[{"data":1,"prerenderedAt":4951},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/snowflake-retro":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"ogImage":118,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1296,"synopsis":1297,"hashTags":118,"publishedDate":1298,"slug":1299,"tagsCollection":1300,"relatedBlogPostsCollection":1306,"authorsCollection":4083,"content":4087,"_id":4946,"_type":4947,"_source":4948,"_file":4949,"_stem":4950,"_extension":4947},"/blog/snowflake-retro","blog",{"id":1280,"publishedAt":1281},"PAPJPr3CIB6J20udYyy1r","2026-04-08T15:56:21.318Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"The campaign against Snowflake customers in 2024 was a watershed moment for the cyber security industry, indicating that we’ve entered a new era of cyber security in which identity is the new perimeter.","text","paragraph","document","Snowflake: Looking back on 2024’s landmark security event","165 Snowflake customers were targeted by criminals using stolen credentials from infostealer infections, impacting hundreds of millions of people. ","2024-11-29T00:00:00.000Z","snowflake-retro",{"items":1301},[1302],{"sys":1303,"name":1305},{"id":1304},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":1307},[1308,2055,3238],{"__typename":1309,"sys":1310,"content":1312,"title":2033,"synopsis":2034,"hashTags":118,"publishedDate":2035,"slug":2036,"tagsCollection":2037,"authorsCollection":2047},"BlogPosts",{"id":1311},"6vCr4d3R1XA1E8dU883l7N",{"json":1313},{"nodeType":1295,"data":1314,"content":1315},{},[1316,1325,1329,1345,1352,1359,1365,1372,1393,1413,1420,1426,1433,1436,1444,1451,1458,1466,1473,1480,1515,1521,1528,1531,1538,1545,1663,1670,1688,1695,1715,1722,1743,1750,1770,1773,1780,1787,1794,1827,1834,1841,1860,1866,1873,1880,1886,1893,1956,1963,1970,1977,1984,1991,1994,2001,2021,2027],{"nodeType":1317,"data":1318,"content":1324},"embedded-entry-block",{"target":1319},{"sys":1320},{"id":1321,"type":1322,"linkType":1323},"HcoxuG8EK0w5uFQlN0hbh","Link","Entry",[],{"nodeType":1326,"data":1327,"content":1328},"hr",{},[],{"nodeType":1294,"data":1330,"content":1331},{},[1332,1336,1341],{"nodeType":1293,"value":1333,"marks":1334,"data":1335},"While ",[],{},{"nodeType":1293,"value":1337,"marks":1338,"data":1340},"striking",[1339],{"type":312},{},{"nodeType":1293,"value":1342,"marks":1343,"data":1344}," gold sure feels good, mining for gold doesn’t. All that sifting for a few grains of value. ",[],{},{"nodeType":1294,"data":1346,"content":1347},{},[1348],{"nodeType":1293,"value":1349,"marks":1350,"data":1351},"If you’ve ever tried to make use of a TI feed on stolen credentials, you’ll know exactly how this feels. Yet the need to identify signal from noise is obvious. When it matters, it really matters. ",[],{},{"nodeType":1294,"data":1353,"content":1354},{},[1355],{"nodeType":1293,"value":1356,"marks":1357,"data":1358},"While there’s an enormous volume of TI data available on stolen creds, data trustworthiness is much harder to establish. Are these creds still in use? Are they in use on company applications? And without trust in the data, it’s harder to take action.",[],{},{"nodeType":1317,"data":1360,"content":1364},{"target":1361},{"sys":1362},{"id":1363,"type":1322,"linkType":1323},"4unFZadFrWEQsiHsD3YAEo",[],{"nodeType":1294,"data":1366,"content":1367},{},[1368],{"nodeType":1293,"value":1369,"marks":1370,"data":1371},"We set out to solve this problem at Push and ended up flipping the script on conventional approaches to evaluating TI on stolen credentials. (Lay down your shovel, friend.)",[],{},{"nodeType":1373,"data":1374,"content":1375},"blockquote",{},[1376],{"nodeType":1294,"data":1377,"content":1378},{},[1379,1383,1389],{"nodeType":1293,"value":1380,"marks":1381,"data":1382},"With our latest release, Push takes TI on stolen credentials sourced from criminal forums and compares it to the actual credentials still being used across customer environments, ",[],{},{"nodeType":1293,"value":1384,"marks":1385,"data":1388},"alerting on validated true positives only",[1386],{"type":1387},"bold",{},{"nodeType":1293,"value":1390,"marks":1391,"data":1392},". ",[],{},{"nodeType":1294,"data":1394,"content":1395},{},[1396,1400,1409],{"nodeType":1293,"value":1397,"marks":1398,"data":1399},"As of January 2025, you can also bring your own TI to the Push platform. Using the ",[],{},{"nodeType":1401,"data":1402,"content":1404},"hyperlink",{"uri":1403},"https://pushsecurity.redoc.ly/rest-v1#tag/Stolen-credential-detection",[1405],{"nodeType":1293,"value":1406,"marks":1407,"data":1408},"Push REST API",[],{},{"nodeType":1293,"value":1410,"marks":1411,"data":1412},", you can share stolen credential reports you receive from your existing vendors and task the Push browser agent with finding the ones still in use by employees.",[],{},{"nodeType":1294,"data":1414,"content":1415},{},[1416],{"nodeType":1293,"value":1417,"marks":1418,"data":1419},"Call it the “dirt in, gold out” model for TI feeds.",[],{},{"nodeType":1317,"data":1421,"content":1425},{"target":1422},{"sys":1423},{"id":1424,"type":1322,"linkType":1323},"5VtuerdMpP4U9yL7pjrb4P",[],{"nodeType":1294,"data":1427,"content":1428},{},[1429],{"nodeType":1293,"value":1430,"marks":1431,"data":1432},"In this article, we’ll cover some of the challenges with threat intel on stolen credentials, why the rise of infostealers has added urgency to determining the trustworthiness of this category of threat, and how Push’s approach of validating stolen credentials cuts through uncertainty. ",[],{},{"nodeType":1326,"data":1434,"content":1435},{},[],{"nodeType":1437,"data":1438,"content":1439},"heading-1",{},[1440],{"nodeType":1293,"value":1441,"marks":1442,"data":1443},"Why actionable intel on creds is hard",[],{},{"nodeType":1294,"data":1445,"content":1446},{},[1447],{"nodeType":1293,"value":1448,"marks":1449,"data":1450},"Both threat actors and security teams have ready access to information on stolen credentials, with obviously opposite goals. There is now a robust economy for this data, driven in part by both the success of attacks using stolen creds, and the SaaS-ification of business software. In the past, security teams could audit their Active Directory passwords. Today, many if not most corporate credentials are stored in apps that do not provide that level of visibility.",[],{},{"nodeType":1294,"data":1452,"content":1453},{},[1454],{"nodeType":1293,"value":1455,"marks":1456,"data":1457},"So when it comes to stolen credential TI, the challenge is not the availability of data — dozens of vendors already do the hard work of establishing presences in these forums in order to collect and disseminate information on credentials such as usernames, passwords, cookies, and API keys that have been stolen through data breaches, phishing attacks, infostealers, or other methods. ",[],{},{"nodeType":1459,"data":1460,"content":1461},"heading-2",{},[1462],{"nodeType":1293,"value":1463,"marks":1464,"data":1465},"Too much data, not enough context",[],{},{"nodeType":1294,"data":1467,"content":1468},{},[1469],{"nodeType":1293,"value":1470,"marks":1471,"data":1472},"Rather, the difficulty is determining which information to act on. Finding the gold, in other words.",[],{},{"nodeType":1294,"data":1474,"content":1475},{},[1476],{"nodeType":1293,"value":1477,"marks":1478,"data":1479},"TI on stolen credentials often suffers from:",[],{},{"nodeType":1481,"data":1482,"content":1483},"unordered-list",{},[1484,1500],{"nodeType":1485,"data":1486,"content":1487},"list-item",{},[1488],{"nodeType":1294,"data":1489,"content":1490},{},[1491,1496],{"nodeType":1293,"value":1492,"marks":1493,"data":1495},"Data overload:",[1494],{"type":1387},{},{"nodeType":1293,"value":1497,"marks":1498,"data":1499}," The double bind of TI is especially evident here — once you know about a potential true positive, you feel obligated to investigate, yet the scale of the information and the high incidence of outdated or incomplete information can pose a risk of desensitizing the SOC or wasting dozens of hours of time investigating what turn out to be false positives, especially when that time could have been better spent on in-depth threat hunting.",[],{},{"nodeType":1485,"data":1501,"content":1502},{},[1503],{"nodeType":1294,"data":1504,"content":1505},{},[1506,1511],{"nodeType":1293,"value":1507,"marks":1508,"data":1510},"Minimal context:",[1509],{"type":1387},{},{"nodeType":1293,"value":1512,"marks":1513,"data":1514}," Intelligence is often incomplete or out of date. TI feeds may present stolen passwords as new breaches, but the data is actually a recycled combolist (aggregated list of lists) rather than a new incident. In some situations, infostealer threat intel can stem from a personal device that was compromised and once accessed corporate assets, but is no longer active or using that password. Then there are the false negatives, where you get an alert for stolen credentials on a core app following a breach, and the creds are no longer in use there — but they are still being used on a different high-value app. ",[],{},{"nodeType":1317,"data":1516,"content":1520},{"target":1517},{"sys":1518},{"id":1519,"type":1322,"linkType":1323},"40ZWbzJFQLRjCAaFCA0YLS",[],{"nodeType":1294,"data":1522,"content":1523},{},[1524],{"nodeType":1293,"value":1525,"marks":1526,"data":1527},"Despite these challenges, there is still a strong case for incorporating TI on stolen creds into your cyber defense practice for one important reason: Attackers are increasingly using stolen credentials to compromise organizations.",[],{},{"nodeType":1326,"data":1529,"content":1530},{},[],{"nodeType":1437,"data":1532,"content":1533},{},[1534],{"nodeType":1293,"value":1535,"marks":1536,"data":1537},"The commodification of stolen creds in the age of infostealers",[],{},{"nodeType":1294,"data":1539,"content":1540},{},[1541],{"nodeType":1293,"value":1542,"marks":1543,"data":1544},"A few headline stats on how ubiquitous stolen credential exploitation has become:",[],{},{"nodeType":1481,"data":1546,"content":1547},{},[1548,1572,1594,1617,1653],{"nodeType":1485,"data":1549,"content":1550},{},[1551],{"nodeType":1294,"data":1552,"content":1553},{},[1554,1558,1568],{"nodeType":1293,"value":1555,"marks":1556,"data":1557},"The ",[],{},{"nodeType":1401,"data":1559,"content":1561},{"uri":1560},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[1562],{"nodeType":1293,"value":1563,"marks":1564,"data":1567},"2024 Verizon DBIR",[1565],{"type":1566},"underline",{},{"nodeType":1293,"value":1569,"marks":1570,"data":1571}," found that 79% of web application compromises were the result of breached credentials.",[],{},{"nodeType":1485,"data":1573,"content":1574},{},[1575],{"nodeType":1294,"data":1576,"content":1577},{},[1578,1581,1590],{"nodeType":1293,"value":37,"marks":1579,"data":1580},[],{},{"nodeType":1401,"data":1582,"content":1584},{"uri":1583},"https://www.ibm.com/reports/threat-intelligence",[1585],{"nodeType":1293,"value":1586,"marks":1587,"data":1589},"Researchers at IBM",[1588],{"type":1566},{},{"nodeType":1293,"value":1591,"marks":1592,"data":1593}," identified a 71% year-over-year increase in cyberattacks using stolen or compromised credentials. This jump made stolen creds the No. 1 source of initial access for cyberattacks in their study. They also found a 266% uptick in the last year in the use of infostealers — malware designed to capture passwords, cookies, and other credential data.",[],{},{"nodeType":1485,"data":1595,"content":1596},{},[1597],{"nodeType":1294,"data":1598,"content":1599},{},[1600,1604,1613],{"nodeType":1293,"value":1601,"marks":1602,"data":1603},"Researchers at threat intelligence provider ",[],{},{"nodeType":1401,"data":1605,"content":1607},{"uri":1606},"https://go.recordedfuture.com/hubfs/reports/ta-2024-0321.pdf",[1608],{"nodeType":1293,"value":1609,"marks":1610,"data":1612},"Recorded Future",[1611],{"type":1566},{},{"nodeType":1293,"value":1614,"marks":1615,"data":1616}," found a 135% increase last year in the number of harvested credentials among their data sources, and a 166% increase in credentials that included cookies, providing an easy way for attackers to bypass MFA protections.",[],{},{"nodeType":1485,"data":1618,"content":1619},{},[1620],{"nodeType":1294,"data":1621,"content":1622},{},[1623,1627,1636,1640,1649],{"nodeType":1293,"value":1624,"marks":1625,"data":1626},"Meanwhile, Mandiant’s last two ",[],{},{"nodeType":1401,"data":1628,"content":1630},{"uri":1629},"https://cloud.google.com/security/resources/m-trends",[1631],{"nodeType":1293,"value":1632,"marks":1633,"data":1635},"M-Trends reports",[1634],{"type":1566},{},{"nodeType":1293,"value":1637,"marks":1638,"data":1639}," found that stolen creds were the third and fourth most-used initial intrusion method of the last two years. Cisco Talos researchers found that the ",[],{},{"nodeType":1401,"data":1641,"content":1643},{"uri":1642},"https://blog.talosintelligence.com/cisco-talos-2023-year-in-review/",[1644],{"nodeType":1293,"value":1645,"marks":1646,"data":1648},"use of valid accounts",[1647],{"type":1566},{},{"nodeType":1293,"value":1650,"marks":1651,"data":1652}," was the second-most common attack technique they observed last year.",[],{},{"nodeType":1485,"data":1654,"content":1655},{},[1656],{"nodeType":1294,"data":1657,"content":1658},{},[1659],{"nodeType":1293,"value":1660,"marks":1661,"data":1662},"Push’s own review of the 25 most notable public identity-related breaches over the last year found that 23 were tied to stolen credentials.",[],{},{"nodeType":1294,"data":1664,"content":1665},{},[1666],{"nodeType":1293,"value":1667,"marks":1668,"data":1669},"What’s not immediately obvious from these statistics is that not only are credential-based attacks becoming more common, but they’re also becoming easier for attackers to execute.",[],{},{"nodeType":1294,"data":1671,"content":1672},{},[1673,1676,1684],{"nodeType":1293,"value":37,"marks":1674,"data":1675},[],{},{"nodeType":1401,"data":1677,"content":1678},{"uri":1583},[1679],{"nodeType":1293,"value":1680,"marks":1681,"data":1683},"IBM X-Force researchers",[1682],{"type":1566},{},{"nodeType":1293,"value":1685,"marks":1686,"data":1687}," have found that credentials for cloud accounts account for 90% of all cloud assets for sale on the dark web, making them readily accessible. Price tags can be as low as $10.",[],{},{"nodeType":1459,"data":1689,"content":1690},{},[1691],{"nodeType":1293,"value":1692,"marks":1693,"data":1694},"The rise of infostealers has supercharged the stolen credential marketplace",[],{},{"nodeType":1294,"data":1696,"content":1697},{},[1698,1702,1711],{"nodeType":1293,"value":1699,"marks":1700,"data":1701},"One category of threat — infostealer malware — has emerged as an especially successful avenue of compromise. While infostealers aren’t new, they have developed alongside what is now a robust economy for stolen credentials (think: dedicated Telegram channels advertising stolen data from the most popular infostealers), making them a fruitful option for attackers. For a deeper dive on the rise of infostealers, see our ",[],{},{"nodeType":1401,"data":1703,"content":1705},{"uri":1704},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/",[1706],{"nodeType":1293,"value":1707,"marks":1708,"data":1710},"previous article",[1709],{"type":1566},{},{"nodeType":1293,"value":1712,"marks":1713,"data":1714},".",[],{},{"nodeType":1294,"data":1716,"content":1717},{},[1718],{"nodeType":1293,"value":1719,"marks":1720,"data":1721},"Once attackers gain possession of stolen creds, they have plenty of soft targets. For organizations with a large amount of SaaS — a percentage of which will always be unmanaged shadow IT or freemium — the risk is heightened because all attackers need to do is log in to potentially hundreds of services, dump the data they find (including additional creds in some cases), and profit. ",[],{},{"nodeType":1294,"data":1723,"content":1724},{},[1725,1729,1739],{"nodeType":1293,"value":1726,"marks":1727,"data":1728},"In other words, the average attack path for SaaS is shorter and occurs in-app, often using legitimate workflows, making it therefore harder to detect than traditional network exploits. We discuss this phenomenon in our ",[],{},{"nodeType":1401,"data":1730,"content":1732},{"uri":1731},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[1733],{"nodeType":1293,"value":1734,"marks":1735,"data":1738},"shifting detection left",[1736,1737],{"type":1566},{"type":1387},{},{"nodeType":1293,"value":1740,"marks":1741,"data":1742}," article.",[],{},{"nodeType":1294,"data":1744,"content":1745},{},[1746],{"nodeType":1293,"value":1747,"marks":1748,"data":1749},"Our take: We haven’t yet seen the peak of identity attacks that leverage compromised credentials. The opportunities for attackers are too numerous, and front-line defenses like MFA are still not widely enough enforced, particularly on unmanaged apps used for work.",[],{},{"nodeType":1294,"data":1751,"content":1752},{},[1753,1757,1766],{"nodeType":1293,"value":1754,"marks":1755,"data":1756},"Push Security’s ",[],{},{"nodeType":1401,"data":1758,"content":1760},{"uri":1759},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[1761],{"nodeType":1293,"value":1762,"marks":1763,"data":1765},"own research",[1764],{"type":1566},{},{"nodeType":1293,"value":1767,"marks":1768,"data":1769}," has found that 37% of corporate identities are using passwords with no MFA. For attackers in possession of stolen creds, these are easy marks.",[],{},{"nodeType":1326,"data":1771,"content":1772},{},[],{"nodeType":1437,"data":1774,"content":1775},{},[1776],{"nodeType":1293,"value":1777,"marks":1778,"data":1779},"How Push detects stolen creds with high confidence",[],{},{"nodeType":1294,"data":1781,"content":1782},{},[1783],{"nodeType":1293,"value":1784,"marks":1785,"data":1786},"Now let’s take a look at how Push’s approach to this problem is different.",[],{},{"nodeType":1294,"data":1788,"content":1789},{},[1790],{"nodeType":1293,"value":1791,"marks":1792,"data":1793},"If you’re not familiar with the Push platform, a bit of context will be useful here: Push uses a browser agent deployed to employee browsers (we support all major browsers) to prevent, detect, and block identity attacks. ",[],{},{"nodeType":1294,"data":1795,"content":1796},{},[1797,1801,1810,1814,1823],{"nodeType":1293,"value":1798,"marks":1799,"data":1800},"In addition to enforcing ",[],{},{"nodeType":1401,"data":1802,"content":1804},{"uri":1803},"https://pushsecurity.com/blog/introducing-set-and-forget-controls-that-stop-real-world-identity-attacks/",[1805],{"nodeType":1293,"value":1806,"marks":1807,"data":1809},"security controls",[1808],{"type":1566},{},{"nodeType":1293,"value":1811,"marks":1812,"data":1813}," in the browser, Push also assesses the strength of end-user passwords by ",[],{},{"nodeType":1401,"data":1815,"content":1817},{"uri":1816},"https://pushsecurity.com/help/10065#start",[1818],{"nodeType":1293,"value":1819,"marks":1820,"data":1822},"creating and analyzing",[1821],{"type":1566},{},{"nodeType":1293,"value":1824,"marks":1825,"data":1826}," a truncated, salted SHA256 hash of the password for a given account. This is called a password fingerprint. These k-anonymized fingerprints are never seen by Push’s back-end and exist only in local browser extension storage.",[],{},{"nodeType":1294,"data":1828,"content":1829},{},[1830],{"nodeType":1293,"value":1831,"marks":1832,"data":1833},"This approach gives Push a directly observable source of truth for corporate credentials, and that data point turns out to be the key to flipping the script on how threat intelligence on stolen credentials is typically evaluated.",[],{},{"nodeType":1294,"data":1835,"content":1836},{},[1837],{"nodeType":1293,"value":1838,"marks":1839,"data":1840},"In the past, evaluating TI on stolen creds meant performing traditional intelligence assessments, such as confidence level based on factors like the intel source and whether the data was still current. Only after determining whether the information was high-confidence could you take action.",[],{},{"nodeType":1294,"data":1842,"content":1843},{},[1844,1848,1856],{"nodeType":1293,"value":1845,"marks":1846,"data":1847},"It’s worth noting, too, that the age of TI alone is not enough of an indicator to determine whether to take action. With the ",[],{},{"nodeType":1401,"data":1849,"content":1851},{"uri":1850},"https://pushsecurity.com/blog/snowflake-retro/",[1852],{"nodeType":1293,"value":1853,"marks":1854,"data":1855},"Snowflake breach earlier this year",[],{},{"nodeType":1293,"value":1857,"marks":1858,"data":1859},", we saw how even older credentials posed a threat of account takeover where these creds were still in use. In the case of Snowflake, the attacker used credentials sourced from historical infostealer campaigns, some dating as far back as 2020.",[],{},{"nodeType":1317,"data":1861,"content":1865},{"target":1862},{"sys":1863},{"id":1864,"type":1322,"linkType":1323},"2lSZ7HbZfLmSFXneCnVJzY",[],{"nodeType":1459,"data":1867,"content":1868},{},[1869],{"nodeType":1293,"value":1870,"marks":1871,"data":1872},"Forget about time-consuming manual TI validation and get straight to the true positives",[],{},{"nodeType":1294,"data":1874,"content":1875},{},[1876],{"nodeType":1293,"value":1877,"marks":1878,"data":1879},"With Push, the platform now can analyze threat intelligence on stolen credentials and alert when there’s a validated match among current credentials in use in your environment. This method works regardless of the source of the data or its age. This method also finds the needles in the haystack — situations where threat intel flags a stolen credential on one app, but that credential is also in use on several other apps. ",[],{},{"nodeType":1317,"data":1881,"content":1885},{"target":1882},{"sys":1883},{"id":1884,"type":1322,"linkType":1323},"7GSFasHfHb3UgpgF8pZ2N2",[],{"nodeType":1294,"data":1887,"content":1888},{},[1889],{"nodeType":1293,"value":1890,"marks":1891,"data":1892},"Here’s how it works:",[],{},{"nodeType":1481,"data":1894,"content":1895},{},[1896,1916,1926,1936,1946],{"nodeType":1485,"data":1897,"content":1898},{},[1899],{"nodeType":1294,"data":1900,"content":1901},{},[1902,1906,1913],{"nodeType":1293,"value":1903,"marks":1904,"data":1905},"Push receives TI on stolen credentials from vendor feeds. Use the feeds that Push supplies (at no additional cost for Push customers), or, additionally, bring your own TI by supplying stolen credential reports via the ",[],{},{"nodeType":1401,"data":1907,"content":1909},{"uri":1908},"https://pushsecurity.redoc.ly/rest-v1#operation/post-controls-stolenCredentials",[1910],{"nodeType":1293,"value":1406,"marks":1911,"data":1912},[],{},{"nodeType":1293,"value":1390,"marks":1914,"data":1915},[],{},{"nodeType":1485,"data":1917,"content":1918},{},[1919],{"nodeType":1294,"data":1920,"content":1921},{},[1922],{"nodeType":1293,"value":1923,"marks":1924,"data":1925},"For each customer environment, Push checks for customer domains in the data set.",[],{},{"nodeType":1485,"data":1927,"content":1928},{},[1929],{"nodeType":1294,"data":1930,"content":1931},{},[1932],{"nodeType":1293,"value":1933,"marks":1934,"data":1935},"When suspected stolen creds for a customer environment are present, Push hashes and salts the passwords and then sends those fingerprints to the relevant browser agents for comparison. ",[],{},{"nodeType":1485,"data":1937,"content":1938},{},[1939],{"nodeType":1294,"data":1940,"content":1941},{},[1942],{"nodeType":1293,"value":1943,"marks":1944,"data":1945},"If the stolen credential fingerprint matches a known credential fingerprint observed to be in use by the Push browser agent, the platform returns a validated true positive alert. Note that Push can alert on a validated true positive regardless of which platform the TI source indicated was the source of the stolen cred, allowing you to find those compromised credentials in use across any of your apps.",[],{},{"nodeType":1485,"data":1947,"content":1948},{},[1949],{"nodeType":1294,"data":1950,"content":1951},{},[1952],{"nodeType":1293,"value":1953,"marks":1954,"data":1955},"You can choose to receive alerts for this detection via webhook, ChatOps notification, or in the Push admin console.",[],{},{"nodeType":1294,"data":1957,"content":1958},{},[1959],{"nodeType":1293,"value":1960,"marks":1961,"data":1962},"From there, security teams can take action to reset passwords, identify potentially compromised devices, or perform other investigations.",[],{},{"nodeType":1294,"data":1964,"content":1965},{},[1966],{"nodeType":1293,"value":1967,"marks":1968,"data":1969},"By comparing all possible matches to only those credentials that are still in use, Push eliminates time-consuming validation exercises. In essence, the provenance of the intel no longer matters; only the true positives do.",[],{},{"nodeType":1459,"data":1971,"content":1972},{},[1973],{"nodeType":1293,"value":1974,"marks":1975,"data":1976},"Bring your own TI",[],{},{"nodeType":1294,"data":1978,"content":1979},{},[1980],{"nodeType":1293,"value":1981,"marks":1982,"data":1983},"With verified stolen credential detection, you can also extract a lot more value from your existing threat intelligence feeds by sharing stolen creds reports with the Push platform via API. ",[],{},{"nodeType":1294,"data":1985,"content":1986},{},[1987],{"nodeType":1293,"value":1988,"marks":1989,"data":1990},"This allows Push to perform the same checks to compare the reports to observed password fingerprints and flag only the true positives — eliminating the time-consuming work of manual triage, investigation, and end-user follow-up for your security team.",[],{},{"nodeType":1326,"data":1992,"content":1993},{},[],{"nodeType":1437,"data":1995,"content":1996},{},[1997],{"nodeType":1293,"value":1998,"marks":1999,"data":2000},"Try Push for yourself",[],{},{"nodeType":1294,"data":2002,"content":2003},{},[2004,2008,2017],{"nodeType":1293,"value":2005,"marks":2006,"data":2007},"The validated stolen credential detections feature is available at no additional cost for all Push customers. If you’d like to explore the platform yourself, ",[],{},{"nodeType":1401,"data":2009,"content":2011},{"uri":2010},"https://pushsecurity.com/demo/",[2012],{"nodeType":1293,"value":2013,"marks":2014,"data":2016},"request a demo",[2015],{"type":1566},{},{"nodeType":1293,"value":2018,"marks":2019,"data":2020},". ",[],{},{"nodeType":1317,"data":2022,"content":2026},{"target":2023},{"sys":2024},{"id":2025,"type":1322,"linkType":1323},"3tqVk7Vr7pYLOEVukIJM2g",[],{"nodeType":1294,"data":2028,"content":2029},{},[2030],{"nodeType":1293,"value":37,"marks":2031,"data":2032},[],{},"Eliminate false positives with verified stolen credential detections using Push","Push now compares user passwords with TI feeds to alert you when valid credentials are available on the clearweb and darkweb.","2024-12-03T00:00:00.000Z","verified-stolen-credential-detection",{"items":2038},[2039,2043],{"sys":2040,"name":2042},{"id":2041},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"sys":2044,"name":2046},{"id":2045},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":2048},[2049],{"fullName":2050,"firstName":2051,"jobTitle":2052,"profilePicture":2053},"Kelly Davenport","Kelly","Product Team",{"url":2054},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1309,"sys":2056,"content":2058,"title":3220,"synopsis":3221,"hashTags":118,"publishedDate":3222,"slug":3223,"tagsCollection":3224,"authorsCollection":3230},{"id":2057},"4OrixXXLxRmSDxa7PF9gfM",{"json":2059},{"nodeType":1295,"data":2060,"content":2061},{},[2062,2095,2107,2123,2130,2137,2140,2147,2154,2289,2296,2303,2399,2406,2413,2466,2473,2496,2553,2556,2563,2582,2602,2609,2628,2635,2647,2650,2657,2664,2712,2719,2726,2746,2749,2756,2763,2770,2789,2796,2803,2810,2830,2837,2844,2851,2858,2877,2884,2891,2898,2905,2937,2943,2946,2953,2960,2966,2973,2980,3003,3010,3017,3060,3076,3096,3102,3109,3116,3123,3155,3201,3208,3214],{"nodeType":1294,"data":2063,"content":2064},{},[2065,2069,2078,2082,2091],{"nodeType":1293,"value":2066,"marks":2067,"data":2068},"Infostealer malware seems to be grabbing the headlines right now. It’s easy to see why, too, after laying claim to one of the ",[],{},{"nodeType":1401,"data":2070,"content":2072},{"uri":2071},"https://www.wired.com/story/snowflake-breach-advanced-auto-parts-lendingtree/",[2073],{"nodeType":1293,"value":2074,"marks":2075,"data":2077},"biggest breaches in history",[2076],{"type":1566},{},{"nodeType":1293,"value":2079,"marks":2080,"data":2081},". The ",[],{},{"nodeType":1401,"data":2083,"content":2085},{"uri":2084},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[2086],{"nodeType":1293,"value":2087,"marks":2088,"data":2090},"recent attacks on Snowflake customers",[2089],{"type":1566},{},{"nodeType":1293,"value":2092,"marks":2093,"data":2094}," saw ~165 businesses compromised using stolen credentials, resulting in millions of breached customer records, with the full impact still emerging. ",[],{},{"nodeType":1294,"data":2096,"content":2097},{},[2098,2102],{"nodeType":1293,"value":2099,"marks":2100,"data":2101},"Notably, ",[],{},{"nodeType":1293,"value":2103,"marks":2104,"data":2106},"80% of the credentials used to access Snowflake customer accounts had found their way online after being stolen in infostealer infections – dating back as early as 2020. ",[2105],{"type":1387},{},{"nodeType":1294,"data":2108,"content":2109},{},[2110,2114,2119],{"nodeType":1293,"value":2111,"marks":2112,"data":2113},"The Snowflake situation is a reminder of how lucrative stolen credentials can be for attackers – and how the cybercrime ecosystem has tilted as a result. As the saying goes nowadays, ",[],{},{"nodeType":1293,"value":2115,"marks":2116,"data":2118},"hackers don’t hack in, they log in",[2117],{"type":1387},{},{"nodeType":1293,"value":2120,"marks":2121,"data":2122},". Stolen credentials are the lowest hanging fruit available to attackers, and their appetite (and the ecosystem needed to feed it) is insatiable. As an attacker, the prospect of picking up access to a major enterprise for just $10 or less (or even for free) is hard to resist – why wouldn’t you buy a ticket and take the gamble?  ",[],{},{"nodeType":1294,"data":2124,"content":2125},{},[2126],{"nodeType":1293,"value":2127,"marks":2128,"data":2129},"Infostealers are a huge part of the shift toward identity attacks. Along with phishing, infostealers are the primary mechanism for attackers to harvest credentials. Unlike phishing, infostealers can collect a large number of credentials (and other helpful data saved in the browser) in one fell swoop. But, they do have limitations. For example, you would expect any credible EDR to detect and block these attacks. And yet, the success of the attacks on Snowflake customers show us that gaps are being found and exploited.  ",[],{},{"nodeType":1294,"data":2131,"content":2132},{},[2133],{"nodeType":1293,"value":2134,"marks":2135,"data":2136},"In this article, we’ll look at the history of infostealers, how they work, and what the trends show us about how the cybercrime ecosystem is leaning into the opportunity they present.    ",[],{},{"nodeType":1326,"data":2138,"content":2139},{},[],{"nodeType":1437,"data":2141,"content":2142},{},[2143],{"nodeType":1293,"value":2144,"marks":2145,"data":2146},"The state of infostealers today",[],{},{"nodeType":1294,"data":2148,"content":2149},{},[2150],{"nodeType":1293,"value":2151,"marks":2152,"data":2153},"Infostealers, and the mass credential harvesting they enable, are a big part of the rise in identity attacks. The stats support this, as:",[],{},{"nodeType":1481,"data":2155,"content":2156},{},[2157,2180,2202,2225,2246,2267],{"nodeType":1485,"data":2158,"content":2159},{},[2160],{"nodeType":1294,"data":2161,"content":2162},{},[2163,2167,2176],{"nodeType":1293,"value":2164,"marks":2165,"data":2166},"One million new stealer logs are distributed every month, with an estimated 3-5% containing credentials and session cookies to corporate IT environments (",[],{},{"nodeType":1401,"data":2168,"content":2170},{"uri":2169},"https://www.bleepingcomputer.com/news/security/single-sign-on-and-the-cybercrime-ecosystem/",[2171],{"nodeType":1293,"value":2172,"marks":2173,"data":2175},"Flare",[2174],{"type":1566},{},{"nodeType":1293,"value":2177,"marks":2178,"data":2179},").",[],{},{"nodeType":1485,"data":2181,"content":2182},{},[2183],{"nodeType":1294,"data":2184,"content":2185},{},[2186,2190,2199],{"nodeType":1293,"value":2187,"marks":2188,"data":2189},"Infostealer activity increased by 266% in 2023, while the number of attacks featuring valid credentials saw a 71% increase year-over-year (",[],{},{"nodeType":1401,"data":2191,"content":2193},{"uri":2192},"https://www.ibm.com/downloads/cas/L0GKXDWJ",[2194],{"nodeType":1293,"value":2195,"marks":2196,"data":2198},"IBM",[2197],{"type":1566},{},{"nodeType":1293,"value":2177,"marks":2200,"data":2201},[],{},{"nodeType":1485,"data":2203,"content":2204},{},[2205],{"nodeType":1294,"data":2206,"content":2207},{},[2208,2212,2221],{"nodeType":1293,"value":2209,"marks":2210,"data":2211},"147,000 token replay attacks were detected by Microsoft in 2023, an 111% increase year-over-year (",[],{},{"nodeType":1401,"data":2213,"content":2215},{"uri":2214},"https://techcommunity.microsoft.com/t5/microsoft-entra-blog/how-to-break-the-token-theft-cyber-attack-chain/ba-p/4062700",[2216],{"nodeType":1293,"value":2217,"marks":2218,"data":2220},"Microsoft",[2219],{"type":1566},{},{"nodeType":1293,"value":2222,"marks":2223,"data":2224},"). ",[],{},{"nodeType":1485,"data":2226,"content":2227},{},[2228],{"nodeType":1294,"data":2229,"content":2230},{},[2231,2235,2243],{"nodeType":1293,"value":2232,"marks":2233,"data":2234},"Over 1000 credentials are posted online per day, per marketplace with an average sale price of $10, and 65% posted less than one day after being collected (",[],{},{"nodeType":1401,"data":2236,"content":2237},{"uri":1560},[2238],{"nodeType":1293,"value":2239,"marks":2240,"data":2242},"Verizon",[2241],{"type":1566},{},{"nodeType":1293,"value":2177,"marks":2244,"data":2245},[],{},{"nodeType":1485,"data":2247,"content":2248},{},[2249],{"nodeType":1294,"data":2250,"content":2251},{},[2252,2256,2264],{"nodeType":1293,"value":2253,"marks":2254,"data":2255},"Nearly half of the malware detected last year by Sophos targeted victims’ data specifically, and the majority of that malware was classified as infostealers (",[],{},{"nodeType":1401,"data":2257,"content":2259},{"uri":2258},"https://news.sophos.com/en-us/2024/03/12/2024-sophos-threat-report/",[2260],{"nodeType":1293,"value":2261,"marks":2262,"data":2263},"Sophos",[],{},{"nodeType":1293,"value":2177,"marks":2265,"data":2266},[],{},{"nodeType":1485,"data":2268,"content":2269},{},[2270],{"nodeType":1294,"data":2271,"content":2272},{},[2273,2277,2286],{"nodeType":1293,"value":2274,"marks":2275,"data":2276},"Attacks on session cookies happen at the same order of magnitude as password-based attacks (",[],{},{"nodeType":1401,"data":2278,"content":2280},{"uri":2279},"https://github.com/WICG/dbsc/issues/13#issuecomment-1977657864",[2281],{"nodeType":1293,"value":2282,"marks":2283,"data":2285},"Google",[2284],{"type":1566},{},{"nodeType":1293,"value":2177,"marks":2287,"data":2288},[],{},{"nodeType":1459,"data":2290,"content":2291},{},[2292],{"nodeType":1293,"value":2293,"marks":2294,"data":2295},"How did we get here?",[],{},{"nodeType":1294,"data":2297,"content":2298},{},[2299],{"nodeType":1293,"value":2300,"marks":2301,"data":2302},"Let’s go back to the beginning. When they first emerged, infostealers were designed to steal online banking and credit card information. The most notable early example comes from as far back as 2006 with the ZeuS trojan. After the ZeuS source code was leaked in March 2011, the creation of multiple variants boosted the popularity of this type of malware and inspired the development of infostealers with increasingly sophisticated capabilities.",[],{},{"nodeType":1294,"data":2304,"content":2305},{},[2306,2310,2319,2323,2332,2336,2345,2349,2358,2361,2370,2373,2382,2386,2395],{"nodeType":1293,"value":2307,"marks":2308,"data":2309},"Modern infostealers rose to prominence in around 2018 with the emergence of ",[],{},{"nodeType":1401,"data":2311,"content":2313},{"uri":2312},"https://malpedia.caad.fkie.fraunhofer.de/details/win.arkei_stealer",[2314],{"nodeType":1293,"value":2315,"marks":2316,"data":2318},"Arkei",[2317],{"type":1566},{},{"nodeType":1293,"value":2320,"marks":2321,"data":2322},", which quickly spawned the more popular ",[],{},{"nodeType":1401,"data":2324,"content":2326},{"uri":2325},"https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar",[2327],{"nodeType":1293,"value":2328,"marks":2329,"data":2331},"Vidar",[2330],{"type":1566},{},{"nodeType":1293,"value":2333,"marks":2334,"data":2335}," stealer. Today, some of the most popular families are ",[],{},{"nodeType":1401,"data":2337,"content":2339},{"uri":2338},"https://malpedia.caad.fkie.fraunhofer.de/details/win.risepro",[2340],{"nodeType":1293,"value":2341,"marks":2342,"data":2344},"RisePro",[2343],{"type":1566},{},{"nodeType":1293,"value":2346,"marks":2347,"data":2348},", ",[],{},{"nodeType":1401,"data":2350,"content":2352},{"uri":2351},"https://malpedia.caad.fkie.fraunhofer.de/details/win.redline_stealer",[2353],{"nodeType":1293,"value":2354,"marks":2355,"data":2357},"RedLine",[2356],{"type":1566},{},{"nodeType":1293,"value":2346,"marks":2359,"data":2360},[],{},{"nodeType":1401,"data":2362,"content":2364},{"uri":2363},"https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc",[2365],{"nodeType":1293,"value":2366,"marks":2367,"data":2369},"StealC",[2368],{"type":1566},{},{"nodeType":1293,"value":2346,"marks":2371,"data":2372},[],{},{"nodeType":1401,"data":2374,"content":2376},{"uri":2375},"https://malpedia.caad.fkie.fraunhofer.de/details/win.raccoon",[2377],{"nodeType":1293,"value":2378,"marks":2379,"data":2381},"Raccoon",[2380],{"type":1566},{},{"nodeType":1293,"value":2383,"marks":2384,"data":2385},", and ",[],{},{"nodeType":1401,"data":2387,"content":2389},{"uri":2388},"https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma",[2390],{"nodeType":1293,"value":2391,"marks":2392,"data":2394},"Lumma",[2393],{"type":1566},{},{"nodeType":1293,"value":2396,"marks":2397,"data":2398},", with new variants and families appearing all the time. ",[],{},{"nodeType":1294,"data":2400,"content":2401},{},[2402],{"nodeType":1293,"value":2403,"marks":2404,"data":2405},"Infostealers are used by all manner of threat actors of varying levels of sophistication. For larger groups with sufficient resources, the creation of new, custom stealers and malware packages is a common tactic to attempt to evade detection. ",[],{},{"nodeType":1294,"data":2407,"content":2408},{},[2409],{"nodeType":1293,"value":2410,"marks":2411,"data":2412},"But despite all the variants, infostealers do have common capabilities and characteristics, such as:",[],{},{"nodeType":1481,"data":2414,"content":2415},{},[2416,2426,2436,2446,2456],{"nodeType":1485,"data":2417,"content":2418},{},[2419],{"nodeType":1294,"data":2420,"content":2421},{},[2422],{"nodeType":1293,"value":2423,"marks":2424,"data":2425},"Extracting information from the browsers of a compromised device, such as passwords, cookies, autofill information, downloaded file information.",[],{},{"nodeType":1485,"data":2427,"content":2428},{},[2429],{"nodeType":1294,"data":2430,"content":2431},{},[2432],{"nodeType":1293,"value":2433,"marks":2434,"data":2435},"Snapshotting the desktop and system inventory, with details such as the username, location data, hardware configuration, and information regarding installed security software.",[],{},{"nodeType":1485,"data":2437,"content":2438},{},[2439],{"nodeType":1294,"data":2440,"content":2441},{},[2442],{"nodeType":1293,"value":2443,"marks":2444,"data":2445},"Sending stolen data back to a C2 server.",[],{},{"nodeType":1485,"data":2447,"content":2448},{},[2449],{"nodeType":1294,"data":2450,"content":2451},{},[2452],{"nodeType":1293,"value":2453,"marks":2454,"data":2455},"Facilitating the deployment of additional tools and malware as part of a package. ",[],{},{"nodeType":1485,"data":2457,"content":2458},{},[2459],{"nodeType":1294,"data":2460,"content":2461},{},[2462],{"nodeType":1293,"value":2463,"marks":2464,"data":2465},"Often (but not always) self-terminating once complete, leaving little trace on the victim machine and no ongoing behavior that might be detected. ",[],{},{"nodeType":1294,"data":2467,"content":2468},{},[2469],{"nodeType":1293,"value":2470,"marks":2471,"data":2472},"Infostealers are distributed in similar ways to other types of malware, such as:",[],{},{"nodeType":1481,"data":2474,"content":2475},{},[2476,2486],{"nodeType":1485,"data":2477,"content":2478},{},[2479],{"nodeType":1294,"data":2480,"content":2481},{},[2482],{"nodeType":1293,"value":2483,"marks":2484,"data":2485},"Delivery of malicious executable files via phishing emails or by having a victim download content from a malicious website. ",[],{},{"nodeType":1485,"data":2487,"content":2488},{},[2489],{"nodeType":1294,"data":2490,"content":2491},{},[2492],{"nodeType":1293,"value":2493,"marks":2494,"data":2495},"‘Drive-by’ style attacks where the victim has only to visit an infected website.",[],{},{"nodeType":1294,"data":2497,"content":2498},{},[2499,2503,2512,2515,2524,2527,2536,2540,2549],{"nodeType":1293,"value":2500,"marks":2501,"data":2502},"They’re typically spread via malvertising, P2P downloads, and deceptive software download sites. ",[],{},{"nodeType":1401,"data":2504,"content":2506},{"uri":2505},"https://www.bleepingcomputer.com/news/security/fake-cheat-lures-gamers-into-spreading-infostealer-malware/",[2507],{"nodeType":1293,"value":2508,"marks":2509,"data":2511},"Gaming forums",[2510],{"type":1566},{},{"nodeType":1293,"value":2346,"marks":2513,"data":2514},[],{},{"nodeType":1401,"data":2516,"content":2518},{"uri":2517},"https://cybersecuritynews.com/facebook-account-hijack-malware/",[2519],{"nodeType":1293,"value":2520,"marks":2521,"data":2523},"Facebook ads",[2522],{"type":1566},{},{"nodeType":1293,"value":2383,"marks":2525,"data":2526},[],{},{"nodeType":1401,"data":2528,"content":2530},{"uri":2529},"https://www.fortinet.com/blog/threat-research/lumma-variant-on-youtube",[2531],{"nodeType":1293,"value":2532,"marks":2533,"data":2535},"YouTube video descriptions",[2534],{"type":1566},{},{"nodeType":1293,"value":2537,"marks":2538,"data":2539}," are popular locations for malicious links, but recent examples also include ",[],{},{"nodeType":1401,"data":2541,"content":2543},{"uri":2542},"https://www.bleepingcomputer.com/news/security/over-3-000-github-accounts-used-by-malware-distribution-service/",[2544],{"nodeType":1293,"value":2545,"marks":2546,"data":2548},"complex malware distribution networks on GitHub",[2547],{"type":1566},{},{"nodeType":1293,"value":2550,"marks":2551,"data":2552}," – such as the recent campaign from ‘Stargazer Goblin’ with more than 3,000 fake accounts creating and promoting hundreds of fake repositories to increase their apparent legitimacy and make them more likely to appear on GitHub's trending section.",[],{},{"nodeType":1326,"data":2554,"content":2555},{},[],{"nodeType":1437,"data":2557,"content":2558},{},[2559],{"nodeType":1293,"value":2560,"marks":2561,"data":2562},"Infostealers are key to the cybercrime ecosystem",[],{},{"nodeType":1294,"data":2564,"content":2565},{},[2566,2570,2578],{"nodeType":1293,"value":2567,"marks":2568,"data":2569},"After being stolen, ",[],{},{"nodeType":1401,"data":2571,"content":2572},{"uri":2169},[2573],{"nodeType":1293,"value":2574,"marks":2575,"data":2577},"infostealer data inevitably finds its way onto hacker forums and marketplaces",[2576],{"type":1566},{},{"nodeType":1293,"value":2579,"marks":2580,"data":2581},", both on the clearweb and darkweb. Popular infostealers have their own dedicated Telegram channels to advertise and sell stolen data. Private channels also exist, with the channel owner distributing tens of thousands of logs per week to a limited number of threat actors who pay $200-$400 for access to the channel. This allows them to get ‘first pick’ of stolen logs, which are later shared through public Telegram channels. ",[],{},{"nodeType":1294,"data":2583,"content":2584},{},[2585,2589,2598],{"nodeType":1293,"value":2586,"marks":2587,"data":2588},"Public data eventually makes its way onto services such as Have I Been Pwned (HIBP), which gives individuals and security teams some visibility of which credentials have been compromised. For example, ",[],{},{"nodeType":1401,"data":2590,"content":2592},{"uri":2591},"https://www.troyhunt.com/telegram-combolists-and-361m-email-addresses/",[2593],{"nodeType":1293,"value":2594,"marks":2595,"data":2597},"in June, Troy Hunt (creator of HIBP) wrote",[2596],{"type":1566},{},{"nodeType":1293,"value":2599,"marks":2600,"data":2601}," about the impact of channels like Telegram and the sale of combolists (username, password, login portal URL), after being sent 122GB of data scraped out of thousands of Telegram channels, containing 361M unique email addresses (of which 151M had never been seen in HIBP before). ",[],{},{"nodeType":1294,"data":2603,"content":2604},{},[2605],{"nodeType":1293,"value":2606,"marks":2607,"data":2608},"The cybercrime ecosystem is complex, with a developed supply chain and organizations fulfilling different roles as a result: from malware-as-a-service developers, to initial access brokers, to the operators that actually conduct the attacks (be they ransomware, data theft, etc.) – and many, many other roles in between. Sometimes, a single group and/or its affiliates will conduct the full chain, but this is far less common today. ",[],{},{"nodeType":1294,"data":2610,"content":2611},{},[2612,2615,2624],{"nodeType":1293,"value":37,"marks":2613,"data":2614},[],{},{"nodeType":1401,"data":2616,"content":2618},{"uri":2617},"https://www.secureworks.com/research/the-growing-threat-from-infostealers",[2619],{"nodeType":1293,"value":2620,"marks":2621,"data":2623},"Infostealers are often sold by malware developers to other attackers as a monthly subscription service.",[2622],{"type":1566},{},{"nodeType":1293,"value":2625,"marks":2626,"data":2627}," The price can range from $50 to over $1,000 USD per month for access to a stealer command and control (C2) server operated by the developer. The service often features a range of support functions, including multiple ways to view, download, and share stolen data. Self-hosted stealer C2 servers are also available and are usually sold for a flat fee. ",[],{},{"nodeType":1294,"data":2629,"content":2630},{},[2631],{"nodeType":1293,"value":2632,"marks":2633,"data":2634},"There’s also evidence that there is an element of target coordination – with one marketplace, Russian Market, allowing users to ‘preorder’ credentials for a $1,000 USD deposit from 2022. ",[],{},{"nodeType":1294,"data":2636,"content":2637},{},[2638,2643],{"nodeType":1293,"value":2639,"marks":2640,"data":2642},"So what? Well, there's evidently an abundance of breached data already online, and attackers have the tools readily available to have this pile grow exponentially bigger and more useful.",[2641],{"type":1387},{},{"nodeType":1293,"value":2644,"marks":2645,"data":2646}," It’s also probably more coordinated than we like to admit – a particularly intimidating prospect in the wake of Snowflake, which will no doubt have many criminals smelling blood in the water. ",[],{},{"nodeType":1326,"data":2648,"content":2649},{},[],{"nodeType":1437,"data":2651,"content":2652},{},[2653],{"nodeType":1293,"value":2654,"marks":2655,"data":2656},"How can stolen data be abused by attackers? ",[],{},{"nodeType":1294,"data":2658,"content":2659},{},[2660],{"nodeType":1293,"value":2661,"marks":2662,"data":2663},"It’s pretty obvious that attackers getting access to all of your passwords and session cookies is bad, but there is a clear value hierarchy from a corporate security perspective. So, from highest to lowest risk:",[],{},{"nodeType":1481,"data":2665,"content":2666},{},[2667,2682,2697],{"nodeType":1485,"data":2668,"content":2669},{},[2670],{"nodeType":1294,"data":2671,"content":2672},{},[2673,2678],{"nodeType":1293,"value":2674,"marks":2675,"data":2677},"Stolen session cookies",[2676],{"type":1387},{},{"nodeType":1293,"value":2679,"marks":2680,"data":2681}," simply need to be imported into an attacker’s browser to resume an active session on an app. That means access can be gained without needing to enter a username and password, or pass any MFA checks. ",[],{},{"nodeType":1485,"data":2683,"content":2684},{},[2685],{"nodeType":1294,"data":2686,"content":2687},{},[2688,2693],{"nodeType":1293,"value":2689,"marks":2690,"data":2692},"Stolen usernames, passwords",[2691],{"type":1387},{},{"nodeType":1293,"value":2694,"marks":2695,"data":2696},", and login page URLs can be used to access any accounts that lack MFA. ",[],{},{"nodeType":1485,"data":2698,"content":2699},{},[2700],{"nodeType":1294,"data":2701,"content":2702},{},[2703,2708],{"nodeType":1293,"value":2704,"marks":2705,"data":2707},"Stolen autofill data",[2706],{"type":1387},{},{"nodeType":1293,"value":2709,"marks":2710,"data":2711}," can be used to gather other valuable information that could be useful for impersonating the victim when speaking to social engineering IT support staff, for example to reset or remove MFA.",[],{},{"nodeType":1294,"data":2713,"content":2714},{},[2715],{"nodeType":1293,"value":2716,"marks":2717,"data":2718},"Naturally, stolen session cookies are the most valuable prize, but they are often valid for only a limited time before the user must re-authenticate, and active sessions can often be terminated by security admins. Unfortunately, it’s not that uncommon for sessions to last for up to a month, or even sometimes indefinitely.",[],{},{"nodeType":1294,"data":2720,"content":2721},{},[2722],{"nodeType":1293,"value":2723,"marks":2724,"data":2725},"Stolen usernames and passwords are a different story. As the Snowflake breaches demonstrate, passwords can remain valid for years after a breach, particularly in the world of SaaS apps where mandatory password rotation is not as common as for a user’s primary domain account.",[],{},{"nodeType":1294,"data":2727,"content":2728},{},[2729,2733,2742],{"nodeType":1293,"value":2730,"marks":2731,"data":2732},"There’s also the problem of ",[],{},{"nodeType":1401,"data":2734,"content":2736},{"uri":2735},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/",[2737],{"nodeType":1293,"value":2738,"marks":2739,"data":2741},"ghost logins",[2740],{"type":1566},{},{"nodeType":1293,"value":2743,"marks":2744,"data":2745}," – where a local login with a username and password (and probably lacking MFA) can exist alongside other, more secure login methods such as SSO. Given the fact that many apps are self-adopted by users, these accounts continue to exist even when an app is subsequently added to SSO via the chosen IdP, meaning they can fly under the radar of security teams. ",[],{},{"nodeType":1326,"data":2747,"content":2748},{},[],{"nodeType":1437,"data":2750,"content":2751},{},[2752],{"nodeType":1293,"value":2753,"marks":2754,"data":2755},"Should you be concerned about infostealers?",[],{},{"nodeType":1294,"data":2757,"content":2758},{},[2759],{"nodeType":1293,"value":2760,"marks":2761,"data":2762},"It’s commonly thought that infostealers are primarily a concern for unmanaged devices that lack security controls common to corporate IT, such as EDR. But there’s a couple of reasons why corporate users are also at risk:",[],{},{"nodeType":1459,"data":2764,"content":2765},{},[2766],{"nodeType":1293,"value":2767,"marks":2768,"data":2769},"EDR can be bypassed",[],{},{"nodeType":1294,"data":2771,"content":2772},{},[2773,2777,2786],{"nodeType":1293,"value":2774,"marks":2775,"data":2776},"EDR is seen as the go-to solution for defending against infostealer malware. However, attackers are always looking for ways to get around security controls by obfuscating malicious behavior and evading signature-based checks. For example, ",[],{},{"nodeType":1401,"data":2778,"content":2780},{"uri":2779},"https://thehackernews.com/2024/07/microsoft-defender-flaw-exploited-to.html",[2781],{"nodeType":1293,"value":2782,"marks":2783,"data":2785},"a flaw in Microsoft Defender SmartScreen was recently exploited to deliver infostealer malware",[2784],{"type":1566},{},{"nodeType":1293,"value":1712,"marks":2787,"data":2788},[],{},{"nodeType":1294,"data":2790,"content":2791},{},[2792],{"nodeType":1293,"value":2793,"marks":2794,"data":2795},"Getting total coverage across your endpoint estate is notoriously difficult, if not totally unrealistic. Unless the malware is stopped on execution, then data will inevitably be stolen, and will continue to be taken until stopped (or it self-terminates). And once an attacker has stolen employee credentials or sessions, the credential stuffing and session hijacking attacks that come next won’t touch the endpoint. For those reasons, you can’t rely on EDR as a single line of defense against infostealers.",[],{},{"nodeType":1459,"data":2797,"content":2798},{},[2799],{"nodeType":1293,"value":2800,"marks":2801,"data":2802},"Unmanaged devices such as BYOD or third-parties are vulnerable",[],{},{"nodeType":1294,"data":2804,"content":2805},{},[2806],{"nodeType":1293,"value":2807,"marks":2808,"data":2809},"Companies that support BYOD often have less secure configurations than those with fully managed devices. The same applies to third-party contractors, who often use their own devices to access company systems on a temporary basis. ",[],{},{"nodeType":1294,"data":2811,"content":2812},{},[2813,2817,2826],{"nodeType":1293,"value":2814,"marks":2815,"data":2816},"This issue was acutely felt in the Snowflake attacks: There is some suggestion that targeting key third-party suppliers – ",[],{},{"nodeType":1401,"data":2818,"content":2820},{"uri":2819},"https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/",[2821],{"nodeType":1293,"value":2822,"marks":2823,"data":2825},"such as EPAM Systems, a software engineering firm and Snowflake ‘Elite Tier Partner’",[2824],{"type":1566},{},{"nodeType":1293,"value":2827,"marks":2828,"data":2829}," – yielded some of the access needed. It’s unclear what came first, but it’s possible (likely, even) that EPAM was identified as a target specifically because of its lucrative customer base – third-parties are a known weak point for red teamers, so it would be foolish to assume that attackers don’t also think this way. It’s possible too that EPAM were specifically targeted because of their Snowflake chops – adding another indicator that Snowflake was potentially a premeditated attack inspired by the availability of Snowflake credentials online. ",[],{},{"nodeType":1459,"data":2831,"content":2832},{},[2833],{"nodeType":1293,"value":2834,"marks":2835,"data":2836},"Browser profiles can be synced across devices, increasing the blast radius",[],{},{"nodeType":1294,"data":2838,"content":2839},{},[2840],{"nodeType":1293,"value":2841,"marks":2842,"data":2843},"It’s not uncommon for employees to access their personal email accounts from company devices. When accessing any browser, you are typically prompted to sign in with your account credentials (e.g. your Google account). If a user signs into a browser on a company device with a personal account, you’re usually prompted to sync your account across devices. This usually means that any saved passwords, search history, and settings are shared across devices. ",[],{},{"nodeType":1294,"data":2845,"content":2846},{},[2847],{"nodeType":1293,"value":2848,"marks":2849,"data":2850},"Naturally, this means that if a personal device is compromised where you’re also logged into the browser profile, then an infostealer will be able to harvest information saved into that profile across devices.",[],{},{"nodeType":1294,"data":2852,"content":2853},{},[2854],{"nodeType":1293,"value":2855,"marks":2856,"data":2857},"Even when using separate browser profiles for work and personal, it’s easy for the two to converge, or to slip into using the wrong profile. Accessing personal accounts (or at least synchronizing data across accounts) is usually a workplace policy violation, but it’s unfortunately all too common. ",[],{},{"nodeType":1294,"data":2859,"content":2860},{},[2861,2865,2874],{"nodeType":1293,"value":2862,"marks":2863,"data":2864},"Previous vulnerabilities have exacerbated this problem, such as ",[],{},{"nodeType":1401,"data":2866,"content":2868},{"uri":2867},"https://thehackernews.com/2024/01/malware-using-google-multilogin-exploit.html",[2869],{"nodeType":1293,"value":2870,"marks":2871,"data":2873},"an exploit affecting Google MultiLogin to maintain access to synced accounts even after a password reset",[2872],{"type":1566},{},{"nodeType":1293,"value":2018,"marks":2875,"data":2876},[],{},{"nodeType":1459,"data":2878,"content":2879},{},[2880],{"nodeType":1293,"value":2881,"marks":2882,"data":2883},"Are infostealers a bigger problem than credential phishing? ",[],{},{"nodeType":1294,"data":2885,"content":2886},{},[2887],{"nodeType":1293,"value":2888,"marks":2889,"data":2890},"The short answer is: No. The longer answer is: They are both part of the bigger problem of identity attacks, and attackers can wield both approaches simultaneously. ",[],{},{"nodeType":1294,"data":2892,"content":2893},{},[2894],{"nodeType":1293,"value":2895,"marks":2896,"data":2897},"While they are delivered to victims in similar ways to phishing links, most organizations are arguably better protected against infostealers than modern phishing attacks because endpoint security controls provide another layer of protection, in theory – whereas modern phishing attacks don’t necessarily involve the delivery of malware that executes on the device. ",[],{},{"nodeType":1294,"data":2899,"content":2900},{},[2901],{"nodeType":1293,"value":2902,"marks":2903,"data":2904},"Infostealers arguably provide more bang for the attacker’s buck, grabbing a stack of credentials and useful data in one go. In contrast, phishing is usually much more targeted, and involves the compromise of a narrower set of credentials – typically focusing on a particular site or app. ",[],{},{"nodeType":1294,"data":2906,"content":2907},{},[2908,2912,2921,2925,2933],{"nodeType":1293,"value":2909,"marks":2910,"data":2911},"It’s worth focusing on the TTP, not the particular tool being used: The attacker technique here is ",[],{},{"nodeType":1401,"data":2913,"content":2915},{"uri":2914},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/session_cookie_theft/description.md",[2916],{"nodeType":1293,"value":2917,"marks":2918,"data":2920},"session cookie theft",[2919],{"type":1566},{},{"nodeType":1293,"value":2922,"marks":2923,"data":2924},", and subsequently session hijacking by importing the cookie into the attacker’s browser. Both infostealers and ",[],{},{"nodeType":1401,"data":2926,"content":2928},{"uri":2927},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[2929],{"nodeType":1293,"value":2930,"marks":2931,"data":2932},"modern phishing attacks",[],{},{"nodeType":1293,"value":2934,"marks":2935,"data":2936}," involve the theft of session tokens, and so are valid means to achieve this end. In fact, there’s nothing to stop threat groups from employing both simultaneously.",[],{},{"nodeType":1317,"data":2938,"content":2942},{"target":2939},{"sys":2940},{"id":2941,"type":1322,"linkType":1323},"7fil6aaQDFfJGYUnQ14k10",[],{"nodeType":1326,"data":2944,"content":2945},{},[],{"nodeType":1437,"data":2947,"content":2948},{},[2949],{"nodeType":1293,"value":2950,"marks":2951,"data":2952},"Infostealers in action",[],{},{"nodeType":1294,"data":2954,"content":2955},{},[2956],{"nodeType":1293,"value":2957,"marks":2958,"data":2959},"Check out the video demo below to see the attack chain in action from the point of an infostealer compromise, showing session cookie theft, reimporting the cookies into the attacker's browser, and evading policy-based controls in M365. It also shows the targeting of downstream apps that are usually accessed via SSO in the context of both a Microsoft Entra and Okta compromise.",[],{},{"nodeType":1317,"data":2961,"content":2965},{"target":2962},{"sys":2963},{"id":2964,"type":1322,"linkType":1323},"4J7LqqjQX2W52AbmcVmjUt",[],{"nodeType":1437,"data":2967,"content":2968},{},[2969],{"nodeType":1293,"value":2970,"marks":2971,"data":2972},"What can organizations do about the infostealer threat? ",[],{},{"nodeType":1294,"data":2974,"content":2975},{},[2976],{"nodeType":1293,"value":2977,"marks":2978,"data":2979},"Security teams should have two main concerns:",[],{},{"nodeType":1481,"data":2981,"content":2982},{},[2983,2993],{"nodeType":1485,"data":2984,"content":2985},{},[2986],{"nodeType":1294,"data":2987,"content":2988},{},[2989],{"nodeType":1293,"value":2990,"marks":2991,"data":2992},"Data that is already out there from historical data dumps, but is still valid. ",[],{},{"nodeType":1485,"data":2994,"content":2995},{},[2996],{"nodeType":1294,"data":2997,"content":2998},{},[2999],{"nodeType":1293,"value":3000,"marks":3001,"data":3002},"Data in private channels that attackers could use in the future, that you are blind to. ",[],{},{"nodeType":1294,"data":3004,"content":3005},{},[3006],{"nodeType":1293,"value":3007,"marks":3008,"data":3009},"As always, the root-cause of the problem is a lack of meaningful visibility of what apps your employees are using (including those outside your IdP) and whether the associated identities are configured securely. ",[],{},{"nodeType":1294,"data":3011,"content":3012},{},[3013],{"nodeType":1293,"value":3014,"marks":3015,"data":3016},"A layered, defense-in-depth approach is required to resolve the issue, by:",[],{},{"nodeType":1481,"data":3018,"content":3019},{},[3020,3030,3040,3050],{"nodeType":1485,"data":3021,"content":3022},{},[3023],{"nodeType":1294,"data":3024,"content":3025},{},[3026],{"nodeType":1293,"value":3027,"marks":3028,"data":3029},"Deploying MFA across all your identities and apps, including any local logins that can’t be put behind SSO. ",[],{},{"nodeType":1485,"data":3031,"content":3032},{},[3033],{"nodeType":1294,"data":3034,"content":3035},{},[3036],{"nodeType":1293,"value":3037,"marks":3038,"data":3039},"Configuring time-limited session lifetimes for all apps to ensure that any stolen session tokens can only be used temporarily. ",[],{},{"nodeType":1485,"data":3041,"content":3042},{},[3043],{"nodeType":1294,"data":3044,"content":3045},{},[3046],{"nodeType":1293,"value":3047,"marks":3048,"data":3049},"Ensuring that employees don’t access or synchronize personal accounts on their work devices, as well as limiting non-work activities on their work device as much as possible.",[],{},{"nodeType":1485,"data":3051,"content":3052},{},[3053],{"nodeType":1294,"data":3054,"content":3055},{},[3056],{"nodeType":1293,"value":3057,"marks":3058,"data":3059},"Implementing a robust EDR/MDR solution to detect and respond to malware compromises on user devices. ",[],{},{"nodeType":1294,"data":3061,"content":3062},{},[3063,3067,3072],{"nodeType":1293,"value":3064,"marks":3065,"data":3066},"Organizations also have the option of investing in a commercial TI feed to detect and report data breaches affecting employees. But in our experience, these feeds contain ",[],{},{"nodeType":1293,"value":3068,"marks":3069,"data":3071},"a lot ",[3070],{"type":1387},{},{"nodeType":1293,"value":3073,"marks":3074,"data":3075},"of false positives – so unless you have password visibility for employee accounts across apps, it’s going to waste a chunk of valuable time for you and your employees.",[],{},{"nodeType":1294,"data":3077,"content":3078},{},[3079,3083,3092],{"nodeType":1293,"value":3080,"marks":3081,"data":3082},"It would be remiss of us not to mention our recently released ",[],{},{"nodeType":1401,"data":3084,"content":3086},{"uri":3085},"https://pushsecurity.com/blog/introducing-session-token-theft-detection-why-browser-is-best/",[3087],{"nodeType":1293,"value":3088,"marks":3089,"data":3091},"session token theft detection feature",[3090],{"type":1566},{},{"nodeType":1293,"value":3093,"marks":3094,"data":3095}," that identifies session token theft by adding telemetry to the user agent string – using the power of our browser agent to create a new high-fidelity signal for security teams. It can also be applied more generally to detect any session taking place in an unmanaged browser – so you can use it to spot unauthorized access to company apps in general, too.  ",[],{},{"nodeType":1317,"data":3097,"content":3101},{"target":3098},{"sys":3099},{"id":3100,"type":1322,"linkType":1323},"3XgpqEGzZSD2J0uvnCg5D8",[],{"nodeType":1459,"data":3103,"content":3104},{},[3105],{"nodeType":1293,"value":3106,"marks":3107,"data":3108},"What’s next for infostealers?",[],{},{"nodeType":1294,"data":3110,"content":3111},{},[3112],{"nodeType":1293,"value":3113,"marks":3114,"data":3115},"All the signs point to the fact that infostealers will continue being a useful tool in the attacker’s arsenal. The Snowflake attacks in particular are both a warning for defenders and encouragement for attackers. It's also a good reminder that while infostealers were once used to harvest things like VPN creds to pivot to the internal network, they're now largely used to target third-party services over the internet. ",[],{},{"nodeType":1294,"data":3117,"content":3118},{},[3119],{"nodeType":1293,"value":3120,"marks":3121,"data":3122},"To evade EDR, it’s likely that we’ll see a growing number of families and variants used by individual groups, or better ‘enterprise’ capabilities from malware-as-a-service vendors. ",[],{},{"nodeType":1294,"data":3124,"content":3125},{},[3126,3130,3139,3143,3151],{"nodeType":1293,"value":3127,"marks":3128,"data":3129},"One notable quirk is that, to date, infostealers have not really branched out from targeting browsers. Take the example of password manager apps – you would think this would be an obvious target, right? But, they’re not usually targeted (",[],{},{"nodeType":1401,"data":3131,"content":3133},{"uri":3132},"https://securitysenses.com/posts/malware-targeting-password-managers",[3134],{"nodeType":1293,"value":3135,"marks":3136,"data":3138},"with some exceptions",[3137],{"type":1566},{},{"nodeType":1293,"value":3140,"marks":3141,"data":3142},"). And when they do, ",[],{},{"nodeType":1401,"data":3144,"content":3145},{"uri":3132},[3146],{"nodeType":1293,"value":3147,"marks":3148,"data":3150},"they work by eavesdropping on the password manager’s browser extension in action",[3149],{"type":1566},{},{"nodeType":1293,"value":3152,"marks":3153,"data":3154}," – meaning they are intercepted one-at-a-time as the user uses them, rather than targeting the password manager directly and exporting the saved passwords all at once. It will be interesting to see whether these capabilities are added in the future. ",[],{},{"nodeType":1294,"data":3156,"content":3157},{},[3158,3162,3171,3175,3184,3188,3197],{"nodeType":1293,"value":3159,"marks":3160,"data":3161},"On the other hand, there are defensive security developments that could reduce the ability of attackers to leverage things like stolen session tokens, such as ",[],{},{"nodeType":1401,"data":3163,"content":3165},{"uri":3164},"https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-token-protection",[3166],{"nodeType":1293,"value":3167,"marks":3168,"data":3170},"Microsoft’s token binding feature in Entra",[3169],{"type":1566},{},{"nodeType":1293,"value":3172,"marks":3173,"data":3174},", or ",[],{},{"nodeType":1401,"data":3176,"content":3178},{"uri":3177},"https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html",[3179],{"nodeType":1293,"value":3180,"marks":3181,"data":3183},"Google’s device bound session cookies",[3182],{"type":1566},{},{"nodeType":1293,"value":3185,"marks":3186,"data":3187},". Google also released an ",[],{},{"nodeType":1401,"data":3189,"content":3191},{"uri":3190},"https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html?m=1",[3192],{"nodeType":1293,"value":3193,"marks":3194,"data":3196},"app-bound encryption feature",[3195],{"type":1566},{},{"nodeType":1293,"value":3198,"marks":3199,"data":3200},", which adds additional protection against infostealers attempting to steal browser data in Chrome if the underlying Windows device is compromised. ",[],{},{"nodeType":1294,"data":3202,"content":3203},{},[3204],{"nodeType":1293,"value":3205,"marks":3206,"data":3207},"That said, mature versions of these controls are still years away, and while session cookie theft is a key risk of infostealers, it’s not the only risk – so alternative controls and mitigations remain valuable to security teams in the present. ",[],{},{"nodeType":1317,"data":3209,"content":3213},{"target":3210},{"sys":3211},{"id":3212,"type":1322,"linkType":1323},"5loTnpvwGD3kaKMXBp23hZ",[],{"nodeType":1294,"data":3215,"content":3216},{},[3217],{"nodeType":1293,"value":37,"marks":3218,"data":3219},[],{},"What the rise of infostealers says about identity attacks","What the rise in popularity of infostealers tells us about the cybercrime ecosystem and the shift toward identity attacks. ","2024-07-31T00:00:00.000Z","what-the-rise-of-infostealers-says-about-identity-attacks",{"items":3225},[3226,3228],{"sys":3227,"name":1305},{"id":1304},{"sys":3229,"name":2046},{"id":2045},{"items":3231},[3232],{"fullName":3233,"firstName":3234,"jobTitle":3235,"profilePicture":3236},"Dan Green","Dan","Threat Research",{"url":3237},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1309,"sys":3239,"content":3241,"title":4069,"synopsis":4070,"hashTags":118,"publishedDate":4071,"slug":4072,"tagsCollection":4073,"authorsCollection":4079},{"id":3240},"4Bc6qX9kURetHcK7nkS8on",{"json":3242},{"nodeType":1295,"data":3243,"content":3244},{},[3245,3252,3259,3266,3272,3280,3287,3293,3300,3306,3313,3321,3328,3334,3341,3373,3380,3387,3420,3428,3435,3443,3451,3458,3465,3485,3492,3499,3506,3514,3521,3528,3561,3568,3621,3628,3635,3643,3650,3657,3664,3672,3679,3702,3709,3757,3764,3770,3777,3820,3827,3835,3842,3849,3882,3890,3897,3903,3910,3916,3923,3929,3936,4022,4029,4037,4044,4062],{"nodeType":1294,"data":3246,"content":3247},{},[3248],{"nodeType":1293,"value":3249,"marks":3250,"data":3251},"As an industry, we’ve been conditioned to think about threat detection and response as something that happens post-compromise. Best practice has formed around resources like the Cyber Kill Chain and the MITRE ATT&CK Framework which focus on detecting indicators of an attacker presence on your network, and their behaviors and actions as they move through it.",[],{},{"nodeType":1294,"data":3253,"content":3254},{},[3255],{"nodeType":1293,"value":3256,"marks":3257,"data":3258},"But with the shift to identity attacks, where attackers look to take over accounts on internet-facing apps and services, relying on an assumed compromise approach to detection is becoming less reliable. The most significant breaches of the last 12-18 months have been the result of browser-based attacks where an attacker has taken over an account, exfiltrated data… and that’s it. ",[],{},{"nodeType":1294,"data":3260,"content":3261},{},[3262],{"nodeType":1293,"value":3263,"marks":3264,"data":3265},"This change means that the typical methods of post-compromise detection and response become much less viable. So, we’re going to talk a bit about what’s changed, why controls are failing, and what we’re doing here at Push to address the detection gaps. ",[],{},{"nodeType":1317,"data":3267,"content":3271},{"target":3268},{"sys":3269},{"id":3270,"type":1322,"linkType":1323},"4179AY8ZEIJ3Ce9jszn4fA",[],{"nodeType":1437,"data":3273,"content":3274},{},[3275],{"nodeType":1293,"value":3276,"marks":3277,"data":3279},"The good old days",[3278],{"type":1387},{},{"nodeType":1294,"data":3281,"content":3282},{},[3283],{"nodeType":1293,"value":3284,"marks":3285,"data":3286},"Over the previous decade the typical attack paths, and the controls that have formed around it, have become very familiar to SecOps teams. ",[],{},{"nodeType":1317,"data":3288,"content":3292},{"target":3289},{"sys":3290},{"id":3291,"type":1322,"linkType":1323},"4AOzwBGuNkXXogyqy46ki5",[],{"nodeType":1294,"data":3294,"content":3295},{},[3296],{"nodeType":1293,"value":3297,"marks":3298,"data":3299},"Even with the more recent transition to enterprise cloud and hybrid networking, the broad offensive logic of “land and expand” remains. This has seen the typical view of a network-based attack path simply expand to add first enterprise cloud, and then SaaS to the picture. ",[],{},{"nodeType":1317,"data":3301,"content":3305},{"target":3302},{"sys":3303},{"id":3304,"type":1322,"linkType":1323},"2J3s38YOVcMuJuTdryhERA",[],{"nodeType":1294,"data":3307,"content":3308},{},[3309],{"nodeType":1293,"value":3310,"marks":3311,"data":3312},"And while this sort of attack path is theoretically possible, what happens in reality looks quite different. ",[],{},{"nodeType":1437,"data":3314,"content":3315},{},[3316],{"nodeType":1293,"value":3317,"marks":3318,"data":3320},"The new world",[3319],{"type":1387},{},{"nodeType":1294,"data":3322,"content":3323},{},[3324],{"nodeType":1293,"value":3325,"marks":3326,"data":3327},"Instead of needing to progress through the network, moving laterally, elevating privileges, etc. modern account takeover tends to take a much more direct approach. ",[],{},{"nodeType":1317,"data":3329,"content":3333},{"target":3330},{"sys":3331},{"id":3332,"type":1322,"linkType":1323},"6wIzMu3jBhaas9jtpV48bz",[],{"nodeType":1294,"data":3335,"content":3336},{},[3337],{"nodeType":1293,"value":3338,"marks":3339,"data":3340},"It’s a common misconception that SaaS compromise typically comes after the traditional attack chain (a myth largely promoted by old-school consultancy providers, MSSPs, and managed SOC providers). There’s no need for an attacker looking to take over a SaaS account to target the network first – and many organizations today simply no longer have a network in the conventional sense.  ",[],{},{"nodeType":1294,"data":3342,"content":3343},{},[3344,3348,3357,3361,3370],{"nodeType":1293,"value":3345,"marks":3346,"data":3347},"This isn’t to say that there aren’t examples of longer SaaS compromises involving lateral movement from SaaS to SaaS, or SaaS to cloud (",[],{},{"nodeType":1401,"data":3349,"content":3351},{"uri":3350},"https://github.com/pushsecurity/saas-attacks",[3352],{"nodeType":1293,"value":3353,"marks":3354,"data":3356},"we created a whole attack matrix demonstrating the art of the possible here",[3355],{"type":1566},{},{"nodeType":1293,"value":3358,"marks":3359,"data":3360},"). Equally, there are examples of very short and direct attacks in enterprise cloud environments leading to ransomware deployment (for example, ",[],{},{"nodeType":1401,"data":3362,"content":3364},{"uri":3363},"https://www.bleepingcomputer.com/news/security/mgm-casinos-esxi-servers-allegedly-encrypted-in-ransomware-attack/",[3365],{"nodeType":1293,"value":3366,"marks":3367,"data":3369},"Scattered Spider turning an initial account takeover in Okta into a full-scale VMware ESXi ransomware compromise",[3368],{"type":1566},{},{"nodeType":1293,"value":2222,"marks":3371,"data":3372},[],{},{"nodeType":1294,"data":3374,"content":3375},{},[3376],{"nodeType":1293,"value":3377,"marks":3378,"data":3379},"But statistically, the average network or enterprise cloud attack involves much more complex lateral movement, privilege escalation, and defense evasion than the average SaaS attack path. ",[],{},{"nodeType":1294,"data":3381,"content":3382},{},[3383],{"nodeType":1293,"value":3384,"marks":3385,"data":3386},"The Snowflake attack path is a useful case study here: ",[],{},{"nodeType":1481,"data":3388,"content":3389},{},[3390,3400,3410],{"nodeType":1485,"data":3391,"content":3392},{},[3393],{"nodeType":1294,"data":3394,"content":3395},{},[3396],{"nodeType":1293,"value":3397,"marks":3398,"data":3399},"Attackers logged into the Snowflake tenant of ~165 organizations using stolen credentials to access user accounts via the web-based ‘SnowSight’ portal. ",[],{},{"nodeType":1485,"data":3401,"content":3402},{},[3403],{"nodeType":1294,"data":3404,"content":3405},{},[3406],{"nodeType":1293,"value":3407,"marks":3408,"data":3409},"To take advantage of the many exposed accounts, the attacker created a utility performing account takeover and recon at-scale. ",[],{},{"nodeType":1485,"data":3411,"content":3412},{},[3413],{"nodeType":1294,"data":3414,"content":3415},{},[3416],{"nodeType":1293,"value":3417,"marks":3418,"data":3419},"The attack finished with the attacker executing the same set of SQL commands across customer instances to stage and exfiltrate data. ",[],{},{"nodeType":1294,"data":3421,"content":3422},{},[3423],{"nodeType":1293,"value":3424,"marks":3425,"data":3427},"And that’s it. ",[3426],{"type":1387},{},{"nodeType":1294,"data":3429,"content":3430},{},[3431],{"nodeType":1293,"value":3432,"marks":3433,"data":3434},"Since these attacks happen in-app, to be able to detect and intercept them you’d need deep app-level telemetry, and probably the ability to automate any containment and response activities. But unfortunately…",[],{},{"nodeType":1437,"data":3436,"content":3437},{},[3438],{"nodeType":1293,"value":3439,"marks":3440,"data":3442},"Detecting and responding after account takeover is really, really difficult",[3441],{"type":1387},{},{"nodeType":1459,"data":3444,"content":3445},{},[3446],{"nodeType":1293,"value":3447,"marks":3448,"data":3450},"Limited log data ",[3449],{"type":1387},{},{"nodeType":1294,"data":3452,"content":3453},{},[3454],{"nodeType":1293,"value":3455,"marks":3456,"data":3457},"The first challenge is that in-app malicious activity is mostly indistinguishable from legitimate user behavior. Even mass data exfiltration might appear legitimate depending on what the app is used for!",[],{},{"nodeType":1294,"data":3459,"content":3460},{},[3461],{"nodeType":1293,"value":3462,"marks":3463,"data":3464},"To meaningfully detect malicious activity in-app, for starters you would need visibility of user behavior and actions. Unfortunately, you don’t have this. ",[],{},{"nodeType":1294,"data":3466,"content":3467},{},[3468,3472,3481],{"nodeType":1293,"value":3469,"marks":3470,"data":3471},"We’ve previously discussed in detail why ",[],{},{"nodeType":1401,"data":3473,"content":3475},{"uri":3474},"https://pushsecurity.com/blog/the-web-proxy-is-dead-long-live-the-browser-extension/",[3476],{"nodeType":1293,"value":3477,"marks":3478,"data":3480},"log sources like network (web proxy), IdP, and app logs fall short",[3479],{"type":1566},{},{"nodeType":1293,"value":3482,"marks":3483,"data":3484}," when it comes to identity attacks, but the TL;DR is that most applications provide extremely limited security logging (if they provide it at all). ",[],{},{"nodeType":1294,"data":3486,"content":3487},{},[3488],{"nodeType":1293,"value":3489,"marks":3490,"data":3491},"When logs are available, you’re limited to the events that the third-party deems suitable to log. Out of the 100 most popular apps we see across our customers, and perhaps the few dozen or so that are security critical, only a small handful provide any useful logging. So extremely risky actions, like cloning a private GitHub repo, or downloading SharePoint files via ‘open in app’ or file syncing, don’t generate any logs at all. ",[],{},{"nodeType":1294,"data":3493,"content":3494},{},[3495],{"nodeType":1293,"value":3496,"marks":3497,"data":3498},"Further, the lack of out-of-the-box connectors for many apps means that complex custom architectures are often required for ingestion.",[],{},{"nodeType":1294,"data":3500,"content":3501},{},[3502],{"nodeType":1293,"value":3503,"marks":3504,"data":3505},"So, even if logs are available and you’re able to ingest them into your SIEM, there’s no guarantee that the telemetry available will contribute to any meaningful detection of malicious activity. ",[],{},{"nodeType":1459,"data":3507,"content":3508},{},[3509],{"nodeType":1293,"value":3510,"marks":3511,"data":3513},"Limited response capabilities",[3512],{"type":1387},{},{"nodeType":1294,"data":3515,"content":3516},{},[3517],{"nodeType":1293,"value":3518,"marks":3519,"data":3520},"By some miracle, you’ve detected an account takeover. Now what?",[],{},{"nodeType":1294,"data":3522,"content":3523},{},[3524],{"nodeType":1293,"value":3525,"marks":3526,"data":3527},"The ability to respond to an attack is dictated by the controls that are available to the security team. Unfortunately:",[],{},{"nodeType":1481,"data":3529,"content":3530},{},[3531,3541,3551],{"nodeType":1485,"data":3532,"content":3533},{},[3534],{"nodeType":1294,"data":3535,"content":3536},{},[3537],{"nodeType":1293,"value":3538,"marks":3539,"data":3540},"Depending on the app and how it was adopted, there’s no guarantee that you have admin rights. ",[],{},{"nodeType":1485,"data":3542,"content":3543},{},[3544],{"nodeType":1294,"data":3545,"content":3546},{},[3547],{"nodeType":1293,"value":3548,"marks":3549,"data":3550},"It’s not guaranteed that admins will have the required security features available to them, like forcing a logout on a session or disabling an account (you may not even know who the users and admins are within your organization, particularly if it was self-adopted by a specific team). ",[],{},{"nodeType":1485,"data":3552,"content":3553},{},[3554],{"nodeType":1294,"data":3555,"content":3556},{},[3557],{"nodeType":1293,"value":3558,"marks":3559,"data":3560},"Response probably requires that you log into the app and perform these actions in the admin interface (rather than being something you can orchestrate via SIEM workflow or API).",[],{},{"nodeType":1294,"data":3562,"content":3563},{},[3564],{"nodeType":1293,"value":3565,"marks":3566,"data":3567},"So at the point that the SecOps team is engaged, the team needs to be able to respond by eradicating the attacker’s access and closing the vulnerabilities exploited to prevent re-entry. To do this, the team needs to be able to identify, for example:",[],{},{"nodeType":1481,"data":3569,"content":3570},{},[3571,3581,3591,3601,3611],{"nodeType":1485,"data":3572,"content":3573},{},[3574],{"nodeType":1294,"data":3575,"content":3576},{},[3577],{"nodeType":1293,"value":3578,"marks":3579,"data":3580},"How the attacker gained access to the account",[],{},{"nodeType":1485,"data":3582,"content":3583},{},[3584],{"nodeType":1294,"data":3585,"content":3586},{},[3587],{"nodeType":1293,"value":3588,"marks":3589,"data":3590},"What the attacker did using the compromised account",[],{},{"nodeType":1485,"data":3592,"content":3593},{},[3594],{"nodeType":1294,"data":3595,"content":3596},{},[3597],{"nodeType":1293,"value":3598,"marks":3599,"data":3600},"Whether any alternative access methods were established (e.g. backup emails, API keys, or OAuth integrations)",[],{},{"nodeType":1485,"data":3602,"content":3603},{},[3604],{"nodeType":1294,"data":3605,"content":3606},{},[3607],{"nodeType":1293,"value":3608,"marks":3609,"data":3610},"Where the attacker could have laterally moved to using the account (based on the integrations and permissions of the identity)",[],{},{"nodeType":1485,"data":3612,"content":3613},{},[3614],{"nodeType":1294,"data":3615,"content":3616},{},[3617],{"nodeType":1293,"value":3618,"marks":3619,"data":3620},"Other accounts the attacker could also access using the same credentials",[],{},{"nodeType":1294,"data":3622,"content":3623},{},[3624],{"nodeType":1293,"value":3625,"marks":3626,"data":3627},"Given the limited tools available and the probable lack of app-specific knowledge (you can’t be an expert in every app!), by the time you’ve managed to respond, the attacker has probably already sailed off into the sunset with all of the data they can lay their hands on. ",[],{},{"nodeType":1294,"data":3629,"content":3630},{},[3631],{"nodeType":1293,"value":3632,"marks":3633,"data":3634},"Clearly, post-compromise detection and response isn’t really a viable option – you’re basically entering full response and recovery mode at this point. ",[],{},{"nodeType":1437,"data":3636,"content":3637},{},[3638],{"nodeType":1293,"value":3639,"marks":3640,"data":3642},"Shifting detection left",[3641],{"type":1387},{},{"nodeType":1294,"data":3644,"content":3645},{},[3646],{"nodeType":1293,"value":3647,"marks":3648,"data":3649},"If you can’t reasonably detect and respond to post-compromise activity, it makes detecting and blocking initial access much more important. ",[],{},{"nodeType":1294,"data":3651,"content":3652},{},[3653],{"nodeType":1293,"value":3654,"marks":3655,"data":3656},"Again, it seems obvious, but it’s yet another notion that’s fallen under the radar – despite the trendiness of ‘shifting left’ in other areas like software development and vulnerability management. Partly because as we’ve discussed, post-compromise detection and response has been the norm for so long. But also because we’ve accepted the status quo of the (somewhat disappointing) preventative controls that are available. ",[],{},{"nodeType":1294,"data":3658,"content":3659},{},[3660],{"nodeType":1293,"value":3661,"marks":3662,"data":3663},"First, let’s isolate the techniques and steps that attackers typically rely on for account takeover. ",[],{},{"nodeType":1459,"data":3665,"content":3666},{},[3667],{"nodeType":1293,"value":3668,"marks":3669,"data":3671},"Methods of account takeover",[3670],{"type":1387},{},{"nodeType":1294,"data":3673,"content":3674},{},[3675],{"nodeType":1293,"value":3676,"marks":3677,"data":3678},"To be able to hijack an account, an attacker needs to possess one of two things:",[],{},{"nodeType":1481,"data":3680,"content":3681},{},[3682,3692],{"nodeType":1485,"data":3683,"content":3684},{},[3685],{"nodeType":1294,"data":3686,"content":3687},{},[3688],{"nodeType":1293,"value":3689,"marks":3690,"data":3691},"Authentication material e.g. a username and password, with a login portal URL.",[],{},{"nodeType":1485,"data":3693,"content":3694},{},[3695],{"nodeType":1294,"data":3696,"content":3697},{},[3698],{"nodeType":1293,"value":3699,"marks":3700,"data":3701},"Session material e.g. session cookies. ",[],{},{"nodeType":1294,"data":3703,"content":3704},{},[3705],{"nodeType":1293,"value":3706,"marks":3707,"data":3708},"There are three main ways that an attacker can hijack an account by acquiring (or generating) these materials: Phishing, infostealers, and credential stuffing. ",[],{},{"nodeType":1481,"data":3710,"content":3711},{},[3712,3727,3742],{"nodeType":1485,"data":3713,"content":3714},{},[3715],{"nodeType":1294,"data":3716,"content":3717},{},[3718,3723],{"nodeType":1293,"value":3719,"marks":3720,"data":3722},"Phishing:",[3721],{"type":1387},{},{"nodeType":1293,"value":3724,"marks":3725,"data":3726}," Stealing valid authentication and session material from victims, including usernames, passwords, and session cookies (if AitM or BitM), for a specific site or app.",[],{},{"nodeType":1485,"data":3728,"content":3729},{},[3730],{"nodeType":1294,"data":3731,"content":3732},{},[3733,3738],{"nodeType":1293,"value":3734,"marks":3735,"data":3737},"Infostealers:",[3736],{"type":1387},{},{"nodeType":1293,"value":3739,"marks":3740,"data":3741}," Stealing valid authentication and session material from the victim’s web browsers for all apps that the user has signed into, as well as desktop information from the device.",[],{},{"nodeType":1485,"data":3743,"content":3744},{},[3745],{"nodeType":1294,"data":3746,"content":3747},{},[3748,3753],{"nodeType":1293,"value":3749,"marks":3750,"data":3752},"Credential stuffing: ",[3751],{"type":1387},{},{"nodeType":1293,"value":3754,"marks":3755,"data":3756},"Using previously breached authentication or session material in data breach dumps, or taking advantage of weak or guessable passwords (as a result of password reuse).",[],{},{"nodeType":1294,"data":3758,"content":3759},{},[3760],{"nodeType":1293,"value":3761,"marks":3762,"data":3763},"Once this information has been acquired, the attack path follows a similar journey regardless of the initial attack technique, ending in the attacker initiating a session in their own browser. ",[],{},{"nodeType":1317,"data":3765,"content":3769},{"target":3766},{"sys":3767},{"id":3768,"type":1322,"linkType":1323},"7CJT84yPsiUaUO4Mfb6oFd",[],{"nodeType":1294,"data":3771,"content":3772},{},[3773],{"nodeType":1293,"value":3774,"marks":3775,"data":3776},"Clearly, there are a number of steps here that involve user behaviors/actions that could in theory be detected with the right visibility:",[],{},{"nodeType":1481,"data":3778,"content":3779},{},[3780,3790,3800,3810],{"nodeType":1485,"data":3781,"content":3782},{},[3783],{"nodeType":1294,"data":3784,"content":3785},{},[3786],{"nodeType":1293,"value":3787,"marks":3788,"data":3789},"The victim being sent and accessing a malicious link, or downloading a malicious file",[],{},{"nodeType":1485,"data":3791,"content":3792},{},[3793],{"nodeType":1294,"data":3794,"content":3795},{},[3796],{"nodeType":1293,"value":3797,"marks":3798,"data":3799},"The victim loading a malicious webpage",[],{},{"nodeType":1485,"data":3801,"content":3802},{},[3803],{"nodeType":1294,"data":3804,"content":3805},{},[3806],{"nodeType":1293,"value":3807,"marks":3808,"data":3809},"The victim interacting with a malicious webpage, such as entering their credentials",[],{},{"nodeType":1485,"data":3811,"content":3812},{},[3813],{"nodeType":1294,"data":3814,"content":3815},{},[3816],{"nodeType":1293,"value":3817,"marks":3818,"data":3819},"(If an infostealer attack) The victim executing malware on their device",[],{},{"nodeType":1294,"data":3821,"content":3822},{},[3823],{"nodeType":1293,"value":3824,"marks":3825,"data":3826},"Finally, the attacker must also access the stolen account from their own device/browser.",[],{},{"nodeType":1459,"data":3828,"content":3829},{},[3830],{"nodeType":1293,"value":3831,"marks":3832,"data":3834},"Existing controls are falling short",[3833],{"type":1387},{},{"nodeType":1294,"data":3836,"content":3837},{},[3838],{"nodeType":1293,"value":3839,"marks":3840,"data":3841},"So, now we know what these attacks look like, how do you feasibly detect and block them? ",[],{},{"nodeType":1294,"data":3843,"content":3844},{},[3845],{"nodeType":1293,"value":3846,"marks":3847,"data":3848},"The vast majority of identity attacks take place entirely over the internet. These attacks don’t involve traditional network and endpoint-based techniques, and therefore don’t run into many of your existing perimeter controls. Infostealer attacks are the exception in that they do involve an endpoint compromise (and therefore come up against EDR), but attackers are continually finding new bypass techniques, or are targeting unmanaged devices that are not protected by EDR. ",[],{},{"nodeType":1294,"data":3850,"content":3851},{},[3852,3856,3865,3869,3878],{"nodeType":1293,"value":3853,"marks":3854,"data":3855},"This leaves us in the hands of TI-driven blocklists and SWG/email controls that identify and block malicious content. However, these controls are largely based on ",[],{},{"nodeType":1401,"data":3857,"content":3859},{"uri":3858},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[3860],{"nodeType":1293,"value":3861,"marks":3862,"data":3864},"indicators like domain names, URLs, and IPs",[3863],{"type":1566},{},{"nodeType":1293,"value":3866,"marks":3867,"data":3868}," which are easy for attackers to change (and therefore bypass). Where pages and downloads are analyzed, ",[],{},{"nodeType":1401,"data":3870,"content":3872},{"uri":3871},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection/",[3873],{"nodeType":1293,"value":3874,"marks":3875,"data":3877},"attackers are routinely implementing obfuscation measures to defeat more advanced dynamic controls",[3876],{"type":1566},{},{"nodeType":1293,"value":3879,"marks":3880,"data":3881}," with a lot of success, or using techniques like HTML smuggling to bypass download scanning tools. ",[],{},{"nodeType":1459,"data":3883,"content":3884},{},[3885],{"nodeType":1293,"value":3886,"marks":3887,"data":3889},"Detecting and responding to account takeover with Push",[3888],{"type":1387},{},{"nodeType":1294,"data":3891,"content":3892},{},[3893],{"nodeType":1293,"value":3894,"marks":3895,"data":3896},"But, Push’s vantage point in the browser gives us a very different perspective. Because in the browser, you have much better visibility of the rendered web page (meaning it's much harder to disguise malicious content). You also aren’t restricted to email, and can intercept a user loading a malicious page whatever it’s source. ",[],{},{"nodeType":1317,"data":3898,"content":3902},{"target":3899},{"sys":3900},{"id":3901,"type":1322,"linkType":1323},"4JpFRHGRGEbCb1hNF0CGlE",[],{"nodeType":1294,"data":3904,"content":3905},{},[3906],{"nodeType":1293,"value":3907,"marks":3908,"data":3909},"So, let’s compare the typical web-based controls that organizations rely on against what’s possible using Push’s browser-based solution. We’ll put EDR to one side here and focus on a typical phishing attack, since the majority of the attack path happens over the internet (and the attacker has to return to the internet to access the app/account anyway). ",[],{},{"nodeType":1317,"data":3911,"content":3915},{"target":3912},{"sys":3913},{"id":3914,"type":1322,"linkType":1323},"4ua9ZNNSnxJnRLwJvRTaf1",[],{"nodeType":1294,"data":3917,"content":3918},{},[3919],{"nodeType":1293,"value":3920,"marks":3921,"data":3922},"You can see here that attackers have established methods of routinely bypassing these controls. In contrast, with Push, there are layered detections against different stages of the attack path to account takeover, providing defense-in-depth should a layer be somehow bypassed.",[],{},{"nodeType":1317,"data":3924,"content":3928},{"target":3925},{"sys":3926},{"id":3927,"type":1322,"linkType":1323},"ogIj92nzV9Q2Z7I9YOgG3",[],{"nodeType":1294,"data":3930,"content":3931},{},[3932],{"nodeType":1293,"value":3933,"marks":3934,"data":3935},"In practice, this creates four strong lines of defense – all before an attacker can even take over an account. ",[],{},{"nodeType":1481,"data":3937,"content":3938},{},[3939,3960,3981,4002],{"nodeType":1485,"data":3940,"content":3941},{},[3942],{"nodeType":1294,"data":3943,"content":3944},{},[3945,3949,3957],{"nodeType":1293,"value":3946,"marks":3947,"data":3948},"1st line: ",[],{},{"nodeType":1401,"data":3950,"content":3952},{"uri":3951},"https://pushsecurity.com/blog/introducing-cloned-login-page-detection/",[3953],{"nodeType":1293,"value":3954,"marks":3955,"data":3956},"Detecting when a login page that you access is cloned from a legitimate page.",[],{},{"nodeType":1293,"value":37,"marks":3958,"data":3959},[],{},{"nodeType":1485,"data":3961,"content":3962},{},[3963],{"nodeType":1294,"data":3964,"content":3965},{},[3966,3970,3978],{"nodeType":1293,"value":3967,"marks":3968,"data":3969},"2nd line: ",[],{},{"nodeType":1401,"data":3971,"content":3973},{"uri":3972},"https://pushsecurity.com/blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser/",[3974],{"nodeType":1293,"value":3975,"marks":3976,"data":3977},"Detecting and blocking access to a page with a known phishing kit signature present on the page",[],{},{"nodeType":1293,"value":2018,"marks":3979,"data":3980},[],{},{"nodeType":1485,"data":3982,"content":3983},{},[3984],{"nodeType":1294,"data":3985,"content":3986},{},[3987,3991,3999],{"nodeType":1293,"value":3988,"marks":3989,"data":3990},"3rd line: ",[],{},{"nodeType":1401,"data":3992,"content":3994},{"uri":3993},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[3995],{"nodeType":1293,"value":3996,"marks":3997,"data":3998},"Detecting and blocking the user behavior of entering their password into any site that the password doesn’t belong to",[],{},{"nodeType":1293,"value":2018,"marks":4000,"data":4001},[],{},{"nodeType":1485,"data":4003,"content":4004},{},[4005],{"nodeType":1294,"data":4006,"content":4007},{},[4008,4012,4019],{"nodeType":1293,"value":4009,"marks":4010,"data":4011},"4th line: ",[],{},{"nodeType":1401,"data":4013,"content":4014},{"uri":3085},[4015],{"nodeType":1293,"value":4016,"marks":4017,"data":4018},"Detecting when an attacker resumes a stolen session in a browser without the Push extension running. ",[],{},{"nodeType":1293,"value":37,"marks":4020,"data":4021},[],{},{"nodeType":1294,"data":4023,"content":4024},{},[4025],{"nodeType":1293,"value":4026,"marks":4027,"data":4028},"Each of these controls either detects and blocks the account takeover attempt outright, or provides a high-fidelity indicator that should trigger a priority investigation via your SecOps workflow. ",[],{},{"nodeType":1437,"data":4030,"content":4031},{},[4032],{"nodeType":1293,"value":4033,"marks":4034,"data":4036},"Conclusion",[4035],{"type":1387},{},{"nodeType":1294,"data":4038,"content":4039},{},[4040],{"nodeType":1293,"value":4041,"marks":4042,"data":4043},"Hopefully we’ve demonstrated shifting detection left isn’t just possible, but essential for defending against modern identity attacks and account takeover. ",[],{},{"nodeType":1294,"data":4045,"content":4046},{},[4047,4051,4059],{"nodeType":1293,"value":4048,"marks":4049,"data":4050},"This is the second post in our design philosophy series, so if you want to read about how we’re building detections that are hard for attackers to bypass using the Pyramid of Pain, ",[],{},{"nodeType":1401,"data":4052,"content":4053},{"uri":3858},[4054],{"nodeType":1293,"value":4055,"marks":4056,"data":4058},"you can check it out here",[4057],{"type":1566},{},{"nodeType":1293,"value":2018,"marks":4060,"data":4061},[],{},{"nodeType":1294,"data":4063,"content":4064},{},[4065],{"nodeType":1293,"value":4066,"marks":4067,"data":4068},"We look forward to sharing more about our design philosophy with you in the future! ",[],{},"Shifting detection left for more effective threat detection","Why relying on post-compromise detection and response is no longer an option for modern browser-based attacks.","2024-10-25T00:00:00.000Z","shifting-detection-left-for-more-effective-threat-detection",{"items":4074},[4075,4077],{"sys":4076,"name":2046},{"id":2045},{"sys":4078,"name":1305},{"id":1304},{"items":4080},[4081],{"fullName":3233,"firstName":3234,"jobTitle":3235,"profilePicture":4082},{"url":3237},{"items":4084},[4085],{"fullName":3233,"firstName":3234,"jobTitle":3235,"profilePicture":4086},{"url":3237},{"json":4088,"links":4874},{"data":4089,"content":4090,"nodeType":1295},{},[4091,4097,4116,4123,4130,4136,4139,4147,4154,4173,4184,4191,4198,4205,4298,4301,4309,4392,4398,4401,4409,4417,4424,4431,4439,4456,4463,4471,4478,4485,4493,4500,4507,4525,4531,4534,4542,4550,4557,4661,4668,4676,4683,4690,4696,4704,4711,4718,4725,4733,4740,4747,4754,4761,4767,4770,4778,4785,4818,4825,4844,4863,4868],{"data":4092,"content":4096,"nodeType":1317},{"target":4093},{"sys":4094},{"id":4095,"type":1322,"linkType":1323},"1eBClNW4NOR66F0tl9h6lD",[],{"data":4098,"content":4099,"nodeType":1294},{},[4100,4104,4112],{"data":4101,"marks":4102,"value":4103,"nodeType":1293},{},[],"The attacks on Snowflake customers in 2024 collectively constituted the biggest cyber security event of the year in terms of the number of organizations and individuals affected (at least, if you exclude CrowdStrike causing a worldwide outage in July) — certainly, it was the largest perpetrated by a criminal group against commercial enterprises. It has been touted by some news outlets as ‘",{"data":4105,"content":4106,"nodeType":1401},{"uri":2071},[4107],{"data":4108,"marks":4109,"value":4111,"nodeType":1293},{},[4110],{"type":1566},"one of the biggest breaches ever",{"data":4113,"marks":4114,"value":4115,"nodeType":1293},{},[],"’.  ",{"data":4117,"content":4118,"nodeType":1294},{},[4119],{"data":4120,"marks":4121,"value":4122,"nodeType":1293},{},[],"Snowflake was a watershed moment that signalled the significant opportunity presented by identity attacks on cloud services. It demonstrated how comparatively unsophisticated methods (logging in to user accounts with stolen credentials and dumping the data) can have the same or greater impact as a traditional network or endpoint based cyber attack involving vulnerability exploitation, malware deployment, ransomware, etc. ",{"data":4124,"content":4125,"nodeType":1294},{},[4126],{"data":4127,"marks":4128,"value":4129,"nodeType":1293},{},[],"Here’s everything you need to know about the Snowflake attacks — and what you can do to protect yourself against the next Snowflake in the future.",{"data":4131,"content":4135,"nodeType":1317},{"target":4132},{"sys":4133},{"id":4134,"type":1322,"linkType":1323},"4QoPUiP5q6Mwj1eWUZT15Q",[],{"data":4137,"content":4138,"nodeType":1326},{},[],{"data":4140,"content":4141,"nodeType":1437},{},[4142],{"data":4143,"marks":4144,"value":4146,"nodeType":1293},{},[4145],{"type":1387},"Snowflake: The facts",{"data":4148,"content":4149,"nodeType":1294},{},[4150],{"data":4151,"marks":4152,"value":4153,"nodeType":1293},{},[],"Cyber criminals associated with the threat group known as ShinyHunters claimed responsibility for breaching multiple organizations using Snowflake, a cloud-based data warehousing and analytics platform. ",{"data":4155,"content":4156,"nodeType":1294},{},[4157,4161,4170],{"data":4158,"marks":4159,"value":4160,"nodeType":1293},{},[],"ShinyHunters associates targeted ~165 organizations that were subjected to account takeover attacks using stolen credentials harvested from historical infostealer infections dating back as far as 2020, ",{"data":4162,"content":4164,"nodeType":1401},{"uri":4163},"https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",[4165],{"data":4166,"marks":4167,"value":4169,"nodeType":1293},{},[4168],{"type":1566},"according to Mandiant’s investigation",{"data":4171,"marks":4172,"value":2018,"nodeType":1293},{},[],{"data":4174,"content":4175,"nodeType":1373},{},[4176],{"data":4177,"content":4178,"nodeType":1294},{},[4179],{"data":4180,"marks":4181,"value":4183,"nodeType":1293},{},[4182],{"type":1387},">80% of the compromised accounts belonging to Snowflake customers had prior credential exposure. ",{"data":4185,"content":4186,"nodeType":1294},{},[4187],{"data":4188,"marks":4189,"value":4190,"nodeType":1293},{},[],"The impacted accounts lacked MFA, meaning successful authentication only required a valid username and password. As the Snowflake credentials found in infostealer malware credential dumps had not been rotated or updated, they remained valid and could be used to authenticate to user accounts on Snowflake tenants belonging to various customers.",{"data":4192,"content":4193,"nodeType":1294},{},[4194],{"data":4195,"marks":4196,"value":4197,"nodeType":1293},{},[],"As a data warehousing platform integrated with a range of connected cloud services, access to a customer’s Snowflake tenant provided attackers with large quantities of sensitive commercial and personal data that could be stolen and monetized by attackers in a variety of ways — such as by ransoming the victim organization, extorting individual end-customers, and selling the data on to other criminal organizations. ",{"data":4199,"content":4200,"nodeType":1294},{},[4201],{"data":4202,"marks":4203,"value":4204,"nodeType":1293},{},[],"In total, 9 public victims were named following the breach, collectively impacting hundreds of millions of people. ",{"data":4206,"content":4207,"nodeType":1481},{},[4208,4218,4228,4238,4248,4258,4268,4278,4288],{"data":4209,"content":4210,"nodeType":1485},{},[4211],{"data":4212,"content":4213,"nodeType":1294},{},[4214],{"data":4215,"marks":4216,"value":4217,"nodeType":1293},{},[],"Lending Tree: Sensitive data for over 190 million people available online including customer details, partial credit card numbers, insurance quotes and other information, being sold for $2m.",{"data":4219,"content":4220,"nodeType":1485},{},[4221],{"data":4222,"content":4223,"nodeType":1294},{},[4224],{"data":4225,"marks":4226,"value":4227,"nodeType":1293},{},[],"Truist Bank: Information belonging to 65,000 employees being sold online for $1m",{"data":4229,"content":4230,"nodeType":1485},{},[4231],{"data":4232,"content":4233,"nodeType":1294},{},[4234],{"data":4235,"marks":4236,"value":4237,"nodeType":1293},{},[],"Advance Auto Parts: 3TB of data for sale for $1.5 million. Affected 2.3 million people, as well as current and former employees and job applicants.",{"data":4239,"content":4240,"nodeType":1485},{},[4241],{"data":4242,"content":4243,"nodeType":1294},{},[4244],{"data":4245,"marks":4246,"value":4247,"nodeType":1293},{},[],"Pure Storage: Workspace with 11k customer records including company, email, LDAP username and software version numbers.",{"data":4249,"content":4250,"nodeType":1485},{},[4251],{"data":4252,"content":4253,"nodeType":1294},{},[4254],{"data":4255,"marks":4256,"value":4257,"nodeType":1293},{},[],"Los Angeles Unified: Student data, disability information, discipline details, and parent information, being sold online for $150k.",{"data":4259,"content":4260,"nodeType":1485},{},[4261],{"data":4262,"content":4263,"nodeType":1294},{},[4264],{"data":4265,"marks":4266,"value":4267,"nodeType":1293},{},[],"Neiman Marcus: 31m email addresses exposed alongside various personal information.",{"data":4269,"content":4270,"nodeType":1485},{},[4271],{"data":4272,"content":4273,"nodeType":1294},{},[4274],{"data":4275,"marks":4276,"value":4277,"nodeType":1293},{},[],"Santander: 30 million customer details for sale relating to customers of Santander Chile, Spain, and Uruguay.",{"data":4279,"content":4280,"nodeType":1485},{},[4281],{"data":4282,"content":4283,"nodeType":1294},{},[4284],{"data":4285,"marks":4286,"value":4287,"nodeType":1293},{},[],"Ticketmaster: 560 million customer details for sale, disruption to events and ticketing worldwide, increasing in scam ticket production.",{"data":4289,"content":4290,"nodeType":1485},{},[4291],{"data":4292,"content":4293,"nodeType":1294},{},[4294],{"data":4295,"marks":4296,"value":4297,"nodeType":1293},{},[],"AT&T: Call logs stolen for approximately 109 million customers (nearly all of its mobile customers). AT&T paid an undisclosed ransom fee. ",{"data":4299,"content":4300,"nodeType":1326},{},[],{"data":4302,"content":4303,"nodeType":1437},{},[4304],{"data":4305,"marks":4306,"value":4308,"nodeType":1293},{},[4307],{"type":1387},"The Snowflake attacks step-by-step",{"data":4310,"content":4311,"nodeType":1481},{},[4312,4322,4332,4342,4352,4362,4372,4382],{"data":4313,"content":4314,"nodeType":1485},{},[4315],{"data":4316,"content":4317,"nodeType":1294},{},[4318],{"data":4319,"marks":4320,"value":4321,"nodeType":1293},{},[],"Snowflake users were infected with infostealer malware that harvested credentials from user devices over an extended period via several infostealer malware variants, including; VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER.",{"data":4323,"content":4324,"nodeType":1485},{},[4325],{"data":4326,"content":4327,"nodeType":1294},{},[4328],{"data":4329,"marks":4330,"value":4331,"nodeType":1293},{},[],"Credentials appeared on criminal marketplaces e.g. dark web forums and Telegram channels.",{"data":4333,"content":4334,"nodeType":1485},{},[4335],{"data":4336,"content":4337,"nodeType":1294},{},[4338],{"data":4339,"marks":4340,"value":4341,"nodeType":1293},{},[],"ShinyHunters saw the potential in targeting Snowflake users, based on the availability of credentials, number of customer organizations, and the value of the data that can be accessed in Snowflake. ",{"data":4343,"content":4344,"nodeType":1485},{},[4345],{"data":4346,"content":4347,"nodeType":1294},{},[4348],{"data":4349,"marks":4350,"value":4351,"nodeType":1293},{},[],"ShinyHunters embarked on a large-scale campaign targeting Snowflake customer accounts using previously breached credentials. ",{"data":4353,"content":4354,"nodeType":1485},{},[4355],{"data":4356,"content":4357,"nodeType":1294},{},[4358],{"data":4359,"marks":4360,"value":4361,"nodeType":1293},{},[],"ShinyHunters accessed user accounts that lacked MFA, belonging to approximately 165 Snowflake customers. ",{"data":4363,"content":4364,"nodeType":1485},{},[4365],{"data":4366,"content":4367,"nodeType":1294},{},[4368],{"data":4369,"marks":4370,"value":4371,"nodeType":1293},{},[],"ShinyHunters used SQL-based reconnaissance, staging, and data exfiltration techniques, expedited by custom hacker tooling developed specifically for Snowflake, to conduct attacks at scale.",{"data":4373,"content":4374,"nodeType":1485},{},[4375],{"data":4376,"content":4377,"nodeType":1294},{},[4378],{"data":4379,"marks":4380,"value":4381,"nodeType":1293},{},[],"ShinyHunters acquired massive quantities of Snowflake data based on the information that each customer stored in Snowflake or connected apps. ",{"data":4383,"content":4384,"nodeType":1485},{},[4385],{"data":4386,"content":4387,"nodeType":1294},{},[4388],{"data":4389,"marks":4390,"value":4391,"nodeType":1293},{},[],"ShinyHunters began attempts to extort Snowflake and end-customers using the data acquired.",{"data":4393,"content":4397,"nodeType":1317},{"target":4394},{"sys":4395},{"id":4396,"type":1322,"linkType":1323},"2J92gFLs1wAAGC4nQTaiWu",[],{"data":4399,"content":4400,"nodeType":1326},{},[],{"data":4402,"content":4403,"nodeType":1437},{},[4404],{"data":4405,"marks":4406,"value":4408,"nodeType":1293},{},[4407],{"type":1387},"Why did the Snowflake breaches happen?",{"data":4410,"content":4411,"nodeType":1459},{},[4412],{"data":4413,"marks":4414,"value":4416,"nodeType":1293},{},[4415],{"type":1387},"Stolen credentials remained valid for years",{"data":4418,"content":4419,"nodeType":1294},{},[4420],{"data":4421,"marks":4422,"value":4423,"nodeType":1293},{},[],"The credentials used to access Snowflake accounts from historical infostealer infections had not been changed or rotated despite dating back as far as 2020, and remained valid. ",{"data":4425,"content":4426,"nodeType":1294},{},[4427],{"data":4428,"marks":4429,"value":4430,"nodeType":1293},{},[],"This highlights the potential risk of breached credentials already in the public domain, particularly in the case of cloud services like Snowflake that may not be subject to the same levels of credential hygiene as other traditional enterprise domain accounts. ",{"data":4432,"content":4433,"nodeType":1459},{},[4434],{"data":4435,"marks":4436,"value":4438,"nodeType":1293},{},[4437],{"type":1387},"Local logins lacked MFA ",{"data":4440,"content":4441,"nodeType":1294},{},[4442,4446,4453],{"data":4443,"marks":4444,"value":4445,"nodeType":1293},{},[],"Even where organizations were primarily encouraging employees to use SSO to access their Snowflake tenant, previously created local logins with a username and password continue to exist even after introducing SSO-based logins. Further, MFA was not globally enforceable at the application level, meaning that MFA was only set when logging into an IdP account for SSO, but not for local logins. We call this problem ",{"data":4447,"content":4448,"nodeType":1401},{"uri":2735},[4449],{"data":4450,"marks":4451,"value":2738,"nodeType":1293},{},[4452],{"type":1566},{"data":4454,"marks":4455,"value":2018,"nodeType":1293},{},[],{"data":4457,"content":4458,"nodeType":1294},{},[4459],{"data":4460,"marks":4461,"value":4462,"nodeType":1293},{},[],"This meant that attackers were able to take over Snowflake accounts with only a single authentication factor (username & password). ",{"data":4464,"content":4465,"nodeType":1459},{},[4466],{"data":4467,"marks":4468,"value":4470,"nodeType":1293},{},[4469],{"type":1387},"Snowflake was a high-value target used by many organizations",{"data":4472,"content":4473,"nodeType":1294},{},[4474],{"data":4475,"marks":4476,"value":4477,"nodeType":1293},{},[],"As a data warehousing platform used by a vast number of organizations, Snowflake represented a high-value target based on the data typically stored within it, and the repeatable way in which Snowflake users could be targeted. ",{"data":4479,"content":4480,"nodeType":1294},{},[4481],{"data":4482,"marks":4483,"value":4484,"nodeType":1293},{},[],"The attacker followed a near identical process when targeting Snowflake victims, meaning it could be scripted and executed at scale, with attacks taking a matter of minutes. ",{"data":4486,"content":4487,"nodeType":1459},{},[4488],{"data":4489,"marks":4490,"value":4492,"nodeType":1293},{},[4491],{"type":1387},"Infostealer infections are driving credential availability",{"data":4494,"content":4495,"nodeType":1294},{},[4496],{"data":4497,"marks":4498,"value":4499,"nodeType":1293},{},[],"Infostealers are often seen as a low-priority issue, but are the primary source of stolen credentials used in campaigns like this one. ",{"data":4501,"content":4502,"nodeType":1294},{},[4503],{"data":4504,"marks":4505,"value":4506,"nodeType":1293},{},[],"EDR is a strong protection but is often bypassed by infostealers as attackers continually modify them to bypass security controls. Further, unmanaged devices such as those used by third-party contractors or BYOD employees often lack the robust controls applied to company-managed devices and are naturally more susceptible to infostealer attacks. And since browser profiles can be synced across devices, even personal device compromises can result in the capture of corporate credentials.  ",{"data":4508,"content":4509,"nodeType":1294},{},[4510,4514,4521],{"data":4511,"marks":4512,"value":4513,"nodeType":1293},{},[],"There is some suggestion that targeting key third-party suppliers – ",{"data":4515,"content":4516,"nodeType":1401},{"uri":2819},[4517],{"data":4518,"marks":4519,"value":2822,"nodeType":1293},{},[4520],{"type":1566},{"data":4522,"marks":4523,"value":4524,"nodeType":1293},{},[]," – provided some of the access to Snowflake customers needed. It’s unclear what came first, but it’s possible (likely, even) that EPAM was identified as a target specifically because of its lucrative customer base and Snowflake credentials — adding another indicator that Snowflake was potentially a premeditated attack inspired by the availability of Snowflake credentials online.",{"data":4526,"content":4530,"nodeType":1317},{"target":4527},{"sys":4528},{"id":4529,"type":1322,"linkType":1323},"4D0gjt5oJLNKJH8GzjP8Je",[],{"data":4532,"content":4533,"nodeType":1326},{},[],{"data":4535,"content":4536,"nodeType":1437},{},[4537],{"data":4538,"marks":4539,"value":4541,"nodeType":1293},{},[4540],{"type":1387},"Key takeaways from the Snowflake attacks",{"data":4543,"content":4544,"nodeType":1459},{},[4545],{"data":4546,"marks":4547,"value":4549,"nodeType":1293},{},[4548],{"type":1387},"Securing your IdP accounts is not enough",{"data":4551,"content":4552,"nodeType":1294},{},[4553],{"data":4554,"marks":4555,"value":4556,"nodeType":1293},{},[],"SSO can help reduce your identity attack surface, but it's not feasible to get every workforce identity behind it.",{"data":4558,"content":4559,"nodeType":1481},{},[4560,4583,4604,4639],{"data":4561,"content":4562,"nodeType":1485},{},[4563],{"data":4564,"content":4565,"nodeType":1294},{},[4566,4570,4579],{"data":4567,"marks":4568,"value":4569,"nodeType":1293},{},[],"Only 1 in 3 apps support SAML SSO, and those that offer it often charge more for it; the “",{"data":4571,"content":4573,"nodeType":1401},{"uri":4572},"https://ssotax.org/",[4574],{"data":4575,"marks":4576,"value":4578,"nodeType":1293},{},[4577],{"type":1566},"SSO tax",{"data":4580,"marks":4581,"value":4582,"nodeType":1293},{},[],"”.",{"data":4584,"content":4585,"nodeType":1485},{},[4586],{"data":4587,"content":4588,"nodeType":1294},{},[4589,4593,4601],{"data":4590,"marks":4591,"value":4592,"nodeType":1293},{},[],"Many apps are self-adopted by employees, leaving security teams unaware and unable to enforce SSO.  The typical organization has ",{"data":4594,"content":4595,"nodeType":1401},{"uri":1759},[4596],{"data":4597,"marks":4598,"value":4600,"nodeType":1293},{},[4599],{"type":1566},"hundreds of apps and thousands of unmanaged identities outside of SSO",{"data":4602,"marks":4603,"value":1712,"nodeType":1293},{},[],{"data":4605,"content":4606,"nodeType":1485},{},[4607],{"data":4608,"content":4609,"nodeType":1294},{},[4610,4614,4622,4626,4635],{"data":4611,"marks":4612,"value":4613,"nodeType":1293},{},[],"Most apps do not prevent users from creating additional \"",{"data":4615,"content":4616,"nodeType":1401},{"uri":2735},[4617],{"data":4618,"marks":4619,"value":4621,"nodeType":1293},{},[4620],{"type":1566},"ghost login",{"data":4623,"marks":4624,"value":4625,"nodeType":1293},{},[],"\" methods outside of SSO (especially by default), accounting for around ",{"data":4627,"content":4629,"nodeType":1401},{"uri":4628},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/#id-identity-configurations-and-how-they-can-be-exploited_id-many-accounts-lack-the-most-basic-protections",[4630],{"data":4631,"marks":4632,"value":4634,"nodeType":1293},{},[4633],{"type":1566},"10% of all identities",{"data":4636,"marks":4637,"value":4638,"nodeType":1293},{},[]," observed by Push. ",{"data":4640,"content":4641,"nodeType":1485},{},[4642],{"data":4643,"content":4644,"nodeType":1294},{},[4645,4649,4657],{"data":4646,"marks":4647,"value":4648,"nodeType":1293},{},[],"In total, we identified that ",{"data":4650,"content":4651,"nodeType":1401},{"uri":1759},[4652],{"data":4653,"marks":4654,"value":4656,"nodeType":1293},{},[4655],{"type":1566},"37% (2 in 5) accounts have a password login set with no MFA",{"data":4658,"marks":4659,"value":4660,"nodeType":1293},{},[],", while 9% have no MFA AND a weak, breached, or reused password.",{"data":4662,"content":4663,"nodeType":1294},{},[4664],{"data":4665,"marks":4666,"value":4667,"nodeType":1293},{},[],"So, relying on locked-down IdP accounts and maximising the use of SSO is an important pillar of an effective identity security strategy, but there will always be gaps. Unless you recognize this, you may be blindsided by attackers finding them before you do. ",{"data":4669,"content":4670,"nodeType":1459},{},[4671],{"data":4672,"marks":4673,"value":4675,"nodeType":1293},{},[4674],{"type":1387},"The threat of infostealers and stolen credentials needs to be taken seriously",{"data":4677,"content":4678,"nodeType":1294},{},[4679],{"data":4680,"marks":4681,"value":4682,"nodeType":1293},{},[],"Breached credentials appearing online is not always seen as a top priority for security teams, particularly when there’s so much noise from all of the outdated or simply erroneous findings (anyone that’s ever subscribed to a credential TI feed knows the pain of this). ",{"data":4684,"content":4685,"nodeType":1294},{},[4686],{"data":4687,"marks":4688,"value":4689,"nodeType":1293},{},[],"But Snowflake serves as a stark reminder that despite all the false positives, stolen credentials are sometimes valid — and when weaponized at-scale they can be a powerful tool for attackers. ",{"data":4691,"content":4695,"nodeType":1317},{"target":4692},{"sys":4693},{"id":4694,"type":1322,"linkType":1323},"4EODpwKsqNivpvP2yMtZCd",[],{"data":4697,"content":4698,"nodeType":1459},{},[4699],{"data":4700,"marks":4701,"value":4703,"nodeType":1293},{},[4702],{"type":1387},"Don’t rely on third-parties to protect your identities for you",{"data":4705,"content":4706,"nodeType":1294},{},[4707],{"data":4708,"marks":4709,"value":4710,"nodeType":1293},{},[],"Snowflake came under fire following the attacks for not enabling MFA by default, or giving security teams sufficient tools to deal with the incident. ",{"data":4712,"content":4713,"nodeType":1294},{},[4714],{"data":4715,"marks":4716,"value":4717,"nodeType":1293},{},[],"This is perhaps justifiable, but is hardly the exception. Very few apps enforce MFA by default or provide a global MFA enforcement mechanism. Most don’t even provide audit logs (and when they do, the scope of logging is pretty limited). And we regularly encounter apps that don’t give you any information about account configuration as an admin — like which accounts have MFA, or the login methods that they’re using (e.g. SSO via SAML, SSO via OIDC, password, which IdPs are being used…) which is essential information to be able to secure your identity attack surface. ",{"data":4719,"content":4720,"nodeType":1294},{},[4721],{"data":4722,"marks":4723,"value":4724,"nodeType":1293},{},[],"Yes, it would be great if app vendors put security first and made controls available by default, for all customers (not just the premium ones). But in the absence of an industrywide shift toward security-first product development, it’s important that organizations don’t just point the finger at service providers — and take matters into their own hands when it comes to securing their user identities. ",{"data":4726,"content":4727,"nodeType":1459},{},[4728],{"data":4729,"marks":4730,"value":4732,"nodeType":1293},{},[4731],{"type":1387},"This isn’t a specific Snowflake problem — it could have been any application",{"data":4734,"content":4735,"nodeType":1294},{},[4736],{"data":4737,"marks":4738,"value":4739,"nodeType":1293},{},[],"While Snowflake was admittedly a high-value target because of the data it collected, apps with sensitive data (or with integrations connecting them to data collected in adjacent apps) are not in short supply. ",{"data":4741,"content":4742,"nodeType":1294},{},[4743],{"data":4744,"marks":4745,"value":4746,"nodeType":1293},{},[],"If we accept that many other apps are similarly desirable targets, then we should also consider that it’s unlikely that Snowflake is the only app that has valid credentials sitting around on the internet, waiting to be weaponized by criminals. Equally, it’s not the only app that doesn’t require mandatory MFA for user accounts, as we discussed above. The next Snowflake is likely to lurk in the same breached datasets, possibly even using the same credentials.",{"data":4748,"content":4749,"nodeType":1294},{},[4750],{"data":4751,"marks":4752,"value":4753,"nodeType":1293},{},[],"There’s been a clear increase in the number of infostealer and stolen credential related breaches and news stories since Snowflake as attackers wise up to the potential opportunity and start seeing the dollar signs. It would be naive to think that this was a one off event — the next Snowflake is probably not too far away. ",{"data":4755,"content":4756,"nodeType":1294},{},[4757],{"data":4758,"marks":4759,"value":4760,"nodeType":1293},{},[],"For a deep-dive analysis of the impact of Snowflake, check out our on-demand webinar from earlier this year.",{"data":4762,"content":4766,"nodeType":1317},{"target":4763},{"sys":4764},{"id":4765,"type":1322,"linkType":1323},"7LkU5DqE9HJ1PQu9BTg6Mw",[],{"data":4768,"content":4769,"nodeType":1326},{},[],{"data":4771,"content":4772,"nodeType":1437},{},[4773],{"data":4774,"marks":4775,"value":4777,"nodeType":1293},{},[4776],{"type":1387},"How to protect yourself from the next Snowflake using Push",{"data":4779,"content":4780,"nodeType":1294},{},[4781],{"data":4782,"marks":4783,"value":4784,"nodeType":1293},{},[],"Organizations looking to reduce their exposure to account takeover using stolen credentials should look to:",{"data":4786,"content":4787,"nodeType":1481},{},[4788,4798,4808],{"data":4789,"content":4790,"nodeType":1485},{},[4791],{"data":4792,"content":4793,"nodeType":1294},{},[4794],{"data":4795,"marks":4796,"value":4797,"nodeType":1293},{},[],"Identify the apps being used across the business and locate vulnerable workforce identities using weak, breached, or reused credentials, and missing MFA. Where SSO is the preferred login method, local username & password logins should ideally be removed. ",{"data":4799,"content":4800,"nodeType":1485},{},[4801],{"data":4802,"content":4803,"nodeType":1294},{},[4804],{"data":4805,"marks":4806,"value":4807,"nodeType":1293},{},[],"Where credentials appear in third-party data breaches, verify where they are still valid and ensure that the credentials are changed. ",{"data":4809,"content":4810,"nodeType":1485},{},[4811],{"data":4812,"content":4813,"nodeType":1294},{},[4814],{"data":4815,"marks":4816,"value":4817,"nodeType":1293},{},[],"Detect unauthorized access to workforce identities where sessions are initiated or resumed from unusual or unexpected locations. It should be noted that while this is a fairly common feature for larger enterprise cloud platforms with configurable access control policies, this is not typically possible for most SaaS applications.  ",{"data":4819,"content":4820,"nodeType":1294},{},[4821],{"data":4822,"marks":4823,"value":4824,"nodeType":1293},{},[],"All of these use cases can be achieved using Push. The Push browser extension detects all logins performed in employee browsers, capturing granular information about the login method and MFA types used, and enriching this data by integrating with your preferred IdP.",{"data":4826,"content":4827,"nodeType":1294},{},[4828,4832,4840],{"data":4829,"marks":4830,"value":4831,"nodeType":1293},{},[],"Push’s ",{"data":4833,"content":4835,"nodeType":1401},{"uri":4834},"https://pushsecurity.com/blog/verified-stolen-credential-detection",[4836],{"data":4837,"marks":4838,"value":4839,"nodeType":1293},{},[],"verified stolen credential detection feature",{"data":4841,"marks":4842,"value":4843,"nodeType":1293},{},[]," compares a k-anonymized hash of user passwords observed with stolen credential TI feeds to cut through the noise and identify where stolen credentials appearing online represent a genuine vulnerability.   ",{"data":4845,"content":4846,"nodeType":1294},{},[4847,4851,4859],{"data":4848,"marks":4849,"value":4850,"nodeType":1293},{},[],"On top of this, all logins made in browsers protected by the Push extension, across every app, are verified by ",{"data":4852,"content":4853,"nodeType":1401},{"uri":3085},[4854],{"data":4855,"marks":4856,"value":4858,"nodeType":1293},{},[4857],{"type":1566},"adding a unique marker to the user agent string of the session",{"data":4860,"marks":4861,"value":4862,"nodeType":1293},{},[],", which will then appear in your IdP logs. This means that any session occurring outside of the Push-protected estate can be flagged to your security team via SIEM alert — including where an attacker uses stolen credentials to log into an app from a browser without the Push extension running. ",{"data":4864,"content":4867,"nodeType":1317},{"target":4865},{"sys":4866},{"id":2025,"type":1322,"linkType":1323},[],{"data":4869,"content":4870,"nodeType":1294},{},[4871],{"data":4872,"marks":4873,"value":37,"nodeType":1293},{},[],{"entries":4875},{"hyperlink":4876,"inline":4877,"block":4878},[],[],[4879,4905,4913,4922,4926,4931,4939],{"sys":4880,"__typename":4881,"content":4882,"name":4904,"title":118},{"id":4095},"InsightTextBlockComponent",{"json":4883},{"nodeType":1295,"data":4884,"content":4885},{},[4886],{"nodeType":1294,"data":4887,"content":4888},{},[4889,4893,4901],{"nodeType":1293,"value":4890,"marks":4891,"data":4892},"The attackers behind this campaign went on a worldwide hacking spree in 2025, taking on the moniker of \"Scattered Lapsus$ Hunters\" and launching attacks on Marks & Spencer, Co-op, Jaguar Land Rover, and hundreds of Salesforce customers. ",[],{},{"nodeType":1401,"data":4894,"content":4896},{"uri":4895},"https://pushsecurity.com/blog/scattered-lapsus-hunters/",[4897],{"nodeType":1293,"value":4898,"marks":4899,"data":4900},"Check out the blog post for all the details. ",[],{},{"nodeType":1293,"value":37,"marks":4902,"data":4903},[],{},"Snowflake insight box 1",{"sys":4906,"__typename":4907,"type":4908,"ctaText":4909,"buttonLabel":4910,"buttonColour":4911,"buttonUrl":4912},{"id":4134},"CtaWidget","Custom","Get our latest ebook to learn about the evolution of identity attacks in 2024 and their role in public breaches. ","Download Now","sea blue","https://pushsecurity.com/resources/2024-identity-attacks",{"sys":4914,"__typename":4915,"title":4916,"caption":4917,"layoutMode":118,"file":4918},{"id":4396},"Image","Snowflake attack path","Attack path traversed in the attacks on Snowflake customers",{"url":4919,"width":4920,"height":4921},"https://images.ctfassets.net/y1cdw1ablpvd/4cjVqskN2svdMLJpOkAGxq/057ec00e3b9965534e5ffeff5b423744/Snowflake_Attack_Path__3_.png",6140,2568,{"sys":4923,"__typename":4907,"type":4908,"ctaText":4924,"buttonLabel":4925,"buttonColour":4911,"buttonUrl":1704},{"id":4529},"Read our blog post to learn more about the rise of infostealers and their role in the credential theft ecosystem. ","Read the Blog",{"sys":4927,"__typename":4907,"type":4908,"ctaText":4928,"buttonLabel":4929,"buttonColour":4930,"buttonUrl":4834},{"id":4694},"Find out how Push helps you to cut through the noise of TI feeds with its validated stolen credentials feature, enabling you to pinpoint and remediate vulnerable accounts. ","Read the Feature Release","orange",{"sys":4932,"__typename":4933,"title":4934,"youTubeUrl":4935,"imagePlaceholder":4936},{"id":4765},"ExternalVideo","Snowflake: The tip of the iceberg – Three practical takeaways from the Snowflake incident","https://www.youtube.com/watch?v=0s0NB4L7oKU",{"url":4937,"width":363,"height":4938},"https://images.ctfassets.net/y1cdw1ablpvd/6DHHMV4gUPSKU36Jzyf0ei/458ed0cc9e04c53b92daa96013ada0d8/Twitter-X_-_1200_x_680.png",675,{"sys":4940,"__typename":4907,"type":4941,"ctaText":4942,"buttonLabel":4943,"buttonColour":4944,"buttonUrl":4945},{"id":2025},"Demo","Book a demo to see how Push helps you detect and prevent account takeover and reduce your identity attack surface","Book Demo","sunny orange","https://pushsecurity.com/demo","content:blog:snowflake-retro.json","json","content","blog/snowflake-retro.json","blog/snowflake-retro",1776359986828]