[{"data":1,"prerenderedAt":4149},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/how-the-browser-became-the-main-cyber-battleground":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"ogImage":118,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1296,"synopsis":1292,"hashTags":118,"publishedDate":1297,"slug":1298,"tagsCollection":1299,"relatedBlogPostsCollection":1309,"authorsCollection":3286,"content":3294,"_id":4144,"_type":4145,"_source":4146,"_file":4147,"_stem":4148,"_extension":4145},"/blog/how-the-browser-became-the-main-cyber-battleground","blog",{"id":1280,"publishedAt":1281},"31m73YMGdCyqVmjHulBwER","2025-09-19T06:36:25.810Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"How attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools.","text","paragraph","document","How the browser became the main cyber battleground","2025-08-15T00:00:00.000Z","how-the-browser-became-the-main-cyber-battleground",{"items":1300},[1301,1305],{"sys":1302,"name":1304},{"id":1303},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"sys":1306,"name":1308},{"id":1307},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":1310},[1311,2338,2706],{"__typename":1312,"sys":1313,"content":1315,"title":2320,"synopsis":2321,"hashTags":118,"publishedDate":2322,"slug":2323,"tagsCollection":2324,"authorsCollection":2330},"BlogPosts",{"id":1314},"6OFdfAsoPUECeRAetWvedp",{"json":1316},{"nodeType":1295,"data":1317,"content":1318},{},[1319,1326,1339,1351,1363,1375,1384,1406,1413,1429,1436,1442,1446,1455,1462,1469,1476,1482,1485,1493,1500,1520,1527,1534,1542,1549,1555,1562,1569,1576,1607,1614,1633,1640,1647,1667,1687,1707,1713,1720,1736,1743,1750,1757,1777,1785,1792,1799,1802,1810,1817,1824,1831,1876,1882,1889,1904,1993,1999,2006,2013,2076,2083,2090,2097,2103,2110,2117,2124,2130,2137,2144,2151,2157,2177,2184,2191,2234,2240,2243,2251,2276,2279,2287,2294,2301],{"nodeType":1294,"data":1320,"content":1321},{},[1322],{"nodeType":1293,"value":1323,"marks":1324,"data":1325},"Oh, look! A time capsule from 2010. Wonder what’s inside … ",[],{},{"nodeType":1294,"data":1327,"content":1328},{},[1329,1335],{"nodeType":1293,"value":1330,"marks":1331,"data":1334},"Listening to:",[1332],{"type":1333},"bold",{},{"nodeType":1293,"value":1336,"marks":1337,"data":1338}," “Like a G6” by Far East Movement (on a Nokia C7 — hey, it even had a touchscreen).",[],{},{"nodeType":1294,"data":1340,"content":1341},{},[1342,1347],{"nodeType":1293,"value":1343,"marks":1344,"data":1346},"Major news event:",[1345],{"type":1333},{},{"nodeType":1293,"value":1348,"marks":1349,"data":1350}," Eyjafjallajökull volcano erupts in Iceland, disrupting air travel.",[],{},{"nodeType":1294,"data":1352,"content":1353},{},[1354,1359],{"nodeType":1293,"value":1355,"marks":1356,"data":1358},"Worried about:",[1357],{"type":1333},{},{"nodeType":1293,"value":1360,"marks":1361,"data":1362}," Exploitable Flash browser plugins and static HTML phishing sites.",[],{},{"nodeType":1294,"data":1364,"content":1365},{},[1366,1371],{"nodeType":1293,"value":1367,"marks":1368,"data":1370},"How to be a hero?",[1369],{"type":1333},{},{"nodeType":1293,"value":1372,"marks":1373,"data":1374}," Roll out the latest AV, implement a web proxy, and add a “report phishing” button to your email solution.",[],{},{"nodeType":1376,"data":1377,"content":1383},"embedded-entry-block",{"target":1378},{"sys":1379},{"id":1380,"type":1381,"linkType":1382},"54xYbMs0ii96xb2jgQVX9m","Link","Entry",[],{"nodeType":1294,"data":1385,"content":1386},{},[1387,1391,1402],{"nodeType":1293,"value":1388,"marks":1389,"data":1390},"We’re halfway through 2025, and the time capsule for this year may need to be an XL when it comes to ",[],{},{"nodeType":1392,"data":1393,"content":1395},"hyperlink",{"uri":1394},"https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/",[1396],{"nodeType":1293,"value":1397,"marks":1398,"data":1401},"how much has happened",[1399],{"type":1400},"underline",{},{"nodeType":1293,"value":1403,"marks":1404,"data":1405}," in the world of browser-based attacks. (Yet fittingly, Drake’s “Nokia” is a pop hit.)",[],{},{"nodeType":1294,"data":1407,"content":1408},{},[1409],{"nodeType":1293,"value":1410,"marks":1411,"data":1412},"While at least we don’t have to worry about Flash anymore, the browser is now the new battleground, and workforce identities are the most common target. Security teams are struggling with approaches and tools that attackers have outpaced.",[],{},{"nodeType":1294,"data":1414,"content":1415},{},[1416,1420,1425],{"nodeType":1293,"value":1417,"marks":1418,"data":1419},"In this article, we’ll cover how browser-based attacks have evolved, and how Push is taking a new approach with the release of our ",[],{},{"nodeType":1293,"value":1421,"marks":1422,"data":1424},"Detections",[1423],{"type":1333},{},{"nodeType":1293,"value":1426,"marks":1427,"data":1428}," capabilities, now generally available to all customers.",[],{},{"nodeType":1294,"data":1430,"content":1431},{},[1432],{"nodeType":1293,"value":1433,"marks":1434,"data":1435},"Push Detections use real-time telemetry to help you understand context, user behavior, and attacker techniques, and then respond — a modern tool for modern browser-based attacks.",[],{},{"nodeType":1376,"data":1437,"content":1441},{"target":1438},{"sys":1439},{"id":1440,"type":1381,"linkType":1382},"2ULDSj85bXtT2OgpXKBHtB",[],{"nodeType":1443,"data":1444,"content":1445},"hr",{},[],{"nodeType":1447,"data":1448,"content":1449},"heading-1",{},[1450],{"nodeType":1293,"value":1451,"marks":1452,"data":1454},"The old world vs. the new world",[1453],{"type":1333},{},{"nodeType":1294,"data":1456,"content":1457},{},[1458],{"nodeType":1293,"value":1459,"marks":1460,"data":1461},"In the early 2010s, the typical attack path involved sending a user an email with a link to a static HTML webpage (most commonly a generic Exchange Web Access clone) that tricked them into giving you Active Directory creds. These could be used to log in to an exposed remote desktop service or the victim’s mailbox, giving the attacker a foothold to install malware. Anyone who’s done “red teaming 101” will recognize this scenario. ",[],{},{"nodeType":1294,"data":1463,"content":1464},{},[1465],{"nodeType":1293,"value":1466,"marks":1467,"data":1468},"A compromised identity was once just part of a system compromise. That meant the scope of detection and response was focused on the organization’s Active Directory domain, correlated with endpoint and network logs. ",[],{},{"nodeType":1294,"data":1470,"content":1471},{},[1472],{"nodeType":1293,"value":1473,"marks":1474,"data":1475},"But now, identity attacks happen beyond traditional on-premises networks, impacting cloud identities that are created, used, and attacked in the browser. What was once the familiar backbone of business IT — internal apps and thick clients — has been replaced with a sprawling cloud and SaaS ecosystem that can be targeted directly via identity, without touching the endpoint. ",[],{},{"nodeType":1376,"data":1477,"content":1481},{"target":1478},{"sys":1479},{"id":1480,"type":1381,"linkType":1382},"2F2p4eTMCHo3LfNQJZeGWB",[],{"nodeType":1443,"data":1483,"content":1484},{},[],{"nodeType":1447,"data":1486,"content":1487},{},[1488],{"nodeType":1293,"value":1489,"marks":1490,"data":1492},"Why detection and response hasn’t kept up with threat evolution",[1491],{"type":1333},{},{"nodeType":1294,"data":1494,"content":1495},{},[1496],{"nodeType":1293,"value":1497,"marks":1498,"data":1499},"This shift in attacker TTPs is forcing a change in how we handle detection and response. ",[],{},{"nodeType":1294,"data":1501,"content":1502},{},[1503,1507,1516],{"nodeType":1293,"value":1504,"marks":1505,"data":1506},"But a lot of organizations are still applying the same old playbooks to this new world where identity attacks are the ",[],{},{"nodeType":1392,"data":1508,"content":1510},{"uri":1509},"https://pushsecurity.com/resources/2024-identity-attacks",[1511],{"nodeType":1293,"value":1512,"marks":1513,"data":1515},"leading cause of breaches",[1514],{"type":1400},{},{"nodeType":1293,"value":1517,"marks":1518,"data":1519},", with uneven outcomes. ",[],{},{"nodeType":1294,"data":1521,"content":1522},{},[1523],{"nodeType":1293,"value":1524,"marks":1525,"data":1526},"This isn’t because of a lack of effort or skill on the part of security teams. It’s a reflection of the tools that have been available. ",[],{},{"nodeType":1294,"data":1528,"content":1529},{},[1530],{"nodeType":1293,"value":1531,"marks":1532,"data":1533},"Let’s look at some of the ways detection and response hasn’t kept up with the evolution of browser-borne threats in this new landscape.",[],{},{"nodeType":1535,"data":1536,"content":1537},"heading-2",{},[1538],{"nodeType":1293,"value":1539,"marks":1540,"data":1541},"Incomplete identity visibility ",[],{},{"nodeType":1294,"data":1543,"content":1544},{},[1545],{"nodeType":1293,"value":1546,"marks":1547,"data":1548},"Today’s cloud identity providers see a fraction of the overall logins your users make to online apps, compared to the comprehensive visibility of Active Directory in the old world. You don’t know where users are logging in, how they’re logging in, or whether these logins are securely using phishing-resistant methods.",[],{},{"nodeType":1376,"data":1550,"content":1554},{"target":1551},{"sys":1552},{"id":1553,"type":1381,"linkType":1382},"1SUYueQct7dtWwLh3AaAtA",[],{"nodeType":1294,"data":1556,"content":1557},{},[1558],{"nodeType":1293,"value":1559,"marks":1560,"data":1561},"This means that identity attacks are routinely bypassing preventative, account hygiene-based controls, putting the strain on detection and response. ",[],{},{"nodeType":1535,"data":1563,"content":1564},{},[1565],{"nodeType":1293,"value":1566,"marks":1567,"data":1568},"Limited detection coverage ",[],{},{"nodeType":1294,"data":1570,"content":1571},{},[1572],{"nodeType":1293,"value":1573,"marks":1574,"data":1575},"Email and network security tools got pretty good at intercepting old-school phishing attacks like the ones from our proverbial time capsule: static HTML pages delivered over email that could be intercepted and analyzed when entering the mailbox or being loaded by the user. ",[],{},{"nodeType":1294,"data":1577,"content":1578},{},[1579,1583,1593,1598,1602],{"nodeType":1293,"value":1580,"marks":1581,"data":1582},"But with modern phishing attacks dynamically obfuscating the code that loads the web page, implementing custom bot protection, and using runtime anti-analysis features, they’re ",[],{},{"nodeType":1392,"data":1584,"content":1586},{"uri":1585},"https://pushsecurity.com/blog/why-most-phishing-attacks-feel-like-a-zero-day/",[1587],{"nodeType":1293,"value":1588,"marks":1589,"data":1592},"increasingly difficult to detect",[1590,1591],{"type":1400},{"type":1333},{},{"nodeType":1293,"value":1594,"marks":1595,"data":1597}," ",[1596],{"type":1333},{},{"nodeType":1293,"value":1599,"marks":1600,"data":1601},"using conventional tools",[],{},{"nodeType":1293,"value":1603,"marks":1604,"data":1606},".   ",[1605],{"type":1333},{},{"nodeType":1294,"data":1608,"content":1609},{},[1610],{"nodeType":1293,"value":1611,"marks":1612,"data":1613},"Of course, email-based detections aren’t much use if attackers are using legitimate services to camouflage their links, or bypassing email altogether by switching to alternative delivery channels like messaging apps (such as Slack and Teams), as well as public services like LinkedIn and Reddit. ",[],{},{"nodeType":1294,"data":1615,"content":1616},{},[1617,1621,1629],{"nodeType":1293,"value":1618,"marks":1619,"data":1620},"More recently, groups like ",[],{},{"nodeType":1392,"data":1622,"content":1623},{"uri":1394},[1624],{"nodeType":1293,"value":1625,"marks":1626,"data":1628},"Scattered Spider",[1627],{"type":1400},{},{"nodeType":1293,"value":1630,"marks":1631,"data":1632}," have even been seen using malvertising techniques, delivering phishing links masquerading as paid Google ads.",[],{},{"nodeType":1535,"data":1634,"content":1635},{},[1636],{"nodeType":1293,"value":1637,"marks":1638,"data":1639},"Inadequate security logs",[],{},{"nodeType":1294,"data":1641,"content":1642},{},[1643],{"nodeType":1293,"value":1644,"marks":1645,"data":1646},"If you fail to spot the attack pre-account takeover, you’re reliant on being able to detect and investigate suspicious or malicious activity resulting from the compromise. ",[],{},{"nodeType":1294,"data":1648,"content":1649},{},[1650,1654,1663],{"nodeType":1293,"value":1651,"marks":1652,"data":1653},"This was more straightforward (if not easy) when you had the luxury of a ",[],{},{"nodeType":1392,"data":1655,"content":1657},{"uri":1656},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[1658],{"nodeType":1293,"value":1659,"marks":1660,"data":1662},"typical on-prem network to fall back",[1661],{"type":1400},{},{"nodeType":1293,"value":1664,"marks":1665,"data":1666}," on. But with cloud exploitation taking place in a matter of minutes, you don’t get much warning — and your endpoint and network-based alarms can’t help you. ",[],{},{"nodeType":1294,"data":1668,"content":1669},{},[1670,1674,1683],{"nodeType":1293,"value":1671,"marks":1672,"data":1673},"The situation is further complicated by the fact that you simply don’t have the logs you need because of the huge variability in how cloud and SaaS services provide logs (with many ",[],{},{"nodeType":1392,"data":1675,"content":1677},{"uri":1676},"https://pushsecurity.com/blog/minimum-viable-identity-security/#id-enable-security-teams-to-detect-and-respond-to-identity-attacks",[1678],{"nodeType":1293,"value":1679,"marks":1680,"data":1682},"failing to provide security logs",[1681],{"type":1400},{},{"nodeType":1293,"value":1684,"marks":1685,"data":1686}," with relevant data points at all). So chances are you’re flying blind when it comes to large chunks of your business app suite. ",[],{},{"nodeType":1294,"data":1688,"content":1689},{},[1690,1694,1703],{"nodeType":1293,"value":1691,"marks":1692,"data":1693},"Ultimately, you’re stuck with what you can observe — typically network traffic. But ",[],{},{"nodeType":1392,"data":1695,"content":1697},{"uri":1696},"https://pushsecurity.com/blog/the-web-proxy-is-dead-long-live-the-browser-extension/",[1698],{"nodeType":1293,"value":1699,"marks":1700,"data":1702},"even with a TLS-terminating proxy",[1701],{"type":1400},{},{"nodeType":1293,"value":1704,"marks":1705,"data":1706},", extracting fine-grained identity data points isn’t really achievable. You’re looking from the outside-in at malicious activity that’s happening in the user’s browser and trying to infer what happened.  ",[],{},{"nodeType":1376,"data":1708,"content":1712},{"target":1709},{"sys":1710},{"id":1711,"type":1381,"linkType":1382},"7FMdHtbE63GMCavObETf3O",[],{"nodeType":1535,"data":1714,"content":1715},{},[1716],{"nodeType":1293,"value":1717,"marks":1718,"data":1719},"Spotty control enforcement",[],{},{"nodeType":1294,"data":1721,"content":1722},{},[1723,1727,1732],{"nodeType":1293,"value":1724,"marks":1725,"data":1726},"And in the case that you do identify that a user clicked a malicious link and ",[],{},{"nodeType":1293,"value":1728,"marks":1729,"data":1731},"maybe ",[1730],{"type":312},{},{"nodeType":1293,"value":1733,"marks":1734,"data":1735},"entered their credentials into the page — now what? ",[],{},{"nodeType":1294,"data":1737,"content":1738},{},[1739],{"nodeType":1293,"value":1740,"marks":1741,"data":1742},"You can reset the account in the affected app, ideally terminating active sessions — which may or may not be possible, depending on the app. This might take a while if you don’t centrally manage the app, and involve some painful emergency phone calls to employees. ",[],{},{"nodeType":1294,"data":1744,"content":1745},{},[1746],{"nodeType":1293,"value":1747,"marks":1748,"data":1749},"What about apps where the same password is reused? ",[],{},{"nodeType":1294,"data":1751,"content":1752},{},[1753],{"nodeType":1293,"value":1754,"marks":1755,"data":1756},"Or if it’s an IdP account used for SSO, what about the other apps that might be accessible now? ",[],{},{"nodeType":1294,"data":1758,"content":1759},{},[1760,1764,1773],{"nodeType":1293,"value":1761,"marks":1762,"data":1763},"If the attacker has created stealthy backdoors that persist through credential changes (like ",[],{},{"nodeType":1392,"data":1765,"content":1767},{"uri":1766},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[1768],{"nodeType":1293,"value":1769,"marks":1770,"data":1772},"creating an API key or a malicious OAuth integration",[1771],{"type":1400},{},{"nodeType":1293,"value":1774,"marks":1775,"data":1776},") they could still be lurking in your environment.",[],{},{"nodeType":1294,"data":1778,"content":1779},{},[1780],{"nodeType":1293,"value":1781,"marks":1782,"data":1784},"Suddenly, you’re not dealing with one possible control point, you’re dealing with several. ",[1783],{"type":1333},{},{"nodeType":1294,"data":1786,"content":1787},{},[1788],{"nodeType":1293,"value":1789,"marks":1790,"data":1791},"And if you can’t trace the attack back to a source — because your email solution missed it, or it didn’t come via email, how can you triage the impact to other users? ",[],{},{"nodeType":1294,"data":1793,"content":1794},{},[1795],{"nodeType":1293,"value":1796,"marks":1797,"data":1798},"It’s no wonder that security teams are struggling to adapt. ",[],{},{"nodeType":1443,"data":1800,"content":1801},{},[],{"nodeType":1447,"data":1803,"content":1804},{},[1805],{"nodeType":1293,"value":1806,"marks":1807,"data":1809},"How Push is solving modern identity investigations in the browser",[1808],{"type":1333},{},{"nodeType":1294,"data":1811,"content":1812},{},[1813],{"nodeType":1293,"value":1814,"marks":1815,"data":1816},"The good news? We’ve seen this phenomenon play out before: In the early 2010s, in fact, when AV evolved into EDR. What was the big innovation then? Getting inside the data stream, in real time, and detecting and responding from a much higher-fidelity source of telemetry.",[],{},{"nodeType":1294,"data":1818,"content":1819},{},[1820],{"nodeType":1293,"value":1821,"marks":1822,"data":1823},"This time around, security teams need tools that take them inside the browser layer.",[],{},{"nodeType":1294,"data":1825,"content":1826},{},[1827],{"nodeType":1293,"value":1828,"marks":1829,"data":1830},"This approach gives you the right vantage point to defend against and investigate browser-based identity attacks, providing access to:",[],{},{"nodeType":1832,"data":1833,"content":1834},"unordered-list",{},[1835,1846,1856,1866],{"nodeType":1836,"data":1837,"content":1838},"list-item",{},[1839],{"nodeType":1294,"data":1840,"content":1841},{},[1842],{"nodeType":1293,"value":1843,"marks":1844,"data":1845},"Full decrypted HTTP traffic — not just DNS and TCP/IP metadata",[],{},{"nodeType":1836,"data":1847,"content":1848},{},[1849],{"nodeType":1294,"data":1850,"content":1851},{},[1852],{"nodeType":1293,"value":1853,"marks":1854,"data":1855},"Full user interaction tracing — every click, keystroke, or DOM change",[],{},{"nodeType":1836,"data":1857,"content":1858},{},[1859],{"nodeType":1294,"data":1860,"content":1861},{},[1862],{"nodeType":1293,"value":1863,"marks":1864,"data":1865},"Full inspection at every layer of execution, not just the initial HTML served",[],{},{"nodeType":1836,"data":1867,"content":1868},{},[1869],{"nodeType":1294,"data":1870,"content":1871},{},[1872],{"nodeType":1293,"value":1873,"marks":1874,"data":1875},"Full access to browser APIs, to correlate with browser history, local storage, cookies, etc.",[],{},{"nodeType":1376,"data":1877,"content":1881},{"target":1878},{"sys":1879},{"id":1880,"type":1381,"linkType":1382},"5qt0s8e1TIEUxhU1GzFO63",[],{"nodeType":1294,"data":1883,"content":1884},{},[1885],{"nodeType":1293,"value":1886,"marks":1887,"data":1888},"With this data, teams have the information they need to respond to and investigate browser-based attacks. But to become valuable, this data needs a translation layer that turns it from raw logs into actionable information.",[],{},{"nodeType":1294,"data":1890,"content":1891},{},[1892,1896,1900],{"nodeType":1293,"value":1893,"marks":1894,"data":1895},"That’s where Push’s ",[],{},{"nodeType":1293,"value":1421,"marks":1897,"data":1899},[1898],{"type":1333},{},{"nodeType":1293,"value":1901,"marks":1902,"data":1903}," capability comes in. With it, you can:",[],{},{"nodeType":1832,"data":1905,"content":1906},{},[1907,1943,1953,1963,1973,1983],{"nodeType":1836,"data":1908,"content":1909},{},[1910],{"nodeType":1294,"data":1911,"content":1912},{},[1913,1917,1926,1930,1939],{"nodeType":1293,"value":1914,"marks":1915,"data":1916},"Get alerted in your platform of choice (via the Push admin console, ",[],{},{"nodeType":1392,"data":1918,"content":1920},{"uri":1919},"https://pushsecurity.com/help/audience/administrators/docs/connect-to-siem-or-soar/send-webhook-events-to-slack/",[1921],{"nodeType":1293,"value":1922,"marks":1923,"data":1925},"Slack integration",[1924],{"type":1400},{},{"nodeType":1293,"value":1927,"marks":1928,"data":1929},", or your ",[],{},{"nodeType":1392,"data":1931,"content":1933},{"uri":1932},"https://pushsecurity.com/help/audience/administrators/docs/connect-to-siem-or-soar/",[1934],{"nodeType":1293,"value":1935,"marks":1936,"data":1938},"SIEM/SOAR",[1937],{"type":1400},{},{"nodeType":1293,"value":1940,"marks":1941,"data":1942}," of choice) whenever Push detects a browser-based attack, such as AiTM phishing or a cloned login page.",[],{},{"nodeType":1836,"data":1944,"content":1945},{},[1946],{"nodeType":1294,"data":1947,"content":1948},{},[1949],{"nodeType":1293,"value":1950,"marks":1951,"data":1952},"Review a curated timeline of the incident: Where a phishing link originated; whether a user entered their credentials on the page; what kind of phishkit was used; and whether the attack was blocked by Push.",[],{},{"nodeType":1836,"data":1954,"content":1955},{},[1956],{"nodeType":1294,"data":1957,"content":1958},{},[1959],{"nodeType":1293,"value":1960,"marks":1961,"data":1962},"See all the other impacted accounts and apps that shared a password with the phished account so you can remediate them.",[],{},{"nodeType":1836,"data":1964,"content":1965},{},[1966],{"nodeType":1294,"data":1967,"content":1968},{},[1969],{"nodeType":1293,"value":1970,"marks":1971,"data":1972},"See a screenshot captured by the Push browser extension of the phishing page, so you can see exactly what the user saw before the page disappears.",[],{},{"nodeType":1836,"data":1974,"content":1975},{},[1976],{"nodeType":1294,"data":1977,"content":1978},{},[1979],{"nodeType":1293,"value":1980,"marks":1981,"data":1982},"Get additional context from urlscan.io about the domains connected to the incident, helping you understand whether a domain has been reported as malicious by other users, when it was registered, and how many times it’s been scanned.",[],{},{"nodeType":1836,"data":1984,"content":1985},{},[1986],{"nodeType":1294,"data":1987,"content":1988},{},[1989],{"nodeType":1293,"value":1990,"marks":1991,"data":1992},"Interrogate and send this telemetry to your SIEM for you to operationalize it as part of SecOps workflows and hunt across events for similar incident characteristics.",[],{},{"nodeType":1376,"data":1994,"content":1998},{"target":1995},{"sys":1996},{"id":1997,"type":1381,"linkType":1382},"5iPYWpPx4IZ2M1DykQiWsN",[],{"nodeType":1535,"data":2000,"content":2001},{},[2002],{"nodeType":1293,"value":2003,"marks":2004,"data":2005},"Browser context",[],{},{"nodeType":1294,"data":2007,"content":2008},{},[2009],{"nodeType":1293,"value":2010,"marks":2011,"data":2012},"With Push, there’s no more: ",[],{},{"nodeType":1832,"data":2014,"content":2015},{},[2016,2026,2036,2046,2056,2066],{"nodeType":1836,"data":2017,"content":2018},{},[2019],{"nodeType":1294,"data":2020,"content":2021},{},[2022],{"nodeType":1293,"value":2023,"marks":2024,"data":2025},"Waiting (and hoping) that a browser-based attack gets recognized and reported by a user.",[],{},{"nodeType":1836,"data":2027,"content":2028},{},[2029],{"nodeType":1294,"data":2030,"content":2031},{},[2032],{"nodeType":1293,"value":2033,"marks":2034,"data":2035},"Guesswork as to exactly what happened on the phishing page. ",[],{},{"nodeType":1836,"data":2037,"content":2038},{},[2039],{"nodeType":1294,"data":2040,"content":2041},{},[2042],{"nodeType":1293,"value":2043,"marks":2044,"data":2045},"Struggling to get your hands on a live version of the page to see if it was actually malicious and getting thwarted because the attacker used a one-time phishing link. ",[],{},{"nodeType":1836,"data":2047,"content":2048},{},[2049],{"nodeType":1294,"data":2050,"content":2051},{},[2052],{"nodeType":1293,"value":2053,"marks":2054,"data":2055},"Manually tracing the attack to see if it arrived by email so you can quarantine the messages. ",[],{},{"nodeType":1836,"data":2057,"content":2058},{},[2059],{"nodeType":1294,"data":2060,"content":2061},{},[2062],{"nodeType":1293,"value":2063,"marks":2064,"data":2065},"Trawling through voluminous proxy logs for scraps of information (who else visited the link; where did it originate; etc.).",[],{},{"nodeType":1836,"data":2067,"content":2068},{},[2069],{"nodeType":1294,"data":2070,"content":2071},{},[2072],{"nodeType":1293,"value":2073,"marks":2074,"data":2075},"Spending precious time on urlscan or VirusTotal to get basic context on a domain or IP address. ",[],{},{"nodeType":1294,"data":2077,"content":2078},{},[2079],{"nodeType":1293,"value":2080,"marks":2081,"data":2082},"Instead, Push gives you all the information you need in one place to investigate and respond. ",[],{},{"nodeType":1294,"data":2084,"content":2085},{},[2086],{"nodeType":1293,"value":2087,"marks":2088,"data":2089},"The foundation for these detections is the Push browser agent, which can be silently installed in all major browsers in your environment to begin streaming information about a user’s entire identity footprint. ",[],{},{"nodeType":1294,"data":2091,"content":2092},{},[2093],{"nodeType":1293,"value":2094,"marks":2095,"data":2096},"This valuable telemetry, combined with Push’s out-of-the-box controls and detections, gives you a seat on the user’s side of the equation, capturing reliable information about network requests, scripts loaded by a malicious website, and what a user clicked and navigated to: the ingredients for showing you how a browser-based attack unfolded, start to finish.",[],{},{"nodeType":1376,"data":2098,"content":2102},{"target":2099},{"sys":2100},{"id":2101,"type":1381,"linkType":1382},"7ylgcaNDrxYhw7bULixM1C",[],{"nodeType":1294,"data":2104,"content":2105},{},[2106],{"nodeType":1293,"value":2107,"marks":2108,"data":2109},"Push raises a detection when it observes a phishing attack or when a user attempts to visit a blocked URL. You can view detections in the Push admin console, or send them to your SIEM or SOAR for correlation and analysis.",[],{},{"nodeType":1535,"data":2111,"content":2112},{},[2113],{"nodeType":1293,"value":2114,"marks":2115,"data":2116},"Screenshot capture",[],{},{"nodeType":1294,"data":2118,"content":2119},{},[2120],{"nodeType":1293,"value":2121,"marks":2122,"data":2123},"The Push extension can also capture a screenshot at the time of a detection firing. This means security teams can see the visual characteristics of the page even if it’s since been taken down (and no more looking at bot protection screens like Cloudflare Turnstile on urlscan). ",[],{},{"nodeType":1376,"data":2125,"content":2129},{"target":2126},{"sys":2127},{"id":2128,"type":1381,"linkType":1382},"58HPrc7wImm3mLxPK0yJOG",[],{"nodeType":1535,"data":2131,"content":2132},{},[2133],{"nodeType":1293,"value":2134,"marks":2135,"data":2136},"Blast radius analysis for all impacted accounts & apps",[],{},{"nodeType":1294,"data":2138,"content":2139},{},[2140],{"nodeType":1293,"value":2141,"marks":2142,"data":2143},"With Push’s knowledge of your workforce identities — based on observing logins in the browser that use corporate credentials — the platform can also provide an analysis of the blast radius of an attack by showing you where other accounts and apps are impacted or at risk.",[],{},{"nodeType":1294,"data":2145,"content":2146},{},[2147],{"nodeType":1293,"value":2148,"marks":2149,"data":2150},"This information helps you understand the true impact of an incident so you can remediate all affected accounts.",[],{},{"nodeType":1376,"data":2152,"content":2156},{"target":2153},{"sys":2154},{"id":2155,"type":1381,"linkType":1382},"77e8XMl2Rb0p7ZrG2wmURO",[],{"nodeType":1294,"data":2158,"content":2159},{},[2160,2164,2173],{"nodeType":1293,"value":2161,"marks":2162,"data":2163},"Push is able to provide this blast radius analysis by ",[],{},{"nodeType":1392,"data":2165,"content":2167},{"uri":2166},"https://pushsecurity.com/help/10043/#how-push-securely-analyzes-passwords",[2168],{"nodeType":1293,"value":2169,"marks":2170,"data":2172},"securely fingerprinting users’ passwords",[2171],{"type":1400},{},{"nodeType":1293,"value":2174,"marks":2175,"data":2176}," when a login is observed; analyzing them for security posture issues such as missing MFA, or stolen, weak, or reused passwords; and then raising that relevant context for a given detection.",[],{},{"nodeType":1535,"data":2178,"content":2179},{},[2180],{"nodeType":1293,"value":2181,"marks":2182,"data":2183},"Correlated context from urlscan.io",[],{},{"nodeType":1294,"data":2185,"content":2186},{},[2187],{"nodeType":1293,"value":2188,"marks":2189,"data":2190},"Finally, through an integration with urlscan.io, Push is able to provide additional context about the domains involved in a detection event, including:",[],{},{"nodeType":1832,"data":2192,"content":2193},{},[2194,2204,2214,2224],{"nodeType":1836,"data":2195,"content":2196},{},[2197],{"nodeType":1294,"data":2198,"content":2199},{},[2200],{"nodeType":1293,"value":2201,"marks":2202,"data":2203},"When they were created",[],{},{"nodeType":1836,"data":2205,"content":2206},{},[2207],{"nodeType":1294,"data":2208,"content":2209},{},[2210],{"nodeType":1293,"value":2211,"marks":2212,"data":2213},"How many times they have previously been scanned",[],{},{"nodeType":1836,"data":2215,"content":2216},{},[2217],{"nodeType":1294,"data":2218,"content":2219},{},[2220],{"nodeType":1293,"value":2221,"marks":2222,"data":2223},"When they were last scanned",[],{},{"nodeType":1836,"data":2225,"content":2226},{},[2227],{"nodeType":1294,"data":2228,"content":2229},{},[2230],{"nodeType":1293,"value":2231,"marks":2232,"data":2233},"If urlscan has marked them as suspicious",[],{},{"nodeType":1376,"data":2235,"content":2239},{"target":2236},{"sys":2237},{"id":2238,"type":1381,"linkType":1382},"2AKpAk65XdmaGBfe2V4qZ5",[],{"nodeType":1443,"data":2241,"content":2242},{},[],{"nodeType":1447,"data":2244,"content":2245},{},[2246],{"nodeType":1293,"value":2247,"marks":2248,"data":2250},"Check out our latest webinar for practical guidance in real-world scenarios",[2249],{"type":1333},{},{"nodeType":1294,"data":2252,"content":2253},{},[2254,2258,2267,2271],{"nodeType":1293,"value":2255,"marks":2256,"data":2257},"For practical advice and applied examples of how to use Push data in incident response — as well as some bonus examples of automated response and remediation use cases — ",[],{},{"nodeType":1392,"data":2259,"content":2261},{"uri":2260},"https://pushsecurity.com/webinar/identity-detection-response",[2262],{"nodeType":1293,"value":2263,"marks":2264,"data":2266},"join us live on August 13 for our webinar",[2265],{"type":1400},{},{"nodeType":1293,"value":2268,"marks":2269,"data":2270},", ",[],{},{"nodeType":1293,"value":2272,"marks":2273,"data":2275},"“Identity attacks have changed — have your IR playbooks?”",[2274],{"type":1333},{},{"nodeType":1443,"data":2277,"content":2278},{},[],{"nodeType":1447,"data":2280,"content":2281},{},[2282],{"nodeType":1293,"value":2283,"marks":2284,"data":2286},"Learn more about Push",[2285],{"type":1333},{},{"nodeType":1294,"data":2288,"content":2289},{},[2290],{"nodeType":1293,"value":2291,"marks":2292,"data":2293},"Push’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying, and session hijacking using stolen session tokens. ",[],{},{"nodeType":1294,"data":2295,"content":2296},{},[2297],{"nodeType":1293,"value":2298,"marks":2299,"data":2300},"You can also use Push to find and fix identity vulnerabilities across every app that your employees use, including ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more.",[],{},{"nodeType":1294,"data":2302,"content":2303},{},[2304,2308,2317],{"nodeType":1293,"value":2305,"marks":2306,"data":2307},"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",[],{},{"nodeType":1392,"data":2309,"content":2311},{"uri":2310},"https://pushsecurity.com/demo/",[2312],{"nodeType":1293,"value":2313,"marks":2314,"data":2316},"request a demo.",[2315],{"type":1400},{},{"nodeType":1293,"value":37,"marks":2318,"data":2319},[],{},"Introducing Push Detections: Equipping SecOps and IR teams to stop browser-based attacks","We’re launching a new Detections capability, enabling security teams to more effectively investigate and triage alerts, and build more effective workflows. ","2025-07-29T00:00:00.000Z","introducing-push-detections",{"items":2325},[2326,2328],{"sys":2327,"name":1304},{"id":1303},{"sys":2329,"name":1308},{"id":1307},{"items":2331},[2332],{"fullName":2333,"firstName":2334,"jobTitle":2335,"profilePicture":2336},"Kelly Davenport","Kelly","Product Team",{"url":2337},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1312,"sys":2339,"content":2341,"title":2689,"synopsis":2690,"hashTags":118,"publishedDate":2691,"slug":2692,"tagsCollection":2693,"authorsCollection":2699},{"id":2340},"4rLP8wr6HnvBG2OzqYYKpF",{"json":2342},{"nodeType":1295,"data":2343,"content":2344},{},[2345,2352,2359,2366,2372,2379,2412,2419,2426,2433,2439,2446,2453,2471,2477,2484,2504,2524,2531,2538,2545,2552,2559,2566,2573,2593,2600,2607,2613,2620,2627,2652,2658,2677,2683],{"nodeType":1294,"data":2346,"content":2347},{},[2348],{"nodeType":1293,"value":2349,"marks":2350,"data":2351},"Scattered Spider has shown the world the devastating effects attackers can achieve by socially engineering IT help desks into performing MFA resets so they can take over accounts on sensitive corporate apps. ",[],{},{"nodeType":1294,"data":2353,"content":2354},{},[2355],{"nodeType":1293,"value":2356,"marks":2357,"data":2358},"That’s why we’re introducing Employee Identity Verification Codes — a simple, browser-based identity check that gives your help desk a reliable way to confirm they’re talking to someone from your organization.",[],{},{"nodeType":1294,"data":2360,"content":2361},{},[2362],{"nodeType":1293,"value":2363,"marks":2364,"data":2365},"Push now provides your employees with a rotating 6-digit verification code in their browser via the Push Security extension. When an employee contacts your IT help desk to request an MFA reset or access recovery, the help desk can ask for this code to verify their identity — ensuring it’s really them, and not an attacker.",[],{},{"nodeType":1376,"data":2367,"content":2371},{"target":2368},{"sys":2369},{"id":2370,"type":1381,"linkType":1382},"3PkiGgzwSt9Nb5rsGRiQVZ",[],{"nodeType":1294,"data":2373,"content":2374},{},[2375],{"nodeType":1293,"value":2376,"marks":2377,"data":2378},"The employee identity verification codes are:",[],{},{"nodeType":1832,"data":2380,"content":2381},{},[2382,2392,2402],{"nodeType":1836,"data":2383,"content":2384},{},[2385],{"nodeType":1294,"data":2386,"content":2387},{},[2388],{"nodeType":1293,"value":2389,"marks":2390,"data":2391},"Session-aware - generated in users’ browsers and only visible to them when they click on the Push Security extension icon in their browser toolbar.",[],{},{"nodeType":1836,"data":2393,"content":2394},{},[2395],{"nodeType":1294,"data":2396,"content":2397},{},[2398],{"nodeType":1293,"value":2399,"marks":2400,"data":2401},"Rotating: they change every 24 hours",[],{},{"nodeType":1836,"data":2403,"content":2404},{},[2405],{"nodeType":1294,"data":2406,"content":2407},{},[2408],{"nodeType":1293,"value":2409,"marks":2410,"data":2411},"Lightweight: no additional apps or devices required",[],{},{"nodeType":1294,"data":2413,"content":2414},{},[2415],{"nodeType":1293,"value":2416,"marks":2417,"data":2418},"It’s a fast, simple verification method — directly in the employee’s browser — that addresses a real-world threat.",[],{},{"nodeType":1447,"data":2420,"content":2421},{},[2422],{"nodeType":1293,"value":2423,"marks":2424,"data":2425},"We think it’s swell, but don’t just take our word for it …",[],{},{"nodeType":1294,"data":2427,"content":2428},{},[2429],{"nodeType":1293,"value":2430,"marks":2431,"data":2432},"Eric Rubin — a Senior Manager in GitLab’s Corporate Security team — has already rolled out Employee Identity Verification Codes across his workforce. Here’s what he had to say about it:",[],{},{"nodeType":1376,"data":2434,"content":2438},{"target":2435},{"sys":2436},{"id":2437,"type":1381,"linkType":1382},"5ZLaA869NXpMjVwkswEyOB",[],{"nodeType":1294,"data":2440,"content":2441},{},[2442],{"nodeType":1293,"value":2443,"marks":2444,"data":2445},"Thank you, Eric!",[],{},{"nodeType":1447,"data":2447,"content":2448},{},[2449],{"nodeType":1293,"value":2450,"marks":2451,"data":2452},"Why are help desk identity verification methods so hot right now?",[],{},{"nodeType":1294,"data":2454,"content":2455},{},[2456,2460,2467],{"nodeType":1293,"value":2457,"marks":2458,"data":2459},"A number of the high-profile incidents attributed to the ",[],{},{"nodeType":1392,"data":2461,"content":2462},{"uri":1394},[2463],{"nodeType":1293,"value":2464,"marks":2465,"data":2466},"Scattered Spider cybercriminal group",[],{},{"nodeType":1293,"value":2468,"marks":2469,"data":2470}," saw them socially engineer IT help desks into resetting MFA on employee accounts that they had already acquired valid credentials for. These compromised accounts were typically on IdP systems like Okta providing SSO access to large numbers of downstream applications.",[],{},{"nodeType":1376,"data":2472,"content":2476},{"target":2473},{"sys":2474},{"id":2475,"type":1381,"linkType":1382},"2F2dpOkyXWnrKgFC3dSl67",[],{"nodeType":1535,"data":2478,"content":2479},{},[2480],{"nodeType":1293,"value":2481,"marks":2482,"data":2483},"Case study: The MGM Resorts breach",[],{},{"nodeType":1294,"data":2485,"content":2486},{},[2487,2491,2500],{"nodeType":1293,"value":2488,"marks":2489,"data":2490},"One of Scattered Spider’s most notorious and well-documented attacks was against ",[],{},{"nodeType":1392,"data":2492,"content":2494},{"uri":2493},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-mgm-resorts-september-2023",[2495],{"nodeType":1293,"value":2496,"marks":2497,"data":2499},"MGM Resorts",[2498],{"type":1400},{},{"nodeType":1293,"value":2501,"marks":2502,"data":2503},". Scattered Spider socially engineered MGM Resorts’ help desk personnel to bypass MFA and log in to accounts for which they had acquired valid login credentials via credential phishing and historical infostealer compromises. ",[],{},{"nodeType":1294,"data":2505,"content":2506},{},[2507,2511,2520],{"nodeType":1293,"value":2508,"marks":2509,"data":2510},"They specifically targeted accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",[],{},{"nodeType":1392,"data":2512,"content":2514},{"uri":2513},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/inbound_federation/description.md",[2515],{"nodeType":1293,"value":2516,"marks":2517,"data":2519},"inbound federation",[2518],{"type":1400},{},{"nodeType":1293,"value":2521,"marks":2522,"data":2523},". This then enabled them to impersonate any user within the Okta tenant. ",[],{},{"nodeType":1294,"data":2525,"content":2526},{},[2527],{"nodeType":1293,"value":2528,"marks":2529,"data":2530},"The attackers were then able to abuse SSO access to downstream apps and platforms from various accounts, culminating in deployment of ransomware to around 100 ESXi servers and data exfiltration. ",[],{},{"nodeType":1294,"data":2532,"content":2533},{},[2534],{"nodeType":1293,"value":2535,"marks":2536,"data":2537},"The breach resulted in a 36-hour outage, a $100M hit to its Q3 results, one-time cyber consulting fees in the region of $10M, and a class-action lawsuit later settled for $45M. ",[],{},{"nodeType":1535,"data":2539,"content":2540},{},[2541],{"nodeType":1293,"value":2542,"marks":2543,"data":2544},"Reassessing help desk verification processes",[],{},{"nodeType":1294,"data":2546,"content":2547},{},[2548],{"nodeType":1293,"value":2549,"marks":2550,"data":2551},"Scattered Spider’s high-profile attacks — including its most recent against UK retailers Marks & Spencer’s and the Co-op — has prompted many security teams to reassess the verification processes used by their IT help desks when an employee requests an MFA reset or access to sensitive applications. ",[],{},{"nodeType":1294,"data":2553,"content":2554},{},[2555],{"nodeType":1293,"value":2556,"marks":2557,"data":2558},"Initial guidance from across the industry included the use of call-back verification for any MFA or credential changes requested by an employee. However, Scattered Spider are also known to use SIM-swapping to trick mobile carriers into transferring a victim’s phone number to a SIM card controlled by the attacker - thereby allowing them to intercept verification calls. ",[],{},{"nodeType":1447,"data":2560,"content":2561},{},[2562],{"nodeType":1293,"value":2563,"marks":2564,"data":2565},"Simple verification using your employees’ browsers",[],{},{"nodeType":1294,"data":2567,"content":2568},{},[2569],{"nodeType":1293,"value":2570,"marks":2571,"data":2572},"Push already provides several controls that directly align to the other TTPs used by Scattered Spider. They include detecting stolen credentials, cloned login pages, AitM toolkits and compromised IdP sessions. ",[],{},{"nodeType":1294,"data":2574,"content":2575},{},[2576,2580,2589],{"nodeType":1293,"value":2577,"marks":2578,"data":2579},"(BTW, if this piques your interest, you can ",[],{},{"nodeType":1392,"data":2581,"content":2583},{"uri":2582},"https://pushsecurity.com/resources?type=webinar#content",[2584],{"nodeType":1293,"value":2585,"marks":2586,"data":2588},"stream our latest webinar",[2587],{"type":1400},{},{"nodeType":1293,"value":2590,"marks":2591,"data":2592}," where we deep-dive into Scattered Spider, how their TTPs are evolving in 2025, and what Push is doing to protect organizations against them.) ",[],{},{"nodeType":1294,"data":2594,"content":2595},{},[2596],{"nodeType":1293,"value":2597,"marks":2598,"data":2599},"But to provide our customers with an additional layer of defense against the Scattered Spider attack chain, we wanted to see how we could make it harder for attackers to socially engineer IT help desks into gaining access to IdP systems and sensitive apps.",[],{},{"nodeType":1294,"data":2601,"content":2602},{},[2603],{"nodeType":1293,"value":2604,"marks":2605,"data":2606},"As so often is the case, the answer was staring us right in the face - we can use our browser extension. By placing a verification code in the details tray of every employees’ Push extension, they can use that to verify their identity with their help desk team.",[],{},{"nodeType":1376,"data":2608,"content":2612},{"target":2609},{"sys":2610},{"id":2611,"type":1381,"linkType":1382},"4hRJVGqKGyOHJ8NSsQYWGP",[],{"nodeType":1447,"data":2614,"content":2615},{},[2616],{"nodeType":1293,"value":2617,"marks":2618,"data":2619},"Get started today!",[],{},{"nodeType":1294,"data":2621,"content":2622},{},[2623],{"nodeType":1293,"value":2624,"marks":2625,"data":2626},"Employee verification codes is a Labs feature, which means it’s available on an early-access basis. We're particularly interested in hearing your feedback on how to develop this feature further.",[],{},{"nodeType":1294,"data":2628,"content":2629},{},[2630,2634,2639,2643,2648],{"nodeType":1293,"value":2631,"marks":2632,"data":2633},"You can enable Labs features by going to the ",[],{},{"nodeType":1293,"value":2635,"marks":2636,"data":2638},"Settings",[2637],{"type":1333},{},{"nodeType":1293,"value":2640,"marks":2641,"data":2642}," page of the Push admin console and choosing the ",[],{},{"nodeType":1293,"value":2644,"marks":2645,"data":2647},"Labs",[2646],{"type":1333},{},{"nodeType":1293,"value":2649,"marks":2650,"data":2651}," tab.",[],{},{"nodeType":1376,"data":2653,"content":2657},{"target":2654},{"sys":2655},{"id":2656,"type":1381,"linkType":1382},"6TyqP2eOmalIF6RRoe476Y",[],{"nodeType":1294,"data":2659,"content":2660},{},[2661,2665,2673],{"nodeType":1293,"value":2662,"marks":2663,"data":2664},"If you’d like to find out more about this feature, and the other ways Push is stopping identity attacks in the browser, ",[],{},{"nodeType":1392,"data":2666,"content":2667},{"uri":2310},[2668],{"nodeType":1293,"value":2669,"marks":2670,"data":2672},"book a demo",[2671],{"type":1400},{},{"nodeType":1293,"value":2674,"marks":2675,"data":2676}," with one of our team. ",[],{},{"nodeType":1376,"data":2678,"content":2682},{"target":2679},{"sys":2680},{"id":2681,"type":1381,"linkType":1382},"7xBE9MrnMy3hfwIkhLhNhQ",[],{"nodeType":1294,"data":2684,"content":2685},{},[2686],{"nodeType":1293,"value":37,"marks":2687,"data":2688},[],{},"A simple, browser-based way to protect your help desk against social engineering","Push's new Employee Identity Verification Codes feature is a simple way for your help desk to confirm they’re talking to someone from your organization.\n","2025-06-19T00:00:00.000Z","employee-identity-verification-codes-release",{"items":2694},[2695],{"sys":2696,"name":2698},{"id":2697},"3pjES4THCIfSAwhGdNwBcy","Identity security",{"items":2700},[2701],{"fullName":2702,"firstName":2703,"jobTitle":2335,"profilePicture":2704},"Alex Henshall","Alex",{"url":2705},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg",{"__typename":1312,"sys":2707,"content":2709,"title":3268,"synopsis":3269,"hashTags":118,"publishedDate":3270,"slug":3271,"tagsCollection":3272,"authorsCollection":3278},{"id":2708},"4XZ6qCr8pjJvcD7hi09x2Y",{"json":2710},{"data":2711,"content":2712,"nodeType":1295},{},[2713,2733,2740,2763,2770,2777,2784,2804,2810,2813,2821,2828,2848,2894,2940,2973,2993,2999,3002,3010,3017,3024,3031,3038,3161,3168,3171,3179,3196,3214,3217,3225,3243,3250],{"data":2714,"content":2715,"nodeType":1294},{},[2716,2720,2729],{"data":2717,"marks":2718,"value":2719,"nodeType":1293},{},[],"Almost two years ago, we released our ",{"data":2721,"content":2723,"nodeType":1392},{"uri":2722},"https://github.com/pushsecurity/saas-attacks",[2724],{"data":2725,"marks":2726,"value":2728,"nodeType":1293},{},[2727],{"type":1400},"SaaS attacks matrix",{"data":2730,"marks":2731,"value":2732,"nodeType":1293},{},[]," on GitHub. At the time, our research into modern attack patterns showed us that attackers were increasingly relying on cloud-native techniques, taking advantage of the shift in business IT from traditional on-premise networks to a web of third-party services accessed over the internet. ",{"data":2734,"content":2735,"nodeType":1294},{},[2736],{"data":2737,"marks":2738,"value":2739,"nodeType":1293},{},[],"As part of our work in maintaining and updating the SaaS attacks matrix in line with our own research and attacks in the wild, we identified that:",{"data":2741,"content":2742,"nodeType":1832},{},[2743,2753],{"data":2744,"content":2745,"nodeType":1836},{},[2746],{"data":2747,"content":2748,"nodeType":1294},{},[2749],{"data":2750,"marks":2751,"value":2752,"nodeType":1293},{},[],"The fastest growing category since day 1 has been initial access, which is entirely driven by identity-based techniques (i.e. logging into apps).",{"data":2754,"content":2755,"nodeType":1836},{},[2756],{"data":2757,"content":2758,"nodeType":1294},{},[2759],{"data":2760,"marks":2761,"value":2762,"nodeType":1293},{},[],"Phishing in various forms is the most widely used, and generally effective, of all the initial access techniques we encounter. ",{"data":2764,"content":2765,"nodeType":1294},{},[2766],{"data":2767,"marks":2768,"value":2769,"nodeType":1293},{},[],"It’s increasingly difficult to reflect a lot of the research we’re doing within the parameters of the SaaS attacks matrix when attackers are doing so much (and to varying levels) in how they architect their phishing sites, distribute links and lures, and find novel ways around authentication and access controls. ",{"data":2771,"content":2772,"nodeType":1294},{},[2773],{"data":2774,"marks":2775,"value":2776,"nodeType":1293},{},[],"Equally, while there’s a huge amount of valuable research and deep-dive analysis of how individual phishing kits are behaving produced by security firms, there’s a gap in how we’re bringing together this knowledge and understanding the broad strokes of why and how phishing attacks are still so successful.  ",{"data":2778,"content":2779,"nodeType":1294},{},[2780],{"data":2781,"marks":2782,"value":2783,"nodeType":1293},{},[],"We come across so many phishing attacks on a daily basis that it’s impossible to write a deep-dive teardown on every one — and to some extent it wouldn’t be useful to do so. What’s arguably more valuable is understanding the patterns and commonalities across phishing campaigns that can help us to understand, generally, how malicious tooling and tradecraft is evolving. ",{"data":2785,"content":2786,"nodeType":1294},{},[2787,2791,2800],{"data":2788,"marks":2789,"value":2790,"nodeType":1293},{},[],"So, we decided to ",{"data":2792,"content":2794,"nodeType":1392},{"uri":2793},"https://pushsecurity.github.io/phishing-techniques/",[2795],{"data":2796,"marks":2797,"value":2799,"nodeType":1293},{},[2798],{"type":1400},"create a new resource",{"data":2801,"marks":2802,"value":2803,"nodeType":1293},{},[]," giving phishing the space to breathe that it deserves. ",{"data":2805,"content":2809,"nodeType":1376},{"target":2806},{"sys":2807},{"id":2808,"type":1381,"linkType":1382},"7rK8RR8KKQ9DbBouZKnjs6",[],{"data":2811,"content":2812,"nodeType":1443},{},[],{"data":2814,"content":2815,"nodeType":1447},{},[2816],{"data":2817,"marks":2818,"value":2820,"nodeType":1293},{},[2819],{"type":1333},"How phishing has evolved",{"data":2822,"content":2823,"nodeType":1294},{},[2824],{"data":2825,"marks":2826,"value":2827,"nodeType":1293},{},[],"It’s easy to write off phishing as unsophisticated and simplistic, particularly when we think back to the first generation of phishing attacks — static HTML pages purely designed to steal your username and password, linked directly from an email. ",{"data":2829,"content":2830,"nodeType":1294},{},[2831,2835,2844],{"data":2832,"marks":2833,"value":2834,"nodeType":1293},{},[],"Modern phishing has changed a lot in the past decade or so. ",{"data":2836,"content":2838,"nodeType":1392},{"uri":2837},"https://phishing-techniques.pushsecurity.com/techniques/aitm-phishing/",[2839],{"data":2840,"marks":2841,"value":2843,"nodeType":1293},{},[2842],{"type":1400},"MFA-bypassing  Attacker-in-the-Middle (AitM) kits",{"data":2845,"marks":2846,"value":2847,"nodeType":1293},{},[]," are table stakes — anyone can pick up a copy of Evilginx and immediately blow past most email and network security solutions on the market.  ",{"data":2849,"content":2850,"nodeType":1294},{},[2851,2855,2864,2868,2877,2881,2890],{"data":2852,"marks":2853,"value":2854,"nodeType":1293},{},[],"But the most sophisticated attacks — the ones that usually hit the headlines in the form of major breaches — are doing much more than this. The latest generation of fully customized AitM phishing kits are ",{"data":2856,"content":2858,"nodeType":1392},{"uri":2857},"https://phishing-techniques.pushsecurity.com/techniques/code-obfuscation/",[2859],{"data":2860,"marks":2861,"value":2863,"nodeType":1293},{},[2862],{"type":1400},"dynamically obfuscating the code that loads the web page",{"data":2865,"marks":2866,"value":2867,"nodeType":1293},{},[],", implementing ",{"data":2869,"content":2871,"nodeType":1392},{"uri":2870},"https://phishing-techniques.pushsecurity.com/techniques/bot-protection/",[2872],{"data":2873,"marks":2874,"value":2876,"nodeType":1293},{},[2875],{"type":1400},"bot protection through custom CAPTCHA",{"data":2878,"marks":2879,"value":2880,"nodeType":1293},{},[],", and using ",{"data":2882,"content":2884,"nodeType":1392},{"uri":2883},"https://phishing-techniques.pushsecurity.com/techniques/anti-sandbox/",[2885],{"data":2886,"marks":2887,"value":2889,"nodeType":1293},{},[2888],{"type":1400},"runtime anti-analysis features",{"data":2891,"marks":2892,"value":2893,"nodeType":1293},{},[],", making them increasingly difficult to detect by the tools most enterprises are using to combat the problem. ",{"data":2895,"content":2896,"nodeType":1294},{},[2897,2901,2910,2914,2923,2927,2936],{"data":2898,"marks":2899,"value":2900,"nodeType":1293},{},[],"The techniques used by attackers to deliver phishing lures are also more sophisticated. Groups like Scattered Spider have been seen using ",{"data":2902,"content":2904,"nodeType":1392},{"uri":2903},"https://phishing-techniques.pushsecurity.com/techniques/malvertising/",[2905],{"data":2906,"marks":2907,"value":2909,"nodeType":1293},{},[2908],{"type":1400},"malvertising",{"data":2911,"marks":2912,"value":2913,"nodeType":1293},{},[]," techniques, delivering phishing links via paid Google ads, while phishing campaigns are frequently encountered in ",{"data":2915,"content":2917,"nodeType":1392},{"uri":2916},"https://phishing-techniques.pushsecurity.com/techniques/instant-messenger/",[2918],{"data":2919,"marks":2920,"value":2922,"nodeType":1293},{},[2921],{"type":1400},"IM apps",{"data":2924,"marks":2925,"value":2926,"nodeType":1293},{},[]," (such as Slack and Teams), as well as ",{"data":2928,"content":2930,"nodeType":1392},{"uri":2929},"https://phishing-techniques.pushsecurity.com/techniques/social-media/",[2931],{"data":2932,"marks":2933,"value":2935,"nodeType":1293},{},[2934],{"type":1400},"public messaging services",{"data":2937,"marks":2938,"value":2939,"nodeType":1293},{},[]," like LinkedIn messenger and Reddit — bypassing email altogether. ",{"data":2941,"content":2942,"nodeType":1294},{},[2943,2947,2956,2960,2969],{"data":2944,"marks":2945,"value":2946,"nodeType":1293},{},[],"The latest trends indicate that attackers are responding to increasingly hardened IdP/SSO configuration by using alternative phishing techniques that circumvent MFA and passkeys, either by ",{"data":2948,"content":2950,"nodeType":1392},{"uri":2949},"https://phishing-techniques.pushsecurity.com/techniques/mfa-downgrade/",[2951],{"data":2952,"marks":2953,"value":2955,"nodeType":1293},{},[2954],{"type":1400},"downgrading to a backup (less secure) authentication method",{"data":2957,"marks":2958,"value":2959,"nodeType":1293},{},[],", or sidestepping the legitimate auth process entirely through methods like ",{"data":2961,"content":2963,"nodeType":1392},{"uri":2962},"https://phishing-techniques.pushsecurity.com/techniques/consent-phishing/",[2964],{"data":2965,"marks":2966,"value":2968,"nodeType":1293},{},[2967],{"type":1400},"consent phishing",{"data":2970,"marks":2971,"value":2972,"nodeType":1293},{},[],". ",{"data":2974,"content":2975,"nodeType":1294},{},[2976,2980,2989],{"data":2977,"marks":2978,"value":2979,"nodeType":1293},{},[],"Attackers have also realized how much valuable data exists in Shadow SaaS highlighted by major SaaS breaches impacting apps like Snowflake. This is driving ",{"data":2981,"content":2983,"nodeType":1392},{"uri":2982},"https://phishing-techniques.pushsecurity.com/techniques/saas-admins/",[2984],{"data":2985,"marks":2986,"value":2988,"nodeType":1293},{},[2987],{"type":1400},"broader targeting against apps like Slack, Mailchimp, Postman, GitHub, and other commonly-used business apps directly",{"data":2990,"marks":2991,"value":2992,"nodeType":1293},{},[]," — bypassing IdPs (MS, Google, Okta, etc.) that typically have more robust authentication controls in place.",{"data":2994,"content":2998,"nodeType":1376},{"target":2995},{"sys":2996},{"id":2997,"type":1381,"linkType":1382},"1II2kHyOZcShLsexx1TAgy",[],{"data":3000,"content":3001,"nodeType":1443},{},[],{"data":3003,"content":3004,"nodeType":1447},{},[3005],{"data":3006,"marks":3007,"value":3009,"nodeType":1293},{},[3008],{"type":1333},"Using the phishing detection evasion techniques matrix",{"data":3011,"content":3012,"nodeType":1294},{},[3013],{"data":3014,"marks":3015,"value":3016,"nodeType":1293},{},[],"With so much attacker innovation happening in the phishing space, it’s tricky for security teams and solution vendors to have a big picture view of the subtle changes attackers are making to their phishing attacks, and precisely why they’re doing it — or more specifically, which detection techniques they’re evading. ",{"data":3018,"content":3019,"nodeType":1294},{},[3020],{"data":3021,"marks":3022,"value":3023,"nodeType":1293},{},[],"If you look at one of the many phishing kit teardowns found in security blogs online (including our own) it can be hard to see the wood for the trees when it comes to understanding why a phishing page behaves in the way it does — why is it behaving in this way? What control exactly is this trying to get around? ",{"data":3025,"content":3026,"nodeType":1294},{},[3027],{"data":3028,"marks":3029,"value":3030,"nodeType":1293},{},[],"By creating a simple framework breaking down the categories of a phishing attack into phases, each with its own specific attacker objective, we can better understand phishing kit behavior and track meaningful changes over time. This ensures that we understand how we need to adapt to as an industry in order to detect and block these attacks. ",{"data":3032,"content":3033,"nodeType":1294},{},[3034],{"data":3035,"marks":3036,"value":3037,"nodeType":1293},{},[],"The matrix covers the following categories:",{"data":3039,"content":3040,"nodeType":1832},{},[3041,3056,3071,3086,3101,3116,3131,3146],{"data":3042,"content":3043,"nodeType":1836},{},[3044],{"data":3045,"content":3046,"nodeType":1294},{},[3047,3052],{"data":3048,"marks":3049,"value":3051,"nodeType":1293},{},[3050],{"type":1333},"Phase 1: Targeting",{"data":3053,"marks":3054,"value":3055,"nodeType":1293},{},[]," — Identifying apps and users to evade security controls and achieve the shortest time-to-impact of a phishing attack. ",{"data":3057,"content":3058,"nodeType":1836},{},[3059],{"data":3060,"content":3061,"nodeType":1294},{},[3062,3067],{"data":3063,"marks":3064,"value":3066,"nodeType":1293},{},[3065],{"type":1333},"Phase 2: Link delivery",{"data":3068,"marks":3069,"value":3070,"nodeType":1293},{},[]," — Deliver links using phishing vectors that evade traditional security controls. ",{"data":3072,"content":3073,"nodeType":1836},{},[3074],{"data":3075,"content":3076,"nodeType":1294},{},[3077,3082],{"data":3078,"marks":3079,"value":3081,"nodeType":1293},{},[3080],{"type":1333},"Phase 3: Link camouflage",{"data":3083,"marks":3084,"value":3085,"nodeType":1293},{},[]," — Masking malicious links to prevent detection at the email, network proxy, or safe browsing layer. ",{"data":3087,"content":3088,"nodeType":1836},{},[3089],{"data":3090,"content":3091,"nodeType":1294},{},[3092,3097],{"data":3093,"marks":3094,"value":3096,"nodeType":1293},{},[3095],{"type":1333},"Phase 4: TI evasion ",{"data":3098,"marks":3099,"value":3100,"nodeType":1293},{},[],"— Preventing TI feeds from flagging and blocking known-bad domains by masking or changing elements likely to be flagged.",{"data":3102,"content":3103,"nodeType":1836},{},[3104],{"data":3105,"content":3106,"nodeType":1294},{},[3107,3112],{"data":3108,"marks":3109,"value":3111,"nodeType":1293},{},[3110],{"type":1333},"Phase 5: Anti-analysis",{"data":3113,"marks":3114,"value":3115,"nodeType":1293},{},[]," — Techniques to defeat automated “sandbox” analysis tools by preventing security teams and bots from accessing the page.",{"data":3117,"content":3118,"nodeType":1836},{},[3119],{"data":3120,"content":3121,"nodeType":1294},{},[3122,3127],{"data":3123,"marks":3124,"value":3126,"nodeType":1293},{},[3125],{"type":1333},"Phase 6: Page obfuscation",{"data":3128,"marks":3129,"value":3130,"nodeType":1293},{},[]," — Obfuscating page elements to break detection signatures analysing page content and code. ",{"data":3132,"content":3133,"nodeType":1836},{},[3134],{"data":3135,"content":3136,"nodeType":1294},{},[3137,3142],{"data":3138,"marks":3139,"value":3141,"nodeType":1293},{},[3140],{"type":1333},"Phase 7: Defeat MFA & CA",{"data":3143,"marks":3144,"value":3145,"nodeType":1293},{},[]," — Defeat authentication and access controls in order to successfully execute the phishing attack.",{"data":3147,"content":3148,"nodeType":1836},{},[3149],{"data":3150,"content":3151,"nodeType":1294},{},[3152,3157],{"data":3153,"marks":3154,"value":3156,"nodeType":1293},{},[3155],{"type":1333},"Phase 8: Account takeover",{"data":3158,"marks":3159,"value":3160,"nodeType":1293},{},[]," — Achieve a form of account takeover and conclude the identity attack, enabling further exploitation to take place.",{"data":3162,"content":3163,"nodeType":1294},{},[3164],{"data":3165,"marks":3166,"value":3167,"nodeType":1293},{},[],"Combining techniques and approaches from these categories is what enables attackers to bypass the majority of phishing detection controls they encounter today. You typically find that the more advanced the phishing kit / attacker, the more techniques they’ll leverage. And as phishing infrastructure becomes increasingly templated and commodified with as-a-Service or for-hire models, the average phishing attack will employ more of these measures to counter security controls. ",{"data":3169,"content":3170,"nodeType":1443},{},[],{"data":3172,"content":3173,"nodeType":1447},{},[3174],{"data":3175,"marks":3176,"value":3178,"nodeType":1293},{},[3177],{"type":1333},"Learn more",{"data":3180,"content":3181,"nodeType":1294},{},[3182,3185,3193],{"data":3183,"marks":3184,"value":37,"nodeType":1293},{},[],{"data":3186,"content":3187,"nodeType":1392},{"uri":2793},[3188],{"data":3189,"marks":3190,"value":3192,"nodeType":1293},{},[3191],{"type":1400},"You can find the matrix here.",{"data":3194,"marks":3195,"value":37,"nodeType":1293},{},[],{"data":3197,"content":3198,"nodeType":1294},{},[3199,3203,3211],{"data":3200,"marks":3201,"value":3202,"nodeType":1293},{},[],"If you want to learn more about the research that led us to this point, and our take on how and why phishing attacks have evolved, ",{"data":3204,"content":3206,"nodeType":1392},{"uri":3205},"https://pushsecurity.com/resources/phishing-evolution",[3207],{"data":3208,"marks":3209,"value":3210,"nodeType":1293},{},[],"you can also check out our latest whitepaper. ",{"data":3212,"marks":3213,"value":37,"nodeType":1293},{},[],{"data":3215,"content":3216,"nodeType":1443},{},[],{"data":3218,"content":3219,"nodeType":1447},{},[3220],{"data":3221,"marks":3222,"value":3224,"nodeType":1293},{},[3223],{"type":1333},"Get involved!",{"data":3226,"content":3227,"nodeType":1294},{},[3228,3232,3239],{"data":3229,"marks":3230,"value":3231,"nodeType":1293},{},[],"Like the ",{"data":3233,"content":3234,"nodeType":1392},{"uri":2722},[3235],{"data":3236,"marks":3237,"value":3238,"nodeType":1293},{},[],"SaaS attack matrix",{"data":3240,"marks":3241,"value":3242,"nodeType":1293},{},[],", we’d love to see the security community using and helping us to maintain this resource to ensure it stays up to date with techniques as they evolve. ",{"data":3244,"content":3245,"nodeType":1294},{},[3246],{"data":3247,"marks":3248,"value":3249,"nodeType":1293},{},[],"Unlike the SaaS matrix, which we’ve seen mostly leveraged by offensive security practitioners, phishing detection evasion techniques are most useful to blue teamers looking to assess current detection capabilities and understand why certain attacks got through existing defenses. ",{"data":3251,"content":3252,"nodeType":1294},{},[3253,3257,3265],{"data":3254,"marks":3255,"value":3256,"nodeType":1293},{},[],"If you’d like to add techniques you’ve observed or examples that you think demonstrate them, ",{"data":3258,"content":3260,"nodeType":1392},{"uri":3259},"https://github.com/pushsecurity/phishing-techniques",[3261],{"data":3262,"marks":3263,"value":3264,"nodeType":1293},{},[],"get involved on GitHub!",{"data":3266,"marks":3267,"value":37,"nodeType":1293},{},[],"Introducing our guide to phishing detection evasion techniques","Introducing our latest resource for security teams breaking down the techniques that modern phishing attacks are using to evade detection. ","2025-08-06T00:00:00.000Z","phishing-detection-evasion-launch",{"items":3273},[3274,3276],{"sys":3275,"name":1304},{"id":1303},{"sys":3277,"name":1308},{"id":1307},{"items":3279},[3280],{"fullName":3281,"firstName":3282,"jobTitle":3283,"profilePicture":3284},"Jacques Louw","Jacques","Co-founder / CRO",{"url":3285},"https://images.ctfassets.net/y1cdw1ablpvd/39m8bektV23lnCRcEq0G8h/2a08f6276a50744f1a4b499b273f6bb2/Push_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-21.jpg",{"items":3287},[3288],{"fullName":3289,"firstName":3290,"jobTitle":3291,"profilePicture":3292},"Dan Green","Dan","Threat Research",{"url":3293},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"json":3295,"links":4082},{"nodeType":1295,"data":3296,"content":3297},{},[3298,3305,3338,3345,3351,3358,3390,3397,3403,3406,3414,3421,3428,3485,3504,3516,3523,3529,3532,3540,3556,3562,3569,3575,3582,3620,3626,3629,3637,3644,3651,3779,3785,3816,3823,3826,3834,3841,3848,3890,3919,3926,4001,4007,4010,4018,4025,4045,4048,4056,4063],{"nodeType":1294,"data":3299,"content":3300},{},[3301],{"nodeType":1293,"value":3302,"marks":3303,"data":3304},"Until recently, the cyber attacker methodology behind the biggest breaches of the last decade or so has been pretty consistent:",[],{},{"nodeType":1832,"data":3306,"content":3307},{},[3308,3318,3328],{"nodeType":1836,"data":3309,"content":3310},{},[3311],{"nodeType":1294,"data":3312,"content":3313},{},[3314],{"nodeType":1293,"value":3315,"marks":3316,"data":3317},"Compromise an endpoint via software exploit, or social engineering a user to run malware on their device; ",[],{},{"nodeType":1836,"data":3319,"content":3320},{},[3321],{"nodeType":1294,"data":3322,"content":3323},{},[3324],{"nodeType":1293,"value":3325,"marks":3326,"data":3327},"Find ways to move laterally inside the network and compromise privileged identities;",[],{},{"nodeType":1836,"data":3329,"content":3330},{},[3331],{"nodeType":1294,"data":3332,"content":3333},{},[3334],{"nodeType":1293,"value":3335,"marks":3336,"data":3337},"Repeat as needed until you can execute your desired attack — usually stealing data from file shares, deploying ransomware, or both. ",[],{},{"nodeType":1294,"data":3339,"content":3340},{},[3341],{"nodeType":1293,"value":3342,"marks":3343,"data":3344},"But attacks have fundamentally changed as networks have evolved. With the SaaS-ification of enterprise IT, core business systems aren’t locally deployed and centrally managed in the way they used to be. Instead, they’re logged into over the internet, via a web browser.",[],{},{"nodeType":1376,"data":3346,"content":3350},{"target":3347},{"sys":3348},{"id":3349,"type":1381,"linkType":1382},"4h4hUYAghbZavOwjRTnBe2",[],{"nodeType":1294,"data":3352,"content":3353},{},[3354],{"nodeType":1293,"value":3355,"marks":3356,"data":3357},"Under the shared responsibility model, the part that’s left to the business consuming a SaaS service is mostly constrained to how they manage identities — the vehicle by which the app is accessed and used by the workforce. It’s no surprise that this has become the soft underbelly in the crosshairs of attackers. ",[],{},{"nodeType":1294,"data":3359,"content":3360},{},[3361,3365,3374,3378,3387],{"nodeType":1293,"value":3362,"marks":3363,"data":3364},"We’ve seen this time and again in the biggest breaches of recent years, with the highlights including the massive ",[],{},{"nodeType":1392,"data":3366,"content":3368},{"uri":3367},"https://pushsecurity.com/blog/snowflake-retro/",[3369],{"nodeType":1293,"value":3370,"marks":3371,"data":3373},"Snowflake campaign in 2024",[3372],{"type":1400},{},{"nodeType":1293,"value":3375,"marks":3376,"data":3377}," and the ",[],{},{"nodeType":1392,"data":3379,"content":3381},{"uri":3380},"https://pushsecurity.com/blog/key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/",[3382],{"nodeType":1293,"value":3383,"marks":3384,"data":3386},"2025 crime wave attributed to Scattered Spider",[3385],{"type":1400},{},{"nodeType":1293,"value":1603,"marks":3388,"data":3389},[],{},{"nodeType":1294,"data":3391,"content":3392},{},[3393],{"nodeType":1293,"value":3394,"marks":3395,"data":3396},"These attacks are so successful because while attackers have moved with the changes to enterprise IT, security hasn’t really kept up. ",[],{},{"nodeType":1376,"data":3398,"content":3402},{"target":3399},{"sys":3400},{"id":3401,"type":1381,"linkType":1382},"xH0ZqgKQXCRRZGYVs6xt6",[],{"nodeType":1443,"data":3404,"content":3405},{},[],{"nodeType":1447,"data":3407,"content":3408},{},[3409],{"nodeType":1293,"value":3410,"marks":3411,"data":3413},"The browser is the new battleground — and a security blind spot",[3412],{"type":1333},{},{"nodeType":1294,"data":3415,"content":3416},{},[3417],{"nodeType":1293,"value":3418,"marks":3419,"data":3420},"Taking over workforce identities is the first objective for attackers looking to target an organization, and the browser is the place where the attacks against users happen. This is because it’s where these digital identities are created and used — and their credentials and sessions live. This is what the attacker wants to get their hands on. ",[],{},{"nodeType":1294,"data":3422,"content":3423},{},[3424],{"nodeType":1293,"value":3425,"marks":3426,"data":3427},"Stolen credentials can be used as part of targeted attacks or in broader credential stuffing (cycling known username and credential pairs against various apps and platforms), while stolen session tokens can be used to log in directly to an active session, bypassing the authentication process. ",[],{},{"nodeType":1294,"data":3429,"content":3430},{},[3431,3435,3440,3443,3448,3451,3456,3459,3464,3467,3472,3476,3481],{"nodeType":1293,"value":3432,"marks":3433,"data":3434},"There are a few different techniques that attackers can use to get access to these identities. Attackers harvest stolen credentials from various places — ",[],{},{"nodeType":1293,"value":3436,"marks":3437,"data":3439},"data breach dumps",[3438],{"type":1333},{},{"nodeType":1293,"value":2268,"marks":3441,"data":3442},[],{},{"nodeType":1293,"value":3444,"marks":3445,"data":3447},"mass",[3446],{"type":1333},{},{"nodeType":1293,"value":1594,"marks":3449,"data":3450},[],{},{"nodeType":1293,"value":3452,"marks":3453,"data":3455},"credential",[3454],{"type":1333},{},{"nodeType":1293,"value":1594,"marks":3457,"data":3458},[],{},{"nodeType":1293,"value":3460,"marks":3461,"data":3463},"phishing campaigns,",[3462],{"type":1333},{},{"nodeType":1293,"value":1594,"marks":3465,"data":3466},[],{},{"nodeType":1293,"value":3468,"marks":3469,"data":3471},"infostealer logs",[3470],{"type":1333},{},{"nodeType":1293,"value":3473,"marks":3474,"data":3475},", even ",[],{},{"nodeType":1293,"value":3477,"marks":3478,"data":3480},"malicious browser extensions",[3479],{"type":1333},{},{"nodeType":1293,"value":3482,"marks":3483,"data":3484}," that they’ve tricked an employee into installing. In fact, the cyber crime ecosystem itself has shifted on its axis to cater to this, with hackers specifically taking on the role of harvesting credentials and establishing account access for others to exploit. ",[],{},{"nodeType":1294,"data":3486,"content":3487},{},[3488,3492,3500],{"nodeType":1293,"value":3489,"marks":3490,"data":3491},"The high-profile ",[],{},{"nodeType":1392,"data":3493,"content":3494},{"uri":3367},[3495],{"nodeType":1293,"value":3496,"marks":3497,"data":3499},"Snowflake",[3498],{"type":1400},{},{"nodeType":1293,"value":3501,"marks":3502,"data":3503}," breaches in 2024 signalled a watershed moment in the shift to identity-driven breaches, where attackers logged into accounts across hundreds of customer tenants using stolen credentials. One of the primary sources of the stolen credentials used in the attacks were infostealer logs dating back to 2020 — breached passwords that hadn’t been rotated or mitigated with MFA. ",[],{},{"nodeType":1294,"data":3505,"content":3506},{},[3507,3511],{"nodeType":1293,"value":3508,"marks":3509,"data":3510},"Infostealers are notable because they’re an endpoint malware attack designed to harvest credentials and session tokens (often from the browser) to enable the attacker to then log into those services… through their own web browser. ",[],{},{"nodeType":1293,"value":3512,"marks":3513,"data":3515},"So, even today’s endpoint attacks are seeing the attacker pivot back into the browser in order to get to identities — the key to the online apps and services where exploitable data and functionality now resides. ",[3514],{"type":1333},{},{"nodeType":1294,"data":3517,"content":3518},{},[3519],{"nodeType":1293,"value":3520,"marks":3521,"data":3522},"The problem here is that this is a blind spot for the security tools we’re currently reliant upon — which don’t have the fine-grained visibility required. This is very similar to the challenge that the industry faced prior to the introduction of EDR in the 2010s — the main sources of data are looking from the outside-in, lacking the process-level visibility and context to be able to detect and stop attacks as they happen.",[],{},{"nodeType":1376,"data":3524,"content":3528},{"target":3525},{"sys":3526},{"id":3527,"type":1381,"linkType":1382},"2qoMH6qCNJc7it7sTuKl4F",[],{"nodeType":1443,"data":3530,"content":3531},{},[],{"nodeType":1447,"data":3533,"content":3534},{},[3535],{"nodeType":1293,"value":3536,"marks":3537,"data":3539},"Identity is the prize, browser is the platform — and phishing is the weapon of choice",[3538],{"type":1333},{},{"nodeType":1294,"data":3541,"content":3542},{},[3543,3547,3552],{"nodeType":1293,"value":3544,"marks":3545,"data":3546},"But the technique that’s STILL driving the most impactful identity-driven breaches? ",[],{},{"nodeType":1293,"value":3548,"marks":3549,"data":3551},"It’s phishing",[3550],{"type":1333},{},{"nodeType":1293,"value":3553,"marks":3554,"data":3555},". Phishing for credentials, sessions, OAuth consent, authorization codes. Phishing via email, instant messenger, social media, malicious Google ads… it all happens in, or leads to, the browser. ",[],{},{"nodeType":1376,"data":3557,"content":3561},{"target":3558},{"sys":3559},{"id":3560,"type":1381,"linkType":1382},"6Gsd3G0sOibNxgVLimb2wV",[],{"nodeType":1294,"data":3563,"content":3564},{},[3565],{"nodeType":1293,"value":3566,"marks":3567,"data":3568},"And modern phishing attacks are more effective than ever. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques to block email and network security tools from intercepting them. Probably the most common example today is the use of bot protection (think CAPTCHA or Cloudflare Turnstile), using legitimate anti-spam features to block security tools. ",[],{},{"nodeType":1376,"data":3570,"content":3574},{"target":3571},{"sys":3572},{"id":3573,"type":1381,"linkType":1382},"6M1My4lSKItu6Qdv4hO1RA",[],{"nodeType":1294,"data":3576,"content":3577},{},[3578],{"nodeType":1293,"value":3579,"marks":3580,"data":3581},"The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom CAPTCHA, and using runtime anti-analysis features, making them increasingly difficult to detect. The ways in which links are delivered has also increased in sophistication, with more delivery channels (as we showed above) and the use of legitimate SaaS services for camouflage. ",[],{},{"nodeType":1294,"data":3583,"content":3584},{},[3585,3589,3594,3598,3603,3607,3616],{"nodeType":1293,"value":3586,"marks":3587,"data":3588},"And the latest trends indicate that attackers are responding to increasingly hardened IdP/SSO configuration by exploiting alternative phishing techniques that ",[],{},{"nodeType":1293,"value":3590,"marks":3591,"data":3593},"circumvent MFA and passkeys",[3592],{"type":1333},{},{"nodeType":1293,"value":3595,"marks":3596,"data":3597},", most commonly by ",[],{},{"nodeType":1293,"value":3599,"marks":3600,"data":3602},"downgrading to a phishable backup authentication method",[3601],{"type":1333},{},{"nodeType":1293,"value":3604,"marks":3605,"data":3606}," — which you can see in action below, and ",[],{},{"nodeType":1392,"data":3608,"content":3610},{"uri":3609},"https://pushsecurity.com/blog/mfa-downgrade-attacks/",[3611],{"nodeType":1293,"value":3612,"marks":3613,"data":3615},"read more about here",[3614],{"type":1400},{},{"nodeType":1293,"value":3617,"marks":3618,"data":3619},".  ",[],{},{"nodeType":1376,"data":3621,"content":3625},{"target":3622},{"sys":3623},{"id":3624,"type":1381,"linkType":1382},"54I3YQ2gK26a8FIocQ3WYT",[],{"nodeType":1443,"data":3627,"content":3628},{},[],{"nodeType":1447,"data":3630,"content":3631},{},[3632],{"nodeType":1293,"value":3633,"marks":3634,"data":3636},"Identities are the lowest-hanging fruit for attackers to aim for",[3635],{"type":1333},{},{"nodeType":1294,"data":3638,"content":3639},{},[3640],{"nodeType":1293,"value":3641,"marks":3642,"data":3643},"The goal of the modern attacker, and the easiest way into your business’s digital environment, is to compromise identities. Whether you’re dealing with phishing attacks, malicious browser extensions, or infostealer malware, the objective remains the same — account takeover. ",[],{},{"nodeType":1294,"data":3645,"content":3646},{},[3647],{"nodeType":1293,"value":3648,"marks":3649,"data":3650},"Organizations are dealing with a vast and vulnerable attack surface consisting of:",[],{},{"nodeType":1832,"data":3652,"content":3653},{},[3654,3676,3698,3720],{"nodeType":1836,"data":3655,"content":3656},{},[3657],{"nodeType":1294,"data":3658,"content":3659},{},[3660,3663,3672],{"nodeType":1293,"value":37,"marks":3661,"data":3662},[],{},{"nodeType":1392,"data":3664,"content":3666},{"uri":3665},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[3667],{"nodeType":1293,"value":3668,"marks":3669,"data":3671},"Hundreds of applications, with thousands of accounts",[3670],{"type":1400},{},{"nodeType":1293,"value":3673,"marks":3674,"data":3675}," spread across the app estate.",[],{},{"nodeType":1836,"data":3677,"content":3678},{},[3679],{"nodeType":1294,"data":3680,"content":3681},{},[3682,3686,3694],{"nodeType":1293,"value":3683,"marks":3684,"data":3685},"Accounts vulnerable to MFA-bypass phishing kits, because they are using a login method that is not phishing-resistant, or because ",[],{},{"nodeType":1392,"data":3687,"content":3688},{"uri":3609},[3689],{"nodeType":1293,"value":3690,"marks":3691,"data":3693},"the login method can be downgraded",[3692],{"type":1400},{},{"nodeType":1293,"value":3695,"marks":3696,"data":3697},".",[],{},{"nodeType":1836,"data":3699,"content":3700},{},[3701],{"nodeType":1294,"data":3702,"content":3703},{},[3704,3708,3716],{"nodeType":1293,"value":3705,"marks":3706,"data":3707},"Accounts with a weak, reused, or breached password and no MFA altogether (usually the result of a forgotten-about ",[],{},{"nodeType":1392,"data":3709,"content":3710},{"uri":1766},[3711],{"nodeType":1293,"value":3712,"marks":3713,"data":3715},"ghost login",[3714],{"type":1400},{},{"nodeType":1293,"value":3717,"marks":3718,"data":3719},").",[],{},{"nodeType":1836,"data":3721,"content":3722},{},[3723],{"nodeType":1294,"data":3724,"content":3725},{},[3726,3730,3739,3742,3751,3755,3763,3766,3775],{"nodeType":1293,"value":3727,"marks":3728,"data":3729},"Bypassing the authentication process entirely to evade otherwise phishing-resistant authentication methods, by abusing features like ",[],{},{"nodeType":1392,"data":3731,"content":3733},{"uri":3732},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/api_keys/description.md",[3734],{"nodeType":1293,"value":3735,"marks":3736,"data":3738},"API key creation",[3737],{"type":1400},{},{"nodeType":1293,"value":2268,"marks":3740,"data":3741},[],{},{"nodeType":1392,"data":3743,"content":3745},{"uri":3744},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/app_specific_password_phishing/description.md",[3746],{"nodeType":1293,"value":3747,"marks":3748,"data":3750},"app-specific passwords",[3749],{"type":1400},{},{"nodeType":1293,"value":3752,"marks":3753,"data":3754},", OAuth ",[],{},{"nodeType":1392,"data":3756,"content":3758},{"uri":3757},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/consent_phishing/description.md",[3759],{"nodeType":1293,"value":2968,"marks":3760,"data":3762},[3761],{"type":1400},{},{"nodeType":1293,"value":2268,"marks":3764,"data":3765},[],{},{"nodeType":1392,"data":3767,"content":3769},{"uri":3768},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/cross-idp_impersonation/description.md",[3770],{"nodeType":1293,"value":3771,"marks":3772,"data":3774},"cross-IdP impersonation",[3773],{"type":1400},{},{"nodeType":1293,"value":3776,"marks":3777,"data":3778},", and more.  ",[],{},{"nodeType":1376,"data":3780,"content":3784},{"target":3781},{"sys":3782},{"id":3783,"type":1381,"linkType":1382},"3WFzina1t5j6bDlTlGQA0l",[],{"nodeType":1294,"data":3786,"content":3787},{},[3788,3792,3801,3805,3812],{"nodeType":1293,"value":3789,"marks":3790,"data":3791},"A key driver of identity vulnerability is the ",[],{},{"nodeType":1392,"data":3793,"content":3795},{"uri":3794},"https://pushsecurity.com/blog/minimum-viable-identity-security/",[3796],{"nodeType":1293,"value":3797,"marks":3798,"data":3800},"huge variance in the configurability of accounts per application",[3799],{"type":1400},{},{"nodeType":1293,"value":3802,"marks":3803,"data":3804},", with different levels of centralized visibility and security control of identities provided — for example, while one app can be locked down to only accept SSO logins via SAML and automatically remove any unused passwords, another provides no control or visibility of login method or MFA status (another big driver of the ",[],{},{"nodeType":1392,"data":3806,"content":3807},{"uri":3367},[3808],{"nodeType":1293,"value":3496,"marks":3809,"data":3811},[3810],{"type":1400},{},{"nodeType":1293,"value":3813,"marks":3814,"data":3815}," breaches last year). Unfortunately, as a by-product of product-led growth and something that is compounded by every new SaaS startup that hits the market, this situation doesn’t look like it’s going to change anytime soon. ",[],{},{"nodeType":1294,"data":3817,"content":3818},{},[3819],{"nodeType":1293,"value":3820,"marks":3821,"data":3822},"The end result is that identities are misconfigured, invisible to the security team, and routinely exploited by commodity attacker tooling. It’s no surprise that they’re the primary target for attackers today. ",[],{},{"nodeType":1443,"data":3824,"content":3825},{},[],{"nodeType":1447,"data":3827,"content":3828},{},[3829],{"nodeType":1293,"value":3830,"marks":3831,"data":3833},"The solution: The browser as a telemetry source and control point",[3832],{"type":1333},{},{"nodeType":1294,"data":3835,"content":3836},{},[3837],{"nodeType":1293,"value":3838,"marks":3839,"data":3840},"Because identity attacks play out in the browser, it’s the perfect place for security teams to observe, intercept, and shut down these attacks. ",[],{},{"nodeType":1294,"data":3842,"content":3843},{},[3844],{"nodeType":1293,"value":3845,"marks":3846,"data":3847},"The browser has a number of advantages over the different places where identity can be observed and protected, because:",[],{},{"nodeType":1832,"data":3849,"content":3850},{},[3851,3861,3871],{"nodeType":1836,"data":3852,"content":3853},{},[3854],{"nodeType":1294,"data":3855,"content":3856},{},[3857],{"nodeType":1293,"value":3858,"marks":3859,"data":3860},"You aren’t limited to the apps and identities directly connected to your IdP (a fraction of your workforce identity sprawl). ",[],{},{"nodeType":1836,"data":3862,"content":3863},{},[3864],{"nodeType":1294,"data":3865,"content":3866},{},[3867],{"nodeType":1293,"value":3868,"marks":3869,"data":3870},"You aren’t limited to the apps that you know about and manage centrally — you can observe every login that passes through the browser.",[],{},{"nodeType":1836,"data":3872,"content":3873},{},[3874],{"nodeType":1294,"data":3875,"content":3876},{},[3877,3881,3886],{"nodeType":1293,"value":3878,"marks":3879,"data":3880},"You can observe all the properties of a login, including the login method, MFA method, etc. You’d otherwise need API access to ",[],{},{"nodeType":1293,"value":3882,"marks":3883,"data":3885},"maybe",[3884],{"type":312},{},{"nodeType":1293,"value":3887,"marks":3888,"data":3889}," get this information (depending on whether an API is provided and whether this specific data can be interrogated, also not standard for many apps). ",[],{},{"nodeType":1294,"data":3891,"content":3892},{},[3893,3897,3902,3906,3915],{"nodeType":1293,"value":3894,"marks":3895,"data":3896},"It’s obvious with all that we’ve covered so far that fixing every identity vulnerability is an ominous task — the SaaS ecosystem itself is working against you. ",[],{},{"nodeType":1293,"value":3898,"marks":3899,"data":3901},"This is why detecting and responding to identity attacks is essential. ",[3900],{"type":1333},{},{"nodeType":1293,"value":3903,"marks":3904,"data":3905},"Because identity compromise almost always involves phishing or social engineering a user to perform an action in their browser (with some exceptions — like the ",[],{},{"nodeType":1392,"data":3907,"content":3909},{"uri":3908},"https://pushsecurity.com/blog/scattered-spider-defending-against-help-desk-scams/",[3910],{"nodeType":1293,"value":3911,"marks":3912,"data":3914},"Scattered Spider-related help desk attacks",[3913],{"type":1400},{},{"nodeType":1293,"value":3916,"marks":3917,"data":3918}," seen recently), it’s also the perfect place to monitor for and intercept attacks. ",[],{},{"nodeType":1294,"data":3920,"content":3921},{},[3922],{"nodeType":1293,"value":3923,"marks":3924,"data":3925},"In the browser, you gather deep, contextualized information about page behavior and user inputs that can be used to detect and shut down risky scenarios in real time. Take the example of phishing pages. Because Push operates in the browser, it sees everything:",[],{},{"nodeType":1832,"data":3927,"content":3928},{},[3929,3939,3949,3959,3981,3991],{"nodeType":1836,"data":3930,"content":3931},{},[3932],{"nodeType":1294,"data":3933,"content":3934},{},[3935],{"nodeType":1293,"value":3936,"marks":3937,"data":3938},"The page layout.",[],{},{"nodeType":1836,"data":3940,"content":3941},{},[3942],{"nodeType":1294,"data":3943,"content":3944},{},[3945],{"nodeType":1293,"value":3946,"marks":3947,"data":3948},"Where the user came from (through the whole redirect chain).",[],{},{"nodeType":1836,"data":3950,"content":3951},{},[3952],{"nodeType":1294,"data":3953,"content":3954},{},[3955],{"nodeType":1293,"value":3956,"marks":3957,"data":3958},"Page interaction events — e.g. tabs opened and closed, popup windows, forms submitted, etc.",[],{},{"nodeType":1836,"data":3960,"content":3961},{},[3962],{"nodeType":1294,"data":3963,"content":3964},{},[3965,3969,3977],{"nodeType":1293,"value":3966,"marks":3967,"data":3968},"The password they enter ",[],{},{"nodeType":1392,"data":3970,"content":3971},{"uri":2166},[3972],{"nodeType":1293,"value":3973,"marks":3974,"data":3976},"(as a salted, abbreviated hash)",[3975],{"type":1400},{},{"nodeType":1293,"value":3978,"marks":3979,"data":3980},", and whether a password was typed or copied, and where from.",[],{},{"nodeType":1836,"data":3982,"content":3983},{},[3984],{"nodeType":1294,"data":3985,"content":3986},{},[3987],{"nodeType":1293,"value":3988,"marks":3989,"data":3990},"What scripts are running on the page and whether they are potentially malicious.",[],{},{"nodeType":1836,"data":3992,"content":3993},{},[3994],{"nodeType":1294,"data":3995,"content":3996},{},[3997],{"nodeType":1293,"value":3998,"marks":3999,"data":4000},"Where credentials are being sent.",[],{},{"nodeType":1376,"data":4002,"content":4006},{"target":4003},{"sys":4004},{"id":4005,"type":1381,"linkType":1382},"6kQejVS63FQ6Oy8nIm6UlV",[],{"nodeType":1443,"data":4008,"content":4009},{},[],{"nodeType":1447,"data":4011,"content":4012},{},[4013],{"nodeType":1293,"value":4014,"marks":4015,"data":4017},"Conclusion",[4016],{"type":1333},{},{"nodeType":1294,"data":4019,"content":4020},{},[4021],{"nodeType":1293,"value":4022,"marks":4023,"data":4024},"Identity attacks are the biggest unsolved problem facing security teams today and the leading cause of security breaches. At the same time, the browser presents security teams with all the tools they need to prevent, detect, and respond to identity-based attacks — proactively by finding and fixing identity vulnerabilities, and reactively by detecting and blocking attacks against users in real time. ",[],{},{"nodeType":1294,"data":4026,"content":4027},{},[4028,4032,4041],{"nodeType":1293,"value":4029,"marks":4030,"data":4031},"Organizations need to move past the old ways of doing identity security — relying on MFA attestations, identity management dashboards, and ",[],{},{"nodeType":1392,"data":4033,"content":4035},{"uri":4034},"https://pushsecurity.com/blog/three-reasons-why-browser-is-best-for-stopping-phishing-attacks/",[4036],{"nodeType":1293,"value":4037,"marks":4038,"data":4040},"legacy email and network anti-phishing tools",[4039],{"type":1400},{},{"nodeType":1293,"value":4042,"marks":4043,"data":4044},". And there’s no better place to stop these attacks than in the browser. ",[],{},{"nodeType":1443,"data":4046,"content":4047},{},[],{"nodeType":1447,"data":4049,"content":4050},{},[4051],{"nodeType":1293,"value":4052,"marks":4053,"data":4055},"Find out more",[4054],{"type":1333},{},{"nodeType":1294,"data":4057,"content":4058},{},[4059],{"nodeType":1293,"value":4060,"marks":4061,"data":4062},"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks identity attacks like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more.",[],{},{"nodeType":1294,"data":4064,"content":4065},{},[4066,4070,4079],{"nodeType":1293,"value":4067,"marks":4068,"data":4069},"If you want to learn more about how Push helps you to detect and stop attacks in the browser, ",[],{},{"nodeType":1392,"data":4071,"content":4073},{"uri":4072},"https://pushsecurity.com/demo",[4074],{"nodeType":1293,"value":4075,"marks":4076,"data":4078},"book some time with one of our team for a live demo",[4077],{"type":1400},{},{"nodeType":1293,"value":3695,"marks":4080,"data":4081},[],{},{"entries":4083},{"hyperlink":4084,"inline":4085,"block":4086},[],[],[4087,4095,4102,4109,4115,4123,4129,4137],{"sys":4088,"__typename":4089,"title":4090,"caption":4090,"layoutMode":118,"file":4091},{"id":3349},"Image","Attacks have shifted from targeting local networks to SaaS services, accessed through employee web browsers.",{"url":4092,"width":4093,"height":4094},"https://images.ctfassets.net/y1cdw1ablpvd/SadRsmdnNZofhrKddH01D/1ba16316bdfa666b2bc387d5b694e515/image2.png",1506,574,{"sys":4096,"__typename":4097,"type":4098,"ctaText":4099,"buttonLabel":4100,"buttonColour":4101,"buttonUrl":3205},{"id":3401},"CtaWidget","Custom","Read how the transformation of business IT has shaped the evolution of phishing attacks in our latest whitepaper.","Download Now","sea blue",{"sys":4103,"__typename":4089,"title":4104,"caption":4104,"layoutMode":118,"file":4105},{"id":3527},"EDR solved endpoint attacks by getting deep visibility into OS-level processes and activity — we now face a similar visibility problem in the browser. ",{"url":4106,"width":4107,"height":4108},"https://images.ctfassets.net/y1cdw1ablpvd/2KuUuYKf2Q9TlIJ9fkOI82/9a52cae72564e69d3cfe8b3b613eb950/image5.png",1999,632,{"sys":4110,"__typename":4089,"title":4111,"caption":4111,"layoutMode":118,"file":4112},{"id":3560},"Phishing is now multi- and cross-channel, targeting a vast range of cloud and SaaS apps using flexible AitM toolkits — but all roads inevitably lead to the browser.",{"url":4113,"width":4107,"height":4114},"https://images.ctfassets.net/y1cdw1ablpvd/4p8sf1x8PfWF06ndwTsdf9/136ed45c7912459a70dbb53b62cf5a90/image6.png",1003,{"sys":4116,"__typename":4089,"title":4117,"caption":4118,"layoutMode":118,"file":4119},{"id":3573},"Cloudflare Turnstile is a simple way for attackers to block automated analysis of their phishing kits — it should probably come with a trigger warning for incident responders.","Cloudflare Turnstile is a simple way for security teams to prevent automated analysis — it should probably come with a trigger warning for incident responders.",{"url":4120,"width":4121,"height":4122},"https://images.ctfassets.net/y1cdw1ablpvd/6gGDHL1jECCm4j02gZZlYe/92e4362eea9fb712aeb64bdd7fb19d59/image3.png",1262,464,{"sys":4124,"__typename":4125,"title":4126,"arcadeDemoUrl":4127,"playText":4128},{"id":3624},"ArcadeDemo","MFA Downgrade Demo","https://demo.arcade.software/1MzRfFaRCD2pYPhIXkvi?embed","2 mins",{"sys":4130,"__typename":4089,"title":4131,"caption":4132,"layoutMode":118,"file":4133},{"id":3783},"Infographic showing the identity vulnerability spread for a 1,000 seat organization","A 1,000 user organization has over 15,000 accounts with various configurations and associated vulnerabilities.",{"url":4134,"width":4135,"height":4136},"https://images.ctfassets.net/y1cdw1ablpvd/266iLQBVsJIQEx6dnUEVrZ/eb5b1be79b7b29365baf299053fddf42/Infographic.png",5480,3012,{"sys":4138,"__typename":4089,"title":4139,"caption":4139,"layoutMode":118,"file":4140},{"id":4005},"Being in the browser gives you unrivalled visibility of phishing page activity and user behavior.",{"url":4141,"width":4142,"height":4143},"https://images.ctfassets.net/y1cdw1ablpvd/42mmDkjfXn0uOkTyvFLNqG/0385dadcb0731bea1de1ca5ae6ee7c18/image1.png",1560,766,"content:blog:how-the-browser-became-the-main-cyber-battleground.json","json","content","blog/how-the-browser-became-the-main-cyber-battleground.json","blog/how-the-browser-became-the-main-cyber-battleground",1776359983548]