[{"data":1,"prerenderedAt":4850},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/minimum-viable-identity-security":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"summary":1282,"title":1296,"subtitle":1297,"metaTitle":1298,"synopsis":1299,"hashTags":118,"publishedDate":1300,"slug":1301,"ogImage":1302,"tagsCollection":1304,"relatedBlogPostsCollection":1314,"authorsCollection":3819,"content":3823,"_id":4845,"_type":4846,"_source":4847,"_file":4848,"_stem":4849,"_extension":4846},"/blog/minimum-viable-identity-security","blog",{"id":1280,"publishedAt":1281},"1VGP8VIzwMh0zjNOzU5qaq","2025-03-03T14:23:30.799Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"How app developers can go beyond the Minimum Viable Secure Product (MVSP) controls framework to implement better identity protections and prevent identity-based attacks. ","text","paragraph","document","Minimum Viable Identity Security","8 ways app developers can go beyond MVSP to mitigate identity-based attacks","8 ways app developers can mitigate identity-based attacks","How app developers can go beyond Minimum Viable Secure Product (MVSP) to implement better identity protections and prevent identity-based attacks. ","2025-02-10T00:00:00.000Z","minimum-viable-identity-security",{"url":1303},"https://images.ctfassets.net/y1cdw1ablpvd/5EErNKIkhkUn2Y9OCLlDjR/2e5c107747f8d881d87484577bfd895c/Dan_Blog_Thumbnail.jpg",{"items":1305},[1306,1310],{"sys":1307,"name":1309},{"id":1308},"3pjES4THCIfSAwhGdNwBcy","Identity security",{"sys":1311,"name":1313},{"id":1312},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1315},[1316,2540,3181],{"__typename":1317,"sys":1318,"content":1320,"title":2522,"synopsis":2523,"hashTags":118,"publishedDate":2524,"slug":2525,"tagsCollection":2526,"authorsCollection":2532},"BlogPosts",{"id":1319},"5KqYY7p174lSpuinfTfEZU",{"json":1321},{"data":1322,"content":1323,"nodeType":1295},{},[1324,1331,1390,1397,1401,1409,1416,1449,1462,1465,1472,1485,1492,1512,1521,1541,1548,1559,1580,1600,1607,1627,1633,1653,1656,1663,1670,1677,1697,1717,1724,1744,1751,1758,1784,1791,1811,1832,1838,1845,1865,1868,1875,1895,1915,1922,1975,1982,1985,1992,1999,2018,2038,2045,2052,2059,2080,2087,2094,2100,2106,2109,2116,2123,2130,2150,2161,2180,2187,2194,2204,2211,2218,2239,2245,2248,2255,2262,2269,2342,2349,2356,2363,2371,2392,2399,2405,2416,2437,2444,2452,2473,2480,2487,2493,2496,2503],{"data":1325,"content":1326,"nodeType":1294},{},[1327],{"data":1328,"marks":1329,"value":1330,"nodeType":1293},{},[],"From massive breaches like the Snowflake incident to novel phishing techniques documented by Push researchers, 2024 was the year that identity attacks left their mark. Looking back over what we saw in the wild and what we found through Push’s own research, three key themes stand out:",{"data":1332,"content":1333,"nodeType":1389},{},[1334,1354,1364],{"data":1335,"content":1336,"nodeType":1353},{},[1337],{"data":1338,"content":1339,"nodeType":1294},{},[1340,1344,1349],{"data":1341,"marks":1342,"value":1343,"nodeType":1293},{},[],"Account takeover techniques on cloud apps are fundamentally different from traditional network-based attacks. To have the best chance of preventing account takeover, defenders need to  disrupt attacks ",{"data":1345,"marks":1346,"value":1348,"nodeType":1293},{},[1347],{"type":312},"before",{"data":1350,"marks":1351,"value":1352,"nodeType":1293},{},[]," they’re successful.","list-item",{"data":1355,"content":1356,"nodeType":1353},{},[1357],{"data":1358,"content":1359,"nodeType":1294},{},[1360],{"data":1361,"marks":1362,"value":1363,"nodeType":1293},{},[],"It’s not easy or practical to maintain 100 percent compliance on identity posture standards in a world where employees are using and signing up to apps outside of IT oversight — but it is possible to make this work a lot easier by using tools that help you scale your remediation activities.",{"data":1365,"content":1366,"nodeType":1353},{},[1367],{"data":1368,"content":1369,"nodeType":1294},{},[1370,1374,1385],{"data":1371,"marks":1372,"value":1373,"nodeType":1293},{},[],"Despite another year where cybersecurity spend increased (now up to almost $1,100 per user, according to ",{"data":1375,"content":1377,"nodeType":1384},{"uri":1376},"https://www.forrester.com/report/2024-cybersecurity-benchmarks-global/RES181118",[1378],{"data":1379,"marks":1380,"value":1383,"nodeType":1293},{},[1381],{"type":1382},"underline","Forrester","hyperlink",{"data":1386,"marks":1387,"value":1388,"nodeType":1293},{},[],"), existing approaches are not successfully preventing account takeovers. Security teams need to be able to detect and respond to these attacks where they happen: The browser.","unordered-list",{"data":1391,"content":1392,"nodeType":1294},{},[1393],{"data":1394,"marks":1395,"value":1396,"nodeType":1293},{},[],"In this article, we’ll take a look back at how these themes influenced key features we delivered for Push customers in 2024.",{"data":1398,"content":1399,"nodeType":1400},{},[],"hr",{"data":1402,"content":1403,"nodeType":1408},{},[1404],{"data":1405,"marks":1406,"value":1407,"nodeType":1293},{},[],"Defending against modern phishing attacks","heading-1",{"data":1410,"content":1411,"nodeType":1294},{},[1412],{"data":1413,"marks":1414,"value":1415,"nodeType":1293},{},[],"Phishing techniques that bypass MFA are now the norm, and few organizations have successfully achieved full coverage of phishing-resistant MFA methods. ",{"data":1417,"content":1418,"nodeType":1294},{},[1419,1423,1432,1436,1445],{"data":1420,"marks":1421,"value":1422,"nodeType":1293},{},[],"Equally, while phishing attacks via email remain the most commonly reported vector, phishing attacks increasingly target users outside of email. For example, phishing links are often encountered through normal internet use — such as ",{"data":1424,"content":1426,"nodeType":1384},{"uri":1425},"https://www.bleepingcomputer.com/news/security/hackers-use-google-search-ads-to-steal-google-ads-accounts/",[1427],{"data":1428,"marks":1429,"value":1431,"nodeType":1293},{},[1430],{"type":1382},"in malicious Google ads",{"data":1433,"marks":1434,"value":1435,"nodeType":1293},{},[]," — and attackers frequently conduct their campaigns over IM platforms like Slack and Teams. Late last year there was ",{"data":1437,"content":1439,"nodeType":1384},{"uri":1438},"https://www.linkedin.com/posts/kevin-beaumont-security_ive-been-assisting-a-few-orgs-hit-with-successful-activity-7268055739116445701-xxjZ?utm_source=share&utm_medium=member_desktop",[1440],{"data":1441,"marks":1442,"value":1444,"nodeType":1293},{},[1443],{"type":1382},"a rise in attackers inundating users with spam via Teams",{"data":1446,"marks":1447,"value":1448,"nodeType":1293},{},[],", combined with phone scams posing as IT admins. Since anti-phishing controls are usually email-based, they fail to protect users from attacks taking place elsewhere. ",{"data":1450,"content":1451,"nodeType":1294},{},[1452,1456],{"data":1453,"marks":1454,"value":1455,"nodeType":1293},{},[],"At Push, we’ve built a suite of anti-phishing features over the last year that act as a defense-in-depth approach to the types of modern phishing techniques we’ve been observing in the wild. ",{"data":1457,"marks":1458,"value":1461,"nodeType":1293},{},[1459],{"type":1460},"bold","Here’s what we built and why.",{"data":1463,"content":1464,"nodeType":1400},{},[],{"data":1466,"content":1467,"nodeType":1408},{},[1468],{"data":1469,"marks":1470,"value":1471,"nodeType":1293},{},[],"Protecting passwords used for SSO",{"data":1473,"content":1474,"nodeType":1484},{},[1475,1480],{"data":1476,"marks":1477,"value":1479,"nodeType":1293},{},[1478],{"type":1460},"What happened?",{"data":1481,"marks":1482,"value":1483,"nodeType":1293},{},[]," ","heading-2",{"data":1486,"content":1487,"nodeType":1294},{},[1488],{"data":1489,"marks":1490,"value":1491,"nodeType":1293},{},[],"Attackers explicitly targeted Okta, Entra, and Google Workspace accounts in 2023 and 2024, so we knew a top priority would be protecting identity provider accounts. These IdP accounts are a key target because they allow attackers to move laterally to other valuable apps and data via SSO following the initial account takeover.",{"data":1493,"content":1494,"nodeType":1294},{},[1495,1499,1508],{"data":1496,"marks":1497,"value":1498,"nodeType":1293},{},[],"It’s not just the typical IdPs you need to watch out for, either: Apps like GitHub, Slack, Salesforce, Facebook, X, and others all provide SSO functionality, increasing the blast radius of a compromise. And as we reported in ",{"data":1500,"content":1502,"nodeType":1384},{"uri":1501},"https://pushsecurity.com/blog/cross-idp-impersonation/",[1503],{"data":1504,"marks":1505,"value":1507,"nodeType":1293},{},[1506],{"type":1382},"our research on cross-IdP impersonation",{"data":1509,"marks":1510,"value":1511,"nodeType":1293},{},[],", apps can be accessed using multiple SSO methods simultaneously — and 3 in 5 apps that we tested recently did not require re-verification by default when adding a new login method.",{"data":1513,"content":1519,"nodeType":1520},{"target":1514},{"sys":1515},{"id":1516,"type":1517,"linkType":1518},"3EOOr4dVQoiPjl2ucUs1mA","Link","Entry",[],"embedded-entry-block",{"data":1522,"content":1523,"nodeType":1294},{},[1524,1528,1537],{"data":1525,"marks":1526,"value":1527,"nodeType":1293},{},[],"Phishing is a problem that would be significantly reduced in a world without passwords. But while the ideal case is that organizations can put in place phishing-resistant authentication methods like passkeys or other WebAuthn-based methods, the reality is that ",{"data":1529,"content":1531,"nodeType":1384},{"uri":1530},"https://www.ncsc.gov.uk/blog-post/passkeys-not-perfect-getting-better",[1532],{"data":1533,"marks":1534,"value":1536,"nodeType":1293},{},[1535],{"type":1382},"it’s not a perfect solution right now",{"data":1538,"marks":1539,"value":1540,"nodeType":1293},{},[]," — widespread passkey implementation is hard to achieve.",{"data":1542,"content":1543,"nodeType":1294},{},[1544],{"data":1545,"marks":1546,"value":1547,"nodeType":1293},{},[],"One of the key advantages of passkeys is that they are domain-bound: Meaning they can’t be used on a site with the wrong domain. So, we started thinking: What if it were possible to essentially domain-bind a password? ",{"data":1549,"content":1550,"nodeType":1484},{},[1551,1556],{"data":1552,"marks":1553,"value":1555,"nodeType":1293},{},[1554],{"type":1460},"What we built",{"data":1557,"marks":1558,"value":1483,"nodeType":1293},{},[],{"data":1560,"content":1561,"nodeType":1294},{},[1562,1566,1576],{"data":1563,"marks":1564,"value":1565,"nodeType":1293},{},[],"In the first half of 2024, we delivered our ",{"data":1567,"content":1569,"nodeType":1384},{"uri":1568},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[1570],{"data":1571,"marks":1572,"value":1575,"nodeType":1293},{},[1573,1574],{"type":1382},{"type":1460},"SSO password protection",{"data":1577,"marks":1578,"value":1579,"nodeType":1293},{},[]," feature, which allows Push administrators to block employees from entering their IdP password into any site that’s not the identity provider — in effect domain-binding SSO credentials. ",{"data":1581,"content":1582,"nodeType":1294},{},[1583,1587,1596],{"data":1584,"marks":1585,"value":1586,"nodeType":1293},{},[],"Push accomplishes this via the Push browser agent, which ",{"data":1588,"content":1590,"nodeType":1384},{"uri":1589},"https://pushsecurity.com/help/10109/#how-does-sso-password-protection-work",[1591],{"data":1592,"marks":1593,"value":1595,"nodeType":1293},{},[1594],{"type":1382},"observes and fingerprints",{"data":1597,"marks":1598,"value":1599,"nodeType":1293},{},[]," the user’s SSO password and legitimate SSO login pages, and then enforces in-browser controls to prevent an SSO password from being submitted on any URL that doesn’t match the legitimate provider, an extremely strong anti-phishing protection. Separately, Push also verifies that passwords it observes are not easily guessable.",{"data":1601,"content":1602,"nodeType":1294},{},[1603],{"data":1604,"marks":1605,"value":1606,"nodeType":1293},{},[],"The idea behind this approach is to gain some similar benefits to passkeys — by ensuring that passwords used for SSO access to your apps cannot be phished and are unique and strong — but in a way that “just works” with existing password-based authentication. ",{"data":1608,"content":1609,"nodeType":1294},{},[1610,1614,1623],{"data":1611,"marks":1612,"value":1613,"nodeType":1293},{},[],"Organizations that monitor for SSO password reuse will find that the practice turns out to be incredibly widespread, so being able to detect and prevent password reuse — even outside of actual phishing attempts — is an asset to security teams. (Our ",{"data":1615,"content":1617,"nodeType":1384},{"uri":1616},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[1618],{"data":1619,"marks":1620,"value":1622,"nodeType":1293},{},[1621],{"type":1382},"research shows",{"data":1624,"marks":1625,"value":1626,"nodeType":1293},{},[]," that 10% of IdP accounts are using a password that is shared with another app — where it is much more likely to be compromised.) ",{"data":1628,"content":1632,"nodeType":1520},{"target":1629},{"sys":1630},{"id":1631,"type":1517,"linkType":1518},"4Ce999wf4mqCZwu1jLofsx",[],{"data":1634,"content":1635,"nodeType":1294},{},[1636,1640,1649],{"data":1637,"marks":1638,"value":1639,"nodeType":1293},{},[],"By streaming events to your SIEM and setting up a simple automation, you can also use Push-supplied intelligence on SSO password reuse to ",{"data":1641,"content":1643,"nodeType":1384},{"uri":1642},"https://pushsecurity.com/blog/automating-sso-password-resets-using-push/",[1644],{"data":1645,"marks":1646,"value":1648,"nodeType":1293},{},[1647],{"type":1382},"automatically reset",{"data":1650,"marks":1651,"value":1652,"nodeType":1293},{},[]," potentially compromised passwords — this provides instant response to successful phishing and gets rid of password re-use of your most sensitive credentials in one move - the kind of combo we love!",{"data":1654,"content":1655,"nodeType":1400},{},[],{"data":1657,"content":1658,"nodeType":1408},{},[1659],{"data":1660,"marks":1661,"value":1662,"nodeType":1293},{},[],"Blocking AitM phishing and cloned login pages",{"data":1664,"content":1665,"nodeType":1484},{},[1666],{"data":1667,"marks":1668,"value":1479,"nodeType":1293},{},[1669],{"type":1460},{"data":1671,"content":1672,"nodeType":1294},{},[1673],{"data":1674,"marks":1675,"value":1676,"nodeType":1293},{},[],"When you’re able to detect SSO passwords being used in all the wrong places, it’s not surprising that one of the main offenders is phishing attacks. ",{"data":1678,"content":1679,"nodeType":1294},{},[1680,1684,1693],{"data":1681,"marks":1682,"value":1683,"nodeType":1293},{},[],"In 2024, we wrote extensively about the rise in ",{"data":1685,"content":1687,"nodeType":1384},{"uri":1686},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[1688],{"data":1689,"marks":1690,"value":1692,"nodeType":1293},{},[1691],{"type":1382},"modern phishing attacks",{"data":1694,"marks":1695,"value":1696,"nodeType":1293},{},[]," that use adversary-in-the middle toolkits (AiTM), including EvilNoVNC, Evilginx, and others.",{"data":1698,"content":1699,"nodeType":1294},{},[1700,1704,1713],{"data":1701,"marks":1702,"value":1703,"nodeType":1293},{},[],"AiTM phishing is a newer variant of phishing that allows attackers to bypass MFA protection by using tools that act as a proxy between the end-user and a legitimate login portal. AitM attacks increased 146% in 2023 (",{"data":1705,"content":1707,"nodeType":1384},{"uri":1706},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf",[1708],{"data":1709,"marks":1710,"value":1712,"nodeType":1293},{},[1711],{"type":1382},"Microsoft",{"data":1714,"marks":1715,"value":1716,"nodeType":1293},{},[],").",{"data":1718,"content":1719,"nodeType":1294},{},[1720],{"data":1721,"marks":1722,"value":1723,"nodeType":1293},{},[],"This trend in tradecraft was reflected in our own customer base last year, but what’s interesting is that we observed a lot of phish kits and tactics that were new — meaning traditional detections failed to find them before Push did. ",{"data":1725,"content":1726,"nodeType":1294},{},[1727,1731,1740],{"data":1728,"marks":1729,"value":1730,"nodeType":1293},{},[],"In particular, we saw newer ",{"data":1732,"content":1734,"nodeType":1384},{"uri":1733},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection/",[1735],{"data":1736,"marks":1737,"value":1739,"nodeType":1293},{},[1738],{"type":1382},"web-based obfuscation techniques",{"data":1741,"marks":1742,"value":1743,"nodeType":1293},{},[]," that allowed attackers to get past the features of email security tools like web gateways and email scanning appliances, such as bypassing web sandbox analysis, and deter other forms of automated investigation by using Cloudflare Turnstile and other tactics — similar to the approaches legit websites use to protect against automated bots (this is essentially the same problem for both).",{"data":1745,"content":1746,"nodeType":1294},{},[1747],{"data":1748,"marks":1749,"value":1750,"nodeType":1293},{},[],"The gap in existing controls was obvious: When all phishing routes eventually lead to the browser, security teams need to be able to detect and respond in the browser. To do this well they need to observe what the employee sees, not what loads in a sandbox.",{"data":1752,"content":1753,"nodeType":1484},{},[1754],{"data":1755,"marks":1756,"value":1555,"nodeType":1293},{},[1757],{"type":1460},{"data":1759,"content":1760,"nodeType":1294},{},[1761,1765,1775,1780],{"data":1762,"marks":1763,"value":1764,"nodeType":1293},{},[],"To address this gap, we released new capabilities for the Push browser agent to be able to ",{"data":1766,"content":1768,"nodeType":1384},{"uri":1767},"https://pushsecurity.com/blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser/",[1769],{"data":1770,"marks":1771,"value":1774,"nodeType":1293},{},[1772,1773],{"type":1382},{"type":1460},"detect and block",{"data":1776,"marks":1777,"value":1779,"nodeType":1293},{},[1778],{"type":1460}," when a site is running AiTM phishing toolkits",{"data":1781,"marks":1782,"value":1783,"nodeType":1293},{},[],". ",{"data":1785,"content":1786,"nodeType":1294},{},[1787],{"data":1788,"marks":1789,"value":1790,"nodeType":1293},{},[],"Push does this via a set of readymade detections for common AiTM tools. By dynamically analyzing the behavior of malware in the browser, the Push browser agent can find indicators of compromise beyond just domains, file names, IP addresses, etc., focusing instead on behavioral attributes, such as Javascript calls being made or data structures saved to local storage.",{"data":1792,"content":1793,"nodeType":1294},{},[1794,1798,1807],{"data":1795,"marks":1796,"value":1797,"nodeType":1293},{},[],"This approach of focusing on the top of the ",{"data":1799,"content":1801,"nodeType":1384},{"uri":1800},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/#id-building-effective-identity-threat-detection-controls_id-scenario-detecting-a-web-based-phishing-attack",[1802],{"data":1803,"marks":1804,"value":1806,"nodeType":1293},{},[1805],{"type":1382},"Pyramid of Pain",{"data":1808,"marks":1809,"value":1810,"nodeType":1293},{},[]," — e.g. building detections for attributes of an attack that are the hardest for attackers to change, and therefore the most reliably accurate — is core to Push’s design philosophy. ",{"data":1812,"content":1813,"nodeType":1294},{},[1814,1818,1828],{"data":1815,"marks":1816,"value":1817,"nodeType":1293},{},[],"Finally, toward the second half of the year, we released ",{"data":1819,"content":1821,"nodeType":1384},{"uri":1820},"https://pushsecurity.com/blog/introducing-cloned-login-page-detection/",[1822],{"data":1823,"marks":1824,"value":1827,"nodeType":1293},{},[1825,1826],{"type":1382},{"type":1460},"cloned login page detection",{"data":1829,"marks":1830,"value":1831,"nodeType":1293},{},[],", a natural extension of our layered approach to preventing phishing attacks in the browser. With this security control, you can identify malicious webpages that are masquerading as legitimate IdP login portals. ",{"data":1833,"content":1837,"nodeType":1520},{"target":1834},{"sys":1835},{"id":1836,"type":1517,"linkType":1518},"4y25OxesssUk9lzEx12HFa",[],{"data":1839,"content":1840,"nodeType":1294},{},[1841],{"data":1842,"marks":1843,"value":1844,"nodeType":1293},{},[],"When a cloned login page is detected, you can add the URL to your blocklist in Push and prevent any other employees from being targeted. ",{"data":1846,"content":1847,"nodeType":1294},{},[1848,1852,1861],{"data":1849,"marks":1850,"value":1851,"nodeType":1293},{},[],"By layering multiple anti-phishing controls that all prevent account takeover, defenders have the best chance at thwarting the ",{"data":1853,"content":1855,"nodeType":1384},{"uri":1854},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[1856],{"data":1857,"marks":1858,"value":1860,"nodeType":1293},{},[1859],{"type":1382},"short, fast attack chains",{"data":1862,"marks":1863,"value":1864,"nodeType":1293},{},[]," that are emblematic of today’s identity attacks.",{"data":1866,"content":1867,"nodeType":1400},{},[],{"data":1869,"content":1870,"nodeType":1408},{},[1871],{"data":1872,"marks":1873,"value":1874,"nodeType":1293},{},[],"Defending against stolen sessions and stolen credentials",{"data":1876,"content":1877,"nodeType":1294},{},[1878,1882,1891],{"data":1879,"marks":1880,"value":1881,"nodeType":1293},{},[],"With as little as $10 to buy a stolen password and a little skill, attackers capitalized on the use of stolen credentials last year. Stolen creds were the No. 1 attacker action in 2023 and 2024, according to ",{"data":1883,"content":1885,"nodeType":1384},{"uri":1884},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[1886],{"data":1887,"marks":1888,"value":1890,"nodeType":1293},{},[1889],{"type":1382},"Verizon",{"data":1892,"marks":1893,"value":1894,"nodeType":1293},{},[],".",{"data":1896,"content":1897,"nodeType":1294},{},[1898,1902,1911],{"data":1899,"marks":1900,"value":1901,"nodeType":1293},{},[],"Nowhere was this more plain than in the ",{"data":1903,"content":1905,"nodeType":1384},{"uri":1904},"https://pushsecurity.com/blog/snowflake-retro/",[1906],{"data":1907,"marks":1908,"value":1910,"nodeType":1293},{},[1909],{"type":1382},"attacks on Snowflake customers",{"data":1912,"marks":1913,"value":1914,"nodeType":1293},{},[],", one of the biggest breaches of last year. In this incident, cyber criminals targeted around 165 customers of the cloud-based data warehouse tool Snowflake by taking over accounts using credentials harvested from infostealer infections dating as far back as 2020.",{"data":1916,"content":1917,"nodeType":1294},{},[1918],{"data":1919,"marks":1920,"value":1921,"nodeType":1293},{},[],"The Snowflake incident underscored the challenges of control and visibility that security teams face when attempting to secure identities on a patchwork of managed and unmanaged apps:",{"data":1923,"content":1924,"nodeType":1389},{},[1925,1935,1945,1955,1965],{"data":1926,"content":1927,"nodeType":1353},{},[1928],{"data":1929,"content":1930,"nodeType":1294},{},[1931],{"data":1932,"marks":1933,"value":1934,"nodeType":1293},{},[],"Do I know all the workforce accounts my employees use?",{"data":1936,"content":1937,"nodeType":1353},{},[1938],{"data":1939,"content":1940,"nodeType":1294},{},[1941],{"data":1942,"marks":1943,"value":1944,"nodeType":1293},{},[],"Do those accounts have a strong security posture?",{"data":1946,"content":1947,"nodeType":1353},{},[1948],{"data":1949,"content":1950,"nodeType":1294},{},[1951],{"data":1952,"marks":1953,"value":1954,"nodeType":1293},{},[],"Do those accounts use MFA? The most phishing-resistant methods?",{"data":1956,"content":1957,"nodeType":1353},{},[1958],{"data":1959,"content":1960,"nodeType":1294},{},[1961],{"data":1962,"marks":1963,"value":1964,"nodeType":1293},{},[],"Do I have tools to detect, respond, and remediate after an account takeover or breach of a critical software vendor?",{"data":1966,"content":1967,"nodeType":1353},{},[1968],{"data":1969,"content":1970,"nodeType":1294},{},[1971],{"data":1972,"marks":1973,"value":1974,"nodeType":1293},{},[],"Do I know when a session has been stolen, pointing to a device compromised by infostealer malware?",{"data":1976,"content":1977,"nodeType":1294},{},[1978],{"data":1979,"marks":1980,"value":1981,"nodeType":1293},{},[],"Here’s what we delivered last year to make it easier for security teams to protect their organizations from the threat of stolen sessions and stolen creds.",{"data":1983,"content":1984,"nodeType":1400},{},[],{"data":1986,"content":1987,"nodeType":1408},{},[1988],{"data":1989,"marks":1990,"value":1991,"nodeType":1293},{},[],"Detecting stolen sessions",{"data":1993,"content":1994,"nodeType":1484},{},[1995],{"data":1996,"marks":1997,"value":1479,"nodeType":1293},{},[1998],{"type":1460},{"data":2000,"content":2001,"nodeType":1294},{},[2002,2005,2014],{"data":2003,"marks":2004,"value":37,"nodeType":1293},{},[],{"data":2006,"content":2008,"nodeType":1384},{"uri":2007},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/",[2009],{"data":2010,"marks":2011,"value":2013,"nodeType":1293},{},[2012],{"type":1382},"Infostealer malware",{"data":2015,"marks":2016,"value":2017,"nodeType":1293},{},[]," — a type of malware designed to collect user credentials, including session cookies, from end-user devices — had a very successful 2024, accounting for nearly 10 percent of activity that Red Canary was able to associate with named threats, and the majority of all detected malware that Sophos threat researchers documented last year.",{"data":2019,"content":2020,"nodeType":1294},{},[2021,2025,2034],{"data":2022,"marks":2023,"value":2024,"nodeType":1293},{},[],"While the use of stolen credentials is rampant, often facilitated by successful infostealer campaigns, a related attack type also ",{"data":2026,"content":2028,"nodeType":1384},{"uri":2027},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/#id-the-state-of-infostealers-today",[2029],{"data":2030,"marks":2031,"value":2033,"nodeType":1293},{},[2032],{"type":1382},"jumped in prevalence",{"data":2035,"marks":2036,"value":2037,"nodeType":1293},{},[]," last year: session token theft attacks.",{"data":2039,"content":2040,"nodeType":1294},{},[2041],{"data":2042,"marks":2043,"value":2044,"nodeType":1293},{},[],"Using stolen tokens, adversaries don’t need to bypass MFA directly. They can simply import the tokens into their browser and assume an already authorized session. ",{"data":2046,"content":2047,"nodeType":1484},{},[2048],{"data":2049,"marks":2050,"value":1555,"nodeType":1293},{},[2051],{"type":1460},{"data":2053,"content":2054,"nodeType":1294},{},[2055],{"data":2056,"marks":2057,"value":2058,"nodeType":1293},{},[],"In order to detect a stolen session in use, you need telemetry that allows you to tie activity to a trusted endpoint. This didn’t previously exist, and you have to be in the browser to do it. So that’s what we built. ",{"data":2060,"content":2061,"nodeType":1294},{},[2062,2066,2076],{"data":2063,"marks":2064,"value":2065,"nodeType":1293},{},[],"Push’s ",{"data":2067,"content":2069,"nodeType":1384},{"uri":2068},"https://pushsecurity.com/blog/introducing-session-token-theft-detection-why-browser-is-best/",[2070],{"data":2071,"marks":2072,"value":2075,"nodeType":1293},{},[2073,2074],{"type":1382},{"type":1460},"session theft detection",{"data":2077,"marks":2078,"value":2079,"nodeType":1293},{},[]," capability uses the power of the Push browser extension to inject a unique marker into the user-agent string of sessions that occur in browsers enrolled in Push. ",{"data":2081,"content":2082,"nodeType":1294},{},[2083],{"data":2084,"marks":2085,"value":2086,"nodeType":1293},{},[],"By analyzing logs from your IdP in your SIEM, you can then identify activity from the same session that both has and that lacks the Push marker, indicating that a session has been extracted from the browser and maliciously imported into a different browser that is not enrolled in Push.",{"data":2088,"content":2089,"nodeType":1294},{},[2090],{"data":2091,"marks":2092,"value":2093,"nodeType":1293},{},[],"This is a reliable signal that a stolen session token is being used and an endpoint has been compromised.",{"data":2095,"content":2099,"nodeType":1520},{"target":2096},{"sys":2097},{"id":2098,"type":1517,"linkType":1518},"1XNNkaoW64t3PPvC54KGXF",[],{"data":2101,"content":2105,"nodeType":1520},{"target":2102},{"sys":2103},{"id":2104,"type":1517,"linkType":1518},"6dOEnPzZXd9DqeSdalqlzO",[],{"data":2107,"content":2108,"nodeType":1400},{},[],{"data":2110,"content":2111,"nodeType":1408},{},[2112],{"data":2113,"marks":2114,"value":2115,"nodeType":1293},{},[],"Detecting compromised credentials",{"data":2117,"content":2118,"nodeType":1484},{},[2119],{"data":2120,"marks":2121,"value":1479,"nodeType":1293},{},[2122],{"type":1460},{"data":2124,"content":2125,"nodeType":1294},{},[2126],{"data":2127,"marks":2128,"value":2129,"nodeType":1293},{},[],"Alongside stolen session cookies, stolen credentials made a lot of headlines last year. The 2024 Verizon DBIR found that 79% of web application compromises were the result of breached creds, and researchers at IBM found a 71% year-over-year increase in cyberattacks using stolen or compromised credentials.",{"data":2131,"content":2132,"nodeType":1294},{},[2133,2137,2146],{"data":2134,"marks":2135,"value":2136,"nodeType":1293},{},[],"In Push’s own research, we counted ",{"data":2138,"content":2140,"nodeType":1384},{"uri":2139},"https://pushsecurity.com/blog/2024-identity-breaches/",[2141],{"data":2142,"marks":2143,"value":2145,"nodeType":1293},{},[2144],{"type":1382},"30 public identity-related breaches",{"data":2147,"marks":2148,"value":2149,"nodeType":1293},{},[]," in 2024 where the breach and the breach vector were disclosed. Of those, nearly three-quarters were the result of compromised credentials, including notable breaches such as Microsoft, Change Healthcare, and the attacks on Snowflake customers.",{"data":2151,"content":2152,"nodeType":2160},{},[2153],{"data":2154,"content":2155,"nodeType":1294},{},[2156],{"data":2157,"marks":2158,"value":2159,"nodeType":1293},{},[],"73% of public identity-related breaches in 2024 were the result of compromised credentials (the rest were phishing attacks). ","blockquote",{"data":2162,"content":2163,"nodeType":1294},{},[2164,2168,2176],{"data":2165,"marks":2166,"value":2167,"nodeType":1293},{},[],"The influx of compromised credentials has been amplified by the ",{"data":2169,"content":2170,"nodeType":1384},{"uri":2007},[2171],{"data":2172,"marks":2173,"value":2175,"nodeType":1293},{},[2174],{"type":1382},"rise of infostealers",{"data":2177,"marks":2178,"value":2179,"nodeType":1293},{},[],", which contribute the vast majority of valid stolen credentials, alongside mass credential phishing campaigns and third-party data breach dumps. ",{"data":2181,"content":2182,"nodeType":1294},{},[2183],{"data":2184,"marks":2185,"value":2186,"nodeType":1293},{},[],"And while there’s no shortage of threat intelligence about stolen credentials for sale on the web, security teams struggle to separate the needle from the haystack because a large portion of TI on stolen creds is out of date.",{"data":2188,"content":2189,"nodeType":1294},{},[2190],{"data":2191,"marks":2192,"value":2193,"nodeType":1293},{},[],"In evaluating TI data here at Push, we reviewed 5,763 username and password combos that matched domains in use by Push customers. We found that less than 1% of the creds in a multi-vendor dataset were true positives. In other words, 99.5% of the stolen creds we checked were false positives at the time of review — illustrating the challenge security teams face when trying to extract actionable intelligence from this kind of data. ",{"data":2195,"content":2196,"nodeType":2160},{},[2197],{"data":2198,"content":2199,"nodeType":1294},{},[2200],{"data":2201,"marks":2202,"value":2203,"nodeType":1293},{},[],"99.5% of the findings in compromised credential feeds were found to be false positives.",{"data":2205,"content":2206,"nodeType":1484},{},[2207],{"data":2208,"marks":2209,"value":1555,"nodeType":1293},{},[2210],{"type":1460},{"data":2212,"content":2213,"nodeType":1294},{},[2214],{"data":2215,"marks":2216,"value":2217,"nodeType":1293},{},[],"Using its browser agent, Push assesses the strength of end-user passwords by creating and analyzing a truncated, salted SHA256 hash of the password for a given account. (These k-anonymized fingerprints are never seen by Push’s back-end and exist only in local browser extension storage.) ",{"data":2219,"content":2220,"nodeType":1294},{},[2221,2225,2235],{"data":2222,"marks":2223,"value":2224,"nodeType":1293},{},[],"These fingerprints give Push a directly observable source of truth for corporate creds, which allowed us to build a ",{"data":2226,"content":2228,"nodeType":1384},{"uri":2227},"https://pushsecurity.com/blog/verified-stolen-credential-detection/",[2229],{"data":2230,"marks":2231,"value":2234,"nodeType":1293},{},[2232,2233],{"type":1382},{"type":1460},"verified stolen credential detection",{"data":2236,"marks":2237,"value":2238,"nodeType":1293},{},[]," capability last year that removes all false positives from TI sources to pinpoint only those stolen creds still actively in use by employees.",{"data":2240,"content":2244,"nodeType":1520},{"target":2241},{"sys":2242},{"id":2243,"type":1517,"linkType":1518},"3BITHZvDadjHpOAqIn0g4w",[],{"data":2246,"content":2247,"nodeType":1400},{},[],{"data":2249,"content":2250,"nodeType":1408},{},[2251],{"data":2252,"marks":2253,"value":2254,"nodeType":1293},{},[],"Reducing and securing shadow IT and account sprawl",{"data":2256,"content":2257,"nodeType":1294},{},[2258],{"data":2259,"marks":2260,"value":2261,"nodeType":1293},{},[],"You can think of this last part of the story as the ground from which the attack trends we’ve been talking about emerged: The shift to doing business almost entirely in the browser, and the resulting sprawl in accounts and unmanaged apps, leading to an explosion of internet-facing identities for threat actors to target.",{"data":2263,"content":2264,"nodeType":1294},{},[2265],{"data":2266,"marks":2267,"value":2268,"nodeType":1293},{},[],"Even in organizations with mature security practices, the challenge of getting 100% compliance with identity posture best practices is evident. Last year, Push researchers analyzed a data set of 300,000 accounts from our customer base and found that:",{"data":2270,"content":2271,"nodeType":1389},{},[2272,2291,2310],{"data":2273,"content":2274,"nodeType":1353},{},[2275],{"data":2276,"content":2277,"nodeType":1294},{},[2278,2282,2287],{"data":2279,"marks":2280,"value":2281,"nodeType":1293},{},[],"Organizations have ",{"data":2283,"marks":2284,"value":2286,"nodeType":1293},{},[2285],{"type":1460},"more apps and identities than they thought",{"data":2288,"marks":2289,"value":2290,"nodeType":1293},{},[]," — an average of ~15 identities per employee and ~220 apps per organization.",{"data":2292,"content":2293,"nodeType":1353},{},[2294],{"data":2295,"content":2296,"nodeType":1294},{},[2297,2301,2306],{"data":2298,"marks":2299,"value":2300,"nodeType":1293},{},[],"Many accounts ",{"data":2302,"marks":2303,"value":2305,"nodeType":1293},{},[2304],{"type":1460},"lack basic security protections",{"data":2307,"marks":2308,"value":2309,"nodeType":1293},{},[],", with 37% of accounts lacking any form of MFA and ~9% of accounts using a password that is leaked, weak, or reused, making them especially susceptible to account takeover. On accounts where password is the only login method in use (e.g. not using SSO or any other federated login like OIDC), there was no MFA in use in 4 out of 5 cases.",{"data":2311,"content":2312,"nodeType":1353},{},[2313],{"data":2314,"content":2315,"nodeType":1294},{},[2316,2320,2325,2329,2338],{"data":2317,"marks":2318,"value":2319,"nodeType":1293},{},[],"Security ",{"data":2321,"marks":2322,"value":2324,"nodeType":1293},{},[2323],{"type":1460},"gaps persist even with SSO",{"data":2326,"marks":2327,"value":2328,"nodeType":1293},{},[]," accounts — with 10% of SSO-using accounts also having a local password, a risk for ",{"data":2330,"content":2332,"nodeType":1384},{"uri":2331},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/",[2333],{"data":2334,"marks":2335,"value":2337,"nodeType":1293},{},[2336],{"type":1382},"ghost logins",{"data":2339,"marks":2340,"value":2341,"nodeType":1293},{},[],"; and 1 in 5 IdP accounts themselves missing MFA.",{"data":2343,"content":2344,"nodeType":1294},{},[2345],{"data":2346,"marks":2347,"value":2348,"nodeType":1293},{},[],"From our perspective, organizations need scalable controls, and they need easy-to-deploy tools that get them visibility of all their workforce identities, apps, and accounts alongside telemetry that makes the information actionable.",{"data":2350,"content":2351,"nodeType":1294},{},[2352],{"data":2353,"marks":2354,"value":2355,"nodeType":1293},{},[],"Push already provides a real-time inventory of all your accounts and apps, including internal corporate apps, and analyzes the security posture, login methods, and MFA status of those accounts to offer a comprehensive picture of your identity attack surface. ",{"data":2357,"content":2358,"nodeType":1294},{},[2359],{"data":2360,"marks":2361,"value":2362,"nodeType":1293},{},[],"To help customers enforce their security policies even more seamlessly, here’s what we built last year:",{"data":2364,"content":2365,"nodeType":1484},{},[2366],{"data":2367,"marks":2368,"value":2370,"nodeType":1293},{},[2369],{"type":1460},"1. App banners",{"data":2372,"content":2373,"nodeType":1294},{},[2374,2378,2388],{"data":2375,"marks":2376,"value":2377,"nodeType":1293},{},[],"With a range of modes from informing to blocking, ",{"data":2379,"content":2381,"nodeType":1384},{"uri":2380},"https://pushsecurity.com/help/10106#start",[2382],{"data":2383,"marks":2384,"value":2387,"nodeType":1293},{},[2385,2386],{"type":1382},{"type":1460},"app banners",{"data":2389,"marks":2390,"value":2391,"nodeType":1293},{},[]," allow security teams to communicate best practices and policies with end-users directly in their browser. It works by displaying a banner with your custom message on the login and signup pages for workplace apps. ",{"data":2393,"content":2394,"nodeType":1294},{},[2395],{"data":2396,"marks":2397,"value":2398,"nodeType":1293},{},[],"Using configuration rules, you can set conditions for how banner controls get applied. Common use cases include: Restricting use of GenAI software; carving out an exception for admins on a specific app; reminding users to log in with SSO instead of a password, and others. ",{"data":2400,"content":2404,"nodeType":1520},{"target":2401},{"sys":2402},{"id":2403,"type":1517,"linkType":1518},"4RPHmeMLyZmb5V8rXYLtey",[],{"data":2406,"content":2407,"nodeType":1484},{},[2408,2413],{"data":2409,"marks":2410,"value":2412,"nodeType":1293},{},[2411],{"type":1460},"2. Password manager identification",{"data":2414,"marks":2415,"value":1483,"nodeType":1293},{},[],{"data":2417,"content":2418,"nodeType":1294},{},[2419,2423,2433],{"data":2420,"marks":2421,"value":2422,"nodeType":1293},{},[],"We also expanded Push’s capability to observe employees’ account security posture by adding an identification of ",{"data":2424,"content":2426,"nodeType":1384},{"uri":2425},"https://pushsecurity.com/blog/stop-users-saving-corp-creds-into-personal-password-managers/",[2427],{"data":2428,"marks":2429,"value":2432,"nodeType":1293},{},[2430,2431],{"type":1382},{"type":1460},"which password manager",{"data":2434,"marks":2435,"value":2436,"nodeType":1293},{},[]," (if any) they’re using. ",{"data":2438,"content":2439,"nodeType":1294},{},[2440],{"data":2441,"marks":2442,"value":2443,"nodeType":1293},{},[],"We’ve heard from many security teams that they’re concerned about corporate credentials being stored in unapproved password managers — not to mention the ROI from ensuring employees are all using the corporate password manager you already pay for. This feature helps them achieve both objectives.",{"data":2445,"content":2446,"nodeType":1484},{},[2447],{"data":2448,"marks":2449,"value":2451,"nodeType":1293},{},[2450],{"type":1460},"3. MFA enforcement",{"data":2453,"content":2454,"nodeType":1294},{},[2455,2459,2469],{"data":2456,"marks":2457,"value":2458,"nodeType":1293},{},[],"Finally, we rounded out 2024 with a new security control called ",{"data":2460,"content":2462,"nodeType":1384},{"uri":2461},"https://pushsecurity.com/blog/enforce-mfa-on-third-party-apps/",[2463],{"data":2464,"marks":2465,"value":2468,"nodeType":1293},{},[2466,2467],{"type":1382},{"type":1460},"MFA enforcement",{"data":2470,"marks":2471,"value":2472,"nodeType":1293},{},[]," that builds on the popular app banners concept by detecting when users lack MFA and then prompting them to register for MFA. ",{"data":2474,"content":2475,"nodeType":1294},{},[2476],{"data":2477,"marks":2478,"value":2479,"nodeType":1293},{},[],"Admins choose which apps they wish to enforce MFA on, and the Push extension does the rest. ",{"data":2481,"content":2482,"nodeType":1294},{},[2483],{"data":2484,"marks":2485,"value":2486,"nodeType":1293},{},[],"Security teams we work with are especially eager to use this feature to close MFA coverage gaps on non-SSO and otherwise unmanaged applications.",{"data":2488,"content":2492,"nodeType":1520},{"target":2489},{"sys":2490},{"id":2491,"type":1517,"linkType":1518},"4imhff7SWJi2Gan5iFEs2P",[],{"data":2494,"content":2495,"nodeType":1400},{},[],{"data":2497,"content":2498,"nodeType":1408},{},[2499],{"data":2500,"marks":2501,"value":2502,"nodeType":1293},{},[],"Want to see more?",{"data":2504,"content":2505,"nodeType":1294},{},[2506,2510,2518],{"data":2507,"marks":2508,"value":2509,"nodeType":1293},{},[],"There’s a lot we didn’t touch on here that Push can help you achieve. If you’d like to learn more, ",{"data":2511,"content":2513,"nodeType":1384},{"uri":2512},"https://pushsecurity.com/demo/",[2514],{"data":2515,"marks":2516,"value":2517,"nodeType":1293},{},[],"set up a demo with our team",{"data":2519,"marks":2520,"value":2521,"nodeType":1293},{},[]," or sign up yourself to have a look at the platform.","How real-world attacks and research drove Push’s most popular features of 2024","How in-the-wild attacks and our own R&D inspired what we built in 2024 to stop account takeover and reduce security risks across your workforce identities. ","2025-01-16T00:00:00.000Z","push-features-2024",{"items":2527},[2528,2530],{"sys":2529,"name":1313},{"id":1312},{"sys":2531,"name":1309},{"id":1308},{"items":2533},[2534],{"fullName":2535,"firstName":2536,"jobTitle":2537,"profilePicture":2538},"Kelly Davenport","Kelly","Product Team",{"url":2539},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1317,"sys":2541,"content":2543,"title":3163,"synopsis":3164,"hashTags":118,"publishedDate":3165,"slug":3166,"tagsCollection":3167,"authorsCollection":3173},{"id":2542},"1pJdOGN0dOd3BKVqO4CxHh",{"json":2544},{"nodeType":1295,"data":2545,"content":2546},{},[2547,2554,2561,2568,2587,2594,2601,2604,2612,2619,2626,2633,2639,2646,2649,2657,2664,2671,2678,2685,2691,2698,2701,2709,2717,2724,2731,2738,2758,2766,2773,2780,2787,2794,2802,2809,2816,2822,2825,2833,2840,2847,2854,2861,2868,2871,2879,2886,2893,2900,2907,2914,3023,3039,3046,3052,3055,3063,3070,3137,3144],{"nodeType":1294,"data":2548,"content":2549},{},[2550],{"nodeType":1293,"value":2551,"marks":2552,"data":2553},"2024 was an unprecedented year in terms of the impact of identity-based attacks. Or that’s what it felt like anyway, so I decided to trawl through a year of news to see if reality stacked up. ",[],{},{"nodeType":1294,"data":2555,"content":2556},{},[2557],{"nodeType":1293,"value":2558,"marks":2559,"data":2560},"My main obstacles here were the ever-disappointing levels of public information disclosure for cyber breaches. Even where breaches are disclosed, it’s rare that any public information contains the nature of the initial access vector (though I can’t say I’m surprised — it’s hard to argue the ‘highly sophisticated’ nature of a breach that involved stolen credentials and no MFA). ",[],{},{"nodeType":1294,"data":2562,"content":2563},{},[2564],{"nodeType":1293,"value":2565,"marks":2566,"data":2567},"Publicly disclosed breaches are just the tip of the iceberg, and with the rise in data theft and extortion over more disruptive attacks (e.g. ransomware), there is often no obvious service interruption indicating that an incident has taken place. This makes it more likely that these situations can be settled quietly or smoothed over, without hitting the headlines. ",[],{},{"nodeType":1294,"data":2569,"content":2570},{},[2571,2575,2584],{"nodeType":1293,"value":2572,"marks":2573,"data":2574},"That said, the requirement that US companies submit a Form-8K for breaches of a material nature does appear to have increased the number of voluntary declarations (inside the US, at least) and the growing willingness of the SEC to prosecute negligent or misleading behavior is also a considerable motivator, such as ",[],{},{"nodeType":1384,"data":2576,"content":2578},{"uri":2577},"https://www.bleepingcomputer.com/news/security/sec-charges-tech-companies-for-downplaying-solarwinds-breaches/",[2579],{"nodeType":1293,"value":2580,"marks":2581,"data":2583},"the recent prosecution of companies for misleading investors about the impact of the 2020 SolarWinds Orion hack",[2582],{"type":1382},{},{"nodeType":1293,"value":1894,"marks":2585,"data":2586},[],{},{"nodeType":1294,"data":2588,"content":2589},{},[2590],{"nodeType":1293,"value":2591,"marks":2592,"data":2593},"Despite all this, I totalled 30 breaches that were the result of an identity-based initial access vector, such as phishing, credential stuffing, social engineering, session hijacking, etc. To make the list, it had to have appeared in the public domain, confirmed by the victim or an authoritative source, and the breach vector had to have been named. ",[],{},{"nodeType":1294,"data":2595,"content":2596},{},[2597],{"nodeType":1293,"value":2598,"marks":2599,"data":2600},"Public identity-related breaches in 2024 resulted in hundreds of millions of breached customer records (with the final impact of many still yet to appear in the public domain).",[],{},{"nodeType":1400,"data":2602,"content":2603},{},[],{"nodeType":1408,"data":2605,"content":2606},{},[2607],{"nodeType":1293,"value":2608,"marks":2609,"data":2611},"What is an identity attack?",[2610],{"type":1460},{},{"nodeType":1294,"data":2613,"content":2614},{},[2615],{"nodeType":1293,"value":2616,"marks":2617,"data":2618},"First, what do we mean by identity attack? ",[],{},{"nodeType":1294,"data":2620,"content":2621},{},[2622],{"nodeType":1293,"value":2623,"marks":2624,"data":2625},"An identity attack is any attack (regardless of the steps that follow) involving identity-based techniques, such as phishing, credential stuffing, and session hijacking, to log into an account/service. Basically, where identity is the initial breach vector.",[],{},{"nodeType":1294,"data":2627,"content":2628},{},[2629],{"nodeType":1293,"value":2630,"marks":2631,"data":2632},"The length and complexity of the overall attack chain will vary. For example, a SaaS-based account takeover where the attacker logs in and dumps the data from the app is naturally going to be more direct than a scenario in which an identity-based compromise leads to the takeover of an endpoint or device in a traditional networking environment. ",[],{},{"nodeType":1520,"data":2634,"content":2638},{"target":2635},{"sys":2636},{"id":2637,"type":1517,"linkType":1518},"SCbhb6dzXnaKUianhgLEL",[],{"nodeType":1294,"data":2640,"content":2641},{},[2642],{"nodeType":1293,"value":2643,"marks":2644,"data":2645},"In 2024, we’ve seen examples of both SaaS-based account takeover as well as identity attacks being used for initial access to more traditional networks, often resulting in ransomware deployment.",[],{},{"nodeType":1400,"data":2647,"content":2648},{},[],{"nodeType":1408,"data":2650,"content":2651},{},[2652],{"nodeType":1293,"value":2653,"marks":2654,"data":2656},"Breakdown of public identity breaches in 2024",[2655],{"type":1460},{},{"nodeType":1294,"data":2658,"content":2659},{},[2660],{"nodeType":1293,"value":2661,"marks":2662,"data":2663},"It’s always tricky to gauge the impact of a cyber breach, particularly when considering the limited information typically shared. Different types of breach are easier to assess than others — for example, any breach involving extortion/ransom payment has a clear cost associated. Regulator fines and penalties are also clear cut. But aside from these, you’re looking at the extent of any disruption/downtime, recovery costs, and the like. Long term, indirect impacts such as the loss of customer confidence are naturally tricky to estimate. ",[],{},{"nodeType":1294,"data":2665,"content":2666},{},[2667],{"nodeType":1293,"value":2668,"marks":2669,"data":2670},"However, many identity breaches don’t even have these metrics to go by. The general shift toward data theft only (as opposed to ransomware deployment) continued in 2024, and many of the public identity breaches reflect this. In these attacks, attackers steal data to extort a ransom payment, blackmail end-customers, and/or sell the data via underground criminal marketplaces. ",[],{},{"nodeType":1294,"data":2672,"content":2673},{},[2674],{"nodeType":1293,"value":2675,"marks":2676,"data":2677},"The one consistent metric we do have is the number of breached records, which is available in many (but not all) cases. Some organizations have attempted to calculate the financial impact per breached record. Most notably IBMs annual ‘Cost of a Data Breach’ report estimates the average data breach to cost $4.88m, and the cost per compromised record to be $169. But when applied to the sheer magnitude of 2024’s biggest attacks (in the region of hundreds of millions of breached records) the figures quickly reach unbelievable levels. ",[],{},{"nodeType":1294,"data":2679,"content":2680},{},[2681],{"nodeType":1293,"value":2682,"marks":2683,"data":2684},"All this is to say: It’s hard to pin down the relative impact of data breaches. But with the information available (profile of the victim organization, type of data impacted, number of customers impacted) it’s possible to provide a finger-in-the-air assessment — which is what I’ve attempted to do below. Here, we can see the overall month-by-month impact of public identity breaches, dated from when they were first reported (or using dates provided in said reports). ",[],{},{"nodeType":1520,"data":2686,"content":2690},{"target":2687},{"sys":2688},{"id":2689,"type":1517,"linkType":1518},"2XYuNqLuKhZbISb4II9IW4",[],{"nodeType":1294,"data":2692,"content":2693},{},[2694],{"nodeType":1293,"value":2695,"marks":2696,"data":2697},"Let’s take a closer look at the most notable breaches (and why they were especially significant). ",[],{},{"nodeType":1400,"data":2699,"content":2700},{},[],{"nodeType":1408,"data":2702,"content":2703},{},[2704],{"nodeType":1293,"value":2705,"marks":2706,"data":2708},"Top 3 public identity-related breaches in 2024",[2707],{"type":1460},{},{"nodeType":1484,"data":2710,"content":2711},{},[2712],{"nodeType":1293,"value":2713,"marks":2714,"data":2716},"#3: Microsoft — January 2024",[2715],{"type":1460},{},{"nodeType":1294,"data":2718,"content":2719},{},[2720],{"nodeType":1293,"value":2721,"marks":2722,"data":2723},"The threat group known as APT29, associated with the Russian SVR intelligence service, utilized password spray attacks that successfully compromised a non-production tenant account that did not have multi-factor authentication (MFA) enabled. They then leveraged this account to compromise a ‘test’ OAuth application that had elevated access to the Microsoft corporate environment. This was then used to access the email accounts of Microsoft employees. ",[],{},{"nodeType":1294,"data":2725,"content":2726},{},[2727],{"nodeType":1293,"value":2728,"marks":2729,"data":2730},"The attacks then continued throughout the year using information stolen from Microsoft mailboxes, with password spraying attacks increasing tenfold since the initial attack, resulting in the further compromise of source code repositories. ",[],{},{"nodeType":1294,"data":2732,"content":2733},{},[2734],{"nodeType":1293,"value":2735,"marks":2736,"data":2737},"Microsoft has shared limited information about the breach, but despite this it caused a significant stir. We can expect the number of email accounts compromised to be significant, given that it was later suggested that at least 100 external organizations had been contacted by Microsoft regarding their communications being breached (we only know this because 100-ish organizations reported the email as spam). The list of companies impacted included both public and private sector organizations, from major enterprises to government agencies in the US and other countries. ",[],{},{"nodeType":1294,"data":2739,"content":2740},{},[2741,2745,2754],{"nodeType":1293,"value":2742,"marks":2743,"data":2744},"Microsoft’s challenges with credential management didn’t end here either, ",[],{},{"nodeType":1384,"data":2746,"content":2748},{"uri":2747},"https://pushsecurity.com/blog/learning-from-the-servicenow-disclosure/",[2749],{"nodeType":1293,"value":2750,"marks":2751,"data":2753},"with bug bounty hunters able to use stolen credentials from a TI platform to breach Microsoft’s ServiceNow tenant",[2752],{"type":1382},{},{"nodeType":1293,"value":2755,"marks":2756,"data":2757},", accessing 1,000s of support ticket descriptions and attachments, and 250k+ employee emails.",[],{},{"nodeType":1484,"data":2759,"content":2760},{},[2761],{"nodeType":1293,"value":2762,"marks":2763,"data":2765},"#2: Change Healthcare — February 2024",[2764],{"type":1460},{},{"nodeType":1294,"data":2767,"content":2768},{},[2769],{"nodeType":1293,"value":2770,"marks":2771,"data":2772},"In February, attackers stole 6TB of data from UnitedHealth subsidiary Change Healthcare as part of a severe ransomware attack that caused massive disruption to the US healthcare industry. This impacted a wide range of critical services used by healthcare providers across the U.S., including payment processing, prescription writing, and insurance claims, and caused financial damages estimated at $872 million. The attack impacted the personal medical data of over 100M customers. ",[],{},{"nodeType":1294,"data":2774,"content":2775},{},[2776],{"nodeType":1293,"value":2777,"marks":2778,"data":2779},"The attacker used stolen credentials to breach the company's Citrix remote access service, which did not have multi-factor authentication enabled, as the initial breach vector for the attack. ",[],{},{"nodeType":1294,"data":2781,"content":2782},{},[2783],{"nodeType":1293,"value":2784,"marks":2785,"data":2786},"Following the attack, the organization's IT team replaced thousands of laptops, rotated credentials, and completely rebuilt Change Healthcare's data center network and core services.",[],{},{"nodeType":1294,"data":2788,"content":2789},{},[2790],{"nodeType":1293,"value":2791,"marks":2792,"data":2793},"The UnitedHealth Group admitted to paying a ransom demand to receive a decryptor and for the threat actors to delete the stolen data. The ransom payment was allegedly $22 million, according to the BlackCat ransomware affiliate who conducted the attack.",[],{},{"nodeType":1484,"data":2795,"content":2796},{},[2797],{"nodeType":1293,"value":2798,"marks":2799,"data":2801},"#1: Snowflake — April-June 2024",[2800],{"type":1460},{},{"nodeType":1294,"data":2803,"content":2804},{},[2805],{"nodeType":1293,"value":2806,"marks":2807,"data":2808},"165 organizations around the world were targeted using stolen credentials gathered from infostealer infections dating back to 2020. The impacted accounts lacked MFA, meaning successful authentication only required a valid username and password. As the Snowflake credentials found in infostealer malware credential dumps had not been rotated or updated, they remained valid and could be used to authenticate to user accounts on Snowflake tenants belonging to various customers. It has been touted by some news outlets as ‘one of the biggest breaches ever’. ",[],{},{"nodeType":1294,"data":2810,"content":2811},{},[2812],{"nodeType":1293,"value":2813,"marks":2814,"data":2815},"In total, nine public victims were named following the breach, collectively impacting hundreds of millions of their respective customers. Data was put up for sale on criminal forums for fees ranging from $150k to $2m per organization, while AT&T was also confirmed as paying an undisclosed ransom fee. ",[],{},{"nodeType":1520,"data":2817,"content":2821},{"target":2818},{"sys":2819},{"id":2820,"type":1517,"linkType":1518},"68txz4KkLmCX2hF9QySUZs",[],{"nodeType":1400,"data":2823,"content":2824},{},[],{"nodeType":1408,"data":2826,"content":2827},{},[2828],{"nodeType":1293,"value":2829,"marks":2830,"data":2832},"Identity attacks vs. other attacks in 2024",[2831],{"type":1460},{},{"nodeType":1294,"data":2834,"content":2835},{},[2836],{"nodeType":1293,"value":2837,"marks":2838,"data":2839},"In many ways, 2024 was a year of identity attacks. The attacks on Snowflake customers was unarguably one of (if not the most) significant cyber security event of the year (at least, if you exclude CrowdStrike causing a worldwide outage in July) — certainly, it was the largest perpetrated by a criminal group against commercial enterprises. ",[],{},{"nodeType":1294,"data":2841,"content":2842},{},[2843],{"nodeType":1293,"value":2844,"marks":2845,"data":2846},"Arguably the biggest non-identity story of the year was the Chinese state-sponsored “Salt Typhoon” campaign against global telecommunications firms, with at least nine major providers compromised — including AT&T, Verizon, and T-Mobile. The group reportedly focused on infiltrating telecommunications infrastructure to steal text messages, phone call information, and voicemails from targeted people. The threat actors also targeted the wiretapping platforms used by the US government, raising serious national security concerns.",[],{},{"nodeType":1294,"data":2848,"content":2849},{},[2850],{"nodeType":1293,"value":2851,"marks":2852,"data":2853},"Undoubtedly this was one of the biggest intelligence compromises in US history and is of major significance. But it’s also arguable that identity attacks had a more widespread commercial impact in 2024 when we look at the big picture.   ",[],{},{"nodeType":1294,"data":2855,"content":2856},{},[2857],{"nodeType":1293,"value":2858,"marks":2859,"data":2860},"Attacks on edge networking devices were also incredibly prominent, as were very much interlinked with the targeting of telecommunications infrastructure. A barrage of 0-days generated a huge amount of concern about the software security practices of many vendors. ",[],{},{"nodeType":1294,"data":2862,"content":2863},{},[2864],{"nodeType":1293,"value":2865,"marks":2866,"data":2867},"But despite these honorable mentions, the runaway threat of the year was an identity-based one… ",[],{},{"nodeType":1400,"data":2869,"content":2870},{},[],{"nodeType":1408,"data":2872,"content":2873},{},[2874],{"nodeType":1293,"value":2875,"marks":2876,"data":2878},"Threat of the year: Infostealers",[2877],{"type":1460},{},{"nodeType":1294,"data":2880,"content":2881},{},[2882],{"nodeType":1293,"value":2883,"marks":2884,"data":2885},"2024 saw an unprecedented rise in the role of infostealers. The played a huge role in the attacks on Snowflake customers, where 80% of the accounts were targeted using credentials found in infostealer infections. ",[],{},{"nodeType":1294,"data":2887,"content":2888},{},[2889],{"nodeType":1293,"value":2890,"marks":2891,"data":2892},"News relating to new infostealer variants and distributions campaigns came thick and fast in 2024, as attackers sought to harvest credentials from victims to use as part of their own malicious campaigns, or to sell on to other criminals on underground marketplaces for compromised credentials. Attackers leaned into alternative distribution channels, branching away from email-based campaigns to target victims via gaming forums, Facebook ads, and YouTube video descriptions. GitHub was also continuously targeted as a malware distribution mechanism throughout the year — and the majority of the time it was to push infostealers. ",[],{},{"nodeType":1294,"data":2894,"content":2895},{},[2896],{"nodeType":1293,"value":2897,"marks":2898,"data":2899},"Infostealers are the weapon of choice for attackers looking to harvest credentials at scale. Compared to credential harvesting phishing campaigns, infostealers target a much broader range of credentials, taking everything saved in the victim’s browser (and often also from local apps, including password managers).",[],{},{"nodeType":1294,"data":2901,"content":2902},{},[2903],{"nodeType":1293,"value":2904,"marks":2905,"data":2906},"Infostealers are nothing new, but have historically been seen as a problem affecting less secure personal devices and accounts. But 2024 has demonstrated that infostealers are finding ways to harvest business data — by finding ways around controls like EDR, and because of the ways that personal and business identities and accounts are converging in the modern workplace. For example, it’s not uncommon for employees to log into their personal Google account on their work device (and vice versa), inadvertently saving corporate credentials to their personal password store — which is later compromised through an infostealer infection on a personal device. ",[],{},{"nodeType":1294,"data":2908,"content":2909},{},[2910],{"nodeType":1293,"value":2911,"marks":2912,"data":2913},"The impact of infostealers (and the resulting stolen credentials and session cookies) is underlined by various figures:",[],{},{"nodeType":1389,"data":2915,"content":2916},{},[2917,2937,2959,2981,3001],{"nodeType":1353,"data":2918,"content":2919},{},[2920],{"nodeType":1294,"data":2921,"content":2922},{},[2923,2927,2934],{"nodeType":1293,"value":2924,"marks":2925,"data":2926},"79% of web application compromises were the result of breached credentials (",[],{},{"nodeType":1384,"data":2928,"content":2929},{"uri":1884},[2930],{"nodeType":1293,"value":1890,"marks":2931,"data":2933},[2932],{"type":1382},{},{"nodeType":1293,"value":1716,"marks":2935,"data":2936},[],{},{"nodeType":1353,"data":2938,"content":2939},{},[2940],{"nodeType":1294,"data":2941,"content":2942},{},[2943,2947,2956],{"nodeType":1293,"value":2944,"marks":2945,"data":2946},"Infostealer activity increased by 266% in 2023, while the number of attacks featuring valid credentials saw a 71% increase year-over-year (",[],{},{"nodeType":1384,"data":2948,"content":2950},{"uri":2949},"https://www.ibm.com/downloads/cas/L0GKXDWJ",[2951],{"nodeType":1293,"value":2952,"marks":2953,"data":2955},"IBM",[2954],{"type":1382},{},{"nodeType":1293,"value":1716,"marks":2957,"data":2958},[],{},{"nodeType":1353,"data":2960,"content":2961},{},[2962],{"nodeType":1294,"data":2963,"content":2964},{},[2965,2969,2978],{"nodeType":1293,"value":2966,"marks":2967,"data":2968},"Nearly half of the malware detected last year targeted victims’ data specifically, and the majority of that malware was classified as infostealers (",[],{},{"nodeType":1384,"data":2970,"content":2972},{"uri":2971},"https://news.sophos.com/en-us/2024/03/12/2024-sophos-threat-report/",[2973],{"nodeType":1293,"value":2974,"marks":2975,"data":2977},"Sophos",[2976],{"type":1382},{},{"nodeType":1293,"value":1716,"marks":2979,"data":2980},[],{},{"nodeType":1353,"data":2982,"content":2983},{},[2984],{"nodeType":1294,"data":2985,"content":2986},{},[2987,2991,2998],{"nodeType":1293,"value":2988,"marks":2989,"data":2990},"39,000 session token attacks are detected per day (",[],{},{"nodeType":1384,"data":2992,"content":2993},{"uri":1706},[2994],{"nodeType":1293,"value":1712,"marks":2995,"data":2997},[2996],{"type":1382},{},{"nodeType":1293,"value":1716,"marks":2999,"data":3000},[],{},{"nodeType":1353,"data":3002,"content":3003},{},[3004],{"nodeType":1294,"data":3005,"content":3006},{},[3007,3011,3020],{"nodeType":1293,"value":3008,"marks":3009,"data":3010},"Attacks on session cookies happen at the same rough order of magnitude as password-based attacks (",[],{},{"nodeType":1384,"data":3012,"content":3014},{"uri":3013},"https://github.com/WICG/dbsc/issues/13#issuecomment-1977657864",[3015],{"nodeType":1293,"value":3016,"marks":3017,"data":3019},"Google",[3018],{"type":1382},{},{"nodeType":1293,"value":1716,"marks":3021,"data":3022},[],{},{"nodeType":1294,"data":3024,"content":3025},{},[3026,3030,3035],{"nodeType":1293,"value":3027,"marks":3028,"data":3029},"And of the confirmed identity-based breaches in the public domain that we identified, ",[],{},{"nodeType":1293,"value":3031,"marks":3032,"data":3034},"a whopping 73% were the result of compromised credentials ",[3033],{"type":1460},{},{"nodeType":1293,"value":3036,"marks":3037,"data":3038},"(the rest were phishing attacks). ",[],{},{"nodeType":1294,"data":3040,"content":3041},{},[3042],{"nodeType":1293,"value":3043,"marks":3044,"data":3045},"As the primary source of compromised credentials, it’s fair to say that infostealers deserve the top spot for 2024.",[],{},{"nodeType":1520,"data":3047,"content":3051},{"target":3048},{"sys":3049},{"id":3050,"type":1517,"linkType":1518},"7mMQEYQTXKAajIGFviDJKt",[],{"nodeType":1400,"data":3053,"content":3054},{},[],{"nodeType":1408,"data":3056,"content":3057},{},[3058],{"nodeType":1293,"value":3059,"marks":3060,"data":3062},"Defend against infostealers with Push",[3061],{"type":1460},{},{"nodeType":1294,"data":3064,"content":3065},{},[3066],{"nodeType":1293,"value":3067,"marks":3068,"data":3069},"As a browser-based identity security platform designed to stop identity attacks, Push helps organizations to defend against the rise in infostealers by:",[],{},{"nodeType":1389,"data":3071,"content":3072},{},[3073,3106,3127],{"nodeType":1353,"data":3074,"content":3075},{},[3076],{"nodeType":1294,"data":3077,"content":3078},{},[3079,3082,3090,3094,3102],{"nodeType":1293,"value":37,"marks":3080,"data":3081},[],{},{"nodeType":1384,"data":3083,"content":3084},{"uri":2227},[3085],{"nodeType":1293,"value":3086,"marks":3087,"data":3089},"Alerting you whenever the valid credentials your employees are using appear in a compromised credential data feed",[3088],{"type":1382},{},{"nodeType":1293,"value":3091,"marks":3092,"data":3093},", which can be leveraged to ",[],{},{"nodeType":1384,"data":3095,"content":3096},{"uri":1642},[3097],{"nodeType":1293,"value":3098,"marks":3099,"data":3101},"trigger automated password resets",[3100],{"type":1382},{},{"nodeType":1293,"value":3103,"marks":3104,"data":3105}," whenever an event fires and is received by your SIEM tool.",[],{},{"nodeType":1353,"data":3107,"content":3108},{},[3109],{"nodeType":1294,"data":3110,"content":3111},{},[3112,3115,3123],{"nodeType":1293,"value":37,"marks":3113,"data":3114},[],{},{"nodeType":1384,"data":3116,"content":3117},{"uri":2068},[3118],{"nodeType":1293,"value":3119,"marks":3120,"data":3122},"Detecting session hijacking attacks using stolen cookies to identify when an attacker logs into an app",[3121],{"type":1382},{},{"nodeType":1293,"value":3124,"marks":3125,"data":3126}," from an unmanaged device without the Push browser extension — this can also be used to detect suspicious access in general!",[],{},{"nodeType":1353,"data":3128,"content":3129},{},[3130],{"nodeType":1294,"data":3131,"content":3132},{},[3133],{"nodeType":1293,"value":3134,"marks":3135,"data":3136},"Enabling you to enforce MFA the next time an employee logs into an app (even when the app itself doesn’t allow you to enforce mandatory MFA) — particularly handy if a weak, breached, or reused password is detected for their account!  ",[],{},{"nodeType":1294,"data":3138,"content":3139},{},[3140],{"nodeType":1293,"value":3141,"marks":3142,"data":3143},"And much, much more. ",[],{},{"nodeType":1294,"data":3145,"content":3146},{},[3147,3151,3160],{"nodeType":1293,"value":3148,"marks":3149,"data":3150},"If you’d like to explore the platform yourself and discover more of our great features, you can ",[],{},{"nodeType":1384,"data":3152,"content":3154},{"uri":3153},"https://pushsecurity.com/demo",[3155],{"nodeType":1293,"value":3156,"marks":3157,"data":3159},"request a demo",[3158],{"type":1382},{},{"nodeType":1293,"value":1894,"marks":3161,"data":3162},[],{},"Looking back on identity-based breaches in 2024","Reviewing public breaches that stemmed from identity attacks in 2024. ","2025-01-10T00:00:00.000Z","2024-identity-breaches",{"items":3168},[3169],{"sys":3170,"name":3172},{"id":3171},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":3174},[3175],{"fullName":3176,"firstName":3177,"jobTitle":3178,"profilePicture":3179},"Dan Green","Dan","Threat Research",{"url":3180},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1317,"sys":3182,"content":3184,"title":3801,"synopsis":3802,"hashTags":118,"publishedDate":3803,"slug":3804,"tagsCollection":3805,"authorsCollection":3811},{"id":3183},"SiALa9w13C6q3OzeTeUum",{"json":3185},{"nodeType":1295,"data":3186,"content":3187},{},[3188,3195,3211,3218,3224,3231,3238,3241,3248,3255,3262,3286,3293,3309,3312,3319,3326,3349,3356,3363,3381,3387,3394,3413,3419,3426,3472,3480,3487,3499,3511,3518,3551,3558,3561,3568,3588,3595,3602,3609,3612,3619,3627,3634,3641,3704,3711,3718,3725,3758,3765,3772,3779,3785],{"nodeType":1294,"data":3189,"content":3190},{},[3191],{"nodeType":1293,"value":3192,"marks":3193,"data":3194},"Computer-Using Agents (CUAs) are a new type of AI agent that drives your browser/OS for you. With the research preview release of OpenAI Operator last week, it’s likely that we’ll be seeing a lot more of this technology in the future as OpenAI iterates and competitors launch their own versions. ",[],{},{"nodeType":1294,"data":3196,"content":3197},{},[3198,3202,3207],{"nodeType":1293,"value":3199,"marks":3200,"data":3201},"These models run on the same UI as the user sees, rather than using code or API based add-ons or tools (e.g. with access via API keys). In Operator’s case, the agent runs in its own browser, where it can navigate to and interact with webpages by typing, clicking, and scrolling. It effectively sees and interacts with pages as a human would, ",[],{},{"nodeType":1293,"value":3203,"marks":3204,"data":3206},"using human (not machine) identities",[3205],{"type":1460},{},{"nodeType":1293,"value":3208,"marks":3209,"data":3210}," — taking actions on the web without requiring custom API integrations. ",[],{},{"nodeType":1294,"data":3212,"content":3213},{},[3214],{"nodeType":1293,"value":3215,"marks":3216,"data":3217},"This means that a user describes a task, and Operator performs it autonomously on their behalf. The examples provided by OpenAI are things like booking a dinner reservation or shopping for groceries — but naturally the potential use cases are much, much broader, especially in a work context.",[],{},{"nodeType":1520,"data":3219,"content":3223},{"target":3220},{"sys":3221},{"id":3222,"type":1517,"linkType":1518},"5mWWi5mfqEcSQX12gOtyQm",[],{"nodeType":1294,"data":3225,"content":3226},{},[3227],{"nodeType":1293,"value":3228,"marks":3229,"data":3230},"Obviously the broad impact of this technology is almost impossible to predict this early in the game. But since we’re focussed on identity security at Push, we can at least describe some of the very predictable impacts in this area.",[],{},{"nodeType":1294,"data":3232,"content":3233},{},[3234],{"nodeType":1293,"value":3235,"marks":3236,"data":3237},"CUAs like Operator are essentially very flexible no-code automation platforms. This means that these tools (or future iterations of them) will enable low-cost, low-effort automation of common web tasks — the very tasks that app developers and vendors have worked hard to prevent from being automated — including those frequently performed by attackers.",[],{},{"nodeType":1400,"data":3239,"content":3240},{},[],{"nodeType":1408,"data":3242,"content":3243},{},[3244],{"nodeType":1293,"value":3245,"marks":3246,"data":3247},"Why do CUAs stand to benefit attackers more than previous AI tools? ",[],{},{"nodeType":1294,"data":3249,"content":3250},{},[3251],{"nodeType":1293,"value":3252,"marks":3253,"data":3254},"Organizations have been concerned about the security and privacy implications of GenAI tools and platforms for a while now — mainly concerning the risk of inputting sensitive data into LLMs, and prompt injection attacks in which models can be tricked into disclosing internal data. ",[],{},{"nodeType":1294,"data":3256,"content":3257},{},[3258],{"nodeType":1293,"value":3259,"marks":3260,"data":3261},"But so far, the primary impact of GenAI on attacker capabilities specifically has been mainly limited to the use of LLMs for the creation of phishing emails and in AI-assisted malware development — no doubt significant, but not exactly transformative. And although the concept of an AI agent is nothing new, they haven’t been particularly common outside of research circles. ",[],{},{"nodeType":1294,"data":3263,"content":3264},{},[3265,3269,3274,3277,3282],{"nodeType":1293,"value":3266,"marks":3267,"data":3268},"CUAs, on the other hand, use LLMs trained using datasets which make them far more able to understand and interact with web pages. Coupled with what is essentially a production-grade integration between browser and LLM, and you have an agent that is able to understand and interact with websites to achieve an outcome, with minimal human input and oversight (as opposed to simply scraping the data) ",[],{},{"nodeType":1293,"value":3270,"marks":3271,"data":3273},"with much the same behaviors and capabilities",[3272],{"type":1460},{},{"nodeType":1293,"value":1483,"marks":3275,"data":3276},[],{},{"nodeType":1293,"value":3278,"marks":3279,"data":3281},"as a human operator.",[3280],{"type":1460},{},{"nodeType":1293,"value":3283,"marks":3284,"data":3285}," ",[],{},{"nodeType":1294,"data":3287,"content":3288},{},[3289],{"nodeType":1293,"value":3290,"marks":3291,"data":3292},"By performing actions autonomously on the user’s behalf, it has a lot in common with a low/no-code automation platform like Zapier or Make.com — except it doesn’t perform actions via API, but by performing actions in the browser as a user would. Unlike no/low-code automations, it doesn’t need a strict or rigid step-by-step description of tasks that should be automated and can dynamically generate steps like a human does. ",[],{},{"nodeType":1294,"data":3294,"content":3295},{},[3296,3300,3305],{"nodeType":1293,"value":3297,"marks":3298,"data":3299},"None of this can’t be done using other automation tools, but it’s the difference between writing code to automate a task by hand and asking a human assistant to do something for you — ",[],{},{"nodeType":1293,"value":3301,"marks":3302,"data":3304},"the effort required is reduced by orders of magnitude.",[3303],{"type":1460},{},{"nodeType":1293,"value":3306,"marks":3307,"data":3308}," This makes it both more flexible and accessible to a much wider range of users. ",[],{},{"nodeType":1400,"data":3310,"content":3311},{},[],{"nodeType":1408,"data":3313,"content":3314},{},[3315],{"nodeType":1293,"value":3316,"marks":3317,"data":3318},"How can CUAs be abused by attackers?",[],{},{"nodeType":1294,"data":3320,"content":3321},{},[3322],{"nodeType":1293,"value":3323,"marks":3324,"data":3325},"There are two main groups of attack to be aware of:",[],{},{"nodeType":1389,"data":3327,"content":3328},{},[3329,3339],{"nodeType":1353,"data":3330,"content":3331},{},[3332],{"nodeType":1294,"data":3333,"content":3334},{},[3335],{"nodeType":1293,"value":3336,"marks":3337,"data":3338},"Attacks enabled by the technology (CUA)",[],{},{"nodeType":1353,"data":3340,"content":3341},{},[3342],{"nodeType":1294,"data":3343,"content":3344},{},[3345],{"nodeType":1293,"value":3346,"marks":3347,"data":3348},"Attacks against specific CUA tools/implementations (e.g. Operator)",[],{},{"nodeType":1294,"data":3350,"content":3351},{},[3352],{"nodeType":1293,"value":3353,"marks":3354,"data":3355},"Because the answer to the latter question is subjective depending on the CUA being targeted (and Operator is still in its “research preview” release) we’ll focus on how attackers can potentially use CUAs for malicious purposes in general. ",[],{},{"nodeType":1484,"data":3357,"content":3358},{},[3359],{"nodeType":1293,"value":3360,"marks":3361,"data":3362},"How attackers can use their own CUAs to conduct AI-powered cyber attacks",[],{},{"nodeType":1294,"data":3364,"content":3365},{},[3366,3370,3378],{"nodeType":1293,"value":3367,"marks":3368,"data":3369},"The most obvious use-case for an attacker-controlled CUA is targeting internet-based app accounts. Most organizations are now using hundreds of apps, with thousands of sprawling identities (including both inside enterprise SSO connected accounts and local username & password logins) — ",[],{},{"nodeType":1384,"data":3371,"content":3372},{"uri":1616},[3373],{"nodeType":1293,"value":3374,"marks":3375,"data":3377},"many of which are highly vulnerable to even low-sophistication attack techniques",[3376],{"type":1382},{},{"nodeType":1293,"value":1783,"marks":3379,"data":3380},[],{},{"nodeType":1520,"data":3382,"content":3386},{"target":3383},{"sys":3384},{"id":3385,"type":1517,"linkType":1518},"7itjimRwqpkrCF7YRI8FTq",[],{"nodeType":1294,"data":3388,"content":3389},{},[3390],{"nodeType":1293,"value":3391,"marks":3392,"data":3393},"Previously, identity attacks against modern SaaS environments and the sprawl of apps and accounts required a lot of manual work to scale. Because web identities are implemented in mostly bespoke ways across thousands of sites (and they are constantly changing) attacks on them are challenging to automate. Further, the act of logging in using automated methods has been impacted by widespread bot protection — specifically to prevent malicious automation. ",[],{},{"nodeType":1294,"data":3395,"content":3396},{},[3397,3401,3409],{"nodeType":1293,"value":3398,"marks":3399,"data":3400},"So, attackers end up sending phishing links through email, and targeting only a few high value apps for cred stuffing — despite the availability of credentials online (which, ",[],{},{"nodeType":1384,"data":3402,"content":3403},{"uri":1904},[3404],{"nodeType":1293,"value":3405,"marks":3406,"data":3408},"as the Snowflake attacks demonstrate",[3407],{"type":1382},{},{"nodeType":1293,"value":3410,"marks":3411,"data":3412},", can be an untapped treasure trove for attackers).",[],{},{"nodeType":1520,"data":3414,"content":3418},{"target":3415},{"sys":3416},{"id":3417,"type":1517,"linkType":1518},"24HV5O6LJ12ZVECTSel2WL",[],{"nodeType":1294,"data":3420,"content":3421},{},[3422],{"nodeType":1293,"value":3423,"marks":3424,"data":3425},"We know that about 1 in 3 users re-use passwords, so there is a great chance a lot of those exact same credentials were actually valid for many other apps. It’s very tough to manually test each credential by logging into even a few dozen apps (or building a web automation to do so). But this is significantly easier if you can ask a CUA to: ",[],{},{"nodeType":1389,"data":3427,"content":3428},{},[3429,3439,3449],{"nodeType":1353,"data":3430,"content":3431},{},[3432],{"nodeType":1294,"data":3433,"content":3434},{},[3435],{"nodeType":1293,"value":3436,"marks":3437,"data":3438},"“Find a list of the top 1000 SaaS apps”. ",[],{},{"nodeType":1353,"data":3440,"content":3441},{},[3442],{"nodeType":1294,"data":3443,"content":3444},{},[3445],{"nodeType":1293,"value":3446,"marks":3447,"data":3448},"“Try to login to the app using this username and password. Let me know which apps you successfully logged into”. ",[],{},{"nodeType":1353,"data":3450,"content":3451},{},[3452],{"nodeType":1294,"data":3453,"content":3454},{},[3455,3459,3468],{"nodeType":1293,"value":3456,"marks":3457,"data":3458},"“Use ",[],{},{"nodeType":1384,"data":3460,"content":3462},{"uri":3461},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/takeout_services/description.md",[3463],{"nodeType":1293,"value":3464,"marks":3465,"data":3467},"takeout services",[3466],{"type":1382},{},{"nodeType":1293,"value":3469,"marks":3470,"data":3471}," to download data from each app and send it to this location, grouping by company name” (or even just ask the model to cut and paste or download the data from the account).",[],{},{"nodeType":1294,"data":3473,"content":3474},{},[3475],{"nodeType":1293,"value":3476,"marks":3477,"data":3479},"This is how you really scale these attacks.",[3478],{"type":1460},{},{"nodeType":1294,"data":3481,"content":3482},{},[3483],{"nodeType":1293,"value":3484,"marks":3485,"data":3486},"CUA agents also change how and where phishing can take place. Where phishing takes place outside of email, it’s much less likely to be intercepted by enterprise anti-phishing controls. You could:",[],{},{"nodeType":1294,"data":3488,"content":3489},{},[3490,3495],{"nodeType":1293,"value":3491,"marks":3492,"data":3494},"1.",[3493],{"type":1460},{},{"nodeType":1293,"value":3496,"marks":3497,"data":3498}," Task an agent to create Reddit, Discord, and Slack accounts, login, and find the 100 (or 10000?) biggest subreddits/communities/channels. Now have it join those, and write posts that seem relevant to ongoing threads, or write targeted DMs and include links to a phishing page. If the account gets banned, no problem, automatically start over. Not enough karma? Instruct the agent to build karma.",[],{},{"nodeType":1294,"data":3500,"content":3501},{},[3502,3507],{"nodeType":1293,"value":3503,"marks":3504,"data":3506},"2.",[3505],{"type":1460},{},{"nodeType":1293,"value":3508,"marks":3509,"data":3510}," Or consider a more targeted scenario: connect to a specific target (or group of targets) via LinkedIn, read all your target’s posts and comments, and using that context start a conversation with them, using a topic you know that will interest them to create a phishing lure, and direct them to your phishing site. ",[],{},{"nodeType":1484,"data":3512,"content":3513},{},[3514],{"nodeType":1293,"value":3515,"marks":3516,"data":3517},"Operator caveats",[],{},{"nodeType":1294,"data":3519,"content":3520},{},[3521,3525,3534,3538,3547],{"nodeType":1293,"value":3522,"marks":3523,"data":3524},"Now, it’s worth pointing out that Operator has controls that are designed to prevent this sort of abuse. ",[],{},{"nodeType":1384,"data":3526,"content":3528},{"uri":3527},"https://openai.com/index/introducing-operator/",[3529],{"nodeType":1293,"value":3530,"marks":3531,"data":3533},"For example",[3532],{"type":1382},{},{"nodeType":1293,"value":3535,"marks":3536,"data":3537},", Operator is trained to proactively ask the user to take over for tasks that require login, payment details, or when solving CAPTCHAs. The ",[],{},{"nodeType":1384,"data":3539,"content":3541},{"uri":3540},"https://openai.com/index/operator-system-card/",[3542],{"nodeType":1293,"value":3543,"marks":3544,"data":3546},"Operator System Card",[3545],{"type":1382},{},{"nodeType":1293,"value":3548,"marks":3549,"data":3550}," also cites proactive refusals of high-risk tasks, confirmation prompts before critical actions, and active monitoring systems to detect and mitigate potential threats.",[],{},{"nodeType":1294,"data":3552,"content":3553},{},[3554],{"nodeType":1293,"value":3555,"marks":3556,"data":3557},"It’s unclear at this point how resistant Operator will be to attack or abuse, but really, as we said earlier, this is not about Operator — once CUA tech becomes more widely available (if recent trends are anything to go by) there’s no doubt that models will emerge with fewer (or no) safety controls. ",[],{},{"nodeType":1400,"data":3559,"content":3560},{},[],{"nodeType":1408,"data":3562,"content":3563},{},[3564],{"nodeType":1293,"value":3565,"marks":3566,"data":3567},"Why CUA-based automation is a problem for security teams",[],{},{"nodeType":1294,"data":3569,"content":3570},{},[3571,3575,3584],{"nodeType":1293,"value":3572,"marks":3573,"data":3574},"Attackers have been using automation tools forever, and in response, developers have been building protections against them (e.g. Cloudflare Turnstile and CAPTCHAs). Using LLMs to super power them isn’t even new, nor is using automation apps for malicious purposes (see our SaaS attack matrix entry for ",[],{},{"nodeType":1384,"data":3576,"content":3578},{"uri":3577},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/shadow_workflows/description.md",[3579],{"nodeType":1293,"value":3580,"marks":3581,"data":3583},"shadow workflows",[3582],{"type":1382},{},{"nodeType":1293,"value":3585,"marks":3586,"data":3587},") — so what’s the difference?",[],{},{"nodeType":1294,"data":3589,"content":3590},{},[3591],{"nodeType":1293,"value":3592,"marks":3593,"data":3594},"Previously, attackers needed to tie together automated browsers, get bot protection bypasses working, write code to extract screenshots from these browsers, pump those screenshots into a traditional LLM, generate response actions, and write code to execute those actions using browser automation. It was a lot of manual work — and needed constant maintenance — and wasn’t very effective because the general LLMs weren’t good at interpreting what they were seeing.",[],{},{"nodeType":1294,"data":3596,"content":3597},{},[3598],{"nodeType":1293,"value":3599,"marks":3600,"data":3601},"So, this isn’t so much a change in capability but a signal that there is going to be a massive increase in performance compared to other AI agents. Bundle the new model’s ability to understand with the ability to interact with webpages and you have something that might soon create real world impact at scale. ",[],{},{"nodeType":1294,"data":3603,"content":3604},{},[3605],{"nodeType":1293,"value":3606,"marks":3607,"data":3608},"Perhaps the only real obstacles are safety controls and cost. But as we’ve seen after previous GenAI launches, most recently with DeepSeek — competitors have been fast following with models that out-perform the original. Some of these models will be open and contain far fewer safety protections. An open CUA model in the future might be the trigger that enables attackers to leverage these capabilities at scale. ",[],{},{"nodeType":1400,"data":3610,"content":3611},{},[],{"nodeType":1408,"data":3613,"content":3614},{},[3615],{"nodeType":1293,"value":3616,"marks":3617,"data":3618},"So what?",[],{},{"nodeType":1294,"data":3620,"content":3621},{},[3622],{"nodeType":1293,"value":3623,"marks":3624,"data":3626},"The TL;DR is that the adoption of CUAs has the potential to significantly lower the cost to attackers of running identity attacks such as phishing and credential stuffing, while increasing their reach.",[3625],{"type":1460},{},{"nodeType":1294,"data":3628,"content":3629},{},[3630],{"nodeType":1293,"value":3631,"marks":3632,"data":3633},"We can expect improved account takeover attacks in the future as this technology becomes more widespread, with phishing attacks being increasingly delivered outside of traditional (well-protected) mediums like email, and credential stuffing being weaponized on an even more widespread scale, across a broader range of apps. These capabilities will also become more accessible, with even less advanced attackers able to harness them.",[],{},{"nodeType":1294,"data":3635,"content":3636},{},[3637],{"nodeType":1293,"value":3638,"marks":3639,"data":3640},"Right now, Operator runs in a sandboxed browser environment. But going forward, more value will require an increased ability to perform authenticated access as the user — so one could imagine a world where new features are built to expose passwords into this sandbox — or that these agents will be enabled outside these sandboxes and operate in your browser (primarily) or directly on your OS using agents. We’ve already seen these agents implemented as browser extensions. This makes sense as extensions can see the tab, and interact with the page — and some early extension-based agents have existed for a while:",[],{},{"nodeType":1389,"data":3642,"content":3643},{},[3644,3664,3684],{"nodeType":1353,"data":3645,"content":3646},{},[3647],{"nodeType":1294,"data":3648,"content":3649},{},[3650,3653,3661],{"nodeType":1293,"value":37,"marks":3651,"data":3652},[],{},{"nodeType":1384,"data":3654,"content":3656},{"uri":3655},"https://github.com/richardyc/Chrome-GPT",[3657],{"nodeType":1293,"value":3655,"marks":3658,"data":3660},[3659],{"type":1382},{},{"nodeType":1293,"value":3283,"marks":3662,"data":3663},[],{},{"nodeType":1353,"data":3665,"content":3666},{},[3667],{"nodeType":1294,"data":3668,"content":3669},{},[3670,3673,3681],{"nodeType":1293,"value":37,"marks":3671,"data":3672},[],{},{"nodeType":1384,"data":3674,"content":3676},{"uri":3675},"https://github.com/handrew/browserpilot",[3677],{"nodeType":1293,"value":3675,"marks":3678,"data":3680},[3679],{"type":1382},{},{"nodeType":1293,"value":37,"marks":3682,"data":3683},[],{},{"nodeType":1353,"data":3685,"content":3686},{},[3687],{"nodeType":1294,"data":3688,"content":3689},{},[3690,3693,3701],{"nodeType":1293,"value":37,"marks":3691,"data":3692},[],{},{"nodeType":1384,"data":3694,"content":3696},{"uri":3695},"https://github.com/TaxyAI/browser-extension",[3697],{"nodeType":1293,"value":3695,"marks":3698,"data":3700},[3699],{"type":1382},{},{"nodeType":1293,"value":1894,"marks":3702,"data":3703},[],{},{"nodeType":1294,"data":3705,"content":3706},{},[3707],{"nodeType":1293,"value":3708,"marks":3709,"data":3710},"If we have agents operating on user endpoints, not in sandboxes, that means they will have access to all identities that are already authenticated, or that can be automatically authenticated (password manager autofills etc.). There’s nothing fundamentally stopping you from prompt-injecting a victim's CUA and tricking it into creating a malicious integration, or sending you an API key.",[],{},{"nodeType":1484,"data":3712,"content":3713},{},[3714],{"nodeType":1293,"value":3715,"marks":3716,"data":3717},"So to summarize...",[],{},{"nodeType":1294,"data":3719,"content":3720},{},[3721],{"nodeType":1293,"value":3722,"marks":3723,"data":3724},"Organizations should anticipate an increase in identity attacks targeting web-based apps and services using techniques that can be amplified by CUAs such as phishing and credential stuffing. We recommend that organizations:",[],{},{"nodeType":1389,"data":3726,"content":3727},{},[3728,3738,3748],{"nodeType":1353,"data":3729,"content":3730},{},[3731],{"nodeType":1294,"data":3732,"content":3733},{},[3734],{"nodeType":1293,"value":3735,"marks":3736,"data":3737},"Anticipate an increase in phishing attacks delivered outside of email, and evaluate your detection capabilities for mediums such as IM platforms and social media sites.",[],{},{"nodeType":1353,"data":3739,"content":3740},{},[3741],{"nodeType":1294,"data":3742,"content":3743},{},[3744],{"nodeType":1293,"value":3745,"marks":3746,"data":3747},"Find and harden identities that could be vulnerable to attacks using techniques that can be automated (e.g. mass credential stuffing) such as those missing phishing resistant MFA (or MFA altogether).",[],{},{"nodeType":1353,"data":3749,"content":3750},{},[3751],{"nodeType":1294,"data":3752,"content":3753},{},[3754],{"nodeType":1293,"value":3755,"marks":3756,"data":3757},"Ensure that all identities are suitably protected — even those outside the scope of traditional identity stores (such as Active Directory and modern equivalents e.g. Entra, Okta) used to access the much broader set of web-based services. ",[],{},{"nodeType":1484,"data":3759,"content":3760},{},[3761],{"nodeType":1293,"value":3762,"marks":3763,"data":3764},"How Push can help",[],{},{"nodeType":1294,"data":3766,"content":3767},{},[3768],{"nodeType":1293,"value":3769,"marks":3770,"data":3771},"AI-powered or not, identity attacks are what Push is designed to combat. Our features and controls designed to stop account takeover via phishing, credential stuffing, and session hijacking remain effective in this new world — in fact, as attackers are granted the ability to conduct these attacks with greater speed and scale, they become more valuable than ever. ",[],{},{"nodeType":1294,"data":3773,"content":3774},{},[3775],{"nodeType":1293,"value":3776,"marks":3777,"data":3778},"If you're interested in learning more, check out our on-demand webinar where we demonstrate the use of CUAs for automating identity attacks, particularly in the context of SaaS account takeover. ",[],{},{"nodeType":1520,"data":3780,"content":3784},{"target":3781},{"sys":3782},{"id":3783,"type":1517,"linkType":1518},"UCmd5kqVZ03ce5Cs9M0r5",[],{"nodeType":1294,"data":3786,"content":3787},{},[3788,3792,3798],{"nodeType":1293,"value":3789,"marks":3790,"data":3791},"If you’d like to learn more about Push, ",[],{},{"nodeType":1384,"data":3793,"content":3794},{"uri":2512},[3795],{"nodeType":1293,"value":2517,"marks":3796,"data":3797},[],{},{"nodeType":1293,"value":2521,"marks":3799,"data":3800},[],{},"Considering the security implications of Computer-Using Agents (like OpenAI Operator)","CUAs are a new type of AI agent that drives your browser/OS for you, enabling effortless automation of web tasks — including those performed by attackers.","2025-01-28T00:00:00.000Z","considering-the-impact-of-computer-using-agents",{"items":3806},[3807,3809],{"sys":3808,"name":3172},{"id":3171},{"sys":3810,"name":1309},{"id":1308},{"items":3812},[3813],{"fullName":3814,"firstName":3815,"jobTitle":3816,"profilePicture":3817},"Jacques Louw","Jacques","Co-founder / CRO",{"url":3818},"https://images.ctfassets.net/y1cdw1ablpvd/39m8bektV23lnCRcEq0G8h/2a08f6276a50744f1a4b499b273f6bb2/Push_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-21.jpg",{"items":3820},[3821],{"fullName":3176,"firstName":3177,"jobTitle":3178,"profilePicture":3822},{"url":3180},{"json":3824,"links":4702},{"nodeType":1295,"data":3825,"content":3826},{},[3827,3834,3841,3848,3854,3857,3865,3885,3892,3899,3906,3929,3937,3940,3948,3955,3962,3969,3976,3982,3989,3996,4029,4036,4044,4050,4057,4076,4096,4104,4124,4130,4137,4144,4177,4185,4192,4198,4205,4212,4245,4253,4273,4281,4301,4309,4316,4322,4329,4332,4340,4360,4416,4423,4430,4438,4445,4468,4475,4494,4500,4507,4513,4520,4583,4591,4611,4618,4641,4644,4652,4659,4665,4672,4690,4696],{"nodeType":1294,"data":3828,"content":3829},{},[3830],{"nodeType":1293,"value":3831,"marks":3832,"data":3833},"A lot happened last year in the world of identity security — particularly in terms of the attacks we’ve experienced targeting internet applications and services. With this trend certain to continue in 2025, it’s more important than ever that product vendors build products with a secure baseline of fundamental controls and safeguards.",[],{},{"nodeType":1294,"data":3835,"content":3836},{},[3837],{"nodeType":1293,"value":3838,"marks":3839,"data":3840},"The vast majority of the identity vulnerabilities we observe in the wild are the result of multiple auth mechanisms being attached to a single account. The more methods that are configured (or are configurable), the greater the risk that insecure identities will be created — and exploited by attackers. ",[],{},{"nodeType":1294,"data":3842,"content":3843},{},[3844],{"nodeType":1293,"value":3845,"marks":3846,"data":3847},"The good news is that with a coordinated response from app vendors, this surface can be significantly reduced. The bad news is that right now, we’re very far from a universal standard when it comes to how apps handle authentication and identities. ",[],{},{"nodeType":1520,"data":3849,"content":3853},{"target":3850},{"sys":3851},{"id":3852,"type":1517,"linkType":1518},"4QoPUiP5q6Mwj1eWUZT15Q",[],{"nodeType":1400,"data":3855,"content":3856},{},[],{"nodeType":1408,"data":3858,"content":3859},{},[3860],{"nodeType":1293,"value":3861,"marks":3862,"data":3864},"Where to start?",[3863],{"type":1460},{},{"nodeType":1294,"data":3866,"content":3867},{},[3868,3872,3881],{"nodeType":1293,"value":3869,"marks":3870,"data":3871},"The ",[],{},{"nodeType":1384,"data":3873,"content":3875},{"uri":3874},"https://mvsp.dev/mvsp.en/",[3876],{"nodeType":1293,"value":3877,"marks":3878,"data":3880},"Minimum Viable Secure Product (MVSP)",[3879],{"type":1382},{},{"nodeType":1293,"value":3882,"marks":3883,"data":3884}," initiative is a great resource for product and engineering teams that sets out essential controls that should be implemented in enterprise-ready products and services. MVSP does a fantastic job of getting to the heart of what’s important for vendor products, as compared to more general frameworks and standards like ISO and NIST that cover wider controls that should be implemented across the enterprise. ",[],{},{"nodeType":1294,"data":3886,"content":3887},{},[3888],{"nodeType":1293,"value":3889,"marks":3890,"data":3891},"We don’t want to reinvent the wheel, so we won’t be redoing the fundamentals already covered in MVSP. But MVSP inspired us to think – what are the vendor controls that would make a meaningful difference against the identity attacks we’re seeing in the wild? ",[],{},{"nodeType":1294,"data":3893,"content":3894},{},[3895],{"nodeType":1293,"value":3896,"marks":3897,"data":3898},"With better, consistent security standards, SaaS developers can close off a number of ATO techniques and generally make life much more difficult for attackers. ",[],{},{"nodeType":1294,"data":3900,"content":3901},{},[3902],{"nodeType":1293,"value":3903,"marks":3904,"data":3905},"We’ve identified two key areas of potential improvement which would make a material difference to ATO resilience:",[],{},{"nodeType":1389,"data":3907,"content":3908},{},[3909,3919],{"nodeType":1353,"data":3910,"content":3911},{},[3912],{"nodeType":1294,"data":3913,"content":3914},{},[3915],{"nodeType":1293,"value":3916,"marks":3917,"data":3918},"Many of the emerging TTPs could be seriously impaired (or prevented entirely) with improved authentication and identity management controls. ",[],{},{"nodeType":1353,"data":3920,"content":3921},{},[3922],{"nodeType":1294,"data":3923,"content":3924},{},[3925],{"nodeType":1293,"value":3926,"marks":3927,"data":3928},"Detecting attacks and responding to identity breaches on third-party apps is a nightmare due to the availability of log data (or lack thereof). ",[],{},{"nodeType":1294,"data":3930,"content":3931},{},[3932],{"nodeType":1293,"value":3933,"marks":3934,"data":3936},"Let’s look at the changes that app vendors can make to improve the situation. ",[3935],{"type":1460},{},{"nodeType":1400,"data":3938,"content":3939},{},[],{"nodeType":1408,"data":3941,"content":3942},{},[3943],{"nodeType":1293,"value":3944,"marks":3945,"data":3947},"Provide the visibility and control to manage and harden identities",[3946],{"type":1460},{},{"nodeType":1294,"data":3949,"content":3950},{},[3951],{"nodeType":1293,"value":3952,"marks":3953,"data":3954},"In the context of SaaS, identity security controls are your best (and in many cases, your last) defense against cyber attacks. ",[],{},{"nodeType":1294,"data":3956,"content":3957},{},[3958],{"nodeType":1293,"value":3959,"marks":3960,"data":3961},"Pretty much every SaaS attack involves ATO through identity-based techniques, such as phishing, credential stuffing, or session hijacking using stolen cookies. In contrast, very few involve classic vulnerability exploitation (e.g. injection vulns, cross-site scripting, etc.). ",[],{},{"nodeType":1294,"data":3963,"content":3964},{},[3965],{"nodeType":1293,"value":3966,"marks":3967,"data":3968},"When all an attacker needs to do is log into an app and dump the data to succeed, there isn’t much in the way of post-ATO activity to detect and respond to (even if you had the logs you need, more on this later) — which is why robust authentication controls to prevent unauthorized access are so important. ",[],{},{"nodeType":1294,"data":3970,"content":3971},{},[3972],{"nodeType":1293,"value":3973,"marks":3974,"data":3975},"If post-ATO activity does occur, it is often to compromise additional accounts with in-app administrative privileges as opposed to pivoting to other environments. ",[],{},{"nodeType":1520,"data":3977,"content":3981},{"target":3978},{"sys":3979},{"id":3980,"type":1517,"linkType":1518},"3l9SxYjTtls6URgbI0NiU3",[],{"nodeType":1294,"data":3983,"content":3984},{},[3985],{"nodeType":1293,"value":3986,"marks":3987,"data":3988},"As you’d expect, many apps prioritize a frictionless user experience over security. This is one of the main drivers of insecure authentication implementation. Consistent implementation of identity and authentication controls would go a long way to reducing the susceptibility of apps to the majority of identity attack techniques. ",[],{},{"nodeType":1294,"data":3990,"content":3991},{},[3992],{"nodeType":1293,"value":3993,"marks":3994,"data":3995},"In terms of authentication and identity management, MVSP focuses on:",[],{},{"nodeType":1389,"data":3997,"content":3998},{},[3999,4009,4019],{"nodeType":1353,"data":4000,"content":4001},{},[4002],{"nodeType":1294,"data":4003,"content":4004},{},[4005],{"nodeType":1293,"value":4006,"marks":4007,"data":4008},"Providing an SSO mechanism, ",[],{},{"nodeType":1353,"data":4010,"content":4011},{},[4012],{"nodeType":1294,"data":4013,"content":4014},{},[4015],{"nodeType":1293,"value":4016,"marks":4017,"data":4018},"Implementing a robust password policy, and ",[],{},{"nodeType":1353,"data":4020,"content":4021},{},[4022],{"nodeType":1294,"data":4023,"content":4024},{},[4025],{"nodeType":1293,"value":4026,"marks":4027,"data":4028},"Logically separating data/functions based on the needs of a user type/group. ",[],{},{"nodeType":1294,"data":4030,"content":4031},{},[4032],{"nodeType":1293,"value":4033,"marks":4034,"data":4035},"We can go beyond these basic auth controls to prevent identity attacks by providing better default security configurations, and giving admins more visibility and control over identities. ",[],{},{"nodeType":1484,"data":4037,"content":4038},{},[4039],{"nodeType":1293,"value":4040,"marks":4041,"data":4043},"1. Allow one active login method (and require external re-verification to change to another).",[4042],{"type":1460},{},{"nodeType":1520,"data":4045,"content":4049},{"target":4046},{"sys":4047},{"id":4048,"type":1517,"linkType":1518},"65YwkaNS3LjB1vZsYQtXQH",[],{"nodeType":1294,"data":4051,"content":4052},{},[4053],{"nodeType":1293,"value":4054,"marks":4055,"data":4056},"There is very rarely a need for multiple authentication methods to be active for the same account at the same time. Perhaps you upgrade from a local password to OIDC or SAML — but there’s no need to have multiple SSO logins from different providers at once, and there’s no need to continue using a local password after adding an SSO method. One exception is Administrators retaining local password access to access the tenant in case SAML configuration breaks (commonly because certificates expire) but in all other cases it’s an anti-pattern to allow any user more than one auth method. ",[],{},{"nodeType":1294,"data":4058,"content":4059},{},[4060,4064,4072],{"nodeType":1293,"value":4061,"marks":4062,"data":4063},"We call these alternative login methods (especially when they are in addition to SAML — so e.g. local password or OIDC logins using Google or Microsoft) ",[],{},{"nodeType":1384,"data":4065,"content":4067},{"uri":4066},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[4068],{"nodeType":1293,"value":2337,"marks":4069,"data":4071},[4070],{"type":1382},{},{"nodeType":1293,"value":4073,"marks":4074,"data":4075}," because they provide attackers with a way around a company’s chosen enterprise SSO option. ",[],{},{"nodeType":1294,"data":4077,"content":4078},{},[4079,4083,4092],{"nodeType":1293,"value":4080,"marks":4081,"data":4082},"This situation most commonly arises because apps automatically merge login methods. So for example, if a user normally logs in with a password, but then attempts to login using an OIDC of social login — many apps automatically merge that new login method with the existing account. This is particularly problematic when it’s done without further verification steps — leading to ",[],{},{"nodeType":1384,"data":4084,"content":4086},{"uri":4085},"https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/",[4087],{"nodeType":1293,"value":4088,"marks":4089,"data":4091},"cross-IdP attacks",[4090],{"type":1382},{},{"nodeType":1293,"value":4093,"marks":4094,"data":4095},". Ideally, apps should disable the old log method when a new one is enabled, but at the very least, external verification of the change should be required (e.g. via email). ",[],{},{"nodeType":1484,"data":4097,"content":4098},{},[4099],{"nodeType":1293,"value":4100,"marks":4101,"data":4103},"2. Require external verification of changes to IdP configuration settings.",[4102],{"type":1460},{},{"nodeType":1294,"data":4105,"content":4106},{},[4107,4111,4120],{"nodeType":1293,"value":4108,"marks":4109,"data":4110},"Attackers that are able to compromise one account with the level of privilege required to change the SAML settings in-app (typically an app admin), even on an app that is otherwise uninteresting or low risk – can perform an attack technique known as ",[],{},{"nodeType":1384,"data":4112,"content":4114},{"uri":4113},"https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/",[4115],{"nodeType":1293,"value":4116,"marks":4117,"data":4119},"SAMLjacking",[4118],{"type":1382},{},{"nodeType":1293,"value":4121,"marks":4122,"data":4123},". This can be used to direct users to authenticate to the app via an attacker-controlled IdP tenant (so e.g. an attacker’s own Okta instance or phishing page that looks like Okta/MS/Google) to capture additional credentials and facilitate further compromise of accounts. ",[],{},{"nodeType":1520,"data":4125,"content":4129},{"target":4126},{"sys":4127},{"id":4128,"type":1517,"linkType":1518},"4YfQDIY2hhE77h2xDr9Ja",[],{"nodeType":1294,"data":4131,"content":4132},{},[4133],{"nodeType":1293,"value":4134,"marks":4135,"data":4136},"To mitigate this, any SAML changes should require external verification, ideally through an out-of-band method like DNS Verification. If this can’t be achieved and you need to rely on email, the request should be sent to all app admins (to increase awareness of the risky change) and come with a cooldown period before the change takes effect. This improves the chance that an attacker’s SAMLjacking attack can be intercepted before half of the victim’s workforce gets keylogged — not after!",[],{},{"nodeType":1294,"data":4138,"content":4139},{},[4140],{"nodeType":1293,"value":4141,"marks":4142,"data":4143},"Other viable control options include:",[],{},{"nodeType":1389,"data":4145,"content":4146},{},[4147,4157,4167],{"nodeType":1353,"data":4148,"content":4149},{},[4150],{"nodeType":1294,"data":4151,"content":4152},{},[4153],{"nodeType":1293,"value":4154,"marks":4155,"data":4156},"Once SAML is configured, ensure it can't be edited without contacting the app developer",[],{},{"nodeType":1353,"data":4158,"content":4159},{},[4160],{"nodeType":1294,"data":4161,"content":4162},{},[4163],{"nodeType":1293,"value":4164,"marks":4165,"data":4166},"Service Provider initiated flows not enabled by default to stop attackers from hijacking logins using Home Realm Discovery for domains they don't own",[],{},{"nodeType":1353,"data":4168,"content":4169},{},[4170],{"nodeType":1294,"data":4171,"content":4172},{},[4173],{"nodeType":1293,"value":4174,"marks":4175,"data":4176},"Disallow new signups using password or OIDC logins when a domain is connected via SAML",[],{},{"nodeType":1484,"data":4178,"content":4179},{},[4180],{"nodeType":1293,"value":4181,"marks":4182,"data":4184},"3. Provide admins with visibility of account authentication (login methods, MFA methods, IdPs used) and allow them to be restricted or removed. ",[4183],{"type":1460},{},{"nodeType":1294,"data":4186,"content":4187},{},[4188],{"nodeType":1293,"value":4189,"marks":4190,"data":4191},"Many apps provide very limited information to admins about the configuration of identities within their tenant, and fewer still provide any mechanism for admins to take action if gaps or potential weak points are discovered. Some don’t even provide information about which accounts have access to the tenant at all. As a security team member this is maddening. ",[],{},{"nodeType":1520,"data":4193,"content":4197},{"target":4194},{"sys":4195},{"id":4196,"type":1517,"linkType":1518},"5z3zNE7z9TWUJsYCmwew1S",[],{"nodeType":1294,"data":4199,"content":4200},{},[4201],{"nodeType":1293,"value":4202,"marks":4203,"data":4204},"It’s vital that, at the bare minimum, admins can access information (ideally in a dashboard) with the accounts, all login methods configured, MFA factors set, and the SSO methods used (specifying the IdP and protocol). All login methods should be visible to security admins, including secondary email addresses, social login connections, and so on. ",[],{},{"nodeType":1294,"data":4206,"content":4207},{},[4208],{"nodeType":1293,"value":4209,"marks":4210,"data":4211},"It should then also be possible to set a preferred method (e.g. only SAML from Microsoft, or OIDC from Google) and delete or disable ones that pose a risk. ",[],{},{"nodeType":1294,"data":4213,"content":4214},{},[4215,4219,4228,4232,4241],{"nodeType":1293,"value":4216,"marks":4217,"data":4218},"For security teams to be able to clean up insecure identities, they need to be able to make changes inside the app without requiring an action from the user. This means removing phishable MFA factors to prevent ",[],{},{"nodeType":1384,"data":4220,"content":4222},{"uri":4221},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_fatigue/description.md",[4223],{"nodeType":1293,"value":4224,"marks":4225,"data":4227},"MFA fatigue",[4226],{"type":1382},{},{"nodeType":1293,"value":4229,"marks":4230,"data":4231}," and ",[],{},{"nodeType":1384,"data":4233,"content":4235},{"uri":4234},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_downgrade/description.md",[4236],{"nodeType":1293,"value":4237,"marks":4238,"data":4240},"MFA downgrade",[4239],{"type":1382},{},{"nodeType":1293,"value":4242,"marks":4243,"data":4244}," attacks.  ",[],{},{"nodeType":1484,"data":4246,"content":4247},{},[4248],{"nodeType":1293,"value":4249,"marks":4250,"data":4252},"4. Support the use of domain-bound credentials (whether in the form of a passkey or MFA method) that are phishing resistant (FIDO key).",[4251],{"type":1460},{},{"nodeType":1294,"data":4254,"content":4255},{},[4256,4260,4269],{"nodeType":1293,"value":4257,"marks":4258,"data":4259},"It’s no longer the case that simply having MFA is enough to stop identity attacks. The vast majority of phishing campaigns now make use of ",[],{},{"nodeType":1384,"data":4261,"content":4263},{"uri":4262},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/aitm_phishing/description.md",[4264],{"nodeType":1293,"value":4265,"marks":4266,"data":4268},"AitM toolkits designed to bypass MFA",[4267],{"type":1382},{},{"nodeType":1293,"value":4270,"marks":4271,"data":4272},". The only MFA methods considered to be phishing resistant are those using device-bound authentication methods such as passkeys/WebAuthn. However, only a handful of apps actually support these authentication methods. While the majority of SSO apps do support them, apps should provide support locally as well, particularly for B2C use-cases where enterprise SSO isn’t being used. ",[],{},{"nodeType":1484,"data":4274,"content":4275},{},[4276],{"nodeType":1293,"value":4277,"marks":4278,"data":4280},"5. Allow active sessions to be viewed and remotely terminated by administrators.",[4279],{"type":1460},{},{"nodeType":1294,"data":4282,"content":4283},{},[4284,4288,4297],{"nodeType":1293,"value":4285,"marks":4286,"data":4287},"Most apps have no way of viewing valid sessions and session activity, even as an administrator. With session hijacking attacks using ",[],{},{"nodeType":1384,"data":4289,"content":4291},{"uri":4290},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/session_cookie_theft/description.md",[4292],{"nodeType":1293,"value":4293,"marks":4294,"data":4296},"stolen session cookies",[4295],{"type":1382},{},{"nodeType":1293,"value":4298,"marks":4299,"data":4300}," on the rise, being able to (at the very least) terminate sessions that are suspected to have been compromised is key to effective incident response. In an ideal world, you would be able to view the properties of the session (such as the browser, IP, location that the session is being accessed from) to identify unusual or suspicious activity, which could in turn be leveraged by SecOps teams for their detection workflows. ",[],{},{"nodeType":1484,"data":4302,"content":4303},{},[4304],{"nodeType":1293,"value":4305,"marks":4306,"data":4308},"6. Allow admins to prevent users with a matching domain from auto-joining a company tenant without being invited or approved by an admin, and notify when they do. ",[4307],{"type":1460},{},{"nodeType":1294,"data":4310,"content":4311},{},[4312],{"nodeType":1293,"value":4313,"marks":4314,"data":4315},"Many apps do not provide the level of granular permissions that we’ve come to associate with enterprise cloud platforms — often because it simply isn’t necessary. This means that a lot of the time, the average user can access most, if not all of the data stored within an app. This is problematic if any user with a matching domain can join a company’s app tenant. This creates insider risk, as well as increasing the blast radius of ATO of an IdP account in terms of affected apps — it’s not just the apps they’re actively using, but any they can sign up to as well. ",[],{},{"nodeType":1520,"data":4317,"content":4321},{"target":4318},{"sys":4319},{"id":4320,"type":1517,"linkType":1518},"SKchIQFHSWumQsORBYNs5",[],{"nodeType":1294,"data":4323,"content":4324},{},[4325],{"nodeType":1293,"value":4326,"marks":4327,"data":4328},"To address this, apps should allow admins to lock down their app tenant to be invite-only should they desire (and enable it by default), and at least issue email notifications to admins whenever a new user joins the company’s app tenant — prompting the admin to check that the event is expected. ",[],{},{"nodeType":1400,"data":4330,"content":4331},{},[],{"nodeType":1408,"data":4333,"content":4334},{},[4335],{"nodeType":1293,"value":4336,"marks":4337,"data":4339},"Enable security teams to detect and respond to identity attacks",[4338],{"type":1460},{},{"nodeType":1294,"data":4341,"content":4342},{},[4343,4347,4356],{"nodeType":1293,"value":4344,"marks":4345,"data":4346},"Security teams required to respond to incidents affecting SaaS apps are ",[],{},{"nodeType":1384,"data":4348,"content":4350},{"uri":4349},"https://mayakaczorowski.com/blogs/what-sucks-in-security",[4351],{"nodeType":1293,"value":4352,"marks":4353,"data":4355},"united in how painful it is",[4354],{"type":1382},{},{"nodeType":1293,"value":4357,"marks":4358,"data":4359},": ",[],{},{"nodeType":1389,"data":4361,"content":4362},{},[4363,4386,4396,4406],{"nodeType":1353,"data":4364,"content":4365},{},[4366],{"nodeType":1294,"data":4367,"content":4368},{},[4369,4373,4382],{"nodeType":1293,"value":4370,"marks":4371,"data":4372},"Many SaaS providers don’t offer audit logs at all (",[],{},{"nodeType":1384,"data":4374,"content":4376},{"uri":4375},"https://audit-logs.tax/",[4377],{"nodeType":1293,"value":4378,"marks":4379,"data":4381},"or charge extra for the privilege",[4380],{"type":1382},{},{"nodeType":1293,"value":4383,"marks":4384,"data":4385},"). ",[],{},{"nodeType":1353,"data":4387,"content":4388},{},[4389],{"nodeType":1294,"data":4390,"content":4391},{},[4392],{"nodeType":1293,"value":4393,"marks":4394,"data":4395},"Even when logs are available, they might be incomplete, like missing login events, or critical pieces of information in the event needed to decide whether it’s malicious or not.",[],{},{"nodeType":1353,"data":4397,"content":4398},{},[4399],{"nodeType":1294,"data":4400,"content":4401},{},[4402],{"nodeType":1293,"value":4403,"marks":4404,"data":4405},"The lack of standardization across tools creates ingestion challenges, with each app requiring custom development work.",[],{},{"nodeType":1353,"data":4407,"content":4408},{},[4409],{"nodeType":1294,"data":4410,"content":4411},{},[4412],{"nodeType":1293,"value":4413,"marks":4414,"data":4415},"The logs you really need can’t always be accessed programmatically. The provider might have them, but you’ll need to put in a request – that could take hours or days to respond to. ",[],{},{"nodeType":1294,"data":4417,"content":4418},{},[4419],{"nodeType":1293,"value":4420,"marks":4421,"data":4422},"All of this makes it very challenging to ingest meaningful security log data from SaaS and harness it for detection and response. Hours or days is an eternity when you’re in the midst of a live incident, and is inevitably going to result in a worse outcome for the business. ",[],{},{"nodeType":1294,"data":4424,"content":4425},{},[4426],{"nodeType":1293,"value":4427,"marks":4428,"data":4429},"MVSP specifies that authentication events should be logged (and for how long they should be stored), but practically there is little consistency in the types of event and the fields captured. App vendors should make sure that the data points they provide (and the format that logs are provided in) can be practically used by security teams. ",[],{},{"nodeType":1484,"data":4431,"content":4432},{},[4433],{"nodeType":1293,"value":4434,"marks":4435,"data":4437},"7. Log detailed authentication/login information.",[4436],{"type":1460},{},{"nodeType":1294,"data":4439,"content":4440},{},[4441],{"nodeType":1293,"value":4442,"marks":4443,"data":4444},"Authentication information is arguably the most important log source in the context of SaaS services which lack granular permissions management, because: ",[],{},{"nodeType":1389,"data":4446,"content":4447},{},[4448,4458],{"nodeType":1353,"data":4449,"content":4450},{},[4451],{"nodeType":1294,"data":4452,"content":4453},{},[4454],{"nodeType":1293,"value":4455,"marks":4456,"data":4457},"If you know a malicious user accessed the app, you can infer/assume the likely impact, and respond accordingly. ",[],{},{"nodeType":1353,"data":4459,"content":4460},{},[4461],{"nodeType":1294,"data":4462,"content":4463},{},[4464],{"nodeType":1293,"value":4465,"marks":4466,"data":4467},"Attacker behavior in-app is often indistinguishable from typical user behavior.",[],{},{"nodeType":1294,"data":4469,"content":4470},{},[4471],{"nodeType":1293,"value":4472,"marks":4473,"data":4474},"This means it’s vital to understand who accessed the app, at what time, and from where.",[],{},{"nodeType":1294,"data":4476,"content":4477},{},[4478,4481,4490],{"nodeType":1293,"value":3869,"marks":4479,"data":4480},[],{},{"nodeType":1384,"data":4482,"content":4484},{"uri":4483},"https://eventmaturitymatrix.com/#salesforce-real-time-event-monitoring-urieventstream",[4485],{"nodeType":1293,"value":4486,"marks":4487,"data":4489},"SaaS Event Maturity Matrix",[4488],{"type":1382},{},{"nodeType":1293,"value":4491,"marks":4492,"data":4493}," provides a great starting point when looking at the availability of authentication logs across different platforms. ",[],{},{"nodeType":1520,"data":4495,"content":4499},{"target":4496},{"sys":4497},{"id":4498,"type":1517,"linkType":1518},"4NppB8YnmXHIQjvLwx79JW",[],{"nodeType":1294,"data":4501,"content":4502},{},[4503],{"nodeType":1293,"value":4504,"marks":4505,"data":4506},"We recommend that all providers include the following Authentication and MFA Verification log fields:",[],{},{"nodeType":1520,"data":4508,"content":4512},{"target":4509},{"sys":4510},{"id":4511,"type":1517,"linkType":1518},"67uAYr6RA3DIr7mUCBgzyn",[],{"nodeType":1294,"data":4514,"content":4515},{},[4516],{"nodeType":1293,"value":4517,"marks":4518,"data":4519},"With this level of granular information it will be much easier for security teams to reliably differentiate malicious from legitimate access, independently or when combined with other data points:",[],{},{"nodeType":1389,"data":4521,"content":4522},{},[4523,4533,4543,4553,4563,4573],{"nodeType":1353,"data":4524,"content":4525},{},[4526],{"nodeType":1294,"data":4527,"content":4528},{},[4529],{"nodeType":1293,"value":4530,"marks":4531,"data":4532},"Identify suspicious logins due to location/impossible travel",[],{},{"nodeType":1353,"data":4534,"content":4535},{},[4536],{"nodeType":1294,"data":4537,"content":4538},{},[4539],{"nodeType":1293,"value":4540,"marks":4541,"data":4542},"Identify failed login attempts due to either credential or MFA failures, indicating possible credential stuffing attacks",[],{},{"nodeType":1353,"data":4544,"content":4545},{},[4546],{"nodeType":1294,"data":4547,"content":4548},{},[4549],{"nodeType":1293,"value":4550,"marks":4551,"data":4552},"Identify the IdP used to login to detect unapproved or unusual IdP logins (a possible indicator of cross-IdP impersonation)",[],{},{"nodeType":1353,"data":4554,"content":4555},{},[4556],{"nodeType":1294,"data":4557,"content":4558},{},[4559],{"nodeType":1293,"value":4560,"marks":4561,"data":4562},"Identify where an unexpected (less secure) MFA method is used, indicating a potential MFA downgrade attack",[],{},{"nodeType":1353,"data":4564,"content":4565},{},[4566],{"nodeType":1294,"data":4567,"content":4568},{},[4569],{"nodeType":1293,"value":4570,"marks":4571,"data":4572},"Detect risky changes to authentication such as initiating SAML configuration changes, tracking which user initiated it and when it completed",[],{},{"nodeType":1353,"data":4574,"content":4575},{},[4576],{"nodeType":1294,"data":4577,"content":4578},{},[4579],{"nodeType":1293,"value":4580,"marks":4581,"data":4582},"Differentiate active session location from the device/client/location of the original session (to detect session hijacking attacks)",[],{},{"nodeType":1484,"data":4584,"content":4585},{},[4586],{"nodeType":1293,"value":4587,"marks":4588,"data":4590},"8. Make audit logs available in a format and using a mechanism that is easy to ingest into common security tools. ",[4589],{"type":1460},{},{"nodeType":1294,"data":4592,"content":4593},{},[4594,4598,4607],{"nodeType":1293,"value":4595,"marks":4596,"data":4597},"Even where logs are available, security teams often have to wrestle with the format they are provided in to be able to make use of them. While JSON is pretty much the de facto standard nowadays, the absence of a common schema and field names is often the tricky part — complicated by the fact that there are multiple competing standards. At the very least, complying with at least one of the more established schemas (e.g. the ",[],{},{"nodeType":1384,"data":4599,"content":4601},{"uri":4600},"https://www.elastic.co/guide/en/ecs/current/ecs-reference.html",[4602],{"nodeType":1293,"value":4603,"marks":4604,"data":4606},"Elastic Common Schema",[4605],{"type":1382},{},{"nodeType":1293,"value":4608,"marks":4609,"data":4610},") will provide a level of standardisation to make things easier for security teams.",[],{},{"nodeType":1294,"data":4612,"content":4613},{},[4614],{"nodeType":1293,"value":4615,"marks":4616,"data":4617},"Arguably an even bigger challenge is pulling the events you actually need from the data — so making it possible to stream logs or access them programmatically to minimize collection delays is a key change that app developers can implement regardless of the schema used, that will make life easier for SecOps teams. With that in mind: ",[],{},{"nodeType":1389,"data":4619,"content":4620},{},[4621,4631],{"nodeType":1353,"data":4622,"content":4623},{},[4624],{"nodeType":1294,"data":4625,"content":4626},{},[4627],{"nodeType":1293,"value":4628,"marks":4629,"data":4630},"Login events indicating a potential identity attack should emit preconfigured webhook events to enable security teams to better detect and respond, (such as in the context of the use cases above). ",[],{},{"nodeType":1353,"data":4632,"content":4633},{},[4634],{"nodeType":1294,"data":4635,"content":4636},{},[4637],{"nodeType":1293,"value":4638,"marks":4639,"data":4640},"API access should also be provided to ensure that logs can be extracted to inform point-in-time investigations in the event of a suspected incident. (It’s no good if you have to request that certain logs be sent to you during a time-sensitive security incident.) ",[],{},{"nodeType":1400,"data":4642,"content":4643},{},[],{"nodeType":1408,"data":4645,"content":4646},{},[4647],{"nodeType":1293,"value":4648,"marks":4649,"data":4651},"Final thoughts",[4650],{"type":1460},{},{"nodeType":1294,"data":4653,"content":4654},{},[4655],{"nodeType":1293,"value":4656,"marks":4657,"data":4658},"The key takeaway here is that the scope for identity attacks and abuse could be significantly mitigated with a better standard of app-level controls. If you’re familiar with Push, you’ll recognize that many of our features compensate for these gaps in visibility and control — made necessary by the fact that so many apps don’t provide basic information about the accounts within your tenant, or give you any controls to manage authentication in accordance with your risk profile.",[],{},{"nodeType":1520,"data":4660,"content":4664},{"target":4661},{"sys":4662},{"id":4663,"type":1517,"linkType":1518},"2skTQlf4ssC083ilExzKPW",[],{"nodeType":1294,"data":4666,"content":4667},{},[4668],{"nodeType":1293,"value":4669,"marks":4670,"data":4671},"If you agree with us and think that stronger identity controls around authentication and security logging are needed, then consider adding these suggestions to your procurement requirements when on-boarding new apps and services. ",[],{},{"nodeType":1294,"data":4673,"content":4674},{},[4675,4678,4686],{"nodeType":1293,"value":37,"marks":4676,"data":4677},[],{},{"nodeType":1384,"data":4679,"content":4680},{"uri":2512},[4681],{"nodeType":1293,"value":4682,"marks":4683,"data":4685},"Book a demo",[4684],{"type":1382},{},{"nodeType":1293,"value":4687,"marks":4688,"data":4689}," to find out how Push can mitigate widespread application security gaps and secure your identity attack surface. ",[],{},{"nodeType":1520,"data":4691,"content":4695},{"target":4692},{"sys":4693},{"id":4694,"type":1517,"linkType":1518},"34OTFgwuW60VWzW4FAqwXi",[],{"nodeType":1294,"data":4697,"content":4698},{},[4699],{"nodeType":1293,"value":37,"marks":4700,"data":4701},[],{},{"entries":4703},{"hyperlink":4704,"inline":4705,"block":4706},[],[],[4707,4715,4720,4736,4750,4784,4810,4819,4826,4840],{"sys":4708,"__typename":4709,"type":4710,"ctaText":4711,"buttonLabel":4712,"buttonColour":4713,"buttonUrl":4714},{"id":3852},"CtaWidget","Custom","Get our latest ebook to learn about the evolution of identity attacks in 2024 and their role in public breaches. ","Download Now","sea blue","https://pushsecurity.com/resources/2024-identity-attacks",{"sys":4716,"__typename":4709,"type":4710,"ctaText":4717,"buttonLabel":4718,"buttonColour":4719,"buttonUrl":1854},{"id":3980},"Learn how Push provides defense in depth against identity attacks before account takeover.","Read the Blog","sunny orange",{"sys":4721,"__typename":4722,"content":4723,"name":4735,"title":118},{"id":4048},"InsightTextBlockComponent",{"json":4724},{"data":4725,"content":4726,"nodeType":1295},{},[4727],{"data":4728,"content":4729,"nodeType":1294},{},[4730],{"data":4731,"marks":4732,"value":4734,"nodeType":1293},{},[4733],{"type":1460},"If you don’t take anything else away from this piece, this control alone will get rid of 80% of the complexity and room for vulnerabilities to creep in. ","MVSI insight box",{"sys":4737,"__typename":4722,"content":4738,"name":4749,"title":118},{"id":4128},{"json":4739},{"nodeType":1295,"data":4740,"content":4741},{},[4742],{"nodeType":1294,"data":4743,"content":4744},{},[4745],{"nodeType":1293,"value":4746,"marks":4747,"data":4748},"Using SAMLjacking, an attacker can turn the compromise of a low risk app/identity into a much more serious one by using it to capture SSO credentials for other users of the app. ",[],{},"MVSI Insight box 2",{"sys":4751,"__typename":4722,"content":4752,"name":4783,"title":118},{"id":4196},{"json":4753},{"nodeType":1295,"data":4754,"content":4755},{},[4756],{"nodeType":1294,"data":4757,"content":4758},{},[4759,4763,4770,4774,4779],{"nodeType":1293,"value":4760,"marks":4761,"data":4762},"One of the leading causes of identity breaches is when ",[],{},{"nodeType":1384,"data":4764,"content":4765},{"uri":4066},[4766],{"nodeType":1293,"value":2337,"marks":4767,"data":4769},[4768],{"type":1382},{},{"nodeType":1293,"value":4771,"marks":4772,"data":4773}," (usually a weak, breached or reused password) exist alongside a more secure login method (e.g. SAML SSO). These ghost logins can be exploitable either as a single factor, or with a weak/phishable MFA method. It doesn’t matter if your employees ",[],{},{"nodeType":1293,"value":4775,"marks":4776,"data":4778},"typically",[4777],{"type":312},{},{"nodeType":1293,"value":4780,"marks":4781,"data":4782}," log in with SAML, if insecure local logins exist alongside it — because attackers can take advantage of this. ",[],{},"MVSI insight box 3",{"sys":4785,"__typename":4722,"content":4786,"name":4809,"title":118},{"id":4320},{"json":4787},{"nodeType":1295,"data":4788,"content":4789},{},[4790],{"nodeType":1294,"data":4791,"content":4792},{},[4793,4797,4805],{"nodeType":1293,"value":4794,"marks":4795,"data":4796},"You might assume that a user with access to an IdP account also has access to the email connected to that account, but as we’ve seen with ",[],{},{"nodeType":1384,"data":4798,"content":4799},{"uri":4085},[4800],{"nodeType":1293,"value":4801,"marks":4802,"data":4804},"cross-IdP impersonation",[4803],{"type":1382},{},{"nodeType":1293,"value":4806,"marks":4807,"data":4808},", this isn’t necessarily the case. ",[],{},"MVSI insight box 4",{"sys":4811,"__typename":4812,"title":4813,"caption":4814,"layoutMode":118,"file":4815},{"id":4498},"Image","MVSI: Example Okta login history logs","Example of Okta login history logs",{"url":4816,"width":4817,"height":4818},"https://images.ctfassets.net/y1cdw1ablpvd/2oRCAyYH72TfB2EsGxQDFK/325fceea5222e1404141e7ed89ba4b53/image1.png",1578,1418,{"sys":4820,"__typename":4812,"title":4821,"caption":118,"layoutMode":118,"file":4822},{"id":4511},"MVSI Recommended Logs",{"url":4823,"width":4824,"height":4825},"https://images.ctfassets.net/y1cdw1ablpvd/GWJoQawV0uYCn4vdVxcXy/00bae170edfc839c7e1f37427eb309c7/Screenshot_2025-02-10_at_12.00.14.png",1264,526,{"sys":4827,"__typename":4722,"content":4828,"name":4839,"title":118},{"id":4663},{"json":4829},{"nodeType":1295,"data":4830,"content":4831},{},[4832],{"nodeType":1294,"data":4833,"content":4834},{},[4835],{"nodeType":1293,"value":4836,"marks":4837,"data":4838},"This is certainly not intended as a definitive standard or exhaustive list of identity controls — but hopefully provides any app developers or standards authors with food for thought! We speak for other potential customers when we say that including these controls would make your app much more attractive to the security and compliance teams of prospective buyers. ",[],{},"MVSI insight box 5",{"sys":4841,"__typename":4709,"type":4710,"ctaText":4842,"buttonLabel":4843,"buttonColour":4844,"buttonUrl":2512},{"id":4694},"Book a demo to see how Push prevents and detects identity attacks across all apps your employees use. ","Book a Demo","orange","content:blog:minimum-viable-identity-security.json","json","content","blog/minimum-viable-identity-security.json","blog/minimum-viable-identity-security",1776359985840]