[{"data":1,"prerenderedAt":3803},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/our-design-philosophy-detecting-what-matters":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1297,"synopsis":1298,"hashTags":118,"publishedDate":1299,"slug":1300,"tagsCollection":1301,"relatedBlogPostsCollection":1311,"ogImage":3096,"authorsCollection":3098,"content":3106,"_id":3798,"_type":3799,"_source":3800,"_file":3801,"_stem":3802,"_extension":3799},"/blog/our-design-philosophy-detecting-what-matters","blog",{"id":1280,"publishedAt":1281},"1qegIy4rMdm5XZXnIEoKpE","2024-08-16T12:39:31.739Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"This is the first blog in a short series we’re putting together about the ‘why’ behind the ‘what’ at Push. This entry is focused on threat detection: Let’s get started. ","text","paragraph","document","Our design philosophy: Detecting what matters","Our approach to threat detection controls","This is the first blog in a short series we’re putting together about the ‘why’ behind the ‘what’ at Push. This entry is focused on threat detection. ","2024-08-05T00:00:00.000Z","our-design-philosophy-detecting-what-matters",{"items":1302},[1303,1307],{"sys":1304,"name":1306},{"id":1305},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"sys":1308,"name":1310},{"id":1309},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":1312},[1313,2144,2669],{"__typename":1314,"sys":1315,"content":1317,"title":2124,"synopsis":2125,"hashTags":118,"publishedDate":2126,"slug":2127,"tagsCollection":2128,"authorsCollection":2136},"BlogPosts",{"id":1316},"20FcoPvHu7zXkTQyv9MmK0",{"json":1318},{"nodeType":1295,"data":1319,"content":1320},{},[1321,1330,1337,1391,1398,1405,1422,1429,1436,1524,1531,1537,1545,1552,1567,1574,1582,1606,1631,1637,1657,1664,1671,1702,1709,1716,1722,1740,1747,1754,1761,1768,1774,1792,1799,1806,1813,1820,1826,1845,1852,1859,1865,1884,1891,1898,1905,1953,1960,2031,2046,2052,2059,2066,2073,2080,2098,2105],{"nodeType":1322,"data":1323,"content":1329},"embedded-entry-block",{"target":1324},{"sys":1325},{"id":1326,"type":1327,"linkType":1328},"7rud2H1hcTAOhxh9zHzxP6","Link","Entry",[],{"nodeType":1294,"data":1331,"content":1332},{},[1333],{"nodeType":1293,"value":1334,"marks":1335,"data":1336},"If someone asked you where you work, you probably wouldn’t answer, “My browser.” But that would be the truth.",[],{},{"nodeType":1294,"data":1338,"content":1339},{},[1340,1344,1353,1357,1365,1368,1376,1379,1387],{"nodeType":1293,"value":1341,"marks":1342,"data":1343},"(Threat actors already know where you work, of course, and they’ve been capitalizing on the massive shift to cloud-based workforces. Just look at any of the ",[],{},{"nodeType":1345,"data":1346,"content":1348},"hyperlink",{"uri":1347},"https://www.crowdstrike.com/global-threat-report/",[1349],{"nodeType":1293,"value":1350,"marks":1351,"data":1352},"latest",[],{},{"nodeType":1293,"value":1354,"marks":1355,"data":1356}," ",[],{},{"nodeType":1345,"data":1358,"content":1360},{"uri":1359},"https://redcanary.com/threat-detection-report/techniques/cloud-accounts/",[1361],{"nodeType":1293,"value":1362,"marks":1363,"data":1364},"threat",[],{},{"nodeType":1293,"value":1354,"marks":1366,"data":1367},[],{},{"nodeType":1345,"data":1369,"content":1371},{"uri":1370},"https://www.verizon.com/business/resources/reports/dbir/",[1372],{"nodeType":1293,"value":1373,"marks":1374,"data":1375},"research",[],{},{"nodeType":1293,"value":1354,"marks":1377,"data":1378},[],{},{"nodeType":1345,"data":1380,"content":1382},{"uri":1381},"https://www.lab539.com/blog/6-months-tracking-aitm-campaigns",[1383],{"nodeType":1293,"value":1384,"marks":1385,"data":1386},"reports",[],{},{"nodeType":1293,"value":1388,"marks":1389,"data":1390}," on identity-based attacks to see how good a job they’ve been doing.)",[],{},{"nodeType":1294,"data":1392,"content":1393},{},[1394],{"nodeType":1293,"value":1395,"marks":1396,"data":1397},"To get visibility of your infrastructure in order to build a strong detection and response program, the equation used to look something like:",[],{},{"nodeType":1294,"data":1399,"content":1400},{},[1401],{"nodeType":1293,"value":1402,"marks":1403,"data":1404},"Network traffic + Logs + Endpoints = Profit!",[],{},{"nodeType":1294,"data":1406,"content":1407},{},[1408,1412,1418],{"nodeType":1293,"value":1409,"marks":1410,"data":1411},"But now there’s a missing piece, as identity infrastructure sprawls across IdPs, core apps, shadow SaaS and third-party integrations: ",[],{},{"nodeType":1293,"value":1413,"marks":1414,"data":1417},"Browser telemetry",[1415],{"type":1416},"bold",{},{"nodeType":1293,"value":1419,"marks":1420,"data":1421},".",[],{},{"nodeType":1294,"data":1423,"content":1424},{},[1425],{"nodeType":1293,"value":1426,"marks":1427,"data":1428},"As a browser agent, Push is uniquely positioned to provide telemetry you can’t easily get anywhere else. We believe that this missing piece is the key to stopping identity attacks by providing the context both for first-class detections and security controls, as well as key correlations for events you observe in traditional log sources.",[],{},{"nodeType":1294,"data":1430,"content":1431},{},[1432],{"nodeType":1293,"value":1433,"marks":1434,"data":1435},"Now we have a better way to bring Push’s data to life to solve meaningful security challenges:",[],{},{"nodeType":1437,"data":1438,"content":1439},"unordered-list",{},[1440,1472],{"nodeType":1441,"data":1442,"content":1443},"list-item",{},[1444],{"nodeType":1294,"data":1445,"content":1446},{},[1447,1452,1456,1468],{"nodeType":1293,"value":1448,"marks":1449,"data":1451},"Plug-and-play security controls",[1450],{"type":1416},{},{"nodeType":1293,"value":1453,"marks":1454,"data":1455},", accessible from the new ",[],{},{"nodeType":1457,"data":1458,"content":1462},"entry-hyperlink",{"target":1459},{"sys":1460},{"id":1461,"type":1327,"linkType":1328},"BtDLgVZRWQ3Ov4WgDQX1W",[1463],{"nodeType":1293,"value":1464,"marks":1465,"data":1467},"Controls",[1466],{"type":1416},{},{"nodeType":1293,"value":1469,"marks":1470,"data":1471}," page in the Push platform",[],{},{"nodeType":1441,"data":1473,"content":1474},{},[1475],{"nodeType":1294,"data":1476,"content":1477},{},[1478,1483,1487,1495,1499,1507,1511,1520],{"nodeType":1293,"value":1479,"marks":1480,"data":1482},"Choose-your-own-adventure tooling",[1481],{"type":1416},{},{"nodeType":1293,"value":1484,"marks":1485,"data":1486},", including a ",[],{},{"nodeType":1345,"data":1488,"content":1490},{"uri":1489},"https://pushsecurity.redoc.ly/rest-v1/",[1491],{"nodeType":1293,"value":1492,"marks":1493,"data":1494},"REST API",[],{},{"nodeType":1293,"value":1496,"marks":1497,"data":1498},", ",[],{},{"nodeType":1345,"data":1500,"content":1502},{"uri":1501},"https://pushsecurity.redoc.ly/webhooks-v1/",[1503],{"nodeType":1293,"value":1504,"marks":1505,"data":1506},"webhooks",[],{},{"nodeType":1293,"value":1508,"marks":1509,"data":1510},", and a new ",[],{},{"nodeType":1345,"data":1512,"content":1514},{"uri":1513},"/help/audience/administrators/docs/connect-to-siem-or-soar/#using-the-events-page",[1515],{"nodeType":1293,"value":1516,"marks":1517,"data":1519},"Events",[1518],{"type":1416},{},{"nodeType":1293,"value":1521,"marks":1522,"data":1523}," page to help you visualize and build custom detections and automations.",[],{},{"nodeType":1294,"data":1525,"content":1526},{},[1527],{"nodeType":1293,"value":1528,"marks":1529,"data":1530},"Let’s take a closer look.",[],{},{"nodeType":1322,"data":1532,"content":1536},{"target":1533},{"sys":1534},{"id":1535,"type":1327,"linkType":1328},"6iKFd9Qys2SSuNqKVQB7ka",[],{"nodeType":1538,"data":1539,"content":1540},"heading-1",{},[1541],{"nodeType":1293,"value":1542,"marks":1543,"data":1544},"Plug-and-play controls",[],{},{"nodeType":1294,"data":1546,"content":1547},{},[1548],{"nodeType":1293,"value":1549,"marks":1550,"data":1551},"Security visibility without security control is a recipe for a stress headache, so we’re big believers in providing meaningful interventions that are easy to use.",[],{},{"nodeType":1294,"data":1553,"content":1554},{},[1555,1559,1563],{"nodeType":1293,"value":1556,"marks":1557,"data":1558},"With the new ",[],{},{"nodeType":1293,"value":1464,"marks":1560,"data":1562},[1561],{"type":1416},{},{"nodeType":1293,"value":1564,"marks":1565,"data":1566}," page in the Push admin console, you can now find these preconfigured detections and interventions in one place. They cover use cases that any organization can benefit from, and take a unique browser-based approach to solving some thorny issues.",[],{},{"nodeType":1294,"data":1568,"content":1569},{},[1570],{"nodeType":1293,"value":1571,"marks":1572,"data":1573},"These controls include:",[],{},{"nodeType":1575,"data":1576,"content":1577},"heading-2",{},[1578],{"nodeType":1293,"value":1579,"marks":1580,"data":1581},"Phishing tool detection",[],{},{"nodeType":1294,"data":1583,"content":1584},{},[1585,1589,1594,1598,1603],{"nodeType":1293,"value":1586,"marks":1587,"data":1588},"Detect and block when employees visit webpages that use advanced phishing tools such as Evilginx or EvilNoVNC, among others. These adversary-in-the-middle (AitM) toolkits can mimic legitimate login screens, such as an Okta login page, to steal ",[],{},{"nodeType":1293,"value":1590,"marks":1591,"data":1593},"credentials",[1592],{"type":1416},{},{"nodeType":1293,"value":1595,"marks":1596,"data":1597}," and ",[],{},{"nodeType":1293,"value":1599,"marks":1600,"data":1602},"MFA codes",[1601],{"type":1416},{},{"nodeType":1293,"value":1419,"marks":1604,"data":1605},[],{},{"nodeType":1294,"data":1607,"content":1608},{},[1609,1613,1618,1622,1627],{"nodeType":1293,"value":1610,"marks":1611,"data":1612},"Push emits a webhook event when the browser agent detects attributes of these malware. You can also set Push to ",[],{},{"nodeType":1293,"value":1614,"marks":1615,"data":1617},"Warn",[1616],{"type":1416},{},{"nodeType":1293,"value":1619,"marks":1620,"data":1621}," or ",[],{},{"nodeType":1293,"value":1623,"marks":1624,"data":1626},"Block",[1625],{"type":1416},{},{"nodeType":1293,"value":1628,"marks":1629,"data":1630}," mode to display a customizable message to end-users when they encounter a phishing site.",[],{},{"nodeType":1322,"data":1632,"content":1636},{"target":1633},{"sys":1634},{"id":1635,"type":1327,"linkType":1328},"2ylIkR0JXHkFStGuCFRjlN",[],{"nodeType":1294,"data":1638,"content":1639},{},[1640,1644,1654],{"nodeType":1293,"value":1641,"marks":1642,"data":1643},"More about ",[],{},{"nodeType":1457,"data":1645,"content":1649},{"target":1646},{"sys":1647},{"id":1648,"type":1327,"linkType":1328},"7KRnTSnJAbbiho69gNyN0B",[1650],{"nodeType":1293,"value":1651,"marks":1652,"data":1653},"phishing tool detection",[],{},{"nodeType":1293,"value":37,"marks":1655,"data":1656},[],{},{"nodeType":1575,"data":1658,"content":1659},{},[1660],{"nodeType":1293,"value":1661,"marks":1662,"data":1663},"SSO password protection",[],{},{"nodeType":1294,"data":1665,"content":1666},{},[1667],{"nodeType":1293,"value":1668,"marks":1669,"data":1670},"Prevent employees from reusing their corporate SSO password on any page that doesn’t belong to the identity provider, including phishing sites. This means that even if that employee was the first person to get phished using a new attacker site, Push still detects it and blocks it.",[],{},{"nodeType":1294,"data":1672,"content":1673},{},[1674,1678,1682,1685,1689,1693,1698],{"nodeType":1293,"value":1675,"marks":1676,"data":1677},"Customize the message that end-users see in ",[],{},{"nodeType":1293,"value":1614,"marks":1679,"data":1681},[1680],{"type":1416},{},{"nodeType":1293,"value":1619,"marks":1683,"data":1684},[],{},{"nodeType":1293,"value":1623,"marks":1686,"data":1688},[1687],{"type":1416},{},{"nodeType":1293,"value":1690,"marks":1691,"data":1692}," mode, or start out in ",[],{},{"nodeType":1293,"value":1694,"marks":1695,"data":1697},"Monitor",[1696],{"type":1416},{},{"nodeType":1293,"value":1699,"marks":1700,"data":1701}," mode to catch any false positives before you enforce the control.",[],{},{"nodeType":1294,"data":1703,"content":1704},{},[1705],{"nodeType":1293,"value":1706,"marks":1707,"data":1708},"This feature supports the following identity providers: Okta, Microsoft 365, Google Workspace, JumpCloud, Duo, and Ping Identity.",[],{},{"nodeType":1294,"data":1710,"content":1711},{},[1712],{"nodeType":1293,"value":1713,"marks":1714,"data":1715},"Push will also emit a webhook event when an SSO password is used, and if an employee clicks through the warning screen.",[],{},{"nodeType":1322,"data":1717,"content":1721},{"target":1718},{"sys":1719},{"id":1720,"type":1327,"linkType":1328},"25c8M2gWYFST7yYxGEji2s",[],{"nodeType":1294,"data":1723,"content":1724},{},[1725,1728,1737],{"nodeType":1293,"value":1641,"marks":1726,"data":1727},[],{},{"nodeType":1457,"data":1729,"content":1733},{"target":1730},{"sys":1731},{"id":1732,"type":1327,"linkType":1328},"6FYHbkcRUrtznPo7RarRsz",[1734],{"nodeType":1293,"value":1661,"marks":1735,"data":1736},[],{},{"nodeType":1293,"value":37,"marks":1738,"data":1739},[],{},{"nodeType":1575,"data":1741,"content":1742},{},[1743],{"nodeType":1293,"value":1744,"marks":1745,"data":1746},"URL blocking",[],{},{"nodeType":1294,"data":1748,"content":1749},{},[1750],{"nodeType":1293,"value":1751,"marks":1752,"data":1753},"When you find malicious sites you want to block, such as when responding to a phishing incident, add them to a blocklist and prevent other employees from accessing those sites. ",[],{},{"nodeType":1294,"data":1755,"content":1756},{},[1757],{"nodeType":1293,"value":1758,"marks":1759,"data":1760},"URL blocking can be used in tandem with Push’s anti-phishing controls, so that as you discover malicious sites, you can block them from a central blocklist. This offers a kind of herd immunity where you can block other users from visiting a malicious site as soon as you have a single incident.",[],{},{"nodeType":1294,"data":1762,"content":1763},{},[1764],{"nodeType":1293,"value":1765,"marks":1766,"data":1767},"You can programmatically manage the blocklist using the Push REST API or sync to other threat intelligence sources you consume.",[],{},{"nodeType":1322,"data":1769,"content":1773},{"target":1770},{"sys":1771},{"id":1772,"type":1327,"linkType":1328},"3m00cFiUDAnddsOBOpkeiZ",[],{"nodeType":1294,"data":1775,"content":1776},{},[1777,1780,1789],{"nodeType":1293,"value":1641,"marks":1778,"data":1779},[],{},{"nodeType":1457,"data":1781,"content":1785},{"target":1782},{"sys":1783},{"id":1784,"type":1327,"linkType":1328},"P0coHgQAdRL0YTu4Rwd4z",[1786],{"nodeType":1293,"value":1744,"marks":1787,"data":1788},[],{},{"nodeType":1293,"value":37,"marks":1790,"data":1791},[],{},{"nodeType":1575,"data":1793,"content":1794},{},[1795],{"nodeType":1293,"value":1796,"marks":1797,"data":1798},"Session token theft detection",[],{},{"nodeType":1294,"data":1800,"content":1801},{},[1802],{"nodeType":1293,"value":1803,"marks":1804,"data":1805},"Inject a unique marker provided by the Push browser agent into the User Agent string of sessions that occur in browsers enrolled in Push. ",[],{},{"nodeType":1294,"data":1807,"content":1808},{},[1809],{"nodeType":1293,"value":1810,"marks":1811,"data":1812},"By analyzing logs from your IdP, you can identify activity from the same session that both has the Push marker and that lacks the marker. This can only ever happen when a session is extracted from a browser and maliciously imported into a different browser.",[],{},{"nodeType":1294,"data":1814,"content":1815},{},[1816],{"nodeType":1293,"value":1817,"marks":1818,"data":1819},"This is a high-fidelity signal that a session token has been stolen and is being used.",[],{},{"nodeType":1322,"data":1821,"content":1825},{"target":1822},{"sys":1823},{"id":1824,"type":1327,"linkType":1328},"43rk3TCqN269Vr2YWT4llP",[],{"nodeType":1294,"data":1827,"content":1828},{},[1829,1832,1842],{"nodeType":1293,"value":1641,"marks":1830,"data":1831},[],{},{"nodeType":1457,"data":1833,"content":1837},{"target":1834},{"sys":1835},{"id":1836,"type":1327,"linkType":1328},"1UMZdjyNQt4Y7NBb2wuK4L",[1838],{"nodeType":1293,"value":1839,"marks":1840,"data":1841},"session token theft detection",[],{},{"nodeType":1293,"value":37,"marks":1843,"data":1844},[],{},{"nodeType":1575,"data":1846,"content":1847},{},[1848],{"nodeType":1293,"value":1849,"marks":1850,"data":1851},"App banners",[],{},{"nodeType":1294,"data":1853,"content":1854},{},[1855],{"nodeType":1293,"value":1856,"marks":1857,"data":1858},"Add guardrails to employees’ use of SaaS apps with in-browser app banner messages you customize with your own text. You can require users to acknowledge having read a message before they can access an app, or even require them to submit a reason for using an app before they can log in.",[],{},{"nodeType":1322,"data":1860,"content":1864},{"target":1861},{"sys":1862},{"id":1863,"type":1327,"linkType":1328},"5nEKTBz6mauHI5mg8jB4ea",[],{"nodeType":1294,"data":1866,"content":1867},{},[1868,1871,1881],{"nodeType":1293,"value":1641,"marks":1869,"data":1870},[],{},{"nodeType":1457,"data":1872,"content":1876},{"target":1873},{"sys":1874},{"id":1875,"type":1327,"linkType":1328},"2ZpKnuljaUH0jzVaae4SMN",[1877],{"nodeType":1293,"value":1878,"marks":1879,"data":1880},"app banners",[],{},{"nodeType":1293,"value":37,"marks":1882,"data":1883},[],{},{"nodeType":1538,"data":1885,"content":1886},{},[1887],{"nodeType":1293,"value":1888,"marks":1889,"data":1890},"Choose your own adventure",[],{},{"nodeType":1294,"data":1892,"content":1893},{},[1894],{"nodeType":1293,"value":1895,"marks":1896,"data":1897},"Want to do something creative? We've got you covered. Push provides a wealth of raw telemetry via the Push REST API and webhook events. Use this data to build both proactive and reactive security operations workflows, or add missing context to other sources, such as your IdP, application, or endpoint logs.",[],{},{"nodeType":1294,"data":1899,"content":1900},{},[1901],{"nodeType":1293,"value":1902,"marks":1903,"data":1904},"You can use this browser telemetry to:",[],{},{"nodeType":1437,"data":1906,"content":1907},{},[1908,1923,1938],{"nodeType":1441,"data":1909,"content":1910},{},[1911],{"nodeType":1294,"data":1912,"content":1913},{},[1914,1919],{"nodeType":1293,"value":1915,"marks":1916,"data":1918},"Harden identities and reduce account compromise",[1917],{"type":1416},{},{"nodeType":1293,"value":1920,"marks":1921,"data":1922},", such as alerting you when passwords are identified in public data breaches or when employees are using an unapproved app or when an SSO app is accessed via local account.",[],{},{"nodeType":1441,"data":1924,"content":1925},{},[1926],{"nodeType":1294,"data":1927,"content":1928},{},[1929,1934],{"nodeType":1293,"value":1930,"marks":1931,"data":1933},"Monitor for suspicious activity or high-risk changes",[1932],{"type":1416},{},{"nodeType":1293,"value":1935,"marks":1936,"data":1937},", such as checking for MFA method changes, or flagging when employees reuse corporate SSO passwords or visit sites running phishing malware.",[],{},{"nodeType":1441,"data":1939,"content":1940},{},[1941],{"nodeType":1294,"data":1942,"content":1943},{},[1944,1949],{"nodeType":1293,"value":1945,"marks":1946,"data":1948},"Investigate indicators of compromise",[1947],{"type":1416},{},{"nodeType":1293,"value":1950,"marks":1951,"data":1952},", such as correlating login events with platform logs, searching for recent signups to risky apps, or identifying post-compromise lateral movement opportunities.",[],{},{"nodeType":1294,"data":1954,"content":1955},{},[1956],{"nodeType":1293,"value":1957,"marks":1958,"data":1959},"In the “make my life easier” category, you can also use Push telemetry to:",[],{},{"nodeType":1437,"data":1961,"content":1962},{},[1963,1982,2001,2016],{"nodeType":1441,"data":1964,"content":1965},{},[1966],{"nodeType":1294,"data":1967,"content":1968},{},[1969,1973,1978],{"nodeType":1293,"value":1970,"marks":1971,"data":1972},"Automate a workflow ",[],{},{"nodeType":1293,"value":1974,"marks":1975,"data":1977},"showing you all the accounts and apps used by an offboarded employee",[1976],{"type":1416},{},{"nodeType":1293,"value":1979,"marks":1980,"data":1981},", and their account login methods.",[],{},{"nodeType":1441,"data":1983,"content":1984},{},[1985],{"nodeType":1294,"data":1986,"content":1987},{},[1988,1992,1997],{"nodeType":1293,"value":1989,"marks":1990,"data":1991},"Automate a workflow to",[],{},{"nodeType":1293,"value":1993,"marks":1994,"data":1996}," revoke licenses on SaaS after a period of inactivity",[1995],{"type":1416},{},{"nodeType":1293,"value":1998,"marks":1999,"data":2000},", saving money.",[],{},{"nodeType":1441,"data":2002,"content":2003},{},[2004],{"nodeType":1294,"data":2005,"content":2006},{},[2007,2012],{"nodeType":1293,"value":2008,"marks":2009,"data":2011},"Build an approved apps list in your company wiki",[2010],{"type":1416},{},{"nodeType":1293,"value":2013,"marks":2014,"data":2015},", synced from Push’s source of truth.",[],{},{"nodeType":1441,"data":2017,"content":2018},{},[2019],{"nodeType":1294,"data":2020,"content":2021},{},[2022,2027],{"nodeType":1293,"value":2023,"marks":2024,"data":2026},"Force-reset an IdP password if Push finds a compromised password",[2025],{"type":1416},{},{"nodeType":1293,"value":2028,"marks":2029,"data":2030}," on an employee account.",[],{},{"nodeType":1294,"data":2032,"content":2033},{},[2034,2038,2042],{"nodeType":1293,"value":2035,"marks":2036,"data":2037},"To help you visualize and plan how you will use this telemetry, Push also provides an ",[],{},{"nodeType":1293,"value":1516,"marks":2039,"data":2041},[2040],{"type":1416},{},{"nodeType":1293,"value":2043,"marks":2044,"data":2045}," page in the admin console with a rolling 7-day snapshot of all the events in your environment.",[],{},{"nodeType":1322,"data":2047,"content":2051},{"target":2048},{"sys":2049},{"id":2050,"type":1327,"linkType":1328},"2a3bJ5sN8dJ0c1kQtZiag7",[],{"nodeType":1294,"data":2053,"content":2054},{},[2055],{"nodeType":1293,"value":2056,"marks":2057,"data":2058},"The Events page can help you see real-world examples, understand the attributes of each event, and gauge event volume before you ingest data into a SIEM or other platform.",[],{},{"nodeType":1538,"data":2060,"content":2061},{},[2062],{"nodeType":1293,"value":2063,"marks":2064,"data":2065},"What if you don’t have a SIEM?",[],{},{"nodeType":1294,"data":2067,"content":2068},{},[2069],{"nodeType":1293,"value":2070,"marks":2071,"data":2072},"While you’d need a SIEM for writing detections and performing log correlations, you can still get a lot of value out of Push telemetry if you don’t have one.",[],{},{"nodeType":1294,"data":2074,"content":2075},{},[2076],{"nodeType":1293,"value":2077,"marks":2078,"data":2079},"Use Push’s webhook events to send alerts directly to your Slack, Teams, or other chat platform, or build workflows that hook into your ticketing system or SOAR platform.",[],{},{"nodeType":1294,"data":2081,"content":2082},{},[2083,2087,2094],{"nodeType":1293,"value":2084,"marks":2085,"data":2086},"Review our ",[],{},{"nodeType":1345,"data":2088,"content":2089},{"uri":1501},[2090],{"nodeType":1293,"value":2091,"marks":2092,"data":2093},"webhooks documentation",[],{},{"nodeType":1293,"value":2095,"marks":2096,"data":2097}," for a list of events.",[],{},{"nodeType":1538,"data":2099,"content":2100},{},[2101],{"nodeType":1293,"value":2102,"marks":2103,"data":2104},"Find out more",[],{},{"nodeType":1294,"data":2106,"content":2107},{},[2108,2112,2120],{"nodeType":1293,"value":2109,"marks":2110,"data":2111},"If you want to see Push in action, ",[],{},{"nodeType":1345,"data":2113,"content":2115},{"uri":2114},"/demo/",[2116],{"nodeType":1293,"value":2117,"marks":2118,"data":2119},"book a demo",[],{},{"nodeType":1293,"value":2121,"marks":2122,"data":2123},". We’ll be happy to show you these features, along with how we discover all the apps your employees are using — even the ones not behind SSO.",[],{},"Introducing set-and-forget controls that stop real-world identity attacks","Enable detections and interventions in the browser using Push’s new security controls.","2024-07-02T00:00:00.000Z","introducing-set-and-forget-controls-that-stop-real-world-identity-attacks",{"items":2129},[2130,2134],{"sys":2131,"name":2133},{"id":2132},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"sys":2135,"name":1306},{"id":1305},{"items":2137},[2138],{"fullName":2139,"firstName":2140,"jobTitle":2141,"profilePicture":2142},"Kelly Davenport","Kelly","Product Team",{"url":2143},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1314,"sys":2145,"content":2147,"title":2655,"synopsis":2656,"hashTags":118,"publishedDate":2657,"slug":2658,"tagsCollection":2659,"authorsCollection":2665},{"id":2146},"6Uvqu6LcWzOVfA9mxtu841",{"json":2148},{"nodeType":1295,"data":2149,"content":2150},{},[2151,2157,2164,2197,2204,2225,2232,2278,2285,2292,2299,2305,2312,2401,2408,2415,2438,2445,2452,2459,2466,2473,2480,2531,2538,2544,2562,2568,2575,2595,2602,2609,2616,2623,2630,2636],{"nodeType":1322,"data":2152,"content":2156},{"target":2153},{"sys":2154},{"id":2155,"type":1327,"linkType":1328},"2HffP4X7owzpfj41jnzXmV",[],{"nodeType":1294,"data":2158,"content":2159},{},[2160],{"nodeType":1293,"value":2161,"marks":2162,"data":2163},"To detect session token theft, you need three things:",[],{},{"nodeType":1437,"data":2165,"content":2166},{},[2167,2177,2187],{"nodeType":1441,"data":2168,"content":2169},{},[2170],{"nodeType":1294,"data":2171,"content":2172},{},[2173],{"nodeType":1293,"value":2174,"marks":2175,"data":2176},"Robust logs that provide an identifier to help tie activity to a specific session",[],{},{"nodeType":1441,"data":2178,"content":2179},{},[2180],{"nodeType":1294,"data":2181,"content":2182},{},[2183],{"nodeType":1293,"value":2184,"marks":2185,"data":2186},"A well-oiled SOC to correlate observed activity in those logs",[],{},{"nodeType":1441,"data":2188,"content":2189},{},[2190],{"nodeType":1294,"data":2191,"content":2192},{},[2193],{"nodeType":1293,"value":2194,"marks":2195,"data":2196},"And telemetry to tie those logs to a trusted endpoint",[],{},{"nodeType":1294,"data":2198,"content":2199},{},[2200],{"nodeType":1293,"value":2201,"marks":2202,"data":2203},"The only problem? That third thing didn’t really exist. So we created it.",[],{},{"nodeType":1294,"data":2205,"content":2206},{},[2207,2211,2221],{"nodeType":1293,"value":2208,"marks":2209,"data":2210},"In this article, we’ll cover how Push’s recently released ",[],{},{"nodeType":1345,"data":2212,"content":2214},{"uri":2213},"https://pushsecurity.com/help/10114#start",[2215],{"nodeType":1293,"value":2216,"marks":2217,"data":2220},"session theft detection",[2218],{"type":2219},"underline",{},{"nodeType":1293,"value":2222,"marks":2223,"data":2224}," feature works, why we built it, and why the unique control point provided by a browser agent unlocks new capabilities for blue teams fighting the effects of infostealer malware and other stolen credential-based attacks.",[],{},{"nodeType":1538,"data":2226,"content":2227},{},[2228],{"nodeType":1293,"value":2229,"marks":2230,"data":2231},"(You probably already know) Why this matters",[],{},{"nodeType":1294,"data":2233,"content":2234},{},[2235,2239,2248,2252,2261,2265,2274],{"nodeType":1293,"value":2236,"marks":2237,"data":2238},"Session token theft is a ",[],{},{"nodeType":1345,"data":2240,"content":2242},{"uri":2241},"https://owasp.org/www-community/attacks/Session_hijacking_attack",[2243],{"nodeType":1293,"value":2244,"marks":2245,"data":2247},"session hijacking",[2246],{"type":2219},{},{"nodeType":1293,"value":2249,"marks":2250,"data":2251}," technique where endpoint malware is used to extract sessions from an endpoint, and until recently it was ",[],{},{"nodeType":1345,"data":2253,"content":2255},{"uri":2254},"https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/",[2256],{"nodeType":1293,"value":2257,"marks":2258,"data":2260},"relatively rare",[2259],{"type":2219},{},{"nodeType":1293,"value":2262,"marks":2263,"data":2264},". It’s easier to ",[],{},{"nodeType":1345,"data":2266,"content":2268},{"uri":2267},"https://pushsecurity.com/blog/what-is-credential-stuffing/",[2269],{"nodeType":1293,"value":2270,"marks":2271,"data":2273},"gain access via a password",[2272],{"type":2219},{},{"nodeType":1293,"value":2275,"marks":2276,"data":2277}," than it is to steal a session cookie. ",[],{},{"nodeType":1294,"data":2279,"content":2280},{},[2281],{"nodeType":1293,"value":2282,"marks":2283,"data":2284},"But there’s an inverse relationship between session-based attacks and MFA adoption. As MFA becomes widespread, adversaries turn to new effective methods of initial entry.",[],{},{"nodeType":1294,"data":2286,"content":2287},{},[2288],{"nodeType":1293,"value":2289,"marks":2290,"data":2291},"An increasingly common approach involves the use of infostealer malware, which can extract saved credentials, browser cookies, cryptowallets, and other valuable data from the infected endpoint.",[],{},{"nodeType":1294,"data":2293,"content":2294},{},[2295],{"nodeType":1293,"value":2296,"marks":2297,"data":2298},"Using stolen tokens, adversaries don’t need to bypass MFA directly. They can simply import the tokens into their browser and assume an already authorized session.",[],{},{"nodeType":1322,"data":2300,"content":2304},{"target":2301},{"sys":2302},{"id":2303,"type":1327,"linkType":1328},"66B5MBFIhbmky7VuLGbuM3",[],{"nodeType":1294,"data":2306,"content":2307},{},[2308],{"nodeType":1293,"value":2309,"marks":2310,"data":2311},"A few recent stats show the scope of the problem:",[],{},{"nodeType":1437,"data":2313,"content":2314},{},[2315,2337,2359,2380],{"nodeType":1441,"data":2316,"content":2317},{},[2318],{"nodeType":1294,"data":2319,"content":2320},{},[2321,2325,2334],{"nodeType":1293,"value":2322,"marks":2323,"data":2324},"Nearly half of the malware detected last year by Sophos targeted victims’ data specifically, and the majority of that malware was classified as infostealers. Source: ",[],{},{"nodeType":1345,"data":2326,"content":2328},{"uri":2327},"https://news.sophos.com/en-us/2024/03/12/2024-sophos-threat-report/",[2329],{"nodeType":1293,"value":2330,"marks":2331,"data":2333},"2024 Sophos Threat Report",[2332],{"type":2219},{},{"nodeType":1293,"value":37,"marks":2335,"data":2336},[],{},{"nodeType":1441,"data":2338,"content":2339},{},[2340],{"nodeType":1294,"data":2341,"content":2342},{},[2343,2347,2356],{"nodeType":1293,"value":2344,"marks":2345,"data":2346},"Information-stealing malware accounted for nearly 10 percent of activity that Red Canary was able to associate with named threats last year. They also found a rise in stealer malware targeting macOS compared to previous years. Source: ",[],{},{"nodeType":1345,"data":2348,"content":2350},{"uri":2349},"https://redcanary.com/threat-detection-report/trends/info-stealers/",[2351],{"nodeType":1293,"value":2352,"marks":2353,"data":2355},"2024 Red Canary Threat Detection Report",[2354],{"type":2219},{},{"nodeType":1293,"value":37,"marks":2357,"data":2358},[],{},{"nodeType":1441,"data":2360,"content":2361},{},[2362],{"nodeType":1294,"data":2363,"content":2364},{},[2365,2369,2377],{"nodeType":1293,"value":2366,"marks":2367,"data":2368},"Stolen credentials continued to rank as the top initial access method for breaches analyzed by Verizon. Source: ",[],{},{"nodeType":1345,"data":2370,"content":2371},{"uri":1370},[2372],{"nodeType":1293,"value":2373,"marks":2374,"data":2376},"2024 Data Breach Investigations Report",[2375],{"type":2219},{},{"nodeType":1293,"value":37,"marks":2378,"data":2379},[],{},{"nodeType":1441,"data":2381,"content":2382},{},[2383],{"nodeType":1294,"data":2384,"content":2385},{},[2386,2390,2398],{"nodeType":1293,"value":2387,"marks":2388,"data":2389},"The number of token replay attacks is increasing, with Microsoft detecting 147,000 attacks in 2023, a 111% increase year-over-year. Source: ",[],{},{"nodeType":1345,"data":2391,"content":2393},{"uri":2392},"https://techcommunity.microsoft.com/t5/microsoft-entra-blog/how-to-break-the-token-theft-cyber-attack-chain/ba-p/4062700",[2394],{"nodeType":1293,"value":2395,"marks":2396,"data":2397},"Microsoft Blog",[],{},{"nodeType":1293,"value":37,"marks":2399,"data":2400},[],{},{"nodeType":1538,"data":2402,"content":2403},{},[2404],{"nodeType":1293,"value":2405,"marks":2406,"data":2407},"What's missing from current defenses",[],{},{"nodeType":1294,"data":2409,"content":2410},{},[2411],{"nodeType":1293,"value":2412,"marks":2413,"data":2414},"When defending against infostealer malware or other forms of session and credential theft, there are a few common challenges that organizations may face:",[],{},{"nodeType":1437,"data":2416,"content":2417},{},[2418,2428],{"nodeType":1441,"data":2419,"content":2420},{},[2421],{"nodeType":1294,"data":2422,"content":2423},{},[2424],{"nodeType":1293,"value":2425,"marks":2426,"data":2427},"Their endpoint security tooling doesn’t provide complete coverage across their device fleet, though they thought it did.",[],{},{"nodeType":1441,"data":2429,"content":2430},{},[2431],{"nodeType":1294,"data":2432,"content":2433},{},[2434],{"nodeType":1293,"value":2435,"marks":2436,"data":2437},"The malware is good enough to evade EDR detection, or it was able to execute and exfiltrate sessions or other data before it was stopped.",[],{},{"nodeType":1294,"data":2439,"content":2440},{},[2441],{"nodeType":1293,"value":2442,"marks":2443,"data":2444},"Existing approaches to detecting stolen sessions also pose a noisy problem. Relying on IP-based or geolocation-based signals can result in frequent false positives. (And not all identity provider logs include a session identifier that you can use to perform correlations in the first place.)",[],{},{"nodeType":1294,"data":2446,"content":2447},{},[2448],{"nodeType":1293,"value":2449,"marks":2450,"data":2451},"The missing piece is a trusted signal for legitimate sessions that you can use to correlate with other data in order to identify unexpected activity that indicates a compromised identity and device.",[],{},{"nodeType":1538,"data":2453,"content":2454},{},[2455],{"nodeType":1293,"value":2456,"marks":2457,"data":2458},"Generating unique telemetry via the browser",[],{},{"nodeType":1294,"data":2460,"content":2461},{},[2462],{"nodeType":1293,"value":2463,"marks":2464,"data":2465},"Push’s solution to detecting stolen sessions falls into the category of “so simple, why didn’t this already exist?”",[],{},{"nodeType":1294,"data":2467,"content":2468},{},[2469],{"nodeType":1293,"value":2470,"marks":2471,"data":2472},"The answer: Because you need to be in the browser to do it. The Push browser agent sits in a unique position that we can leverage to provide telemetry that otherwise would be extremely difficult to create.",[],{},{"nodeType":1294,"data":2474,"content":2475},{},[2476],{"nodeType":1293,"value":2477,"marks":2478,"data":2479},"Here’s how it works:",[],{},{"nodeType":1437,"data":2481,"content":2482},{},[2483,2493,2503],{"nodeType":1441,"data":2484,"content":2485},{},[2486],{"nodeType":1294,"data":2487,"content":2488},{},[2489],{"nodeType":1293,"value":2490,"marks":2491,"data":2492},"Via the Push browser agent, Push injects a unique marker into the user agent string of sessions that occur in browsers enrolled in Push.",[],{},{"nodeType":1441,"data":2494,"content":2495},{},[2496],{"nodeType":1294,"data":2497,"content":2498},{},[2499],{"nodeType":1293,"value":2500,"marks":2501,"data":2502},"Administrators then add the list of domains where they wish to inject the marker into sessions, such as an identity provider like Okta or Microsoft.",[],{},{"nodeType":1441,"data":2504,"content":2505},{},[2506],{"nodeType":1294,"data":2507,"content":2508},{},[2509,2513,2518,2522,2527],{"nodeType":1293,"value":2510,"marks":2511,"data":2512},"By analyzing logs from the IdP, you can identify activity from the same session that both ",[],{},{"nodeType":1293,"value":2514,"marks":2515,"data":2517},"has",[2516],{"type":312},{},{"nodeType":1293,"value":2519,"marks":2520,"data":2521}," the Push marker and that ",[],{},{"nodeType":1293,"value":2523,"marks":2524,"data":2526},"lacks",[2525],{"type":312},{},{"nodeType":1293,"value":2528,"marks":2529,"data":2530}," the marker. This can only ever happen when a session is extracted from a browser and maliciously imported into a different browser.",[],{},{"nodeType":1294,"data":2532,"content":2533},{},[2534],{"nodeType":1293,"value":2535,"marks":2536,"data":2537},"This is a high-fidelity signal that a stolen session token is in use.",[],{},{"nodeType":1322,"data":2539,"content":2543},{"target":2540},{"sys":2541},{"id":2542,"type":1327,"linkType":1328},"3zQamWSaZFIbMUhQZtM2II",[],{"nodeType":1294,"data":2545,"content":2546},{},[2547,2551,2559],{"nodeType":1293,"value":2548,"marks":2549,"data":2550},"Learn more about configuring this feature in our ",[],{},{"nodeType":1345,"data":2552,"content":2553},{"uri":2213},[2554],{"nodeType":1293,"value":2555,"marks":2556,"data":2558},"Help Center",[2557],{"type":2219},{},{"nodeType":1293,"value":1419,"marks":2560,"data":2561},[],{},{"nodeType":1322,"data":2563,"content":2567},{"target":2564},{"sys":2565},{"id":2566,"type":1327,"linkType":1328},"35dpGqNY6cTM0fSQRflLiO",[],{"nodeType":1538,"data":2569,"content":2570},{},[2571],{"nodeType":1293,"value":2572,"marks":2573,"data":2574},"Unlocking new capabilities for blue teams",[],{},{"nodeType":1294,"data":2576,"content":2577},{},[2578,2582,2591],{"nodeType":1293,"value":2579,"marks":2580,"data":2581},"As we’ve said before, we see browser telemetry and browser-based controls as the ",[],{},{"nodeType":1345,"data":2583,"content":2585},{"uri":2584},"https://pushsecurity.com/blog/what-is-itdr-identity-threat-detection-response/",[2586],{"nodeType":1293,"value":2587,"marks":2588,"data":2590},"missing piece",[2589],{"type":2219},{},{"nodeType":1293,"value":2592,"marks":2593,"data":2594}," in security strategies to stop identity attacks — particularly for modern organizations with complex identity ecosystems that span IdPs, SaaS apps, OAuth-connected apps, and more.",[],{},{"nodeType":1294,"data":2596,"content":2597},{},[2598],{"nodeType":1293,"value":2599,"marks":2600,"data":2601},"Where the browser agent approach particularly shines is that it’s application-agnostic. ",[],{},{"nodeType":1294,"data":2603,"content":2604},{},[2605],{"nodeType":1293,"value":2606,"marks":2607,"data":2608},"As long as the app you want to monitor provides robust logs, you can inject the Push-supplied marker into any session on any app. ",[],{},{"nodeType":1294,"data":2610,"content":2611},{},[2612],{"nodeType":1293,"value":2613,"marks":2614,"data":2615},"This allows you to detect suspicious activity even on internal corporate assets, such as an intranet. ",[],{},{"nodeType":1294,"data":2617,"content":2618},{},[2619],{"nodeType":1293,"value":2620,"marks":2621,"data":2622},"A tidy side effect is that you can also use this feature to identify unmanaged devices accessing sensitive corporate internal resources because they will lack the Push browser agent-supplied marker.",[],{},{"nodeType":1294,"data":2624,"content":2625},{},[2626],{"nodeType":1293,"value":2627,"marks":2628,"data":2629},"There are probably a few other creative use cases for this feature, so we look forward to seeing what you come up with!",[],{},{"nodeType":1538,"data":2631,"content":2632},{},[2633],{"nodeType":1293,"value":2102,"marks":2634,"data":2635},[],{},{"nodeType":1294,"data":2637,"content":2638},{},[2639,2643,2651],{"nodeType":1293,"value":2640,"marks":2641,"data":2642},"To see Push in action, ",[],{},{"nodeType":1345,"data":2644,"content":2646},{"uri":2645},"https://pushsecurity.com/demo/",[2647],{"nodeType":1293,"value":2117,"marks":2648,"data":2650},[2649],{"type":2219},{},{"nodeType":1293,"value":2652,"marks":2653,"data":2654},". We’ll be happy to show you this feature, along with how we discover all the apps your employees are using, even the ones not behind SSO, and how we detect vulnerable identities and stop identity attacks with browser-based controls.",[],{},"Introducing session token theft detection: Why browser is best","Push's browser agent identifies session token theft by adding telemetry to the user agent string to create a new high-fidelity signal for your security team.","2024-06-25T00:00:00.000Z","introducing-session-token-theft-detection-why-browser-is-best",{"items":2660},[2661,2663],{"sys":2662,"name":1306},{"id":1305},{"sys":2664,"name":2133},{"id":2132},{"items":2666},[2667],{"fullName":2139,"firstName":2140,"jobTitle":2141,"profilePicture":2668},{"url":2143},{"__typename":1314,"sys":2670,"content":2672,"title":3082,"synopsis":3083,"hashTags":118,"publishedDate":3084,"slug":3085,"tagsCollection":3086,"authorsCollection":3092},{"id":2671},"4EfGLsD4qOkE4AoTUoL83m",{"json":2673},{"nodeType":1295,"data":2674,"content":2675},{},[2676,2682,2703,2724,2742,2762,2785,2792,2812,2833,2840,2846,2853,2860,2867,2874,2881,2888,2895,2902,2909,2929,2936,2942,2965,2972,2990,2996,3015,3022,3029,3036,3043,3061,3067],{"nodeType":1322,"data":2677,"content":2681},{"target":2678},{"sys":2679},{"id":2680,"type":1327,"linkType":1328},"B8i0EK90Dn7FLrJXR4ANh",[],{"nodeType":1294,"data":2683,"content":2684},{},[2685,2689,2699],{"nodeType":1293,"value":2686,"marks":2687,"data":2688},"Is the golden era of MFA protection over? Watch a demo of an ",[],{},{"nodeType":1457,"data":2690,"content":2694},{"target":2691},{"sys":2692},{"id":2693,"type":1327,"linkType":1328},"7DJnckJxP4CXyXhPJJpby5",[2695],{"nodeType":1293,"value":2696,"marks":2697,"data":2698},"EvilNoVNC phishing attack",[],{},{"nodeType":1293,"value":2700,"marks":2701,"data":2702}," and you may be left sweating a little and whispering “FIDO2” like a protection spell.",[],{},{"nodeType":1294,"data":2704,"content":2705},{},[2706,2710,2720],{"nodeType":1293,"value":2707,"marks":2708,"data":2709},"With the widespread adoption of MFA, attackers are ",[],{},{"nodeType":1457,"data":2711,"content":2715},{"target":2712},{"sys":2713},{"id":2714,"type":1327,"linkType":1328},"6XIts2UEnrsJDki8gKDXyI",[2716],{"nodeType":1293,"value":2717,"marks":2718,"data":2719},"increasingly turning",[],{},{"nodeType":1293,"value":2721,"marks":2722,"data":2723}," to more sophisticated methods of credential theft as their initial point of entry. ",[],{},{"nodeType":1294,"data":2725,"content":2726},{},[2727,2731,2738],{"nodeType":1293,"value":2728,"marks":2729,"data":2730},"Newer phishing approaches include reverse proxies as well as tools that mimic legitimate login pages by rendering the webpages and then displaying those renders to the unsuspecting end-user. While these tools are not always common knowledge among blue teams, their use is ",[],{},{"nodeType":1345,"data":2732,"content":2733},{"uri":1381},[2734],{"nodeType":1293,"value":2735,"marks":2736,"data":2737},"on the rise",[],{},{"nodeType":1293,"value":2739,"marks":2740,"data":2741},", an unsurprising response to the broad use of multi-factor authentication in many organizations.",[],{},{"nodeType":1294,"data":2743,"content":2744},{},[2745,2749,2758],{"nodeType":1293,"value":2746,"marks":2747,"data":2748},"What sets this generation of ",[],{},{"nodeType":1457,"data":2750,"content":2753},{"target":2751},{"sys":2752},{"id":2693,"type":1327,"linkType":1328},[2754],{"nodeType":1293,"value":2755,"marks":2756,"data":2757},"Adversary-in-the-Middle (AitM) phishing tools",[],{},{"nodeType":1293,"value":2759,"marks":2760,"data":2761}," apart? ",[],{},{"nodeType":1437,"data":2763,"content":2764},{},[2765,2775],{"nodeType":1441,"data":2766,"content":2767},{},[2768],{"nodeType":1294,"data":2769,"content":2770},{},[2771],{"nodeType":1293,"value":2772,"marks":2773,"data":2774},"They act as a proxy between the user and a legitimate web login page, allowing the attacker to bypass MFA and harvest credentials and session tokens.",[],{},{"nodeType":1441,"data":2776,"content":2777},{},[2778],{"nodeType":1294,"data":2779,"content":2780},{},[2781],{"nodeType":1293,"value":2782,"marks":2783,"data":2784},"They give off little scent to end-users, because the end-user is logging into the legitimate site, just by taking a detour via the attacker’s device.",[],{},{"nodeType":1294,"data":2786,"content":2787},{},[2788],{"nodeType":1293,"value":2789,"marks":2790,"data":2791},"These AitM tools are also difficult to detect — unless you have eyes in the browser.",[],{},{"nodeType":1294,"data":2793,"content":2794},{},[2795,2799,2808],{"nodeType":1293,"value":2796,"marks":2797,"data":2798},"Powered by the Push browser agent, Push now offers a ",[],{},{"nodeType":1457,"data":2800,"content":2803},{"target":2801},{"sys":2802},{"id":1648,"type":1327,"linkType":1328},[2804],{"nodeType":1293,"value":2805,"marks":2806,"data":2807},"preconfigured set of detections",[],{},{"nodeType":1293,"value":2809,"marks":2810,"data":2811}," for phishing tools like Evilginx and others, informed by our threat detection team’s research into their behavior. This phishing tool detection feature will automatically prevent users from accessing a site that’s running one of these malicious tools, and display a custom warning message to your end-users.",[],{},{"nodeType":1294,"data":2813,"content":2814},{},[2815,2819,2829],{"nodeType":1293,"value":2816,"marks":2817,"data":2818},"While Push already provides strong phishing protection by ",[],{},{"nodeType":1457,"data":2820,"content":2824},{"target":2821},{"sys":2822},{"id":2823,"type":1327,"linkType":1328},"4UtRVoFElDduWJBx9Sa4Cw",[2825],{"nodeType":1293,"value":2826,"marks":2827,"data":2828},"preventing SSO password use",[],{},{"nodeType":1293,"value":2830,"marks":2831,"data":2832}," on non-IdP webpages (in other words, it stops you from using your Okta password on any page that isn’t an Okta login page), this new feature allows us to sharpen our anti-phishing capabilities by detecting malware on a site before a user even interacts with the page. ",[],{},{"nodeType":1294,"data":2834,"content":2835},{},[2836],{"nodeType":1293,"value":2837,"marks":2838,"data":2839},"In this article, we’ll describe our approach to detecting these newer phishing tools, including how we’re borrowing techniques from the world of EDR, and how you can combine phishing tool detection with other Push controls for a defense-in-depth strategy that covers both the user and the application sides of the equation.",[],{},{"nodeType":1322,"data":2841,"content":2845},{"target":2842},{"sys":2843},{"id":2844,"type":1327,"linkType":1328},"59q6klX2j7ClgUvmix93sG",[],{"nodeType":1538,"data":2847,"content":2848},{},[2849],{"nodeType":1293,"value":2850,"marks":2851,"data":2852},"Taking a page from EDR",[],{},{"nodeType":1294,"data":2854,"content":2855},{},[2856],{"nodeType":1293,"value":2857,"marks":2858,"data":2859},"Most phishing prevention solutions rely on lists of known-bad sites as the source of intelligence. These are always going to be a step behind reality because they rely on ever-shifting secondary attributes such as domain names (though we won’t be disabling Chrome Safe Browsing anytime soon, and we’re not trying to replace it).",[],{},{"nodeType":1294,"data":2861,"content":2862},{},[2863],{"nodeType":1293,"value":2864,"marks":2865,"data":2866},"As veterans of the EDR world, we’re drawn to think in analogous terms. With detecting AitM phishing tools, that means expanding on the concept of dynamic analysis on the endpoint. EDR allows you to dynamically analyze the behavior of malware live and at scale, rather than focusing on easy-to-change indicators like file hashes or domain names.",[],{},{"nodeType":1294,"data":2868,"content":2869},{},[2870],{"nodeType":1293,"value":2871,"marks":2872,"data":2873},"Applying this idea to malware that runs in the browser requires a solution that is in the browser, like the Push browser agent.",[],{},{"nodeType":1294,"data":2875,"content":2876},{},[2877],{"nodeType":1293,"value":2878,"marks":2879,"data":2880},"So we’re expanding the attributes that are traditionally analyzed to spot indicators of compromise (IoCs) beyond domains, file names, file hashes, IP addresses, etc., to also include behavioral attributes of malware that are much harder to change, such as Javascript calls being made or data structures saved to local storage.",[],{},{"nodeType":1294,"data":2882,"content":2883},{},[2884],{"nodeType":1293,"value":2885,"marks":2886,"data":2887},"By performing behavioral analysis on AitM automated proxy tools, we can directly analyze the application for a precise and immediate identification. ",[],{},{"nodeType":1294,"data":2889,"content":2890},{},[2891],{"nodeType":1293,"value":2892,"marks":2893,"data":2894},"Push researchers are regularly identifying and adding detections for new toolkits — think of this like Push’s database of threat research in action.",[],{},{"nodeType":1538,"data":2896,"content":2897},{},[2898],{"nodeType":1293,"value":2899,"marks":2900,"data":2901},"How it works",[],{},{"nodeType":1294,"data":2903,"content":2904},{},[2905],{"nodeType":1293,"value":2906,"marks":2907,"data":2908},"If you’re new to Push, a bit of context may be useful. Push uses a browser agent deployed to employee browsers (we support all major browsers) to prevent, detect, and block identity attacks. ",[],{},{"nodeType":1294,"data":2910,"content":2911},{},[2912,2916,2925],{"nodeType":1293,"value":2913,"marks":2914,"data":2915},"By directly observing user behavior at the login event, Push provides broad and actionable context across all the apps your employees are using, how they are accessing them, their MFA methods, and where they’re using insecure and reused passwords. With this context as the foundation, Push enforces your desired ",[],{},{"nodeType":1457,"data":2917,"content":2920},{"target":2918},{"sys":2919},{"id":1461,"type":1327,"linkType":1328},[2921],{"nodeType":1293,"value":2922,"marks":2923,"data":2924},"security controls",[],{},{"nodeType":1293,"value":2926,"marks":2927,"data":2928},", including preventing SSO password reuse, blocking malicious websites, or steering employees to approved apps only.",[],{},{"nodeType":1294,"data":2930,"content":2931},{},[2932],{"nodeType":1293,"value":2933,"marks":2934,"data":2935},"Once configured by an administrator, phishing tool detection will immediately check for the fingerprints of these toolkits as end-users visit websites and then display your custom warn or block message. ",[],{},{"nodeType":1322,"data":2937,"content":2941},{"target":2938},{"sys":2939},{"id":2940,"type":1327,"linkType":1328},"1LdHJjTDlOiie5mctbAVvZ",[],{"nodeType":1294,"data":2943,"content":2944},{},[2945,2949,2953,2957,2961],{"nodeType":1293,"value":2946,"marks":2947,"data":2948},"In ",[],{},{"nodeType":1293,"value":1623,"marks":2950,"data":2952},[2951],{"type":1416},{},{"nodeType":1293,"value":2954,"marks":2955,"data":2956}," mode, users cannot proceed to the site where malicious software has been detected. In ",[],{},{"nodeType":1293,"value":1614,"marks":2958,"data":2960},[2959],{"type":1416},{},{"nodeType":1293,"value":2962,"marks":2963,"data":2964}," mode, users can choose to proceed if they are sure it’s not a phishing site.",[],{},{"nodeType":1294,"data":2966,"content":2967},{},[2968],{"nodeType":1293,"value":2969,"marks":2970,"data":2971},"In both cases, users do not need to interact with a page (by typing, clicking, etc.) for Push to trigger the custom message. ",[],{},{"nodeType":1294,"data":2973,"content":2974},{},[2975,2979,2986],{"nodeType":1293,"value":2976,"marks":2977,"data":2978},"Administrators can also consume phishing tool detection events via the ",[],{},{"nodeType":1345,"data":2980,"content":2981},{"uri":1489},[2982],{"nodeType":1293,"value":2983,"marks":2984,"data":2985},"Push REST API",[],{},{"nodeType":1293,"value":2987,"marks":2988,"data":2989}," into their SIEM or use Push’s webhooks to alert when a warn or block event has occurred.",[],{},{"nodeType":1322,"data":2991,"content":2995},{"target":2992},{"sys":2993},{"id":2994,"type":1327,"linkType":1328},"6oAhxLBPVxN3Rcw2kFeVtG",[],{"nodeType":1294,"data":2997,"content":2998},{},[2999,3003,3011],{"nodeType":1293,"value":3000,"marks":3001,"data":3002},"Pairing this phishing detection capability with Push’s ",[],{},{"nodeType":1457,"data":3004,"content":3007},{"target":3005},{"sys":3006},{"id":1732,"type":1327,"linkType":1328},[3008],{"nodeType":1293,"value":1661,"marks":3009,"data":3010},[],{},{"nodeType":1293,"value":3012,"marks":3013,"data":3014}," feature provides a strong defense-in-depth strategy for stopping credential theft.",[],{},{"nodeType":1294,"data":3016,"content":3017},{},[3018],{"nodeType":1293,"value":3019,"marks":3020,"data":3021},"SSO password protection works by analyzing user behavior — namely, is a user entering their SSO password onto a page that does not belong to the legitimate identity provider.",[],{},{"nodeType":1294,"data":3023,"content":3024},{},[3025],{"nodeType":1293,"value":3026,"marks":3027,"data":3028},"Phishing tool detection adds in the application-level behavioral analysis. In addition, when Push identifies a new, previously unknown phishing tool in the wild via blocked SSO credential theft, we add its fingerprints to the browser agent’s detective capabilities.  ",[],{},{"nodeType":1538,"data":3030,"content":3031},{},[3032],{"nodeType":1293,"value":3033,"marks":3034,"data":3035},"Looking ahead",[],{},{"nodeType":1294,"data":3037,"content":3038},{},[3039],{"nodeType":1293,"value":3040,"marks":3041,"data":3042},"We’re just scratching the surface on this approach and are exploring how Push can identify and block other web-delivered malware and Javascript-based attack types beyond AitM tools. Think HTML smuggling, tabnabbing, and the like.",[],{},{"nodeType":1294,"data":3044,"content":3045},{},[3046,3050,3058],{"nodeType":1293,"value":3047,"marks":3048,"data":3049},"Got feedback? We’d ",[],{},{"nodeType":1345,"data":3051,"content":3053},{"uri":3052},"/contact/",[3054],{"nodeType":1293,"value":3055,"marks":3056,"data":3057},"love to talk",[],{},{"nodeType":1293,"value":1419,"marks":3059,"data":3060},[],{},{"nodeType":1538,"data":3062,"content":3063},{},[3064],{"nodeType":1293,"value":2102,"marks":3065,"data":3066},[],{},{"nodeType":1294,"data":3068,"content":3069},{},[3070,3073,3079],{"nodeType":1293,"value":2640,"marks":3071,"data":3072},[],{},{"nodeType":1345,"data":3074,"content":3075},{"uri":2645},[3076],{"nodeType":1293,"value":2117,"marks":3077,"data":3078},[],{},{"nodeType":1293,"value":2652,"marks":3080,"data":3081},[],{},"Introducing AitM phishing toolkit detection, powered by the Push browser agent","Push analyzes behavioral attributes of malware to identify phishing tools like Evilginx and NakedPages and immediately block end-users from visiting them.","2024-06-06T00:00:00.000Z","introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser",{"items":3087},[3088,3090],{"sys":3089,"name":2133},{"id":2132},{"sys":3091,"name":1306},{"id":1305},{"items":3093},[3094],{"fullName":2139,"firstName":2140,"jobTitle":2141,"profilePicture":3095},{"url":2143},{"url":3097},"https://images.ctfassets.net/y1cdw1ablpvd/30YWVepOBUQeSVGynF251a/3821d6b78bf8cc2edac6770f587e1ed8/Frame_627569__10_.png",{"items":3099},[3100],{"fullName":3101,"firstName":3102,"jobTitle":3103,"profilePicture":3104},"Dan Green","Dan","Threat Research",{"url":3105},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"json":3107,"links":3762},{"nodeType":1295,"data":3108,"content":3109},{},[3110,3117,3124,3149,3155,3162,3169,3173,3180,3200,3206,3213,3256,3263,3270,3277,3284,3291,3298,3317,3325,3328,3335,3342,3349,3356,3363,3370,3377,3425,3432,3439,3446,3466,3473,3480,3487,3494,3501,3508,3515,3533,3551,3594,3601,3608,3674,3681,3684,3691,3707,3726,3733,3739,3745,3748,3755],{"nodeType":1294,"data":3111,"content":3112},{},[3113],{"nodeType":1293,"value":3114,"marks":3115,"data":3116},"The field of threat detection and security monitoring has changed significantly over the last decade. Security tools and product categories have been added and replaced, specialist disciplines established, and methodologies created. ",[],{},{"nodeType":1294,"data":3118,"content":3119},{},[3120],{"nodeType":1293,"value":3121,"marks":3122,"data":3123},"Naturally, defenders have had to mature their approach because of the changing nature of the threat facing organizations. Attackers have always looked for new ways to target their victims, and naturally, defenders have had to adapt, forcing attackers to change things up… it’s a cat and mouse game. ",[],{},{"nodeType":1294,"data":3125,"content":3126},{},[3127,3131,3140,3144],{"nodeType":1293,"value":3128,"marks":3129,"data":3130},"Blue teamers have used the concept of the ",[],{},{"nodeType":1345,"data":3132,"content":3134},{"uri":3133},"https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html",[3135],{"nodeType":1293,"value":3136,"marks":3137,"data":3139},"Pyramid of Pain",[3138],{"type":2219},{},{"nodeType":1293,"value":3141,"marks":3142,"data":3143}," for over a decade. The logic is simple: ",[],{},{"nodeType":1293,"value":3145,"marks":3146,"data":3148},"Focus on detecting and responding to indicators that are hard for attackers to change. ",[3147],{"type":1416},{},{"nodeType":1322,"data":3150,"content":3154},{"target":3151},{"sys":3152},{"id":3153,"type":1327,"linkType":1328},"6cG2fx3AikwptyEyXKrYCK",[],{"nodeType":1294,"data":3156,"content":3157},{},[3158],{"nodeType":1293,"value":3159,"marks":3160,"data":3161},"If an attacker only has to tweak a variable to get around your detection rule, like adding a space to change a hash value, it’s probably not a very good detection. It’s not going to remain effective for long and you’re always going to be one step behind the attacker – waiting for them to make their next move so you can react. This usually ends up meaning that attackers enjoy at least some success before they can be shut out again. ",[],{},{"nodeType":1294,"data":3163,"content":3164},{},[3165],{"nodeType":1293,"value":3166,"marks":3167,"data":3168},"The Pyramid of Pain – and the goal of implementing hard-to-bypass detections that hit attackers where it hurts – is central to our design philosophy. But before we get into how we apply this approach, and the types of controls we’ve created as a result, it’s useful to look at how IT and security have changed since the Pyramid was created more than a decade ago. ",[],{},{"nodeType":3170,"data":3171,"content":3172},"hr",{},[],{"nodeType":1538,"data":3174,"content":3175},{},[3176],{"nodeType":1293,"value":3177,"marks":3178,"data":3179},"A new era for cyber security",[],{},{"nodeType":1294,"data":3181,"content":3182},{},[3183,3187,3196],{"nodeType":1293,"value":3184,"marks":3185,"data":3186},"We’ve spoken a lot about how we’re in the midst of a new era in cybersecurity, in which identity is now the outermost digital perimeter for security teams to defend. (",[],{},{"nodeType":1345,"data":3188,"content":3190},{"uri":3189},"https://pushsecurity.com/resources/video/the-new-saas-cyber-kill-chain-so-con-2024/",[3191],{"nodeType":1293,"value":3192,"marks":3193,"data":3195},"You’ll be familiar with this if you’ve seen any of Luke’s talks on the New SaaS Cyber Kill Chain.",[3194],{"type":2219},{},{"nodeType":1293,"value":3197,"marks":3198,"data":3199},") ",[],{},{"nodeType":1322,"data":3201,"content":3205},{"target":3202},{"sys":3203},{"id":3204,"type":1327,"linkType":1328},"6nYSZAYpsbj78jKm0q75zs",[],{"nodeType":1294,"data":3207,"content":3208},{},[3209],{"nodeType":1293,"value":3210,"marks":3211,"data":3212},"This is primarily because modern working is no longer contained to a heavily centralized corporate network, and instead happens primarily in applications accessed over the internet via web browser.",[],{},{"nodeType":1294,"data":3214,"content":3215},{},[3216,3220,3228,3232,3240,3244,3252],{"nodeType":1293,"value":3217,"marks":3218,"data":3219},"In this new world, attacks don’t even have to touch the old perimeters, because all the data and functionality they could want exists on the public internet. As a result, we’re seeing more and more ",[],{},{"nodeType":1345,"data":3221,"content":3223},{"uri":3222},"https://pushsecurity.com/blog/saas-attack-techniques/",[3224],{"nodeType":1293,"value":3225,"marks":3226,"data":3227},"attacks targeting SaaS apps",[],{},{"nodeType":1293,"value":3229,"marks":3230,"data":3231},", with the entire attack chain being concluded outside customer networks, not touching any traditional endpoints or networks. The ",[],{},{"nodeType":1345,"data":3233,"content":3235},{"uri":3234},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[3236],{"nodeType":1293,"value":3237,"marks":3238,"data":3239},"recent attacks on Snowflake customers",[],{},{"nodeType":1293,"value":3241,"marks":3242,"data":3243},", hailed ",[],{},{"nodeType":1345,"data":3245,"content":3247},{"uri":3246},"https://www.wired.com/story/snowflake-breach-advanced-auto-parts-lendingtree/",[3248],{"nodeType":1293,"value":3249,"marks":3250,"data":3251},"one of the biggest breaches in history",[],{},{"nodeType":1293,"value":3253,"marks":3254,"data":3255},", demonstrate this risk all too well. ",[],{},{"nodeType":1294,"data":3257,"content":3258},{},[3259],{"nodeType":1293,"value":3260,"marks":3261,"data":3262},"This creates a problem for security teams looking to detect and respond to these attacks. ",[],{},{"nodeType":1575,"data":3264,"content":3265},{},[3266],{"nodeType":1293,"value":3267,"marks":3268,"data":3269},"Attacks today are shorter and faster, but just as dangerous",[],{},{"nodeType":1294,"data":3271,"content":3272},{},[3273],{"nodeType":1293,"value":3274,"marks":3275,"data":3276},"Detecting and responding to identity attacks – phishing, credential stuffing, etc. – used to be just one possible method of initial access in quite a lengthy Kill Chain that stretched from the compromise of the user device, pivoting to internal network resources, escalating privileges, moving laterally, and finally achieving their objectives.",[],{},{"nodeType":1294,"data":3278,"content":3279},{},[3280],{"nodeType":1293,"value":3281,"marks":3282,"data":3283},"This meant that defenders could adopt an assumed compromise mentality and build layered detections, as well as proactively hunting for threats across these various stages and layers of the network. The more actions an attacker has to perform, the more opportunities for detection, and the higher the likelihood that they’ll be caught in the act before any real, lasting damage can be caused. ",[],{},{"nodeType":1294,"data":3285,"content":3286},{},[3287],{"nodeType":1293,"value":3288,"marks":3289,"data":3290},"Today, attackers have a lot of opportunities to cause significant damage for much less effort than before. For example, if the goal is to compromise an app like Snowflake and dump the data from it, the Kill Chain is way shorter than a traditional network-based attack. And all the great tools and security products you have, like EDR, don’t come into play. ",[],{},{"nodeType":1294,"data":3292,"content":3293},{},[3294],{"nodeType":1293,"value":3295,"marks":3296,"data":3297},"This means that the initial layer of anti-account takeover controls are much more important in this context. But, the historical detections in this space – email gateway security products, analyzing web pages for malicious content, and URL blocklisting – are either less relevant, or built upon easy to bypass detections toward the bottom of the Pyramid of Pain. ",[],{},{"nodeType":1294,"data":3299,"content":3300},{},[3301,3305,3313],{"nodeType":1293,"value":3302,"marks":3303,"data":3304},"As an example, ",[],{},{"nodeType":1345,"data":3306,"content":3308},{"uri":3307},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection/",[3309],{"nodeType":1293,"value":3310,"marks":3311,"data":3312},"we recently published an article on all the ways that AitM phishing sites are evading detection",[],{},{"nodeType":1293,"value":3314,"marks":3315,"data":3316},". TL;DR – there are a lot, and they seem to be quite effective. But this is partly because the majority of the detections they're trying to avoid are built on shaky ground.   ",[],{},{"nodeType":1294,"data":3318,"content":3319},{},[3320],{"nodeType":1293,"value":3321,"marks":3322,"data":3324},"So what? Well, it’s clear that the controls that the industry has relied on in the past to stop identity attacks are too easy to bypass, and are no longer sufficient. ",[3323],{"type":1416},{},{"nodeType":3170,"data":3326,"content":3327},{},[],{"nodeType":1538,"data":3329,"content":3330},{},[3331],{"nodeType":1293,"value":3332,"marks":3333,"data":3334},"Building effective identity threat detection controls",[],{},{"nodeType":1294,"data":3336,"content":3337},{},[3338],{"nodeType":1293,"value":3339,"marks":3340,"data":3341},"Now we’ve covered the problem that we set out to solve, let’s look at what we’re doing differently. ",[],{},{"nodeType":1294,"data":3343,"content":3344},{},[3345],{"nodeType":1293,"value":3346,"marks":3347,"data":3348},"In order to climb the Pyramid toward the apex, you need to find ways to detect increasingly generic parts of an attack technique. So you want to avoid things like what a specific malware’s code looks like, or where it connects back to. But what the malware does, or what happens when it runs, is more generic, and therefore more interesting to us.  ",[],{},{"nodeType":1294,"data":3350,"content":3351},{},[3352],{"nodeType":1293,"value":3353,"marks":3354,"data":3355},"The shift from static code signatures and fuzzy hashes to dynamic analysis of what code does on a live system is at the heart of why EDR killed antivirus a decade ago. It proved at-scale the value of moving detections up the pyramid.",[],{},{"nodeType":1294,"data":3357,"content":3358},{},[3359],{"nodeType":1293,"value":3360,"marks":3361,"data":3362},"We’re always on the lookout for ways to move our detections up the pyramid as well. It’s easiest to explain how we’ve applied this by looking at an example. ",[],{},{"nodeType":1575,"data":3364,"content":3365},{},[3366],{"nodeType":1293,"value":3367,"marks":3368,"data":3369},"Scenario: Detecting a web-based phishing attack",[],{},{"nodeType":1294,"data":3371,"content":3372},{},[3373],{"nodeType":1293,"value":3374,"marks":3375,"data":3376},"Let’s break down the stages of a web-based phishing attack as an example. For a user to be successfully phished:",[],{},{"nodeType":1437,"data":3378,"content":3379},{},[3380,3395,3410],{"nodeType":1441,"data":3381,"content":3382},{},[3383],{"nodeType":1294,"data":3384,"content":3385},{},[3386,3391],{"nodeType":1293,"value":3387,"marks":3388,"data":3390},"Stage 1:",[3389],{"type":1416},{},{"nodeType":1293,"value":3392,"marks":3393,"data":3394}," The victim must be lured to visit a website.",[],{},{"nodeType":1441,"data":3396,"content":3397},{},[3398],{"nodeType":1294,"data":3399,"content":3400},{},[3401,3406],{"nodeType":1293,"value":3402,"marks":3403,"data":3405},"Stage 2:",[3404],{"type":1416},{},{"nodeType":1293,"value":3407,"marks":3408,"data":3409}," The website must somehow trick or convince the user that it’s legitimate and trustworthy, for example by mimicking a legitimate site.",[],{},{"nodeType":1441,"data":3411,"content":3412},{},[3413],{"nodeType":1294,"data":3414,"content":3415},{},[3416,3421],{"nodeType":1293,"value":3417,"marks":3418,"data":3420},"Stage 3:",[3419],{"type":1416},{},{"nodeType":1293,"value":3422,"marks":3423,"data":3424}," The user must enter their actual credentials into that website.",[],{},{"nodeType":1294,"data":3426,"content":3427},{},[3428],{"nodeType":1293,"value":3429,"marks":3430,"data":3431},"So, how might you go about detecting this attack? Let’s start from the bottom of the pyramid and work our way up.",[],{},{"nodeType":1575,"data":3433,"content":3434},{},[3435],{"nodeType":1293,"value":3436,"marks":3437,"data":3438},"Stage 1: Determining if a URL, IP, or domain is bad",[],{},{"nodeType":1294,"data":3440,"content":3441},{},[3442],{"nodeType":1293,"value":3443,"marks":3444,"data":3445},"You might start by looking for the lure – historically an email. You could look for links in emails, or links in attachments in an email and then check if they are bad (which is essentially what email security products do). You could look for known-bad URLs in emails, but these change for every phishing campaign. In modern attacks, every target can receive a unique email and link. Even just using a URL shortener can bypass this. It’s equivalent to a malware hash – trivial to change, and therefore not a great thing to pin your detections on. ",[],{},{"nodeType":1294,"data":3447,"content":3448},{},[3449,3453,3462],{"nodeType":1293,"value":3450,"marks":3451,"data":3452},"You could look at which IP address the user connects to, but these days it’s very simple for attackers to add a new IP to their cloud-hosted server. If a domain is flagged as known-bad, the attacker only has to register a new domain, or compromise a WordPress server on an already trusted domain. Both of these things are ",[],{},{"nodeType":1345,"data":3454,"content":3456},{"uri":3455},"https://www.bleepingcomputer.com/news/security/revolver-rabbit-gang-registers-500-000-domains-for-malware-campaigns/",[3457],{"nodeType":1293,"value":3458,"marks":3459,"data":3461},"happening on a massive scale",[3460],{"type":2219},{},{"nodeType":1293,"value":3463,"marks":3464,"data":3465}," as attackers pre-plan for the fact that their domains will be burned at some point. Attackers are more than happy to spend $10-$20 per new domain in the grand scheme of the potential proceeds of crime. ",[],{},{"nodeType":1294,"data":3467,"content":3468},{},[3469],{"nodeType":1293,"value":3470,"marks":3471,"data":3472},"But there’s a more fundamental flaw here – for defenders to know that a URL, IP, or domain name is bad, it needs to be reported first. When are things reported? Typically after being used in an attack – so unfortunately, someone always gets hurt.  ",[],{},{"nodeType":1575,"data":3474,"content":3475},{},[3476],{"nodeType":1293,"value":3477,"marks":3478,"data":3479},"Stage 2: Determining if a site is legitimate",[],{},{"nodeType":1294,"data":3481,"content":3482},{},[3483],{"nodeType":1293,"value":3484,"marks":3485,"data":3486},"So how can we detect a phishing website, on day-zero, the first time anyone runs into it? Well we can look at the second step – does the URL resemble a real website, does the HTML code for a page look similar to a legitimate login page for a known website, is it loading the same image files? This is not trivial to detect, but with the right fuzzy matches and image analysis it can be automated.",[],{},{"nodeType":1294,"data":3488,"content":3489},{},[3490],{"nodeType":1293,"value":3491,"marks":3492,"data":3493},"We’ve now moved up a level on the Pyramid – we’re detecting website artifacts. If we see a legitimate looking website on an unknown domain, it’s likely to be a malicious clone.",[],{},{"nodeType":1294,"data":3495,"content":3496},{},[3497],{"nodeType":1293,"value":3498,"marks":3499,"data":3500},"Unfortunately, the attacker’s website doesn’t need to send each visitor to the same website. It can change dynamically based on where the visitor is coming from – or even randomly, so that not all visitors are served the phishing page. This means that tools which resolve where the links in emails go to be able to analyze them (such as email security appliances) don’t necessarily see the same site the user is actually visiting – a fact that is commonly abused by attackers to bypass detection. It’s critical that detection happens on the actual web page that the victim sees.",[],{},{"nodeType":1575,"data":3502,"content":3503},{},[3504],{"nodeType":1293,"value":3505,"marks":3506,"data":3507},"Stage 3: Detecting the user entering their credentials",[],{},{"nodeType":1294,"data":3509,"content":3510},{},[3511],{"nodeType":1293,"value":3512,"marks":3513,"data":3514},"For a phishing attack to succeed, the victim must enter their actual credentials into the webpage. If you can stop the user entering their real password, there’s no attack. There’s no getting around it. ",[],{},{"nodeType":1294,"data":3516,"content":3517},{},[3518,3522,3530],{"nodeType":1293,"value":3519,"marks":3520,"data":3521},"So, this is exactly what we did: Earlier this year, we released a control which ",[],{},{"nodeType":1345,"data":3523,"content":3525},{"uri":3524},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[3526],{"nodeType":1293,"value":3527,"marks":3528,"data":3529},"stops users from entering their password belonging to a particular login page anywhere else",[],{},{"nodeType":1293,"value":1419,"marks":3531,"data":3532},[],{},{"nodeType":1294,"data":3534,"content":3535},{},[3536,3540,3547],{"nodeType":1293,"value":3537,"marks":3538,"data":3539},"Seems simple, right? By focusing on this generic action, that always has to happen, you can essentially stop your users being phished altogether. This means, it doesn’t matter ",[],{},{"nodeType":1345,"data":3541,"content":3542},{"uri":3307},[3543],{"nodeType":1293,"value":3544,"marks":3545,"data":3546},"what the attacker does before that point",[],{},{"nodeType":1293,"value":3548,"marks":3549,"data":3550},":",[],{},{"nodeType":1437,"data":3552,"content":3553},{},[3554,3564,3574,3584],{"nodeType":1441,"data":3555,"content":3556},{},[3557],{"nodeType":1294,"data":3558,"content":3559},{},[3560],{"nodeType":1293,"value":3561,"marks":3562,"data":3563},"It doesn't matter if they run the site using Cloudflare Workers to block automatic analysis.",[],{},{"nodeType":1441,"data":3565,"content":3566},{},[3567],{"nodeType":1294,"data":3568,"content":3569},{},[3570],{"nodeType":1293,"value":3571,"marks":3572,"data":3573},"It doesn’t matter if they hack a WordPress blog to get a reputable domain.",[],{},{"nodeType":1441,"data":3575,"content":3576},{},[3577],{"nodeType":1294,"data":3578,"content":3579},{},[3580],{"nodeType":1293,"value":3581,"marks":3582,"data":3583},"It doesn’t matter if they use clever redirects and rotate the URLs delivered to the user.",[],{},{"nodeType":1441,"data":3585,"content":3586},{},[3587],{"nodeType":1294,"data":3588,"content":3589},{},[3590],{"nodeType":1293,"value":3591,"marks":3592,"data":3593},"It doesn’t matter if they randomize the HTML title for the web page. ",[],{},{"nodeType":1294,"data":3595,"content":3596},{},[3597],{"nodeType":1293,"value":3598,"marks":3599,"data":3600},"They can’t avoid the fact that a user is required to enter their credentials on the page for the attack to succeed. ",[],{},{"nodeType":1294,"data":3602,"content":3603},{},[3604],{"nodeType":1293,"value":3605,"marks":3606,"data":3607},"So, when you apply the Pyramid of Pain to some of the controls we’ve shipped this year, we get a clear feel for the value, from highest to lowest:",[],{},{"nodeType":1437,"data":3609,"content":3610},{},[3611,3632,3653],{"nodeType":1441,"data":3612,"content":3613},{},[3614],{"nodeType":1294,"data":3615,"content":3616},{},[3617,3621,3628],{"nodeType":1293,"value":3618,"marks":3619,"data":3620},"User Behavior: ",[],{},{"nodeType":1345,"data":3622,"content":3623},{"uri":3524},[3624],{"nodeType":1293,"value":3625,"marks":3626,"data":3627},"Detecting and blocking the user behavior of entering their password into any site that the password doesn’t belong to",[],{},{"nodeType":1293,"value":3629,"marks":3630,"data":3631},". ",[],{},{"nodeType":1441,"data":3633,"content":3634},{},[3635],{"nodeType":1294,"data":3636,"content":3637},{},[3638,3642,3650],{"nodeType":1293,"value":3639,"marks":3640,"data":3641},"Tool Behavior: ",[],{},{"nodeType":1345,"data":3643,"content":3645},{"uri":3644},"https://pushsecurity.com/blog/introducing-cloned-login-page-detection/",[3646],{"nodeType":1293,"value":3647,"marks":3648,"data":3649},"Detecting when a login page that you access is cloned from a legitimate page.",[],{},{"nodeType":1293,"value":37,"marks":3651,"data":3652},[],{},{"nodeType":1441,"data":3654,"content":3655},{},[3656],{"nodeType":1294,"data":3657,"content":3658},{},[3659,3663,3671],{"nodeType":1293,"value":3660,"marks":3661,"data":3662},"Tool Signature: ",[],{},{"nodeType":1345,"data":3664,"content":3666},{"uri":3665},"https://pushsecurity.com/blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser/",[3667],{"nodeType":1293,"value":3668,"marks":3669,"data":3670},"Detecting and blocking access to a page with a known phishing kit signature present on the page",[],{},{"nodeType":1293,"value":3629,"marks":3672,"data":3673},[],{},{"nodeType":1294,"data":3675,"content":3676},{},[3677],{"nodeType":1293,"value":3678,"marks":3679,"data":3680},"Naturally, we want to continue focusing on the apex of the Pyramid – at TTPs and Tools – to ensure that the controls we build are as robust as possible, and can’t be bypassed by attackers. ",[],{},{"nodeType":3170,"data":3682,"content":3683},{},[],{"nodeType":1538,"data":3685,"content":3686},{},[3687],{"nodeType":1293,"value":3688,"marks":3689,"data":3690},"The power of the Push browser agent",[],{},{"nodeType":1294,"data":3692,"content":3693},{},[3694,3698,3703],{"nodeType":1293,"value":3695,"marks":3696,"data":3697},"You might ask: ",[],{},{"nodeType":1293,"value":3699,"marks":3700,"data":3702},"If it’s so simple, why hasn’t this been done yet?",[3701],{"type":1416},{},{"nodeType":1293,"value":3704,"marks":3705,"data":3706}," Well, before now, there was no good way of doing it! Teams simply didn’t have tools in the right place to be able to capture the level of data needed, or respond effectively (i.e. automatically, at the point of impact). ",[],{},{"nodeType":1294,"data":3708,"content":3709},{},[3710,3714,3722],{"nodeType":1293,"value":3711,"marks":3712,"data":3713},"This is where being in the browser comes into play. The browser is a great place to observe the behavior of a page in real time, without needing to reconstruct decrypted HTTP data post-TLS termination and try to guess what the rendered page in all its Javascript-infused glory actually does, ",[],{},{"nodeType":1345,"data":3715,"content":3717},{"uri":3716},"https://pushsecurity.com/blog/the-web-proxy-is-dead-long-live-the-browser-extension/",[3718],{"nodeType":1293,"value":3719,"marks":3720,"data":3721},"as we’ve blogged about previously",[],{},{"nodeType":1293,"value":3723,"marks":3724,"data":3725},". As we’ve seen through the ability to not only detect but prevent phishing attacks, it’s also a great control enforcement point, as you’re able to intercept the user at the point of impact, and you sit as closely as possible to where their work typically happens – in the browser. ",[],{},{"nodeType":1294,"data":3727,"content":3728},{},[3729],{"nodeType":1293,"value":3730,"marks":3731,"data":3732},"To illustrate how crucial the browser is to implementing controls that sit at the apex of the Pyramid of Pain, we created a modified version designed specifically for identity attacks. ",[],{},{"nodeType":1322,"data":3734,"content":3738},{"target":3735},{"sys":3736},{"id":3737,"type":1327,"linkType":1328},"HrK2xQak6KfjInDbeSgv8",[],{"nodeType":1322,"data":3740,"content":3744},{"target":3741},{"sys":3742},{"id":3743,"type":1327,"linkType":1328},"7kLilJ8Y08smUI9ttM3BSO",[],{"nodeType":3170,"data":3746,"content":3747},{},[],{"nodeType":1538,"data":3749,"content":3750},{},[3751],{"nodeType":1293,"value":3752,"marks":3753,"data":3754},"Conclusion",[],{},{"nodeType":1294,"data":3756,"content":3757},{},[3758],{"nodeType":1293,"value":3759,"marks":3760,"data":3761},"Hopefully, this blog post has shone a light on why we do things the way we do here at Push. The goal of building generic detections that are difficult, painful, and costly for attackers to bypass is a key part of our design strategy, and we look forward to sharing many more controls with you that demonstrate this in the future.",[],{},{"entries":3763},{"hyperlink":3764,"inline":3765,"block":3766},[],[],[3767,3776,3784,3791],{"sys":3768,"__typename":3769,"title":3770,"caption":3771,"layoutMode":118,"file":3772},{"id":3153},"Image","Pyramid of Pain: Original","Original Pyramid of Pain model, created by David Bianco.",{"url":3773,"width":3774,"height":3775},"https://images.ctfassets.net/y1cdw1ablpvd/7dPJT7PYKX71FCCi0GeDzg/16fb3b07959612a45c1b7636da33e541/image3.png",720,405,{"sys":3777,"__typename":3769,"title":3778,"caption":3779,"layoutMode":118,"file":3780},{"id":3204},"A new era for cyber attacks","The digital perimeter for organizations has shifted as business IT has evolved: We now know how attacks are playing out, but the industry response is still being defined.",{"url":3781,"width":3782,"height":3783},"https://images.ctfassets.net/y1cdw1ablpvd/6Sflv5jP0xHb8gLVIvcGaG/098d8fc27c15e74c2e7d2b860218ec89/Slide_16_9_-_27__2_.png",1920,1080,{"sys":3785,"__typename":3769,"title":3786,"caption":3787,"layoutMode":118,"file":3788},{"id":3737},"Pyramid of pain: Identity attacks edition","Applying the Pyramid of Pain concept to identity attacks.",{"url":3097,"width":3789,"height":3790},2815,1087,{"sys":3792,"__typename":3793,"type":3794,"ctaText":3795,"buttonLabel":3796,"buttonColour":3797,"buttonUrl":3716},{"id":3743},"CtaWidget","Custom","Learn more about how browser telemetry stacks up against up against other data sources for detecting identity attacks.","Read the Blog","sunny orange","content:blog:our-design-philosophy-detecting-what-matters.json","json","content","blog/our-design-philosophy-detecting-what-matters.json","blog/our-design-philosophy-detecting-what-matters",1776359987881]