[{"data":1,"prerenderedAt":4107},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/introducing-set-and-forget-controls-that-stop-real-world-identity-attacks":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"ogImage":118,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1297,"synopsis":1298,"hashTags":118,"publishedDate":1299,"slug":1300,"tagsCollection":1301,"relatedBlogPostsCollection":1311,"authorsCollection":3224,"content":3228,"_id":4102,"_type":4103,"_source":4104,"_file":4105,"_stem":4106,"_extension":4103},"/blog/introducing-set-and-forget-controls-that-stop-real-world-identity-attacks","blog",{"id":1280,"publishedAt":1281},"20FcoPvHu7zXkTQyv9MmK0","2026-01-30T09:19:46.911Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"Enable plug-and-play detections and interventions in the browser using Push’s new security controls, or create your own automations from unique browser telemetry provided via API and webhooks.","text","paragraph","document","Introducing set-and-forget controls that stop real-world identity attacks","Stop identity attacks with Push's security controls","Enable detections and interventions in the browser using Push’s new security controls.","2024-07-02T00:00:00.000Z","introducing-set-and-forget-controls-that-stop-real-world-identity-attacks",{"items":1302},[1303,1307],{"sys":1304,"name":1306},{"id":1305},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"sys":1308,"name":1310},{"id":1309},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1312},[1313,1854,2726],{"__typename":1314,"sys":1315,"content":1317,"title":1836,"synopsis":1837,"hashTags":118,"publishedDate":1838,"slug":1839,"tagsCollection":1840,"authorsCollection":1846},"BlogPosts",{"id":1316},"6Uvqu6LcWzOVfA9mxtu841",{"json":1318},{"nodeType":1295,"data":1319,"content":1320},{},[1321,1330,1337,1372,1379,1401,1409,1455,1462,1469,1476,1482,1489,1579,1586,1593,1616,1623,1630,1637,1644,1651,1658,1709,1716,1722,1741,1747,1754,1774,1781,1788,1795,1802,1809,1816],{"nodeType":1322,"data":1323,"content":1329},"embedded-entry-block",{"target":1324},{"sys":1325},{"id":1326,"type":1327,"linkType":1328},"2HffP4X7owzpfj41jnzXmV","Link","Entry",[],{"nodeType":1294,"data":1331,"content":1332},{},[1333],{"nodeType":1293,"value":1334,"marks":1335,"data":1336},"To detect session token theft, you need three things:",[],{},{"nodeType":1338,"data":1339,"content":1340},"unordered-list",{},[1341,1352,1362],{"nodeType":1342,"data":1343,"content":1344},"list-item",{},[1345],{"nodeType":1294,"data":1346,"content":1347},{},[1348],{"nodeType":1293,"value":1349,"marks":1350,"data":1351},"Robust logs that provide an identifier to help tie activity to a specific session",[],{},{"nodeType":1342,"data":1353,"content":1354},{},[1355],{"nodeType":1294,"data":1356,"content":1357},{},[1358],{"nodeType":1293,"value":1359,"marks":1360,"data":1361},"A well-oiled SOC to correlate observed activity in those logs",[],{},{"nodeType":1342,"data":1363,"content":1364},{},[1365],{"nodeType":1294,"data":1366,"content":1367},{},[1368],{"nodeType":1293,"value":1369,"marks":1370,"data":1371},"And telemetry to tie those logs to a trusted endpoint",[],{},{"nodeType":1294,"data":1373,"content":1374},{},[1375],{"nodeType":1293,"value":1376,"marks":1377,"data":1378},"The only problem? That third thing didn’t really exist. So we created it.",[],{},{"nodeType":1294,"data":1380,"content":1381},{},[1382,1386,1397],{"nodeType":1293,"value":1383,"marks":1384,"data":1385},"In this article, we’ll cover how Push’s recently released ",[],{},{"nodeType":1387,"data":1388,"content":1390},"hyperlink",{"uri":1389},"https://pushsecurity.com/help/10114#start",[1391],{"nodeType":1293,"value":1392,"marks":1393,"data":1396},"session theft detection",[1394],{"type":1395},"underline",{},{"nodeType":1293,"value":1398,"marks":1399,"data":1400}," feature works, why we built it, and why the unique control point provided by a browser agent unlocks new capabilities for blue teams fighting the effects of infostealer malware and other stolen credential-based attacks.",[],{},{"nodeType":1402,"data":1403,"content":1404},"heading-1",{},[1405],{"nodeType":1293,"value":1406,"marks":1407,"data":1408},"(You probably already know) Why this matters",[],{},{"nodeType":1294,"data":1410,"content":1411},{},[1412,1416,1425,1429,1438,1442,1451],{"nodeType":1293,"value":1413,"marks":1414,"data":1415},"Session token theft is a ",[],{},{"nodeType":1387,"data":1417,"content":1419},{"uri":1418},"https://owasp.org/www-community/attacks/Session_hijacking_attack",[1420],{"nodeType":1293,"value":1421,"marks":1422,"data":1424},"session hijacking",[1423],{"type":1395},{},{"nodeType":1293,"value":1426,"marks":1427,"data":1428}," technique where endpoint malware is used to extract sessions from an endpoint, and until recently it was ",[],{},{"nodeType":1387,"data":1430,"content":1432},{"uri":1431},"https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/",[1433],{"nodeType":1293,"value":1434,"marks":1435,"data":1437},"relatively rare",[1436],{"type":1395},{},{"nodeType":1293,"value":1439,"marks":1440,"data":1441},". It’s easier to ",[],{},{"nodeType":1387,"data":1443,"content":1445},{"uri":1444},"https://pushsecurity.com/blog/what-is-credential-stuffing/",[1446],{"nodeType":1293,"value":1447,"marks":1448,"data":1450},"gain access via a password",[1449],{"type":1395},{},{"nodeType":1293,"value":1452,"marks":1453,"data":1454}," than it is to steal a session cookie. ",[],{},{"nodeType":1294,"data":1456,"content":1457},{},[1458],{"nodeType":1293,"value":1459,"marks":1460,"data":1461},"But there’s an inverse relationship between session-based attacks and MFA adoption. As MFA becomes widespread, adversaries turn to new effective methods of initial entry.",[],{},{"nodeType":1294,"data":1463,"content":1464},{},[1465],{"nodeType":1293,"value":1466,"marks":1467,"data":1468},"An increasingly common approach involves the use of infostealer malware, which can extract saved credentials, browser cookies, cryptowallets, and other valuable data from the infected endpoint.",[],{},{"nodeType":1294,"data":1470,"content":1471},{},[1472],{"nodeType":1293,"value":1473,"marks":1474,"data":1475},"Using stolen tokens, adversaries don’t need to bypass MFA directly. They can simply import the tokens into their browser and assume an already authorized session.",[],{},{"nodeType":1322,"data":1477,"content":1481},{"target":1478},{"sys":1479},{"id":1480,"type":1327,"linkType":1328},"66B5MBFIhbmky7VuLGbuM3",[],{"nodeType":1294,"data":1483,"content":1484},{},[1485],{"nodeType":1293,"value":1486,"marks":1487,"data":1488},"A few recent stats show the scope of the problem:",[],{},{"nodeType":1338,"data":1490,"content":1491},{},[1492,1514,1536,1558],{"nodeType":1342,"data":1493,"content":1494},{},[1495],{"nodeType":1294,"data":1496,"content":1497},{},[1498,1502,1511],{"nodeType":1293,"value":1499,"marks":1500,"data":1501},"Nearly half of the malware detected last year by Sophos targeted victims’ data specifically, and the majority of that malware was classified as infostealers. Source: ",[],{},{"nodeType":1387,"data":1503,"content":1505},{"uri":1504},"https://news.sophos.com/en-us/2024/03/12/2024-sophos-threat-report/",[1506],{"nodeType":1293,"value":1507,"marks":1508,"data":1510},"2024 Sophos Threat Report",[1509],{"type":1395},{},{"nodeType":1293,"value":37,"marks":1512,"data":1513},[],{},{"nodeType":1342,"data":1515,"content":1516},{},[1517],{"nodeType":1294,"data":1518,"content":1519},{},[1520,1524,1533],{"nodeType":1293,"value":1521,"marks":1522,"data":1523},"Information-stealing malware accounted for nearly 10 percent of activity that Red Canary was able to associate with named threats last year. They also found a rise in stealer malware targeting macOS compared to previous years. Source: ",[],{},{"nodeType":1387,"data":1525,"content":1527},{"uri":1526},"https://redcanary.com/threat-detection-report/trends/info-stealers/",[1528],{"nodeType":1293,"value":1529,"marks":1530,"data":1532},"2024 Red Canary Threat Detection Report",[1531],{"type":1395},{},{"nodeType":1293,"value":37,"marks":1534,"data":1535},[],{},{"nodeType":1342,"data":1537,"content":1538},{},[1539],{"nodeType":1294,"data":1540,"content":1541},{},[1542,1546,1555],{"nodeType":1293,"value":1543,"marks":1544,"data":1545},"Stolen credentials continued to rank as the top initial access method for breaches analyzed by Verizon. Source: ",[],{},{"nodeType":1387,"data":1547,"content":1549},{"uri":1548},"https://www.verizon.com/business/resources/reports/dbir/",[1550],{"nodeType":1293,"value":1551,"marks":1552,"data":1554},"2024 Data Breach Investigations Report",[1553],{"type":1395},{},{"nodeType":1293,"value":37,"marks":1556,"data":1557},[],{},{"nodeType":1342,"data":1559,"content":1560},{},[1561],{"nodeType":1294,"data":1562,"content":1563},{},[1564,1568,1576],{"nodeType":1293,"value":1565,"marks":1566,"data":1567},"The number of token replay attacks is increasing, with Microsoft detecting 147,000 attacks in 2023, a 111% increase year-over-year. Source: ",[],{},{"nodeType":1387,"data":1569,"content":1571},{"uri":1570},"https://techcommunity.microsoft.com/t5/microsoft-entra-blog/how-to-break-the-token-theft-cyber-attack-chain/ba-p/4062700",[1572],{"nodeType":1293,"value":1573,"marks":1574,"data":1575},"Microsoft Blog",[],{},{"nodeType":1293,"value":37,"marks":1577,"data":1578},[],{},{"nodeType":1402,"data":1580,"content":1581},{},[1582],{"nodeType":1293,"value":1583,"marks":1584,"data":1585},"What's missing from current defenses",[],{},{"nodeType":1294,"data":1587,"content":1588},{},[1589],{"nodeType":1293,"value":1590,"marks":1591,"data":1592},"When defending against infostealer malware or other forms of session and credential theft, there are a few common challenges that organizations may face:",[],{},{"nodeType":1338,"data":1594,"content":1595},{},[1596,1606],{"nodeType":1342,"data":1597,"content":1598},{},[1599],{"nodeType":1294,"data":1600,"content":1601},{},[1602],{"nodeType":1293,"value":1603,"marks":1604,"data":1605},"Their endpoint security tooling doesn’t provide complete coverage across their device fleet, though they thought it did.",[],{},{"nodeType":1342,"data":1607,"content":1608},{},[1609],{"nodeType":1294,"data":1610,"content":1611},{},[1612],{"nodeType":1293,"value":1613,"marks":1614,"data":1615},"The malware is good enough to evade EDR detection, or it was able to execute and exfiltrate sessions or other data before it was stopped.",[],{},{"nodeType":1294,"data":1617,"content":1618},{},[1619],{"nodeType":1293,"value":1620,"marks":1621,"data":1622},"Existing approaches to detecting stolen sessions also pose a noisy problem. Relying on IP-based or geolocation-based signals can result in frequent false positives. (And not all identity provider logs include a session identifier that you can use to perform correlations in the first place.)",[],{},{"nodeType":1294,"data":1624,"content":1625},{},[1626],{"nodeType":1293,"value":1627,"marks":1628,"data":1629},"The missing piece is a trusted signal for legitimate sessions that you can use to correlate with other data in order to identify unexpected activity that indicates a compromised identity and device.",[],{},{"nodeType":1402,"data":1631,"content":1632},{},[1633],{"nodeType":1293,"value":1634,"marks":1635,"data":1636},"Generating unique telemetry via the browser",[],{},{"nodeType":1294,"data":1638,"content":1639},{},[1640],{"nodeType":1293,"value":1641,"marks":1642,"data":1643},"Push’s solution to detecting stolen sessions falls into the category of “so simple, why didn’t this already exist?”",[],{},{"nodeType":1294,"data":1645,"content":1646},{},[1647],{"nodeType":1293,"value":1648,"marks":1649,"data":1650},"The answer: Because you need to be in the browser to do it. The Push browser agent sits in a unique position that we can leverage to provide telemetry that otherwise would be extremely difficult to create.",[],{},{"nodeType":1294,"data":1652,"content":1653},{},[1654],{"nodeType":1293,"value":1655,"marks":1656,"data":1657},"Here’s how it works:",[],{},{"nodeType":1338,"data":1659,"content":1660},{},[1661,1671,1681],{"nodeType":1342,"data":1662,"content":1663},{},[1664],{"nodeType":1294,"data":1665,"content":1666},{},[1667],{"nodeType":1293,"value":1668,"marks":1669,"data":1670},"Via the Push browser agent, Push injects a unique marker into the user agent string of sessions that occur in browsers enrolled in Push.",[],{},{"nodeType":1342,"data":1672,"content":1673},{},[1674],{"nodeType":1294,"data":1675,"content":1676},{},[1677],{"nodeType":1293,"value":1678,"marks":1679,"data":1680},"Administrators then add the list of domains where they wish to inject the marker into sessions, such as an identity provider like Okta or Microsoft.",[],{},{"nodeType":1342,"data":1682,"content":1683},{},[1684],{"nodeType":1294,"data":1685,"content":1686},{},[1687,1691,1696,1700,1705],{"nodeType":1293,"value":1688,"marks":1689,"data":1690},"By analyzing logs from the IdP, you can identify activity from the same session that both ",[],{},{"nodeType":1293,"value":1692,"marks":1693,"data":1695},"has",[1694],{"type":312},{},{"nodeType":1293,"value":1697,"marks":1698,"data":1699}," the Push marker and that ",[],{},{"nodeType":1293,"value":1701,"marks":1702,"data":1704},"lacks",[1703],{"type":312},{},{"nodeType":1293,"value":1706,"marks":1707,"data":1708}," the marker. This can only ever happen when a session is extracted from a browser and maliciously imported into a different browser.",[],{},{"nodeType":1294,"data":1710,"content":1711},{},[1712],{"nodeType":1293,"value":1713,"marks":1714,"data":1715},"This is a high-fidelity signal that a stolen session token is in use.",[],{},{"nodeType":1322,"data":1717,"content":1721},{"target":1718},{"sys":1719},{"id":1720,"type":1327,"linkType":1328},"3zQamWSaZFIbMUhQZtM2II",[],{"nodeType":1294,"data":1723,"content":1724},{},[1725,1729,1737],{"nodeType":1293,"value":1726,"marks":1727,"data":1728},"Learn more about configuring this feature in our ",[],{},{"nodeType":1387,"data":1730,"content":1731},{"uri":1389},[1732],{"nodeType":1293,"value":1733,"marks":1734,"data":1736},"Help Center",[1735],{"type":1395},{},{"nodeType":1293,"value":1738,"marks":1739,"data":1740},".",[],{},{"nodeType":1322,"data":1742,"content":1746},{"target":1743},{"sys":1744},{"id":1745,"type":1327,"linkType":1328},"35dpGqNY6cTM0fSQRflLiO",[],{"nodeType":1402,"data":1748,"content":1749},{},[1750],{"nodeType":1293,"value":1751,"marks":1752,"data":1753},"Unlocking new capabilities for blue teams",[],{},{"nodeType":1294,"data":1755,"content":1756},{},[1757,1761,1770],{"nodeType":1293,"value":1758,"marks":1759,"data":1760},"As we’ve said before, we see browser telemetry and browser-based controls as the ",[],{},{"nodeType":1387,"data":1762,"content":1764},{"uri":1763},"https://pushsecurity.com/blog/what-is-itdr-identity-threat-detection-response/",[1765],{"nodeType":1293,"value":1766,"marks":1767,"data":1769},"missing piece",[1768],{"type":1395},{},{"nodeType":1293,"value":1771,"marks":1772,"data":1773}," in security strategies to stop identity attacks — particularly for modern organizations with complex identity ecosystems that span IdPs, SaaS apps, OAuth-connected apps, and more.",[],{},{"nodeType":1294,"data":1775,"content":1776},{},[1777],{"nodeType":1293,"value":1778,"marks":1779,"data":1780},"Where the browser agent approach particularly shines is that it’s application-agnostic. ",[],{},{"nodeType":1294,"data":1782,"content":1783},{},[1784],{"nodeType":1293,"value":1785,"marks":1786,"data":1787},"As long as the app you want to monitor provides robust logs, you can inject the Push-supplied marker into any session on any app. ",[],{},{"nodeType":1294,"data":1789,"content":1790},{},[1791],{"nodeType":1293,"value":1792,"marks":1793,"data":1794},"This allows you to detect suspicious activity even on internal corporate assets, such as an intranet. ",[],{},{"nodeType":1294,"data":1796,"content":1797},{},[1798],{"nodeType":1293,"value":1799,"marks":1800,"data":1801},"A tidy side effect is that you can also use this feature to identify unmanaged devices accessing sensitive corporate internal resources because they will lack the Push browser agent-supplied marker.",[],{},{"nodeType":1294,"data":1803,"content":1804},{},[1805],{"nodeType":1293,"value":1806,"marks":1807,"data":1808},"There are probably a few other creative use cases for this feature, so we look forward to seeing what you come up with!",[],{},{"nodeType":1402,"data":1810,"content":1811},{},[1812],{"nodeType":1293,"value":1813,"marks":1814,"data":1815},"Find out more",[],{},{"nodeType":1294,"data":1817,"content":1818},{},[1819,1823,1832],{"nodeType":1293,"value":1820,"marks":1821,"data":1822},"To see Push in action, ",[],{},{"nodeType":1387,"data":1824,"content":1826},{"uri":1825},"https://pushsecurity.com/demo/",[1827],{"nodeType":1293,"value":1828,"marks":1829,"data":1831},"book a demo",[1830],{"type":1395},{},{"nodeType":1293,"value":1833,"marks":1834,"data":1835},". We’ll be happy to show you this feature, along with how we discover all the apps your employees are using, even the ones not behind SSO, and how we detect vulnerable identities and stop identity attacks with browser-based controls.",[],{},"Introducing session token theft detection: Why browser is best","Push's browser agent identifies session token theft by adding telemetry to the user agent string to create a new high-fidelity signal for your security team.","2024-06-25T00:00:00.000Z","introducing-session-token-theft-detection-why-browser-is-best",{"items":1841},[1842,1844],{"sys":1843,"name":1310},{"id":1309},{"sys":1845,"name":1306},{"id":1305},{"items":1847},[1848],{"fullName":1849,"firstName":1850,"jobTitle":1851,"profilePicture":1852},"Kelly Davenport","Kelly","Product Team",{"url":1853},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1314,"sys":1855,"content":1857,"title":2706,"synopsis":2707,"hashTags":118,"publishedDate":2708,"slug":2709,"tagsCollection":2710,"authorsCollection":2718},{"id":1856},"7DJnckJxP4CXyXhPJJpby5",{"json":1858},{"nodeType":1295,"data":1859,"content":1860},{},[1861,1868,1875,1882,1889,1896,1903,1910,1917,1924,1930,1938,1945,1952,2010,2017,2024,2044,2051,2058,2065,2098,2115,2122,2129,2136,2143,2150,2157,2177,2197,2305,2312,2332,2339,2346,2353,2359,2366,2373,2380,2413,2420,2427,2460,2467,2474,2571,2590,2597,2604,2611,2618,2677,2684,2688,2695,2700],{"nodeType":1294,"data":1862,"content":1863},{},[1864],{"nodeType":1293,"value":1865,"marks":1866,"data":1867},"Phishing attacks have always been a go-to technique for both red teamers and real-world threat actors alike. Whether focused on harvesting creds or running malicious payloads, phishing has continued to be adapted to circumvent defenses and has remained highly effective due to this.",[],{},{"nodeType":1294,"data":1869,"content":1870},{},[1871],{"nodeType":1293,"value":1872,"marks":1873,"data":1874},"As MFA has become more common, classic password harvesting focused phishing attacks have become less effective. Typically, for a full account compromise, an MFA push notification or a one-time passcode (OTP) needs to be entered at the time of login. This means harvesting passwords and using them later is no longer effective alone, because an MFA factor is still required each time a valid login is performed.",[],{},{"nodeType":1294,"data":1876,"content":1877},{},[1878],{"nodeType":1293,"value":1879,"marks":1880,"data":1881},"Adversary-in-the-Middle (AitM) phishing is a newer variant of phishing that allows attackers to circumvent MFA protection. In this article, we’re going to look at what AitM phishing is, how it works, and what you can do about it.",[],{},{"nodeType":1402,"data":1883,"content":1884},{},[1885],{"nodeType":1293,"value":1886,"marks":1887,"data":1888},"What is AitM phishing?",[],{},{"nodeType":1294,"data":1890,"content":1891},{},[1892],{"nodeType":1293,"value":1893,"marks":1894,"data":1895},"AitM phishing is a technique that uses dedicated tooling to act as a proxy between the target and a legitimate login portal for an application, principally to make it easier to defeat MFA protection. ",[],{},{"nodeType":1294,"data":1897,"content":1898},{},[1899],{"nodeType":1293,"value":1900,"marks":1901,"data":1902},"While any login portal can be a target, attackers typically look for SSO login portals such as Microsoft Entra, Okta, or Google Workspace. This allows the target to log in successfully with a legitimate service they use and even continue to interact with it, while providing additional access to connected SSO apps if the attack is successful. ",[],{},{"nodeType":1294,"data":1904,"content":1905},{},[1906],{"nodeType":1293,"value":1907,"marks":1908,"data":1909},"As it’s a proxy to the real application, the page will appear exactly as the user expects, because they are logging into the legitimate site – just taking a detour via the attacker’s device. For example, if accessing their webmail, the user will see all their real emails; if accessing their cloud file store then all their real files will be present, etc. This gives the method an increased sense of authenticity and makes the compromise less obvious to the user. However, because the attacker is sitting in the middle of this connection, they are able to observe all interactions and also take control of the authenticated session to gain control of the user account. ",[],{},{"nodeType":1294,"data":1911,"content":1912},{},[1913],{"nodeType":1293,"value":1914,"marks":1915,"data":1916},"While this access is technically temporary, since the attacker is unable to re-authenticate in future without additional MFA prompts, in practice authenticated sessions can often last as long as 30 days or more if kept active. Additionally, there are a wide range of persistence techniques that allow an attacker to maintain some level of access to the user account and/or targeted application indefinitely. ",[],{},{"nodeType":1294,"data":1918,"content":1919},{},[1920],{"nodeType":1293,"value":1921,"marks":1922,"data":1923},"We’ll revisit this point later, but for now let’s consider the two main techniques that are used to implement AitM phishing: Reverse web proxies and Browser-in-the-Middle techniques.",[],{},{"nodeType":1322,"data":1925,"content":1929},{"target":1926},{"sys":1927},{"id":1928,"type":1327,"linkType":1328},"6WEolDcviadCgAW4dCgTPW",[],{"nodeType":1931,"data":1932,"content":1933},"heading-2",{},[1934],{"nodeType":1293,"value":1935,"marks":1936,"data":1937},"Reverse web proxy techniques",[],{},{"nodeType":1294,"data":1939,"content":1940},{},[1941],{"nodeType":1293,"value":1942,"marks":1943,"data":1944},"One common AitM phishing approach is to use tooling that acts as a reverse web proxy. For example, let’s say a victim is tricked into visiting a malicious domain. Under the hood, HTTP requests are passed between the victim’s browser and the real site via the malicious site. When the malicious site receives an HTTP request, it forwards this request on to the legitimate site it is impersonating, receives the response, and then forwards that on to the victim. ",[],{},{"nodeType":1294,"data":1946,"content":1947},{},[1948],{"nodeType":1293,"value":1949,"marks":1950,"data":1951},"In practice, there are many technical challenges, such as rewriting all links and references to the impersonated site to ensure everything continues to be sent to the attacker. However, at a high level, it really is just acting as a reverse web proxy.",[],{},{"nodeType":1294,"data":1953,"content":1954},{},[1955,1959,1968,1972,1981,1985,1994,1998,2007],{"nodeType":1293,"value":1956,"marks":1957,"data":1958},"This is arguably the most scalable and reliable approach from an attacker’s point of view. Open-source tools that demonstrate this method include ",[],{},{"nodeType":1387,"data":1960,"content":1962},{"uri":1961},"https://github.com/drk1wi/Modlishka",[1963],{"nodeType":1293,"value":1964,"marks":1965,"data":1967},"Modlishka",[1966],{"type":1395},{},{"nodeType":1293,"value":1969,"marks":1970,"data":1971},", ",[],{},{"nodeType":1387,"data":1973,"content":1975},{"uri":1974},"https://github.com/muraenateam/muraena",[1976],{"nodeType":1293,"value":1977,"marks":1978,"data":1980},"Muraena",[1979],{"type":1395},{},{"nodeType":1293,"value":1982,"marks":1983,"data":1984},", and the ever popular ",[],{},{"nodeType":1387,"data":1986,"content":1988},{"uri":1987},"https://github.com/kgretzky/evilginx2",[1989],{"nodeType":1293,"value":1990,"marks":1991,"data":1993},"Evilginx",[1992],{"type":1395},{},{"nodeType":1293,"value":1995,"marks":1996,"data":1997},". In the criminal world, there are also similar private toolsets available that have been used in many breaches in the past. A good example of this would be ",[],{},{"nodeType":1387,"data":1999,"content":2001},{"uri":2000},"https://www.bleepingcomputer.com/news/security/evilproxy-uses-indeedcom-open-redirect-for-microsoft-365-phishing/",[2002],{"nodeType":1293,"value":2003,"marks":2004,"data":2006},"Evilproxy",[2005],{"type":1395},{},{"nodeType":1293,"value":1738,"marks":2008,"data":2009},[],{},{"nodeType":1294,"data":2011,"content":2012},{},[2013],{"nodeType":1293,"value":2014,"marks":2015,"data":2016},"One downside to this approach is that there are controls that can be put in place to block it. For example, application developers can hide obfuscated JavaScript code that will fail if the correct value is not produced, checking that the origin matches the expected (legitimate) domains or contains encrypted tokens including this material sent as part of the login process. ",[],{},{"nodeType":1294,"data":2018,"content":2019},{},[2020],{"nodeType":1293,"value":2021,"marks":2022,"data":2023},"While your average small website is not going to be implementing such checks, major identity providers have a strong vested interest in evolving their defenses to block these techniques. At this point, it’s a cat-and-mouse game. ",[],{},{"nodeType":1294,"data":2025,"content":2026},{},[2027,2031,2040],{"nodeType":1293,"value":2028,"marks":2029,"data":2030},"If you want to know more about this space, then definitely check out ",[],{},{"nodeType":1387,"data":2032,"content":2034},{"uri":2033},"https://www.youtube.com/watch?v=C-Fh4sIdY8c",[2035],{"nodeType":1293,"value":2036,"marks":2037,"data":2039},"Kuba Gretzky’s talk on this at x33fcon",[2038],{"type":1395},{},{"nodeType":1293,"value":2041,"marks":2042,"data":2043},".  ",[],{},{"nodeType":1931,"data":2045,"content":2046},{},[2047],{"nodeType":1293,"value":2048,"marks":2049,"data":2050},"Browser-in-the-Middle (BitM) techniques ",[],{},{"nodeType":1294,"data":2052,"content":2053},{},[2054],{"nodeType":1293,"value":2055,"marks":2056,"data":2057},"Another common approach is known as Browser-in-the-Middle (BitM). Rather than act as a reverse web proxy, this technique tricks a target into directly controlling the attacker’s own browser remotely using desktop screen sharing and control approaches, much like VNC and RDP. This enables the attacker to harvest not just the username and password, but all other associated secrets and tokens that go along with the login. ",[],{},{"nodeType":1294,"data":2059,"content":2060},{},[2061],{"nodeType":1293,"value":2062,"marks":2063,"data":2064},"In this case, the victim isn’t interacting with a fake website clone or proxy. They are literally remotely controlling the attacker’s browser to log in to the legitimate application without realizing. This is the virtual equivalent of an attacker handing their laptop to their victim, asking them to login to Okta for them, and then taking their laptop back afterwards. Thanks very much!",[],{},{"nodeType":1294,"data":2066,"content":2067},{},[2068,2072,2081,2085,2094],{"nodeType":1293,"value":2069,"marks":2070,"data":2071},"Practically speaking, the most common approach for implementing this technique is using the open-source project noVNC, which is a JavaScript-based VNC client that allows VNC to be used in the browser. Probably the most well-known example of an offensive tool implementing this is ",[],{},{"nodeType":1387,"data":2073,"content":2075},{"uri":2074},"https://github.com/JoelGMSec/EvilnoVNC",[2076],{"nodeType":1293,"value":2077,"marks":2078,"data":2080},"EvilnoVNC",[2079],{"type":1395},{},{"nodeType":1293,"value":2082,"marks":2083,"data":2084},", which spins up Docker instances of VNC and proxies access to them, while also logging keystrokes and cookies to facilitate account compromise. Tools like ",[],{},{"nodeType":1387,"data":2086,"content":2088},{"uri":2087},"https://posts.specterops.io/phishing-with-dynamite-7d33d8fac038",[2089],{"nodeType":1293,"value":2090,"marks":2091,"data":2093},"Cuddlephish",[2092],{"type":1395},{},{"nodeType":1293,"value":2095,"marks":2096,"data":2097}," offer similar functionality using WebRTC. ",[],{},{"nodeType":1294,"data":2099,"content":2100},{},[2101,2105,2111],{"nodeType":1293,"value":2102,"marks":2103,"data":2104},"The advantage of this approach is that ",[],{},{"nodeType":1293,"value":2106,"marks":2107,"data":2110},"it is incredibly difficult for the target websites to do anything to stop it",[2108],{"type":2109},"bold",{},{"nodeType":1293,"value":2112,"marks":2113,"data":2114},". From their perspective, all they see is a legitimate browser accessing their website and logging in. None of the JavaScript tricks for checking the origin will work. They aren’t in a position to be able to see that the browser is secretly being controlled remotely by the victim user without their knowledge. ",[],{},{"nodeType":1294,"data":2116,"content":2117},{},[2118],{"nodeType":1293,"value":2119,"marks":2120,"data":2121},"On the downside, while noVNC can be extremely convincing, the illusion can sometimes be broken due to it not behaving exactly like a real website would due it being a graphical rendering. For example, something as simple as resizing the browser window can introduce render resolution issues. It’s also more difficult to scale for attacking large numbers of users than a reverse proxy technique.",[],{},{"nodeType":1294,"data":2123,"content":2124},{},[2125],{"nodeType":1293,"value":2126,"marks":2127,"data":2128},"Footnote: BitM is not to be confused with Browser-in-the-Browser (BitB), which is more of a malicious pop-up (think when a login button spawns a new browser window). ",[],{},{"nodeType":1402,"data":2130,"content":2131},{},[2132],{"nodeType":1293,"value":2133,"marks":2134,"data":2135},"Beyond initial access",[],{},{"nodeType":1294,"data":2137,"content":2138},{},[2139],{"nodeType":1293,"value":2140,"marks":2141,"data":2142},"So maybe you’re thinking now “OK, sounds kinda bad, but I’m not that worried. Maybe some user accounts get compromised by this method despite all my MFA protections, but at least the attacker only has temporary access, right?” ",[],{},{"nodeType":1294,"data":2144,"content":2145},{},[2146],{"nodeType":1293,"value":2147,"marks":2148,"data":2149},"In theory, access is temporary as sessions time out. And if spotted, the security team can respond by killing the authenticated sessions and forcing password changes for the compromised users. Then the attacker is back to square one, right? Their session is lost, they still don’t have MFA, and even the password they keylogged has now been changed.",[],{},{"nodeType":1294,"data":2151,"content":2152},{},[2153],{"nodeType":1293,"value":2154,"marks":2155,"data":2156},"In practice, it’s not this simple. We mentioned earlier how SSO portals are often the most common targets for these attacks. For most modern organizations, this means their core identity provider, which just so happens to be the gateway to accessing many other web applications, whether internal applications or a multitude of SaaS applications. ",[],{},{"nodeType":1294,"data":2158,"content":2159},{},[2160,2164,2173],{"nodeType":1293,"value":2161,"marks":2162,"data":2163},"Let’s consider the example of an organization using Okta where their Okta login portal has been used as the target for AitM phishing. A smart attacker is going to immediately leverage this access to establish authenticated sessions on every single application that Okta provides the user access to. They are also going to ",[],{},{"nodeType":1387,"data":2165,"content":2167},{"uri":2166},"https://pushsecurity.com/blog/okta-swa/",[2168],{"nodeType":1293,"value":2169,"marks":2170,"data":2172},"abuse Okta SWA",[2171],{"type":1395},{},{"nodeType":1293,"value":2174,"marks":2175,"data":2176}," to steal valid credentials for whichever applications support this method. And if that’s not enough, there are a variety of simple methods to achieve persistence on most downstream SaaS applications and sometimes even identity providers themselves.",[],{},{"nodeType":1294,"data":2178,"content":2179},{},[2180,2184,2193],{"nodeType":1293,"value":2181,"marks":2182,"data":2183},"While the full details of these persistence attacks are outside the scope of this article, more details on some key attacks can be found in a resource we created called the ",[],{},{"nodeType":1387,"data":2185,"content":2187},{"uri":2186},"https://github.com/pushsecurity/saas-attacks",[2188],{"nodeType":1293,"value":2189,"marks":2190,"data":2192},"SaaS attacks matrix",[2191],{"type":1395},{},{"nodeType":1293,"value":2194,"marks":2195,"data":2196},". Some of the most common techniques that apply here are: ",[],{},{"nodeType":1338,"data":2198,"content":2199},{},[2200,2221,2242,2263,2284],{"nodeType":1342,"data":2201,"content":2202},{},[2203],{"nodeType":1294,"data":2204,"content":2205},{},[2206,2209,2218],{"nodeType":1293,"value":37,"marks":2207,"data":2208},[],{},{"nodeType":1387,"data":2210,"content":2212},{"uri":2211},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/api_keys/description.md",[2213],{"nodeType":1293,"value":2214,"marks":2215,"data":2217},"SAT1004 - API keys",[2216],{"type":1395},{},{"nodeType":1293,"value":37,"marks":2219,"data":2220},[],{},{"nodeType":1342,"data":2222,"content":2223},{},[2224],{"nodeType":1294,"data":2225,"content":2226},{},[2227,2230,2239],{"nodeType":1293,"value":37,"marks":2228,"data":2229},[],{},{"nodeType":1387,"data":2231,"content":2233},{"uri":2232},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/link_sharing/description.md",[2234],{"nodeType":1293,"value":2235,"marks":2236,"data":2238},"SAT1022 - Link sharing",[2237],{"type":1395},{},{"nodeType":1293,"value":37,"marks":2240,"data":2241},[],{},{"nodeType":1342,"data":2243,"content":2244},{},[2245],{"nodeType":1294,"data":2246,"content":2247},{},[2248,2251,2260],{"nodeType":1293,"value":37,"marks":2249,"data":2250},[],{},{"nodeType":1387,"data":2252,"content":2254},{"uri":2253},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[2255],{"nodeType":1293,"value":2256,"marks":2257,"data":2259},"SAT1017 - Ghost logins",[2258],{"type":1395},{},{"nodeType":1293,"value":37,"marks":2261,"data":2262},[],{},{"nodeType":1342,"data":2264,"content":2265},{},[2266],{"nodeType":1294,"data":2267,"content":2268},{},[2269,2272,2281],{"nodeType":1293,"value":37,"marks":2270,"data":2271},[],{},{"nodeType":1387,"data":2273,"content":2275},{"uri":2274},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/oauth_tokens/description.md",[2276],{"nodeType":1293,"value":2277,"marks":2278,"data":2280},"SAT1027 - OAuth tokens",[2279],{"type":1395},{},{"nodeType":1293,"value":37,"marks":2282,"data":2283},[],{},{"nodeType":1342,"data":2285,"content":2286},{},[2287],{"nodeType":1294,"data":2288,"content":2289},{},[2290,2293,2302],{"nodeType":1293,"value":37,"marks":2291,"data":2292},[],{},{"nodeType":1387,"data":2294,"content":2296},{"uri":2295},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/shadow_workflows/description.md",[2297],{"nodeType":1293,"value":2298,"marks":2299,"data":2301},"SAT1033 - Shadow workflows",[2300],{"type":1395},{},{"nodeType":1293,"value":37,"marks":2303,"data":2304},[],{},{"nodeType":1294,"data":2306,"content":2307},{},[2308],{"nodeType":1293,"value":2309,"marks":2310,"data":2311},"Suddenly, containing the breach just got a LOT more complicated.",[],{},{"nodeType":1294,"data":2313,"content":2314},{},[2315,2319,2328],{"nodeType":1293,"value":2316,"marks":2317,"data":2318},"It’s not just application-level lateral movement and persistence to worry about, though. It’s possible the attacker can start moving laterally across other user accounts. If they have selected their targets well, they might even find they have admin access to some downstream SaaS application that has been configured for SAML logins using Okta. For example, maybe they compromise a finance employee who has admin access to their business expenses SaaS application. Then the attacker might be able to use a new technique like ",[],{},{"nodeType":1387,"data":2320,"content":2322},{"uri":2321},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/samljacking/description.md",[2323],{"nodeType":1293,"value":2324,"marks":2325,"data":2327},"SAMLjacking",[2326],{"type":1395},{},{"nodeType":1293,"value":2329,"marks":2330,"data":2331}," to start attacking other users in a watering hole attack to achieve lateral movement.",[],{},{"nodeType":1402,"data":2333,"content":2334},{},[2335],{"nodeType":1293,"value":2336,"marks":2337,"data":2338},"Video demo – chaining it all together",[],{},{"nodeType":1294,"data":2340,"content":2341},{},[2342],{"nodeType":1293,"value":2343,"marks":2344,"data":2345},"OK, so we’ve just jumped from an account compromise for initial access using an AitM phishing attack to bringing up a huge number of other connected techniques. Let’s look at a quick video demonstration of an AitM phishing attack chained together with post-exploitation steps for persistence and lateral movement so we can see how it all fits together.",[],{},{"nodeType":1294,"data":2347,"content":2348},{},[2349],{"nodeType":1293,"value":2350,"marks":2351,"data":2352},"In this case, we’ll use EvilnoVNC targeting Okta as the core example for the AitM phishing attack:",[],{},{"nodeType":1322,"data":2354,"content":2358},{"target":2355},{"sys":2356},{"id":2357,"type":1327,"linkType":1328},"QGTEWzmOL1vrgjXPuV4Gg",[],{"nodeType":1294,"data":2360,"content":2361},{},[2362],{"nodeType":1293,"value":2363,"marks":2364,"data":2365},"We can see here that AitM phishing attacks are not only highly effective even in the presence of MFA, but that post-exploitation steps have become so numerous that effective response and containment for even a low-privileged user account are now a significant challenge.",[],{},{"nodeType":1402,"data":2367,"content":2368},{},[2369],{"nodeType":1293,"value":2370,"marks":2371,"data":2372},"Post-exploitation automation is coming",[],{},{"nodeType":1294,"data":2374,"content":2375},{},[2376],{"nodeType":1293,"value":2377,"marks":2378,"data":2379},"There is a saying that attacks only become more effective over time. In the past, toolsets like Metasploit and Cobalt Strike became increasingly focused on post-exploitation and automation to enable much more sophisticated compromises.",[],{},{"nodeType":1294,"data":2381,"content":2382},{},[2383,2387,2400,2404,2409],{"nodeType":1293,"value":2384,"marks":2385,"data":2386},"As AitM becomes increasingly popular (for example, researchers at Lab539 have reported ",[],{},{"nodeType":1387,"data":2388,"content":2390},{"uri":2389},"https://www.lab539.com/blog/6-months-tracking-aitm-campaigns",[2391,2396],{"nodeType":1293,"value":2392,"marks":2393,"data":2395},"a significant ramp up in attacker infrastructure linked to AitM campaigns",[2394],{"type":1395},{},{"nodeType":1293,"value":2397,"marks":2398,"data":2399},")",[],{},{"nodeType":1293,"value":2401,"marks":2402,"data":2403}," it’s only a matter of time now before we see AitM phishing frameworks moving in the same direction and performing many of the lateral movement and persistence steps we saw above – automatically on every successful account compromise. The threat will increase ",[],{},{"nodeType":1293,"value":2405,"marks":2406,"data":2408},"significantly",[2407],{"type":2109},{},{"nodeType":1293,"value":2410,"marks":2411,"data":2412}," when this becomes the case.",[],{},{"nodeType":1402,"data":2414,"content":2415},{},[2416],{"nodeType":1293,"value":2417,"marks":2418,"data":2419},"Impact summary",[],{},{"nodeType":1294,"data":2421,"content":2422},{},[2423],{"nodeType":1293,"value":2424,"marks":2425,"data":2426},"We’ve covered a lot of ground here, so let’s take a step back and consider the key points of impact:",[],{},{"nodeType":1338,"data":2428,"content":2429},{},[2430,2440,2450],{"nodeType":1342,"data":2431,"content":2432},{},[2433],{"nodeType":1294,"data":2434,"content":2435},{},[2436],{"nodeType":1293,"value":2437,"marks":2438,"data":2439},"AitM phishing techniques are highly effective and increasingly common, and can bypass most common forms of MFA.",[],{},{"nodeType":1342,"data":2441,"content":2442},{},[2443],{"nodeType":1294,"data":2444,"content":2445},{},[2446],{"nodeType":1293,"value":2447,"marks":2448,"data":2449},"These techniques are being used by real threat actors and red teamers alike, with both criminal and open-source tools available for performing these attacks.",[],{},{"nodeType":1342,"data":2451,"content":2452},{},[2453],{"nodeType":1294,"data":2454,"content":2455},{},[2456],{"nodeType":1293,"value":2457,"marks":2458,"data":2459},"There are many options for lateral movement and persistence after an account compromise, so simple containment actions like password resets for SSO credentials are not nearly enough to contain a knowledgeable attacker.",[],{},{"nodeType":1402,"data":2461,"content":2462},{},[2463],{"nodeType":1293,"value":2464,"marks":2465,"data":2466},"What can blue teams do about it?",[],{},{"nodeType":1294,"data":2468,"content":2469},{},[2470],{"nodeType":1293,"value":2471,"marks":2472,"data":2473},"It’s important that organizations develop their capability to detect and respond to AitM attacks. Possible approaches include:",[],{},{"nodeType":1338,"data":2475,"content":2476},{},[2477,2492,2528,2556],{"nodeType":1342,"data":2478,"content":2479},{},[2480],{"nodeType":1294,"data":2481,"content":2482},{},[2483,2488],{"nodeType":1293,"value":2484,"marks":2485,"data":2487},"Move to FIDO MFA where possible",[2486],{"type":2109},{},{"nodeType":1293,"value":2489,"marks":2490,"data":2491}," (though, if no more susceptible backup methods are enabled, this does introduce operational challenges if passkeys are lost).",[],{},{"nodeType":1342,"data":2493,"content":2494},{},[2495],{"nodeType":1294,"data":2496,"content":2497},{},[2498,2503,2507,2512,2516,2525],{"nodeType":1293,"value":2499,"marks":2500,"data":2502},"Detect and block known-bad malicious",[2501],{"type":2109},{},{"nodeType":1293,"value":2504,"marks":2505,"data":2506}," ",[],{},{"nodeType":1293,"value":2508,"marks":2509,"data":2511},"sites",[2510],{"type":2109},{},{"nodeType":1293,"value":2513,"marks":2514,"data":2515}," used in phishing campaigns. There are many threat intelligence feeds that can be ingested to achieve this. Usually, a domain has to be used in a malicious campaign before it can be catalogued – meaning there's typically a window of opportunity before the infrastructure is burned. That said, security researchers at Lab539 (yes, another shout out) have developed a way of identifying sites running AitM tooling – even before they are used for the first time. ",[],{},{"nodeType":1387,"data":2517,"content":2519},{"uri":2518},"https://www.lab539.com/aitm",[2520],{"nodeType":1293,"value":2521,"marks":2522,"data":2524},"You can sign up to get access to their feed here.",[2523],{"type":1395},{},{"nodeType":1293,"value":37,"marks":2526,"data":2527},[],{},{"nodeType":1342,"data":2529,"content":2530},{},[2531],{"nodeType":1294,"data":2532,"content":2533},{},[2534,2539,2543,2552],{"nodeType":1293,"value":2535,"marks":2536,"data":2538},"Introduce controls to detect phishing toolkits and cloned websites",[2537],{"type":2109},{},{"nodeType":1293,"value":2540,"marks":2541,"data":2542},". You can never rely on blocking malicious sites via TI feeds alone, so additional layers of defence are required. Push customers benefit from detection of AitM toolkits like Evilginx and EvilNoVNC in the browser (more to come on this soon!), while Thinkst Canary has developed ",[],{},{"nodeType":1387,"data":2544,"content":2546},{"uri":2545},"https://blog.thinkst.com/2024/01/defending-against-the-attack-of-the-cloned-websites.html",[2547],{"nodeType":1293,"value":2548,"marks":2549,"data":2551},"methods of detecting whenever your website or login portal is cloned",[2550],{"type":1395},{},{"nodeType":1293,"value":2553,"marks":2554,"data":2555}," – very cool.  ",[],{},{"nodeType":1342,"data":2557,"content":2558},{},[2559],{"nodeType":1294,"data":2560,"content":2561},{},[2562,2567],{"nodeType":1293,"value":2563,"marks":2564,"data":2566},"Update IR playbooks to to deal with SSO account compromise,",[2565],{"type":2109},{},{"nodeType":1293,"value":2568,"marks":2569,"data":2570}," factoring in lateral movement and persistence across cloud apps. This really necessitates that you understand what business apps your organization is using, how they are accessed (e.g. SSO or username and password) and what functionality exists that could be abused by an attacker. ",[],{},{"nodeType":1294,"data":2572,"content":2573},{},[2574,2578,2586],{"nodeType":1293,"value":2575,"marks":2576,"data":2577},"If you want to know more about how Push detects and blocks phishing tools in the browser, you can ",[],{},{"nodeType":1387,"data":2579,"content":2581},{"uri":2580},"https://pushsecurity.com/blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser/",[2582],{"nodeType":1293,"value":2583,"marks":2584,"data":2585},"check out our article here",[],{},{"nodeType":1293,"value":2587,"marks":2588,"data":2589},". ",[],{},{"nodeType":1402,"data":2591,"content":2592},{},[2593],{"nodeType":1293,"value":2594,"marks":2595,"data":2596},"Conclusion",[],{},{"nodeType":1294,"data":2598,"content":2599},{},[2600],{"nodeType":1293,"value":2601,"marks":2602,"data":2603},"We’ve seen in this article how there are multiple ways to perform AitM phishing attacks and how they can be extremely effective at targeting users even when their accounts are protected by MFA.  ",[],{},{"nodeType":1294,"data":2605,"content":2606},{},[2607],{"nodeType":1293,"value":2608,"marks":2609,"data":2610},"Very few organizations are universally using phishing-resistant MFA, such as FIDO-based methods, and even those that do often have fallback options to handle situations where they cannot be used and/or tokens malfunction or are lost. Therefore, the vast majority of organizations are at risk of AitM phishing attacks.",[],{},{"nodeType":1294,"data":2612,"content":2613},{},[2614],{"nodeType":1293,"value":2615,"marks":2616,"data":2617},"To make things worse, there are lateral movement and persistence techniques that can be exploited to greatly extend the depth of compromise even for a single low-privilege user account. This makes response and containment a significant challenge.",[],{},{"nodeType":1294,"data":2619,"content":2620},{},[2621,2625,2634,2638,2647,2651,2660,2664,2673],{"nodeType":1293,"value":2622,"marks":2623,"data":2624},"Phishing attacks are clearly evolving. Phishing attacks are no longer limited to email-based delivery mechanisms or being hosted on custom domains. There are many options now for delivering phishing attacks using ",[],{},{"nodeType":1387,"data":2626,"content":2628},{"uri":2627},"https://pushsecurity.com/blog/slack-phishing-for-initial-access/",[2629],{"nodeType":1293,"value":2630,"marks":2631,"data":2633},"Slack",[2632],{"type":1395},{},{"nodeType":1293,"value":2635,"marks":2636,"data":2637}," or ",[],{},{"nodeType":1387,"data":2639,"content":2641},{"uri":2640},"https://pushsecurity.com/blog/phishing-microsoft-teams-for-initial-access/",[2642],{"nodeType":1293,"value":2643,"marks":2644,"data":2646},"Microsoft Teams",[2645],{"type":1395},{},{"nodeType":1293,"value":2648,"marks":2649,"data":2650},", using ",[],{},{"nodeType":1387,"data":2652,"content":2654},{"uri":2653},"https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/",[2655],{"nodeType":1293,"value":2656,"marks":2657,"data":2659},"SAMLjacking attacks",[2658],{"type":1395},{},{"nodeType":1293,"value":2661,"marks":2662,"data":2663}," to host the initial landing page on legitimate SaaS web domains or even using ",[],{},{"nodeType":1387,"data":2665,"content":2667},{"uri":2666},"https://pushsecurity.com/blog/oktajacking/",[2668],{"nodeType":1293,"value":2669,"marks":2670,"data":2672},"Okta to keylog credentials",[2671],{"type":1395},{},{"nodeType":1293,"value":2674,"marks":2675,"data":2676}," on behalf of the attacker. ",[],{},{"nodeType":1294,"data":2678,"content":2679},{},[2680],{"nodeType":1293,"value":2681,"marks":2682,"data":2683},"Increasingly, we should expect to see AitM toolkits being used as a standard part of phishing campaigns, and featured in Initial Access Broker tooling – AitM will effectively supersede legacy phishing methods in line with MFA adoption. Rather, it already is. ",[],{},{"nodeType":2685,"data":2686,"content":2687},"hr",{},[],{"nodeType":1294,"data":2689,"content":2690},{},[2691],{"nodeType":1293,"value":2692,"marks":2693,"data":2694},"If you're interested in seeing some more AitM tools in action, you can watch our recent webinar on-demand via the link below. ",[],{},{"nodeType":1322,"data":2696,"content":2699},{"target":2697},{"sys":2698},{"id":1928,"type":1327,"linkType":1328},[],{"nodeType":1294,"data":2701,"content":2702},{},[2703],{"nodeType":1293,"value":37,"marks":2704,"data":2705},[],{},"Phishing 2.0 – how phishing toolkits are evolving with AitM","Attackers are using Adversary in the Middle (AitM) phishing toolkits to bypass MFA. We look at what AitM is, how it works, and what you can do about it.","2024-05-23T00:00:00.000Z","phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm",{"items":2711},[2712,2716],{"sys":2713,"name":2715},{"id":2714},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":2717,"name":1310},{"id":1309},{"items":2719},[2720],{"fullName":2721,"firstName":2722,"jobTitle":2723,"profilePicture":2724},"Luke Jennings","Luke","Vice President, R&D",{"url":2725},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"__typename":1314,"sys":2727,"content":2729,"title":3206,"synopsis":3207,"hashTags":118,"publishedDate":3208,"slug":3209,"tagsCollection":3210,"authorsCollection":3216},{"id":2728},"7yCGcUryKQGOHYHRtipn6W",{"json":2730},{"nodeType":1295,"data":2731,"content":2732},{},[2733,2740,2747,2754,2761,2768,2775,2782,2789,2796,2814,2832,2839,2846,2866,2873,2885,2928,2935,2954,2962,2969,2976,2983,2990,2997,3063,3070,3076,3083,3090,3097,3104,3124,3131,3138,3145,3152,3159,3166,3173,3180,3187,3193,3199],{"nodeType":1294,"data":2734,"content":2735},{},[2736],{"nodeType":1293,"value":2737,"marks":2738,"data":2739},"User web activity can be a rich source of attack detection data. To this end, most organizations today ingest some form of network traffic data for security monitoring purposes. ",[],{},{"nodeType":1294,"data":2741,"content":2742},{},[2743],{"nodeType":1293,"value":2744,"marks":2745,"data":2746},"Typically, network traffic data is gathered by analyzing web proxy and/or DNS logs. But, we regularly speak to organizations that are frustrated with the challenge of piecing together web traffic data, without understanding the opportunity presented by the alternatives.",[],{},{"nodeType":1294,"data":2748,"content":2749},{},[2750],{"nodeType":1293,"value":2751,"marks":2752,"data":2753},"Even with proxies that can terminate TLS-encrypted datastreams, it’s difficult for even expert security teams to collect and analyze any meaningful data from web proxy logs. While the kind of data needed might be technically possible to extract, the process of reconstructing proxy data to analyze the specific data points that you really need, at scale, is prohibitively complicated.",[],{},{"nodeType":1294,"data":2755,"content":2756},{},[2757],{"nodeType":1293,"value":2758,"marks":2759,"data":2760},"The old “needle in a haystack” adage is very apt here! Rather than trying to piece together half-broken data – overlaying noisy proxy logs with other sources such as app and IdP telemetry – we think that the browser presents a much simpler way of analyzing relevant data points, particularly when it comes to identity attacks. ",[],{},{"nodeType":1294,"data":2762,"content":2763},{},[2764],{"nodeType":1293,"value":2765,"marks":2766,"data":2767},"Before we get on to detection opportunities in the browser, let’s take a deeper look at the web proxy situation.",[],{},{"nodeType":1402,"data":2769,"content":2770},{},[2771],{"nodeType":1293,"value":2772,"marks":2773,"data":2774},"Detection based on web proxy – how does it work and what are the limitations?",[],{},{"nodeType":1294,"data":2776,"content":2777},{},[2778],{"nodeType":1293,"value":2779,"marks":2780,"data":2781},"Web proxies generate common data points that can be used for threat detection, particularly when looking for indicators of an endpoint compromise. They work by inspecting network traffic to and from the endpoint, which includes web activity in the browser. ",[],{},{"nodeType":1294,"data":2783,"content":2784},{},[2785],{"nodeType":1293,"value":2786,"marks":2787,"data":2788},"The classic use case would be inspecting traffic from an endpoint to networked servers and devices, either on the local network or over the internet (e.g. via VPN), to detect signs of suspicious/malicious behavior from the device (indicating a potential compromise). Data is then shipped to a central proxy server where it can be analyzed for indicators of malicious activity. ",[],{},{"nodeType":1294,"data":2790,"content":2791},{},[2792],{"nodeType":1293,"value":2793,"marks":2794,"data":2795},"The traditional proxy setup has a number of limitations: ",[],{},{"nodeType":1338,"data":2797,"content":2798},{},[2799],{"nodeType":1342,"data":2800,"content":2801},{},[2802],{"nodeType":1294,"data":2803,"content":2804},{},[2805,2810],{"nodeType":1293,"value":2806,"marks":2807,"data":2809},"The proxy needs to be in a position to intercept traffic.",[2808],{"type":2109},{},{"nodeType":1293,"value":2811,"marks":2812,"data":2813}," It may only be active when a user is in the office, on a VPN and/or for external web traffic only. It might not work if a user is on their home or other other Wi-Fi – e.g. when working from Starbucks, or visiting a customer site, which isn’t an ideal setup in the era of remote working.  ",[],{},{"nodeType":1338,"data":2815,"content":2816},{},[2817],{"nodeType":1342,"data":2818,"content":2819},{},[2820],{"nodeType":1294,"data":2821,"content":2822},{},[2823,2828],{"nodeType":1293,"value":2824,"marks":2825,"data":2827},"Most web traffic is protected by TLS – so a proxy has to decrypt this to inspect what’s inside.",[2826],{"type":2109},{},{"nodeType":1293,"value":2829,"marks":2830,"data":2831}," At the very least you’re going to need to deploy a CA cert to every endpoint. But, some websites use things like certificate pinning or other SSL-enforcement controls to straight up prevent this. Unless you’re doing TLS-termination at scale with a COTS solution, then the ability to do proxy-based monitoring is seriously limited. ",[],{},{"nodeType":1931,"data":2833,"content":2834},{},[2835],{"nodeType":1293,"value":2836,"marks":2837,"data":2838},"Proxies under the hood",[],{},{"nodeType":1294,"data":2840,"content":2841},{},[2842],{"nodeType":1293,"value":2843,"marks":2844,"data":2845},"Let’s pop the hood and take a look at the data you can collect using a web proxy that is useful for threat detection. ",[],{},{"nodeType":1294,"data":2847,"content":2848},{},[2849,2853,2862],{"nodeType":1293,"value":2850,"marks":2851,"data":2852},"Typically, you’re looking at data points such as domain names or IP addresses. If the proxy is terminating TLS, you might also have web URLs, the type of web content accessed, and other HTTP-level metadata. Higher level data like file uploads/downloads can sometimes be reconstructed when using very vanilla methods. More advanced proxies might run or open downloaded files in a sandbox for dynamic analysis to identify potentially malicious properties, which has ",[],{},{"nodeType":1387,"data":2854,"content":2856},{"uri":2855},"https://www.cyfirma.com/research/html-smuggling-a-stealthier-approach-to-deliver-malware/",[2857],{"nodeType":1293,"value":2858,"marks":2859,"data":2861},"given rise to techniques like HTML smuggling",[2860],{"type":1395},{},{"nodeType":1293,"value":2863,"marks":2864,"data":2865}," to hide these file downloads from advanced proxies. ",[],{},{"nodeType":1294,"data":2867,"content":2868},{},[2869],{"nodeType":1293,"value":2870,"marks":2871,"data":2872},"In practice this means that you might see that an endpoint at IP address X accessed google.com. If it’s an authenticated proxy, you might see the user of the endpoint as well. Using this data, it’s possible to see which endpoint’s owner accessed the web domain, but not the identity/account they used, or whether they actually logged in at all. So for the majority of in-house proxy setups not doing TLS-termination… that’s it. Even then, without decrypting TLS you can’t be sure you’re seeing the actual/final domain because of technologies like domain fronting that are commonly implemented in modern CDNs. ",[],{},{"nodeType":1294,"data":2874,"content":2875},{},[2876,2880],{"nodeType":1293,"value":2877,"marks":2878,"data":2879},"With TLS termination, it’s possible to see a lot more by inspecting/unpacking the HTTP data. At this point there are two possible approaches: Manual analysis after the fact, or automated analysis on the fly. ",[],{},{"nodeType":1293,"value":2881,"marks":2882,"data":2884},"Unfortunately, there are problems with both options. ",[2883],{"type":2109},{},{"nodeType":1338,"data":2886,"content":2887},{},[2888,2908],{"nodeType":1342,"data":2889,"content":2890},{},[2891],{"nodeType":1294,"data":2892,"content":2893},{},[2894,2899,2903],{"nodeType":1293,"value":2895,"marks":2896,"data":2898},"There is too much HTTP data to store and manually analyze everything:",[2897],{"type":2109},{},{"nodeType":1293,"value":2900,"marks":2901,"data":2902}," Usually, organizations limit the data being stored to specific metadata as opposed to trying to store everything (terabytes of data per day), which would be impossibly expensive to store (and also to build the server infrastructure required to index and search it – effectively a mini-datacenter). ",[],{},{"nodeType":1293,"value":2904,"marks":2905,"data":2907},"Not to mention that storing detailed HTTP body data presents a significant security risk, as it includes valid session tokens/cookies for all your identities…  ",[2906],{"type":312},{},{"nodeType":1342,"data":2909,"content":2910},{},[2911],{"nodeType":1294,"data":2912,"content":2913},{},[2914,2919,2923],{"nodeType":1293,"value":2915,"marks":2916,"data":2918},"Each web app is custom, making automated analysis (virtually) impossible:",[2917],{"type":2109},{},{"nodeType":1293,"value":2920,"marks":2921,"data":2922}," Proxy-based solutions have to reconstruct the data after TLS encryption. HTTP data is usually stored in large application JSON/XML objects or even in totally custom encoding – per each app. This means that complex, custom code is required per each app to be able to perform automated analysis. When businesses today are using hundreds of apps on average, ",[],{},{"nodeType":1293,"value":2924,"marks":2925,"data":2927},"automating this process is not feasible as it requires constant reverse engineering of every web app. ",[2926],{"type":2109},{},{"nodeType":1294,"data":2929,"content":2930},{},[2931],{"nodeType":1293,"value":2932,"marks":2933,"data":2934},"So what does this mean? Well, even organizations with a TLS-terminating proxy are limited to manual analysis of select metadata after-the-fact, which massively reduces its utility. You could sink a day or more’s analysis into gathering a small amount of useful data, for example whether a URL was accessed, but not necessarily which device/user, or what account/creds were used to log in). This means you’re probably going to use proxy data to aid in the investigation of a known incident rather than anything proactive. ",[],{},{"nodeType":1294,"data":2936,"content":2937},{},[2938,2943,2949],{"nodeType":1293,"value":2939,"marks":2940,"data":2942},"It might be ",[2941],{"type":2109},{},{"nodeType":1293,"value":2944,"marks":2945,"data":2948},"theoretically",[2946,2947],{"type":312},{"type":2109},{},{"nodeType":1293,"value":2950,"marks":2951,"data":2953}," possible to sift through decrypted HTTP data to identify and correlate identities and actions, effectively reconstructing web pages from the network traffic automatically and on the fly (in the same way that it’s theoretically possible to remove my head and transplant it onto your body), but is it practical or reasonable for most organizations to do this? No. ",[2952],{"type":2109},{},{"nodeType":1402,"data":2955,"content":2956},{},[2957],{"nodeType":1293,"value":2958,"marks":2959,"data":2961},"Browser data: a better alternative?",[2960],{"type":2109},{},{"nodeType":1294,"data":2963,"content":2964},{},[2965],{"nodeType":1293,"value":2966,"marks":2967,"data":2968},"One way of overcoming some of the limitations of the classic web proxy setup is to use a browser-based solution. It’s much easier to collect data at the browser level before it’s encrypted. ",[],{},{"nodeType":1294,"data":2970,"content":2971},{},[2972],{"nodeType":1293,"value":2973,"marks":2974,"data":2975},"A browser agent isn’t just a proxy for pre-TLS HTML data, though. In the browser, you’re able to dynamically interact with the DOM or the rendered web application, including its JS code. This makes it easy to find, for example, input fields for usernames and passwords. You can see what information the user is inputting and where, without needing to figure out how the data is encoded and sent back to the app. These are fairly generic fields that can be identified across your suite of apps without needing complex custom code. To put it in perspective, approximately 10 login cases cover the entirety of the SaaS apps we support (~1000). Using a proxy-based solution, each of these would require custom development.   ",[],{},{"nodeType":1294,"data":2977,"content":2978},{},[2979],{"nodeType":1293,"value":2980,"marks":2981,"data":2982},"While it's technically possible to keep track of multiple sessions for thousands of users across hundreds of apps via proxy, it’s no mean feat – made much easier when each extension is tracking one user, in one browser, and even knows the browser tab it’s running in. You also get additional context at the identity layer such as the email address, authentication protocol, and credentials used, neatly mapped to that specific user and browser profile – no more trying to link the owner of an IP address to log events!",[],{},{"nodeType":1294,"data":2984,"content":2985},{},[2986],{"nodeType":1293,"value":2987,"marks":2988,"data":2989},"The browser also has the added benefit of being a natural enforcement point. You can collect and analyze data dynamically, and produce an immediate response – rather than taking info away, analyzing it, and coming back with a detection minutes or hours later (and potentially prompting a manual response). ",[],{},{"nodeType":1294,"data":2991,"content":2992},{},[2993],{"nodeType":1293,"value":2994,"marks":2995,"data":2996},"Let’s look at a couple of examples based on how we’re using our browser agent to detect and block identity attacks. ",[],{},{"nodeType":1338,"data":2998,"content":2999},{},[3000,3022,3042],{"nodeType":1342,"data":3001,"content":3002},{},[3003],{"nodeType":1294,"data":3004,"content":3005},{},[3006,3009,3018],{"nodeType":1293,"value":37,"marks":3007,"data":3008},[],{},{"nodeType":1387,"data":3010,"content":3012},{"uri":3011},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[3013],{"nodeType":1293,"value":3014,"marks":3015,"data":3017},"Pinning passwords to the legitimate site they are linked with",[3016],{"type":1395},{},{"nodeType":1293,"value":3019,"marks":3020,"data":3021},". This is made possible by interacting with the DOM to observe passwords being entered – enabling the Push agent to intercept and block before an HTTP network request can even be made. ",[],{},{"nodeType":1342,"data":3023,"content":3024},{},[3025],{"nodeType":1294,"data":3026,"content":3027},{},[3028,3031,3038],{"nodeType":1293,"value":37,"marks":3029,"data":3030},[],{},{"nodeType":1387,"data":3032,"content":3033},{"uri":2580},[3034],{"nodeType":1293,"value":3035,"marks":3036,"data":3037},"Detecting and blocking malicious phishing tools",[],{},{"nodeType":1293,"value":3039,"marks":3040,"data":3041}," running on websites by observing behavioral attributes in the browser, such as Javascript calls being made or data structures saved to local storage.",[],{},{"nodeType":1342,"data":3043,"content":3044},{},[3045],{"nodeType":1294,"data":3046,"content":3047},{},[3048,3051,3059],{"nodeType":1293,"value":37,"marks":3049,"data":3050},[],{},{"nodeType":1387,"data":3052,"content":3054},{"uri":3053},"https://pushsecurity.com/blog/manage-third-party-data-access/",[3055],{"nodeType":1293,"value":3056,"marks":3057,"data":3058},"Observing users signing up to and using risky apps",[],{},{"nodeType":1293,"value":3060,"marks":3061,"data":3062},", or changing or removing authentication methods, MFA methods, and configuration methods, which could indicate account takeover. ",[],{},{"nodeType":1294,"data":3064,"content":3065},{},[3066],{"nodeType":1293,"value":3067,"marks":3068,"data":3069},"It’s always useful to refer back to the concept of the Pyramid of Pain in these situations. The opportunities to detect and block in the browser tend to align with indicators at the apex of the pyramid, meaning they are a significant obstruction for attackers – and difficult to circumvent. This contrasts the indicators aligned with proxy-based solutions, which are much easier to bypass through, for example, IP masking using residential proxy networks, or changing the domains and URLs used for phishing campaigns.  ",[],{},{"nodeType":1322,"data":3071,"content":3075},{"target":3072},{"sys":3073},{"id":3074,"type":1327,"linkType":1328},"HrK2xQak6KfjInDbeSgv8",[],{"nodeType":1294,"data":3077,"content":3078},{},[3079],{"nodeType":1293,"value":3080,"marks":3081,"data":3082},"In summary: Browser data provides high-fidelity indicators of malicious activity, without the complications of proxy-based approaches. The scope for response in the browser is significant and immediate, meaning it’s a great enforcement point for security controls to be able to disrupt attacks. ",[],{},{"nodeType":1402,"data":3084,"content":3085},{},[3086],{"nodeType":1293,"value":3087,"marks":3088,"data":3089},"Won’t my app and IdP logs cover this?",[],{},{"nodeType":1294,"data":3091,"content":3092},{},[3093],{"nodeType":1293,"value":3094,"marks":3095,"data":3096},"App and IdP logs are useful (when you can get them), but neither give you the full picture. ",[],{},{"nodeType":1931,"data":3098,"content":3099},{},[3100],{"nodeType":1293,"value":3101,"marks":3102,"data":3103},"App logs are limited in availability, scope, and ease of ingestion ",[],{},{"nodeType":1294,"data":3105,"content":3106},{},[3107,3111,3120],{"nodeType":1293,"value":3108,"marks":3109,"data":3110},"When relying on app logs, you’re naturally constrained by the app provider. Many smaller apps provide no security logging, while others ",[],{},{"nodeType":1387,"data":3112,"content":3114},{"uri":3113},"https://audit-logs.tax/",[3115],{"nodeType":1293,"value":3116,"marks":3117,"data":3119},"lock security logging behind the premium tier subscription",[3118],{"type":1395},{},{"nodeType":1293,"value":3121,"marks":3122,"data":3123},". When logs are available, you’re limited to the events that the third-party deems suitable to log. ",[],{},{"nodeType":1294,"data":3125,"content":3126},{},[3127],{"nodeType":1293,"value":3128,"marks":3129,"data":3130},"Out of the 100 most popular apps we see across our customers, and perhaps the few dozen or so that are security critical, only a small handful provide any useful logging. This means, naturally, that the majority of apps do not. ",[],{},{"nodeType":1294,"data":3132,"content":3133},{},[3134],{"nodeType":1293,"value":3135,"marks":3136,"data":3137},"To top it all off, the process of extracting these logs and feeding them into your SIEM (or equivalent) is also not straightforward. The lack of out-of-the-box connectors for many apps means that complex custom architectures are required for collecting data. Some vendors place constraints on the format and mechanism for extracting logs which can make ingestion difficult to feed reliable detections – even before any meaningful analysis of the data can take place. ",[],{},{"nodeType":1294,"data":3139,"content":3140},{},[3141],{"nodeType":1293,"value":3142,"marks":3143,"data":3144},"Until application security logs are made widely available (and at no additional cost) it’s unlikely you’re going to be able to get the visibility you need from app logs, for every app your employees use (though of course there are exceptions – and we hope to see more vendors in future treating security as a minimum requirement, not a chargeable addon). ",[],{},{"nodeType":1931,"data":3146,"content":3147},{},[3148],{"nodeType":1293,"value":3149,"marks":3150,"data":3151},"IdP logs cover only SSO integrated apps and are limited in scope",[],{},{"nodeType":1294,"data":3153,"content":3154},{},[3155],{"nodeType":1293,"value":3156,"marks":3157,"data":3158},"You might think, “but all of our business apps are behind SSO, right?” In reality, only about 1 in 3 apps support SSO (and even fewer at the ‘free’ tier). And in practice, our data shows us that only 1 in 5 apps on average are actually behind SSO per organization. The theoretical security benefit of IdP logs is that they provide context, a foundation for the user’s activity across (and between) a suite of apps. But because of the lack of coverage, this isn’t the case. ",[],{},{"nodeType":1294,"data":3160,"content":3161},{},[3162],{"nodeType":1293,"value":3163,"marks":3164,"data":3165},"IdP logs are naturally focused on authentication, and so don’t compensate for any gaps in app logging. Naturally, they are only able to observe what happens on the IdP side – and so are blind to client side attacks like phishing (which we’ve already shown the browser provides superior visibility of compared to typical alternatives like proxy logs).   ",[],{},{"nodeType":1931,"data":3167,"content":3168},{},[3169],{"nodeType":1293,"value":3170,"marks":3171,"data":3172},"Browser is best for stopping identity attacks",[],{},{"nodeType":1294,"data":3174,"content":3175},{},[3176],{"nodeType":1293,"value":3177,"marks":3178,"data":3179},"This is where the browser comes in. Think of your browser as your source of truth, a broad data baseline for user activity where the browser provides complete context of the browser profile, employee, accounts, credentials, auth methods, and MFA types – as well as employee interaction with web sites.",[],{},{"nodeType":1294,"data":3181,"content":3182},{},[3183],{"nodeType":1293,"value":3184,"marks":3185,"data":3186},"The TL;DR is that your visibility in the browser is theoretically limitless. Every page loaded (and its source, javascript state, local storage), every user interaction can be observed. And best of all, this analysis is done securely in the browser and only the results of detections are reported back, rather than decrypting the entire raw traffic stream including all session data in an additional centralized system. ",[],{},{"nodeType":1322,"data":3188,"content":3192},{"target":3189},{"sys":3190},{"id":3191,"type":1327,"linkType":1328},"5jPCGPO1tnIkoI7MKW4oUi",[],{"nodeType":1402,"data":3194,"content":3195},{},[3196],{"nodeType":1293,"value":2594,"marks":3197,"data":3198},[],{},{"nodeType":1294,"data":3200,"content":3201},{},[3202],{"nodeType":1293,"value":3203,"marks":3204,"data":3205},"As an industry, we need to start looking at browser-based detection and response as the next logical evolution to stop identity attacks. There are clear parallels with the emergence of EDR – which came about because existing endpoint log sources were not sufficient. Today, we wouldn’t dream of trying to detect and respond to endpoint-based attacks without EDR – it’s time we started thinking about cloud identity attacks and the browser in the same way.  ",[],{},"The web proxy is dead… long live the browser extension!","Right now the majority of detections for identity attacks rely on web proxy telemetry. Here’s why the browser can be a better alternative.","2024-06-11T00:00:00.000Z","the-web-proxy-is-dead-long-live-the-browser-extension",{"items":3211},[3212,3214],{"sys":3213,"name":1310},{"id":1309},{"sys":3215,"name":2715},{"id":2714},{"items":3217},[3218],{"fullName":3219,"firstName":3220,"jobTitle":3221,"profilePicture":3222},"Dan Green","Dan","Threat Research",{"url":3223},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"items":3225},[3226],{"fullName":1849,"firstName":1850,"jobTitle":1851,"profilePicture":3227},{"url":1853},{"json":3229,"links":4018},{"nodeType":1295,"data":3230,"content":3231},{},[3232,3238,3245,3295,3302,3309,3324,3331,3338,3423,3430,3436,3443,3450,3465,3472,3479,3503,3527,3533,3553,3560,3567,3598,3605,3612,3618,3636,3643,3650,3657,3664,3670,3688,3695,3702,3709,3716,3722,3741,3748,3755,3761,3780,3787,3794,3801,3849,3856,3927,3942,3948,3955,3962,3969,3976,3994,4000],{"nodeType":1322,"data":3233,"content":3237},{"target":3234},{"sys":3235},{"id":3236,"type":1327,"linkType":1328},"7rud2H1hcTAOhxh9zHzxP6",[],{"nodeType":1294,"data":3239,"content":3240},{},[3241],{"nodeType":1293,"value":3242,"marks":3243,"data":3244},"If someone asked you where you work, you probably wouldn’t answer, “My browser.” But that would be the truth.",[],{},{"nodeType":1294,"data":3246,"content":3247},{},[3248,3252,3260,3263,3271,3274,3281,3284,3291],{"nodeType":1293,"value":3249,"marks":3250,"data":3251},"(Threat actors already know where you work, of course, and they’ve been capitalizing on the massive shift to cloud-based workforces. Just look at any of the ",[],{},{"nodeType":1387,"data":3253,"content":3255},{"uri":3254},"https://www.crowdstrike.com/global-threat-report/",[3256],{"nodeType":1293,"value":3257,"marks":3258,"data":3259},"latest",[],{},{"nodeType":1293,"value":2504,"marks":3261,"data":3262},[],{},{"nodeType":1387,"data":3264,"content":3266},{"uri":3265},"https://redcanary.com/threat-detection-report/techniques/cloud-accounts/",[3267],{"nodeType":1293,"value":3268,"marks":3269,"data":3270},"threat",[],{},{"nodeType":1293,"value":2504,"marks":3272,"data":3273},[],{},{"nodeType":1387,"data":3275,"content":3276},{"uri":1548},[3277],{"nodeType":1293,"value":3278,"marks":3279,"data":3280},"research",[],{},{"nodeType":1293,"value":2504,"marks":3282,"data":3283},[],{},{"nodeType":1387,"data":3285,"content":3286},{"uri":2389},[3287],{"nodeType":1293,"value":3288,"marks":3289,"data":3290},"reports",[],{},{"nodeType":1293,"value":3292,"marks":3293,"data":3294}," on identity-based attacks to see how good a job they’ve been doing.)",[],{},{"nodeType":1294,"data":3296,"content":3297},{},[3298],{"nodeType":1293,"value":3299,"marks":3300,"data":3301},"To get visibility of your infrastructure in order to build a strong detection and response program, the equation used to look something like:",[],{},{"nodeType":1294,"data":3303,"content":3304},{},[3305],{"nodeType":1293,"value":3306,"marks":3307,"data":3308},"Network traffic + Logs + Endpoints = Profit!",[],{},{"nodeType":1294,"data":3310,"content":3311},{},[3312,3316,3321],{"nodeType":1293,"value":3313,"marks":3314,"data":3315},"But now there’s a missing piece, as identity infrastructure sprawls across IdPs, core apps, shadow SaaS and third-party integrations: ",[],{},{"nodeType":1293,"value":3317,"marks":3318,"data":3320},"Browser telemetry",[3319],{"type":2109},{},{"nodeType":1293,"value":1738,"marks":3322,"data":3323},[],{},{"nodeType":1294,"data":3325,"content":3326},{},[3327],{"nodeType":1293,"value":3328,"marks":3329,"data":3330},"As a browser agent, Push is uniquely positioned to provide telemetry you can’t easily get anywhere else. We believe that this missing piece is the key to stopping identity attacks by providing the context both for first-class detections and security controls, as well as key correlations for events you observe in traditional log sources.",[],{},{"nodeType":1294,"data":3332,"content":3333},{},[3334],{"nodeType":1293,"value":3335,"marks":3336,"data":3337},"Now we have a better way to bring Push’s data to life to solve meaningful security challenges:",[],{},{"nodeType":1338,"data":3339,"content":3340},{},[3341,3372],{"nodeType":1342,"data":3342,"content":3343},{},[3344],{"nodeType":1294,"data":3345,"content":3346},{},[3347,3352,3356,3368],{"nodeType":1293,"value":3348,"marks":3349,"data":3351},"Plug-and-play security controls",[3350],{"type":2109},{},{"nodeType":1293,"value":3353,"marks":3354,"data":3355},", accessible from the new ",[],{},{"nodeType":3357,"data":3358,"content":3362},"entry-hyperlink",{"target":3359},{"sys":3360},{"id":3361,"type":1327,"linkType":1328},"BtDLgVZRWQ3Ov4WgDQX1W",[3363],{"nodeType":1293,"value":3364,"marks":3365,"data":3367},"Controls",[3366],{"type":2109},{},{"nodeType":1293,"value":3369,"marks":3370,"data":3371}," page in the Push platform",[],{},{"nodeType":1342,"data":3373,"content":3374},{},[3375],{"nodeType":1294,"data":3376,"content":3377},{},[3378,3383,3387,3395,3398,3406,3410,3419],{"nodeType":1293,"value":3379,"marks":3380,"data":3382},"Choose-your-own-adventure tooling",[3381],{"type":2109},{},{"nodeType":1293,"value":3384,"marks":3385,"data":3386},", including a ",[],{},{"nodeType":1387,"data":3388,"content":3390},{"uri":3389},"https://pushsecurity.redoc.ly/rest-v1/",[3391],{"nodeType":1293,"value":3392,"marks":3393,"data":3394},"REST API",[],{},{"nodeType":1293,"value":1969,"marks":3396,"data":3397},[],{},{"nodeType":1387,"data":3399,"content":3401},{"uri":3400},"https://pushsecurity.redoc.ly/webhooks-v1/",[3402],{"nodeType":1293,"value":3403,"marks":3404,"data":3405},"webhooks",[],{},{"nodeType":1293,"value":3407,"marks":3408,"data":3409},", and a new ",[],{},{"nodeType":1387,"data":3411,"content":3413},{"uri":3412},"/help/audience/administrators/docs/connect-to-siem-or-soar/#using-the-events-page",[3414],{"nodeType":1293,"value":3415,"marks":3416,"data":3418},"Events",[3417],{"type":2109},{},{"nodeType":1293,"value":3420,"marks":3421,"data":3422}," page to help you visualize and build custom detections and automations.",[],{},{"nodeType":1294,"data":3424,"content":3425},{},[3426],{"nodeType":1293,"value":3427,"marks":3428,"data":3429},"Let’s take a closer look.",[],{},{"nodeType":1322,"data":3431,"content":3435},{"target":3432},{"sys":3433},{"id":3434,"type":1327,"linkType":1328},"6iKFd9Qys2SSuNqKVQB7ka",[],{"nodeType":1402,"data":3437,"content":3438},{},[3439],{"nodeType":1293,"value":3440,"marks":3441,"data":3442},"Plug-and-play controls",[],{},{"nodeType":1294,"data":3444,"content":3445},{},[3446],{"nodeType":1293,"value":3447,"marks":3448,"data":3449},"Security visibility without security control is a recipe for a stress headache, so we’re big believers in providing meaningful interventions that are easy to use.",[],{},{"nodeType":1294,"data":3451,"content":3452},{},[3453,3457,3461],{"nodeType":1293,"value":3454,"marks":3455,"data":3456},"With the new ",[],{},{"nodeType":1293,"value":3364,"marks":3458,"data":3460},[3459],{"type":2109},{},{"nodeType":1293,"value":3462,"marks":3463,"data":3464}," page in the Push admin console, you can now find these preconfigured detections and interventions in one place. They cover use cases that any organization can benefit from, and take a unique browser-based approach to solving some thorny issues.",[],{},{"nodeType":1294,"data":3466,"content":3467},{},[3468],{"nodeType":1293,"value":3469,"marks":3470,"data":3471},"These controls include:",[],{},{"nodeType":1931,"data":3473,"content":3474},{},[3475],{"nodeType":1293,"value":3476,"marks":3477,"data":3478},"Phishing tool detection",[],{},{"nodeType":1294,"data":3480,"content":3481},{},[3482,3486,3491,3495,3500],{"nodeType":1293,"value":3483,"marks":3484,"data":3485},"Detect and block when employees visit webpages that use advanced phishing tools such as Evilginx or EvilNoVNC, among others. These adversary-in-the-middle (AitM) toolkits can mimic legitimate login screens, such as an Okta login page, to steal ",[],{},{"nodeType":1293,"value":3487,"marks":3488,"data":3490},"credentials",[3489],{"type":2109},{},{"nodeType":1293,"value":3492,"marks":3493,"data":3494}," and ",[],{},{"nodeType":1293,"value":3496,"marks":3497,"data":3499},"MFA codes",[3498],{"type":2109},{},{"nodeType":1293,"value":1738,"marks":3501,"data":3502},[],{},{"nodeType":1294,"data":3504,"content":3505},{},[3506,3510,3515,3518,3523],{"nodeType":1293,"value":3507,"marks":3508,"data":3509},"Push emits a webhook event when the browser agent detects attributes of these malware. You can also set Push to ",[],{},{"nodeType":1293,"value":3511,"marks":3512,"data":3514},"Warn",[3513],{"type":2109},{},{"nodeType":1293,"value":2635,"marks":3516,"data":3517},[],{},{"nodeType":1293,"value":3519,"marks":3520,"data":3522},"Block",[3521],{"type":2109},{},{"nodeType":1293,"value":3524,"marks":3525,"data":3526}," mode to display a customizable message to end-users when they encounter a phishing site.",[],{},{"nodeType":1322,"data":3528,"content":3532},{"target":3529},{"sys":3530},{"id":3531,"type":1327,"linkType":1328},"2ylIkR0JXHkFStGuCFRjlN",[],{"nodeType":1294,"data":3534,"content":3535},{},[3536,3540,3550],{"nodeType":1293,"value":3537,"marks":3538,"data":3539},"More about ",[],{},{"nodeType":3357,"data":3541,"content":3545},{"target":3542},{"sys":3543},{"id":3544,"type":1327,"linkType":1328},"7KRnTSnJAbbiho69gNyN0B",[3546],{"nodeType":1293,"value":3547,"marks":3548,"data":3549},"phishing tool detection",[],{},{"nodeType":1293,"value":37,"marks":3551,"data":3552},[],{},{"nodeType":1931,"data":3554,"content":3555},{},[3556],{"nodeType":1293,"value":3557,"marks":3558,"data":3559},"SSO password protection",[],{},{"nodeType":1294,"data":3561,"content":3562},{},[3563],{"nodeType":1293,"value":3564,"marks":3565,"data":3566},"Prevent employees from reusing their corporate SSO password on any page that doesn’t belong to the identity provider, including phishing sites. This means that even if that employee was the first person to get phished using a new attacker site, Push still detects it and blocks it.",[],{},{"nodeType":1294,"data":3568,"content":3569},{},[3570,3574,3578,3581,3585,3589,3594],{"nodeType":1293,"value":3571,"marks":3572,"data":3573},"Customize the message that end-users see in ",[],{},{"nodeType":1293,"value":3511,"marks":3575,"data":3577},[3576],{"type":2109},{},{"nodeType":1293,"value":2635,"marks":3579,"data":3580},[],{},{"nodeType":1293,"value":3519,"marks":3582,"data":3584},[3583],{"type":2109},{},{"nodeType":1293,"value":3586,"marks":3587,"data":3588}," mode, or start out in ",[],{},{"nodeType":1293,"value":3590,"marks":3591,"data":3593},"Monitor",[3592],{"type":2109},{},{"nodeType":1293,"value":3595,"marks":3596,"data":3597}," mode to catch any false positives before you enforce the control.",[],{},{"nodeType":1294,"data":3599,"content":3600},{},[3601],{"nodeType":1293,"value":3602,"marks":3603,"data":3604},"This feature supports the following identity providers: Okta, Microsoft 365, Google Workspace, JumpCloud, Duo, and Ping Identity.",[],{},{"nodeType":1294,"data":3606,"content":3607},{},[3608],{"nodeType":1293,"value":3609,"marks":3610,"data":3611},"Push will also emit a webhook event when an SSO password is used, and if an employee clicks through the warning screen.",[],{},{"nodeType":1322,"data":3613,"content":3617},{"target":3614},{"sys":3615},{"id":3616,"type":1327,"linkType":1328},"25c8M2gWYFST7yYxGEji2s",[],{"nodeType":1294,"data":3619,"content":3620},{},[3621,3624,3633],{"nodeType":1293,"value":3537,"marks":3622,"data":3623},[],{},{"nodeType":3357,"data":3625,"content":3629},{"target":3626},{"sys":3627},{"id":3628,"type":1327,"linkType":1328},"6FYHbkcRUrtznPo7RarRsz",[3630],{"nodeType":1293,"value":3557,"marks":3631,"data":3632},[],{},{"nodeType":1293,"value":37,"marks":3634,"data":3635},[],{},{"nodeType":1931,"data":3637,"content":3638},{},[3639],{"nodeType":1293,"value":3640,"marks":3641,"data":3642},"URL blocking",[],{},{"nodeType":1294,"data":3644,"content":3645},{},[3646],{"nodeType":1293,"value":3647,"marks":3648,"data":3649},"When you find malicious sites you want to block, such as when responding to a phishing incident, add them to a blocklist and prevent other employees from accessing those sites. ",[],{},{"nodeType":1294,"data":3651,"content":3652},{},[3653],{"nodeType":1293,"value":3654,"marks":3655,"data":3656},"URL blocking can be used in tandem with Push’s anti-phishing controls, so that as you discover malicious sites, you can block them from a central blocklist. This offers a kind of herd immunity where you can block other users from visiting a malicious site as soon as you have a single incident.",[],{},{"nodeType":1294,"data":3658,"content":3659},{},[3660],{"nodeType":1293,"value":3661,"marks":3662,"data":3663},"You can programmatically manage the blocklist using the Push REST API or sync to other threat intelligence sources you consume.",[],{},{"nodeType":1322,"data":3665,"content":3669},{"target":3666},{"sys":3667},{"id":3668,"type":1327,"linkType":1328},"3m00cFiUDAnddsOBOpkeiZ",[],{"nodeType":1294,"data":3671,"content":3672},{},[3673,3676,3685],{"nodeType":1293,"value":3537,"marks":3674,"data":3675},[],{},{"nodeType":3357,"data":3677,"content":3681},{"target":3678},{"sys":3679},{"id":3680,"type":1327,"linkType":1328},"P0coHgQAdRL0YTu4Rwd4z",[3682],{"nodeType":1293,"value":3640,"marks":3683,"data":3684},[],{},{"nodeType":1293,"value":37,"marks":3686,"data":3687},[],{},{"nodeType":1931,"data":3689,"content":3690},{},[3691],{"nodeType":1293,"value":3692,"marks":3693,"data":3694},"Session token theft detection",[],{},{"nodeType":1294,"data":3696,"content":3697},{},[3698],{"nodeType":1293,"value":3699,"marks":3700,"data":3701},"Inject a unique marker provided by the Push browser agent into the User Agent string of sessions that occur in browsers enrolled in Push. ",[],{},{"nodeType":1294,"data":3703,"content":3704},{},[3705],{"nodeType":1293,"value":3706,"marks":3707,"data":3708},"By analyzing logs from your IdP, you can identify activity from the same session that both has the Push marker and that lacks the marker. This can only ever happen when a session is extracted from a browser and maliciously imported into a different browser.",[],{},{"nodeType":1294,"data":3710,"content":3711},{},[3712],{"nodeType":1293,"value":3713,"marks":3714,"data":3715},"This is a high-fidelity signal that a session token has been stolen and is being used.",[],{},{"nodeType":1322,"data":3717,"content":3721},{"target":3718},{"sys":3719},{"id":3720,"type":1327,"linkType":1328},"43rk3TCqN269Vr2YWT4llP",[],{"nodeType":1294,"data":3723,"content":3724},{},[3725,3728,3738],{"nodeType":1293,"value":3537,"marks":3726,"data":3727},[],{},{"nodeType":3357,"data":3729,"content":3733},{"target":3730},{"sys":3731},{"id":3732,"type":1327,"linkType":1328},"1UMZdjyNQt4Y7NBb2wuK4L",[3734],{"nodeType":1293,"value":3735,"marks":3736,"data":3737},"session token theft detection",[],{},{"nodeType":1293,"value":37,"marks":3739,"data":3740},[],{},{"nodeType":1931,"data":3742,"content":3743},{},[3744],{"nodeType":1293,"value":3745,"marks":3746,"data":3747},"App banners",[],{},{"nodeType":1294,"data":3749,"content":3750},{},[3751],{"nodeType":1293,"value":3752,"marks":3753,"data":3754},"Add guardrails to employees’ use of SaaS apps with in-browser app banner messages you customize with your own text. You can require users to acknowledge having read a message before they can access an app, or even require them to submit a reason for using an app before they can log in.",[],{},{"nodeType":1322,"data":3756,"content":3760},{"target":3757},{"sys":3758},{"id":3759,"type":1327,"linkType":1328},"5nEKTBz6mauHI5mg8jB4ea",[],{"nodeType":1294,"data":3762,"content":3763},{},[3764,3767,3777],{"nodeType":1293,"value":3537,"marks":3765,"data":3766},[],{},{"nodeType":3357,"data":3768,"content":3772},{"target":3769},{"sys":3770},{"id":3771,"type":1327,"linkType":1328},"2ZpKnuljaUH0jzVaae4SMN",[3773],{"nodeType":1293,"value":3774,"marks":3775,"data":3776},"app banners",[],{},{"nodeType":1293,"value":37,"marks":3778,"data":3779},[],{},{"nodeType":1402,"data":3781,"content":3782},{},[3783],{"nodeType":1293,"value":3784,"marks":3785,"data":3786},"Choose your own adventure",[],{},{"nodeType":1294,"data":3788,"content":3789},{},[3790],{"nodeType":1293,"value":3791,"marks":3792,"data":3793},"Want to do something creative? We've got you covered. Push provides a wealth of raw telemetry via the Push REST API and webhook events. Use this data to build both proactive and reactive security operations workflows, or add missing context to other sources, such as your IdP, application, or endpoint logs.",[],{},{"nodeType":1294,"data":3795,"content":3796},{},[3797],{"nodeType":1293,"value":3798,"marks":3799,"data":3800},"You can use this browser telemetry to:",[],{},{"nodeType":1338,"data":3802,"content":3803},{},[3804,3819,3834],{"nodeType":1342,"data":3805,"content":3806},{},[3807],{"nodeType":1294,"data":3808,"content":3809},{},[3810,3815],{"nodeType":1293,"value":3811,"marks":3812,"data":3814},"Harden identities and reduce account compromise",[3813],{"type":2109},{},{"nodeType":1293,"value":3816,"marks":3817,"data":3818},", such as alerting you when passwords are identified in public data breaches or when employees are using an unapproved app or when an SSO app is accessed via local account.",[],{},{"nodeType":1342,"data":3820,"content":3821},{},[3822],{"nodeType":1294,"data":3823,"content":3824},{},[3825,3830],{"nodeType":1293,"value":3826,"marks":3827,"data":3829},"Monitor for suspicious activity or high-risk changes",[3828],{"type":2109},{},{"nodeType":1293,"value":3831,"marks":3832,"data":3833},", such as checking for MFA method changes, or flagging when employees reuse corporate SSO passwords or visit sites running phishing malware.",[],{},{"nodeType":1342,"data":3835,"content":3836},{},[3837],{"nodeType":1294,"data":3838,"content":3839},{},[3840,3845],{"nodeType":1293,"value":3841,"marks":3842,"data":3844},"Investigate indicators of compromise",[3843],{"type":2109},{},{"nodeType":1293,"value":3846,"marks":3847,"data":3848},", such as correlating login events with platform logs, searching for recent signups to risky apps, or identifying post-compromise lateral movement opportunities.",[],{},{"nodeType":1294,"data":3850,"content":3851},{},[3852],{"nodeType":1293,"value":3853,"marks":3854,"data":3855},"In the “make my life easier” category, you can also use Push telemetry to:",[],{},{"nodeType":1338,"data":3857,"content":3858},{},[3859,3878,3897,3912],{"nodeType":1342,"data":3860,"content":3861},{},[3862],{"nodeType":1294,"data":3863,"content":3864},{},[3865,3869,3874],{"nodeType":1293,"value":3866,"marks":3867,"data":3868},"Automate a workflow ",[],{},{"nodeType":1293,"value":3870,"marks":3871,"data":3873},"showing you all the accounts and apps used by an offboarded employee",[3872],{"type":2109},{},{"nodeType":1293,"value":3875,"marks":3876,"data":3877},", and their account login methods.",[],{},{"nodeType":1342,"data":3879,"content":3880},{},[3881],{"nodeType":1294,"data":3882,"content":3883},{},[3884,3888,3893],{"nodeType":1293,"value":3885,"marks":3886,"data":3887},"Automate a workflow to",[],{},{"nodeType":1293,"value":3889,"marks":3890,"data":3892}," revoke licenses on SaaS after a period of inactivity",[3891],{"type":2109},{},{"nodeType":1293,"value":3894,"marks":3895,"data":3896},", saving money.",[],{},{"nodeType":1342,"data":3898,"content":3899},{},[3900],{"nodeType":1294,"data":3901,"content":3902},{},[3903,3908],{"nodeType":1293,"value":3904,"marks":3905,"data":3907},"Build an approved apps list in your company wiki",[3906],{"type":2109},{},{"nodeType":1293,"value":3909,"marks":3910,"data":3911},", synced from Push’s source of truth.",[],{},{"nodeType":1342,"data":3913,"content":3914},{},[3915],{"nodeType":1294,"data":3916,"content":3917},{},[3918,3923],{"nodeType":1293,"value":3919,"marks":3920,"data":3922},"Force-reset an IdP password if Push finds a compromised password",[3921],{"type":2109},{},{"nodeType":1293,"value":3924,"marks":3925,"data":3926}," on an employee account.",[],{},{"nodeType":1294,"data":3928,"content":3929},{},[3930,3934,3938],{"nodeType":1293,"value":3931,"marks":3932,"data":3933},"To help you visualize and plan how you will use this telemetry, Push also provides an ",[],{},{"nodeType":1293,"value":3415,"marks":3935,"data":3937},[3936],{"type":2109},{},{"nodeType":1293,"value":3939,"marks":3940,"data":3941}," page in the admin console with a rolling 7-day snapshot of all the events in your environment.",[],{},{"nodeType":1322,"data":3943,"content":3947},{"target":3944},{"sys":3945},{"id":3946,"type":1327,"linkType":1328},"2a3bJ5sN8dJ0c1kQtZiag7",[],{"nodeType":1294,"data":3949,"content":3950},{},[3951],{"nodeType":1293,"value":3952,"marks":3953,"data":3954},"The Events page can help you see real-world examples, understand the attributes of each event, and gauge event volume before you ingest data into a SIEM or other platform.",[],{},{"nodeType":1402,"data":3956,"content":3957},{},[3958],{"nodeType":1293,"value":3959,"marks":3960,"data":3961},"What if you don’t have a SIEM?",[],{},{"nodeType":1294,"data":3963,"content":3964},{},[3965],{"nodeType":1293,"value":3966,"marks":3967,"data":3968},"While you’d need a SIEM for writing detections and performing log correlations, you can still get a lot of value out of Push telemetry if you don’t have one.",[],{},{"nodeType":1294,"data":3970,"content":3971},{},[3972],{"nodeType":1293,"value":3973,"marks":3974,"data":3975},"Use Push’s webhook events to send alerts directly to your Slack, Teams, or other chat platform, or build workflows that hook into your ticketing system or SOAR platform.",[],{},{"nodeType":1294,"data":3977,"content":3978},{},[3979,3983,3990],{"nodeType":1293,"value":3980,"marks":3981,"data":3982},"Review our ",[],{},{"nodeType":1387,"data":3984,"content":3985},{"uri":3400},[3986],{"nodeType":1293,"value":3987,"marks":3988,"data":3989},"webhooks documentation",[],{},{"nodeType":1293,"value":3991,"marks":3992,"data":3993}," for a list of events.",[],{},{"nodeType":1402,"data":3995,"content":3996},{},[3997],{"nodeType":1293,"value":1813,"marks":3998,"data":3999},[],{},{"nodeType":1294,"data":4001,"content":4002},{},[4003,4007,4014],{"nodeType":1293,"value":4004,"marks":4005,"data":4006},"If you want to see Push in action, ",[],{},{"nodeType":1387,"data":4008,"content":4010},{"uri":4009},"/demo/",[4011],{"nodeType":1293,"value":1828,"marks":4012,"data":4013},[],{},{"nodeType":1293,"value":4015,"marks":4016,"data":4017},". We’ll be happy to show you these features, along with how we discover all the apps your employees are using — even the ones not behind SSO.",[],{},{"entries":4019},{"inline":4020,"hyperlink":4021,"block":4054},[],[4022,4028,4034,4039,4044,4049],{"sys":4023,"__typename":4024,"linkedFromParent":118,"title":4025,"slug":4026,"audience":4027},{"id":3361},"DocumentationPage","Manage security controls","manage-security-controls","administrators",{"sys":4029,"__typename":4030,"title":4031,"slug":4032,"articleId":4033},{"id":3544},"HelpArticle","Can I use Push to detect phishing tools like Evilginx, Modlishka, NakedPages, or Muraena?","can-i-use-push-to-detect-phishing-tools-like-evilnovnc-and-evilginx",10113,{"sys":4035,"__typename":4030,"title":4036,"slug":4037,"articleId":4038},{"id":3628},"How does Push protect passwords from being reused or phished?","how-does-push-detect-and-prevent-phishing-attacks",10109,{"sys":4040,"__typename":4030,"title":4041,"slug":4042,"articleId":4043},{"id":3680},"Can Push block users from visiting websites?","can-push-block-users-from-visiting-websites",10112,{"sys":4045,"__typename":4030,"title":4046,"slug":4047,"articleId":4048},{"id":3732},"How does Push help detect session token theft?","how-does-push-help-detect-session-token-theft",10114,{"sys":4050,"__typename":4030,"title":4051,"slug":4052,"articleId":4053},{"id":3771},"What can I use the app banner for? Templates and examples","what-can-i-use-the-app-banner-for-templates-and-examples",10106,[4055,4064,4071,4077,4082,4086,4090,4094],{"sys":4056,"__typename":4057,"title":4058,"youTubeUrl":4059,"imagePlaceholder":4060},{"id":3236},"ExternalVideo","Introducing the Push set-and-forget controls page and events feed","https://www.youtube.com/watch?v=rdbEjLtHVeI",{"url":4061,"width":4062,"height":4063},"https://images.ctfassets.net/y1cdw1ablpvd/3erssFxQsawGjQYO1OgpaY/6dce14e1031c59a31c16fc3a4aef7052/Screenshot_2024-08-15_at_07.18.14.png",3330,1866,{"sys":4065,"__typename":4066,"type":4067,"ctaText":4068,"buttonLabel":4069,"buttonColour":4070,"buttonUrl":118},{"id":3434},"CtaWidget","Demo","Learn how Push can help you secure identities across your org","Book a demo!","sunny orange",{"sys":4072,"__typename":4073,"title":4074,"arcadeDemoUrl":4075,"playText":4076},{"id":3531},"ArcadeDemo","Phishing tool detection demo","https://demo.arcade.software/56g5alxkmegzjvQnZxrC?embed","1 min",{"sys":4078,"__typename":4073,"title":4079,"arcadeDemoUrl":4080,"playText":4081},{"id":3616},"SSO password protection demo","https://demo.arcade.software/tydMEka88g65V2KMU018?embed","2 mins",{"sys":4083,"__typename":4073,"title":4084,"arcadeDemoUrl":4085,"playText":4081},{"id":3668},"URL blocking demo","https://demo.arcade.software/A6pdxTOHjVl2BaPJ98Vj?embed",{"sys":4087,"__typename":4073,"title":4088,"arcadeDemoUrl":4089,"playText":4081},{"id":3720},"Session theft detection demo","https://demo.arcade.software/ALltBFZnFbBmVFUgx7z5?embed",{"sys":4091,"__typename":4073,"title":4092,"arcadeDemoUrl":4093,"playText":4081},{"id":3759},"App banners demo","https://demo.arcade.software/TlBO2p8454bN4szY4Jxq?embed",{"sys":4095,"__typename":4096,"title":4097,"caption":118,"layoutMode":118,"file":4098},{"id":3946},"Image","Events page - event details - docs - Connect to SIEM or SOAR",{"url":4099,"width":4100,"height":4101},"https://images.ctfassets.net/y1cdw1ablpvd/l6JvepRcU8ZCviZaSWM4T/2b0288c3080c3aa0040de13d73f4c782/events_page_filtered_20260305.png",3016,1726,"content:blog:introducing-set-and-forget-controls-that-stop-real-world-identity-attacks.json","json","content","blog/introducing-set-and-forget-controls-that-stop-real-world-identity-attacks.json","blog/introducing-set-and-forget-controls-that-stop-real-world-identity-attacks",1776359988529]