[{"data":1,"prerenderedAt":3777},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/email-security-how-hackers-use-mail-rules-to-access-your-inbox":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"ogImage":118,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1297,"synopsis":1298,"hashTags":1299,"publishedDate":1306,"slug":1307,"tagsCollection":1308,"relatedBlogPostsCollection":1318,"authorsCollection":3398,"content":3406,"_id":3773,"_type":3774,"_source":1479,"_file":3775,"_stem":3776,"_extension":3774},"/blog/email-security-how-hackers-use-mail-rules-to-access-your-inbox","blog",{"id":1280,"publishedAt":1281},"2zZ8kxP0t8Smi9b6hpT34k","2026-01-30T09:44:27.371Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"After a successful phishing campaign against Office 365 and Google Workspace users, a malicious mail rule can be automatically created in the user’s mailbox that forwards sensitive emails to an external address. Learn the best way to protect your company.","text","paragraph","document","Email security: How hackers use mail rules to access your inbox","How hackers use mail rules to access your inbox","After phishing campaigns target Office 365 and Google Workspace users, malicious mail rules are automatically added to the user’s mailbox. Take steps to defend.",[1300,1301,1302,1303,1304,1305],"businessemailcompromise","bec","mailrules","office365","googleworkspace","emailsecurity","2021-06-10T00:00:00.000+01:00","email-security-how-hackers-use-mail-rules-to-access-your-inbox",{"items":1309},[1310,1314],{"sys":1311,"name":1313},{"id":1312},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":1315,"name":1317},{"id":1316},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1319},[1320,2006,2874],{"__typename":1321,"sys":1322,"content":1324,"title":1988,"synopsis":1989,"hashTags":118,"publishedDate":1990,"slug":1991,"tagsCollection":1992,"authorsCollection":1998},"BlogPosts",{"id":1323},"3dtvtDQdcQ6fAW7CB8VOFP",{"json":1325},{"nodeType":1295,"data":1326,"content":1327},{},[1328,1335,1342,1349,1353,1363,1370,1392,1427,1436,1456,1462,1487,1490,1498,1505,1521,1537,1543,1550,1557,1563,1579,1582,1590,1597,1604,1611,1618,1621,1629,1636,1643,1663,1670,1678,1721,1728,1734,1741,1747,1754,1757,1765,1780,1787,1829,1841,1844,1852,1859,1866,1899,1906,1926,1932,1938,1941,1949,1956,1976,1982],{"nodeType":1294,"data":1329,"content":1330},{},[1331],{"nodeType":1293,"value":1332,"marks":1333,"data":1334},"Phishing attacks remain a huge challenge for organizations in 2025. In fact, with attackers increasingly leveraging identity-based techniques over software exploits, phishing arguably poses a bigger threat than ever before. ",[],{},{"nodeType":1294,"data":1336,"content":1337},{},[1338],{"nodeType":1293,"value":1339,"marks":1340,"data":1341},"Attackers are turning to identity attacks like phishing because they can achieve all of the same objectives as they would in a traditional endpoint or network attack, simply by logging into a victim’s account. And with organizations now using hundreds of internet apps across their workforce, the scope of accounts that can be phished or targeted with stolen credentials has grown exponentially. ",[],{},{"nodeType":1294,"data":1343,"content":1344},{},[1345],{"nodeType":1293,"value":1346,"marks":1347,"data":1348},"With MFA-bypassing phishing kits the new normal, capable of phishing accounts protected by SMS, OTP, and push-based methods, detection controls are being put under constant pressure as prevention controls fall short. ",[],{},{"nodeType":1350,"data":1351,"content":1352},"hr",{},[],{"nodeType":1354,"data":1355,"content":1356},"heading-1",{},[1357],{"nodeType":1293,"value":1358,"marks":1359,"data":1362},"Attackers are bypassing detection controls",[1360],{"type":1361},"bold",{},{"nodeType":1294,"data":1364,"content":1365},{},[1366],{"nodeType":1293,"value":1367,"marks":1368,"data":1369},"The majority of phishing detection and control enforcement is focused at the email and network layer — typically at the Secure Email Gateway (SEG), Secure Web Gateway (SWG)/proxy, or both. ",[],{},{"nodeType":1294,"data":1371,"content":1372},{},[1373,1377,1388],{"nodeType":1293,"value":1374,"marks":1375,"data":1376},"But attackers know this, ",[],{},{"nodeType":1378,"data":1379,"content":1381},"hyperlink",{"uri":1380},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/",[1382],{"nodeType":1293,"value":1383,"marks":1384,"data":1387},"and are taking steps to avoid these controls",[1385],{"type":1386},"underline",{},{"nodeType":1293,"value":1389,"marks":1390,"data":1391},", by:",[],{},{"nodeType":1393,"data":1394,"content":1395},"unordered-list",{},[1396,1407,1417],{"nodeType":1397,"data":1398,"content":1399},"list-item",{},[1400],{"nodeType":1294,"data":1401,"content":1402},{},[1403],{"nodeType":1293,"value":1404,"marks":1405,"data":1406},"Routinely evading IoC driven blocklists by dynamically rotating and updating commonly signatured elements like IPs, domains, and URLs.",[],{},{"nodeType":1397,"data":1408,"content":1409},{},[1410],{"nodeType":1294,"data":1411,"content":1412},{},[1413],{"nodeType":1293,"value":1414,"marks":1415,"data":1416},"Preventing analysis of their phishing pages by implementing bot protection like CAPTCHA or Cloudflare Turnstile alongside other detection evasion methods. ",[],{},{"nodeType":1397,"data":1418,"content":1419},{},[1420],{"nodeType":1294,"data":1421,"content":1422},{},[1423],{"nodeType":1293,"value":1424,"marks":1425,"data":1426},"Changing visual and DOM elements on the page so that even when the page is loaded, detection signatures may fail to trigger.  ",[],{},{"nodeType":1428,"data":1429,"content":1435},"embedded-entry-block",{"target":1430},{"sys":1431},{"id":1432,"type":1433,"linkType":1434},"5w44LsamEfcwSACx3MA997","Link","Entry",[],{"nodeType":1294,"data":1437,"content":1438},{},[1439,1443,1452],{"nodeType":1293,"value":1440,"marks":1441,"data":1442},"And in fact, by launching multi- and cross-channel attacks, attackers are evading email-based controls entirely. Just see ",[],{},{"nodeType":1378,"data":1444,"content":1446},{"uri":1445},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[1447],{"nodeType":1293,"value":1448,"marks":1449,"data":1451},"this recent example",[1450],{"type":1386},{},{"nodeType":1293,"value":1453,"marks":1454,"data":1455},", where attackers impersonating Onfido delivered their phishing attack via malicious Google ads (aka malvertising) — bypassing email altogether. ",[],{},{"nodeType":1428,"data":1457,"content":1461},{"target":1458},{"sys":1459},{"id":1460,"type":1433,"linkType":1434},"3sGmVHl1Rwjyw3TMZSYuy4",[],{"nodeType":1294,"data":1463,"content":1464},{},[1465,1469,1474,1478,1483],{"nodeType":1293,"value":1466,"marks":1467,"data":1468},"It’s worth pointing out the limitations of email-based solutions here too. Email has some additional checks around the sender’s reputation and things like DMARC/DKIM, but these don’t actually identify malicious ",[],{},{"nodeType":1293,"value":1470,"marks":1471,"data":1473},"pages",[1472],{"type":1361},{},{"nodeType":1293,"value":1475,"marks":1476,"data":1477},". Similarly, some modern email solutions are doing much deeper analysis of the ",[],{},{"nodeType":1293,"value":1479,"marks":1480,"data":1482},"content",[1481],{"type":1361},{},{"nodeType":1293,"value":1484,"marks":1485,"data":1486}," of an email. But… that doesn’t really help with identifying the phishing sites themselves (just indicates that one might be linked in the email). This is much more appropriate for BEC-style attacks where the goal is to social engineer the victim, as opposed to linking them to a malicious page. And this still doesn’t help with attacks launched over different mediums as we’ve highlighted above.",[],{},{"nodeType":1350,"data":1488,"content":1489},{},[],{"nodeType":1354,"data":1491,"content":1492},{},[1493],{"nodeType":1293,"value":1494,"marks":1495,"data":1497},"How browser-based detection and response can level the playing field",[1496],{"type":1361},{},{"nodeType":1294,"data":1499,"content":1500},{},[1501],{"nodeType":1293,"value":1502,"marks":1503,"data":1504},"Most phishing attacks involve the delivery of a malicious link to a user. The user clicks the link and loads a malicious page. In the vast majority of cases, the malicious page is a login portal for a specific website, where the goal for the attacker is to steal the victim’s account.",[],{},{"nodeType":1294,"data":1506,"content":1507},{},[1508,1512,1517],{"nodeType":1293,"value":1509,"marks":1510,"data":1511},"These attacks are happening pretty much exclusively in the victim’s browser. So rather than building more email or network based controls looking from the outside-in at phishing pages accessed in the browser, there’s a huge opportunity presented by building phishing detection and response capabilities ",[],{},{"nodeType":1293,"value":1513,"marks":1514,"data":1516},"inside",[1515],{"type":312},{},{"nodeType":1293,"value":1518,"marks":1519,"data":1520}," the browser. ",[],{},{"nodeType":1294,"data":1522,"content":1523},{},[1524,1528,1533],{"nodeType":1293,"value":1525,"marks":1526,"data":1527},"When we look at the history of detection and response, this makes a lot of sense. When endpoint attacks skyrocketed in the late 2000s / early 2010s, they took advantage of the fact that defenders were trying to detect malware with primarily network-based detections, signature-based analysis of files, and running files in sandboxes (which was reliably defeated with sandbox-aware malware and using things as simple as putting an execution delay in the code). But this gave way to EDR, which presented a better way of observing and intercepting malicious software in ",[],{},{"nodeType":1293,"value":1529,"marks":1530,"data":1532},"real-time",[1531],{"type":1361},{},{"nodeType":1293,"value":1534,"marks":1535,"data":1536},". ",[],{},{"nodeType":1428,"data":1538,"content":1542},{"target":1539},{"sys":1540},{"id":1541,"type":1433,"linkType":1434},"1KFwJvbIMiWHb1erWlljZf",[],{"nodeType":1294,"data":1544,"content":1545},{},[1546],{"nodeType":1293,"value":1547,"marks":1548,"data":1549},"The key here was getting inside the data stream to be able to observe activity in real-time on the endpoint. ",[],{},{"nodeType":1294,"data":1551,"content":1552},{},[1553],{"nodeType":1293,"value":1554,"marks":1555,"data":1556},"We’re in a similar position today. Modern phishing attacks are happening on web pages accessed via the browser, and the tools we’re relying on — email, network, even endpoint — don’t have the required visibility. They’re looking from the outside-in. ",[],{},{"nodeType":1428,"data":1558,"content":1562},{"target":1559},{"sys":1560},{"id":1561,"type":1433,"linkType":1434},"59t6AcjpRjs3VQQXQO3PWu",[],{"nodeType":1294,"data":1564,"content":1565},{},[1566,1570,1575],{"nodeType":1293,"value":1567,"marks":1568,"data":1569},"But what if we could do detection and response from ",[],{},{"nodeType":1293,"value":1571,"marks":1572,"data":1574},"inside the browser?",[1573],{"type":1361},{},{"nodeType":1293,"value":1576,"marks":1577,"data":1578}," Here’s three reasons why the browser is best for stopping phishing attacks:",[],{},{"nodeType":1350,"data":1580,"content":1581},{},[],{"nodeType":1354,"data":1583,"content":1584},{},[1585],{"nodeType":1293,"value":1586,"marks":1587,"data":1589},"#1: Analyze pages, not links",[1588],{"type":1361},{},{"nodeType":1294,"data":1591,"content":1592},{},[1593],{"nodeType":1293,"value":1594,"marks":1595,"data":1596},"Common phishing detections rely on the analysis of links or static HTML as opposed to malicious pages. Modern phishing pages are no longer static HTML — like most other modern web pages, these are dynamic web apps rendered in the browser, with JavaScript dynamically rewriting the page and launching the malicious content. This means that most basic, static checks fail to identify the malicious content running on the page. ",[],{},{"nodeType":1294,"data":1598,"content":1599},{},[1600],{"nodeType":1293,"value":1601,"marks":1602,"data":1603},"Without deeper analysis, you’re reliant on analysing things like domains, URLs and IP addresses against known-bad blocklists. But these are all highly disposable. Attackers are buying them in bulk, constantly taking over legitimate domains, and generally planning for the fact that they’ll get through a lot of them. Modern phishing architecture is also able to dynamically rotate and update the links served to visitors from a continually refreshed pool (so every person that clicks the link gets served a different URL) and even going as far as using things like one-time magic links (which also means that any security team members trying to investigate the page later won’t be able to do so). ",[],{},{"nodeType":1294,"data":1605,"content":1606},{},[1607],{"nodeType":1293,"value":1608,"marks":1609,"data":1610},"Ultimately, this means that blocklists just aren’t that effective — because it’s trivial for attackers to change the indicators being used to create detections. If you think about the Pyramid of Pain, these indicators sit right at the bottom — the kind of thing we’ve been moving away from for years in the endpoint security world.  ",[],{},{"nodeType":1294,"data":1612,"content":1613},{},[1614],{"nodeType":1293,"value":1615,"marks":1616,"data":1617},"But in the browser, you can observe the rendered web page in all its glory. With much deeper visibility of the page (and its malicious elements) you can…",[],{},{"nodeType":1350,"data":1619,"content":1620},{},[],{"nodeType":1354,"data":1622,"content":1623},{},[1624],{"nodeType":1293,"value":1625,"marks":1626,"data":1628},"#2: Detect TTPs, not IoCs",[1627],{"type":1361},{},{"nodeType":1294,"data":1630,"content":1631},{},[1632],{"nodeType":1293,"value":1633,"marks":1634,"data":1635},"Even where TTP-based detections are in play, they’re typically reliant on either piecing together network requests, or loading the page in a sandbox. ",[],{},{"nodeType":1294,"data":1637,"content":1638},{},[1639],{"nodeType":1293,"value":1640,"marks":1641,"data":1642},"However, attackers are getting pretty good at evading sandbox analysis — simply by implementing bot protection by requiring user interaction with a CAPTCHA or Cloudflare Turnstile. Even if you can get past Turnstile, then you’ll need to supply the correct URL parameters and headers, and execute JavaScript, to be served the malicious page. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",[],{},{"nodeType":1294,"data":1644,"content":1645},{},[1646,1650,1659],{"nodeType":1293,"value":1647,"marks":1648,"data":1649},"And if all this wasn’t enough, ",[],{},{"nodeType":1378,"data":1651,"content":1653},{"uri":1652},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[1654],{"nodeType":1293,"value":1655,"marks":1656,"data":1658},"they’re also obfuscating both visual and DOM elements to prevent signature-based detections from picking them up",[1657],{"type":1386},{},{"nodeType":1293,"value":1660,"marks":1661,"data":1662}," — so even if you can land on the page, there’s a high chance that your detections won’t trigger.",[],{},{"nodeType":1294,"data":1664,"content":1665},{},[1666],{"nodeType":1293,"value":1667,"marks":1668,"data":1669},"When using a proxy, you’ll have some visibility of the network traffic generated by a user accessing and interacting with a page. However, you’ll struggle to correlate key actions like whether the user entered their password with the specific tab when dealing with the sheer volume of disorganized network traffic data. ",[],{},{"nodeType":1294,"data":1671,"content":1672},{},[1673],{"nodeType":1293,"value":1674,"marks":1675,"data":1677},"But you get much better visibility of all this in the browser, with access to:",[1676],{"type":1361},{},{"nodeType":1393,"data":1679,"content":1680},{},[1681,1691,1701,1711],{"nodeType":1397,"data":1682,"content":1683},{},[1684],{"nodeType":1294,"data":1685,"content":1686},{},[1687],{"nodeType":1293,"value":1688,"marks":1689,"data":1690},"Full decrypted HTTP traffic — not just DNS and TCP/IP metadata",[],{},{"nodeType":1397,"data":1692,"content":1693},{},[1694],{"nodeType":1294,"data":1695,"content":1696},{},[1697],{"nodeType":1293,"value":1698,"marks":1699,"data":1700},"Full user interaction tracing — every click, keystroke, or DOM change can be traced",[],{},{"nodeType":1397,"data":1702,"content":1703},{},[1704],{"nodeType":1294,"data":1705,"content":1706},{},[1707],{"nodeType":1293,"value":1708,"marks":1709,"data":1710},"Full inspection at every layer of execution, not just initial HTML served",[],{},{"nodeType":1397,"data":1712,"content":1713},{},[1714],{"nodeType":1294,"data":1715,"content":1716},{},[1717],{"nodeType":1293,"value":1718,"marks":1719,"data":1720},"Full access to browser APIs, to correlate with browser history, local storage, attached cookies, etc.",[],{},{"nodeType":1294,"data":1722,"content":1723},{},[1724],{"nodeType":1293,"value":1725,"marks":1726,"data":1727},"This gives you everything you need to build high-fidelity detections focused on page behavior and user interaction – that are much harder for attackers to get around when compared to IoC-based detections. ",[],{},{"nodeType":1428,"data":1729,"content":1733},{"target":1730},{"sys":1731},{"id":1732,"type":1433,"linkType":1434},"1YggWcADAWgt3sUkXMsVIw",[],{"nodeType":1294,"data":1735,"content":1736},{},[1737],{"nodeType":1293,"value":1738,"marks":1739,"data":1740},"In the browser, you get much better visibility of the user and page behavior to enable phishing page detection.",[],{},{"nodeType":1428,"data":1742,"content":1746},{"target":1743},{"sys":1744},{"id":1745,"type":1433,"linkType":1434},"1BKgjnYkLJIRW0LJZYpfga",[],{"nodeType":1294,"data":1748,"content":1749},{},[1750],{"nodeType":1293,"value":1751,"marks":1752,"data":1753},"And with this new visibility, because you’re in the browser and seeing the page at the same time as the user is interacting with it, you can…",[],{},{"nodeType":1350,"data":1755,"content":1756},{},[],{"nodeType":1354,"data":1758,"content":1759},{},[1760],{"nodeType":1293,"value":1761,"marks":1762,"data":1764},"#3: Intercept in real time, not post mortem",[1763],{"type":1361},{},{"nodeType":1294,"data":1766,"content":1767},{},[1768,1772,1777],{"nodeType":1293,"value":1769,"marks":1770,"data":1771},"For non-browser solutions, ",[],{},{"nodeType":1293,"value":1773,"marks":1774,"data":1776},"real-time phishing detection is basically nonexistent",[1775],{"type":1361},{},{"nodeType":1293,"value":1534,"marks":1778,"data":1779},[],{},{"nodeType":1294,"data":1781,"content":1782},{},[1783],{"nodeType":1293,"value":1784,"marks":1785,"data":1786},"At best, your proxy-based solution might be able to detect malicious behavior via the network traffic generated by your user interacting with the page. But because of the complexity of reconstructing network requests post-TLS-encryption, this typically happens on a time delay and is not entirely reliable. ",[],{},{"nodeType":1294,"data":1788,"content":1789},{},[1790,1794,1799,1803,1808,1812,1816,1820,1825],{"nodeType":1293,"value":1791,"marks":1792,"data":1793},"If a page is flagged, it usually requires further investigation by a security team to rule out any false positives and kick off an investigation. This can take ",[],{},{"nodeType":1293,"value":1795,"marks":1796,"data":1798},"hours",[1797],{"type":1361},{},{"nodeType":1293,"value":1800,"marks":1801,"data":1802}," at best, probably ",[],{},{"nodeType":1293,"value":1804,"marks":1805,"data":1807},"days",[1806],{"type":1361},{},{"nodeType":1293,"value":1809,"marks":1810,"data":1811},". Then, once a page is identified as malicious and IoCs are created, it can take ",[],{},{"nodeType":1293,"value":1804,"marks":1813,"data":1815},[1814],{"type":1361},{},{"nodeType":1293,"value":1817,"marks":1818,"data":1819}," or even ",[],{},{"nodeType":1293,"value":1821,"marks":1822,"data":1824},"weeks",[1823],{"type":1361},{},{"nodeType":1293,"value":1826,"marks":1827,"data":1828}," before the information is distributed, TI feeds are updated, and ingested into blocklists. ",[],{},{"nodeType":1294,"data":1830,"content":1831},{},[1832,1836],{"nodeType":1293,"value":1833,"marks":1834,"data":1835},"But in the browser, you’re observing the page in real-time, as the user sees it, from inside the browser. This is a game changer when it comes to not just detecting, but intercepting and shutting down attacks before a user is phished and the damage is done. ",[],{},{"nodeType":1293,"value":1837,"marks":1838,"data":1840},"This changes the focus from post mortem containment and cleanup, to pre-compromise interception in real time. ",[1839],{"type":1361},{},{"nodeType":1350,"data":1842,"content":1843},{},[],{"nodeType":1354,"data":1845,"content":1846},{},[1847],{"nodeType":1293,"value":1848,"marks":1849,"data":1851},"The future of phishing detection and response is browser based",[1850],{"type":1361},{},{"nodeType":1294,"data":1853,"content":1854},{},[1855],{"nodeType":1293,"value":1856,"marks":1857,"data":1858},"Push provides a browser-based identity security solution that intercepts phishing attacks as they happen — in employee browsers. Being in the browser delivers a lot of advantages when it comes to detecting and intercepting phishing attacks. You see the live webpage that the user sees, as they see it, meaning you have much better visibility of malicious elements running on the page. It also means that you can implement real-time controls that kick in when a malicious element is detected. ",[],{},{"nodeType":1294,"data":1860,"content":1861},{},[1862],{"nodeType":1293,"value":1863,"marks":1864,"data":1865},"When a phishing attack hits a user with Push, regardless of the delivery channel, our browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page, detecting that:",[],{},{"nodeType":1393,"data":1867,"content":1868},{},[1869,1879,1889],{"nodeType":1397,"data":1870,"content":1871},{},[1872],{"nodeType":1294,"data":1873,"content":1874},{},[1875],{"nodeType":1293,"value":1876,"marks":1877,"data":1878},"The password the user is entering into the phishing site has been used to log into another site previously. This means that the password is being reused (bad) or the user is being phished (even worse).  ",[],{},{"nodeType":1397,"data":1880,"content":1881},{},[1882],{"nodeType":1294,"data":1883,"content":1884},{},[1885],{"nodeType":1293,"value":1886,"marks":1887,"data":1888},"The web page is cloned from a legitimate login page that has been fingerprinted by Push. ",[],{},{"nodeType":1397,"data":1890,"content":1891},{},[1892],{"nodeType":1294,"data":1893,"content":1894},{},[1895],{"nodeType":1293,"value":1896,"marks":1897,"data":1898},"A phishing toolkit is running on the web page. ",[],{},{"nodeType":1294,"data":1900,"content":1901},{},[1902],{"nodeType":1293,"value":1903,"marks":1904,"data":1905},"As a result, the user is blocked from interacting with the phishing site and prevented from continuing. ",[],{},{"nodeType":1294,"data":1907,"content":1908},{},[1909,1914,1923],{"nodeType":1293,"value":1910,"marks":1911,"data":1913},"These are good examples of detections that are difficult (or impossible) for an attacker to evade — you can’t phish a victim if they can’t enter their credentials into your phishing site! ",[1912],{"type":1361},{},{"nodeType":1378,"data":1915,"content":1917},{"uri":1916},"https://pushsecurity.com/blog/detecting-and-blocking-phishing-attacks-in-the-browser/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[1918],{"nodeType":1293,"value":1919,"marks":1920,"data":1922},"Find out more about how Push detects and blocks phishing attacks here.",[1921],{"type":1386},{},{"nodeType":1293,"value":37,"marks":1924,"data":1925},[],{},{"nodeType":1428,"data":1927,"content":1931},{"target":1928},{"sys":1929},{"id":1930,"type":1433,"linkType":1434},"4ixcEsEW4EyqckOTmP5Pbb",[],{"nodeType":1428,"data":1933,"content":1937},{"target":1934},{"sys":1935},{"id":1936,"type":1433,"linkType":1434},"4PJKxWTroEPohYm4mklfl6",[],{"nodeType":1350,"data":1939,"content":1940},{},[],{"nodeType":1354,"data":1942,"content":1943},{},[1944],{"nodeType":1293,"value":1945,"marks":1946,"data":1948},"Learn more",[1947],{"type":1361},{},{"nodeType":1294,"data":1950,"content":1951},{},[1952],{"nodeType":1293,"value":1953,"marks":1954,"data":1955},"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",[],{},{"nodeType":1294,"data":1957,"content":1958},{},[1959,1963,1972],{"nodeType":1293,"value":1960,"marks":1961,"data":1962},"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",[],{},{"nodeType":1378,"data":1964,"content":1966},{"uri":1965},"https://pushsecurity.com/demo?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[1967],{"nodeType":1293,"value":1968,"marks":1969,"data":1971},"book some time with one of our team for a live demo",[1970],{"type":1386},{},{"nodeType":1293,"value":1973,"marks":1974,"data":1975},".",[],{},{"nodeType":1428,"data":1977,"content":1981},{"target":1978},{"sys":1979},{"id":1980,"type":1433,"linkType":1434},"2DviJNOMbKgbcqwkNl0LDP",[],{"nodeType":1294,"data":1983,"content":1984},{},[1985],{"nodeType":1293,"value":37,"marks":1986,"data":1987},[],{},"Three reasons why browser is best for stopping phishing attacks","Why being in the browser gives defenders a key advantage over network and email phishing prevention, detection, and response tools. ","2025-04-28T00:00:00.000Z","three-reasons-why-browser-is-best-for-stopping-phishing-attacks",{"items":1993},[1994,1996],{"sys":1995,"name":1317},{"id":1316},{"sys":1997,"name":1313},{"id":1312},{"items":1999},[2000],{"fullName":2001,"firstName":2002,"jobTitle":2003,"profilePicture":2004},"Dan Green","Dan","Threat Research",{"url":2005},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1321,"sys":2007,"content":2009,"title":2856,"synopsis":2857,"hashTags":118,"publishedDate":2858,"slug":2859,"tagsCollection":2860,"authorsCollection":2866},{"id":2008},"7DJnckJxP4CXyXhPJJpby5",{"json":2010},{"nodeType":1295,"data":2011,"content":2012},{},[2013,2020,2027,2034,2041,2048,2055,2062,2069,2076,2082,2090,2097,2104,2162,2169,2176,2196,2203,2210,2217,2250,2266,2273,2280,2287,2294,2301,2308,2328,2348,2456,2463,2483,2490,2497,2504,2510,2517,2524,2531,2564,2571,2578,2611,2618,2625,2722,2741,2748,2755,2762,2769,2828,2835,2838,2845,2850],{"nodeType":1294,"data":2014,"content":2015},{},[2016],{"nodeType":1293,"value":2017,"marks":2018,"data":2019},"Phishing attacks have always been a go-to technique for both red teamers and real-world threat actors alike. Whether focused on harvesting creds or running malicious payloads, phishing has continued to be adapted to circumvent defenses and has remained highly effective due to this.",[],{},{"nodeType":1294,"data":2021,"content":2022},{},[2023],{"nodeType":1293,"value":2024,"marks":2025,"data":2026},"As MFA has become more common, classic password harvesting focused phishing attacks have become less effective. Typically, for a full account compromise, an MFA push notification or a one-time passcode (OTP) needs to be entered at the time of login. This means harvesting passwords and using them later is no longer effective alone, because an MFA factor is still required each time a valid login is performed.",[],{},{"nodeType":1294,"data":2028,"content":2029},{},[2030],{"nodeType":1293,"value":2031,"marks":2032,"data":2033},"Adversary-in-the-Middle (AitM) phishing is a newer variant of phishing that allows attackers to circumvent MFA protection. In this article, we’re going to look at what AitM phishing is, how it works, and what you can do about it.",[],{},{"nodeType":1354,"data":2035,"content":2036},{},[2037],{"nodeType":1293,"value":2038,"marks":2039,"data":2040},"What is AitM phishing?",[],{},{"nodeType":1294,"data":2042,"content":2043},{},[2044],{"nodeType":1293,"value":2045,"marks":2046,"data":2047},"AitM phishing is a technique that uses dedicated tooling to act as a proxy between the target and a legitimate login portal for an application, principally to make it easier to defeat MFA protection. ",[],{},{"nodeType":1294,"data":2049,"content":2050},{},[2051],{"nodeType":1293,"value":2052,"marks":2053,"data":2054},"While any login portal can be a target, attackers typically look for SSO login portals such as Microsoft Entra, Okta, or Google Workspace. This allows the target to log in successfully with a legitimate service they use and even continue to interact with it, while providing additional access to connected SSO apps if the attack is successful. ",[],{},{"nodeType":1294,"data":2056,"content":2057},{},[2058],{"nodeType":1293,"value":2059,"marks":2060,"data":2061},"As it’s a proxy to the real application, the page will appear exactly as the user expects, because they are logging into the legitimate site – just taking a detour via the attacker’s device. For example, if accessing their webmail, the user will see all their real emails; if accessing their cloud file store then all their real files will be present, etc. This gives the method an increased sense of authenticity and makes the compromise less obvious to the user. However, because the attacker is sitting in the middle of this connection, they are able to observe all interactions and also take control of the authenticated session to gain control of the user account. ",[],{},{"nodeType":1294,"data":2063,"content":2064},{},[2065],{"nodeType":1293,"value":2066,"marks":2067,"data":2068},"While this access is technically temporary, since the attacker is unable to re-authenticate in future without additional MFA prompts, in practice authenticated sessions can often last as long as 30 days or more if kept active. Additionally, there are a wide range of persistence techniques that allow an attacker to maintain some level of access to the user account and/or targeted application indefinitely. ",[],{},{"nodeType":1294,"data":2070,"content":2071},{},[2072],{"nodeType":1293,"value":2073,"marks":2074,"data":2075},"We’ll revisit this point later, but for now let’s consider the two main techniques that are used to implement AitM phishing: Reverse web proxies and Browser-in-the-Middle techniques.",[],{},{"nodeType":1428,"data":2077,"content":2081},{"target":2078},{"sys":2079},{"id":2080,"type":1433,"linkType":1434},"6WEolDcviadCgAW4dCgTPW",[],{"nodeType":2083,"data":2084,"content":2085},"heading-2",{},[2086],{"nodeType":1293,"value":2087,"marks":2088,"data":2089},"Reverse web proxy techniques",[],{},{"nodeType":1294,"data":2091,"content":2092},{},[2093],{"nodeType":1293,"value":2094,"marks":2095,"data":2096},"One common AitM phishing approach is to use tooling that acts as a reverse web proxy. For example, let’s say a victim is tricked into visiting a malicious domain. Under the hood, HTTP requests are passed between the victim’s browser and the real site via the malicious site. When the malicious site receives an HTTP request, it forwards this request on to the legitimate site it is impersonating, receives the response, and then forwards that on to the victim. ",[],{},{"nodeType":1294,"data":2098,"content":2099},{},[2100],{"nodeType":1293,"value":2101,"marks":2102,"data":2103},"In practice, there are many technical challenges, such as rewriting all links and references to the impersonated site to ensure everything continues to be sent to the attacker. However, at a high level, it really is just acting as a reverse web proxy.",[],{},{"nodeType":1294,"data":2105,"content":2106},{},[2107,2111,2120,2124,2133,2137,2146,2150,2159],{"nodeType":1293,"value":2108,"marks":2109,"data":2110},"This is arguably the most scalable and reliable approach from an attacker’s point of view. Open-source tools that demonstrate this method include ",[],{},{"nodeType":1378,"data":2112,"content":2114},{"uri":2113},"https://github.com/drk1wi/Modlishka",[2115],{"nodeType":1293,"value":2116,"marks":2117,"data":2119},"Modlishka",[2118],{"type":1386},{},{"nodeType":1293,"value":2121,"marks":2122,"data":2123},", ",[],{},{"nodeType":1378,"data":2125,"content":2127},{"uri":2126},"https://github.com/muraenateam/muraena",[2128],{"nodeType":1293,"value":2129,"marks":2130,"data":2132},"Muraena",[2131],{"type":1386},{},{"nodeType":1293,"value":2134,"marks":2135,"data":2136},", and the ever popular ",[],{},{"nodeType":1378,"data":2138,"content":2140},{"uri":2139},"https://github.com/kgretzky/evilginx2",[2141],{"nodeType":1293,"value":2142,"marks":2143,"data":2145},"Evilginx",[2144],{"type":1386},{},{"nodeType":1293,"value":2147,"marks":2148,"data":2149},". In the criminal world, there are also similar private toolsets available that have been used in many breaches in the past. A good example of this would be ",[],{},{"nodeType":1378,"data":2151,"content":2153},{"uri":2152},"https://www.bleepingcomputer.com/news/security/evilproxy-uses-indeedcom-open-redirect-for-microsoft-365-phishing/",[2154],{"nodeType":1293,"value":2155,"marks":2156,"data":2158},"Evilproxy",[2157],{"type":1386},{},{"nodeType":1293,"value":1973,"marks":2160,"data":2161},[],{},{"nodeType":1294,"data":2163,"content":2164},{},[2165],{"nodeType":1293,"value":2166,"marks":2167,"data":2168},"One downside to this approach is that there are controls that can be put in place to block it. For example, application developers can hide obfuscated JavaScript code that will fail if the correct value is not produced, checking that the origin matches the expected (legitimate) domains or contains encrypted tokens including this material sent as part of the login process. ",[],{},{"nodeType":1294,"data":2170,"content":2171},{},[2172],{"nodeType":1293,"value":2173,"marks":2174,"data":2175},"While your average small website is not going to be implementing such checks, major identity providers have a strong vested interest in evolving their defenses to block these techniques. At this point, it’s a cat-and-mouse game. ",[],{},{"nodeType":1294,"data":2177,"content":2178},{},[2179,2183,2192],{"nodeType":1293,"value":2180,"marks":2181,"data":2182},"If you want to know more about this space, then definitely check out ",[],{},{"nodeType":1378,"data":2184,"content":2186},{"uri":2185},"https://www.youtube.com/watch?v=C-Fh4sIdY8c",[2187],{"nodeType":1293,"value":2188,"marks":2189,"data":2191},"Kuba Gretzky’s talk on this at x33fcon",[2190],{"type":1386},{},{"nodeType":1293,"value":2193,"marks":2194,"data":2195},".  ",[],{},{"nodeType":2083,"data":2197,"content":2198},{},[2199],{"nodeType":1293,"value":2200,"marks":2201,"data":2202},"Browser-in-the-Middle (BitM) techniques ",[],{},{"nodeType":1294,"data":2204,"content":2205},{},[2206],{"nodeType":1293,"value":2207,"marks":2208,"data":2209},"Another common approach is known as Browser-in-the-Middle (BitM). Rather than act as a reverse web proxy, this technique tricks a target into directly controlling the attacker’s own browser remotely using desktop screen sharing and control approaches, much like VNC and RDP. This enables the attacker to harvest not just the username and password, but all other associated secrets and tokens that go along with the login. ",[],{},{"nodeType":1294,"data":2211,"content":2212},{},[2213],{"nodeType":1293,"value":2214,"marks":2215,"data":2216},"In this case, the victim isn’t interacting with a fake website clone or proxy. They are literally remotely controlling the attacker’s browser to log in to the legitimate application without realizing. This is the virtual equivalent of an attacker handing their laptop to their victim, asking them to login to Okta for them, and then taking their laptop back afterwards. Thanks very much!",[],{},{"nodeType":1294,"data":2218,"content":2219},{},[2220,2224,2233,2237,2246],{"nodeType":1293,"value":2221,"marks":2222,"data":2223},"Practically speaking, the most common approach for implementing this technique is using the open-source project noVNC, which is a JavaScript-based VNC client that allows VNC to be used in the browser. Probably the most well-known example of an offensive tool implementing this is ",[],{},{"nodeType":1378,"data":2225,"content":2227},{"uri":2226},"https://github.com/JoelGMSec/EvilnoVNC",[2228],{"nodeType":1293,"value":2229,"marks":2230,"data":2232},"EvilnoVNC",[2231],{"type":1386},{},{"nodeType":1293,"value":2234,"marks":2235,"data":2236},", which spins up Docker instances of VNC and proxies access to them, while also logging keystrokes and cookies to facilitate account compromise. Tools like ",[],{},{"nodeType":1378,"data":2238,"content":2240},{"uri":2239},"https://posts.specterops.io/phishing-with-dynamite-7d33d8fac038",[2241],{"nodeType":1293,"value":2242,"marks":2243,"data":2245},"Cuddlephish",[2244],{"type":1386},{},{"nodeType":1293,"value":2247,"marks":2248,"data":2249}," offer similar functionality using WebRTC. ",[],{},{"nodeType":1294,"data":2251,"content":2252},{},[2253,2257,2262],{"nodeType":1293,"value":2254,"marks":2255,"data":2256},"The advantage of this approach is that ",[],{},{"nodeType":1293,"value":2258,"marks":2259,"data":2261},"it is incredibly difficult for the target websites to do anything to stop it",[2260],{"type":1361},{},{"nodeType":1293,"value":2263,"marks":2264,"data":2265},". From their perspective, all they see is a legitimate browser accessing their website and logging in. None of the JavaScript tricks for checking the origin will work. They aren’t in a position to be able to see that the browser is secretly being controlled remotely by the victim user without their knowledge. ",[],{},{"nodeType":1294,"data":2267,"content":2268},{},[2269],{"nodeType":1293,"value":2270,"marks":2271,"data":2272},"On the downside, while noVNC can be extremely convincing, the illusion can sometimes be broken due to it not behaving exactly like a real website would due it being a graphical rendering. For example, something as simple as resizing the browser window can introduce render resolution issues. It’s also more difficult to scale for attacking large numbers of users than a reverse proxy technique.",[],{},{"nodeType":1294,"data":2274,"content":2275},{},[2276],{"nodeType":1293,"value":2277,"marks":2278,"data":2279},"Footnote: BitM is not to be confused with Browser-in-the-Browser (BitB), which is more of a malicious pop-up (think when a login button spawns a new browser window). ",[],{},{"nodeType":1354,"data":2281,"content":2282},{},[2283],{"nodeType":1293,"value":2284,"marks":2285,"data":2286},"Beyond initial access",[],{},{"nodeType":1294,"data":2288,"content":2289},{},[2290],{"nodeType":1293,"value":2291,"marks":2292,"data":2293},"So maybe you’re thinking now “OK, sounds kinda bad, but I’m not that worried. Maybe some user accounts get compromised by this method despite all my MFA protections, but at least the attacker only has temporary access, right?” ",[],{},{"nodeType":1294,"data":2295,"content":2296},{},[2297],{"nodeType":1293,"value":2298,"marks":2299,"data":2300},"In theory, access is temporary as sessions time out. And if spotted, the security team can respond by killing the authenticated sessions and forcing password changes for the compromised users. Then the attacker is back to square one, right? Their session is lost, they still don’t have MFA, and even the password they keylogged has now been changed.",[],{},{"nodeType":1294,"data":2302,"content":2303},{},[2304],{"nodeType":1293,"value":2305,"marks":2306,"data":2307},"In practice, it’s not this simple. We mentioned earlier how SSO portals are often the most common targets for these attacks. For most modern organizations, this means their core identity provider, which just so happens to be the gateway to accessing many other web applications, whether internal applications or a multitude of SaaS applications. ",[],{},{"nodeType":1294,"data":2309,"content":2310},{},[2311,2315,2324],{"nodeType":1293,"value":2312,"marks":2313,"data":2314},"Let’s consider the example of an organization using Okta where their Okta login portal has been used as the target for AitM phishing. A smart attacker is going to immediately leverage this access to establish authenticated sessions on every single application that Okta provides the user access to. They are also going to ",[],{},{"nodeType":1378,"data":2316,"content":2318},{"uri":2317},"https://pushsecurity.com/blog/okta-swa/",[2319],{"nodeType":1293,"value":2320,"marks":2321,"data":2323},"abuse Okta SWA",[2322],{"type":1386},{},{"nodeType":1293,"value":2325,"marks":2326,"data":2327}," to steal valid credentials for whichever applications support this method. And if that’s not enough, there are a variety of simple methods to achieve persistence on most downstream SaaS applications and sometimes even identity providers themselves.",[],{},{"nodeType":1294,"data":2329,"content":2330},{},[2331,2335,2344],{"nodeType":1293,"value":2332,"marks":2333,"data":2334},"While the full details of these persistence attacks are outside the scope of this article, more details on some key attacks can be found in a resource we created called the ",[],{},{"nodeType":1378,"data":2336,"content":2338},{"uri":2337},"https://github.com/pushsecurity/saas-attacks",[2339],{"nodeType":1293,"value":2340,"marks":2341,"data":2343},"SaaS attacks matrix",[2342],{"type":1386},{},{"nodeType":1293,"value":2345,"marks":2346,"data":2347},". Some of the most common techniques that apply here are: ",[],{},{"nodeType":1393,"data":2349,"content":2350},{},[2351,2372,2393,2414,2435],{"nodeType":1397,"data":2352,"content":2353},{},[2354],{"nodeType":1294,"data":2355,"content":2356},{},[2357,2360,2369],{"nodeType":1293,"value":37,"marks":2358,"data":2359},[],{},{"nodeType":1378,"data":2361,"content":2363},{"uri":2362},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/api_keys/description.md",[2364],{"nodeType":1293,"value":2365,"marks":2366,"data":2368},"SAT1004 - API keys",[2367],{"type":1386},{},{"nodeType":1293,"value":37,"marks":2370,"data":2371},[],{},{"nodeType":1397,"data":2373,"content":2374},{},[2375],{"nodeType":1294,"data":2376,"content":2377},{},[2378,2381,2390],{"nodeType":1293,"value":37,"marks":2379,"data":2380},[],{},{"nodeType":1378,"data":2382,"content":2384},{"uri":2383},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/link_sharing/description.md",[2385],{"nodeType":1293,"value":2386,"marks":2387,"data":2389},"SAT1022 - Link sharing",[2388],{"type":1386},{},{"nodeType":1293,"value":37,"marks":2391,"data":2392},[],{},{"nodeType":1397,"data":2394,"content":2395},{},[2396],{"nodeType":1294,"data":2397,"content":2398},{},[2399,2402,2411],{"nodeType":1293,"value":37,"marks":2400,"data":2401},[],{},{"nodeType":1378,"data":2403,"content":2405},{"uri":2404},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[2406],{"nodeType":1293,"value":2407,"marks":2408,"data":2410},"SAT1017 - Ghost logins",[2409],{"type":1386},{},{"nodeType":1293,"value":37,"marks":2412,"data":2413},[],{},{"nodeType":1397,"data":2415,"content":2416},{},[2417],{"nodeType":1294,"data":2418,"content":2419},{},[2420,2423,2432],{"nodeType":1293,"value":37,"marks":2421,"data":2422},[],{},{"nodeType":1378,"data":2424,"content":2426},{"uri":2425},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/oauth_tokens/description.md",[2427],{"nodeType":1293,"value":2428,"marks":2429,"data":2431},"SAT1027 - OAuth tokens",[2430],{"type":1386},{},{"nodeType":1293,"value":37,"marks":2433,"data":2434},[],{},{"nodeType":1397,"data":2436,"content":2437},{},[2438],{"nodeType":1294,"data":2439,"content":2440},{},[2441,2444,2453],{"nodeType":1293,"value":37,"marks":2442,"data":2443},[],{},{"nodeType":1378,"data":2445,"content":2447},{"uri":2446},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/shadow_workflows/description.md",[2448],{"nodeType":1293,"value":2449,"marks":2450,"data":2452},"SAT1033 - Shadow workflows",[2451],{"type":1386},{},{"nodeType":1293,"value":37,"marks":2454,"data":2455},[],{},{"nodeType":1294,"data":2457,"content":2458},{},[2459],{"nodeType":1293,"value":2460,"marks":2461,"data":2462},"Suddenly, containing the breach just got a LOT more complicated.",[],{},{"nodeType":1294,"data":2464,"content":2465},{},[2466,2470,2479],{"nodeType":1293,"value":2467,"marks":2468,"data":2469},"It’s not just application-level lateral movement and persistence to worry about, though. It’s possible the attacker can start moving laterally across other user accounts. If they have selected their targets well, they might even find they have admin access to some downstream SaaS application that has been configured for SAML logins using Okta. For example, maybe they compromise a finance employee who has admin access to their business expenses SaaS application. Then the attacker might be able to use a new technique like ",[],{},{"nodeType":1378,"data":2471,"content":2473},{"uri":2472},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/samljacking/description.md",[2474],{"nodeType":1293,"value":2475,"marks":2476,"data":2478},"SAMLjacking",[2477],{"type":1386},{},{"nodeType":1293,"value":2480,"marks":2481,"data":2482}," to start attacking other users in a watering hole attack to achieve lateral movement.",[],{},{"nodeType":1354,"data":2484,"content":2485},{},[2486],{"nodeType":1293,"value":2487,"marks":2488,"data":2489},"Video demo – chaining it all together",[],{},{"nodeType":1294,"data":2491,"content":2492},{},[2493],{"nodeType":1293,"value":2494,"marks":2495,"data":2496},"OK, so we’ve just jumped from an account compromise for initial access using an AitM phishing attack to bringing up a huge number of other connected techniques. Let’s look at a quick video demonstration of an AitM phishing attack chained together with post-exploitation steps for persistence and lateral movement so we can see how it all fits together.",[],{},{"nodeType":1294,"data":2498,"content":2499},{},[2500],{"nodeType":1293,"value":2501,"marks":2502,"data":2503},"In this case, we’ll use EvilnoVNC targeting Okta as the core example for the AitM phishing attack:",[],{},{"nodeType":1428,"data":2505,"content":2509},{"target":2506},{"sys":2507},{"id":2508,"type":1433,"linkType":1434},"QGTEWzmOL1vrgjXPuV4Gg",[],{"nodeType":1294,"data":2511,"content":2512},{},[2513],{"nodeType":1293,"value":2514,"marks":2515,"data":2516},"We can see here that AitM phishing attacks are not only highly effective even in the presence of MFA, but that post-exploitation steps have become so numerous that effective response and containment for even a low-privileged user account are now a significant challenge.",[],{},{"nodeType":1354,"data":2518,"content":2519},{},[2520],{"nodeType":1293,"value":2521,"marks":2522,"data":2523},"Post-exploitation automation is coming",[],{},{"nodeType":1294,"data":2525,"content":2526},{},[2527],{"nodeType":1293,"value":2528,"marks":2529,"data":2530},"There is a saying that attacks only become more effective over time. In the past, toolsets like Metasploit and Cobalt Strike became increasingly focused on post-exploitation and automation to enable much more sophisticated compromises.",[],{},{"nodeType":1294,"data":2532,"content":2533},{},[2534,2538,2551,2555,2560],{"nodeType":1293,"value":2535,"marks":2536,"data":2537},"As AitM becomes increasingly popular (for example, researchers at Lab539 have reported ",[],{},{"nodeType":1378,"data":2539,"content":2541},{"uri":2540},"https://www.lab539.com/blog/6-months-tracking-aitm-campaigns",[2542,2547],{"nodeType":1293,"value":2543,"marks":2544,"data":2546},"a significant ramp up in attacker infrastructure linked to AitM campaigns",[2545],{"type":1386},{},{"nodeType":1293,"value":2548,"marks":2549,"data":2550},")",[],{},{"nodeType":1293,"value":2552,"marks":2553,"data":2554}," it’s only a matter of time now before we see AitM phishing frameworks moving in the same direction and performing many of the lateral movement and persistence steps we saw above – automatically on every successful account compromise. The threat will increase ",[],{},{"nodeType":1293,"value":2556,"marks":2557,"data":2559},"significantly",[2558],{"type":1361},{},{"nodeType":1293,"value":2561,"marks":2562,"data":2563}," when this becomes the case.",[],{},{"nodeType":1354,"data":2565,"content":2566},{},[2567],{"nodeType":1293,"value":2568,"marks":2569,"data":2570},"Impact summary",[],{},{"nodeType":1294,"data":2572,"content":2573},{},[2574],{"nodeType":1293,"value":2575,"marks":2576,"data":2577},"We’ve covered a lot of ground here, so let’s take a step back and consider the key points of impact:",[],{},{"nodeType":1393,"data":2579,"content":2580},{},[2581,2591,2601],{"nodeType":1397,"data":2582,"content":2583},{},[2584],{"nodeType":1294,"data":2585,"content":2586},{},[2587],{"nodeType":1293,"value":2588,"marks":2589,"data":2590},"AitM phishing techniques are highly effective and increasingly common, and can bypass most common forms of MFA.",[],{},{"nodeType":1397,"data":2592,"content":2593},{},[2594],{"nodeType":1294,"data":2595,"content":2596},{},[2597],{"nodeType":1293,"value":2598,"marks":2599,"data":2600},"These techniques are being used by real threat actors and red teamers alike, with both criminal and open-source tools available for performing these attacks.",[],{},{"nodeType":1397,"data":2602,"content":2603},{},[2604],{"nodeType":1294,"data":2605,"content":2606},{},[2607],{"nodeType":1293,"value":2608,"marks":2609,"data":2610},"There are many options for lateral movement and persistence after an account compromise, so simple containment actions like password resets for SSO credentials are not nearly enough to contain a knowledgeable attacker.",[],{},{"nodeType":1354,"data":2612,"content":2613},{},[2614],{"nodeType":1293,"value":2615,"marks":2616,"data":2617},"What can blue teams do about it?",[],{},{"nodeType":1294,"data":2619,"content":2620},{},[2621],{"nodeType":1293,"value":2622,"marks":2623,"data":2624},"It’s important that organizations develop their capability to detect and respond to AitM attacks. Possible approaches include:",[],{},{"nodeType":1393,"data":2626,"content":2627},{},[2628,2643,2679,2707],{"nodeType":1397,"data":2629,"content":2630},{},[2631],{"nodeType":1294,"data":2632,"content":2633},{},[2634,2639],{"nodeType":1293,"value":2635,"marks":2636,"data":2638},"Move to FIDO MFA where possible",[2637],{"type":1361},{},{"nodeType":1293,"value":2640,"marks":2641,"data":2642}," (though, if no more susceptible backup methods are enabled, this does introduce operational challenges if passkeys are lost).",[],{},{"nodeType":1397,"data":2644,"content":2645},{},[2646],{"nodeType":1294,"data":2647,"content":2648},{},[2649,2654,2658,2663,2667,2676],{"nodeType":1293,"value":2650,"marks":2651,"data":2653},"Detect and block known-bad malicious",[2652],{"type":1361},{},{"nodeType":1293,"value":2655,"marks":2656,"data":2657}," ",[],{},{"nodeType":1293,"value":2659,"marks":2660,"data":2662},"sites",[2661],{"type":1361},{},{"nodeType":1293,"value":2664,"marks":2665,"data":2666}," used in phishing campaigns. There are many threat intelligence feeds that can be ingested to achieve this. Usually, a domain has to be used in a malicious campaign before it can be catalogued – meaning there's typically a window of opportunity before the infrastructure is burned. That said, security researchers at Lab539 (yes, another shout out) have developed a way of identifying sites running AitM tooling – even before they are used for the first time. ",[],{},{"nodeType":1378,"data":2668,"content":2670},{"uri":2669},"https://www.lab539.com/aitm",[2671],{"nodeType":1293,"value":2672,"marks":2673,"data":2675},"You can sign up to get access to their feed here.",[2674],{"type":1386},{},{"nodeType":1293,"value":37,"marks":2677,"data":2678},[],{},{"nodeType":1397,"data":2680,"content":2681},{},[2682],{"nodeType":1294,"data":2683,"content":2684},{},[2685,2690,2694,2703],{"nodeType":1293,"value":2686,"marks":2687,"data":2689},"Introduce controls to detect phishing toolkits and cloned websites",[2688],{"type":1361},{},{"nodeType":1293,"value":2691,"marks":2692,"data":2693},". You can never rely on blocking malicious sites via TI feeds alone, so additional layers of defence are required. Push customers benefit from detection of AitM toolkits like Evilginx and EvilNoVNC in the browser (more to come on this soon!), while Thinkst Canary has developed ",[],{},{"nodeType":1378,"data":2695,"content":2697},{"uri":2696},"https://blog.thinkst.com/2024/01/defending-against-the-attack-of-the-cloned-websites.html",[2698],{"nodeType":1293,"value":2699,"marks":2700,"data":2702},"methods of detecting whenever your website or login portal is cloned",[2701],{"type":1386},{},{"nodeType":1293,"value":2704,"marks":2705,"data":2706}," – very cool.  ",[],{},{"nodeType":1397,"data":2708,"content":2709},{},[2710],{"nodeType":1294,"data":2711,"content":2712},{},[2713,2718],{"nodeType":1293,"value":2714,"marks":2715,"data":2717},"Update IR playbooks to to deal with SSO account compromise,",[2716],{"type":1361},{},{"nodeType":1293,"value":2719,"marks":2720,"data":2721}," factoring in lateral movement and persistence across cloud apps. This really necessitates that you understand what business apps your organization is using, how they are accessed (e.g. SSO or username and password) and what functionality exists that could be abused by an attacker. ",[],{},{"nodeType":1294,"data":2723,"content":2724},{},[2725,2729,2737],{"nodeType":1293,"value":2726,"marks":2727,"data":2728},"If you want to know more about how Push detects and blocks phishing tools in the browser, you can ",[],{},{"nodeType":1378,"data":2730,"content":2732},{"uri":2731},"https://pushsecurity.com/blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser/",[2733],{"nodeType":1293,"value":2734,"marks":2735,"data":2736},"check out our article here",[],{},{"nodeType":1293,"value":2738,"marks":2739,"data":2740},". ",[],{},{"nodeType":1354,"data":2742,"content":2743},{},[2744],{"nodeType":1293,"value":2745,"marks":2746,"data":2747},"Conclusion",[],{},{"nodeType":1294,"data":2749,"content":2750},{},[2751],{"nodeType":1293,"value":2752,"marks":2753,"data":2754},"We’ve seen in this article how there are multiple ways to perform AitM phishing attacks and how they can be extremely effective at targeting users even when their accounts are protected by MFA.  ",[],{},{"nodeType":1294,"data":2756,"content":2757},{},[2758],{"nodeType":1293,"value":2759,"marks":2760,"data":2761},"Very few organizations are universally using phishing-resistant MFA, such as FIDO-based methods, and even those that do often have fallback options to handle situations where they cannot be used and/or tokens malfunction or are lost. Therefore, the vast majority of organizations are at risk of AitM phishing attacks.",[],{},{"nodeType":1294,"data":2763,"content":2764},{},[2765],{"nodeType":1293,"value":2766,"marks":2767,"data":2768},"To make things worse, there are lateral movement and persistence techniques that can be exploited to greatly extend the depth of compromise even for a single low-privilege user account. This makes response and containment a significant challenge.",[],{},{"nodeType":1294,"data":2770,"content":2771},{},[2772,2776,2785,2789,2798,2802,2811,2815,2824],{"nodeType":1293,"value":2773,"marks":2774,"data":2775},"Phishing attacks are clearly evolving. Phishing attacks are no longer limited to email-based delivery mechanisms or being hosted on custom domains. There are many options now for delivering phishing attacks using ",[],{},{"nodeType":1378,"data":2777,"content":2779},{"uri":2778},"https://pushsecurity.com/blog/slack-phishing-for-initial-access/",[2780],{"nodeType":1293,"value":2781,"marks":2782,"data":2784},"Slack",[2783],{"type":1386},{},{"nodeType":1293,"value":2786,"marks":2787,"data":2788}," or ",[],{},{"nodeType":1378,"data":2790,"content":2792},{"uri":2791},"https://pushsecurity.com/blog/phishing-microsoft-teams-for-initial-access/",[2793],{"nodeType":1293,"value":2794,"marks":2795,"data":2797},"Microsoft Teams",[2796],{"type":1386},{},{"nodeType":1293,"value":2799,"marks":2800,"data":2801},", using ",[],{},{"nodeType":1378,"data":2803,"content":2805},{"uri":2804},"https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/",[2806],{"nodeType":1293,"value":2807,"marks":2808,"data":2810},"SAMLjacking attacks",[2809],{"type":1386},{},{"nodeType":1293,"value":2812,"marks":2813,"data":2814}," to host the initial landing page on legitimate SaaS web domains or even using ",[],{},{"nodeType":1378,"data":2816,"content":2818},{"uri":2817},"https://pushsecurity.com/blog/oktajacking/",[2819],{"nodeType":1293,"value":2820,"marks":2821,"data":2823},"Okta to keylog credentials",[2822],{"type":1386},{},{"nodeType":1293,"value":2825,"marks":2826,"data":2827}," on behalf of the attacker. ",[],{},{"nodeType":1294,"data":2829,"content":2830},{},[2831],{"nodeType":1293,"value":2832,"marks":2833,"data":2834},"Increasingly, we should expect to see AitM toolkits being used as a standard part of phishing campaigns, and featured in Initial Access Broker tooling – AitM will effectively supersede legacy phishing methods in line with MFA adoption. Rather, it already is. ",[],{},{"nodeType":1350,"data":2836,"content":2837},{},[],{"nodeType":1294,"data":2839,"content":2840},{},[2841],{"nodeType":1293,"value":2842,"marks":2843,"data":2844},"If you're interested in seeing some more AitM tools in action, you can watch our recent webinar on-demand via the link below. ",[],{},{"nodeType":1428,"data":2846,"content":2849},{"target":2847},{"sys":2848},{"id":2080,"type":1433,"linkType":1434},[],{"nodeType":1294,"data":2851,"content":2852},{},[2853],{"nodeType":1293,"value":37,"marks":2854,"data":2855},[],{},"Phishing 2.0 – how phishing toolkits are evolving with AitM","Attackers are using Adversary in the Middle (AitM) phishing toolkits to bypass MFA. We look at what AitM is, how it works, and what you can do about it.","2024-05-23T00:00:00.000Z","phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm",{"items":2861},[2862,2864],{"sys":2863,"name":1313},{"id":1312},{"sys":2865,"name":1317},{"id":1316},{"items":2867},[2868],{"fullName":2869,"firstName":2870,"jobTitle":2871,"profilePicture":2872},"Luke Jennings","Luke","Vice President, R&D",{"url":2873},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"__typename":1321,"sys":2875,"content":2877,"title":3385,"synopsis":3386,"hashTags":118,"publishedDate":1990,"slug":3387,"tagsCollection":3388,"authorsCollection":3394},{"id":2876},"7JngmuGwqKvYLzU8bGMTQD",{"json":2878},{"nodeType":1295,"data":2879,"content":2880},{},[2881,2887,2893,2905,2917,2920,2928,2934,2941,2948,2955,2962,2968,2975,2980,2983,2991,2998,3031,3038,3046,3053,3060,3067,3073,3081,3088,3093,3100,3121,3128,3136,3143,3150,3157,3162,3169,3186,3189,3197,3211,3217,3251,3259,3262,3270,3277,3291,3296,3302,3308,3315,3320,3327,3332,3335,3342,3348,3353,3358,3379],{"nodeType":1294,"data":2882,"content":2883},{},[2884],{"nodeType":1293,"value":1332,"marks":2885,"data":2886},[],{},{"nodeType":1294,"data":2888,"content":2889},{},[2890],{"nodeType":1293,"value":1346,"marks":2891,"data":2892},[],{},{"nodeType":1294,"data":2894,"content":2895},{},[2896,2900],{"nodeType":1293,"value":2897,"marks":2898,"data":2899},"A key challenge with phishing detection is that based on the known-bad indicators that we as an industry use to commonly detect phishing pages, pretty much every phishing attack looks different and uses a unique combination of domain, URL, IPs, page composition, target app, etc. ",[],{},{"nodeType":1293,"value":2901,"marks":2902,"data":2904},"Effectively, every phishing attack is completely novel. You might even describe them as “zero-days” (cue the collective sharp intake of breath)...",[2903],{"type":1361},{},{"nodeType":1294,"data":2906,"content":2907},{},[2908,2912],{"nodeType":1293,"value":2909,"marks":2910,"data":2911},"The goal here isn’t to sensationalize phishing attacks — quite the opposite. Rather, this shines a light on the state of phishing detection controls. ",[],{},{"nodeType":1293,"value":2913,"marks":2914,"data":2916},"Frankly, if every phishing attack is a zero-day, something has gone very wrong with how we detect these attacks…",[2915],{"type":1361},{},{"nodeType":1350,"data":2918,"content":2919},{},[],{"nodeType":1354,"data":2921,"content":2922},{},[2923],{"nodeType":1293,"value":2924,"marks":2925,"data":2927},"Phishing detection 101",[2926],{"type":1361},{},{"nodeType":1294,"data":2929,"content":2930},{},[2931],{"nodeType":1293,"value":1502,"marks":2932,"data":2933},[],{},{"nodeType":1294,"data":2935,"content":2936},{},[2937],{"nodeType":1293,"value":2938,"marks":2939,"data":2940},"Phishing detection, at its core, relies on blocklists made up of indicators of compromise (IoCs) relating to phishing pages that have been successfully identified as malicious. These IoCs consist of malicious domains, URLs, and IPs that have appeared in an attack. ",[],{},{"nodeType":1294,"data":2942,"content":2943},{},[2944],{"nodeType":1293,"value":2945,"marks":2946,"data":2947},"IoCs are collected by security vendors and service providers across a range of sources. Mostly though, the malicious page needs to be used in a phishing campaign before it has a chance of being detected. This means that a would-be victim needs to interact with it in some way — either by falling for a phishing attack, or reporting it as suspicious. ",[],{},{"nodeType":1294,"data":2949,"content":2950},{},[2951],{"nodeType":1293,"value":2952,"marks":2953,"data":2954},"Once a page is flagged, it can be investigated — either manually (by a security person) or automatically (by a product/tool). If the page can be accessed and analyzed, and malicious content is found (more on this later) then the page’s IoCs can be collected and added to a blocklist. ",[],{},{"nodeType":1294,"data":2956,"content":2957},{},[2958],{"nodeType":1293,"value":2959,"marks":2960,"data":2961},"This information will then begin to circulate across the various threat intelligence feeds and security products leveraging this information. The majority of phishing detection and control enforcement is focused at the email and network layer — typically at the Secure Email Gateway (SEG), Secure Web Gateway (SWG)/proxy, or both. ",[],{},{"nodeType":1428,"data":2963,"content":2967},{"target":2964},{"sys":2965},{"id":2966,"type":1433,"linkType":1434},"7xPrHlTjDI1Lc620fAnxvX",[],{"nodeType":1294,"data":2969,"content":2970},{},[2971],{"nodeType":1293,"value":2972,"marks":2973,"data":2974},"If you’re following the thought pattern here, you can probably already see the root of the problem. To detect and block a phishing page, it needs to be used in an attack first…",[],{},{"nodeType":1428,"data":2976,"content":2979},{"target":2977},{"sys":2978},{"id":1980,"type":1433,"linkType":1434},[],{"nodeType":1350,"data":2981,"content":2982},{},[],{"nodeType":1354,"data":2984,"content":2985},{},[2986],{"nodeType":1293,"value":2987,"marks":2988,"data":2990},"Why most phishing attacks are zero-day",[2989],{"type":1361},{},{"nodeType":1294,"data":2992,"content":2993},{},[2994],{"nodeType":1293,"value":2995,"marks":2996,"data":2997},"Attackers know that phishing detection and blocking:",[],{},{"nodeType":1393,"data":2999,"content":3000},{},[3001,3011,3021],{"nodeType":1397,"data":3002,"content":3003},{},[3004],{"nodeType":1294,"data":3005,"content":3006},{},[3007],{"nodeType":1293,"value":3008,"marks":3009,"data":3010},"Relies on blocklisting IoCs like domains, URLs and IPs",[],{},{"nodeType":1397,"data":3012,"content":3013},{},[3014],{"nodeType":1294,"data":3015,"content":3016},{},[3017],{"nodeType":1293,"value":3018,"marks":3019,"data":3020},"Is situated at the email and network layer",[],{},{"nodeType":1397,"data":3022,"content":3023},{},[3024],{"nodeType":1294,"data":3025,"content":3026},{},[3027],{"nodeType":1293,"value":3028,"marks":3029,"data":3030},"Requires that a page is accessed and analyzed before it can be blocked",[],{},{"nodeType":1294,"data":3032,"content":3033},{},[3034],{"nodeType":1293,"value":3035,"marks":3036,"data":3037},"These methods have remained practically unchanged for more than a decade. So it stands to reason that attackers are getting pretty good at avoiding them. ",[],{},{"nodeType":2083,"data":3039,"content":3040},{},[3041],{"nodeType":1293,"value":3042,"marks":3043,"data":3045},"It’s easy for attackers to evade IoC-based detections",[3044],{"type":1361},{},{"nodeType":1294,"data":3047,"content":3048},{},[3049],{"nodeType":1293,"value":3050,"marks":3051,"data":3052},"Phishing domains are highly disposable by nature. Attackers are buying them in bulk, constantly taking over legitimate domains, and generally planning for the fact that they’ll get through a lot of them.",[],{},{"nodeType":1294,"data":3054,"content":3055},{},[3056],{"nodeType":1293,"value":3057,"marks":3058,"data":3059},"Modern phishing architecture is also able to dynamically rotate and update commonly signatured elements — for example, by dynamically rotating the links served to visitors from a continually refreshed pool (so every person that clicks the link gets served a different URL) and even going as far as using things like one-time magic links (which also means that any security team members trying to investigate the page later won’t be able to do so). ",[],{},{"nodeType":1294,"data":3061,"content":3062},{},[3063],{"nodeType":1293,"value":3064,"marks":3065,"data":3066},"You could look at which IP address the user connects to, but these days it’s very simple for attackers to add a new IP to their cloud-hosted server. If a domain is flagged as known-bad, the attacker only has to register a new domain, or compromise a WordPress server on an already trusted domain. Both of these things are happening on a massive scale as attackers pre-plan for the fact that their domains will be burned at some point. ",[],{},{"nodeType":1294,"data":3068,"content":3069},{},[3070],{"nodeType":1293,"value":1608,"marks":3071,"data":3072},[],{},{"nodeType":2083,"data":3074,"content":3075},{},[3076],{"nodeType":1293,"value":3077,"marks":3078,"data":3080},"Phishing doesn’t just happen over email",[3079],{"type":1361},{},{"nodeType":1294,"data":3082,"content":3083},{},[3084],{"nodeType":1293,"value":3085,"marks":3086,"data":3087},"To evade email-based detections, attackers are going multi- and cross-channel with their attacks. ",[],{},{"nodeType":1428,"data":3089,"content":3092},{"target":3090},{"sys":3091},{"id":1460,"type":1433,"linkType":1434},[],{"nodeType":1294,"data":3094,"content":3095},{},[3096],{"nodeType":1293,"value":3097,"marks":3098,"data":3099},"Not only are attackers using different phishing vectors, they’re chaining them together to prevent security tools from intercepting the link. So for example, a social media message that sends you a non-malicious PDF with a link embedded in it, that finally directs you to a malicious webpage.",[],{},{"nodeType":1294,"data":3101,"content":3102},{},[3103,3107,3111,3114,3118],{"nodeType":1293,"value":3104,"marks":3105,"data":3106},"It’s worth also pointing out the limitations of email-based solutions here too. Email has some additional checks around the sender’s reputation and things like DMARC/DKIM, but these don’t actually identify malicious ",[],{},{"nodeType":1293,"value":1470,"marks":3108,"data":3110},[3109],{"type":1361},{},{"nodeType":1293,"value":1475,"marks":3112,"data":3113},[],{},{"nodeType":1293,"value":1479,"marks":3115,"data":3117},[3116],{"type":1361},{},{"nodeType":1293,"value":1484,"marks":3119,"data":3120},[],{},{"nodeType":1294,"data":3122,"content":3123},{},[3124],{"nodeType":1293,"value":3125,"marks":3126,"data":3127},"In any case, while modern email solutions can bring a lot more to the table, neither email or network (proxy) based tools can’t definitively know that a page is malicious unless they can access the page and analyze it… ",[],{},{"nodeType":2083,"data":3129,"content":3130},{},[3131],{"nodeType":1293,"value":3132,"marks":3133,"data":3135},"Attackers are preventing their pages from being analyzed",[3134],{"type":1361},{},{"nodeType":1294,"data":3137,"content":3138},{},[3139],{"nodeType":1293,"value":3140,"marks":3141,"data":3142},"Both email and network (proxy) based solutions rely on being able to inspect and analyze a page to identify whether it is malicious or not, after which IoCs are generated that can be enforced when a link is clicked (or received in your email inbox).",[],{},{"nodeType":1294,"data":3144,"content":3145},{},[3146],{"nodeType":1293,"value":3147,"marks":3148,"data":3149},"Modern phishing pages aren’t static HTML — like most other modern web pages, these are dynamic web apps rendered in the browser, with JavaScript dynamically rewriting the page and launching the malicious content. This means that most basic, static checks fail to identify the malicious content running on the page. ",[],{},{"nodeType":1294,"data":3151,"content":3152},{},[3153],{"nodeType":1293,"value":3154,"marks":3155,"data":3156},"To address this, both email and network security tools will try to explode links in a sandbox to observe the page’s behavior. But attackers are getting around this simply by implementing bot protection by requiring user interaction with a CAPTCHA or Cloudflare Turnstile. ",[],{},{"nodeType":1428,"data":3158,"content":3161},{"target":3159},{"sys":3160},{"id":1432,"type":1433,"linkType":1434},[],{"nodeType":1294,"data":3163,"content":3164},{},[3165],{"nodeType":1293,"value":3166,"marks":3167,"data":3168},"Even if you can get past Turnstile, then you’ll need to supply the correct URL parameters and headers, and execute JavaScript, to be served the malicious page. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",[],{},{"nodeType":1294,"data":3170,"content":3171},{},[3172,3175,3183],{"nodeType":1293,"value":1647,"marks":3173,"data":3174},[],{},{"nodeType":1378,"data":3176,"content":3178},{"uri":3177},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/?utm_campaign=12100141-FY25Q2_Bleeping-Computer-Article&utm_source=bleepingcomputer&utm_medium=sponsored&utm_content=external-article",[3179],{"nodeType":1293,"value":1655,"marks":3180,"data":3182},[3181],{"type":1386},{},{"nodeType":1293,"value":1660,"marks":3184,"data":3185},[],{},{"nodeType":1350,"data":3187,"content":3188},{},[],{"nodeType":1354,"data":3190,"content":3191},{},[3192],{"nodeType":1293,"value":3193,"marks":3194,"data":3196},"Phishing attacks are zero-day because phishing detection is post mortem",[3195],{"type":1361},{},{"nodeType":1294,"data":3198,"content":3199},{},[3200,3204,3208],{"nodeType":1293,"value":3201,"marks":3202,"data":3203},"The result of these detection evasion and obfuscation techniques is that ",[],{},{"nodeType":1293,"value":1773,"marks":3205,"data":3207},[3206],{"type":1361},{},{"nodeType":1293,"value":1534,"marks":3209,"data":3210},[],{},{"nodeType":1294,"data":3212,"content":3213},{},[3214],{"nodeType":1293,"value":1784,"marks":3215,"data":3216},[],{},{"nodeType":1294,"data":3218,"content":3219},{},[3220,3223,3227,3230,3234,3237,3241,3244,3248],{"nodeType":1293,"value":1791,"marks":3221,"data":3222},[],{},{"nodeType":1293,"value":1795,"marks":3224,"data":3226},[3225],{"type":1361},{},{"nodeType":1293,"value":1800,"marks":3228,"data":3229},[],{},{"nodeType":1293,"value":1804,"marks":3231,"data":3233},[3232],{"type":1361},{},{"nodeType":1293,"value":1809,"marks":3235,"data":3236},[],{},{"nodeType":1293,"value":1804,"marks":3238,"data":3240},[3239],{"type":1361},{},{"nodeType":1293,"value":1817,"marks":3242,"data":3243},[],{},{"nodeType":1293,"value":1821,"marks":3245,"data":3247},[3246],{"type":1361},{},{"nodeType":1293,"value":1826,"marks":3249,"data":3250},[],{},{"nodeType":1294,"data":3252,"content":3253},{},[3254],{"nodeType":1293,"value":3255,"marks":3256,"data":3258},"The result? Most phishing attacks are entirely novel because phishing detection is inherently post mortem — it relies on known-bads. How does something become known-bad? When a user is phished…",[3257],{"type":1361},{},{"nodeType":1350,"data":3260,"content":3261},{},[],{"nodeType":1354,"data":3263,"content":3264},{},[3265],{"nodeType":1293,"value":3266,"marks":3267,"data":3269},"To fix phishing detection, we need real-time analysis",[3268],{"type":1361},{},{"nodeType":1294,"data":3271,"content":3272},{},[3273],{"nodeType":1293,"value":3274,"marks":3275,"data":3276},"It’s clear that how we detect and block phishing attacks is fundamentally flawed. The good news is, we’ve been here before. ",[],{},{"nodeType":1294,"data":3278,"content":3279},{},[3280,3284,3288],{"nodeType":1293,"value":3281,"marks":3282,"data":3283},"When endpoint attacks skyrocketed in the late 2000s / early 2010s, they took advantage of the fact that defenders were trying to detect malware with primarily network-based detections, signature-based analysis of files, and running files in sandboxes (which was reliably defeated with sandbox-aware malware and using things as simple as putting an execution delay in the code). But this gave way to EDR, which presented a better way of observing and intercepting malicious software in ",[],{},{"nodeType":1293,"value":1529,"marks":3285,"data":3287},[3286],{"type":1361},{},{"nodeType":1293,"value":1534,"marks":3289,"data":3290},[],{},{"nodeType":1428,"data":3292,"content":3295},{"target":3293},{"sys":3294},{"id":1541,"type":1433,"linkType":1434},[],{"nodeType":1294,"data":3297,"content":3298},{},[3299],{"nodeType":1293,"value":1547,"marks":3300,"data":3301},[],{},{"nodeType":1294,"data":3303,"content":3304},{},[3305],{"nodeType":1293,"value":1554,"marks":3306,"data":3307},[],{},{"nodeType":1294,"data":3309,"content":3310},{},[3311],{"nodeType":1293,"value":3312,"marks":3313,"data":3314},"In many ways, the browser is the new Operating System. It’s where modern work predominantly takes place — and where attacks are happening too.  ",[],{},{"nodeType":1428,"data":3316,"content":3319},{"target":3317},{"sys":3318},{"id":1561,"type":1433,"linkType":1434},[],{"nodeType":1294,"data":3321,"content":3322},{},[3323],{"nodeType":1293,"value":3324,"marks":3325,"data":3326},"To stop phishing attacks as they happen, we need to be able to observe the page in real-time, as the user sees it from inside the browser. Not in a sandbox — seeing the real page, at the same time as the user. Only then can we build the detection and containment controls required to move phishing beyond the current cat-and-mouse game, where attackers are always two steps ahead. ",[],{},{"nodeType":1428,"data":3328,"content":3331},{"target":3329},{"sys":3330},{"id":1732,"type":1433,"linkType":1434},[],{"nodeType":1350,"data":3333,"content":3334},{},[],{"nodeType":1354,"data":3336,"content":3337},{},[3338],{"nodeType":1293,"value":1848,"marks":3339,"data":3341},[3340],{"type":1361},{},{"nodeType":1294,"data":3343,"content":3344},{},[3345],{"nodeType":1293,"value":1856,"marks":3346,"data":3347},[],{},{"nodeType":1428,"data":3349,"content":3352},{"target":3350},{"sys":3351},{"id":1745,"type":1433,"linkType":1434},[],{"nodeType":1428,"data":3354,"content":3357},{"target":3355},{"sys":3356},{"id":1980,"type":1433,"linkType":1434},[],{"nodeType":3359,"data":3360,"content":3361},"blockquote",{},[3362],{"nodeType":1294,"data":3363,"content":3364},{},[3365,3368,3376],{"nodeType":1293,"value":1960,"marks":3366,"data":3367},[],{},{"nodeType":1378,"data":3369,"content":3371},{"uri":3370},"https://pushsecurity.com/demo?utm_campaign=12100141-FY25Q2_Bleeping-Computer-Article&utm_source=bleepingcomputer&utm_medium=sponsored&utm_content=external-article",[3372],{"nodeType":1293,"value":1968,"marks":3373,"data":3375},[3374],{"type":1386},{},{"nodeType":1293,"value":1973,"marks":3377,"data":3378},[],{},{"nodeType":1294,"data":3380,"content":3381},{},[3382],{"nodeType":1293,"value":37,"marks":3383,"data":3384},[],{},"Why most phishing attacks feel like a zero-day","Most phishing attacks involve a phishing page that has never been seen before. When detection relies on known-bad, this makes every attack feel like a zero-day.","why-most-phishing-attacks-feel-like-a-zero-day",{"items":3389},[3390,3392],{"sys":3391,"name":1317},{"id":1316},{"sys":3393,"name":1313},{"id":1312},{"items":3395},[3396],{"fullName":2001,"firstName":2002,"jobTitle":2003,"profilePicture":3397},{"url":2005},{"items":3399},[3400],{"fullName":3401,"firstName":3402,"jobTitle":3403,"profilePicture":3404},"Andy Waugh","Andy","VP Product",{"url":3405},"https://images.ctfassets.net/y1cdw1ablpvd/3Rf76rJn6S9inMb4dUnAIJ/0a787f8141d05b95300e2fe77c4493fa/DSC_6868.jpg",{"json":3407,"links":3749},{"nodeType":1295,"data":3408,"content":3409},{},[3410,3417,3423,3430,3449,3478,3485,3569,3588,3591,3598,3616,3623,3630,3633,3640,3686,3693,3710,3717,3720,3727,3734],{"nodeType":1294,"data":3411,"content":3412},{},[3413],{"nodeType":1293,"value":3414,"marks":3415,"data":3416},"Mail rules are a handy feature found in most email clients. You might have used them to forward emails to your teammates while you’re off sipping Piña coladas, or to move incoming email from that spammy colleague to the ‘don’t read’ folder.",[],{},{"nodeType":1428,"data":3418,"content":3422},{"target":3419},{"sys":3420},{"id":3421,"type":1433,"linkType":1434},"7xLVXoCCjansV1u50e2pbM",[],{"nodeType":1294,"data":3424,"content":3425},{},[3426],{"nodeType":1293,"value":3427,"marks":3428,"data":3429},"Sadly for us defenders, they’re just as useful for attackers. After gaining access to a victim's account, attackers will often create a mail rule inside their mailbox as a way to maintain stealthy access. This mail rule can do anything a normal mail rule could but is usually used to forward emails matching sensitive keywords, like ‘invoice’ or ‘payment’, to an external email address controlled by the attacker.",[],{},{"nodeType":3359,"data":3431,"content":3432},{},[3433],{"nodeType":1294,"data":3434,"content":3435},{},[3436,3440,3445],{"nodeType":1293,"value":3437,"marks":3438,"data":3439},"This gives the ",[],{},{"nodeType":1293,"value":3441,"marks":3442,"data":3444},"attacker persistent access to the mailbox",[3443],{"type":1361},{},{"nodeType":1293,"value":3446,"marks":3447,"data":3448},". Even if the victim's password is changed, they turn on MFA, or their workstation is completely rebuilt - as long as the rule stays in place, it remains effective.",[],{},{"nodeType":1294,"data":3450,"content":3451},{},[3452,3456,3465,3469,3474],{"nodeType":1293,"value":3453,"marks":3454,"data":3455},"As another example, in ",[],{},{"nodeType":1378,"data":3457,"content":3459},{"uri":3458},"https://www.reddit.com/r/sysadmin/comments/6l63x6/malicious_outlook_rules/",[3460],{"nodeType":1293,"value":3461,"marks":3462,"data":3464},"this Reddit thread",[3463],{"type":1386},{},{"nodeType":1293,"value":3466,"marks":3467,"data":3468}," the author describes how mail rules were used to ",[],{},{"nodeType":1293,"value":3470,"marks":3471,"data":3473},"delete ",[3472],{"type":312},{},{"nodeType":1293,"value":3475,"marks":3476,"data":3477},"any emails the affected user received from the company’s Chief Finance Officer (CFO) so that the attacker could pretend to be the CFO, sending them fake emails to convince them to transfer out company funds.",[],{},{"nodeType":1294,"data":3479,"content":3480},{},[3481],{"nodeType":1293,"value":3482,"marks":3483,"data":3484},"Business Email Compromise (BEC) like this is the most popular type of attack at the moment, causing damages well into the billions according to the FBI. Here are just a few publicly documented breaches involving mail rules:",[],{},{"nodeType":1393,"data":3486,"content":3487},{},[3488,3508,3528,3549],{"nodeType":1397,"data":3489,"content":3490},{},[3491],{"nodeType":1294,"data":3492,"content":3493},{},[3494,3497,3505],{"nodeType":1293,"value":37,"marks":3495,"data":3496},[],{},{"nodeType":1378,"data":3498,"content":3500},{"uri":3499},"https://www.sans.org/dataincident2020",[3501],{"nodeType":1293,"value":3502,"marks":3503,"data":3504},"SANS: 28,000 PII records lost",[],{},{"nodeType":1293,"value":37,"marks":3506,"data":3507},[],{},{"nodeType":1397,"data":3509,"content":3510},{},[3511],{"nodeType":1294,"data":3512,"content":3513},{},[3514,3517,3525],{"nodeType":1293,"value":37,"marks":3515,"data":3516},[],{},{"nodeType":1378,"data":3518,"content":3520},{"uri":3519},"https://www.ic3.gov/Media/News/2020/201204.pdf",[3521],{"nodeType":1293,"value":3522,"marks":3523,"data":3524},"FBI report: BEC involving malicious mail rules costs company $175k",[],{},{"nodeType":1293,"value":37,"marks":3526,"data":3527},[],{},{"nodeType":1397,"data":3529,"content":3530},{},[3531],{"nodeType":1294,"data":3532,"content":3533},{},[3534,3537,3545],{"nodeType":1293,"value":37,"marks":3535,"data":3536},[],{},{"nodeType":1378,"data":3538,"content":3540},{"uri":3539},"https://www.reddit.com/r/Office365/comments/ej0wkx/hacker_created_forwarding_rules_for_users_account/",[3541],{"nodeType":1293,"value":3542,"marks":3543,"data":3544},"Reddit thread: Hacker created forwarding rule for user's account",[],{},{"nodeType":1293,"value":3546,"marks":3547,"data":3548}," ",[],{},{"nodeType":1397,"data":3550,"content":3551},{},[3552],{"nodeType":1294,"data":3553,"content":3554},{},[3555,3558,3566],{"nodeType":1293,"value":37,"marks":3556,"data":3557},[],{},{"nodeType":1378,"data":3559,"content":3561},{"uri":3560},"https://www.microsoft.com/security/blog/2021/06/14/behind-the-scenes-of-business-email-compromise-using-cross-domain-threat-data-to-disrupt-a-large-bec-infrastructure/",[3562],{"nodeType":1293,"value":3563,"marks":3564,"data":3565},"Microsoft case study of BEC operation using mail rules",[],{},{"nodeType":1293,"value":37,"marks":3567,"data":3568},[],{},{"nodeType":1294,"data":3570,"content":3571},{},[3572,3576,3584],{"nodeType":1293,"value":3573,"marks":3574,"data":3575},"You can read ",[],{},{"nodeType":1378,"data":3577,"content":3579},{"uri":3578},"/blog/case-study-business-email-compromise-bec-attack-nearly-cost-us-millions/",[3580],{"nodeType":1293,"value":3581,"marks":3582,"data":3583},"this case study",[],{},{"nodeType":1293,"value":3585,"marks":3586,"data":3587}," of a how a real Business Email Compromise (BEC) attack played out at an engineering firm that we interviewed.",[],{},{"nodeType":1350,"data":3589,"content":3590},{},[],{"nodeType":1354,"data":3592,"content":3593},{},[3594],{"nodeType":1293,"value":3595,"marks":3596,"data":3597},"How likely is this to actually happen?",[],{},{"nodeType":1294,"data":3599,"content":3600},{},[3601,3604,3612],{"nodeType":1293,"value":37,"marks":3602,"data":3603},[],{},{"nodeType":1378,"data":3605,"content":3607},{"uri":3606},"https://attack.mitre.org/techniques/T1114/003/",[3608],{"nodeType":1293,"value":3609,"marks":3610,"data":3611},"MITRE lists threat groups",[],{},{"nodeType":1293,"value":3613,"marks":3614,"data":3615}," that have been known to use mail rules in this way as part of targeted attacks. However, most often, this technique is used opportunistically.",[],{},{"nodeType":1294,"data":3617,"content":3618},{},[3619],{"nodeType":1293,"value":3620,"marks":3621,"data":3622},"Attackers run phishing campaigns containing thousands of harvested emails from multiple companies. A classic scenario is to trick a user into logging in to a fake Office 365 or Google Workspace login screen, stealing their credentials. Those credentials are then used to create a malicious mail rule inside the compromised user's mailbox. For scale and speed, this process is completely automated.",[],{},{"nodeType":1294,"data":3624,"content":3625},{},[3626],{"nodeType":1293,"value":3627,"marks":3628,"data":3629},"Similarly a mail rule could be created automatically as the result of a user’s workstation becoming infected with malware.",[],{},{"nodeType":1350,"data":3631,"content":3632},{},[],{"nodeType":1354,"data":3634,"content":3635},{},[3636],{"nodeType":1293,"value":3637,"marks":3638,"data":3639},"How to defend against this type of attack?",[],{},{"nodeType":1294,"data":3641,"content":3642},{},[3643,3647,3655,3659,3670,3673,3683],{"nodeType":1293,"value":3644,"marks":3645,"data":3646},"The first step is to check your mailboxes to make sure no malicious mail rules have already been created. On Office 365, this will require rolling some PowerShell; on Google Workspace, you'll need to query the APIs (we discuss some detail of these options ",[],{},{"nodeType":1378,"data":3648,"content":3650},{"uri":3649},"/blog/should-you-disable-external-email-auto-forwarding/",[3651],{"nodeType":1293,"value":3652,"marks":3653,"data":3654},"in this post",[],{},{"nodeType":1293,"value":3656,"marks":3657,"data":3658},"). Or you can save yourself some pain and use the free tool linked above, which we built for this very purpose. If you find rules that don't look right, follow these guides for what to do next on ",[],{},{"nodeType":3660,"data":3661,"content":3665},"entry-hyperlink",{"target":3662},{"sys":3663},{"id":3664,"type":1433,"linkType":1434},"e4805bba-2531-4250-bdcc-ab996dd33519",[3666],{"nodeType":1293,"value":3667,"marks":3668,"data":3669},"Office 365",[],{},{"nodeType":1293,"value":2786,"marks":3671,"data":3672},[],{},{"nodeType":3660,"data":3674,"content":3678},{"target":3675},{"sys":3676},{"id":3677,"type":1433,"linkType":1434},"50dab356-e78b-479d-ad45-a07b898b5ec4",[3679],{"nodeType":1293,"value":3680,"marks":3681,"data":3682},"Google Workspace",[],{},{"nodeType":1293,"value":1973,"marks":3684,"data":3685},[],{},{"nodeType":1294,"data":3687,"content":3688},{},[3689],{"nodeType":1293,"value":3690,"marks":3691,"data":3692},"It's also possible to stop users from creating auto-forwarding rules altogether. If no one is using the feature, this is probably a good idea - you might as well reduce risk. However, there are plenty of situations where teams benefit from the automation and efficiency mail rules bring. Security works best when it enables the business to work securely, rather than constraining it - leaving the feature available whilst managing the risk through detection is a good option as well.",[],{},{"nodeType":1294,"data":3694,"content":3695},{},[3696,3700,3707],{"nodeType":1293,"value":3697,"marks":3698,"data":3699},"We discuss more about the pros and cons of disabling mail rules and some options for some security controls you can implement so that you can keep them enabled ",[],{},{"nodeType":1378,"data":3701,"content":3702},{"uri":3649},[3703],{"nodeType":1293,"value":3704,"marks":3705,"data":3706},"in this blog post",[],{},{"nodeType":1293,"value":1973,"marks":3708,"data":3709},[],{},{"nodeType":1294,"data":3711,"content":3712},{},[3713],{"nodeType":1293,"value":3714,"marks":3715,"data":3716},"If you'd like, try Push for free and we'll spot any suspicious mail rules, then work with employees to make sure the mail rule wasn't something they created for a legitimate use. If they haven't, we'll notify you to take action and investigate a potential incident. Find out more here.",[],{},{"nodeType":1350,"data":3718,"content":3719},{},[],{"nodeType":1354,"data":3721,"content":3722},{},[3723],{"nodeType":1293,"value":1945,"marks":3724,"data":3726},[3725],{"type":1361},{},{"nodeType":1294,"data":3728,"content":3729},{},[3730],{"nodeType":1293,"value":3731,"marks":3732,"data":3733},"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",[],{},{"nodeType":1294,"data":3735,"content":3736},{},[3737,3740,3746],{"nodeType":1293,"value":1960,"marks":3738,"data":3739},[],{},{"nodeType":1378,"data":3741,"content":3742},{"uri":1965},[3743],{"nodeType":1293,"value":1968,"marks":3744,"data":3745},[],{},{"nodeType":1293,"value":1973,"marks":3747,"data":3748},[],{},{"entries":3750},{"inline":3751,"hyperlink":3752,"block":3764},[],[3753,3759],{"sys":3754,"__typename":3755,"title":3756,"slug":3757,"articleId":3758},{"id":3664},"HelpArticle","What to do if you find a malicious mail rule in Microsoft 365","what-to-do-if-you-find-a-malicious-mail-rule-microsoft-office-365",10021,{"sys":3760,"__typename":3755,"title":3761,"slug":3762,"articleId":3763},{"id":3677},"What to do when you find a malicious mail filter in Google Workspace","what-to-do-when-you-find-a-malicious-mail-filter-in-google-workspace",10022,[3765],{"sys":3766,"__typename":3767,"title":3768,"caption":3768,"layoutMode":118,"file":3769},{"id":3421},"Image","Microsoft Outlook ‘forward email’ rule in Office 365",{"url":3770,"width":3771,"height":3772},"https://images.ctfassets.net/y1cdw1ablpvd/7d9KtwtX1HE0imQzE6tvwm/d1316f98a9bfc1245d93377236c94282/legit-rules.jpg",930,408,"content:blog:email-security-how-hackers-use-mail-rules-to-access-your-inbox.json","json","blog/email-security-how-hackers-use-mail-rules-to-access-your-inbox.json","blog/email-security-how-hackers-use-mail-rules-to-access-your-inbox",1776359951644]