[{"data":1,"prerenderedAt":3043},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/dev-diary-phishing-prevention-behind-the-scenes":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1297,"synopsis":1298,"hashTags":118,"publishedDate":1299,"slug":1300,"tagsCollection":1301,"relatedBlogPostsCollection":1311,"ogImage":2560,"authorsCollection":2562,"content":2566,"_id":3038,"_type":3039,"_source":3040,"_file":3041,"_stem":3042,"_extension":3039},"/blog/dev-diary-phishing-prevention-behind-the-scenes","blog",{"id":1280,"publishedAt":1281},"1RT7MmC7mJH5H3iWmzgqRI","2024-05-15T09:40:19.153Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"Behind the scenes view of designing and developing our latest feature, SSO password protection, preventing SSO password use outside of the official login page to stop credential phishing for high-risk accounts. ","text","paragraph","document","Dev diary: Phishing prevention behind the scenes","Behind the scenes of our SSO password protection feature","Behind the scenes of our approach to designing and developing our latest feature, SSO password protection.","2024-05-13T00:00:00.000Z","dev-diary-phishing-prevention-behind-the-scenes",{"items":1302},[1303,1307],{"sys":1304,"name":1306},{"id":1305},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"sys":1308,"name":1310},{"id":1309},"3pjES4THCIfSAwhGdNwBcy","Identity security",{"items":1312},[1313,1895,2096],{"__typename":1314,"sys":1315,"content":1317,"title":1875,"synopsis":1876,"hashTags":118,"publishedDate":1877,"slug":1878,"tagsCollection":1879,"authorsCollection":1887},"BlogPosts",{"id":1316},"4UtRVoFElDduWJBx9Sa4Cw",{"json":1318},{"data":1319,"content":1320,"nodeType":1295},{},[1321,1327,1336,1343,1350,1367,1402,1409,1417,1423,1439,1447,1453,1461,1468,1475,1482,1490,1497,1517,1533,1539,1546,1565,1587,1594,1619,1626,1649,1665,1672,1693,1700,1776,1783,1799,1806,1813,1820,1827,1843,1849,1856],{"data":1322,"content":1323,"nodeType":1294},{},[1324],{"data":1325,"marks":1326,"value":37,"nodeType":1293},{},[],{"data":1328,"content":1334,"nodeType":1335},{"target":1329},{"sys":1330},{"id":1331,"type":1332,"linkType":1333},"5cseu1Cre2FrSQrIhSFxQw","Link","Entry",[],"embedded-entry-block",{"data":1337,"content":1338,"nodeType":1294},{},[1339],{"data":1340,"marks":1341,"value":1342,"nodeType":1293},{},[],"Reliably detecting phishing sites is like trying to hit a moving target, as malicious websites and domains emerge, get taken down, and re-emerge continuously across the sprawl of the web.",{"data":1344,"content":1345,"nodeType":1294},{},[1346],{"data":1347,"marks":1348,"value":1349,"nodeType":1293},{},[],"Existing phishing prevention solutions have tried to solve the problem by protecting the inbox, a common (but not the only) attack vector, or by chasing lists of known-bad domains.",{"data":1351,"content":1352,"nodeType":1294},{},[1353,1357,1363],{"data":1354,"marks":1355,"value":1356,"nodeType":1293},{},[],"But these approaches have ",{"data":1358,"marks":1359,"value":1362,"nodeType":1293},{},[1360],{"type":1361},"bold","two major shortcomings",{"data":1364,"marks":1365,"value":1366,"nodeType":1293},{},[],":",{"data":1368,"content":1369,"nodeType":1401},{},[1370,1386],{"data":1371,"content":1372,"nodeType":1385},{},[1373],{"data":1374,"content":1375,"nodeType":1294},{},[1376,1381],{"data":1377,"marks":1378,"value":1380,"nodeType":1293},{},[1379],{"type":1361},"Lack of coverage:",{"data":1382,"marks":1383,"value":1384,"nodeType":1293},{},[]," Email-based phishing prevention tools can catch general spray-and-pray email phishing campaigns, but it only takes a small amount of tailoring to fly under their radar. The use of LLM tools to tailor phishing emails for their intended victims already makes this possible at scale. Email-based tools also fail to cover phishing attacks beyond the inbox, such as Slack and Teams phishing.","list-item",{"data":1387,"content":1388,"nodeType":1385},{},[1389],{"data":1390,"content":1391,"nodeType":1294},{},[1392,1397],{"data":1393,"marks":1394,"value":1396,"nodeType":1293},{},[1395],{"type":1361},"Expired intel:",{"data":1398,"marks":1399,"value":1400,"nodeType":1293},{},[]," Tools that rely on known-bad domains always have an incomplete picture because a domain must be reported as malicious in order to get added to a blocklist. Meanwhile, attackers can spin up new sites or host phishing pages on existing sites by exploiting vulnerabilities in them, bypassing rules around preventing visits to newly registered domains. ","unordered-list",{"data":1403,"content":1404,"nodeType":1294},{},[1405],{"data":1406,"marks":1407,"value":1408,"nodeType":1293},{},[],"Using Push’s unique vantage point in the browser, we set out to attack this problem from a new angle. ",{"data":1410,"content":1411,"nodeType":1294},{},[1412],{"data":1413,"marks":1414,"value":1416,"nodeType":1293},{},[1415],{"type":1361},"Instead of trying to detect phishing websites and domains that constantly change, we can now detect (and block!) phishing attempts based on directly observing user behavior in the browser.",{"data":1418,"content":1422,"nodeType":1335},{"target":1419},{"sys":1420},{"id":1421,"type":1332,"linkType":1333},"2vFMyWtMlxzTqqtvCPmlGW",[],{"data":1424,"content":1425,"nodeType":1294},{},[1426,1430,1435],{"data":1427,"marks":1428,"value":1429,"nodeType":1293},{},[],"Our latest feature, ",{"data":1431,"marks":1432,"value":1434,"nodeType":1293},{},[1433],{"type":1361},"SSO password protection",{"data":1436,"marks":1437,"value":1438,"nodeType":1293},{},[],", detects and blocks when a user enters their identity provider password on a webpage that does not belong to the IdP (e.g Okta, Google Workspace, Microsoft 365, etc.).",{"data":1440,"content":1441,"nodeType":1294},{},[1442],{"data":1443,"marks":1444,"value":1446,"nodeType":1293},{},[1445],{"type":1361},"This means that even if that employee was the first person to get phished using a new attacker site, Push still detects it and blocks it.",{"data":1448,"content":1452,"nodeType":1335},{"target":1449},{"sys":1450},{"id":1451,"type":1332,"linkType":1333},"4eCSQGec7mozFLDucNMO7m",[],{"data":1454,"content":1455,"nodeType":1460},{},[1456],{"data":1457,"marks":1458,"value":1459,"nodeType":1293},{},[],"How does it work?","heading-2",{"data":1462,"content":1463,"nodeType":1294},{},[1464],{"data":1465,"marks":1466,"value":1467,"nodeType":1293},{},[],"Instead of detecting a phishing page based on a known-bad signature, the Push browser agent dynamically inspects user behavior and the attributes of the page itself.",{"data":1469,"content":1470,"nodeType":1294},{},[1471],{"data":1472,"marks":1473,"value":1474,"nodeType":1293},{},[],"The browser agent works by observing all logins and generating a salted partial hash of the user’s password, known as a fingerprint. This fingerprint is then stored locally to allow Push to perform comparisons. ",{"data":1476,"content":1477,"nodeType":1294},{},[1478],{"data":1479,"marks":1480,"value":1481,"nodeType":1293},{},[],"To detect potential phishing attacks, the browser agent compares the observed password fingerprint to known fingerprints for identity provider passwords that already exist in local storage. ",{"data":1483,"content":1484,"nodeType":1294},{},[1485],{"data":1486,"marks":1487,"value":1489,"nodeType":1293},{},[1488],{"type":1361},"If an employee enters a known IdP password on a webpage that Push doesn’t recognize, Push blocks it. ",{"data":1491,"content":1492,"nodeType":1294},{},[1493],{"data":1494,"marks":1495,"value":1496,"nodeType":1293},{},[],"Once you’ve discovered a malicious site, use Push’s companion feature, URL blocking, to add the domain to a blocklist and prevent your other end-users from visiting the site. ",{"data":1498,"content":1499,"nodeType":1294},{},[1500,1504,1513],{"data":1501,"marks":1502,"value":1503,"nodeType":1293},{},[],"You can programmatically manage URL blocking as part of responding to an attempted phishing incident by using the ",{"data":1505,"content":1507,"nodeType":1512},{"uri":1506},"https://pushsecurity.redoc.ly/rest-v1/",[1508],{"data":1509,"marks":1510,"value":1511,"nodeType":1293},{},[],"Push REST API","hyperlink",{"data":1514,"marks":1515,"value":1516,"nodeType":1293},{},[]," to automatically add URLs to the blocklist or to sync with other threat intelligence sources of known-bad sites.",{"data":1518,"content":1519,"nodeType":1294},{},[1520,1524,1529],{"data":1521,"marks":1522,"value":1523,"nodeType":1293},{},[],"Push administrators can configure SSO password protection in Monitor, Warn, or Block modes to first observe how often employees are re-using IdP credentials on other sites, eliminating any false positives by adding them to an ignore list, and then turning on Warn or Block to ",{"data":1525,"marks":1526,"value":1528,"nodeType":1293},{},[1527],{"type":1361},"show a custom message",{"data":1530,"marks":1531,"value":1532,"nodeType":1293},{},[]," that either provides a speedbump for users (“Are you sure this isn’t a phishing site?”) or prevents them from logging in altogether.",{"data":1534,"content":1538,"nodeType":1335},{"target":1535},{"sys":1536},{"id":1537,"type":1332,"linkType":1333},"74l82HIeaumFX4u9AMjj79",[],{"data":1540,"content":1541,"nodeType":1294},{},[1542],{"data":1543,"marks":1544,"value":1545,"nodeType":1293},{},[],"Supported identity providers include Okta, Microsoft 365, Google Workspace, JumpCloud, Duo and Ping Identity. ",{"data":1547,"content":1548,"nodeType":1294},{},[1549,1553,1561],{"data":1550,"marks":1551,"value":1552,"nodeType":1293},{},[],"You can also ",{"data":1554,"content":1556,"nodeType":1512},{"uri":1555},"https://pushsecurity.redoc.ly/webhooks-v1/",[1557],{"data":1558,"marks":1559,"value":1560,"nodeType":1293},{},[],"get alerted",{"data":1562,"marks":1563,"value":1564,"nodeType":1293},{},[]," via webhook when Push detects a suspected phishing event.",{"data":1566,"content":1567,"nodeType":1294},{},[1568,1572,1583],{"data":1569,"marks":1570,"value":1571,"nodeType":1293},{},[],"Learn more about how it works and the end-user experience in our ",{"data":1573,"content":1577,"nodeType":1582},{"target":1574},{"sys":1575},{"id":1576,"type":1332,"linkType":1333},"6FYHbkcRUrtznPo7RarRsz",[1578],{"data":1579,"marks":1580,"value":1581,"nodeType":1293},{},[],"help article","entry-hyperlink",{"data":1584,"marks":1585,"value":1586,"nodeType":1293},{},[],".",{"data":1588,"content":1589,"nodeType":1460},{},[1590],{"data":1591,"marks":1592,"value":1593,"nodeType":1293},{},[],"But what about … ",{"data":1595,"content":1596,"nodeType":1294},{},[1597,1601,1606,1610,1615],{"data":1598,"marks":1599,"value":1600,"nodeType":1293},{},[],"Yes, we believe ",{"data":1602,"marks":1603,"value":1605,"nodeType":1293},{},[1604],{"type":1361},"MFA",{"data":1607,"marks":1608,"value":1609,"nodeType":1293},{},[]," and ",{"data":1611,"marks":1612,"value":1614,"nodeType":1293},{},[1613],{"type":1361},"conditional access policies",{"data":1616,"marks":1617,"value":1618,"nodeType":1293},{},[]," are important parts of a defense-in-depth strategy against phishing — in addition to protecting IdP credentials directly in the browser.",{"data":1620,"content":1621,"nodeType":1294},{},[1622],{"data":1623,"marks":1624,"value":1625,"nodeType":1293},{},[],"Here’s why MFA and conditional access policies aren’t enough:",{"data":1627,"content":1628,"nodeType":1401},{},[1629,1639],{"data":1630,"content":1631,"nodeType":1385},{},[1632],{"data":1633,"content":1634,"nodeType":1294},{},[1635],{"data":1636,"marks":1637,"value":1638,"nodeType":1293},{},[],"MFA is not infallible and not all MFA methods are created equal. Methods such as SMS, TOTP, or even push notifications are phishable. Even if your employees are also using more phishing-resistant forms of MFA, such as WebAuthn, it’s common for accounts to use multiple MFA methods and an attacker need only target the weakest one. An attacker in possession of an SSO password also has leverage to socially engineer an authentication reset, including an MFA reset.",{"data":1640,"content":1641,"nodeType":1385},{},[1642],{"data":1643,"content":1644,"nodeType":1294},{},[1645],{"data":1646,"marks":1647,"value":1648,"nodeType":1293},{},[],"It’s worryingly common for us to deploy Push and find that a customer’s conditional access policies aren’t implemented as they are designed to be. The most common reason is that admins have to create so many exceptions to allow for real-world situations that policies become complex and full of gaps.",{"data":1650,"content":1651,"nodeType":1294},{},[1652,1656,1661],{"data":1653,"marks":1654,"value":1655,"nodeType":1293},{},[],"And of course, protecting ",{"data":1657,"marks":1658,"value":1660,"nodeType":1293},{},[1659],{"type":312},"all",{"data":1662,"marks":1663,"value":1664,"nodeType":1293},{},[]," your organization’s passwords is important. In fact, we’re currently developing this feature further so it will do just that! We focus here on IdP passwords because they’re a higher-value target for attackers — and the frequent target of recent real-world attacks.",{"data":1666,"content":1667,"nodeType":1460},{},[1668],{"data":1669,"marks":1670,"value":1671,"nodeType":1293},{},[],"Why IdP accounts?",{"data":1673,"content":1674,"nodeType":1294},{},[1675,1679,1689],{"data":1676,"marks":1677,"value":1678,"nodeType":1293},{},[],"IdP accounts have been targeted in several high-profile recent attacks, like those carried out by Scattered Spider against MGM resorts and in the Retool breach. You can read more about them in our ",{"data":1680,"content":1684,"nodeType":1582},{"target":1681},{"sys":1682},{"id":1683,"type":1332,"linkType":1333},"6XIts2UEnrsJDki8gKDXyI",[1685],{"data":1686,"marks":1687,"value":1688,"nodeType":1293},{},[],"identity attacks in the wild",{"data":1690,"marks":1691,"value":1692,"nodeType":1293},{},[]," blog article.",{"data":1694,"content":1695,"nodeType":1294},{},[1696],{"data":1697,"marks":1698,"value":1699,"nodeType":1293},{},[],"In the cloud-first world, a compromised IdP account is like a compromised user workstation. It gives an attacker a solid initial foothold from which they can operate:",{"data":1701,"content":1702,"nodeType":1401},{},[1703,1725],{"data":1704,"content":1705,"nodeType":1385},{},[1706],{"data":1707,"content":1708,"nodeType":1294},{},[1709,1713,1722],{"data":1710,"marks":1711,"value":1712,"nodeType":1293},{},[],"They instantly get access to all the apps the compromised user was accessing with SSO. It’s easy to move laterally to sensitive apps or to apps where the user has admin privileges. This obviously enables an attacker to directly exfiltrate data from these apps or to use them maliciously, as in the ",{"data":1714,"content":1717,"nodeType":1582},{"target":1715},{"sys":1716},{"id":1683,"type":1332,"linkType":1333},[1718],{"data":1719,"marks":1720,"value":1721,"nodeType":1293},{},[],"Mandiant and SEC Twitter/X breaches",{"data":1723,"marks":1724,"value":1586,"nodeType":1293},{},[],{"data":1726,"content":1727,"nodeType":1385},{},[1728],{"data":1729,"content":1730,"nodeType":1294},{},[1731,1735,1745,1749,1759,1762,1772],{"data":1732,"marks":1733,"value":1734,"nodeType":1293},{},[],"Assuming an attacker hasn’t initially gotten access to a privileged IdP account, they can escalate their privileges by performing ",{"data":1736,"content":1740,"nodeType":1582},{"target":1737},{"sys":1738},{"id":1739,"type":1332,"linkType":1333},"3F96pyn4qqkbVctSOH69vm",[1741],{"data":1742,"marks":1743,"value":1744,"nodeType":1293},{},[],"SAMLjacking",{"data":1746,"marks":1747,"value":1748,"nodeType":1293},{},[]," on any low-risk app where the user is an admin or by using apps like ",{"data":1750,"content":1754,"nodeType":1582},{"target":1751},{"sys":1752},{"id":1753,"type":1332,"linkType":1333},"2rjLrCo6KWwLicfpV2qTOZ",[1755],{"data":1756,"marks":1757,"value":1758,"nodeType":1293},{},[],"Slack",{"data":1760,"marks":1761,"value":1609,"nodeType":1293},{},[],{"data":1763,"content":1767,"nodeType":1582},{"target":1764},{"sys":1765},{"id":1766,"type":1332,"linkType":1333},"2cv7Yq1DQpm1Mho7fKDs44",[1768],{"data":1769,"marks":1770,"value":1771,"nodeType":1293},{},[],"Teams",{"data":1773,"marks":1774,"value":1775,"nodeType":1293},{},[]," to phish higher-privilege users.",{"data":1777,"content":1778,"nodeType":1460},{},[1779],{"data":1780,"marks":1781,"value":1782,"nodeType":1293},{},[],"It also protects against credential stuffing attacks",{"data":1784,"content":1785,"nodeType":1294},{},[1786,1790,1795],{"data":1787,"marks":1788,"value":1789,"nodeType":1293},{},[],"As well as protecting your users against phishing, the SSO password protection feature can prevent credential stuffing attacks succeeding against your IdP instance. How? By stopping your employees from reusing their SSO password on other apps.  \nPush monitors the identities of thousands of employees. Around ",{"data":1791,"marks":1792,"value":1794,"nodeType":1293},{},[1793],{"type":1361},"1 in 3 of them reuse passwords",{"data":1796,"marks":1797,"value":1798,"nodeType":1293},{},[]," across multiple accounts. ",{"data":1800,"content":1801,"nodeType":1294},{},[1802],{"data":1803,"marks":1804,"value":1805,"nodeType":1293},{},[],"Employees know that their SSO password is one they’ll need to use a lot, and so they tend to choose one they know they will remember, because they are already using it successfully. That’s why we see higher levels of password reuse on IdP apps in particular.",{"data":1807,"content":1808,"nodeType":1294},{},[1809],{"data":1810,"marks":1811,"value":1812,"nodeType":1293},{},[],"Every time an SSO password is reused on another app, its exposure increases, along with the likelihood of it falling into the wrong hands. This can happen when another app experiences a breach and credentials are stolen. Or alternatively, when an attacker steals credentials in a phishing attack aimed at users of other apps where the password is being reused.",{"data":1814,"content":1815,"nodeType":1294},{},[1816],{"data":1817,"marks":1818,"value":1819,"nodeType":1293},{},[],"Armed with stolen credentials, an attacker can spray them across common cloud apps and see what additional accounts they can gain access to. IdP apps will be high on the list of cloud apps attackers will try because they provide much more in the way of access than a general SaaS user account.",{"data":1821,"content":1822,"nodeType":1294},{},[1823],{"data":1824,"marks":1825,"value":1826,"nodeType":1293},{},[],"You might be wondering if this feature can also be used to stop other password attacks such as password spraying and brute-forcing attacks. While this specific feature does not, Push’s other features do. ",{"data":1828,"content":1829,"nodeType":1294},{},[1830,1834,1839],{"data":1831,"marks":1832,"value":1833,"nodeType":1293},{},[],"These include ",{"data":1835,"marks":1836,"value":1838,"nodeType":1293},{},[1837],{"type":1361},"in-browser guidance",{"data":1840,"marks":1841,"value":1842,"nodeType":1293},{},[]," that stops users from creating and using easily guessable passwords as well as Push’s ability to detect when employees are not registered for MFA (and whether the methods they are using are phishing-resistant or not).",{"data":1844,"content":1848,"nodeType":1335},{"target":1845},{"sys":1846},{"id":1847,"type":1332,"linkType":1333},"uy6utpRA35spZFM7Da4Nt",[],{"data":1850,"content":1851,"nodeType":1460},{},[1852],{"data":1853,"marks":1854,"value":1855,"nodeType":1293},{},[],"Find out more",{"data":1857,"content":1858,"nodeType":1294},{},[1859,1863,1871],{"data":1860,"marks":1861,"value":1862,"nodeType":1293},{},[],"To see Push in action, ",{"data":1864,"content":1866,"nodeType":1512},{"uri":1865},"https://pushsecurity.com/demo/",[1867],{"data":1868,"marks":1869,"value":1870,"nodeType":1293},{},[],"book a demo",{"data":1872,"marks":1873,"value":1874,"nodeType":1293},{},[],". We’ll be happy to show you this feature, along with how we discover all the apps your employees are using and how we detect vulnerable identities.","Introducing SSO Password Protection: Stop employees’ IdP credentials being exposed or phished","Use the Push browser agent’s unique vantage point to protect SSO credentials by blocking employees from entering their password into any other site. ","2024-04-29T00:00:00.000Z","introducing-sso-password-protection",{"items":1880},[1881,1885],{"sys":1882,"name":1884},{"id":1883},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"sys":1886,"name":1306},{"id":1305},{"items":1888},[1889],{"fullName":1890,"firstName":1891,"jobTitle":1892,"profilePicture":1893},"Alex Henshall","Alex","Product Team",{"url":1894},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg",{"__typename":1314,"sys":1896,"content":1898,"title":2080,"synopsis":2081,"hashTags":118,"publishedDate":2082,"slug":2083,"tagsCollection":2084,"authorsCollection":2088},{"id":1897},"3xoO1mzZMMQO8Q2vHuYLFt",{"json":1899},{"data":1900,"content":1901,"nodeType":1295},{},[1902,1909,1942,1948,1964,1970,1987,1994,2010,2016,2033,2040,2056,2062],{"data":1903,"content":1904,"nodeType":1460},{},[1905],{"data":1906,"marks":1907,"value":1908,"nodeType":1293},{},[],"Here's what's new on the Push platform this month:",{"data":1910,"content":1911,"nodeType":1401},{},[1912,1922,1932],{"data":1913,"content":1914,"nodeType":1385},{},[1915],{"data":1916,"content":1917,"nodeType":1294},{},[1918],{"data":1919,"marks":1920,"value":1921,"nodeType":1293},{},[],"Faster insights with the Push dashboard",{"data":1923,"content":1924,"nodeType":1385},{},[1925],{"data":1926,"content":1927,"nodeType":1294},{},[1928],{"data":1929,"marks":1930,"value":1931,"nodeType":1293},{},[],"Integrate with Okta",{"data":1933,"content":1934,"nodeType":1385},{},[1935],{"data":1936,"content":1937,"nodeType":1294},{},[1938],{"data":1939,"marks":1940,"value":1941,"nodeType":1293},{},[],"App banner acknowledge mode",{"data":1943,"content":1944,"nodeType":1460},{},[1945],{"data":1946,"marks":1947,"value":1921,"nodeType":1293},{},[],{"data":1949,"content":1950,"nodeType":1294},{},[1951,1955,1960],{"data":1952,"marks":1953,"value":1954,"nodeType":1293},{},[],"Get an overview of the ",{"data":1956,"marks":1957,"value":1959,"nodeType":1293},{},[1958],{"type":1361},"actionable insights ",{"data":1961,"marks":1962,"value":1963,"nodeType":1293},{},[],"from across your ecosystem of accounts, apps, and identities using the Push dashboard, now available in the Push admin console. Pinpoint vulnerable identities at risk of account takeover, see SSO trends across all accounts, and get a snapshot of your identity inventory.",{"data":1965,"content":1969,"nodeType":1335},{"target":1966},{"sys":1967},{"id":1968,"type":1332,"linkType":1333},"1AbJEm5rHOxwYer519AT9C",[],{"data":1971,"content":1972,"nodeType":1294},{},[1973,1976,1984],{"data":1974,"marks":1975,"value":37,"nodeType":1293},{},[],{"data":1977,"content":1979,"nodeType":1512},{"uri":1978},"/help/audience/administrators/docs/view-saas-apps-and-employee-activity/#dashboard",[1980],{"data":1981,"marks":1982,"value":1983,"nodeType":1293},{},[],"Learn more",{"data":1985,"marks":1986,"value":37,"nodeType":1293},{},[],{"data":1988,"content":1989,"nodeType":1460},{},[1990],{"data":1991,"marks":1992,"value":1993,"nodeType":1293},{},[],"Integrate with Okta to enrich your Push data",{"data":1995,"content":1996,"nodeType":1294},{},[1997,2001,2006],{"data":1998,"marks":1999,"value":2000,"nodeType":1293},{},[],"You can now ",{"data":2002,"marks":2003,"value":2005,"nodeType":1293},{},[2004],{"type":1361},"integrate with Okta",{"data":2007,"marks":2008,"value":2009,"nodeType":1293},{},[]," to sync employee records and pull in a list of your SSO apps to the Push platform, providing a valuable source of truth for data on your workforce accounts and approved apps. By integrating with Okta, you will also be able to capture additional login methods used by employees, such as Okta SWA.",{"data":2011,"content":2015,"nodeType":1335},{"target":2012},{"sys":2013},{"id":2014,"type":1332,"linkType":1333},"2p7QbcSx8G2R8DVpCEZWYk",[],{"data":2017,"content":2018,"nodeType":1294},{},[2019,2022,2030],{"data":2020,"marks":2021,"value":37,"nodeType":1293},{},[],{"data":2023,"content":2025,"nodeType":1512},{"uri":2024},"/help/audience/administrators/docs/add-employees/#integrate-with-okta",[2026],{"data":2027,"marks":2028,"value":2029,"nodeType":1293},{},[],"How to integrate",{"data":2031,"marks":2032,"value":37,"nodeType":1293},{},[],{"data":2034,"content":2035,"nodeType":1460},{},[2036],{"data":2037,"marks":2038,"value":2039,"nodeType":1293},{},[],"New ‘Acknowledge’ mode for app banners",{"data":2041,"content":2042,"nodeType":1294},{},[2043,2047,2052],{"data":2044,"marks":2045,"value":2046,"nodeType":1293},{},[],"You can now configure app banners to show a larger central message and also ",{"data":2048,"marks":2049,"value":2051,"nodeType":1293},{},[2050],{"type":1361},"require that an end-user acknowledge the message",{"data":2053,"marks":2054,"value":2055,"nodeType":1293},{},[]," before proceeding to use an app, providing stronger in-browser guidance. You may wish to use this mode for GenAI apps or to strongly steer employees away from unapproved file-sharing apps, for example.",{"data":2057,"content":2061,"nodeType":1335},{"target":2058},{"sys":2059},{"id":2060,"type":1332,"linkType":1333},"7chqbwof9wgjdc7642zUbf",[],{"data":2063,"content":2064,"nodeType":1294},{},[2065,2068,2077],{"data":2066,"marks":2067,"value":37,"nodeType":1293},{},[],{"data":2069,"content":2073,"nodeType":1582},{"target":2070},{"sys":2071},{"id":2072,"type":1332,"linkType":1333},"2ZpKnuljaUH0jzVaae4SMN",[2074],{"data":2075,"marks":2076,"value":1983,"nodeType":1293},{},[],{"data":2078,"marks":2079,"value":37,"nodeType":1293},{},[],"Product release: April 2024","Here’s what’s new on the Push platform for April 2024.","2024-04-17T00:00:00.000Z","product-release-april-2024",{"items":2085},[2086],{"sys":2087,"name":1306},{"id":1305},{"items":2089},[2090],{"fullName":2091,"firstName":2092,"jobTitle":2093,"profilePicture":2094},"Andy Waugh","Andy","VP Product",{"url":2095},"https://images.ctfassets.net/y1cdw1ablpvd/3Rf76rJn6S9inMb4dUnAIJ/0a787f8141d05b95300e2fe77c4493fa/DSC_6868.jpg",{"__typename":1314,"sys":2097,"content":2099,"title":2544,"synopsis":2545,"hashTags":118,"publishedDate":2546,"slug":2547,"tagsCollection":2548,"authorsCollection":2556},{"id":2098},"1uhswJr9ITxnhjIJur8UKL",{"json":2100},{"nodeType":1295,"data":2101,"content":2102},{},[2103,2110,2117,2124,2154,2161,2167,2183,2204,2236,2242,2249,2256,2263,2270,2277,2283,2290,2297,2316,2323,2424,2431,2438,2445,2471,2492,2516,2537],{"nodeType":1294,"data":2104,"content":2105},{},[2106],{"nodeType":1293,"value":2107,"marks":2108,"data":2109},"As we look back at a year of building on the Product team at Push, three big themes stand out:",[],{},{"nodeType":1460,"data":2111,"content":2112},{},[2113],{"nodeType":1293,"value":2114,"marks":2115,"data":2116},"Cloud identities are increasingly under attack",[],{},{"nodeType":1294,"data":2118,"content":2119},{},[2120],{"nodeType":1293,"value":2121,"marks":2122,"data":2123},"A big focus for us this year was to deepen our understanding of the landscape of adversarial techniques in the world of emerging SaaS-first attacks that don’t touch the endpoint or network, and it’s clear they are becoming both more prevalent and more advanced.",[],{},{"nodeType":1294,"data":2125,"content":2126},{},[2127,2130,2138,2142,2150],{"nodeType":1293,"value":37,"marks":2128,"data":2129},[],{},{"nodeType":1512,"data":2131,"content":2133},{"uri":2132},"https://pushsecurity.com/blog/what-is-credential-stuffing/",[2134],{"nodeType":1293,"value":2135,"marks":2136,"data":2137},"Credential stuffing",[],{},{"nodeType":1293,"value":2139,"marks":2140,"data":2141}," is the internet’s most prolific attack vector today. In December 2023, ",[],{},{"nodeType":1512,"data":2143,"content":2145},{"uri":2144},"https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report-2023-state-of-cybercrime",[2146],{"nodeType":1293,"value":2147,"marks":2148,"data":2149},"Microsoft reported",[],{},{"nodeType":1293,"value":2151,"marks":2152,"data":2153}," that attempted password attacks against Entra have increased to an average of 4,000 per second. This is a tenfold increase from the same time period in 2022.",[],{},{"nodeType":1294,"data":2155,"content":2156},{},[2157],{"nodeType":1293,"value":2158,"marks":2159,"data":2160},"To help address this, our app helps you quickly determine which accounts are at highest risk of attack by highlighting which use passwords (as opposed to SSO), have a weak or leaked password, and don’t have MFA. We built a dashboard that brings all this together, allowing you to quickly zero in on at-risk accounts — you can even filter it by the apps that house sensitive data to have a focused starting place.",[],{},{"nodeType":1335,"data":2162,"content":2166},{"target":2163},{"sys":2164},{"id":2165,"type":1332,"linkType":1333},"3tuUzr0DOhxUs6ytxCHUcg",[],{"nodeType":1294,"data":2168,"content":2169},{},[2170,2173,2180],{"nodeType":1293,"value":37,"marks":2171,"data":2172},[],{},{"nodeType":1512,"data":2174,"content":2175},{"uri":1978},[2176],{"nodeType":1293,"value":2177,"marks":2178,"data":2179},"Explore the dashboard >>",[],{},{"nodeType":1293,"value":37,"marks":2181,"data":2182},[],{},{"nodeType":1294,"data":2184,"content":2185},{},[2186,2190,2200],{"nodeType":1293,"value":2187,"marks":2188,"data":2189},"We also spent the last year going deep into emerging methods that are powerful but lesser-known, publishing our ",[],{},{"nodeType":1582,"data":2191,"content":2195},{"target":2192},{"sys":2193},{"id":2194,"type":1332,"linkType":1333},"6VZQJzQ2FNetGNMEjiuXB2",[2196],{"nodeType":1293,"value":2197,"marks":2198,"data":2199},"SaaS attack matrix",[],{},{"nodeType":1293,"value":2201,"marks":2202,"data":2203}," project on Github.",[],{},{"nodeType":1294,"data":2205,"content":2206},{},[2207,2211,2220,2224,2232],{"nodeType":1293,"value":2208,"marks":2209,"data":2210},"Just a few months after publishing the project, we’ve seen increasingly ",[],{},{"nodeType":1582,"data":2212,"content":2215},{"target":2213},{"sys":2214},{"id":1683,"type":1332,"linkType":1333},[2216],{"nodeType":1293,"value":2217,"marks":2218,"data":2219},"regular headlines",[],{},{"nodeType":1293,"value":2221,"marks":2222,"data":2223}," from organizations battling cloud-native attacks that target insecure identities. It’s abundantly clear that we are seeing ",[],{},{"nodeType":1512,"data":2225,"content":2227},{"uri":2226},"https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access",[2228],{"nodeType":1293,"value":2229,"marks":2230,"data":2231},"real-world attacks",[],{},{"nodeType":1293,"value":2233,"marks":2234,"data":2235}," shifting to an organization’s cloud and SaaS attack surface.",[],{},{"nodeType":1335,"data":2237,"content":2241},{"target":2238},{"sys":2239},{"id":2240,"type":1332,"linkType":1333},"79wGG37CY7aBdRrdjO5eQY",[],{"nodeType":1294,"data":2243,"content":2244},{},[2245],{"nodeType":1293,"value":2246,"marks":2247,"data":2248},"As a product, Push will continue to leverage its privileged position in the browser to do even more to prevent and detect identity-based attacks in the coming months. ",[],{},{"nodeType":1460,"data":2250,"content":2251},{},[2252],{"nodeType":1293,"value":2253,"marks":2254,"data":2255},"Being in the browser is invaluable for securing identities — and we’re going to push the power further",[],{},{"nodeType":1294,"data":2257,"content":2258},{},[2259],{"nodeType":1293,"value":2260,"marks":2261,"data":2262},"Beyond providing the most reliable telemetry for managing identity security posture, being in the browser means that Push can engage directly with end-users to encourage security best practices.",[],{},{"nodeType":1294,"data":2264,"content":2265},{},[2266],{"nodeType":1293,"value":2267,"marks":2268,"data":2269},"Over the last year in conversations with customers, we kept hearing a phrase repeated: “I just need to add some guardrails to help employees.”",[],{},{"nodeType":1294,"data":2271,"content":2272},{},[2273],{"nodeType":1293,"value":2274,"marks":2275,"data":2276},"The idea was born for our most popular feature to date: The app banner.",[],{},{"nodeType":1335,"data":2278,"content":2282},{"target":2279},{"sys":2280},{"id":2281,"type":1332,"linkType":1333},"6tfTX8lzV6soQtoaJp38kS",[],{"nodeType":1294,"data":2284,"content":2285},{},[2286],{"nodeType":1293,"value":2287,"marks":2288,"data":2289},"App banners are custom messages that appear on the signup and login pages of an app and provide quick contextual guidance to employees. They’re fully customizable to match an organization’s policies and voice – even their preferred language (we’ve got at least 1 customer using bilingual app banners). ",[],{},{"nodeType":1294,"data":2291,"content":2292},{},[2293],{"nodeType":1293,"value":2294,"marks":2295,"data":2296},"We’ll be continuing to iterate on this feature, with more ideas in store.",[],{},{"nodeType":1294,"data":2298,"content":2299},{},[2300,2303,2313],{"nodeType":1293,"value":37,"marks":2301,"data":2302},[],{},{"nodeType":1582,"data":2304,"content":2308},{"target":2305},{"sys":2306},{"id":2307,"type":1332,"linkType":1333},"3m48a0kFoN8gh0IZQBup5U",[2309],{"nodeType":1293,"value":2310,"marks":2311,"data":2312},"More about app banners >>",[],{},{"nodeType":1293,"value":37,"marks":2314,"data":2315},[],{},{"nodeType":1294,"data":2317,"content":2318},{},[2319],{"nodeType":1293,"value":2320,"marks":2321,"data":2322},"Other features we shipped this year that rely on Push’s position in the browser:",[],{},{"nodeType":1401,"data":2324,"content":2325},{},[2326,2389],{"nodeType":1385,"data":2327,"content":2328},{},[2329,2336],{"nodeType":1294,"data":2330,"content":2331},{},[2332],{"nodeType":1293,"value":2333,"marks":2334,"data":2335},"Assuring password quality:",[],{},{"nodeType":1401,"data":2337,"content":2338},{},[2339],{"nodeType":1385,"data":2340,"content":2341},{},[2342,2363],{"nodeType":1294,"data":2343,"content":2344},{},[2345,2349,2359],{"nodeType":1293,"value":2346,"marks":2347,"data":2348},"Ability to ",[],{},{"nodeType":1582,"data":2350,"content":2354},{"target":2351},{"sys":2352},{"id":2353,"type":1332,"linkType":1333},"5d9a04bd-bde1-4012-9b91-175e6c90d75c",[2355],{"nodeType":1293,"value":2356,"marks":2357,"data":2358},"detect leaked passwords",[],{},{"nodeType":1293,"value":2360,"marks":2361,"data":2362}," by comparing a k-anonymized salted hash of a password and the corresponding username to the Have I Been Pwned data set.",[],{},{"nodeType":1401,"data":2364,"content":2365},{},[2366],{"nodeType":1385,"data":2367,"content":2368},{},[2369],{"nodeType":1294,"data":2370,"content":2371},{},[2372,2375,2385],{"nodeType":1293,"value":2346,"marks":2373,"data":2374},[],{},{"nodeType":1582,"data":2376,"content":2380},{"target":2377},{"sys":2378},{"id":2379,"type":1332,"linkType":1333},"cc8f7924-0248-4267-b974-2d6c8559955f",[2381],{"nodeType":1293,"value":2382,"marks":2383,"data":2384},"flag passwords that use restricted terms",[],{},{"nodeType":1293,"value":2386,"marks":2387,"data":2388},", such as the company name. Administrators can customize this word list.",[],{},{"nodeType":1385,"data":2390,"content":2391},{},[2392,2399],{"nodeType":1294,"data":2393,"content":2394},{},[2395],{"nodeType":1293,"value":2396,"marks":2397,"data":2398},"Guiding end-users at the point of need:",[],{},{"nodeType":1401,"data":2400,"content":2401},{},[2402],{"nodeType":1385,"data":2403,"content":2404},{},[2405],{"nodeType":1294,"data":2406,"content":2407},{},[2408,2412,2420],{"nodeType":1293,"value":2409,"marks":2410,"data":2411},"Ability to set ",[],{},{"nodeType":1512,"data":2413,"content":2415},{"uri":2414},"/blog/product-release-march-2023/#id-catch-weak-passwords-before-they-happen-with-new-push-labs-feature",[2416],{"nodeType":1293,"value":2417,"marks":2418,"data":2419},"inline browser prompts",[],{},{"nodeType":1293,"value":2421,"marks":2422,"data":2423}," that alert end-users when they’re signing up or logging in to an app with a weak or reused password and provide them with guidance on fixing the issue.",[],{},{"nodeType":1460,"data":2425,"content":2426},{},[2427],{"nodeType":1293,"value":2428,"marks":2429,"data":2430},"Organizations don’t need more ‘data’ — they need context and control",[],{},{"nodeType":1294,"data":2432,"content":2433},{},[2434],{"nodeType":1293,"value":2435,"marks":2436,"data":2437},"A big puzzle we set out to solve this year was how to give customers the context they needed to identify risks and enact decisions about their cloud identities and SaaS estate, without contributing to the noise so commonly associated with legacy tools.",[],{},{"nodeType":1294,"data":2439,"content":2440},{},[2441],{"nodeType":1293,"value":2442,"marks":2443,"data":2444},"Here’s how we are approaching the solution and what we built this year.",[],{},{"nodeType":1294,"data":2446,"content":2447},{},[2448,2453,2457,2467],{"nodeType":1293,"value":2449,"marks":2450,"data":2452},"Focus on showing core work apps — but make it possible to see everything:",[2451],{"type":1361},{},{"nodeType":1293,"value":2454,"marks":2455,"data":2456}," We recently added the ability to see all apps that employees access with their company credentials so customers can get a fuller picture of their identity and app sprawl. This improves the coverage of their app estate. But we also made a conscious choice to segment out those ",[],{},{"nodeType":1582,"data":2458,"content":2462},{"target":2459},{"sys":2460},{"id":2461,"type":1332,"linkType":1333},"WciLKam7PCkbAASOdfiEw",[2463],{"nodeType":1293,"value":2464,"marks":2465,"data":2466},"“other apps”",[],{},{"nodeType":1293,"value":2468,"marks":2469,"data":2470}," (which could be unrelated to work) from the main data tables in the Push platform so the noise is minimal. ",[],{},{"nodeType":1294,"data":2472,"content":2473},{},[2474,2478,2488],{"nodeType":1293,"value":2475,"marks":2476,"data":2477},"Similarly, Push also now supports the ability to ",[],{},{"nodeType":1582,"data":2479,"content":2483},{"target":2480},{"sys":2481},{"id":2482,"type":1332,"linkType":1333},"4Z9ApuJ9JkrdsW9BfMIkQf",[2484],{"nodeType":1293,"value":2485,"marks":2486,"data":2487},"monitor all email domains",[],{},{"nodeType":1293,"value":2489,"marks":2490,"data":2491}," an employee might use to access work apps, filling in the gaps for users who may be accessing company assets with personal accounts.",[],{},{"nodeType":1294,"data":2493,"content":2494},{},[2495,2500,2504,2512],{"nodeType":1293,"value":2496,"marks":2497,"data":2499},"Give important context by surfacing login methods:",[2498],{"type":1361},{},{"nodeType":1293,"value":2501,"marks":2502,"data":2503}," One data point we’ve made a point of enriching in Push this year is ",[],{},{"nodeType":1512,"data":2505,"content":2507},{"uri":2506},"/help/audience/administrators/docs/view-saas-apps-and-employee-activity/#view-app-usage-details",[2508],{"nodeType":1293,"value":2509,"marks":2510,"data":2511},"login methods",[],{},{"nodeType":1293,"value":2513,"marks":2514,"data":2515},". We can now detect if an employee is accessing an app using SAML, OIDC, or local password.",[],{},{"nodeType":1294,"data":2517,"content":2518},{},[2519,2523,2533],{"nodeType":1293,"value":2520,"marks":2521,"data":2522},"First, this information helps security teams understand where users are actually using apps (unlike legacy solutions that only show network traffic). Second, it helps security teams gauge their progress toward ",[],{},{"nodeType":1582,"data":2524,"content":2528},{"target":2525},{"sys":2526},{"id":2527,"type":1332,"linkType":1333},"6rflXTFCRMvmM8JU8ZPSCt",[2529],{"nodeType":1293,"value":2530,"marks":2531,"data":2532},"reducing identity sprawl",[],{},{"nodeType":1293,"value":2534,"marks":2535,"data":2536}," by reducing the use of unmanaged accounts — important context for achieving security goals.",[],{},{"nodeType":1294,"data":2538,"content":2539},{},[2540],{"nodeType":1293,"value":2541,"marks":2542,"data":2543},"We’re now turning our attention to continue providing meaningful controls — building on the success of our employee guardrails, like app banners, as well as new features for detecting attacks, blocking malicious sites, and preventing phishing. Lots more to come!\n\n",[],{},"A year of building: Top features we shipped this year","Some highlights of what we've built over the last year on our mission of stopping identity attacks.","2024-03-28T00:00:00.000Z","a-year-of-building-top-features-we-shipped-this-year",{"items":2549},[2550,2552],{"sys":2551,"name":1306},{"id":1305},{"sys":2553,"name":2555},{"id":2554},"4EtskIWlj3SOH3UHbFR8uG","Company news",{"items":2557},[2558],{"fullName":2091,"firstName":2092,"jobTitle":2093,"profilePicture":2559},{"url":2095},{"url":2561},"https://images.ctfassets.net/y1cdw1ablpvd/3FVY7rJiSiWnLgadi9eFoP/090491956211b73133561a42b92394a3/Three_person_podcast__2_.png",{"items":2563},[2564],{"fullName":2091,"firstName":2092,"jobTitle":2093,"profilePicture":2565},{"url":2095},{"json":2567,"links":3005},{"data":2568,"content":2569,"nodeType":1295},{},[2570,2577,2598,2605,2658,2662,2670,2677,2684,2690,2697,2708,2715,2721,2724,2731,2751,2757,2763,2766,2773,2780,2787,2796,2803,2811,2827,2834,2842,2845,2852,2859,2866,2873,2876,2883,2890,2897,2930,2937,2940,2947,2954,2961,2981,2984,2991,2998],{"data":2571,"content":2572,"nodeType":1294},{},[2573],{"data":2574,"marks":2575,"value":2576,"nodeType":1293},{},[],"We recently released a new feature that prevents employees from reusing their SSO password on other sites. Our goal with this feature is to stop high-risk credentials from being compromised (via phishing or data breach). If you aren’t reusing your Okta password for example, there’s no risk of it being compromised in another breach, and any attempt to dupe a user into using it on a phishing site will fail.",{"data":2578,"content":2579,"nodeType":1294},{},[2580,2584,2594],{"data":2581,"marks":2582,"value":2583,"nodeType":1293},{},[],"To read more about why we developed this feature and how it works, check out this ",{"data":2585,"content":2587,"nodeType":1512},{"uri":2586},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[2588],{"data":2589,"marks":2590,"value":2593,"nodeType":1293},{},[2591],{"type":2592},"underline","earlier blog post",{"data":2595,"marks":2596,"value":2597,"nodeType":1293},{},[],". ",{"data":2599,"content":2600,"nodeType":1294},{},[2601],{"data":2602,"marks":2603,"value":2604,"nodeType":1293},{},[],"While the concept for this feature is simple, we learned that there were several important nuances and design choices to make it both effective and practical:",{"data":2606,"content":2607,"nodeType":1401},{},[2608,2618,2628,2638,2648],{"data":2609,"content":2610,"nodeType":1385},{},[2611],{"data":2612,"content":2613,"nodeType":1294},{},[2614],{"data":2615,"marks":2616,"value":2617,"nodeType":1293},{},[],"Should employees be allowed to reuse their SSO password if they’re doing it intentionally?",{"data":2619,"content":2620,"nodeType":1385},{},[2621],{"data":2622,"content":2623,"nodeType":1294},{},[2624],{"data":2625,"marks":2626,"value":2627,"nodeType":1293},{},[],"If allowed, how do you give employees the right context to help them be sure they’re only reusing in the intended places?",{"data":2629,"content":2630,"nodeType":1385},{},[2631],{"data":2632,"content":2633,"nodeType":1294},{},[2634],{"data":2635,"marks":2636,"value":2637,"nodeType":1293},{},[],"How do you make the content for an employee-facing feature work for all organizations?",{"data":2639,"content":2640,"nodeType":1385},{},[2641],{"data":2642,"content":2643,"nodeType":1294},{},[2644],{"data":2645,"marks":2646,"value":2647,"nodeType":1293},{},[],"How feasible is it to block all password reuse without encouraging the wrong behaviours or workarounds?",{"data":2649,"content":2650,"nodeType":1385},{},[2651],{"data":2652,"content":2653,"nodeType":1294},{},[2654],{"data":2655,"marks":2656,"value":2657,"nodeType":1293},{},[],"Where does threat intelligence fit into a password phishing prevention feature?",{"data":2659,"content":2660,"nodeType":2661},{},[],"hr",{"data":2663,"content":2664,"nodeType":2669},{},[2665],{"data":2666,"marks":2667,"value":2668,"nodeType":1293},{},[],"To warn or to block?","heading-1",{"data":2671,"content":2672,"nodeType":1294},{},[2673],{"data":2674,"marks":2675,"value":2676,"nodeType":1293},{},[],"Fundamentally, the feature works by looking for when an employee enters their password for an app into somewhere that isn’t that app. Simple, right? ",{"data":2678,"content":2679,"nodeType":1294},{},[2680],{"data":2681,"marks":2682,"value":2683,"nodeType":1293},{},[],"The initial plan was that when detected, we’d block the form submission, let the employee know they almost got phished, and ride off into the sunset having saved the day.",{"data":2685,"content":2689,"nodeType":1335},{"target":2686},{"sys":2687},{"id":2688,"type":1332,"linkType":1333},"6M3969P6CfpKVieeyLWVPx",[],{"data":2691,"content":2692,"nodeType":1294},{},[2693],{"data":2694,"marks":2695,"value":2696,"nodeType":1293},{},[],"Unfortunately, despite password managers becoming more popular, some people still use the same password across multiple apps. In fact, our data shows around 1 in 3 people reuse passwords between accounts and we actually see higher levels of password reuse on IdP apps in particular.",{"data":2698,"content":2699,"nodeType":2707},{},[2700],{"data":2701,"content":2702,"nodeType":1294},{},[2703],{"data":2704,"marks":2705,"value":2706,"nodeType":1293},{},[],"1 in 3 people reuse passwords, with higher levels of password reuse on IdP apps","blockquote",{"data":2709,"content":2710,"nodeType":1294},{},[2711],{"data":2712,"marks":2713,"value":2714,"nodeType":1293},{},[],"Since password reuse is so common, this feature would cause friction by forcing employees to change their reused SSO passwords. Some security teams will consider this a good thing, but others might not be so comfortable. To support both cultures, we introduced WARN mode, where employees are stopped from reusing their password, but they’re given the option to continue anyway.",{"data":2716,"content":2720,"nodeType":1335},{"target":2717},{"sys":2718},{"id":2719,"type":1332,"linkType":1333},"Qj5Uqh1a4ErgJ9Bi1rscE",[],{"data":2722,"content":2723,"nodeType":2661},{},[],{"data":2725,"content":2726,"nodeType":2669},{},[2727],{"data":2728,"marks":2729,"value":2730,"nodeType":1293},{},[],"Customizing block screen content",{"data":2732,"content":2733,"nodeType":1294},{},[2734,2738,2747],{"data":2735,"marks":2736,"value":2737,"nodeType":1293},{},[],"Through our ",{"data":2739,"content":2741,"nodeType":1512},{"uri":2740},"https://pushsecurity.com/blog/introducing-in-browser-app-banners-set-guardrails-for-cloud-apps/",[2742],{"data":2743,"marks":2744,"value":2746,"nodeType":1293},{},[2745],{"type":2592},"app banner feature",{"data":2748,"marks":2749,"value":2750,"nodeType":1293},{},[],", we’ve already learned that orgs like to customize any messages their employees see. This helps them give company-specific information (like how to contact the security team), match the tone of the business, or even just deliver the message in the right language if that’s not English.",{"data":2752,"content":2756,"nodeType":1335},{"target":2753},{"sys":2754},{"id":2755,"type":1332,"linkType":1333},"1BlJyoWAeNm4thWxpnb6s7",[],{"data":2758,"content":2762,"nodeType":1335},{"target":2759},{"sys":2760},{"id":2761,"type":1332,"linkType":1333},"3Cjd6KQHscTcO9csgb6AZ9",[],{"data":2764,"content":2765,"nodeType":2661},{},[],{"data":2767,"content":2768,"nodeType":2669},{},[2769],{"data":2770,"marks":2771,"value":2772,"nodeType":1293},{},[],"Adding helpful context",{"data":2774,"content":2775,"nodeType":1294},{},[2776],{"data":2777,"marks":2778,"value":2779,"nodeType":1293},{},[],"To help employees tell the difference between a phishing attack and their intentional password reuse, they need to know the context. Specifically, they need to know which password they’re about to enter and where they’re about to enter it. ",{"data":2781,"content":2782,"nodeType":1294},{},[2783],{"data":2784,"marks":2785,"value":2786,"nodeType":1293},{},[],"For example, a sensible default warning might look something like:",{"data":2788,"content":2789,"nodeType":1294},{},[2790],{"data":2791,"marks":2792,"value":2795,"nodeType":1293},{},[2793],{"type":2794},"code","Are you sure? You're about to enter your Okta password into evil.com. This is not Okta.",{"data":2797,"content":2798,"nodeType":1294},{},[2799],{"data":2800,"marks":2801,"value":2802,"nodeType":1293},{},[],"This is distinctly different from:",{"data":2804,"content":2805,"nodeType":1294},{},[2806],{"data":2807,"marks":2808,"value":2810,"nodeType":1293},{},[2809],{"type":2794},"Are you sure? You're about to enter your Okta password into openai.com. This is not Okta.",{"data":2812,"content":2813,"nodeType":1294},{},[2814,2818,2823],{"data":2815,"marks":2816,"value":2817,"nodeType":1293},{},[],"Although I ",{"data":2819,"marks":2820,"value":2822,"nodeType":1293},{},[2821],{"type":312},"shouldn’t",{"data":2824,"marks":2825,"value":2826,"nodeType":1293},{},[]," be using the same password for Okta and OpenAI, this extra information gives me the context to make a decision about whether this is intentional. Hopefully it has the added benefit of making me think twice about my intentional password reuse.",{"data":2828,"content":2829,"nodeType":1294},{},[2830],{"data":2831,"marks":2832,"value":2833,"nodeType":1293},{},[],"This extra context means the message shown to the employee needs to be dynamic. Since we have also established it’s important for our user to be able to customize the message shown, we needed to support these as variables. As such, the final default warning message looks like:",{"data":2835,"content":2836,"nodeType":1294},{},[2837],{"data":2838,"marks":2839,"value":2841,"nodeType":1293},{},[2840],{"type":2794},"Are you sure? You're about to enter your $IDP password into $URL. This is not $IDP.",{"data":2843,"content":2844,"nodeType":2661},{},[],{"data":2846,"content":2847,"nodeType":2669},{},[2848],{"data":2849,"marks":2850,"value":2851,"nodeType":1293},{},[],"Focusing the scope",{"data":2853,"content":2854,"nodeType":1294},{},[2855],{"data":2856,"marks":2857,"value":2858,"nodeType":1293},{},[],"This feature could be applied to all passwords to just forcibly prevent password reuse. However, applying it everywhere increases the chances employees will trigger this feature due to intentional password reuse on less sensitive apps. The more they see the block or warn screen, the less weight it will hold.",{"data":2860,"content":2861,"nodeType":1294},{},[2862],{"data":2863,"marks":2864,"value":2865,"nodeType":1293},{},[],"Password phishing attacks are increasingly targeting identity provider platforms such as Okta and Microsoft 365 and for good reason. With this in mind, we decided to reduce the scope of this feature to only monitor identity provider accounts. This means that when it triggers, it really matters. Hopefully, this ensures employees take the notice seriously.",{"data":2867,"content":2868,"nodeType":1294},{},[2869],{"data":2870,"marks":2871,"value":2872,"nodeType":1293},{},[],"In the future, if there’s appetite from our customers, we could open this feature up to let security teams choose which apps are protected, so you can apply it to other systems you might consider highly sensitive, such as GitHub or AWS.",{"data":2874,"content":2875,"nodeType":2661},{},[],{"data":2877,"content":2878,"nodeType":2669},{},[2879],{"data":2880,"marks":2881,"value":2882,"nodeType":1293},{},[],"Reducing false positives",{"data":2884,"content":2885,"nodeType":1294},{},[2886],{"data":2887,"marks":2888,"value":2889,"nodeType":1293},{},[],"It’s imperative the accuracy of this feature is high, since false reports have the potential to cause alarm or annoyance.",{"data":2891,"content":2892,"nodeType":1294},{},[2893],{"data":2894,"marks":2895,"value":2896,"nodeType":1293},{},[],"As our browser agent is already monitoring for password reuse, we were well positioned to ensure this feature wouldn’t trigger incorrectly by analyzing existing password reuse alerts. ",{"data":2898,"content":2899,"nodeType":1294},{},[2900,2904,2909,2913,2917,2921,2926],{"data":2901,"marks":2902,"value":2903,"nodeType":1293},{},[],"There were some unexpected examples we needed to make sure were handled correctly, such as the ",{"data":2905,"marks":2906,"value":2908,"nodeType":1293},{},[2907],{"type":312},"newtab",{"data":2910,"marks":2911,"value":2912,"nodeType":1293},{},[]," page in Edge – did you know you can login to Microsoft 365 right inside the ",{"data":2914,"marks":2915,"value":2908,"nodeType":1293},{},[2916],{"type":312},{"data":2918,"marks":2919,"value":2920,"nodeType":1293},{},[]," page? Since the URL is not ",{"data":2922,"marks":2923,"value":2925,"nodeType":1293},{},[2924],{"type":312},"login.microsoftonline.com",{"data":2927,"marks":2928,"value":2929,"nodeType":1293},{},[],", this looks like strange password reuse! Also, certain shopping websites (which shall not be named) resubmit your credentials on every page, which caused the warn screen to be shown for each page visited.",{"data":2931,"content":2932,"nodeType":1294},{},[2933],{"data":2934,"marks":2935,"value":2936,"nodeType":1293},{},[],"Inside your organization, it is reasonable that you might have your own examples of this - sites which aren’t hosted by your IdP but use the same underlying authentication. To the browser agent, this would look like password reuse, even though it isn’t, because the URL is different. To manage this, the feature starts in MONITOR mode so you can see where, if anywhere, this feature would trigger, and you can build up an ignore list for the browser agent.",{"data":2938,"content":2939,"nodeType":2661},{},[],{"data":2941,"content":2942,"nodeType":2669},{},[2943],{"data":2944,"marks":2945,"value":2946,"nodeType":1293},{},[],"The threat intelligence question",{"data":2948,"content":2949,"nodeType":1294},{},[2950],{"data":2951,"marks":2952,"value":2953,"nodeType":1293},{},[],"We’ve come all this way and I’ve not mentioned threat intel even once! Surely that is a component of any phishing prevention tool? We considered it – and decided against it. Here’s why.",{"data":2955,"content":2956,"nodeType":1294},{},[2957],{"data":2958,"marks":2959,"value":2960,"nodeType":1293},{},[],"Primarily, you’d think threat intel could be used to detect known-bad sites and outright block them. And sure, we could do this, but we’d really just be reimplementing Google Safe Browsing. On the assumption we aren’t going to access a better threat intel feed than Google, we wouldn’t be adding anything above what your browser is already doing.",{"data":2962,"content":2963,"nodeType":1294},{},[2964,2968,2977],{"data":2965,"marks":2966,"value":2967,"nodeType":1293},{},[],"We hope this approach adds an extra layer of protection to the whack-a-mole of threat intel. Back in 2013, David Bianco introduced ",{"data":2969,"content":2971,"nodeType":1512},{"uri":2970},"https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html",[2972],{"data":2973,"marks":2974,"value":2976,"nodeType":1293},{},[2975],{"type":2592},"the pyramid of pain",{"data":2978,"marks":2979,"value":2980,"nodeType":1293},{},[]," which captures this concept well. By generally preventing the TTP of password phishing, we hope to introduce much more pain for an attacker than focusing on known-bad indicators, such as domains.",{"data":2982,"content":2983,"nodeType":2661},{},[],{"data":2985,"content":2986,"nodeType":2669},{},[2987],{"data":2988,"marks":2989,"value":2990,"nodeType":1293},{},[],"Let us know what you think!",{"data":2992,"content":2993,"nodeType":1294},{},[2994],{"data":2995,"marks":2996,"value":2997,"nodeType":1293},{},[],"Give it a go, we’d love to hear how you get on and whether you have any ideas for how we could strengthen the feature in future.",{"data":2999,"content":3000,"nodeType":1294},{},[3001],{"data":3002,"marks":3003,"value":3004,"nodeType":1293},{},[],"I didn’t focus on it here, but hopefully it goes without saying that any account that uses a password should be backed with MFA. If you don’t have a good view of which of your employees are using MFA across your cloud identities, Push can do this for you too!",{"entries":3006},{"hyperlink":3007,"inline":3008,"block":3009},[],[],[3010,3018,3024,3031],{"sys":3011,"__typename":3012,"title":3013,"caption":118,"layoutMode":118,"file":3014},{"id":2688},"Image","Password reuse detected",{"url":3015,"width":3016,"height":3017},"https://images.ctfassets.net/y1cdw1ablpvd/7KTlqMK8jpGNImQjqdoLr3/d6590ae58135ed929f3ed76fa4ab702e/image2.png",1999,773,{"sys":3019,"__typename":3012,"title":3020,"caption":118,"layoutMode":118,"file":3021},{"id":2719},"Password reuse image 2",{"url":3022,"width":3016,"height":3023},"https://images.ctfassets.net/y1cdw1ablpvd/14Pd9ANV7IALxMh4lh4tZQ/08a9bf87cc48916b814a35ff503fa982/image1.png",885,{"sys":3025,"__typename":3012,"title":3026,"caption":3027,"layoutMode":118,"file":3028},{"id":2755},"password reuse image 3","A formal employee message",{"url":3029,"width":3016,"height":3030},"https://images.ctfassets.net/y1cdw1ablpvd/4zOIKm4CM9AkOJtMXOO3cI/a23143a8fe2604bb445d2b5eb7dc9e24/image3.png",608,{"sys":3032,"__typename":3012,"title":3033,"caption":3034,"layoutMode":118,"file":3035},{"id":2761},"Password image 4","A multi-lingual employee message",{"url":3036,"width":3016,"height":3037},"https://images.ctfassets.net/y1cdw1ablpvd/3p44G0SJzMazQhr4Yistr/d084631c64cc961128dc3a15f03e2ee6/image4.png",612,"content:blog:dev-diary-phishing-prevention-behind-the-scenes.json","json","content","blog/dev-diary-phishing-prevention-behind-the-scenes.json","blog/dev-diary-phishing-prevention-behind-the-scenes",1776359989273]