri":1677},"https://www.troyhunt.com/telegram-combolists-and-361m-email-addresses/",[1679],{"nodeType":1293,"value":1680,"marks":1681,"data":1683},"Telegram channels",[1682],{"type":1351},{},{"nodeType":1293,"value":1685,"marks":1686,"data":1687}," as combolists (username, password, and login portal combinations). ",[],{},{"nodeType":1418,"data":1689,"content":1690},{},[1691],{"nodeType":1294,"data":1692,"content":1693},{},[1694],{"nodeType":1293,"value":1695,"marks":1696,"data":1697},"Criminal groups (either ShinyHunters or another organization) saw the potential in targeting Snowflake users, based on the availability of credentials, number of customer organizations, and the value of the data that can be accessed in Snowflake. ",[],{},{"nodeType":1418,"data":1699,"content":1700},{},[1701],{"nodeType":1294,"data":1702,"content":1703},{},[1704],{"nodeType":1293,"value":1705,"marks":1706,"data":1707},"ShinyHunters embarked on a large-scale campaign targeting Snowflake customer accounts using previously breached credentials. ",[],{},{"nodeType":1418,"data":1709,"content":1710},{},[1711],{"nodeType":1294,"data":1712,"content":1713},{},[1714],{"nodeType":1293,"value":1715,"marks":1716,"data":1717},"ShinyHunters accessed user accounts that lacked MFA, belonging to approximately 165 Snowflake customers. ",[],{},{"nodeType":1418,"data":1719,"content":1720},{},[1721],{"nodeType":1294,"data":1722,"content":1723},{},[1724],{"nodeType":1293,"value":1725,"marks":1726,"data":1727},"ShinyHunters used SQL-based reconnaissance, staging, and data exfiltration techniques, expedited by custom hacker tooling developed specifically for Snowflake, to conduct attacks at scale.",[],{},{"nodeType":1418,"data":1729,"content":1730},{},[1731],{"nodeType":1294,"data":1732,"content":1733},{},[1734],{"nodeType":1293,"value":1735,"marks":1736,"data":1737},"ShinyHunters acquired massive quantities of Snowflake data based on the information that each customer stored in Snowflake or connected apps. The most sensitive data declared so far pertains to end-customers of each victim, for example PII, bank account and card information, etc.  ",[],{},{"nodeType":1418,"data":1739,"content":1740},{},[1741],{"nodeType":1294,"data":1742,"content":1743},{},[1744],{"nodeType":1293,"value":1745,"marks":1746,"data":1747},"ShinyHunters began attempts to extort Snowflake and end-customers using the data acquired. ",[],{},{"nodeType":1446,"data":1749,"content":1750},{},[1751],{"nodeType":1293,"value":1752,"marks":1753,"data":1754},"What was the impact of the Snowflake breach?",[],{},{"nodeType":1414,"data":1756,"content":1757},{},[1758,1777,1809,1837,1856,1875],{"nodeType":1418,"data":1759,"content":1760},{},[1761],{"nodeType":1294,"data":1762,"content":1763},{},[1764,1768,1773],{"nodeType":1293,"value":1765,"marks":1766,"data":1767},"Approximately ",[],{},{"nodeType":1293,"value":1769,"marks":1770,"data":1772},"165 victims were identified by Mandiant",[1771],{"type":1464},{},{"nodeType":1293,"value":1774,"marks":1775,"data":1776},". Organizations are gradually coming forward to declare the breach and release customer communications accordingly, but not all victims have been named.",[],{},{"nodeType":1418,"data":1778,"content":1779},{},[1780],{"nodeType":1294,"data":1781,"content":1782},{},[1783,1787,1792,1796,1805],{"nodeType":1293,"value":1784,"marks":1785,"data":1786},"Based on the figures being suggested so far, the impact upon end-customers is huge, with the data of ",[],{},{"nodeType":1293,"value":1788,"marks":1789,"data":1791},"hundreds of millions of people exposed",[1790],{"type":1464},{},{"nodeType":1293,"value":1793,"marks":1794,"data":1795},", and has been touted by some news outlets as ‘",[],{},{"nodeType":1343,"data":1797,"content":1799},{"uri":1798},"https://www.wired.com/story/snowflake-breach-advanced-auto-parts-lendingtree/",[1800],{"nodeType":1293,"value":1801,"marks":1802,"data":1804},"one of the biggest breaches ever",[1803],{"type":1351},{},{"nodeType":1293,"value":1806,"marks":1807,"data":1808},"’.  ",[],{},{"nodeType":1418,"data":1810,"content":1811},{},[1812],{"nodeType":1294,"data":1813,"content":1814},{},[1815,1819,1824,1828,1833],{"nodeType":1293,"value":1816,"marks":1817,"data":1818},"The impact on the affected businesses is largely unknown at this stage. It’s clear that the victims will suffer ",[],{},{"nodeType":1293,"value":1820,"marks":1821,"data":1823},"reputational damage",[1822],{"type":1464},{},{"nodeType":1293,"value":1825,"marks":1826,"data":1827}," based on the extent of their individual breaches, and possibly face other ",[],{},{"nodeType":1293,"value":1829,"marks":1830,"data":1832},"penalties and sanctions",[1831],{"type":1464},{},{"nodeType":1293,"value":1834,"marks":1835,"data":1836}," if they are found to be at fault by their respective regulators and/or national information security authorities. ",[],{},{"nodeType":1418,"data":1838,"content":1839},{},[1840],{"nodeType":1294,"data":1841,"content":1842},{},[1843,1847,1852],{"nodeType":1293,"value":1844,"marks":1845,"data":1846},"The impact upon individuals will be significant, with high potential for further targeting in terms of ",[],{},{"nodeType":1293,"value":1848,"marks":1849,"data":1851},"identity theft, blackmail, financial crime",[1850],{"type":1464},{},{"nodeType":1293,"value":1853,"marks":1854,"data":1855},", etc.  ",[],{},{"nodeType":1418,"data":1857,"content":1858},{},[1859],{"nodeType":1294,"data":1860,"content":1861},{},[1862,1866,1871],{"nodeType":1293,"value":1863,"marks":1864,"data":1865},"It is unclear what data has been exposed in addition to personal data affecting end-customers. If other sensitive commercial or business data pertaining to ",[],{},{"nodeType":1293,"value":1867,"marks":1868,"data":1870},"Intellectual Property",[1869],{"type":1464},{},{"nodeType":1293,"value":1872,"marks":1873,"data":1874}," has been exposed then this data may also be sold on via other nefarious channels, with a potential future impact.",[],{},{"nodeType":1418,"data":1876,"content":1877},{},[1878],{"nodeType":1294,"data":1879,"content":1880},{},[1881,1885,1890],{"nodeType":1293,"value":1882,"marks":1883,"data":1884},"Given the lack of MFA for the compromised accounts, there has been a general criticism of the ‘opt-in’ nature of MFA for SaaS services, with many security professionals suggesting that ",[],{},{"nodeType":1293,"value":1886,"marks":1887,"data":1889},"Snowflake should enforce MFA by default",[1888],{"type":1464},{},{"nodeType":1293,"value":1891,"marks":1892,"data":1893}," given the critical nature of the service. ",[],{},{"nodeType":1446,"data":1895,"content":1896},{},[1897],{"nodeType":1293,"value":1898,"marks":1899,"data":1900},"What stands out in the Snowflake breach?",[],{},{"nodeType":1414,"data":1902,"content":1903},{},[1904,1923,1968,1996],{"nodeType":1418,"data":1905,"content":1906},{},[1907],{"nodeType":1294,"data":1908,"content":1909},{},[1910,1914,1919],{"nodeType":1293,"value":1911,"marks":1912,"data":1913},"The breach ",[],{},{"nodeType":1293,"value":1915,"marks":1916,"data":1918},"was achieved by using stolen credentials dating back as far as 2020",[1917],{"type":1464},{},{"nodeType":1293,"value":1920,"marks":1921,"data":1922},", that had not been rotated or changed. This indicates that many of the credentials used were not necessarily the result of any recent data sharing. This highlights the potential risk of breached credentials already in the public domain; particularly in the case of cloud services that may not be subject to the same levels of credential hygiene as other traditional network logins. ",[],{},{"nodeType":1418,"data":1924,"content":1925},{},[1926],{"nodeType":1294,"data":1927,"content":1928},{},[1929,1933,1942,1946,1951,1955,1964],{"nodeType":1293,"value":1930,"marks":1931,"data":1932},"Much of the industry response has focused on ensuring that accounts are using SSO (and therefore are protected by MFA at the IdP level). However, due to the existence of ",[],{},{"nodeType":1343,"data":1934,"content":1936},{"uri":1935},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[1937],{"nodeType":1293,"value":1938,"marks":1939,"data":1941},"ghost logins",[1940],{"type":1351},{},{"nodeType":1293,"value":1943,"marks":1944,"data":1945},", ",[],{},{"nodeType":1293,"value":1947,"marks":1948,"data":1950},"local logins without MFA can exist simultaneously with the SSO login unless expressly disabled",[1949],{"type":1464},{},{"nodeType":1293,"value":1952,"marks":1953,"data":1954},". Organizations using Snowflake that are looking to lock down their accounts can ",[],{},{"nodeType":1343,"data":1956,"content":1958},{"uri":1957},"https://pushsecurity.com/resources/video/demonstrating-ghost-logins-in-snowflake-and-how-to-remediate-them/",[1959],{"nodeType":1293,"value":1960,"marks":1961,"data":1963},"watch our recent demo of how to effectively remediate this vulnerability in Snowflake",[1962],{"type":1351},{},{"nodeType":1293,"value":1965,"marks":1966,"data":1967},".  ",[],{},{"nodeType":1418,"data":1969,"content":1970},{},[1971],{"nodeType":1294,"data":1972,"content":1973},{},[1974,1979,1983,1992],{"nodeType":1293,"value":1975,"marks":1976,"data":1978},"80% of the credentials were gathered through infostealer malware",[1977],{"type":1464},{},{"nodeType":1293,"value":1980,"marks":1981,"data":1982},". Typically, this occurs when unmanaged devices are used to access company resources, or personal browser profiles are synchronized on both work and personal devices. Malware deployed to an insecure personal device can then access and steal credentials for company resources. This situation usually occurs when working with third-party contractors on a BYOD basis; ",[],{},{"nodeType":1343,"data":1984,"content":1986},{"uri":1985},"https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/",[1987],{"nodeType":1293,"value":1988,"marks":1989,"data":1991},"a recent article indicates that Ukraine-based EPAM Systems",[1990],{"type":1351},{},{"nodeType":1293,"value":1993,"marks":1994,"data":1995},", an engineering and digital service provider and “Elite Tier Partner” of Snowflake, was one such organization breached in this way. Organizations consuming Snowflake-related services from EPAM were then subsequently affected, as the compromise of EPAM users granted access to a large number of Snowflake credentials for various company tenants.  ",[],{},{"nodeType":1418,"data":1997,"content":1998},{},[1999],{"nodeType":1294,"data":2000,"content":2001},{},[2002,2006,2011,2015,2020],{"nodeType":1293,"value":2003,"marks":2004,"data":2005},"While attacker activity has focused on Snowflake to date, the success of this attack will signal the potential for further credential based attacks against similar apps. ",[],{},{"nodeType":1293,"value":2007,"marks":2008,"data":2010},"There may already be a 'Snowflake 2.0' among the credentials already available online",[2009],{"type":1464},{},{"nodeType":1293,"value":2012,"marks":2013,"data":2014},". Further, credentials can be used against a wide range of apps to capitalize on potential ",[],{},{"nodeType":1293,"value":2016,"marks":2017,"data":2019},"password reuse (which we see for 1 in 3 employees)",[2018],{"type":1464},{},{"nodeType":1293,"value":2021,"marks":2022,"data":2023},", so the exact creds for a particular app don’t have to be explicitly breached, so long as the domain for the login portal can be guessed or has been exposed elsewhere.   ",[],{},{"nodeType":1446,"data":2025,"content":2026},{},[2027],{"nodeType":1293,"value":2028,"marks":2029,"data":2030},"SaaS attack matrix mapping",[],{},{"nodeType":1294,"data":2032,"content":2033},{},[2034],{"nodeType":1293,"value":2035,"marks":2036,"data":2037},"For more information on each TTP please navigate to the GitHub entries linked in the table below. ",[],{},{"nodeType":2039,"data":2040,"content":2041},"table",{},[2042,2087,2151],{"nodeType":2043,"data":2044,"content":2045},"table-row",{},[2046,2057,2067,2077],{"nodeType":2047,"data":2048,"content":2049},"table-header-cell",{},[2050],{"nodeType":1294,"data":2051,"content":2052},{},[2053],{"nodeType":1293,"value":2054,"marks":2055,"data":2056},"ID",[],{},{"nodeType":2047,"data":2058,"content":2059},{},[2060],{"nodeType":1294,"data":2061,"content":2062},{},[2063],{"nodeType":1293,"value":2064,"marks":2065,"data":2066},"Name",[],{},{"nodeType":2047,"data":2068,"content":2069},{},[2070],{"nodeType":1294,"data":2071,"content":2072},{},[2073],{"nodeType":1293,"value":2074,"marks":2075,"data":2076},"Stage",[],{},{"nodeType":2047,"data":2078,"content":2079},{},[2080],{"nodeType":1294,"data":2081,"content":2082},{},[2083],{"nodeType":1293,"value":2084,"marks":2085,"data":2086},"Description",[],{},{"nodeType":2043,"data":2088,"content":2089},{},[2090,2111,2131,2141],{"nodeType":2091,"data":2092,"content":2093},"table-cell",{},[2094],{"nodeType":1294,"data":2095,"content":2096},{},[2097,2100,2108],{"nodeType":1293,"value":37,"marks":2098,"data":2099},[],{},{"nodeType":1343,"data":2101,"content":2102},{"uri":1935},[2103],{"nodeType":1293,"value":2104,"marks":2105,"data":2107},"SAT1017",[2106],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2109,"data":2110},[],{},{"nodeType":2091,"data":2112,"content":2113},{},[2114],{"nodeType":1294,"data":2115,"content":2116},{},[2117,2120,2128],{"nodeType":1293,"value":37,"marks":2118,"data":2119},[],{},{"nodeType":1343,"data":2121,"content":2122},{"uri":1935},[2123],{"nodeType":1293,"value":2124,"marks":2125,"data":2127},"Ghost logins",[2126],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2129,"data":2130},[],{},{"nodeType":2091,"data":2132,"content":2133},{},[2134],{"nodeType":1294,"data":2135,"content":2136},{},[2137],{"nodeType":1293,"value":2138,"marks":2139,"data":2140},"Initial Access; Persistence; Defense Evasion",[],{},{"nodeType":2091,"data":2142,"content":2143},{},[2144],{"nodeType":1294,"data":2145,"content":2146},{},[2147],{"nodeType":1293,"value":2148,"marks":2149,"data":2150},"Abusing non-SSO additional login methods such as password-based authentication (local to the SaaS app), social logins, API access, etc. ",[],{},{"nodeType":2043,"data":2152,"content":2153},{},[2154,2175,2195,2205],{"nodeType":2091,"data":2155,"content":2156},{},[2157],{"nodeType":1294,"data":2158,"content":2159},{},[2160,2163,2172],{"nodeType":1293,"value":37,"marks":2161,"data":2162},[],{},{"nodeType":1343,"data":2164,"content":2166},{"uri":2165},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/session_cookie_theft/description.md",[2167],{"nodeType":1293,"value":2168,"marks":2169,"data":2171},"SAT1044",[2170],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2173,"data":2174},[],{},{"nodeType":2091,"data":2176,"content":2177},{},[2178],{"nodeType":1294,"data":2179,"content":2180},{},[2181,2184,2192],{"nodeType":1293,"value":37,"marks":2182,"data":2183},[],{},{"nodeType":1343,"data":2185,"content":2186},{"uri":2165},[2187],{"nodeType":1293,"value":2188,"marks":2189,"data":2191},"Session cookie theft",[2190],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2193,"data":2194},[],{},{"nodeType":2091,"data":2196,"content":2197},{},[2198],{"nodeType":1294,"data":2199,"content":2200},{},[2201],{"nodeType":1293,"value":2202,"marks":2203,"data":2204},"Lateral Movement; Defense Evasion",[],{},{"nodeType":2091,"data":2206,"content":2207},{},[2208],{"nodeType":1294,"data":2209,"content":2210},{},[2211],{"nodeType":1293,"value":2212,"marks":2213,"data":2214},"Session cookies are used to pivot from an endpoint compromise and laterally move to downstream SaaS applications.",[],{},{"nodeType":1446,"data":2216,"content":2217},{},[2218],{"nodeType":1293,"value":2219,"marks":2220,"data":2221},"Related breaches",[],{},{"nodeType":1294,"data":2223,"content":2224},{},[2225],{"nodeType":1293,"value":2226,"marks":2227,"data":2228},"Named victims are listed below:",[],{},{"nodeType":1414,"data":2230,"content":2231},{},[2232,2242,2252,2262,2272,2282,2292,2302],{"nodeType":1418,"data":2233,"content":2234},{},[2235],{"nodeType":1294,"data":2236,"content":2237},{},[2238],{"nodeType":1293,"value":2239,"marks":2240,"data":2241},"Ticketmaster",[],{},{"nodeType":1418,"data":2243,"content":2244},{},[2245],{"nodeType":1294,"data":2246,"content":2247},{},[2248],{"nodeType":1293,"value":2249,"marks":2250,"data":2251},"Santander",[],{},{"nodeType":1418,"data":2253,"content":2254},{},[2255],{"nodeType":1294,"data":2256,"content":2257},{},[2258],{"nodeType":1293,"value":2259,"marks":2260,"data":2261},"Neiman Marcus",[],{},{"nodeType":1418,"data":2263,"content":2264},{},[2265],{"nodeType":1294,"data":2266,"content":2267},{},[2268],{"nodeType":1293,"value":2269,"marks":2270,"data":2271},"Los Angeles Unified",[],{},{"nodeType":1418,"data":2273,"content":2274},{},[2275],{"nodeType":1294,"data":2276,"content":2277},{},[2278],{"nodeType":1293,"value":2279,"marks":2280,"data":2281},"Pure Storage",[],{},{"nodeType":1418,"data":2283,"content":2284},{},[2285],{"nodeType":1294,"data":2286,"content":2287},{},[2288],{"nodeType":1293,"value":2289,"marks":2290,"data":2291},"Advance Auto Parts",[],{},{"nodeType":1418,"data":2293,"content":2294},{},[2295],{"nodeType":1294,"data":2296,"content":2297},{},[2298],{"nodeType":1293,"value":2299,"marks":2300,"data":2301},"Truist Bank",[],{},{"nodeType":1418,"data":2303,"content":2304},{},[2305],{"nodeType":1294,"data":2306,"content":2307},{},[2308],{"nodeType":1293,"value":2309,"marks":2310,"data":2311},"Lending Tree",[],{},{"nodeType":1522,"data":2313,"content":2314},{},[],{"nodeType":1328,"data":2316,"content":2317},{},[2318],{"nodeType":1293,"value":2319,"marks":2320,"data":2321},"Microsoft — January 2024",[],{},{"nodeType":1294,"data":2323,"content":2324},{},[2325],{"nodeType":1293,"value":2326,"marks":2327,"data":2328},"The threat group known as APT29 (also known as “The Dukes”, “Cozy Bear”, and labeled “Midnight Blizzard” by Microsoft) executed a cleverly executed password-guessing attack to compromise test cloud identities that were also lacking MFA. Attackers then leveraged this access to compromise some OAuth applications that allowed lateral movement to Microsoft’s corporate environment and the creation of other malicious OAuth applications to achieve persistence.",[],{},{"nodeType":1446,"data":2330,"content":2331},{},[2332],{"nodeType":1293,"value":2333,"marks":2334,"data":2335},"How did Microsoft get breached?",[],{},{"nodeType":1414,"data":2337,"content":2338},{},[2339,2349,2359,2369,2379,2389],{"nodeType":1418,"data":2340,"content":2341},{},[2342],{"nodeType":1294,"data":2343,"content":2344},{},[2345],{"nodeType":1293,"value":2346,"marks":2347,"data":2348},"APT29 utilized password spraying / credential stuffing attacks to compromise test cloud identities that were also lacking MFA, attached to a non-production test tenant.",[],{},{"nodeType":1418,"data":2350,"content":2351},{},[2352],{"nodeType":1294,"data":2353,"content":2354},{},[2355],{"nodeType":1293,"value":2356,"marks":2357,"data":2358},"APT29 leveraged their initial access to the test tenant to identify and compromise a test OAuth application that had access to the Microsoft corporate environment by leveraging permissive Entra ID roles in the test tenant.",[],{},{"nodeType":1418,"data":2360,"content":2361},{},[2362],{"nodeType":1294,"data":2363,"content":2364},{},[2365],{"nodeType":1293,"value":2366,"marks":2367,"data":2368},"APT29 used the existing configurations to access the Microsoft corporate Entra ID tenant whereupon the app registration from the test tenant was installed as a service principal in the corporate tenant, granting the equivalent of global admin rights.",[],{},{"nodeType":1418,"data":2370,"content":2371},{},[2372],{"nodeType":1294,"data":2373,"content":2374},{},[2375],{"nodeType":1293,"value":2376,"marks":2377,"data":2378},"Using these new permissions, APT29 registered additional malicious OAuth applications in the Microsoft corporate environment, and created a new user in the Microsoft corporate tenant to grant consent to the new malicious OAuth apps, thereby achieving persistent access to the environment.",[],{},{"nodeType":1418,"data":2380,"content":2381},{},[2382],{"nodeType":1294,"data":2383,"content":2384},{},[2385],{"nodeType":1293,"value":2386,"marks":2387,"data":2388},"APT29 leveraged the elevated (maximum) privileges assigned to the ‘test’ app service principal to grant app roles to other newly created app service principals, granting them the Office 365 Exchange Online full_access_as_app role in the corporate tenant, which allows access to mailboxes.",[],{},{"nodeType":1418,"data":2390,"content":2391},{},[2392],{"nodeType":1294,"data":2393,"content":2394},{},[2395],{"nodeType":1293,"value":2396,"marks":2397,"data":2398},"APT29 leveraged these malicious OAuth applications to authenticate to Microsoft Exchange Online and target Microsoft corporate email accounts.",[],{},{"nodeType":1446,"data":2400,"content":2401},{},[2402],{"nodeType":1293,"value":2403,"marks":2404,"data":2405},"What was the impact of the Microsoft breach?",[],{},{"nodeType":1414,"data":2407,"content":2408},{},[2409,2419,2429],{"nodeType":1418,"data":2410,"content":2411},{},[2412],{"nodeType":1294,"data":2413,"content":2414},{},[2415],{"nodeType":1293,"value":2416,"marks":2417,"data":2418},"APT29 had access to Microsoft corporate email accounts, including members of the senior leadership team and employees in the cybersecurity, legal, and other functions, resulting in sensitive data leakage.",[],{},{"nodeType":1418,"data":2420,"content":2421},{},[2422],{"nodeType":1294,"data":2423,"content":2424},{},[2425],{"nodeType":1293,"value":2426,"marks":2427,"data":2428},"Microsoft has not disclosed any further impacts at this time, but it is likely that the adversary had complete, unmitigated control of the Microsoft corporate tenant for a period of time, with global administrator level access.",[],{},{"nodeType":1418,"data":2430,"content":2431},{},[2432],{"nodeType":1294,"data":2433,"content":2434},{},[2435],{"nodeType":1293,"value":2436,"marks":2437,"data":2438},"Since the initial attack there has been evidence of continued targeting, with password spraying attacks reportedly increasing tenfold, likely informed by stolen information.",[],{},{"nodeType":1446,"data":2440,"content":2441},{},[2442],{"nodeType":1293,"value":2443,"marks":2444,"data":2445},"What stands out in the Microsoft breach?",[],{},{"nodeType":1414,"data":2447,"content":2448},{},[2449,2459,2469,2479],{"nodeType":1418,"data":2450,"content":2451},{},[2452],{"nodeType":1294,"data":2453,"content":2454},{},[2455],{"nodeType":1293,"value":2456,"marks":2457,"data":2458},"The attack was covert and targeted, with APT29 tailoring the attack to a limited number of accounts and using a low number of attempts to evade detection and avoid account blocks based on the volume of failures.",[],{},{"nodeType":1418,"data":2460,"content":2461},{},[2462],{"nodeType":1294,"data":2463,"content":2464},{},[2465],{"nodeType":1293,"value":2466,"marks":2467,"data":2468},"APT29 used residential proxy networks when interacting with the compromised tenant and, subsequently, with Exchange Online to obfuscate the source of their attack and avoid impossible travel detections. ",[],{},{"nodeType":1418,"data":2470,"content":2471},{},[2472],{"nodeType":1294,"data":2473,"content":2474},{},[2475],{"nodeType":1293,"value":2476,"marks":2477,"data":2478},"APT29 demonstrated mature and in-depth understanding of cloud infrastructure, protocols, and workflows, particularly in terms of privilege escalation and lateral movement.",[],{},{"nodeType":1418,"data":2480,"content":2481},{},[2482],{"nodeType":1294,"data":2483,"content":2484},{},[2485],{"nodeType":1293,"value":2486,"marks":2487,"data":2488},"If even Microsoft (an organization with pretty much unrivaled security resources) can’t ensure that all their accounts are protected by MFA and that there are no weak links between test/dev and prod systems, this should be a wake-up call for any company that thinks their MFA implementation is flawless. ",[],{},{"nodeType":1446,"data":2490,"content":2491},{},[2492],{"nodeType":1293,"value":2493,"marks":2494,"data":2495},"SaaS Attack Matrix mapping",[],{},{"nodeType":1294,"data":2497,"content":2498},{},[2499],{"nodeType":1293,"value":2035,"marks":2500,"data":2501},[],{},{"nodeType":2039,"data":2503,"content":2504},{},[2505,2545,2609,2673],{"nodeType":2043,"data":2506,"content":2507},{},[2508,2517,2527,2536],{"nodeType":2047,"data":2509,"content":2510},{},[2511],{"nodeType":1294,"data":2512,"content":2513},{},[2514],{"nodeType":1293,"value":2054,"marks":2515,"data":2516},[],{},{"nodeType":2047,"data":2518,"content":2519},{},[2520],{"nodeType":1294,"data":2521,"content":2522},{},[2523],{"nodeType":1293,"value":2524,"marks":2525,"data":2526},"Technique",[],{},{"nodeType":2047,"data":2528,"content":2529},{},[2530],{"nodeType":1294,"data":2531,"content":2532},{},[2533],{"nodeType":1293,"value":2074,"marks":2534,"data":2535},[],{},{"nodeType":2047,"data":2537,"content":2538},{},[2539],{"nodeType":1294,"data":2540,"content":2541},{},[2542],{"nodeType":1293,"value":2084,"marks":2543,"data":2544},[],{},{"nodeType":2043,"data":2546,"content":2547},{},[2548,2569,2589,2599],{"nodeType":2091,"data":2549,"content":2550},{},[2551],{"nodeType":1294,"data":2552,"content":2553},{},[2554,2557,2566],{"nodeType":1293,"value":37,"marks":2555,"data":2556},[],{},{"nodeType":1343,"data":2558,"content":2560},{"uri":2559},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/credential_stuffing/description.md",[2561],{"nodeType":1293,"value":2562,"marks":2563,"data":2565},"SAT1011",[2564],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2567,"data":2568},[],{},{"nodeType":2091,"data":2570,"content":2571},{},[2572],{"nodeType":1294,"data":2573,"content":2574},{},[2575,2578,2586],{"nodeType":1293,"value":37,"marks":2576,"data":2577},[],{},{"nodeType":1343,"data":2579,"content":2580},{"uri":2559},[2581],{"nodeType":1293,"value":2582,"marks":2583,"data":2585},"Credential stuffing",[2584],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2587,"data":2588},[],{},{"nodeType":2091,"data":2590,"content":2591},{},[2592],{"nodeType":1294,"data":2593,"content":2594},{},[2595],{"nodeType":1293,"value":2596,"marks":2597,"data":2598},"Initial Access",[],{},{"nodeType":2091,"data":2600,"content":2601},{},[2602],{"nodeType":1294,"data":2603,"content":2604},{},[2605],{"nodeType":1293,"value":2606,"marks":2607,"data":2608},"Attempt to authenticate to a SaaS account by guessing a large number of passwords ",[],{},{"nodeType":2043,"data":2610,"content":2611},{},[2612,2633,2653,2663],{"nodeType":2091,"data":2613,"content":2614},{},[2615],{"nodeType":1294,"data":2616,"content":2617},{},[2618,2621,2630],{"nodeType":1293,"value":37,"marks":2619,"data":2620},[],{},{"nodeType":1343,"data":2622,"content":2624},{"uri":2623},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/oauth_tokens/description.md",[2625],{"nodeType":1293,"value":2626,"marks":2627,"data":2629},"SAT1027",[2628],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2631,"data":2632},[],{},{"nodeType":2091,"data":2634,"content":2635},{},[2636],{"nodeType":1294,"data":2637,"content":2638},{},[2639,2642,2650],{"nodeType":1293,"value":37,"marks":2640,"data":2641},[],{},{"nodeType":1343,"data":2643,"content":2644},{"uri":2623},[2645],{"nodeType":1293,"value":2646,"marks":2647,"data":2649},"OAuth tokens",[2648],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2651,"data":2652},[],{},{"nodeType":2091,"data":2654,"content":2655},{},[2656],{"nodeType":1294,"data":2657,"content":2658},{},[2659],{"nodeType":1293,"value":2660,"marks":2661,"data":2662},"Execution; Persistence; Defense Evasion",[],{},{"nodeType":2091,"data":2664,"content":2665},{},[2666],{"nodeType":1294,"data":2667,"content":2668},{},[2669],{"nodeType":1293,"value":2670,"marks":2671,"data":2672},"Use a malicious OAuth app to create an OAuth token, using arbitrary permissions to maintain long-term programmatic access to a compromised user account.",[],{},{"nodeType":2043,"data":2674,"content":2675},{},[2676,2697,2717,2727],{"nodeType":2091,"data":2677,"content":2678},{},[2679],{"nodeType":1294,"data":2680,"content":2681},{},[2682,2685,2694],{"nodeType":1293,"value":37,"marks":2683,"data":2684},[],{},{"nodeType":1343,"data":2686,"content":2688},{"uri":2687},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/abuse_existing_oauth_integrations/description.md",[2689],{"nodeType":1293,"value":2690,"marks":2691,"data":2693},"SAT1001",[2692],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2695,"data":2696},[],{},{"nodeType":2091,"data":2698,"content":2699},{},[2700],{"nodeType":1294,"data":2701,"content":2702},{},[2703,2706,2714],{"nodeType":1293,"value":37,"marks":2704,"data":2705},[],{},{"nodeType":1343,"data":2707,"content":2708},{"uri":2687},[2709],{"nodeType":1293,"value":2710,"marks":2711,"data":2713},"Abuse existing OAuth integrations",[2712],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2715,"data":2716},[],{},{"nodeType":2091,"data":2718,"content":2719},{},[2720],{"nodeType":1294,"data":2721,"content":2722},{},[2723],{"nodeType":1293,"value":2724,"marks":2725,"data":2726},"Privilege Escalation;\nLateral Movement",[],{},{"nodeType":2091,"data":2728,"content":2729},{},[2730],{"nodeType":1294,"data":2731,"content":2732},{},[2733],{"nodeType":1293,"value":2734,"marks":2735,"data":2736},"If an adversary compromises a SaaS account integrated with other apps, they can escalate privileges and move laterally to other apps.",[],{},{"nodeType":1446,"data":2738,"content":2739},{},[2740],{"nodeType":1293,"value":2219,"marks":2741,"data":2742},[],{},{"nodeType":1294,"data":2744,"content":2745},{},[2746],{"nodeType":1293,"value":2747,"marks":2748,"data":2750},"Hewlett Packard Enterprise (HPE) — May 2023",[2749],{"type":1464},{},{"nodeType":1294,"data":2752,"content":2753},{},[2754],{"nodeType":1293,"value":2755,"marks":2756,"data":2757},"At the time of the Microsoft breach becoming public knowledge, HPE disclosed that they had become aware of a historical incident in Dec 2023, involving unauthorized access to and exfiltration of a limited number of SharePoint files as early as May 2023. Hackers accessed and exfiltrated data from HPE mailboxes belonging to individuals in the cybersecurity, go-to-market, business segments, and other functions. No further information is available on the techniques used or impact of the breach. ",[],{},{"nodeType":1522,"data":2759,"content":2760},{},[],{"nodeType":1328,"data":2762,"content":2763},{},[2764],{"nodeType":1293,"value":2765,"marks":2766,"data":2767},"Okta — October 2023",[],{},{"nodeType":1294,"data":2769,"content":2770},{},[2771],{"nodeType":1293,"value":2772,"marks":2773,"data":2774},"An unknown threat group compromised an Okta employee's personal Google account that was being used on a company-managed device, granting the threat actor access to a service account for Okta’s customer support system, that included session tokens for 134 customers. This was then used to hijack the legitimate Okta sessions of five customers. ",[],{},{"nodeType":1446,"data":2776,"content":2777},{},[2778],{"nodeType":1293,"value":2779,"marks":2780,"data":2781},"How did Okta get breached?",[],{},{"nodeType":1414,"data":2783,"content":2784},{},[2785,2795,2805,2815,2825],{"nodeType":1418,"data":2786,"content":2787},{},[2788],{"nodeType":1294,"data":2789,"content":2790},{},[2791],{"nodeType":1293,"value":2792,"marks":2793,"data":2794},"The threat actor compromised a personal Google account that the user had accessed from their Okta-managed work device by signing into their personal profile from the Chrome browser.",[],{},{"nodeType":1418,"data":2796,"content":2797},{},[2798],{"nodeType":1294,"data":2799,"content":2800},{},[2801],{"nodeType":1293,"value":2802,"marks":2803,"data":2804},"The personal account credentials are likely to have been compromised in a historical data breach and did not have MFA enabled.",[],{},{"nodeType":1418,"data":2806,"content":2807},{},[2808],{"nodeType":1294,"data":2809,"content":2810},{},[2811],{"nodeType":1293,"value":2812,"marks":2813,"data":2814},"The username and password of a service account for Okta’s customer support system had been saved into the employee’s personal Google account and was therefore compromised.",[],{},{"nodeType":1418,"data":2816,"content":2817},{},[2818],{"nodeType":1294,"data":2819,"content":2820},{},[2821],{"nodeType":1293,"value":2822,"marks":2823,"data":2824},"The threat actor was able to access the service account by logging in using the stolen credentials, which again likely did not have MFA deployed as a service account.",[],{},{"nodeType":1418,"data":2826,"content":2827},{},[2828],{"nodeType":1294,"data":2829,"content":2830},{},[2831],{"nodeType":1293,"value":2832,"marks":2833,"data":2834},"The threat actor was able to use session tokens in the HAR files to impersonate staff and hijack the legitimate Okta sessions of five customers, including 1Password, BeyondTrust, and Cloudflare.",[],{},{"nodeType":1446,"data":2836,"content":2837},{},[2838],{"nodeType":1293,"value":2839,"marks":2840,"data":2841},"What was the impact of the Okta breach?",[],{},{"nodeType":1414,"data":2843,"content":2844},{},[2845,2855,2865,2875],{"nodeType":1418,"data":2846,"content":2847},{},[2848],{"nodeType":1294,"data":2849,"content":2850},{},[2851],{"nodeType":1293,"value":2852,"marks":2853,"data":2854},"The threat actor gained unauthorized access to files inside Okta’s customer support system associated with 134 Okta customers.",[],{},{"nodeType":1418,"data":2856,"content":2857},{},[2858],{"nodeType":1294,"data":2859,"content":2860},{},[2861],{"nodeType":1293,"value":2862,"marks":2863,"data":2864},"The threat actor was able to use these session tokens to hijack the legitimate Okta sessions of 5 (publicly disclosed) customers.",[],{},{"nodeType":1418,"data":2866,"content":2867},{},[2868],{"nodeType":1294,"data":2869,"content":2870},{},[2871],{"nodeType":1293,"value":2872,"marks":2873,"data":2874},"Okta originally claimed the breach had impacted only 1% of customers, but later found that a report run and downloaded by the threat actor contained the names and email addresses of all 18,400 Okta customer support users, as well as some Okta employee information, meaning 100% of customer support users were impacted.",[],{},{"nodeType":1418,"data":2876,"content":2877},{},[2878],{"nodeType":1294,"data":2879,"content":2880},{},[2881],{"nodeType":1293,"value":2882,"marks":2883,"data":2884},"Okta users are at higher risk of phishing and credential stuffing attacks based on the data stolen by the threat actor, increasing the importance of robust MFA implementation.",[],{},{"nodeType":1446,"data":2886,"content":2887},{},[2888],{"nodeType":1293,"value":2889,"marks":2890,"data":2891},"What stands out in the Okta breach?",[],{},{"nodeType":1414,"data":2893,"content":2894},{},[2895,2905,2915],{"nodeType":1418,"data":2896,"content":2897},{},[2898],{"nodeType":1294,"data":2899,"content":2900},{},[2901],{"nodeType":1293,"value":2902,"marks":2903,"data":2904},"This attack demonstrates the risk associated with cloud Identity Providers and the potential goldmine that they are to attackers. Much in the same way that the manufacturers of physical and virtual network appliances are continuously probed for software vulnerabilities, cloud IdPs like Okta present a huge potential opportunity, both in terms of targeting specific organizational instances as well as the Okta organization. This attack showcases the possibility of third-party supply chain attacks to target downstream organizations using IdP services. ",[],{},{"nodeType":1418,"data":2906,"content":2907},{},[2908],{"nodeType":1294,"data":2909,"content":2910},{},[2911],{"nodeType":1293,"value":2912,"marks":2913,"data":2914},"Similar to the Microsoft breach, gaps were discovered and exploited in Okta’s MFA coverage and implementation, highlighting that there are gaps in even the most mature organizations. ",[],{},{"nodeType":1418,"data":2916,"content":2917},{},[2918],{"nodeType":1294,"data":2919,"content":2920},{},[2921],{"nodeType":1293,"value":2922,"marks":2923,"data":2924},"The subsequent attack on Cloudflare (see below) and the scale of the recovery effort demonstrates the significant operational overhead in responding to and recovering from a breach of identity infrastructure, with a similar or greater scale than a traditional Active Directory compromise. While addressing the incident, Cloudflare's staff rotated all production credentials (over 5,000 unique ones), physically segmented test and staging systems, performed forensic triage on 4,893 systems, reimaged and rebooted all systems on the company's global network, including all Atlassian servers (Jira, Confluence, and Bitbucket) and machines accessed by the threat actor. All equipment in Cloudflare's Brazil data center, which was unsuccessfully targeted by the threat actor, was later returned to the manufacturers to ensure that the data center was secure.",[],{},{"nodeType":1446,"data":2926,"content":2927},{},[2928],{"nodeType":1293,"value":2493,"marks":2929,"data":2930},[],{},{"nodeType":1294,"data":2932,"content":2933},{},[2934],{"nodeType":1293,"value":2035,"marks":2935,"data":2936},[],{},{"nodeType":2039,"data":2938,"content":2939},{},[2940,2979,3038],{"nodeType":2043,"data":2941,"content":2942},{},[2943,2952,2961,2970],{"nodeType":2047,"data":2944,"content":2945},{},[2946],{"nodeType":1294,"data":2947,"content":2948},{},[2949],{"nodeType":1293,"value":2054,"marks":2950,"data":2951},[],{},{"nodeType":2047,"data":2953,"content":2954},{},[2955],{"nodeType":1294,"data":2956,"content":2957},{},[2958],{"nodeType":1293,"value":2524,"marks":2959,"data":2960},[],{},{"nodeType":2047,"data":2962,"content":2963},{},[2964],{"nodeType":1294,"data":2965,"content":2966},{},[2967],{"nodeType":1293,"value":2074,"marks":2968,"data":2969},[],{},{"nodeType":2047,"data":2971,"content":2972},{},[2973],{"nodeType":1294,"data":2974,"content":2975},{},[2976],{"nodeType":1293,"value":2084,"marks":2977,"data":2978},[],{},{"nodeType":2043,"data":2980,"content":2981},{},[2982,3001,3020,3029],{"nodeType":2091,"data":2983,"content":2984},{},[2985],{"nodeType":1294,"data":2986,"content":2987},{},[2988,2991,2998],{"nodeType":1293,"value":37,"marks":2989,"data":2990},[],{},{"nodeType":1343,"data":2992,"content":2993},{"uri":2559},[2994],{"nodeType":1293,"value":2562,"marks":2995,"data":2997},[2996],{"type":1351},{},{"nodeType":1293,"value":37,"marks":2999,"data":3000},[],{},{"nodeType":2091,"data":3002,"content":3003},{},[3004],{"nodeType":1294,"data":3005,"content":3006},{},[3007,3010,3017],{"nodeType":1293,"value":37,"marks":3008,"data":3009},[],{},{"nodeType":1343,"data":3011,"content":3012},{"uri":2559},[3013],{"nodeType":1293,"value":2582,"marks":3014,"data":3016},[3015],{"type":1351},{},{"nodeType":1293,"value":37,"marks":3018,"data":3019},[],{},{"nodeType":2091,"data":3021,"content":3022},{},[3023],{"nodeType":1294,"data":3024,"content":3025},{},[3026],{"nodeType":1293,"value":2596,"marks":3027,"data":3028},[],{},{"nodeType":2091,"data":3030,"content":3031},{},[3032],{"nodeType":1294,"data":3033,"content":3034},{},[3035],{"nodeType":1293,"value":2606,"marks":3036,"data":3037},[],{},{"nodeType":2043,"data":3039,"content":3040},{},[3041,3062,3082,3092],{"nodeType":2091,"data":3042,"content":3043},{},[3044],{"nodeType":1294,"data":3045,"content":3046},{},[3047,3050,3059],{"nodeType":1293,"value":37,"marks":3048,"data":3049},[],{},{"nodeType":1343,"data":3051,"content":3053},{"uri":3052},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/password_scraping/description.md",[3054],{"nodeType":1293,"value":3055,"marks":3056,"data":3058},"SAT1028",[3057],{"type":1351},{},{"nodeType":1293,"value":37,"marks":3060,"data":3061},[],{},{"nodeType":2091,"data":3063,"content":3064},{},[3065],{"nodeType":1294,"data":3066,"content":3067},{},[3068,3071,3079],{"nodeType":1293,"value":37,"marks":3069,"data":3070},[],{},{"nodeType":1343,"data":3072,"content":3073},{"uri":3052},[3074],{"nodeType":1293,"value":3075,"marks":3076,"data":3078},"Password Scraping",[3077],{"type":1351},{},{"nodeType":1293,"value":37,"marks":3080,"data":3081},[],{},{"nodeType":2091,"data":3083,"content":3084},{},[3085],{"nodeType":1294,"data":3086,"content":3087},{},[3088],{"nodeType":1293,"value":3089,"marks":3090,"data":3091},"Credential Access",[],{},{"nodeType":2091,"data":3093,"content":3094},{},[3095],{"nodeType":1294,"data":3096,"content":3097},{},[3098],{"nodeType":1293,"value":3099,"marks":3100,"data":3101},"Collection of credentials and secrets from repositories e.g. password managers, SaaS file stores, etc.",[],{},{"nodeType":1446,"data":3103,"content":3104},{},[3105],{"nodeType":1293,"value":2219,"marks":3106,"data":3107},[],{},{"nodeType":1294,"data":3109,"content":3110},{},[3111],{"nodeType":1293,"value":3112,"marks":3113,"data":3115},"Cloudflare — November 2023",[3114],{"type":1464},{},{"nodeType":1294,"data":3117,"content":3118},{},[3119],{"nodeType":1293,"value":3120,"marks":3121,"data":3122},"The threat actor used tokens and credentials that had not been rotated to breach Cloudflare’s internal Atlassian server and access its Confluence wiki, Jira bug database, and Bitbucket source code management system. The threat actor first gained access to Cloudflare's self-hosted Atlassian server and then accessed the company's Confluence and Jira systems following a reconnaissance stage. Cloudflare says that this breach did not impact customer data or systems or the provision of services.",[],{},{"nodeType":1294,"data":3124,"content":3125},{},[3126],{"nodeType":1293,"value":3127,"marks":3128,"data":3130},"1Password — October 2023",[3129],{"type":1464},{},{"nodeType":1294,"data":3132,"content":3133},{},[3134],{"nodeType":1293,"value":3135,"marks":3136,"data":3137},"1Password reported unsolicited activity in their Okta environment which was traced to a suspicious IP address. Later it was confirmed that an threat actor had accessed 1Password’s Okta environment using administrative privileges. They attempted to access the IT team member’s user dashboard, but that attempt was blocked by Okta. They also requested a report of administrative users, which was identified as suspicious and triggered an investigation. 1Password says it terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing.",[],{},{"nodeType":1294,"data":3139,"content":3140},{},[3141],{"nodeType":1293,"value":3142,"marks":3143,"data":3145},"BeyondTrust - October 2023",[3144],{"type":1464},{},{"nodeType":1294,"data":3147,"content":3148},{},[3149],{"nodeType":1293,"value":3150,"marks":3151,"data":3152},"BeyondTrust security teams detected an identity-centric attack on an in-house Okta administrator account. BeyondTrust blocked all access to the threat actor, and verified that they did not gain access to any systems. BeyondTrust has confirmed that there was no additional exposure to our internal systems or BeyondTrust’s customers.",[],{},{"nodeType":1522,"data":3154,"content":3155},{},[],{"nodeType":1328,"data":3157,"content":3158},{},[3159],{"nodeType":1293,"value":3160,"marks":3161,"data":3162},"MGM Resorts — September 2023",[],{},{"nodeType":1294,"data":3164,"content":3165},{},[3166],{"nodeType":1293,"value":3167,"marks":3168,"data":3169},"The threat group known as Scattered Spider socially engineered MGM help desk personnel to grant ‘super admin’ access to the Okta tenant, which was then used to steal data and deploy ransomware, resulting in significant business disruption. ",[],{},{"nodeType":1446,"data":3171,"content":3172},{},[3173],{"nodeType":1293,"value":3174,"marks":3175,"data":3176},"How did MGM get breached?",[],{},{"nodeType":1414,"data":3178,"content":3179},{},[3180,3190,3200,3210,3220,3230],{"nodeType":1418,"data":3181,"content":3182},{},[3183],{"nodeType":1294,"data":3184,"content":3185},{},[3186],{"nodeType":1293,"value":3187,"marks":3188,"data":3189},"Scattered Spider researched MGM employees on LinkedIn to identify individuals likely to have privileged Okta access, specifically Super Administrator privileges. ",[],{},{"nodeType":1418,"data":3191,"content":3192},{},[3193],{"nodeType":1294,"data":3194,"content":3195},{},[3196],{"nodeType":1293,"value":3197,"marks":3198,"data":3199},"Scattered Spider contacted the IT help desk impersonating an employee with a privileged account asking for an authentication reset (password and MFA).",[],{},{"nodeType":1418,"data":3201,"content":3202},{},[3203],{"nodeType":1294,"data":3204,"content":3205},{},[3206],{"nodeType":1293,"value":3207,"marks":3208,"data":3209},"With privileged access, the compromised Super Administrator accounts were used to assign higher privileges to other accounts, circumventing MFA by removing enrolled authenticators and/or removing MFA from authentication policies.",[],{},{"nodeType":1418,"data":3211,"content":3212},{},[3213],{"nodeType":1294,"data":3214,"content":3215},{},[3216],{"nodeType":1293,"value":3217,"marks":3218,"data":3219},"Scattered Spider registered a second, attacker-controlled IdP via Org2Org using inbound federation, granting the ability to impersonate users and access applications on their behalf. By matching the username of target accounts in the second IdP to the original, the attacker was able to SSO into target applications. ",[],{},{"nodeType":1418,"data":3221,"content":3222},{},[3223],{"nodeType":1294,"data":3224,"content":3225},{},[3226],{"nodeType":1293,"value":3227,"marks":3228,"data":3229},"Through inbound federation, Scattered Spider obtained global admin rights in Azure, effectively granting full control over connected systems and granting domain admin privileges in target environments.",[],{},{"nodeType":1418,"data":3231,"content":3232},{},[3233],{"nodeType":1294,"data":3234,"content":3235},{},[3236],{"nodeType":1293,"value":3237,"marks":3238,"data":3239},"Scattered Spider deployed encryption software to around 100 ESXi servers and exfiltrated data, disrupting core business operations.",[],{},{"nodeType":1446,"data":3241,"content":3242},{},[3243],{"nodeType":1293,"value":3244,"marks":3245,"data":3246},"What was the impact of the MGM breach?",[],{},{"nodeType":1414,"data":3248,"content":3249},{},[3250,3260,3270],{"nodeType":1418,"data":3251,"content":3252},{},[3253],{"nodeType":1294,"data":3254,"content":3255},{},[3256],{"nodeType":1293,"value":3257,"marks":3258,"data":3259},"Led to a 36-hour outage of multiple MGM IT systems and affected a number of its casinos on the Las Vegas strip, including the Bellagio, Excalibur, Luxor, Mandalay Bay and New York New York.",[],{},{"nodeType":1418,"data":3261,"content":3262},{},[3263],{"nodeType":1294,"data":3264,"content":3265},{},[3266],{"nodeType":1293,"value":3267,"marks":3268,"data":3269},"Personal data compromise of an unspecified number of customers including various contact information, dates of births, genders, driver’s license numbers, social security numbers, and passport information. ",[],{},{"nodeType":1418,"data":3271,"content":3272},{},[3273],{"nodeType":1294,"data":3274,"content":3275},{},[3276],{"nodeType":1293,"value":3277,"marks":3278,"data":3279},"MGM reported that the attack would cause a $100 million hit to its third-quarter results, including $10 million in one-time cyber security consulting fees. ",[],{},{"nodeType":1446,"data":3281,"content":3282},{},[3283],{"nodeType":1293,"value":3284,"marks":3285,"data":3286},"What stands out in the MGM breach?",[],{},{"nodeType":1414,"data":3288,"content":3289},{},[3290,3300,3310],{"nodeType":1418,"data":3291,"content":3292},{},[3293],{"nodeType":1294,"data":3294,"content":3295},{},[3296],{"nodeType":1293,"value":3297,"marks":3298,"data":3299},"The MGM breach demonstrates how financially motivated organized criminal groups are specifically targeting the identity infrastructure of an organization (e.g. the chosen IdP solution) and leveraging cloud-native functionality. ",[],{},{"nodeType":1418,"data":3301,"content":3302},{},[3303],{"nodeType":1294,"data":3304,"content":3305},{},[3306],{"nodeType":1293,"value":3307,"marks":3308,"data":3309},"The MGM breach is notable for being a hybrid attack that ended in what has become a typical “actions on objective” for ransomware operators and their affiliates - the propagation of malware and encryption of core business servers. In this way attackers are leveraging the newer functionality that cloud services provide them to target non-cloud/on-premise resources. This potentially indicates that attackers see cloud applications and services as the path of least resistance to achieving their goals, exploiting more limited security team visibility and understanding of these services compared to more traditional (now well protected) targets. ",[],{},{"nodeType":1418,"data":3311,"content":3312},{},[3313],{"nodeType":1294,"data":3314,"content":3315},{},[3316],{"nodeType":1293,"value":3317,"marks":3318,"data":3319},"While attackers were focused on taking control of the cloud IdP, the initial access vector was notable for being a more traditional method (vishing) to bypass the need to acquire credentials (password and MFA token). This type of technique remains consistently effective, regardless of the technology landscape and whether MFA is correctly implemented or not.    ",[],{},{"nodeType":1446,"data":3321,"content":3322},{},[3323],{"nodeType":1293,"value":2493,"marks":3324,"data":3325},[],{},{"nodeType":1294,"data":3327,"content":3328},{},[3329],{"nodeType":1293,"value":2035,"marks":3330,"data":3331},[],{},{"nodeType":2039,"data":3333,"content":3334},{},[3335,3374],{"nodeType":2043,"data":3336,"content":3337},{},[3338,3347,3356,3365],{"nodeType":2047,"data":3339,"content":3340},{},[3341],{"nodeType":1294,"data":3342,"content":3343},{},[3344],{"nodeType":1293,"value":2054,"marks":3345,"data":3346},[],{},{"nodeType":2047,"data":3348,"content":3349},{},[3350],{"nodeType":1294,"data":3351,"content":3352},{},[3353],{"nodeType":1293,"value":2524,"marks":3354,"data":3355},[],{},{"nodeType":2047,"data":3357,"content":3358},{},[3359],{"nodeType":1294,"data":3360,"content":3361},{},[3362],{"nodeType":1293,"value":2074,"marks":3363,"data":3364},[],{},{"nodeType":2047,"data":3366,"content":3367},{},[3368],{"nodeType":1294,"data":3369,"content":3370},{},[3371],{"nodeType":1293,"value":2084,"marks":3372,"data":3373},[],{},{"nodeType":2043,"data":3375,"content":3376},{},[3377,3398,3418,3428],{"nodeType":2091,"data":3378,"content":3379},{},[3380],{"nodeType":1294,"data":3381,"content":3382},{},[3383,3386,3395],{"nodeType":1293,"value":37,"marks":3384,"data":3385},[],{},{"nodeType":1343,"data":3387,"content":3389},{"uri":3388},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/inbound_federation/description.md",[3390],{"nodeType":1293,"value":3391,"marks":3392,"data":3394},"SAT1041",[3393],{"type":1351},{},{"nodeType":1293,"value":37,"marks":3396,"data":3397},[],{},{"nodeType":2091,"data":3399,"content":3400},{},[3401],{"nodeType":1294,"data":3402,"content":3403},{},[3404,3407,3415],{"nodeType":1293,"value":37,"marks":3405,"data":3406},[],{},{"nodeType":1343,"data":3408,"content":3409},{"uri":3388},[3410],{"nodeType":1293,"value":3411,"marks":3412,"data":3414},"Inbound Federation",[3413],{"type":1351},{},{"nodeType":1293,"value":37,"marks":3416,"data":3417},[],{},{"nodeType":2091,"data":3419,"content":3420},{},[3421],{"nodeType":1294,"data":3422,"content":3423},{},[3424],{"nodeType":1293,"value":3425,"marks":3426,"data":3427},"Persistence; Lateral Movement",[],{},{"nodeType":2091,"data":3429,"content":3430},{},[3431],{"nodeType":1294,"data":3432,"content":3433},{},[3434],{"nodeType":1293,"value":3435,"marks":3436,"data":3437},"Inbound federation allows users to login to a target identity provider by authenticating with a source identity provider",[],{},{"nodeType":1522,"data":3439,"content":3440},{},[],{"nodeType":1328,"data":3442,"content":3443},{},[3444],{"nodeType":1293,"value":3445,"marks":3446,"data":3447},"Retool — August 2023",[],{},{"nodeType":1294,"data":3449,"content":3450},{},[3451],{"nodeType":1293,"value":3452,"marks":3453,"data":3454},"Software development company Retool disclosed that the accounts of 27 of its cloud customers were compromised following a targeted SMS-based social engineering attack, which was enabled by Google Authenticator’s default synchronization of MFA tokens with the associated Google account.  ",[],{},{"nodeType":1446,"data":3456,"content":3457},{},[3458],{"nodeType":1293,"value":3459,"marks":3460,"data":3461},"How did Retool get breached?",[],{},{"nodeType":1414,"data":3463,"content":3464},{},[3465,3475,3485,3495,3505,3515],{"nodeType":1418,"data":3466,"content":3467},{},[3468],{"nodeType":1294,"data":3469,"content":3470},{},[3471],{"nodeType":1293,"value":3472,"marks":3473,"data":3474},"The threat actor launched a targeted SMS-based phishing campaign against Retool employees with a custom lure relating to their workplace healthcare coverage.",[],{},{"nodeType":1418,"data":3476,"content":3477},{},[3478],{"nodeType":1294,"data":3479,"content":3480},{},[3481],{"nodeType":1293,"value":3482,"marks":3483,"data":3484},"The timing coincided with a recently announced migration of logins to Okta, and the message contained a url disguised to look like their internal identity portal.",[],{},{"nodeType":1418,"data":3486,"content":3487},{},[3488],{"nodeType":1294,"data":3489,"content":3490},{},[3491],{"nodeType":1293,"value":3492,"marks":3493,"data":3494},"After logging into the fake portal – which included an MFA form – the threat actor called the employee impersonating an IT team member, deepfaking the IT employee’s real voice and using real information about the company to build trust.",[],{},{"nodeType":1418,"data":3496,"content":3497},{},[3498],{"nodeType":1294,"data":3499,"content":3500},{},[3501],{"nodeType":1293,"value":3502,"marks":3503,"data":3504},"The phished employee shared an MFA OTP token which allowed the threat actor to add their own personal device to the employee’s Okta account and enabled their own Okta MFA from that point forward.",[],{},{"nodeType":1418,"data":3506,"content":3507},{},[3508],{"nodeType":1294,"data":3509,"content":3510},{},[3511],{"nodeType":1293,"value":3512,"marks":3513,"data":3514},"Due to the Google Authenticator synchronization feature that syncs MFA codes to the cloud by default, meaning that access to a Google account immediately gave access to all MFA tokens held within that account.",[],{},{"nodeType":1418,"data":3516,"content":3517},{},[3518],{"nodeType":1294,"data":3519,"content":3520},{},[3521],{"nodeType":1293,"value":3522,"marks":3523,"data":3524},"This enabled the threat actor to take over a number of identities associated with a range of target apps and change the credentials.",[],{},{"nodeType":1446,"data":3526,"content":3527},{},[3528],{"nodeType":1293,"value":3529,"marks":3530,"data":3531},"What was the impact of the Retool breach?",[],{},{"nodeType":1414,"data":3533,"content":3534},{},[3535,3545,3555],{"nodeType":1418,"data":3536,"content":3537},{},[3538],{"nodeType":1294,"data":3539,"content":3540},{},[3541],{"nodeType":1293,"value":3542,"marks":3543,"data":3544},"A total of 27 customers were impacted, with the threat actor specifically targeting customers in the Crypto industry.",[],{},{"nodeType":1418,"data":3546,"content":3547},{},[3548],{"nodeType":1294,"data":3549,"content":3550},{},[3551],{"nodeType":1293,"value":3552,"marks":3553,"data":3554},"After taking over the accounts, the threat actor was observed gathering information and exploring the Retool apps.",[],{},{"nodeType":1418,"data":3556,"content":3557},{},[3558],{"nodeType":1294,"data":3559,"content":3560},{},[3561],{"nodeType":1293,"value":3562,"marks":3563,"data":3564},"After learning of the attack, Retool revoked all internal authenticated sessions (Okta, GSuite, etc.) for employees, locked down access to the affected accounts, notified the affected customers, and restored their accounts to their original state.",[],{},{"nodeType":1446,"data":3566,"content":3567},{},[3568],{"nodeType":1293,"value":3569,"marks":3570,"data":3571},"What stands out in the Retool breach?",[],{},{"nodeType":1414,"data":3573,"content":3574},{},[3575,3585,3595],{"nodeType":1418,"data":3576,"content":3577},{},[3578],{"nodeType":1294,"data":3579,"content":3580},{},[3581],{"nodeType":1293,"value":3582,"marks":3583,"data":3584},"Like the MGM breach, the Retool breach demonstrates how financially motivated organized criminal groups are specifically targeting the identity infrastructure of an organization (e.g. the chosen IdP solution) and leveraging cloud-native functionality. ",[],{},{"nodeType":1418,"data":3586,"content":3587},{},[3588],{"nodeType":1294,"data":3589,"content":3590},{},[3591],{"nodeType":1293,"value":3592,"marks":3593,"data":3594},"A further similarity with the MGM breach, while attackers were focused on taking control of the cloud IdP, the initial access vector was notable for being a more traditional method (SMS phishing in this case) to bypass the need to acquire credentials (password and MFA token). This type of technique remains consistently effective, regardless of the technology landscape and whether MFA is correctly implemented or not.    ",[],{},{"nodeType":1418,"data":3596,"content":3597},{},[3598],{"nodeType":1294,"data":3599,"content":3600},{},[3601],{"nodeType":1293,"value":3602,"marks":3603,"data":3604},"In this case, the attacker abused inherent weaknesses in Google Authenticator, which came under fire following the breach for its default synchronization of MFA codes to the cloud when connected to an account, in order to move laterally and compromise other target apps. ",[],{},{"nodeType":1446,"data":3606,"content":3607},{},[3608],{"nodeType":1293,"value":2493,"marks":3609,"data":3610},[],{},{"nodeType":1294,"data":3612,"content":3613},{},[3614],{"nodeType":1293,"value":2035,"marks":3615,"data":3616},[],{},{"nodeType":2039,"data":3618,"content":3619},{},[3620,3659,3724],{"nodeType":2043,"data":3621,"content":3622},{},[3623,3632,3641,3650],{"nodeType":2047,"data":3624,"content":3625},{},[3626],{"nodeType":1294,"data":3627,"content":3628},{},[3629],{"nodeType":1293,"value":2054,"marks":3630,"data":3631},[],{},{"nodeType":2047,"data":3633,"content":3634},{},[3635],{"nodeType":1294,"data":3636,"content":3637},{},[3638],{"nodeType":1293,"value":2524,"marks":3639,"data":3640},[],{},{"nodeType":2047,"data":3642,"content":3643},{},[3644],{"nodeType":1294,"data":3645,"content":3646},{},[3647],{"nodeType":1293,"value":2074,"marks":3648,"data":3649},[],{},{"nodeType":2047,"data":3651,"content":3652},{},[3653],{"nodeType":1294,"data":3654,"content":3655},{},[3656],{"nodeType":1293,"value":2084,"marks":3657,"data":3658},[],{},{"nodeType":2043,"data":3660,"content":3661},{},[3662,3684,3705,3714],{"nodeType":2091,"data":3663,"content":3664},{},[3665],{"nodeType":1294,"data":3666,"content":3667},{},[3668,3672,3681],{"nodeType":1293,"value":37,"marks":3669,"data":3671},[3670],{"type":1351},{},{"nodeType":1343,"data":3673,"content":3675},{"uri":3674},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/aitm_phishing/description.md",[3676],{"nodeType":1293,"value":3677,"marks":3678,"data":3680},"SAT1042",[3679],{"type":1351},{},{"nodeType":1293,"value":37,"marks":3682,"data":3683},[],{},{"nodeType":2091,"data":3685,"content":3686},{},[3687],{"nodeType":1294,"data":3688,"content":3689},{},[3690,3694,3702],{"nodeType":1293,"value":37,"marks":3691,"data":3693},[3692],{"type":1351},{},{"nodeType":1343,"data":3695,"content":3696},{"uri":3674},[3697],{"nodeType":1293,"value":3698,"marks":3699,"data":3701},"AiTM Phishing",[3700],{"type":1351},{},{"nodeType":1293,"value":37,"marks":3703,"data":3704},[],{},{"nodeType":2091,"data":3706,"content":3707},{},[3708],{"nodeType":1294,"data":3709,"content":3710},{},[3711],{"nodeType":1293,"value":2596,"marks":3712,"data":3713},[],{},{"nodeType":2091,"data":3715,"content":3716},{},[3717],{"nodeType":1294,"data":3718,"content":3719},{},[3720],{"nodeType":1293,"value":3721,"marks":3722,"data":3723},"Attacker-in-the-Middle (AiTM) phishing uses dedicated tooling to act as a web proxy between the victim and a legitimate login portal for an application the victim has access to, principally to make it easier to defeat MFA protection.",[],{},{"nodeType":2043,"data":3725,"content":3726},{},[3727,3748,3770,3780],{"nodeType":2091,"data":3728,"content":3729},{},[3730],{"nodeType":1294,"data":3731,"content":3732},{},[3733,3736,3745],{"nodeType":1293,"value":37,"marks":3734,"data":3735},[],{},{"nodeType":1343,"data":3737,"content":3739},{"uri":3738},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_enrollment/description.md",[3740],{"nodeType":1293,"value":3741,"marks":3742,"data":3744},"SAT1043",[3743],{"type":1351},{},{"nodeType":1293,"value":37,"marks":3746,"data":3747},[],{},{"nodeType":2091,"data":3749,"content":3750},{},[3751],{"nodeType":1294,"data":3752,"content":3753},{},[3754,3758,3766],{"nodeType":1293,"value":37,"marks":3755,"data":3757},[3756],{"type":1351},{},{"nodeType":1343,"data":3759,"content":3760},{"uri":3738},[3761],{"nodeType":1293,"value":3762,"marks":3763,"data":3765},"Device Enrollment",[3764],{"type":1351},{},{"nodeType":1293,"value":37,"marks":3767,"data":3769},[3768],{"type":1351},{},{"nodeType":2091,"data":3771,"content":3772},{},[3773],{"nodeType":1294,"data":3774,"content":3775},{},[3776],{"nodeType":1293,"value":3777,"marks":3778,"data":3779},"Initial Access; Persistence",[],{},{"nodeType":2091,"data":3781,"content":3782},{},[3783],{"nodeType":1294,"data":3784,"content":3785},{},[3786],{"nodeType":1293,"value":3787,"marks":3788,"data":3789},"Enrollment of a new MFA device in order to allow an adversary to complete MFA challenges for future authentication. ",[],{},{"nodeType":1522,"data":3791,"content":3792},{},[],{"nodeType":1328,"data":3794,"content":3795},{},[3796],{"nodeType":1293,"value":3797,"marks":3798,"data":3799},"GitHub / Heroku / Travis-CI / npm — April 2022",[],{},{"nodeType":1294,"data":3801,"content":3802},{},[3803],{"nodeType":1293,"value":3804,"marks":3805,"data":3806},"An unknown threat actor used stolen OAuth user tokens (issued to Heroku and Travis-CI) to download data from private repositories. The threat actor then compromised an internal Heroku customer database as well as accessed and stole data from dozens of downstream organizations using Heroku and Travis-CI-maintained OAuth apps.",[],{},{"nodeType":1446,"data":3808,"content":3809},{},[3810],{"nodeType":1293,"value":3811,"marks":3812,"data":3813},"How did they get breached?",[],{},{"nodeType":1414,"data":3815,"content":3816},{},[3817,3827,3837,3847,3857,3867,3877],{"nodeType":1418,"data":3818,"content":3819},{},[3820],{"nodeType":1294,"data":3821,"content":3822},{},[3823],{"nodeType":1293,"value":3824,"marks":3825,"data":3826},"The threat actor obtained access to two third-party OAuth integrators, Heroku and Travis-CI, accessing databases and downloading stored customer GitHub integration OAuth tokens. These tokens had earlier been used by Travis-CI and Heroku OAuth applications to integrate with GitHub to deploy applications.",[],{},{"nodeType":1418,"data":3828,"content":3829},{},[3830],{"nodeType":1294,"data":3831,"content":3832},{},[3833],{"nodeType":1293,"value":3834,"marks":3835,"data":3836},"Access to the environment was gained by leveraging a compromised token for a Heroku machine account, but it is not disclosed how the threat actor achieved this. ",[],{},{"nodeType":1418,"data":3838,"content":3839},{},[3840],{"nodeType":1294,"data":3841,"content":3842},{},[3843],{"nodeType":1293,"value":3844,"marks":3845,"data":3846},"The threat actor authenticated to the GitHub API using the stolen OAuth tokens issued to Heroku and Travis CI.",[],{},{"nodeType":1418,"data":3848,"content":3849},{},[3850],{"nodeType":1294,"data":3851,"content":3852},{},[3853],{"nodeType":1293,"value":3854,"marks":3855,"data":3856},"For users who had the affected Heroku or Travis CI OAuth apps authorized in their GitHub accounts, the threat actor listed all the user's organizations.",[],{},{"nodeType":1418,"data":3858,"content":3859},{},[3860],{"nodeType":1294,"data":3861,"content":3862},{},[3863],{"nodeType":1293,"value":3864,"marks":3865,"data":3866},"The threat actor then selected targets based on the listed organizations.",[],{},{"nodeType":1418,"data":3868,"content":3869},{},[3870],{"nodeType":1294,"data":3871,"content":3872},{},[3873],{"nodeType":1293,"value":3874,"marks":3875,"data":3876},"The threat actor listed the private repositories for user accounts of interest and proceeded to clone private repositories of interest.",[],{},{"nodeType":1418,"data":3878,"content":3879},{},[3880],{"nodeType":1294,"data":3881,"content":3882},{},[3883],{"nodeType":1293,"value":3884,"marks":3885,"data":3886},"GitHub identified unauthorized access to their npm production infrastructure using a compromised AWS API key, obtained by the threat actor when they downloaded a set of private npm repositories using a stolen OAuth token from one of the two affected third-party OAuth applications.",[],{},{"nodeType":1446,"data":3888,"content":3889},{},[3890],{"nodeType":1293,"value":3891,"marks":3892,"data":3893},"What was the impact?",[],{},{"nodeType":1414,"data":3895,"content":3896},{},[3897,3907,3917],{"nodeType":1418,"data":3898,"content":3899},{},[3900],{"nodeType":1294,"data":3901,"content":3902},{},[3903],{"nodeType":1293,"value":3904,"marks":3905,"data":3906},"By stealing these OAuth tokens, the threat actor could access and download data from GitHub repositories belonging to those who authorized the compromised Heroku or Travis CI OAuth apps with their accounts. ",[],{},{"nodeType":1418,"data":3908,"content":3909},{},[3910],{"nodeType":1294,"data":3911,"content":3912},{},[3913],{"nodeType":1293,"value":3914,"marks":3915,"data":3916},"The threat actor was able to mine the downloaded private repositories for secrets that could be used to pivot to other infrastructure, stealing data from dozens of organizations. ",[],{},{"nodeType":1418,"data":3918,"content":3919},{},[3920],{"nodeType":1294,"data":3921,"content":3922},{},[3923],{"nodeType":1293,"value":3924,"marks":3925,"data":3926},"In addition to user repo’s downstream, the compromised token for a Heroku machine account obtained by threat actors also allowed unauthorized access into Heroku's internal database of customer accounts, enabling the threat actor to extract the hashed and salted passwords. ",[],{},{"nodeType":1446,"data":3928,"content":3929},{},[3930],{"nodeType":1293,"value":3931,"marks":3932,"data":3933},"What stands out in the Github breach?",[],{},{"nodeType":1414,"data":3935,"content":3936},{},[3937,3947,3957],{"nodeType":1418,"data":3938,"content":3939},{},[3940],{"nodeType":1294,"data":3941,"content":3942},{},[3943],{"nodeType":1293,"value":3944,"marks":3945,"data":3946},"Similar to the Okta breach, this attack showcases the possibility of third-party supply chain attacks to target downstream organizations using cloud SaaS services. In this case, targeting OAuth integrators as opposed to IdP providers, but with a similar goal and impact of compromising the real target organizations downstream. ",[],{},{"nodeType":1418,"data":3948,"content":3949},{},[3950],{"nodeType":1294,"data":3951,"content":3952},{},[3953],{"nodeType":1293,"value":3954,"marks":3955,"data":3956},"Applications like Github are an obvious target for attackers due to their widespread adoption. There have been numerous attacks leveraging Github as the vehicle for attacks by compromising repo’s to insert malicious code, or registering malicious copycat repo’s to dupe users into using them. ",[],{},{"nodeType":1418,"data":3958,"content":3959},{},[3960],{"nodeType":1294,"data":3961,"content":3962},{},[3963],{"nodeType":1293,"value":3964,"marks":3965,"data":3966},"Unlike the attacks abusing the functionality of Github (repo poisoning) which target the legitimate developer processes when using the app, this attack could have been prevented at the identity layer before the attacker was able to breach the Heroku/Travis-CI accounts. ",[],{},{"nodeType":1446,"data":3968,"content":3969},{},[3970],{"nodeType":1293,"value":2493,"marks":3971,"data":3972},[],{},{"nodeType":1294,"data":3974,"content":3975},{},[3976],{"nodeType":1293,"value":2035,"marks":3977,"data":3978},[],{},{"nodeType":2039,"data":3980,"content":3981},{},[3982,4021,4081,4145],{"nodeType":2043,"data":3983,"content":3984},{},[3985,3994,4003,4012],{"nodeType":2047,"data":3986,"content":3987},{},[3988],{"nodeType":1294,"data":3989,"content":3990},{},[3991],{"nodeType":1293,"value":2054,"marks":3992,"data":3993},[],{},{"nodeType":2047,"data":3995,"content":3996},{},[3997],{"nodeType":1294,"data":3998,"content":3999},{},[4000],{"nodeType":1293,"value":2524,"marks":4001,"data":4002},[],{},{"nodeType":2047,"data":4004,"content":4005},{},[4006],{"nodeType":1294,"data":4007,"content":4008},{},[4009],{"nodeType":1293,"value":2074,"marks":4010,"data":4011},[],{},{"nodeType":2047,"data":4013,"content":4014},{},[4015],{"nodeType":1294,"data":4016,"content":4017},{},[4018],{"nodeType":1293,"value":2084,"marks":4019,"data":4020},[],{},{"nodeType":2043,"data":4022,"content":4023},{},[4024,4043,4062,4072],{"nodeType":2091,"data":4025,"content":4026},{},[4027],{"nodeType":1294,"data":4028,"content":4029},{},[4030,4033,4040],{"nodeType":1293,"value":37,"marks":4031,"data":4032},[],{},{"nodeType":1343,"data":4034,"content":4035},{"uri":2687},[4036],{"nodeType":1293,"value":2690,"marks":4037,"data":4039},[4038],{"type":1351},{},{"nodeType":1293,"value":37,"marks":4041,"data":4042},[],{},{"nodeType":2091,"data":4044,"content":4045},{},[4046],{"nodeType":1294,"data":4047,"content":4048},{},[4049,4052,4059],{"nodeType":1293,"value":37,"marks":4050,"data":4051},[],{},{"nodeType":1343,"data":4053,"content":4054},{"uri":2687},[4055],{"nodeType":1293,"value":2710,"marks":4056,"data":4058},[4057],{"type":1351},{},{"nodeType":1293,"value":37,"marks":4060,"data":4061},[],{},{"nodeType":2091,"data":4063,"content":4064},{},[4065],{"nodeType":1294,"data":4066,"content":4067},{},[4068],{"nodeType":1293,"value":4069,"marks":4070,"data":4071},"Privilege Escalation; Lateral Movement",[],{},{"nodeType":2091,"data":4073,"content":4074},{},[4075],{"nodeType":1294,"data":4076,"content":4077},{},[4078],{"nodeType":1293,"value":2734,"marks":4079,"data":4080},[],{},{"nodeType":2043,"data":4082,"content":4083},{},[4084,4105,4125,4135],{"nodeType":2091,"data":4085,"content":4086},{},[4087],{"nodeType":1294,"data":4088,"content":4089},{},[4090,4093,4102],{"nodeType":1293,"value":37,"marks":4091,"data":4092},[],{},{"nodeType":1343,"data":4094,"content":4096},{"uri":4095},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/api_keys/description.md",[4097],{"nodeType":1293,"value":4098,"marks":4099,"data":4101},"SAT1004",[4100],{"type":1351},{},{"nodeType":1293,"value":37,"marks":4103,"data":4104},[],{},{"nodeType":2091,"data":4106,"content":4107},{},[4108],{"nodeType":1294,"data":4109,"content":4110},{},[4111,4114,4122],{"nodeType":1293,"value":37,"marks":4112,"data":4113},[],{},{"nodeType":1343,"data":4115,"content":4116},{"uri":4095},[4117],{"nodeType":1293,"value":4118,"marks":4119,"data":4121},"API keys",[4120],{"type":1351},{},{"nodeType":1293,"value":37,"marks":4123,"data":4124},[],{},{"nodeType":2091,"data":4126,"content":4127},{},[4128],{"nodeType":1294,"data":4129,"content":4130},{},[4131],{"nodeType":1293,"value":4132,"marks":4133,"data":4134},"Persistence; Defense Evasion",[],{},{"nodeType":2091,"data":4136,"content":4137},{},[4138],{"nodeType":1294,"data":4139,"content":4140},{},[4141],{"nodeType":1293,"value":4142,"marks":4143,"data":4144},"An adversary that has compromised an account could then read existing API keys from the app settings, if the app allows this, or create a new API key.",[],{},{"nodeType":2043,"data":4146,"content":4147},{},[4148,4169,4189,4199],{"nodeType":2091,"data":4149,"content":4150},{},[4151],{"nodeType":1294,"data":4152,"content":4153},{},[4154,4157,4166],{"nodeType":1293,"value":37,"marks":4155,"data":4156},[],{},{"nodeType":1343,"data":4158,"content":4160},{"uri":4159},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/app_directory_lookup/description.md#app-directory-lookup",[4161],{"nodeType":1293,"value":4162,"marks":4163,"data":4165},"SAT1006",[4164],{"type":1351},{},{"nodeType":1293,"value":37,"marks":4167,"data":4168},[],{},{"nodeType":2091,"data":4170,"content":4171},{},[4172],{"nodeType":1294,"data":4173,"content":4174},{},[4175,4178,4186],{"nodeType":1293,"value":37,"marks":4176,"data":4177},[],{},{"nodeType":1343,"data":4179,"content":4180},{"uri":4159},[4181],{"nodeType":1293,"value":4182,"marks":4183,"data":4185},"App directory lookup",[4184],{"type":1351},{},{"nodeType":1293,"value":37,"marks":4187,"data":4188},[],{},{"nodeType":2091,"data":4190,"content":4191},{},[4192],{"nodeType":1294,"data":4193,"content":4194},{},[4195],{"nodeType":1293,"value":4196,"marks":4197,"data":4198},"Discovery",[],{},{"nodeType":2091,"data":4200,"content":4201},{},[4202],{"nodeType":1294,"data":4203,"content":4204},{},[4205],{"nodeType":1293,"value":4206,"marks":4207,"data":4208},"An adversary who has gained a foothold via a SaaS app could download the list of users accessible to them in order to better target attacks against other users.",[],{},{"nodeType":1522,"data":4210,"content":4211},{},[],{"nodeType":1328,"data":4213,"content":4214},{},[4215],{"nodeType":1293,"value":4216,"marks":4217,"data":4218},"Other notable attacks",[],{},{"nodeType":1446,"data":4220,"content":4221},{},[4222],{"nodeType":1293,"value":4223,"marks":4224,"data":4225},"SEC X hack — January 2024",[],{},{"nodeType":1294,"data":4227,"content":4228},{},[4229],{"nodeType":1293,"value":4230,"marks":4231,"data":4232},"The X account for the U.S. Securities and Exchange Commission was victim to a SIM swapping attack, whereupon the attacker used the social media platform to issue a fake announcement on the approval of Bitcoin ETFs on security exchanges.",[],{},{"nodeType":1294,"data":4234,"content":4235},{},[4236],{"nodeType":1293,"value":4237,"marks":4238,"data":4239},"Once the threat actors controlled the number, they reset the password for the @SECGov account, and created the fake announcement. The SEC also confirmed that multi-factor authentication was not enabled on the account, as they had asked X support to disable it when they encountered problems logging into the account.",[],{},{"nodeType":1522,"data":4241,"content":4242},{},[],{"nodeType":1446,"data":4244,"content":4245},{},[4246],{"nodeType":1293,"value":4247,"marks":4248,"data":4249},"Mandiant X hack — January 2024",[],{},{"nodeType":1294,"data":4251,"content":4252},{},[4253],{"nodeType":1293,"value":4254,"marks":4255,"data":4256},"The X account for Mandiant was hacked by a Drainer-as-a-Service (DaaS) gang in a brute force attack. MFA was not enabled on the account. The threat actor used the social media account to share links redirecting to a phishing page to steal cryptocurrency. ",[],{},{"nodeType":1294,"data":4258,"content":4259},{},[4260],{"nodeType":1293,"value":4261,"marks":4262,"data":4263},"The attacker used a wallet drainer dubbed CLINKSINK. This same drainer has been used since December to steal funds and tokens from users of Solana cryptocurrency as part of a large-scale campaign involving at least 35 affiliate IDs linked to a shared DaaS.",[],{},{"nodeType":1522,"data":4265,"content":4266},{},[],{"nodeType":1446,"data":4268,"content":4269},{},[4270],{"nodeType":1293,"value":4271,"marks":4272,"data":4273},"23andMe data breach — April 2023",[],{},{"nodeType":1294,"data":4275,"content":4276},{},[4277],{"nodeType":1293,"value":4278,"marks":4279,"data":4280},"Genetic testing provider 23andMe confirmed that hackers downloaded the data of 6.9 million people of the existing 14 million customers after breaching around 14,000 user accounts. ",[],{},{"nodeType":1294,"data":4282,"content":4283},{},[4284],{"nodeType":1293,"value":4285,"marks":4286,"data":4287},"The attacker stole health reports and raw genotype data of customers affected by a credential stuffing attack that went unnoticed for five months, from April 29 to September 27. ",[],{},{"nodeType":1294,"data":4289,"content":4290},{},[4291],{"nodeType":1293,"value":4292,"marks":4293,"data":4294},"The credentials used by the attackers to breach the customers' accounts were stolen in other data breaches or used on previously compromised online platforms, and targeted accounts without MFA. ",[],{},"Tracking identity-based attacks in the wild","To keep track of how identity attacks are evolving, we’ve put together this helpful index of recent breaches, focusing on the latest identity-based techniques. ","2024-03-21T00:00:00.000Z","identity-attacks-in-the-wild",{"items":4300},[4301,4305],{"sys":4302,"name":4304},{"id":4303},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":4306,"name":1312},{"id":1311},{"items":4308},[4309],{"fullName":4310,"firstName":4311,"jobTitle":4312,"profilePicture":4313},"Dan Green","Dan","Threat Research",{"url":4314},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1320,"sys":4316,"content":4318,"title":5114,"synopsis":5115,"hashTags":118,"publishedDate":5116,"slug":5117,"tagsCollection":5118,"authorsCollection":5126},{"id":4317},"20FcoPvHu7zXkTQyv9MmK0",{"json":4319},{"nodeType":1302,"data":4320,"content":4321},{},[4322,4328,4335,4388,4395,4402,4417,4424,4431,4516,4523,4529,4536,4543,4558,4565,4572,4596,4621,4627,4647,4654,4661,4692,4699,4706,4712,4730,4737,4744,4751,4758,4764,4782,4789,4796,4803,4810,4816,4835,4842,4849,4855,4874,4881,4888,4895,4943,4950,5021,5036,5042,5049,5056,5063,5070,5088,5095],{"nodeType":1378,"data":4323,"content":4327},{"target":4324},{"sys":4325},{"id":4326,"type":1383,"linkType":1384},"7rud2H1hcTAOhxh9zHzxP6",[],{"nodeType":1294,"data":4329,"content":4330},{},[4331],{"nodeType":1293,"value":4332,"marks":4333,"data":4334},"If someone asked you where you work, you probably wouldn’t answer, “My browser.” But that would be the truth.",[],{},{"nodeType":1294,"data":4336,"content":4337},{},[4338,4342,4350,4354,4362,4365,4373,4376,4384],{"nodeType":1293,"value":4339,"marks":4340,"data":4341},"(Threat actors already know where you work, of course, and they’ve been capitalizing on the massive shift to cloud-based workforces. Just look at any of the ",[],{},{"nodeType":1343,"data":4343,"content":4345},{"uri":4344},"https://www.crowdstrike.com/global-threat-report/",[4346],{"nodeType":1293,"value":4347,"marks":4348,"data":4349},"latest",[],{},{"nodeType":1293,"value":4351,"marks":4352,"data":4353}," ",[],{},{"nodeType":1343,"data":4355,"content":4357},{"uri":4356},"https://redcanary.com/threat-detection-report/techniques/cloud-accounts/",[4358],{"nodeType":1293,"value":4359,"marks":4360,"data":4361},"threat",[],{},{"nodeType":1293,"value":4351,"marks":4363,"data":4364},[],{},{"nodeType":1343,"data":4366,"content":4368},{"uri":4367},"https://www.verizon.com/business/resources/reports/dbir/",[4369],{"nodeType":1293,"value":4370,"marks":4371,"data":4372},"research",[],{},{"nodeType":1293,"value":4351,"marks":4374,"data":4375},[],{},{"nodeType":1343,"data":4377,"content":4379},{"uri":4378},"https://www.lab539.com/blog/6-months-tracking-aitm-campaigns",[4380],{"nodeType":1293,"value":4381,"marks":4382,"data":4383},"reports",[],{},{"nodeType":1293,"value":4385,"marks":4386,"data":4387}," on identity-based attacks to see how good a job they’ve been doing.)",[],{},{"nodeType":1294,"data":4389,"content":4390},{},[4391],{"nodeType":1293,"value":4392,"marks":4393,"data":4394},"To get visibility of your infrastructure in order to build a strong detection and response program, the equation used to look something like:",[],{},{"nodeType":1294,"data":4396,"content":4397},{},[4398],{"nodeType":1293,"value":4399,"marks":4400,"data":4401},"Network traffic + Logs + Endpoints = Profit!",[],{},{"nodeType":1294,"data":4403,"content":4404},{},[4405,4409,4414],{"nodeType":1293,"value":4406,"marks":4407,"data":4408},"But now there’s a missing piece, as identity infrastructure sprawls across IdPs, core apps, shadow SaaS and third-party integrations: ",[],{},{"nodeType":1293,"value":4410,"marks":4411,"data":4413},"Browser telemetry",[4412],{"type":1464},{},{"nodeType":1293,"value":1367,"marks":4415,"data":4416},[],{},{"nodeType":1294,"data":4418,"content":4419},{},[4420],{"nodeType":1293,"value":4421,"marks":4422,"data":4423},"As a browser agent, Push is uniquely positioned to provide telemetry you can’t easily get anywhere else. We believe that this missing piece is the key to stopping identity attacks by providing the context both for first-class detections and security controls, as well as key correlations for events you observe in traditional log sources.",[],{},{"nodeType":1294,"data":4425,"content":4426},{},[4427],{"nodeType":1293,"value":4428,"marks":4429,"data":4430},"Now we have a better way to bring Push’s data to life to solve meaningful security challenges:",[],{},{"nodeType":1414,"data":4432,"content":4433},{},[4434,4465],{"nodeType":1418,"data":4435,"content":4436},{},[4437],{"nodeType":1294,"data":4438,"content":4439},{},[4440,4445,4449,4461],{"nodeType":1293,"value":4441,"marks":4442,"data":4444},"Plug-and-play security controls",[4443],{"type":1464},{},{"nodeType":1293,"value":4446,"marks":4447,"data":4448},", accessible from the new ",[],{},{"nodeType":4450,"data":4451,"content":4455},"entry-hyperlink",{"target":4452},{"sys":4453},{"id":4454,"type":1383,"linkType":1384},"BtDLgVZRWQ3Ov4WgDQX1W",[4456],{"nodeType":1293,"value":4457,"marks":4458,"data":4460},"Controls",[4459],{"type":1464},{},{"nodeType":1293,"value":4462,"marks":4463,"data":4464}," page in the Push platform",[],{},{"nodeType":1418,"data":4466,"content":4467},{},[4468],{"nodeType":1294,"data":4469,"content":4470},{},[4471,4476,4480,4488,4491,4499,4503,4512],{"nodeType":1293,"value":4472,"marks":4473,"data":4475},"Choose-your-own-adventure tooling",[4474],{"type":1464},{},{"nodeType":1293,"value":4477,"marks":4478,"data":4479},", including a ",[],{},{"nodeType":1343,"data":4481,"content":4483},{"uri":4482},"https://pushsecurity.redoc.ly/rest-v1/",[4484],{"nodeType":1293,"value":4485,"marks":4486,"data":4487},"REST API",[],{},{"nodeType":1293,"value":1943,"marks":4489,"data":4490},[],{},{"nodeType":1343,"data":4492,"content":4494},{"uri":4493},"https://pushsecurity.redoc.ly/webhooks-v1/",[4495],{"nodeType":1293,"value":4496,"marks":4497,"data":4498},"webhooks",[],{},{"nodeType":1293,"value":4500,"marks":4501,"data":4502},", and a new ",[],{},{"nodeType":1343,"data":4504,"content":4506},{"uri":4505},"/help/audience/administrators/docs/connect-to-siem-or-soar/#using-the-events-page",[4507],{"nodeType":1293,"value":4508,"marks":4509,"data":4511},"Events",[4510],{"type":1464},{},{"nodeType":1293,"value":4513,"marks":4514,"data":4515}," page to help you visualize and build custom detections and automations.",[],{},{"nodeType":1294,"data":4517,"content":4518},{},[4519],{"nodeType":1293,"value":4520,"marks":4521,"data":4522},"Let’s take a closer look.",[],{},{"nodeType":1378,"data":4524,"content":4528},{"target":4525},{"sys":4526},{"id":4527,"type":1383,"linkType":1384},"6iKFd9Qys2SSuNqKVQB7ka",[],{"nodeType":1328,"data":4530,"content":4531},{},[4532],{"nodeType":1293,"value":4533,"marks":4534,"data":4535},"Plug-and-play controls",[],{},{"nodeType":1294,"data":4537,"content":4538},{},[4539],{"nodeType":1293,"value":4540,"marks":4541,"data":4542},"Security visibility without security control is a recipe for a stress headache, so we’re big believers in providing meaningful interventions that are easy to use.",[],{},{"nodeType":1294,"data":4544,"content":4545},{},[4546,4550,4554],{"nodeType":1293,"value":4547,"marks":4548,"data":4549},"With the new ",[],{},{"nodeType":1293,"value":4457,"marks":4551,"data":4553},[4552],{"type":1464},{},{"nodeType":1293,"value":4555,"marks":4556,"data":4557}," page in the Push admin console, you can now find these preconfigured detections and interventions in one place. They cover use cases that any organization can benefit from, and take a unique browser-based approach to solving some thorny issues.",[],{},{"nodeType":1294,"data":4559,"content":4560},{},[4561],{"nodeType":1293,"value":4562,"marks":4563,"data":4564},"These controls include:",[],{},{"nodeType":1446,"data":4566,"content":4567},{},[4568],{"nodeType":1293,"value":4569,"marks":4570,"data":4571},"Phishing tool detection",[],{},{"nodeType":1294,"data":4573,"content":4574},{},[4575,4579,4584,4588,4593],{"nodeType":1293,"value":4576,"marks":4577,"data":4578},"Detect and block when employees visit webpages that use advanced phishing tools such as Evilginx or EvilNoVNC, among others. These adversary-in-the-middle (AitM) toolkits can mimic legitimate login screens, such as an Okta login page, to steal ",[],{},{"nodeType":1293,"value":4580,"marks":4581,"data":4583},"credentials",[4582],{"type":1464},{},{"nodeType":1293,"value":4585,"marks":4586,"data":4587}," and ",[],{},{"nodeType":1293,"value":4589,"marks":4590,"data":4592},"MFA codes",[4591],{"type":1464},{},{"nodeType":1293,"value":1367,"marks":4594,"data":4595},[],{},{"nodeType":1294,"data":4597,"content":4598},{},[4599,4603,4608,4612,4617],{"nodeType":1293,"value":4600,"marks":4601,"data":4602},"Push emits a webhook event when the browser agent detects attributes of these malware. You can also set Push to ",[],{},{"nodeType":1293,"value":4604,"marks":4605,"data":4607},"Warn",[4606],{"type":1464},{},{"nodeType":1293,"value":4609,"marks":4610,"data":4611}," or ",[],{},{"nodeType":1293,"value":4613,"marks":4614,"data":4616},"Block",[4615],{"type":1464},{},{"nodeType":1293,"value":4618,"marks":4619,"data":4620}," mode to display a customizable message to end-users when they encounter a phishing site.",[],{},{"nodeType":1378,"data":4622,"content":4626},{"target":4623},{"sys":4624},{"id":4625,"type":1383,"linkType":1384},"2ylIkR0JXHkFStGuCFRjlN",[],{"nodeType":1294,"data":4628,"content":4629},{},[4630,4634,4644],{"nodeType":1293,"value":4631,"marks":4632,"data":4633},"More about ",[],{},{"nodeType":4450,"data":4635,"content":4639},{"target":4636},{"sys":4637},{"id":4638,"type":1383,"linkType":1384},"7KRnTSnJAbbiho69gNyN0B",[4640],{"nodeType":1293,"value":4641,"marks":4642,"data":4643},"phishing tool detection",[],{},{"nodeType":1293,"value":37,"marks":4645,"data":4646},[],{},{"nodeType":1446,"data":4648,"content":4649},{},[4650],{"nodeType":1293,"value":4651,"marks":4652,"data":4653},"SSO password protection",[],{},{"nodeType":1294,"data":4655,"content":4656},{},[4657],{"nodeType":1293,"value":4658,"marks":4659,"data":4660},"Prevent employees from reusing their corporate SSO password on any page that doesn’t belong to the identity provider, including phishing sites. This means that even if that employee was the first person to get phished using a new attacker site, Push still detects it and blocks it.",[],{},{"nodeType":1294,"data":4662,"content":4663},{},[4664,4668,4672,4675,4679,4683,4688],{"nodeType":1293,"value":4665,"marks":4666,"data":4667},"Customize the message that end-users see in ",[],{},{"nodeType":1293,"value":4604,"marks":4669,"data":4671},[4670],{"type":1464},{},{"nodeType":1293,"value":4609,"marks":4673,"data":4674},[],{},{"nodeType":1293,"value":4613,"marks":4676,"data":4678},[4677],{"type":1464},{},{"nodeType":1293,"value":4680,"marks":4681,"data":4682}," mode, or start out in ",[],{},{"nodeType":1293,"value":4684,"marks":4685,"data":4687},"Monitor",[4686],{"type":1464},{},{"nodeType":1293,"value":4689,"marks":4690,"data":4691}," mode to catch any false positives before you enforce the control.",[],{},{"nodeType":1294,"data":4693,"content":4694},{},[4695],{"nodeType":1293,"value":4696,"marks":4697,"data":4698},"This feature supports the following identity providers: Okta, Microsoft 365, Google Workspace, JumpCloud, Duo, and Ping Identity.",[],{},{"nodeType":1294,"data":4700,"content":4701},{},[4702],{"nodeType":1293,"value":4703,"marks":4704,"data":4705},"Push will also emit a webhook event when an SSO password is used, and if an employee clicks through the warning screen.",[],{},{"nodeType":1378,"data":4707,"content":4711},{"target":4708},{"sys":4709},{"id":4710,"type":1383,"linkType":1384},"25c8M2gWYFST7yYxGEji2s",[],{"nodeType":1294,"data":4713,"content":4714},{},[4715,4718,4727],{"nodeType":1293,"value":4631,"marks":4716,"data":4717},[],{},{"nodeType":4450,"data":4719,"content":4723},{"target":4720},{"sys":4721},{"id":4722,"type":1383,"linkType":1384},"6FYHbkcRUrtznPo7RarRsz",[4724],{"nodeType":1293,"value":4651,"marks":4725,"data":4726},[],{},{"nodeType":1293,"value":37,"marks":4728,"data":4729},[],{},{"nodeType":1446,"data":4731,"content":4732},{},[4733],{"nodeType":1293,"value":4734,"marks":4735,"data":4736},"URL blocking",[],{},{"nodeType":1294,"data":4738,"content":4739},{},[4740],{"nodeType":1293,"value":4741,"marks":4742,"data":4743},"When you find malicious sites you want to block, such as when responding to a phishing incident, add them to a blocklist and prevent other employees from accessing those sites. ",[],{},{"nodeType":1294,"data":4745,"content":4746},{},[4747],{"nodeType":1293,"value":4748,"marks":4749,"data":4750},"URL blocking can be used in tandem with Push’s anti-phishing controls, so that as you discover malicious sites, you can block them from a central blocklist. This offers a kind of herd immunity where you can block other users from visiting a malicious site as soon as you have a single incident.",[],{},{"nodeType":1294,"data":4752,"content":4753},{},[4754],{"nodeType":1293,"value":4755,"marks":4756,"data":4757},"You can programmatically manage the blocklist using the Push REST API or sync to other threat intelligence sources you consume.",[],{},{"nodeType":1378,"data":4759,"content":4763},{"target":4760},{"sys":4761},{"id":4762,"type":1383,"linkType":1384},"3m00cFiUDAnddsOBOpkeiZ",[],{"nodeType":1294,"data":4765,"content":4766},{},[4767,4770,4779],{"nodeType":1293,"value":4631,"marks":4768,"data":4769},[],{},{"nodeType":4450,"data":4771,"content":4775},{"target":4772},{"sys":4773},{"id":4774,"type":1383,"linkType":1384},"P0coHgQAdRL0YTu4Rwd4z",[4776],{"nodeType":1293,"value":4734,"marks":4777,"data":4778},[],{},{"nodeType":1293,"value":37,"marks":4780,"data":4781},[],{},{"nodeType":1446,"data":4783,"content":4784},{},[4785],{"nodeType":1293,"value":4786,"marks":4787,"data":4788},"Session token theft detection",[],{},{"nodeType":1294,"data":4790,"content":4791},{},[4792],{"nodeType":1293,"value":4793,"marks":4794,"data":4795},"Inject a unique marker provided by the Push browser agent into the User Agent string of sessions that occur in browsers enrolled in Push. ",[],{},{"nodeType":1294,"data":4797,"content":4798},{},[4799],{"nodeType":1293,"value":4800,"marks":4801,"data":4802},"By analyzing logs from your IdP, you can identify activity from the same session that both has the Push marker and that lacks the marker. This can only ever happen when a session is extracted from a browser and maliciously imported into a different browser.",[],{},{"nodeType":1294,"data":4804,"content":4805},{},[4806],{"nodeType":1293,"value":4807,"marks":4808,"data":4809},"This is a high-fidelity signal that a session token has been stolen and is being used.",[],{},{"nodeType":1378,"data":4811,"content":4815},{"target":4812},{"sys":4813},{"id":4814,"type":1383,"linkType":1384},"43rk3TCqN269Vr2YWT4llP",[],{"nodeType":1294,"data":4817,"content":4818},{},[4819,4822,4832],{"nodeType":1293,"value":4631,"marks":4820,"data":4821},[],{},{"nodeType":4450,"data":4823,"content":4827},{"target":4824},{"sys":4825},{"id":4826,"type":1383,"linkType":1384},"1UMZdjyNQt4Y7NBb2wuK4L",[4828],{"nodeType":1293,"value":4829,"marks":4830,"data":4831},"session token theft detection",[],{},{"nodeType":1293,"value":37,"marks":4833,"data":4834},[],{},{"nodeType":1446,"data":4836,"content":4837},{},[4838],{"nodeType":1293,"value":4839,"marks":4840,"data":4841},"App banners",[],{},{"nodeType":1294,"data":4843,"content":4844},{},[4845],{"nodeType":1293,"value":4846,"marks":4847,"data":4848},"Add guardrails to employees’ use of SaaS apps with in-browser app banner messages you customize with your own text. You can require users to acknowledge having read a message before they can access an app, or even require them to submit a reason for using an app before they can log in.",[],{},{"nodeType":1378,"data":4850,"content":4854},{"target":4851},{"sys":4852},{"id":4853,"type":1383,"linkType":1384},"5nEKTBz6mauHI5mg8jB4ea",[],{"nodeType":1294,"data":4856,"content":4857},{},[4858,4861,4871],{"nodeType":1293,"value":4631,"marks":4859,"data":4860},[],{},{"nodeType":4450,"data":4862,"content":4866},{"target":4863},{"sys":4864},{"id":4865,"type":1383,"linkType":1384},"2ZpKnuljaUH0jzVaae4SMN",[4867],{"nodeType":1293,"value":4868,"marks":4869,"data":4870},"app banners",[],{},{"nodeType":1293,"value":37,"marks":4872,"data":4873},[],{},{"nodeType":1328,"data":4875,"content":4876},{},[4877],{"nodeType":1293,"value":4878,"marks":4879,"data":4880},"Choose your own adventure",[],{},{"nodeType":1294,"data":4882,"content":4883},{},[4884],{"nodeType":1293,"value":4885,"marks":4886,"data":4887},"Want to do something creative? We've got you covered. Push provides a wealth of raw telemetry via the Push REST API and webhook events. Use this data to build both proactive and reactive security operations workflows, or add missing context to other sources, such as your IdP, application, or endpoint logs.",[],{},{"nodeType":1294,"data":4889,"content":4890},{},[4891],{"nodeType":1293,"value":4892,"marks":4893,"data":4894},"You can use this browser telemetry to:",[],{},{"nodeType":1414,"data":4896,"content":4897},{},[4898,4913,4928],{"nodeType":1418,"data":4899,"content":4900},{},[4901],{"nodeType":1294,"data":4902,"content":4903},{},[4904,4909],{"nodeType":1293,"value":4905,"marks":4906,"data":4908},"Harden identities and reduce account compromise",[4907],{"type":1464},{},{"nodeType":1293,"value":4910,"marks":4911,"data":4912},", such as alerting you when passwords are identified in public data breaches or when employees are using an unapproved app or when an SSO app is accessed via local account.",[],{},{"nodeType":1418,"data":4914,"content":4915},{},[4916],{"nodeType":1294,"data":4917,"content":4918},{},[4919,4924],{"nodeType":1293,"value":4920,"marks":4921,"data":4923},"Monitor for suspicious activity or high-risk changes",[4922],{"type":1464},{},{"nodeType":1293,"value":4925,"marks":4926,"data":4927},", such as checking for MFA method changes, or flagging when employees reuse corporate SSO passwords or visit sites running phishing malware.",[],{},{"nodeType":1418,"data":4929,"content":4930},{},[4931],{"nodeType":1294,"data":4932,"content":4933},{},[4934,4939],{"nodeType":1293,"value":4935,"marks":4936,"data":4938},"Investigate indicators of compromise",[4937],{"type":1464},{},{"nodeType":1293,"value":4940,"marks":4941,"data":4942},", such as correlating login events with platform logs, searching for recent signups to risky apps, or identifying post-compromise lateral movement opportunities.",[],{},{"nodeType":1294,"data":4944,"content":4945},{},[4946],{"nodeType":1293,"value":4947,"marks":4948,"data":4949},"In the “make my life easier” category, you can also use Push telemetry to:",[],{},{"nodeType":1414,"data":4951,"content":4952},{},[4953,4972,4991,5006],{"nodeType":1418,"data":4954,"content":4955},{},[4956],{"nodeType":1294,"data":4957,"content":4958},{},[4959,4963,4968],{"nodeType":1293,"value":4960,"marks":4961,"data":4962},"Automate a workflow ",[],{},{"nodeType":1293,"value":4964,"marks":4965,"data":4967},"showing you all the accounts and apps used by an offboarded employee",[4966],{"type":1464},{},{"nodeType":1293,"value":4969,"marks":4970,"data":4971},", and their account login methods.",[],{},{"nodeType":1418,"data":4973,"content":4974},{},[4975],{"nodeType":1294,"data":4976,"content":4977},{},[4978,4982,4987],{"nodeType":1293,"value":4979,"marks":4980,"data":4981},"Automate a workflow to",[],{},{"nodeType":1293,"value":4983,"marks":4984,"data":4986}," revoke licenses on SaaS after a period of inactivity",[4985],{"type":1464},{},{"nodeType":1293,"value":4988,"marks":4989,"data":4990},", saving money.",[],{},{"nodeType":1418,"data":4992,"content":4993},{},[4994],{"nodeType":1294,"data":4995,"content":4996},{},[4997,5002],{"nodeType":1293,"value":4998,"marks":4999,"data":5001},"Build an approved apps list in your company wiki",[5000],{"type":1464},{},{"nodeType":1293,"value":5003,"marks":5004,"data":5005},", synced from Push’s source of truth.",[],{},{"nodeType":1418,"data":5007,"content":5008},{},[5009],{"nodeType":1294,"data":5010,"content":5011},{},[5012,5017],{"nodeType":1293,"value":5013,"marks":5014,"data":5016},"Force-reset an IdP password if Push finds a compromised password",[5015],{"type":1464},{},{"nodeType":1293,"value":5018,"marks":5019,"data":5020}," on an employee account.",[],{},{"nodeType":1294,"data":5022,"content":5023},{},[5024,5028,5032],{"nodeType":1293,"value":5025,"marks":5026,"data":5027},"To help you visualize and plan how you will use this telemetry, Push also provides an ",[],{},{"nodeType":1293,"value":4508,"marks":5029,"data":5031},[5030],{"type":1464},{},{"nodeType":1293,"value":5033,"marks":5034,"data":5035}," page in the admin console with a rolling 7-day snapshot of all the events in your environment.",[],{},{"nodeType":1378,"data":5037,"content":5041},{"target":5038},{"sys":5039},{"id":5040,"type":1383,"linkType":1384},"2a3bJ5sN8dJ0c1kQtZiag7",[],{"nodeType":1294,"data":5043,"content":5044},{},[5045],{"nodeType":1293,"value":5046,"marks":5047,"data":5048},"The Events page can help you see real-world examples, understand the attributes of each event, and gauge event volume before you ingest data into a SIEM or other platform.",[],{},{"nodeType":1328,"data":5050,"content":5051},{},[5052],{"nodeType":1293,"value":5053,"marks":5054,"data":5055},"What if you don’t have a SIEM?",[],{},{"nodeType":1294,"data":5057,"content":5058},{},[5059],{"nodeType":1293,"value":5060,"marks":5061,"data":5062},"While you’d need a SIEM for writing detections and performing log correlations, you can still get a lot of value out of Push telemetry if you don’t have one.",[],{},{"nodeType":1294,"data":5064,"content":5065},{},[5066],{"nodeType":1293,"value":5067,"marks":5068,"data":5069},"Use Push’s webhook events to send alerts directly to your Slack, Teams, or other chat platform, or build workflows that hook into your ticketing system or SOAR platform.",[],{},{"nodeType":1294,"data":5071,"content":5072},{},[5073,5077,5084],{"nodeType":1293,"value":5074,"marks":5075,"data":5076},"Review our ",[],{},{"nodeType":1343,"data":5078,"content":5079},{"uri":4493},[5080],{"nodeType":1293,"value":5081,"marks":5082,"data":5083},"webhooks documentation",[],{},{"nodeType":1293,"value":5085,"marks":5086,"data":5087}," for a list of events.",[],{},{"nodeType":1328,"data":5089,"content":5090},{},[5091],{"nodeType":1293,"value":5092,"marks":5093,"data":5094},"Find out more",[],{},{"nodeType":1294,"data":5096,"content":5097},{},[5098,5102,5110],{"nodeType":1293,"value":5099,"marks":5100,"data":5101},"If you want to see Push in action, ",[],{},{"nodeType":1343,"data":5103,"content":5105},{"uri":5104},"/demo/",[5106],{"nodeType":1293,"value":5107,"marks":5108,"data":5109},"book a demo",[],{},{"nodeType":1293,"value":5111,"marks":5112,"data":5113},". We’ll be happy to show you these features, along with how we discover all the apps your employees are using — even the ones not behind SSO.",[],{},"Introducing set-and-forget controls that stop real-world identity attacks","Enable detections and interventions in the browser using Push’s new security controls.","2024-07-02T00:00:00.000Z","introducing-set-and-forget-controls-that-stop-real-world-identity-attacks",{"items":5119},[5120,5124],{"sys":5121,"name":5123},{"id":5122},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"sys":5125,"name":1312},{"id":1311},{"items":5127},[5128],{"fullName":5129,"firstName":5130,"jobTitle":5131,"profilePicture":5132},"Kelly Davenport","Kelly","Product Team",{"url":5133},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1320,"sys":5135,"content":5137,"title":5970,"synopsis":5971,"hashTags":118,"publishedDate":5972,"slug":5973,"tagsCollection":5974,"authorsCollection":5980},{"id":5136},"174u87EYeKMKHzYYxBLlHO",{"json":5138},{"nodeType":1302,"data":5139,"content":5140},{},[5141,5148,5155,5162,5191,5198,5205,5223,5230,5237,5255,5262,5269,5276,5282,5289,5332,5339,5346,5353,5376,5383,5390,5397,5445,5452,5459,5466,5473,5485,5492,5500,5507,5540,5547,5554,5561,5568,5638,5646,5653,5660,5694,5701,5709,5716,5723,5735,5751,5784,5803,5810,5829,5836,5843,5860,5867,5874,5881,5914,5921,5940,5958,5964],{"nodeType":1294,"data":5142,"content":5143},{},[5144],{"nodeType":1293,"value":5145,"marks":5146,"data":5147},"Identity attacks like phishing, credential stuffing, and session hijacking are now the leading cause of cyber security breaches, as attackers shift their attention to the sprawl of third-party applications and services that has become the backbone of business IT. ",[],{},{"nodeType":1294,"data":5149,"content":5150},{},[5151],{"nodeType":1293,"value":5152,"marks":5153,"data":5154},"The attacker’s goal in these attacks is account takeover: logging into a user account to access your company app tenant. From there, the attacker can usually achieve all of their objectives from inside the compromised app, usually involving dumping sensitive data with which to hold the company to ransom, or selling the data on underground criminal marketplaces. ",[],{},{"nodeType":1294,"data":5156,"content":5157},{},[5158],{"nodeType":1293,"value":5159,"marks":5160,"data":5161},"These attack techniques have been commonplace for over a decade — but the shift in attack context away from attacking endpoints (user devices and servers) to cloud services is seeing something of an identity attack renaissance. ",[],{},{"nodeType":1294,"data":5163,"content":5164},{},[5165,5168,5175,5179,5187],{"nodeType":1293,"value":37,"marks":5166,"data":5167},[],{},{"nodeType":1343,"data":5169,"content":5170},{"uri":1935},[5171],{"nodeType":1293,"value":2124,"marks":5172,"data":5174},[5173],{"type":1351},{},{"nodeType":1293,"value":5176,"marks":5177,"data":5178}," are one of the leading factors in successful ",[],{},{"nodeType":1343,"data":5180,"content":5181},{"uri":2559},[5182],{"nodeType":1293,"value":5183,"marks":5184,"data":5186},"credential stuffing",[5185],{"type":1351},{},{"nodeType":1293,"value":5188,"marks":5189,"data":5190}," attacks driving account takeover.",[],{},{"nodeType":1328,"data":5192,"content":5193},{},[5194],{"nodeType":1293,"value":5195,"marks":5196,"data":5197},"Ghost logins 101",[],{},{"nodeType":1294,"data":5199,"content":5200},{},[5201],{"nodeType":1293,"value":5202,"marks":5203,"data":5204},"Simply put, ghost logins are often-forgotten alternative login methods that are tricky for security teams to manage and secure — because they don’t know about them. Because of this, they’re likely to possess weak configurations that make them susceptible to account takeover attacks. ",[],{},{"nodeType":1294,"data":5206,"content":5207},{},[5208,5212,5220],{"nodeType":1293,"value":5209,"marks":5210,"data":5211},"We found that ",[],{},{"nodeType":1343,"data":5213,"content":5215},{"uri":5214},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[5216],{"nodeType":1293,"value":5217,"marks":5218,"data":5219},"ghost logins are present in ~10% of the accounts per organization",[],{},{"nodeType":1293,"value":1604,"marks":5221,"data":5222},[],{},{"nodeType":1446,"data":5224,"content":5225},{},[5226],{"nodeType":1293,"value":5227,"marks":5228,"data":5229},"Why do ghost logins exist?",[],{},{"nodeType":1294,"data":5231,"content":5232},{},[5233],{"nodeType":1293,"value":5234,"marks":5235,"data":5236},"Identity management used to be something that was centrally contained and managed using an enterprise identity service like Active Directory. Most users probably only had one or two identities that you really cared about: the one they used to log into their company laptop and domain, and maybe also to log into a VPN. ",[],{},{"nodeType":1294,"data":5238,"content":5239},{},[5240,5244,5251],{"nodeType":1293,"value":5241,"marks":5242,"data":5243},"Now, there are ",[],{},{"nodeType":1343,"data":5245,"content":5246},{"uri":5214},[5247],{"nodeType":1293,"value":5248,"marks":5249,"data":5250},"200+ business apps in use per company, creating 1000s of sprawled identities",[],{},{"nodeType":1293,"value":5252,"marks":5253,"data":5254}," across an ecosystem of business apps and services accessed over the internet.",[],{},{"nodeType":1294,"data":5256,"content":5257},{},[5258],{"nodeType":1293,"value":5259,"marks":5260,"data":5261},"Most businesses have tried to solve this problem with single sign on (SSO). The logic being that if you can use a single set of credentials (and therefore, a single identity) to access all of your business apps, and then secure those credentials with MFA, then this problem goes away. However…",[],{},{"nodeType":1446,"data":5263,"content":5264},{},[5265],{"nodeType":1293,"value":5266,"marks":5267,"data":5268},"SSO expectations versus reality",[],{},{"nodeType":1294,"data":5270,"content":5271},{},[5272],{"nodeType":1293,"value":5273,"marks":5274,"data":5275},"Unfortunately, the reality of SSO implementation is flawed. Most apps accept multiple login methods that can be configured — and used — simultaneously (yes, most apps don’t have proper session controls).  ",[],{},{"nodeType":1378,"data":5277,"content":5281},{"target":5278},{"sys":5279},{"id":5280,"type":1383,"linkType":1384},"3sOz3HkiyJpY9nFtGCWEOV",[],{"nodeType":1294,"data":5283,"content":5284},{},[5285],{"nodeType":1293,"value":5286,"marks":5287,"data":5288},"This is made worse by the fact that:",[],{},{"nodeType":1414,"data":5290,"content":5291},{},[5292,5302,5312,5322],{"nodeType":1418,"data":5293,"content":5294},{},[5295],{"nodeType":1294,"data":5296,"content":5297},{},[5298],{"nodeType":1293,"value":5299,"marks":5300,"data":5301},"Most apps can't be locked down to restrict which login methods are accepted.",[],{},{"nodeType":1418,"data":5303,"content":5304},{},[5305],{"nodeType":1294,"data":5306,"content":5307},{},[5308],{"nodeType":1293,"value":5309,"marks":5310,"data":5311},"Users often self-adopt apps, and default to a username and password (and typically miss out MFA). ",[],{},{"nodeType":1418,"data":5313,"content":5314},{},[5315],{"nodeType":1294,"data":5316,"content":5317},{},[5318],{"nodeType":1293,"value":5319,"marks":5320,"data":5321},"SSO isn’t always possible if you aren’t using a supported IdP — and only one in three apps support SAML, the preferred enterprise-grade protocol.",[],{},{"nodeType":1418,"data":5323,"content":5324},{},[5325],{"nodeType":1294,"data":5326,"content":5327},{},[5328],{"nodeType":1293,"value":5329,"marks":5330,"data":5331},"Even where SSO is possible, configuring an app for SSO doesn't automatically delete any legacy local logins.",[],{},{"nodeType":1294,"data":5333,"content":5334},{},[5335],{"nodeType":1293,"value":5336,"marks":5337,"data":5338},"Inevitably, this means that there are many situations in which users will create local accounts — typically with a username and password, and without MFA. This is how ghost logins are born.",[],{},{"nodeType":1446,"data":5340,"content":5341},{},[5342],{"nodeType":1293,"value":5343,"marks":5344,"data":5345},"How are ghost logins created? ",[],{},{"nodeType":1294,"data":5347,"content":5348},{},[5349],{"nodeType":1293,"value":5350,"marks":5351,"data":5352},"Ghost logins can be created in the following ways:",[],{},{"nodeType":1414,"data":5354,"content":5355},{},[5356,5366],{"nodeType":1418,"data":5357,"content":5358},{},[5359],{"nodeType":1294,"data":5360,"content":5361},{},[5362],{"nodeType":1293,"value":5363,"marks":5364,"data":5365},"A user self-adopts an app, setting up an account with a local username and password. The app is later adopted companywide and brought under SSO. This creates an additional SSO login method, likely as the default, but the local login will continue to exist unless explicitly disabled or deleted. ",[],{},{"nodeType":1418,"data":5367,"content":5368},{},[5369],{"nodeType":1294,"data":5370,"content":5371},{},[5372],{"nodeType":1293,"value":5373,"marks":5374,"data":5375},"Secondary/backup login methods can often be added later in the app settings after logging in. This includes things like setting up a secondary email to send a login link to, or setting up API access to remove the need to authenticate altogether. ",[],{},{"nodeType":1294,"data":5377,"content":5378},{},[5379],{"nodeType":1293,"value":5380,"marks":5381,"data":5382},"So, ghost logins are very easily introduced through the normal course of app adoption and use by employees. ",[],{},{"nodeType":1446,"data":5384,"content":5385},{},[5386],{"nodeType":1293,"value":5387,"marks":5388,"data":5389},"Why do ghost logins pose a risk? ",[],{},{"nodeType":1294,"data":5391,"content":5392},{},[5393],{"nodeType":1293,"value":5394,"marks":5395,"data":5396},"Ghost logins pose a risk for a number of reasons, as they: ",[],{},{"nodeType":1414,"data":5398,"content":5399},{},[5400,5415,5430],{"nodeType":1418,"data":5401,"content":5402},{},[5403],{"nodeType":1294,"data":5404,"content":5405},{},[5406,5411],{"nodeType":1293,"value":5407,"marks":5408,"data":5410},"Typically have less secure configurations ",[5409],{"type":1464},{},{"nodeType":1293,"value":5412,"marks":5413,"data":5414},"than your preferred login method – and may be missing key controls like MFA.  ",[],{},{"nodeType":1418,"data":5416,"content":5417},{},[5418],{"nodeType":1294,"data":5419,"content":5420},{},[5421,5426],{"nodeType":1293,"value":5422,"marks":5423,"data":5425},"Are effectively shadow logins",[5424],{"type":1464},{},{"nodeType":1293,"value":5427,"marks":5428,"data":5429}," – IT/security don’t know about them, and if using an IdP as your primary identity security interface, they won’t necessarily be visible without taking a deeper look at individual apps. ",[],{},{"nodeType":1418,"data":5431,"content":5432},{},[5433],{"nodeType":1294,"data":5434,"content":5435},{},[5436,5441],{"nodeType":1293,"value":5437,"marks":5438,"data":5440},"Can be used simultaneously with SSO",[5439],{"type":1464},{},{"nodeType":1293,"value":5442,"marks":5443,"data":5444}," – so you can have an unrestricted number of concurrent sessions with SSO and non SSO logins active at the same time, without the user being kicked out of the previous session.",[],{},{"nodeType":1294,"data":5446,"content":5447},{},[5448],{"nodeType":1293,"value":5449,"marks":5450,"data":5451},"Ghost logins provide opportunities for attackers to bypass security controls for initial access and persistence in an application (which we’ll come onto in more detail later). They also provide an opportunity for malicious insiders, e.g. a disgruntled employee, to access systems even after SSO access is revoked. If the security team relies on IdP logs to audit app logins, these accounts can go undetected.",[],{},{"nodeType":1294,"data":5453,"content":5454},{},[5455],{"nodeType":1293,"value":5456,"marks":5457,"data":5458},"To be able to identify them, you’d need to log into the app admin dashboard. But depending on how the app was adopted, you (as a security admin) may not even be an app-level admin — it’s not unusual for individual teams to administer their own apps. And even if you do have access, it’s not always easy (or possible) to gather this level of information about user account configuration. ",[],{},{"nodeType":1294,"data":5460,"content":5461},{},[5462],{"nodeType":1293,"value":5463,"marks":5464,"data":5465},"It’s very easy to see how these vulnerable login methods can be overlooked by security teams – let’s look at how they can be identified and exploited by attackers. ",[],{},{"nodeType":1328,"data":5467,"content":5468},{},[5469],{"nodeType":1293,"value":5470,"marks":5471,"data":5472},"How can ghost logins be exploited by attackers?",[],{},{"nodeType":1294,"data":5474,"content":5475},{},[5476,5481],{"nodeType":1293,"value":5477,"marks":5478,"data":5480},"Let’s take an example scenario:",[5479],{"type":1464},{},{"nodeType":1293,"value":5482,"marks":5483,"data":5484}," You’re using an IdP solution like Okta or Microsoft/Entra with SAML SSO as the default login method for your core business apps. Via your IdP you require MFA when authenticating to your IdP apps page, and also potentially when signing into an individual connected app. ",[],{},{"nodeType":1294,"data":5486,"content":5487},{},[5488],{"nodeType":1293,"value":5489,"marks":5490,"data":5491},"However, you only recently introduced your IdP solution, and your users previously accessed this app with a local username and password. Although you asked your users to configure MFA in the app itself, not all of them did. And when you deployed your IdP solution, you didn’t manually unset all the local password-based logins for the apps you connected to it. ",[],{},{"nodeType":1294,"data":5493,"content":5494},{},[5495],{"nodeType":1293,"value":5496,"marks":5497,"data":5499},"Unknown to you, there are now hundreds of local accounts for core business apps which lack MFA. ",[5498],{"type":1464},{},{"nodeType":1294,"data":5501,"content":5502},{},[5503],{"nodeType":1293,"value":5504,"marks":5505,"data":5506},"There are two main scenarios in which ghost logins can be utilized by an attacker:",[],{},{"nodeType":1414,"data":5508,"content":5509},{},[5510,5525],{"nodeType":1418,"data":5511,"content":5512},{},[5513],{"nodeType":1294,"data":5514,"content":5515},{},[5516,5521],{"nodeType":1293,"value":5517,"marks":5518,"data":5520},"To bypass robustly configured login methods",[5519],{"type":1464},{},{"nodeType":1293,"value":5522,"marks":5523,"data":5524}," such as SSO to compromise an app identity during the initial access phase of an attack. ",[],{},{"nodeType":1418,"data":5526,"content":5527},{},[5528],{"nodeType":1294,"data":5529,"content":5530},{},[5531,5536],{"nodeType":1293,"value":5532,"marks":5533,"data":5535},"To create additional login methods for an already compromised account to ensure persistent access",[5534],{"type":1464},{},{"nodeType":1293,"value":5537,"marks":5538,"data":5539}," – even if the original compromised login method is revoked or disabled. This could be either the result of compromising an identity belonging to a specific app, or having previously compromised an IdP account (e.g. Okta).",[],{},{"nodeType":1294,"data":5541,"content":5542},{},[5543],{"nodeType":1293,"value":5544,"marks":5545,"data":5546},"Let's look at these use cases in more detail. ",[],{},{"nodeType":1446,"data":5548,"content":5549},{},[5550],{"nodeType":1293,"value":5551,"marks":5552,"data":5553},"Ghost logins for initial access",[],{},{"nodeType":1294,"data":5555,"content":5556},{},[5557],{"nodeType":1293,"value":5558,"marks":5559,"data":5560},"Arguably the most dangerous use case for ghost logins is to conduct credential attacks against accounts using a username and password. Logins with a weak or guessable password, or a reused password that has appeared in a public data breach dump, are primed for account takeover. ",[],{},{"nodeType":1294,"data":5562,"content":5563},{},[5564],{"nodeType":1293,"value":5565,"marks":5566,"data":5567},"The cyber crime ecosystem is leaning toward the theft, sale, and use of stolen credentials (not just emails and passwords, but session tokens too). ",[],{},{"nodeType":1414,"data":5569,"content":5570},{},[5571,5594,5616],{"nodeType":1418,"data":5572,"content":5573},{},[5574],{"nodeType":1294,"data":5575,"content":5576},{},[5577,5581,5590],{"nodeType":1293,"value":5578,"marks":5579,"data":5580},"There are 600 million identity attacks per day, with 99% involving passwords (",[],{},{"nodeType":1343,"data":5582,"content":5584},{"uri":5583},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf",[5585],{"nodeType":1293,"value":5586,"marks":5587,"data":5589},"Microsoft",[5588],{"type":1351},{},{"nodeType":1293,"value":5591,"marks":5592,"data":5593},").",[],{},{"nodeType":1418,"data":5595,"content":5596},{},[5597],{"nodeType":1294,"data":5598,"content":5599},{},[5600,5604,5613],{"nodeType":1293,"value":5601,"marks":5602,"data":5603},"Over 1000 credentials are posted online per day, per marketplace with an average sale price of $10, and 65% posted less than one day after being collected (",[],{},{"nodeType":1343,"data":5605,"content":5607},{"uri":5606},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[5608],{"nodeType":1293,"value":5609,"marks":5610,"data":5612},"Verizon",[5611],{"type":1351},{},{"nodeType":1293,"value":5591,"marks":5614,"data":5615},[],{},{"nodeType":1418,"data":5617,"content":5618},{},[5619],{"nodeType":1294,"data":5620,"content":5621},{},[5622,5626,5635],{"nodeType":1293,"value":5623,"marks":5624,"data":5625},"One million new stealer logs are distributed every month, with an estimated 3-5% containing credentials and session cookies to corporate IT environments (",[],{},{"nodeType":1343,"data":5627,"content":5629},{"uri":5628},"https://www.bleepingcomputer.com/news/security/single-sign-on-and-the-cybercrime-ecosystem/",[5630],{"nodeType":1293,"value":5631,"marks":5632,"data":5634},"Flare",[5633],{"type":1351},{},{"nodeType":1293,"value":5591,"marks":5636,"data":5637},[],{},{"nodeType":1294,"data":5639,"content":5640},{},[5641],{"nodeType":1293,"value":5642,"marks":5643,"data":5645},"So, it’s easier than ever for attackers to gather breached credentials and weaponize them at scale. ",[5644],{"type":1464},{},{"nodeType":1294,"data":5647,"content":5648},{},[5649],{"nodeType":1293,"value":5650,"marks":5651,"data":5652},"Realistically, any username and password combination for addresses belonging to a specific organization/domain can be attempted on any app. Breached credential data will often provide a strong indicator of other apps also in use for that organization. And for apps with a custom tenant URL (that cannot be easily guessed) data dumps often helpfully include the URLs for those login pages, too.  ",[],{},{"nodeType":1294,"data":5654,"content":5655},{},[5656],{"nodeType":1293,"value":5657,"marks":5658,"data":5659},"The risk posed by the massive amounts of leaked credentials available is heightened because: ",[],{},{"nodeType":1414,"data":5661,"content":5662},{},[5663,5684],{"nodeType":1418,"data":5664,"content":5665},{},[5666],{"nodeType":1294,"data":5667,"content":5668},{},[5669,5673,5680],{"nodeType":1293,"value":5670,"marks":5671,"data":5672},"Many employees reuse passwords, with ",[],{},{"nodeType":1343,"data":5674,"content":5675},{"uri":5214},[5676],{"nodeType":1293,"value":5677,"marks":5678,"data":5679},"~9% of all accounts using a breached, weak, or reused password",[],{},{"nodeType":1293,"value":5681,"marks":5682,"data":5683},". This isn’t just for low-risk apps either, and includes the reuse of highly sensitive IdP creds. ",[],{},{"nodeType":1418,"data":5685,"content":5686},{},[5687],{"nodeType":1294,"data":5688,"content":5689},{},[5690],{"nodeType":1293,"value":5691,"marks":5692,"data":5693},"Organizations don’t typically rotate or enforce changes to SaaS app passwords in the same way they might for company account/device login connected to Active Directory.  ",[],{},{"nodeType":1294,"data":5695,"content":5696},{},[5697],{"nodeType":1293,"value":5698,"marks":5699,"data":5700},"Ghost logins aren’t limited to just username and password either. For example, a breached social account such as Facebook or Google can result in a broader compromise if those accounts have been connected to any corporate apps.   ",[],{},{"nodeType":1294,"data":5702,"content":5703},{},[5704],{"nodeType":1293,"value":5705,"marks":5706,"data":5708},"So, exploiting ghost logins can be a highly effective method for attackers to gain initial access to a user account from which to launch further attacks.  ",[5707],{"type":1464},{},{"nodeType":1446,"data":5710,"content":5711},{},[5712],{"nodeType":1293,"value":5713,"marks":5714,"data":5715},"Ghost logins for persistence and defense evasion",[],{},{"nodeType":1294,"data":5717,"content":5718},{},[5719],{"nodeType":1293,"value":5720,"marks":5721,"data":5722},"Now, we’ll take a look at how attackers can leverage ghost logins as part of the later stages of an attack, having already established an initial foothold via account compromise. ",[],{},{"nodeType":1294,"data":5724,"content":5725},{},[5726,5730],{"nodeType":1293,"value":5727,"marks":5728,"data":5729},"If an organization has a reasonable level of security monitoring in-place (depending on log availability from the particular app vendor), or a victim receives a notification about an unusual login (e.g. from a new device or unusual IP) then access to an account can be short-lived. ",[],{},{"nodeType":1293,"value":5731,"marks":5732,"data":5734},"However, ghost logins can provide attackers with the tools to maintain persistent access to a compromised account, even if the initial compromised login method is disabled or revoked. ",[5733],{"type":1464},{},{"nodeType":1294,"data":5736,"content":5737},{},[5738,5742,5747],{"nodeType":1293,"value":5739,"marks":5740,"data":5741},"For example, if a social login is used to access an account, an adversary may be able to configure a separate username/password login, or even (though much less commonly) connect a second social account that the adversary controls. This allows the adversary to maintain persistent access to the user account ",[],{},{"nodeType":1293,"value":5743,"marks":5744,"data":5746},"even in the event of password changes or MFA changes",[5745],{"type":1464},{},{"nodeType":1293,"value":5748,"marks":5749,"data":5750},". The attack will go unnoticed if the victim organization relies on SSO logs for auditing access to SaaS applications because the attack bypasses SSO, as the login remains local to the SaaS app or, in the case of an OIDC SSO login, the adversary’s own social account.",[],{},{"nodeType":1294,"data":5752,"content":5753},{},[5754,5758,5767,5771,5780],{"nodeType":1293,"value":5755,"marks":5756,"data":5757},"Another quirk is that it’s common for ordinary users to become app-level admins when an app is self-adopted by an individual or team. If an attacker is able to gain control of such an account, it can then be used to target other users without needing to deliver phishing links by hijacking SAML-based authentication. In this scenario, users attempting to sign in using SAML SSO are directed it to an attacker-controlled tenant in a watering hole attack (also known as ",[],{},{"nodeType":1343,"data":5759,"content":5761},{"uri":5760},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/samljacking/description.md",[5762],{"nodeType":1293,"value":5763,"marks":5764,"data":5766},"SAMLjacking",[5765],{"type":1351},{},{"nodeType":1293,"value":5768,"marks":5769,"data":5770},", which you can ",[],{},{"nodeType":1343,"data":5772,"content":5774},{"uri":5773},"https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/",[5775],{"nodeType":1293,"value":5776,"marks":5777,"data":5779},"read more about in another blog post",[5778],{"type":1351},{},{"nodeType":1293,"value":5781,"marks":5782,"data":5783},"). ",[],{},{"nodeType":1294,"data":5785,"content":5786},{},[5787,5791,5800],{"nodeType":1293,"value":5788,"marks":5789,"data":5790},"If you're curious as to how an attacker might be able to compromise an IdP account such as Okta, ",[],{},{"nodeType":1343,"data":5792,"content":5794},{"uri":5793},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[5795],{"nodeType":1293,"value":5796,"marks":5797,"data":5799},"you should check out our blog post on AitM and BitM phishing techniques",[5798],{"type":1351},{},{"nodeType":1293,"value":1965,"marks":5801,"data":5802},[],{},{"nodeType":1328,"data":5804,"content":5805},{},[5806],{"nodeType":1293,"value":5807,"marks":5808,"data":5809},"Case study: Snowflake",[],{},{"nodeType":1294,"data":5811,"content":5812},{},[5813,5817,5825],{"nodeType":1293,"value":5814,"marks":5815,"data":5816},"The ",[],{},{"nodeType":1343,"data":5818,"content":5820},{"uri":5819},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[5821],{"nodeType":1293,"value":5822,"marks":5823,"data":5824},"recent attacks on 165 Snowflake customers",[],{},{"nodeType":1293,"value":5826,"marks":5827,"data":5828},", resulting in hundreds of millions of breached customer records, were the product of a credential stuffing campaign using stolen credentials from infostealer infections dating back to 2020. ",[],{},{"nodeType":1294,"data":5830,"content":5831},{},[5832],{"nodeType":1293,"value":5833,"marks":5834,"data":5835},"The industry response to Snowflake was typical: check whether Snowflake has been set up for SSO, and if so, job done — we’re protected by MFA.",[],{},{"nodeType":1294,"data":5837,"content":5838},{},[5839],{"nodeType":1293,"value":5840,"marks":5841,"data":5842},"The reality was that MFA was not — and could not — be centrally enforced for username and password accounts. Even if MFA was applied at the IdP level for SSO logins, it was not enforced for local username and password logins. It needed to be opted-into by the user. ",[],{},{"nodeType":1294,"data":5844,"content":5845},{},[5846,5850,5857],{"nodeType":1293,"value":5847,"marks":5848,"data":5849},"This meant the most logical thing to do was to disable local accounts. But because Snowflake is essentially a cloud-hosted SQL database, there was no easy-to-use GUI to access local account config data. Once you’d managed to get an admin account with the right permissions, you needed to run various commands to find and unset the accounts. ",[],{},{"nodeType":1343,"data":5851,"content":5852},{"uri":1957},[5853],{"nodeType":1293,"value":5854,"marks":5855,"data":5856},"But if you didn’t have the exact type of admin account, misleading results would be returned — and even after you had fixed the vulnerability it took hours to update the database. ",[],{},{"nodeType":1293,"value":37,"marks":5858,"data":5859},[],{},{"nodeType":1294,"data":5861,"content":5862},{},[5863],{"nodeType":1293,"value":5864,"marks":5865,"data":5866},"This meant that organizations were exposed to these attacks for a prolonged period, and were left uncertain as to whether they had addressed the vulnerabilities or not. ",[],{},{"nodeType":1328,"data":5868,"content":5869},{},[5870],{"nodeType":1293,"value":5871,"marks":5872,"data":5873},"Using Push to find and fix ghost logins across your app inventory",[],{},{"nodeType":1294,"data":5875,"content":5876},{},[5877],{"nodeType":1293,"value":5878,"marks":5879,"data":5880},"Finding and fixing ghost logins is a challenge for most organizations. Since you can’t rely on the view provided by your IdP, you need to:",[],{},{"nodeType":1414,"data":5882,"content":5883},{},[5884,5894,5904],{"nodeType":1418,"data":5885,"content":5886},{},[5887],{"nodeType":1294,"data":5888,"content":5889},{},[5890],{"nodeType":1293,"value":5891,"marks":5892,"data":5893},"Discover the apps in use across your organization",[],{},{"nodeType":1418,"data":5895,"content":5896},{},[5897],{"nodeType":1294,"data":5898,"content":5899},{},[5900],{"nodeType":1293,"value":5901,"marks":5902,"data":5903},"Get admin rights, audit each app, and unset any local credentials (enforcing MFA at the app-level too if you can, for good measure)",[],{},{"nodeType":1418,"data":5905,"content":5906},{},[5907],{"nodeType":1294,"data":5908,"content":5909},{},[5910],{"nodeType":1293,"value":5911,"marks":5912,"data":5913},"Configure the app to prevent local accounts being created (again, if possible)",[],{},{"nodeType":1294,"data":5915,"content":5916},{},[5917],{"nodeType":1293,"value":5918,"marks":5919,"data":5920},"Not only is this a sisyphean task with continually moving goalposts, but depending on which apps you use, and how they’ve been designed, it may not be possible to remediate every instance of ghost logins. For that reason, it’s important to also invest in your identity threat detection and response capabilities — for when, not if, an account takeover attempt occurs. ",[],{},{"nodeType":1294,"data":5922,"content":5923},{},[5924,5928,5937],{"nodeType":1293,"value":5925,"marks":5926,"data":5927},"Push helps organizations to defend against ghost logins and other identity threats with a defense-in-depth approach: Using a browser-based agent to generate visibility of all logins (not just via IdP logs) while also detecting, intercepting, and shutting down account takeover attempts via phishing, credential stuffing, and session hijacking. ",[],{},{"nodeType":1343,"data":5929,"content":5931},{"uri":5930},"https://pushsecurity.com/",[5932],{"nodeType":1293,"value":5933,"marks":5934,"data":5936},"Learn more here.",[5935],{"type":1351},{},{"nodeType":1293,"value":37,"marks":5938,"data":5939},[],{},{"nodeType":1294,"data":5941,"content":5942},{},[5943,5947,5955],{"nodeType":1293,"value":5944,"marks":5945,"data":5946},"And if you'd like to learn more about ghost logins and other identity attack techniques, ",[],{},{"nodeType":1343,"data":5948,"content":5950},{"uri":5949},"https://github.com/pushsecurity/saas-attacks?tab=readme-ov-file",[5951],{"nodeType":1293,"value":5952,"marks":5953,"data":5954},"check out the SaaS attack matrix on GitHub",[],{},{"nodeType":1293,"value":1604,"marks":5956,"data":5957},[],{},{"nodeType":1378,"data":5959,"content":5963},{"target":5960},{"sys":5961},{"id":5962,"type":1383,"linkType":1384},"1VMpMgZvx9hgps2OoxCTmF",[],{"nodeType":1294,"data":5965,"content":5966},{},[5967],{"nodeType":1293,"value":37,"marks":5968,"data":5969},[],{},"Ghost logins: When forgotten identities come back to haunt you","How ghost logins can be used by cyber attackers for account takeover and persistence.","2024-07-10T00:00:00.000Z","ghost-logins-when-forgotten-identities-come-back-to-haunt-you",{"items":5975},[5976,5978],{"sys":5977,"name":4304},{"id":4303},{"sys":5979,"name":1312},{"id":1311},{"items":5981},[5982],{"fullName":4310,"firstName":4311,"jobTitle":4312,"profilePicture":5983},{"url":4314},{"items":5985},[5986],{"fullName":4310,"firstName":4311,"jobTitle":4312,"profilePicture":5987},{"url":4314},{"json":5989,"links":7362},{"data":5990,"content":5991,"nodeType":1302},{},[5992,6012,6018,6025,6032,6053,6060,6063,6070,6077,6084,6091,6179,6186,6277,6285,6292,6299,6307,6310,6317,6324,6331,6360,6393,6422,6429,6436,6466,6473,6505,6512,6540,6547,6554,6581,6593,6600,6619,6651,6663,6666,6673,6693,6705,6723,6738,6745,6765,6795,6814,6821,6828,6847,6854,6862,6865,6872,6879,6917,6925,6932,6939,6946,7032,7056,7063,7070,7082,7102,7114,7117,7124,7131,7194,7213,7219,7222,7229,7258,7265,7272,7350,7356],{"data":5993,"content":5994,"nodeType":1294},{},[5995,5999,6008],{"data":5996,"marks":5997,"value":5998,"nodeType":1293},{},[],"If you caught ",{"data":6000,"content":6002,"nodeType":1343},{"uri":6001},"https://cisoseries.com/securing-identities-in-the-cloud/",[6003],{"data":6004,"marks":6005,"value":6007,"nodeType":1293},{},[6006],{"type":1351},"our CEO Adam’s recent appearance on the Defense in Depth podcast",{"data":6009,"marks":6010,"value":6011,"nodeType":1293},{},[]," you’ll have heard some top-tier banter between Geoff and David on the problem of identity security – and how, in Geoff’s words, “way too many people” think they’ve got it covered when it comes to identity attacks.",{"data":6013,"content":6017,"nodeType":1378},{"target":6014},{"sys":6015},{"id":6016,"type":1383,"linkType":1384},"UcfFq2lOiMMJKaDfaNBqx",[],{"data":6019,"content":6020,"nodeType":1294},{},[6021],{"data":6022,"marks":6023,"value":6024,"nodeType":1293},{},[],"At Push, we’re constantly exploring the limits of controls against the latest threats. But naturally, security teams with hundreds of priorities can’t afford to dedicate the same amount of research time to this problem that we can. This means we come across a lot of common misconceptions about how controls like MFA, SSO and EDR perform against current identity attack techniques. ",{"data":6026,"content":6027,"nodeType":1294},{},[6028],{"data":6029,"marks":6030,"value":6031,"nodeType":1293},{},[],"These common misconceptions are severely impacting the ability of security teams to plan for, and defend against, identity-based attacks – giving attackers the window of opportunity they need to continue exploiting people and businesses. ",{"data":6033,"content":6034,"nodeType":1294},{},[6035,6039,6044,6048],{"data":6036,"marks":6037,"value":6038,"nodeType":1293},{},[],"So, we hope that this allows you a clearer perspective when building your identity security strategy, with a realistic view of what a particular control will give you – and what it won’t. ",{"data":6040,"marks":6041,"value":6043,"nodeType":1293},{},[6042],{"type":1464},"That isn’t to say you should discard any of these controls; they all have an important part to play! ",{"data":6045,"marks":6046,"value":6047,"nodeType":1293},{},[],"But, it’s important to be aware of their limitations to be able to build a resilient security model, ",{"data":6049,"marks":6050,"value":6052,"nodeType":1293},{},[6051],{"type":1464},"with strategic defense in depth to compensate for known weaknesses. ",{"data":6054,"content":6055,"nodeType":1294},{},[6056],{"data":6057,"marks":6058,"value":6059,"nodeType":1293},{},[],"Without further ado, here are the top reasons why Push Security shouldn’t exist. ",{"data":6061,"content":6062,"nodeType":1522},{},[],{"data":6064,"content":6065,"nodeType":1328},{},[6066],{"data":6067,"marks":6068,"value":6069,"nodeType":1293},{},[],"Reason 1: “Browser-based attacks aren’t a priority”",{"data":6071,"content":6072,"nodeType":1294},{},[6073],{"data":6074,"marks":6075,"value":6076,"nodeType":1293},{},[],"Particularly in the current economic climate, with many security teams feeling the squeeze, organizations often haven’t budgeted (mentally or financially) for a new kind of threat to factor into their modelling. ",{"data":6078,"content":6079,"nodeType":1294},{},[6080],{"data":6081,"marks":6082,"value":6083,"nodeType":1293},{},[],"We get it, now isn’t a great time to be tackling a new problem. Getting the budget to do the same as last year is difficult enough, never mind adding something new. ",{"data":6085,"content":6086,"nodeType":1294},{},[6087],{"data":6088,"marks":6089,"value":6090,"nodeType":1293},{},[],"But, there’s clear evidence that we're facing something a new kind of security problem. Modern attacks are consciously evading the network and endpoint, and are increasingly playing out entirely over the internet in the form of account takeover. ",{"data":6092,"content":6093,"nodeType":1414},{},[6094,6115,6136,6158],{"data":6095,"content":6096,"nodeType":1418},{},[6097],{"data":6098,"content":6099,"nodeType":1294},{},[6100,6104,6111],{"data":6101,"marks":6102,"value":6103,"nodeType":1293},{},[],"Stolen creds are the #1 breach vector in 79% of web app attacks (",{"data":6105,"content":6106,"nodeType":1343},{"uri":5606},[6107],{"data":6108,"marks":6109,"value":5609,"nodeType":1293},{},[6110],{"type":1351},{"data":6112,"marks":6113,"value":6114,"nodeType":1293},{},[],").  ",{"data":6116,"content":6117,"nodeType":1418},{},[6118],{"data":6119,"content":6120,"nodeType":1294},{},[6121,6125,6133],{"data":6122,"marks":6123,"value":6124,"nodeType":1293},{},[],"147,000 token replay attacks in 2023, 111% increase year-over-year (",{"data":6126,"content":6128,"nodeType":1343},{"uri":6127},"https://techcommunity.microsoft.com/t5/microsoft-entra-blog/how-to-break-the-token-theft-cyber-attack-chain/ba-p/4062700",[6129],{"data":6130,"marks":6131,"value":5586,"nodeType":1293},{},[6132],{"type":1351},{"data":6134,"marks":6135,"value":5781,"nodeType":1293},{},[],{"data":6137,"content":6138,"nodeType":1418},{},[6139],{"data":6140,"content":6141,"nodeType":1294},{},[6142,6146,6155],{"data":6143,"marks":6144,"value":6145,"nodeType":1293},{},[],"80% of attacks involve identity and compromised credentials (",{"data":6147,"content":6149,"nodeType":1343},{"uri":6148},"https://www.crowdstrike.com/blog/relentless-threat-activity-puts-identities-in-the-crosshairs/",[6150],{"data":6151,"marks":6152,"value":6154,"nodeType":1293},{},[6153],{"type":1351},"Crowdstrike",{"data":6156,"marks":6157,"value":6114,"nodeType":1293},{},[],{"data":6159,"content":6160,"nodeType":1418},{},[6161],{"data":6162,"content":6163,"nodeType":1294},{},[6164,6168,6176],{"data":6165,"marks":6166,"value":6167,"nodeType":1293},{},[],"4,000 password-based attacks per second observed (",{"data":6169,"content":6171,"nodeType":1343},{"uri":6170},"https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report-2023",[6172],{"data":6173,"marks":6174,"value":5586,"nodeType":1293},{},[6175],{"type":1351},{"data":6177,"marks":6178,"value":5591,"nodeType":1293},{},[],{"data":6180,"content":6181,"nodeType":1294},{},[6182],{"data":6183,"marks":6184,"value":6185,"nodeType":1293},{},[],"It’s also telling that the cyber crime ecosystem itself seems to be leaning toward the theft, sale, and use of stolen credentials (not just emails and passwords, but session tokens too). ",{"data":6187,"content":6188,"nodeType":1414},{},[6189,6210,6232,6254],{"data":6190,"content":6191,"nodeType":1418},{},[6192],{"data":6193,"content":6194,"nodeType":1294},{},[6195,6198,6206],{"data":6196,"marks":6197,"value":37,"nodeType":1293},{},[],{"data":6199,"content":6200,"nodeType":1343},{"uri":5606},[6201],{"data":6202,"marks":6203,"value":6205,"nodeType":1293},{},[6204],{"type":1351},"According to the 2024 DBIR",{"data":6207,"marks":6208,"value":6209,"nodeType":1293},{},[],", more than 1000 credentials appear on criminal forums and marketplaces every day, with the majority (65%) appearing less than a day after first being discovered. ",{"data":6211,"content":6212,"nodeType":1418},{},[6213],{"data":6214,"content":6215,"nodeType":1294},{},[6216,6220,6228],{"data":6217,"marks":6218,"value":6219,"nodeType":1293},{},[],"In June, ",{"data":6221,"content":6222,"nodeType":1343},{"uri":1677},[6223],{"data":6224,"marks":6225,"value":6227,"nodeType":1293},{},[6226],{"type":1351},"Troy Hunt at Have I Been Pwned (HIBP) wrote about the impact of channels like Telegram",{"data":6229,"marks":6230,"value":6231,"nodeType":1293},{},[]," and the sale of combolists (username, password, login portal URL), after being sent 122GB of data scraped out of thousands of Telegram channels, containing 361M unique email addresses (of which 151M had never been seen in HIBP before). ",{"data":6233,"content":6234,"nodeType":1418},{},[6235],{"data":6236,"content":6237,"nodeType":1294},{},[6238,6242,6251],{"data":6239,"marks":6240,"value":6241,"nodeType":1293},{},[],"In July, ",{"data":6243,"content":6245,"nodeType":1343},{"uri":6244},"https://cybernews.com/security/rockyou2024-largest-password-compilation-leak/",[6246],{"data":6247,"marks":6248,"value":6250,"nodeType":1293},{},[6249],{"type":1351},"10 billion passwords were leaked in the RockYou2024 compilation",{"data":6252,"marks":6253,"value":1634,"nodeType":1293},{},[],{"data":6255,"content":6256,"nodeType":1418},{},[6257],{"data":6258,"content":6259,"nodeType":1294},{},[6260,6264,6273],{"data":6261,"marks":6262,"value":6263,"nodeType":1293},{},[],"And ultimately, ",{"data":6265,"content":6267,"nodeType":1343},{"uri":6266},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/",[6268],{"data":6269,"marks":6270,"value":6272,"nodeType":1293},{},[6271],{"type":1351},"high-profile breaches",{"data":6274,"marks":6275,"value":6276,"nodeType":1293},{},[]," of Snowflake customers, Microsoft, Okta, and others reinforce the threat behind the numbers, all of which are the result of identity attacks. ",{"data":6278,"content":6279,"nodeType":1294},{},[6280],{"data":6281,"marks":6282,"value":6284,"nodeType":1293},{},[6283],{"type":1464},"So, if a business uses any third-party provided web applications or services, then its workforce identities are the lowest-hanging fruit for attackers to pick, and the risk of account takeover should be high up on the risk register. ",{"data":6286,"content":6287,"nodeType":1294},{},[6288],{"data":6289,"marks":6290,"value":6291,"nodeType":1293},{},[],"Yes, it’s tough to redo budgets on the fly or rip up a five year plan. But, asymmetrical cyber TTPs have always sought to undermine the best laid plans of CISOs – attackers usually look in the places that defenders aren't. ",{"data":6293,"content":6294,"nodeType":1294},{},[6295],{"data":6296,"marks":6297,"value":6298,"nodeType":1293},{},[],"When looking at the evidence, is securing the identity attack surface really a lower priority than adding a CASB, CSPM, or shiny new AI tool? Even when we look at historical recurring spend on things like EDR or vulnerability management, it’s arguable that the risk of identity attacks has overtaken software-based exploits for many organizations whose traditional networks are shrinking, while their cloud app estate grows. ",{"data":6300,"content":6301,"nodeType":1294},{},[6302],{"data":6303,"marks":6304,"value":6306,"nodeType":1293},{},[6305],{"type":1464},"It’s important to consider what’s right for your business, but the evidence shows us that securing the identity attack surface promises real risk reduction in the face of a genuine threat. ",{"data":6308,"content":6309,"nodeType":1522},{},[],{"data":6311,"content":6312,"nodeType":1328},{},[6313],{"data":6314,"marks":6315,"value":6316,"nodeType":1293},{},[],"Reason 2: “Our business apps are all behind SSO”",{"data":6318,"content":6319,"nodeType":1294},{},[6320],{"data":6321,"marks":6322,"value":6323,"nodeType":1293},{},[],"SSO is often seen as a utopia where each employee has a single, secure digital identity that is used to access all of their work applications. When businesses are using SSO, we usually hear:",{"data":6325,"content":6326,"nodeType":1446},{},[6327],{"data":6328,"marks":6329,"value":6330,"nodeType":1293},{},[],"“Everything is behind SSO, there are no apps outside of it.”",{"data":6332,"content":6333,"nodeType":1294},{},[6334,6338,6347,6351,6356],{"data":6335,"marks":6336,"value":6337,"nodeType":1293},{},[],"Unfortunately, organizations are always using more apps than they realize. The impact of ",{"data":6339,"content":6341,"nodeType":1343},{"uri":6340},"https://productled.com/blog/product-led-growth-definition",[6342],{"data":6343,"marks":6344,"value":6346,"nodeType":1293},{},[6345],{"type":1351},"product-led growth",{"data":6348,"marks":6349,"value":6350,"nodeType":1293},{},[]," on the self adoption of cloud services is well documented, and we see that ",{"data":6352,"marks":6353,"value":6355,"nodeType":1293},{},[6354],{"type":1464},"even SMEs typically have 100+ apps in their estate",{"data":6357,"marks":6358,"value":6359,"nodeType":1293},{},[],", and the number of apps per business continues to grow year on year. ",{"data":6361,"content":6362,"nodeType":1294},{},[6363,6367,6372,6376,6380,6384,6389],{"data":6364,"marks":6365,"value":6366,"nodeType":1293},{},[],"So, while every ",{"data":6368,"marks":6369,"value":6371,"nodeType":1293},{},[6370],{"type":1464},"known ",{"data":6373,"marks":6374,"value":6375,"nodeType":1293},{},[],"app",{"data":6377,"marks":6378,"value":4351,"nodeType":1293},{},[6379],{"type":1464},{"data":6381,"marks":6382,"value":6383,"nodeType":1293},{},[],"might be behind SSO, this still leaves tens or hundreds of ",{"data":6385,"marks":6386,"value":6388,"nodeType":1293},{},[6387],{"type":1464},"unknown",{"data":6390,"marks":6391,"value":6392,"nodeType":1293},{},[]," apps, with thousands of associated identities. ",{"data":6394,"content":6395,"nodeType":1294},{},[6396,6400,6405,6409,6418],{"data":6397,"marks":6398,"value":6399,"nodeType":1293},{},[],"But even if you did know about every app, the fact of the matter is ",{"data":6401,"marks":6402,"value":6404,"nodeType":1293},{},[6403],{"type":1464},"that fewer than 1 in 3 apps actually support SAML SSO",{"data":6406,"marks":6407,"value":6408,"nodeType":1293},{},[],", and many of those ",{"data":6410,"content":6412,"nodeType":1343},{"uri":6411},"https://sso.tax/",[6413],{"data":6414,"marks":6415,"value":6417,"nodeType":1293},{},[6416],{"type":1351},"only at the premium tier",{"data":6419,"marks":6420,"value":6421,"nodeType":1293},{},[],". Our data shows that the proportion of apps actually behind SSO is even lower, at 1 in 5. So getting everything behind SSO just isn’t a realistic goal for any organization. ",{"data":6423,"content":6424,"nodeType":1446},{},[6425],{"data":6426,"marks":6427,"value":6428,"nodeType":1293},{},[],"“Everything important is behind SSO, and the apps that aren’t don’t pose a risk.” ",{"data":6430,"content":6431,"nodeType":1294},{},[6432],{"data":6433,"marks":6434,"value":6435,"nodeType":1293},{},[],"There’s often a view that if it wasn’t centrally procured, IT wasn’t involved, and it’s not behind SSO, then it’s just not a concern. But apps can have complex integrations and permissions that increase the potential blast radius of an app compromise. ",{"data":6437,"content":6438,"nodeType":1294},{},[6439,6443,6451,6455,6462],{"data":6440,"marks":6441,"value":6442,"nodeType":1293},{},[],"We’ve published ",{"data":6444,"content":6445,"nodeType":1343},{"uri":1583},[6446],{"data":6447,"marks":6448,"value":6450,"nodeType":1293},{},[6449],{"type":1351},"extensive research on SaaS-native attack techniques",{"data":6452,"marks":6453,"value":6454,"nodeType":1293},{},[]," and documented many of the scenarios in which attackers can expand from hijacking a single SaaS app with a small number of users into a larger-scale compromise, for example through ",{"data":6456,"content":6457,"nodeType":1343},{"uri":5773},[6458],{"data":6459,"marks":6460,"value":5763,"nodeType":1293},{},[6461],{"type":1351},{"data":6463,"marks":6464,"value":6465,"nodeType":1293},{},[],": Modifying SAML for a compromised app to redirect users to a malicious domain during the authentication process that proxies a legitimate authentication service (e.g. Google, Okta or Microsoft) – effectively acting as a watering hole for further credential harvesting. ",{"data":6467,"content":6468,"nodeType":1294},{},[6469],{"data":6470,"marks":6471,"value":6472,"nodeType":1293},{},[],"Also, the value of an app is not necessarily tied to the number of users it has in the business. A sales and marketing app can contain huge amounts of sensitive data, as can developer apps – just look at Snowflake! It only takes a single account to be created, a single integration to be set up, to result in a major data breach down the line. ",{"data":6474,"content":6475,"nodeType":1294},{},[6476,6480,6489,6492,6501],{"data":6477,"marks":6478,"value":6479,"nodeType":1293},{},[],"You can check out our ",{"data":6481,"content":6483,"nodeType":1343},{"uri":6482},"https://pushsecurity.com/blog/",[6484],{"data":6485,"marks":6486,"value":6488,"nodeType":1293},{},[6487],{"type":1351},"blog page",{"data":6490,"marks":6491,"value":4609,"nodeType":1293},{},[],{"data":6493,"content":6495,"nodeType":1343},{"uri":6494},"https://www.youtube.com/watch?v=xZIQd_0v9sE&t=12s",[6496],{"data":6497,"marks":6498,"value":6500,"nodeType":1293},{},[6499],{"type":1351},"watch one of our videos",{"data":6502,"marks":6503,"value":6504,"nodeType":1293},{},[]," for more information.   ",{"data":6506,"content":6507,"nodeType":1446},{},[6508],{"data":6509,"marks":6510,"value":6511,"nodeType":1293},{},[],"Ghost logins: A nightmare for SSO, dreamy for attackers",{"data":6513,"content":6514,"nodeType":1294},{},[6515,6519,6524,6528,6536],{"data":6516,"marks":6517,"value":6518,"nodeType":1293},{},[],"You might already be feeling a bit deflated that SSO isn’t going to give you everything you wanted, and we’re sorry to be the bearer of bad news. Unfortunately, ",{"data":6520,"marks":6521,"value":6523,"nodeType":1293},{},[6522],{"type":1464},"even if you are using SSO, additional login methods can still exist alongside SSO",{"data":6525,"marks":6526,"value":6527,"nodeType":1293},{},[],". We call these ",{"data":6529,"content":6530,"nodeType":1343},{"uri":1935},[6531],{"data":6532,"marks":6533,"value":1938,"nodeType":1293},{},[6534,6535],{"type":1351},{"type":1464},{"data":6537,"marks":6538,"value":1634,"nodeType":1293},{},[6539],{"type":1464},{"data":6541,"content":6542,"nodeType":1294},{},[6543],{"data":6544,"marks":6545,"value":6546,"nodeType":1293},{},[],"Ghost logins are effectively any alternative login method. In addition to SSO, you could have a local password, a social login (e.g., login with Google, Facebook, etc.), backup emails, or API-based login methods. ",{"data":6548,"content":6549,"nodeType":1294},{},[6550],{"data":6551,"marks":6552,"value":6553,"nodeType":1293},{},[],"Multiple methods are often enabled by default and need to be explicitly disabled at the app level. Further, migrating an existing app to SSO doesn’t automatically remove local accounts, but effectively adds an SSO layer on top. ",{"data":6555,"content":6556,"nodeType":1294},{},[6557,6561,6566,6570,6578],{"data":6558,"marks":6559,"value":6560,"nodeType":1293},{},[],"The final problem here is that because MFA is applied separately at the app level and SSO level, ",{"data":6562,"marks":6563,"value":6565,"nodeType":1293},{},[6564],{"type":1464},"you can have local logins without MFA, at the same time as SSO logins with MFA — that can be used concurrently.",{"data":6567,"marks":6568,"value":6569,"nodeType":1293},{},[]," This was acutely felt during the recent Snowflake breaches, ",{"data":6571,"content":6572,"nodeType":1343},{"uri":1957},[6573],{"data":6574,"marks":6575,"value":6577,"nodeType":1293},{},[6576],{"type":1351},"where in-app identification and disabling of non-SSO logins proved to be particularly error-prone",{"data":6579,"marks":6580,"value":1965,"nodeType":1293},{},[],{"data":6582,"content":6583,"nodeType":1294},{},[6584,6588],{"data":6585,"marks":6586,"value":6587,"nodeType":1293},{},[],"The result here is that credential stuffing attacks can still prove successful against your SSO-joined apps if local logins exist, and MFA hasn’t been specifically set at the app level. ",{"data":6589,"marks":6590,"value":6592,"nodeType":1293},{},[6591],{"type":1464},"And unless you’ve specifically disabled them and unset every non-SSO login for every app, they probably do. ",{"data":6594,"content":6595,"nodeType":1446},{},[6596],{"data":6597,"marks":6598,"value":6599,"nodeType":1293},{},[],"The verdict: SSO is great, but it's no silver bullet",{"data":6601,"content":6602,"nodeType":1294},{},[6603,6607,6615],{"data":6604,"marks":6605,"value":6606,"nodeType":1293},{},[],"While SSO is invariably a beneficial security control, ",{"data":6608,"content":6610,"nodeType":1343},{"uri":6609},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/#id-how-can-ghost-logins-be-abused-by-attackers_id-ghost-logins-for-persistence-and-defense-evasion",[6611],{"data":6612,"marks":6613,"value":6614,"nodeType":1293},{},[],"attackers can also naturally exploit it to gain access to a large number of downstream applications",{"data":6616,"marks":6617,"value":6618,"nodeType":1293},{},[],". If you compromise an IdP account like Okta, you can then access any connected app, often without requiring any further authentication.",{"data":6620,"content":6621,"nodeType":1294},{},[6622,6626,6635,6639,6648],{"data":6623,"marks":6624,"value":6625,"nodeType":1293},{},[],"We’ve seen this recently, with an ",{"data":6627,"content":6629,"nodeType":1343},{"uri":6628},"https://www.bleepingcomputer.com/news/security/okta-warns-of-unprecedented-credential-stuffing-attacks-on-customers/",[6630],{"data":6631,"marks":6632,"value":6634,"nodeType":1293},{},[6633],{"type":1351},"unprecedented spike in credential stuffing attacks reported by Okta",{"data":6636,"marks":6637,"value":6638,"nodeType":1293},{},[],", as well as ",{"data":6640,"content":6642,"nodeType":1343},{"uri":6641},"https://www.bleepingcomputer.com/news/security/okta-warns-of-credential-stuffing-attacks-targeting-its-cors-feature/",[6643],{"data":6644,"marks":6645,"value":6647,"nodeType":1293},{},[6646],{"type":1351},"attacks looking to exploit Okta’s CORS feature",{"data":6649,"marks":6650,"value":1634,"nodeType":1293},{},[],{"data":6652,"content":6653,"nodeType":1294},{},[6654,6659],{"data":6655,"marks":6656,"value":6658,"nodeType":1293},{},[6657],{"type":1464},"Ultimately, the promised land of a 1:1 employee to identity ratio just isn’t realistic. ",{"data":6660,"marks":6661,"value":6662,"nodeType":1293},{},[],"So while SSO is a big part of the solution to identity attacks, it’s not a silver bullet.   ",{"data":6664,"content":6665,"nodeType":1522},{},[],{"data":6667,"content":6668,"nodeType":1328},{},[6669],{"data":6670,"marks":6671,"value":6672,"nodeType":1293},{},[],"Reason 3: “We’ve got MFA deployed everywhere”",{"data":6674,"content":6675,"nodeType":1294},{},[6676,6680,6689],{"data":6677,"marks":6678,"value":6679,"nodeType":1293},{},[],"Microsoft famously stated that ",{"data":6681,"content":6683,"nodeType":1343},{"uri":6682},"https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report-2023#:~:text=Outlier%20attacks%20make%20up%20just,of%20compromise%20by%2099.2%20percent.",[6684],{"data":6685,"marks":6686,"value":6688,"nodeType":1293},{},[6687],{"type":1351},"MFA reduces the risk of compromise by 99.2%",{"data":6690,"marks":6691,"value":6692,"nodeType":1293},{},[],". But this doesn’t mean that it stops 99% of attacks. Or, that it should make up 99% of your defense. ",{"data":6694,"content":6695,"nodeType":1294},{},[6696,6700],{"data":6697,"marks":6698,"value":6699,"nodeType":1293},{},[],"MFA unarguably raises the bar for attackers, even if that bar is still pretty low. Naturally, accounts without MFA are an easier target. ",{"data":6701,"marks":6702,"value":6704,"nodeType":1293},{},[6703],{"type":1464},"But the problem is that MFA isn’t an enterprise-wide castle wall. It’s more like a row of hurdles with gaps in-between. ",{"data":6706,"content":6707,"nodeType":1294},{},[6708,6712,6720],{"data":6709,"marks":6710,"value":6711,"nodeType":1293},{},[],"MFA is usually handled separately at the SSO level and app level. For apps that are self-adopted by end users, they can't be relied on to add in a security control that will introduce friction to their user experience. Building on the aforementioned ghost logins, even if MFA is adopted at the SSO level, local logins can exist without MFA unless also applied at the app level. ",{"data":6713,"content":6714,"nodeType":1343},{"uri":1957},[6715],{"data":6716,"marks":6717,"value":6719,"nodeType":1293},{},[6718],{"type":1351},"The recent Snowflake breach is a perfect example of this problem",{"data":6721,"marks":6722,"value":1634,"nodeType":1293},{},[],{"data":6724,"content":6725,"nodeType":1294},{},[6726,6730,6735],{"data":6727,"marks":6728,"value":6729,"nodeType":1293},{},[],"Because of this, ",{"data":6731,"marks":6732,"value":6734,"nodeType":1293},{},[6733],{"type":1464},"we find that only around 1 in 3 identities actually have MFA enabled",{"data":6736,"marks":6737,"value":1634,"nodeType":1293},{},[],{"data":6739,"content":6740,"nodeType":1446},{},[6741],{"data":6742,"marks":6743,"value":6744,"nodeType":1293},{},[],"\"MFA protects us against phishing attacks\"",{"data":6746,"content":6747,"nodeType":1294},{},[6748,6752,6761],{"data":6749,"marks":6750,"value":6751,"nodeType":1293},{},[],"Even where MFA is deployed, most MFA methods are proven to be phishable or otherwise bypassable. SMS and push-based MFA are susceptible to well known bypasses including SIM swapping and ",{"data":6753,"content":6755,"nodeType":1343},{"uri":6754},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_fatigue/description.md",[6756],{"data":6757,"marks":6758,"value":6760,"nodeType":1293},{},[6759],{"type":1351},"MFA fatigue",{"data":6762,"marks":6763,"value":6764,"nodeType":1293},{},[]," attacks. TOTP is a little better, but still vulnerable. ",{"data":6766,"content":6767,"nodeType":1294},{},[6768,6772,6780,6784,6792],{"data":6769,"marks":6770,"value":6771,"nodeType":1293},{},[],"Many attacks are simply cutting out the middleman and focusing on ",{"data":6773,"content":6774,"nodeType":1343},{"uri":2165},[6775],{"data":6776,"marks":6777,"value":6779,"nodeType":1293},{},[6778],{"type":1351},"using stolen session tokens",{"data":6781,"marks":6782,"value":6783,"nodeType":1293},{},[]," to bypass MFA. The most common method for this is via infostealers, which typically scrape all credentials (e.g. usernames, passwords, login pages, session tokens) as well as other information stored in the browser of an infected device. ",{"data":6785,"content":6786,"nodeType":1343},{"uri":1985},[6787],{"data":6788,"marks":6789,"value":6791,"nodeType":1293},{},[6790],{"type":1351},"Infostealers played a major role in the recent Snowflake breach",{"data":6793,"marks":6794,"value":1634,"nodeType":1293},{},[],{"data":6796,"content":6797,"nodeType":1294},{},[6798,6802,6810],{"data":6799,"marks":6800,"value":6801,"nodeType":1293},{},[],"Additionally, ",{"data":6803,"content":6804,"nodeType":1343},{"uri":5793},[6805],{"data":6806,"marks":6807,"value":6809,"nodeType":1293},{},[6808],{"type":1351},"modern phishing techniques like adversary-in-the-middle (AitM) and browser-in-the-middle (BitM)",{"data":6811,"marks":6812,"value":6813,"nodeType":1293},{},[]," see the attacker steal the live session and associated tokens from the victim, with the victim prompted to complete the MFA process as part of the attack. ",{"data":6815,"content":6816,"nodeType":1446},{},[6817],{"data":6818,"marks":6819,"value":6820,"nodeType":1293},{},[],"“We’re using passkeys”",{"data":6822,"content":6823,"nodeType":1294},{},[6824],{"data":6825,"marks":6826,"value":6827,"nodeType":1293},{},[],"Great! Passkey users are in a better position than 99% of other businesses. Passkeys are widely accepted to be phishing resistant – at least for now, although as more businesses use them, new ways of getting around them will no doubt be discovered by attackers. ",{"data":6829,"content":6830,"nodeType":1294},{},[6831,6835,6844],{"data":6832,"marks":6833,"value":6834,"nodeType":1293},{},[],"But, MFA downgrade attacks are possible. There are often backup MFA methods set that can be selected by canceling the authentication prompt and selecting a different method. Even when these aren’t selectable, ",{"data":6836,"content":6838,"nodeType":1343},{"uri":6837},"https://pushsecurity.com/blog/mfa-downgrade-attacks/",[6839],{"data":6840,"marks":6841,"value":6843,"nodeType":1293},{},[6842],{"type":1351},"researchers have demonstrated ways of downgrading authentication to use a phishable method",{"data":6845,"marks":6846,"value":1634,"nodeType":1293},{},[],{"data":6848,"content":6849,"nodeType":1294},{},[6850],{"data":6851,"marks":6852,"value":6853,"nodeType":1293},{},[],"Most apps are designed primarily for user flexibility, not security. And backup methods have a legitimate use-case – what if the authenticator device is lost or stops working? If passkeys are the only authentication method, you just got locked out of all of your accounts. But at least no hackers can access them either, right?",{"data":6855,"content":6856,"nodeType":1294},{},[6857],{"data":6858,"marks":6859,"value":6861,"nodeType":1293},{},[6860],{"type":1464},"Like SSO, unless backup MFA methods are disabled for all identities and apps, and all users have enabled MFA across all their accounts and login methods, this isn’t a silver bullet either.  ",{"data":6863,"content":6864,"nodeType":1522},{},[],{"data":6866,"content":6867,"nodeType":1328},{},[6868],{"data":6869,"marks":6870,"value":6871,"nodeType":1293},{},[],"Reason 4: “We’ve got anti-phishing controls already”",{"data":6873,"content":6874,"nodeType":1294},{},[6875],{"data":6876,"marks":6877,"value":6878,"nodeType":1293},{},[],"Identity attacks have evolved significantly in recent years, as have the environments being targeted by attackers with the shift to cloud services and decentralized business IT. Unfortunately, traditional anti-phishing controls weren’t designed for this reality. ",{"data":6880,"content":6881,"nodeType":1414},{},[6882,6902],{"data":6883,"content":6884,"nodeType":1418},{},[6885],{"data":6886,"content":6887,"nodeType":1294},{},[6888,6893,6898],{"data":6889,"marks":6890,"value":6892,"nodeType":1293},{},[6891],{"type":1464},"A",{"data":6894,"marks":6895,"value":6897,"nodeType":1293},{},[6896],{"type":1464},"ttacks used to be focused on a single VPN/webmail endpoint ",{"data":6899,"marks":6900,"value":6901,"nodeType":1293},{},[],"that was naturally easier to protect than 100+ SaaS apps (especially if the security team isn’t even aware of them). Attackers now have 1000s of sprawled identities to target per enterprise, increasing the chance that weak or reused passwords will be found. ",{"data":6903,"content":6904,"nodeType":1418},{},[6905],{"data":6906,"content":6907,"nodeType":1294},{},[6908,6913],{"data":6909,"marks":6910,"value":6912,"nodeType":1293},{},[6911],{"type":1464},"Likewise, security teams only needed to care about a small set of credentials ",{"data":6914,"marks":6915,"value":6916,"nodeType":1293},{},[],"relating to user directory accounts and VPN/remote access tooling used to tunnel into the corporate network. Now, business functions and data are dispersed across cloud apps rather than being neatly contained in on-prem apps and databases.",{"data":6918,"content":6919,"nodeType":1294},{},[6920],{"data":6921,"marks":6922,"value":6924,"nodeType":1293},{},[6923],{"type":1464},"Now, attackers have more platforms on which to phish your users, more credentials to choose from, and more apps to spray them across, while security teams have a much larger surface to defend.",{"data":6926,"content":6927,"nodeType":1446},{},[6928],{"data":6929,"marks":6930,"value":6931,"nodeType":1293},{},[],"“Our email and content filtering controls stop phishing attacks”",{"data":6933,"content":6934,"nodeType":1294},{},[6935],{"data":6936,"marks":6937,"value":6938,"nodeType":1293},{},[],"Existing phishing prevention solutions have tried to solve the problem by protecting the inbox, a common (but not the only) attack vector, or by blocking lists of known-bad domains. ",{"data":6940,"content":6941,"nodeType":1294},{},[6942],{"data":6943,"marks":6944,"value":6945,"nodeType":1293},{},[],"But, these approaches have major shortcomings:",{"data":6947,"content":6948,"nodeType":1414},{},[6949,6989,7004],{"data":6950,"content":6951,"nodeType":1418},{},[6952],{"data":6953,"content":6954,"nodeType":1294},{},[6955,6960,6964,6973,6976,6985],{"data":6956,"marks":6957,"value":6959,"nodeType":1293},{},[6958],{"type":1464},"Incomplete coverage: ",{"data":6961,"marks":6962,"value":6963,"nodeType":1293},{},[],"Email-based phishing prevention tools can catch general spray-and-pray email phishing campaigns, but it only takes a small amount of tailoring to fly under their radar. The use of LLM tools to tailor phishing emails for their intended victims already makes this possible at scale. Email-based tools also fail to cover phishing attacks beyond the inbox, such as ",{"data":6965,"content":6967,"nodeType":1343},{"uri":6966},"https://pushsecurity.com/blog/slack-phishing-for-initial-access/",[6968],{"data":6969,"marks":6970,"value":6972,"nodeType":1293},{},[6971],{"type":1351},"Slack",{"data":6974,"marks":6975,"value":4585,"nodeType":1293},{},[],{"data":6977,"content":6979,"nodeType":1343},{"uri":6978},"https://pushsecurity.com/blog/phishing-microsoft-teams-for-initial-access/",[6980],{"data":6981,"marks":6982,"value":6984,"nodeType":1293},{},[6983],{"type":1351},"Teams",{"data":6986,"marks":6987,"value":6988,"nodeType":1293},{},[]," phishing.",{"data":6990,"content":6991,"nodeType":1418},{},[6992],{"data":6993,"content":6994,"nodeType":1294},{},[6995,7000],{"data":6996,"marks":6997,"value":6999,"nodeType":1293},{},[6998],{"type":1464},"Expired intel: ",{"data":7001,"marks":7002,"value":7003,"nodeType":1293},{},[],"Tools that rely on known-bad domains always have an incomplete picture because a domain must be reported as malicious in order to get added to a blocklist. Meanwhile, attackers can spin up new sites or host phishing pages on existing sites by exploiting vulnerabilities in them, bypassing rules around preventing visits to newly registered domains. It’s like trying to hit a moving target.",{"data":7005,"content":7006,"nodeType":1418},{},[7007],{"data":7008,"content":7009,"nodeType":1294},{},[7010,7015,7019,7028],{"data":7011,"marks":7012,"value":7014,"nodeType":1293},{},[7013],{"type":1464},"Web-based obfuscation: ",{"data":7016,"marks":7017,"value":7018,"nodeType":1293},{},[],"Attacker tools and malicious implants running on webpages are constantly evolving to evade fingerprinting, and attackers are using techniques like ",{"data":7020,"content":7022,"nodeType":1343},{"uri":7021},"https://www.cyfirma.com/research/html-smuggling-a-stealthier-approach-to-deliver-malware/",[7023],{"data":7024,"marks":7025,"value":7027,"nodeType":1293},{},[7026],{"type":1351},"HTML smuggling",{"data":7029,"marks":7030,"value":7031,"nodeType":1293},{},[]," to get around web-based controls put in place by developers. ",{"data":7033,"content":7034,"nodeType":1294},{},[7035,7039,7044,7048,7053],{"data":7036,"marks":7037,"value":7038,"nodeType":1293},{},[],"Even if these controls are sometimes successful, attackers have reliably demonstrated ways to get around them, ",{"data":7040,"marks":7041,"value":7043,"nodeType":1293},{},[7042],{"type":1464},"it really is a cat-and-mouse game at this point",{"data":7045,"marks":7046,"value":7047,"nodeType":1293},{},[],". There usually needs to be a compromise before the attacker's infrastructure or tooling can be tagged and blocked, but ",{"data":7049,"marks":7050,"value":7052,"nodeType":1293},{},[7051],{"type":1464},"they evolve so rapidly that defenders are always one step behind",{"data":7054,"marks":7055,"value":1634,"nodeType":1293},{},[],{"data":7057,"content":7058,"nodeType":1446},{},[7059],{"data":7060,"marks":7061,"value":7062,"nodeType":1293},{},[],"“All our employees use a password manager”",{"data":7064,"content":7065,"nodeType":1294},{},[7066],{"data":7067,"marks":7068,"value":7069,"nodeType":1293},{},[],"Password managers are increasingly necessary due to the large number of credentials that users now have to juggle. Since the majority of apps don’t support SAML SSO, the need for separate credentials per app isn’t going away any time soon. ",{"data":7071,"content":7072,"nodeType":1294},{},[7073,7077],{"data":7074,"marks":7075,"value":7076,"nodeType":1293},{},[],"We often find 2 or more password managers in use per organization (not exactly optimal), but despite increased password manager adoption we see consistently high levels of password reuse, ",{"data":7078,"marks":7079,"value":7081,"nodeType":1293},{},[7080],{"type":1464},"with 1 in 3 users reusing passwords – including their sensitive IdP credentials. ",{"data":7083,"content":7084,"nodeType":1294},{},[7085,7089,7098],{"data":7086,"marks":7087,"value":7088,"nodeType":1293},{},[],"High levels of password reuse shows us that password managers don’t automatically result in secure employee behaviors, while widespread credential reuse significantly increases exposure to ",{"data":7090,"content":7092,"nodeType":1343},{"uri":7091},"https://pushsecurity.com/blog/what-is-credential-stuffing/",[7093],{"data":7094,"marks":7095,"value":7097,"nodeType":1293},{},[7096],{"type":1351},"credential stuffing attacks",{"data":7099,"marks":7100,"value":7101,"nodeType":1293},{},[]," where attackers spray known username and password combinations across a range of app login pages.  ",{"data":7103,"content":7104,"nodeType":1294},{},[7105,7110],{"data":7106,"marks":7107,"value":7109,"nodeType":1293},{},[7108],{"type":1464},"Generally, businesses have very limited visibility into employee password data",{"data":7111,"marks":7112,"value":7113,"nodeType":1293},{},[]," to be able to enforce good practice or accurately respond to data breaches involving credential dumps, even if employees are using a password manager (or several, as the case may be).  ",{"data":7115,"content":7116,"nodeType":1522},{},[],{"data":7118,"content":7119,"nodeType":1328},{},[7120],{"data":7121,"marks":7122,"value":7123,"nodeType":1293},{},[],"Reason 5: “We’ve got all the security data we need”",{"data":7125,"content":7126,"nodeType":1294},{},[7127],{"data":7128,"marks":7129,"value":7130,"nodeType":1293},{},[],"Organizations looking to protect themselves from modern identity attacks suffer from a pretty substantial telemetry gap. ",{"data":7132,"content":7133,"nodeType":1414},{},[7134,7149,7164,7179],{"data":7135,"content":7136,"nodeType":1418},{},[7137],{"data":7138,"content":7139,"nodeType":1294},{},[7140,7145],{"data":7141,"marks":7142,"value":7144,"nodeType":1293},{},[7143],{"type":1464},"Endpoint logs ",{"data":7146,"marks":7147,"value":7148,"nodeType":1293},{},[],"won’t show anything meaningful because most identity attacks don’t need to target the endpoint – no malware is deployed, everything happens in the browser, over the internet. ",{"data":7150,"content":7151,"nodeType":1418},{},[7152],{"data":7153,"content":7154,"nodeType":1294},{},[7155,7160],{"data":7156,"marks":7157,"value":7159,"nodeType":1293},{},[7158],{"type":1464},"Application logs",{"data":7161,"marks":7162,"value":7163,"nodeType":1293},{},[]," are limited in availability, scope, and ease of ingestion, with most app vendors providing substandard logging, and requiring complex custom integrations to get what little data is available. ",{"data":7165,"content":7166,"nodeType":1418},{},[7167],{"data":7168,"content":7169,"nodeType":1294},{},[7170,7175],{"data":7171,"marks":7172,"value":7174,"nodeType":1293},{},[7173],{"type":1464},"Network logs",{"data":7176,"marks":7177,"value":7178,"nodeType":1293},{},[]," (such as via web proxy) struggle to gather and piece together identity data points at-scale, across different apps, due to the sheer volume and broken format of the data post-TLS-termination. ",{"data":7180,"content":7181,"nodeType":1418},{},[7182],{"data":7183,"content":7184,"nodeType":1294},{},[7185,7190],{"data":7186,"marks":7187,"value":7189,"nodeType":1293},{},[7188],{"type":1464},"Identity provider logs",{"data":7191,"marks":7192,"value":7193,"nodeType":1293},{},[]," naturally only cover SSO integrated apps (and therefore don’t cover ⅔ of your business apps) and look exclusively at authentication, and so are blind to client side attacks like phishing. ",{"data":7195,"content":7196,"nodeType":1294},{},[7197,7201,7210],{"data":7198,"marks":7199,"value":7200,"nodeType":1293},{},[],"Unless you’re ingesting data from a browser-based solution like Push, it’s unlikely you have a full monitoring visibility of your identity attack surface. ",{"data":7202,"content":7204,"nodeType":1343},{"uri":7203},"https://pushsecurity.com/blog/the-web-proxy-is-dead-long-live-the-browser-extension/",[7205],{"data":7206,"marks":7207,"value":7209,"nodeType":1293},{},[7208],{"type":1351},"Read more on the value of browser telemetry here. ",{"data":7211,"marks":7212,"value":37,"nodeType":1293},{},[],{"data":7214,"content":7218,"nodeType":1378},{"target":7215},{"sys":7216},{"id":7217,"type":1383,"linkType":1384},"5jPCGPO1tnIkoI7MKW4oUi",[],{"data":7220,"content":7221,"nodeType":1522},{},[],{"data":7223,"content":7224,"nodeType":1328},{},[7225],{"data":7226,"marks":7227,"value":7228,"nodeType":1293},{},[],"Maybe there’s a reason for Push to exist after all!",{"data":7230,"content":7231,"nodeType":1294},{},[7232,7237,7241,7246,7249,7254],{"data":7233,"marks":7234,"value":7236,"nodeType":1293},{},[7235],{"type":1464},"The key takeaway here is that there are no quick fixes or silver bullets. ",{"data":7238,"marks":7239,"value":7240,"nodeType":1293},{},[],"Things like SSO, MFA, and password managers are all part of the solution, ",{"data":7242,"marks":7243,"value":7245,"nodeType":1293},{},[7244],{"type":1464},"but",{"data":7247,"marks":7248,"value":4351,"nodeType":1293},{},[],{"data":7250,"marks":7251,"value":7253,"nodeType":1293},{},[7252],{"type":1464},"aren’t set-and-forget controls",{"data":7255,"marks":7256,"value":7257,"nodeType":1293},{},[],". They need to be continually monitored and maintained to ensure they remain effective.",{"data":7259,"content":7260,"nodeType":1294},{},[7261],{"data":7262,"marks":7263,"value":7264,"nodeType":1293},{},[],"Push stops identity attacks by continually finding and fixing identity vulnerabilities, providing deep context to manage the identity attack surface without looking through blinkers at the IdP or individual apps. ",{"data":7266,"content":7267,"nodeType":1294},{},[7268],{"data":7269,"marks":7270,"value":7271,"nodeType":1293},{},[],"Push helps businesses to get the most out of their identity controls (and bridge the gaps they leave) by:",{"data":7273,"content":7274,"nodeType":1414},{},[7275,7290,7305,7320,7335],{"data":7276,"content":7277,"nodeType":1418},{},[7278],{"data":7279,"content":7280,"nodeType":1294},{},[7281,7286],{"data":7282,"marks":7283,"value":7285,"nodeType":1293},{},[7284],{"type":1464},"Locating all business apps",{"data":7287,"marks":7288,"value":7289,"nodeType":1293},{},[],", not just those plugged into your IdP, so they can be put behind SSO (where possible) or at least securely managed and configured.",{"data":7291,"content":7292,"nodeType":1418},{},[7293],{"data":7294,"content":7295,"nodeType":1294},{},[7296,7301],{"data":7297,"marks":7298,"value":7300,"nodeType":1293},{},[7299],{"type":1464},"Identifying all workforce identities, associated login types, and MFA methods",{"data":7302,"marks":7303,"value":7304,"nodeType":1293},{},[]," to more clearly pinpoint gaps, harden identities, and remediate vulnerabilities like ghost logins.",{"data":7306,"content":7307,"nodeType":1418},{},[7308],{"data":7309,"content":7310,"nodeType":1294},{},[7311,7316],{"data":7312,"marks":7313,"value":7315,"nodeType":1293},{},[7314],{"type":1464},"Stopping account takeover attempts",{"data":7317,"marks":7318,"value":7319,"nodeType":1293},{},[]," by detecting and blocking AitM and BitM phishing toolkits running on webpages, blocking sensitive credential reuse to prevent credential phishing, and identifying stolen sessions running in attacker browsers. ",{"data":7321,"content":7322,"nodeType":1418},{},[7323],{"data":7324,"content":7325,"nodeType":1294},{},[7326,7331],{"data":7327,"marks":7328,"value":7330,"nodeType":1293},{},[7329],{"type":1464},"Preventing password-based attacks",{"data":7332,"marks":7333,"value":7334,"nodeType":1293},{},[]," by detecting the use of weak, reused, and breached passwords across the app estate.  ",{"data":7336,"content":7337,"nodeType":1418},{},[7338],{"data":7339,"content":7340,"nodeType":1294},{},[7341,7346],{"data":7342,"marks":7343,"value":7345,"nodeType":1293},{},[7344],{"type":1464},"Providing unique telemetry in the browser",{"data":7347,"marks":7348,"value":7349,"nodeType":1293},{},[]," to build both proactive and reactive security operations workflows, or add missing context to other data sources, such as IdP, application, or endpoint logs.",{"data":7351,"content":7355,"nodeType":1378},{"target":7352},{"sys":7353},{"id":7354,"type":1383,"linkType":1384},"11p9wnGrZHqp3XPpThHFk3",[],{"data":7357,"content":7358,"nodeType":1294},{},[7359],{"data":7360,"marks":7361,"value":37,"nodeType":1293},{},[],{"entries":7363},{"hyperlink":7364,"inline":7365,"block":7366},[],[],[7367,7375,7383],{"sys":7368,"__typename":7369,"title":7370,"caption":7371,"layoutMode":118,"file":7372},{"id":6016},"Image","Nobody has any identity problems, right?","Push Security’s cheekiest advisor, Geoff Belknap.",{"url":7373,"width":7374,"height":7374},"https://images.ctfassets.net/y1cdw1ablpvd/28qcLq225o8kusjQQQUnCC/98b10fe4f9e6916eb7657f60ab869062/Geoff_Ad__1_.png",1210,{"sys":7376,"__typename":7369,"title":7377,"caption":7378,"layoutMode":118,"file":7379},{"id":7217},"Telemetry comparison table","The browser presents a significant advantage over other sources of identity attack data.",{"url":7380,"width":7381,"height":7382},"https://images.ctfassets.net/y1cdw1ablpvd/4feAEpfP6tetyTjcLIopwG/5bec8c8c10e6e328ebe258bc59bc3cb6/Frame_627570__7_.png",2444,894,{"sys":7384,"__typename":7385,"type":7386,"ctaText":7387,"buttonLabel":7388,"buttonColour":7389,"buttonUrl":118},{"id":7354},"CtaWidget","Demo","Book a demo to see how Push stops account takeover","Book demo","sunny orange","content:blog:5-reasons-why-push-security-shouldnt-exist.json","json","content","blog/5-reasons-why-push-security-shouldnt-exist.json","blog/5-reasons-why-push-security-shouldnt-exist",1776359988439]