[{"data":1,"prerenderedAt":4497},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/what-the-rise-of-infostealers-says-about-identity-attacks":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"ogImage":118,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1296,"synopsis":1297,"hashTags":118,"publishedDate":1298,"slug":1299,"tagsCollection":1300,"relatedBlogPostsCollection":1310,"authorsCollection":3306,"content":3310,"_id":4492,"_type":4493,"_source":4494,"_file":4495,"_stem":4496,"_extension":4493},"/blog/what-the-rise-of-infostealers-says-about-identity-attacks","blog",{"id":1280,"publishedAt":1281},"4OrixXXLxRmSDxa7PF9gfM","2024-10-07T08:12:28.910Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"Infostealers seem to have become an overnight celebrity, having been previously shrugged off by enterprises with bigger fish to fry. The reality is that infostealers haven’t necessarily changed – but the world that they inhabit and how stolen data is used has.  ","text","paragraph","document","What the rise of infostealers says about identity attacks","What the rise in popularity of infostealers tells us about the cybercrime ecosystem and the shift toward identity attacks. ","2024-07-31T00:00:00.000Z","what-the-rise-of-infostealers-says-about-identity-attacks",{"items":1301},[1302,1306],{"sys":1303,"name":1305},{"id":1304},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":1307,"name":1309},{"id":1308},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1311},[1312,1912,2447],{"__typename":1313,"sys":1314,"content":1316,"title":1894,"synopsis":1895,"hashTags":118,"publishedDate":1896,"slug":1897,"tagsCollection":1898,"authorsCollection":1904},"BlogPosts",{"id":1315},"11C3shj5SlkS8sAd3AlYDp",{"json":1317},{"data":1318,"content":1319,"nodeType":1295},{},[1320,1342,1362,1369,1378,1385,1393,1400,1407,1416,1436,1443,1450,1457,1463,1470,1503,1510,1517,1524,1531,1537,1544,1551,1558,1590,1596,1603,1610,1641,1647,1654,1661,1668,1675,1681,1687,1694,1701,1708,1714,1721,1728,1735,1742,1761,1778,1785,1792,1799,1805,1812,1831,1837,1844,1872,1879,1886],{"data":1321,"content":1322,"nodeType":1294},{},[1323,1327,1338],{"data":1324,"marks":1325,"value":1326,"nodeType":1293},{},[],"It’s been well reported that ",{"data":1328,"content":1330,"nodeType":1337},{"uri":1329},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/",[1331],{"data":1332,"marks":1333,"value":1336,"nodeType":1293},{},[1334],{"type":1335},"underline","identity attacks are on the rise","hyperlink",{"data":1339,"marks":1340,"value":1341,"nodeType":1293},{},[],", and constantly evolving phishing tools and techniques are a big part of this. In particular, the increasing prevalence of MFA has led to AitM phishing attacks becoming much more common. The threat intelligence industry naturally wants to locate and shutdown all the phishing servers – but the phishers are fighting back.",{"data":1343,"content":1344,"nodeType":1294},{},[1345,1349,1358],{"data":1346,"marks":1347,"value":1348,"nodeType":1293},{},[],"Before we dive into how AitM phishing kits evade detection, you should check out our earlier blog post on ‘",{"data":1350,"content":1352,"nodeType":1337},{"uri":1351},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[1353],{"data":1354,"marks":1355,"value":1357,"nodeType":1293},{},[1356],{"type":1335},"Phishing 2.0 – how phishing toolkits are evolving with AitM",{"data":1359,"marks":1360,"value":1361,"nodeType":1293},{},[],"’ if you want to get up to speed with what these toolkits are, and why attackers are using them more regularly. ",{"data":1363,"content":1364,"nodeType":1294},{},[1365],{"data":1366,"marks":1367,"value":1368,"nodeType":1293},{},[],"In this blog post, we’re going to look at a recent instance of the NakedPages AitM phishing toolkit and some of the steps it takes to frustrate detection and analysis. In particular, we’ll look at how malicious activity is obfuscated through the use of legitimate SaaS services. NakedPages uses a range of different techniques and so serves as a good case study as to how AitM toolkits are being designed to evade detection.",{"data":1370,"content":1376,"nodeType":1377},{"target":1371},{"sys":1372},{"id":1373,"type":1374,"linkType":1375},"2Qcn2nNRXVkdqqxGO8lDZf","Link","Entry",[],"embedded-entry-block",{"data":1379,"content":1380,"nodeType":1294},{},[1381],{"data":1382,"marks":1383,"value":1384,"nodeType":1293},{},[],"Before we dive in, it’s useful to keep in mind that while there is a lot of complication here, most of this happens in seconds and is transparent to the intended victim accessing from a real browser.",{"data":1386,"content":1387,"nodeType":1392},{},[1388],{"data":1389,"marks":1390,"value":1391,"nodeType":1293},{},[],"Step 1: Cloudflare Workers for the initial gateway","heading-1",{"data":1394,"content":1395,"nodeType":1294},{},[1396],{"data":1397,"marks":1398,"value":1399,"nodeType":1293},{},[],"A key feature of the NakedPages kit is that it has several stages and redirections and, in order for it to operate as intended, the target has to arrive at the beginning. The first step involves visiting a URL that is simply a Cloudflare Worker. Cloudflare Workers are a serverless execution environment, a bit like AWS lambdas.",{"data":1401,"content":1402,"nodeType":1294},{},[1403],{"data":1404,"marks":1405,"value":1406,"nodeType":1293},{},[],"The benefit to the attacker is that this gives them a highly reputable primary domain as it is one owned and operated by Cloudflare. Flagging recently registered or uncategorized/rare domains for further analysis won’t work for this. For example, the URL used in this instance was the following:",{"data":1408,"content":1409,"nodeType":1294},{},[1410],{"data":1411,"marks":1412,"value":1415,"nodeType":1293},{},[1413],{"type":1414},"code","hxxps://226028cc.502f135e3e036e726fba22d4.workers.dev",{"data":1417,"content":1418,"nodeType":1294},{},[1419,1423,1432],{"data":1420,"marks":1421,"value":1422,"nodeType":1293},{},[],"For other examples of Cloudflare Workers being abused for phishing, ",{"data":1424,"content":1426,"nodeType":1337},{"uri":1425},"https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/its-raining-phish-and-scams-how-cloudflare-pages-dev-and-workers-dev-domains-get-abused/",[1427],{"data":1428,"marks":1429,"value":1431,"nodeType":1293},{},[1430],{"type":1335},"check out this blog post from Trustwave",{"data":1433,"marks":1434,"value":1435,"nodeType":1293},{},[],".",{"data":1437,"content":1438,"nodeType":1392},{},[1439],{"data":1440,"marks":1441,"value":1442,"nodeType":1293},{},[],"Step 2: Cloudflare Turnstile for bot detection",{"data":1444,"content":1445,"nodeType":1294},{},[1446],{"data":1447,"marks":1448,"value":1449,"nodeType":1293},{},[],"The only purpose of the Cloudflare Worker is to act as a bot gateway to prevent automated analysis getting further than this point. For this it uses Cloudflare Turnstile. Turnstile is a highly effective tool for detecting the difference between bots and human users as a replacement for CAPTCHAs used by websites across the world. ",{"data":1451,"content":1452,"nodeType":1294},{},[1453],{"data":1454,"marks":1455,"value":1456,"nodeType":1293},{},[],"If it doesn’t work transparently then you’ll probably see something like this:",{"data":1458,"content":1462,"nodeType":1377},{"target":1459},{"sys":1460},{"id":1461,"type":1374,"linkType":1375},"4XNxLbiZf3xUK1WeFDjjxl",[],{"data":1464,"content":1465,"nodeType":1294},{},[1466],{"data":1467,"marks":1468,"value":1469,"nodeType":1293},{},[],"However, who else wants to keep out the bots? Well, phishers of course! There are many sandbox environments and other automated platforms out there, visiting every URL they come across in the search for malicious behavior. This stops many of them in their tracks as they never get past the Turnstile check. ",{"data":1471,"content":1472,"nodeType":1294},{},[1473,1477,1486,1490,1499],{"data":1474,"marks":1475,"value":1476,"nodeType":1293},{},[],"Malicious use of Turnstile use has become much more common now. Examples include other criminal kits ",{"data":1478,"content":1480,"nodeType":1337},{"uri":1479},"https://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/",[1481],{"data":1482,"marks":1483,"value":1485,"nodeType":1293},{},[1484],{"type":1335},"such as Tycoon",{"data":1487,"marks":1488,"value":1489,"nodeType":1293},{},[],", as well as ",{"data":1491,"content":1493,"nodeType":1337},{"uri":1492},"https://fin3ss3g0d.net/index.php/2024/04/08/evilgophishs-approach-to-advanced-bot-detection-with-cloudflare-turnstile/",[1494],{"data":1495,"marks":1496,"value":1498,"nodeType":1293},{},[1497],{"type":1335},"open-source phishing tools focused on red teaming",{"data":1500,"marks":1501,"value":1502,"nodeType":1293},{},[],". ",{"data":1504,"content":1505,"nodeType":1392},{},[1506],{"data":1507,"marks":1508,"value":1509,"nodeType":1293},{},[],"Step 3: Required URL parameters and custom auth headers",{"data":1511,"content":1512,"nodeType":1294},{},[1513],{"data":1514,"marks":1515,"value":1516,"nodeType":1293},{},[],"If you get past Turnstile, then you’ll finally be redirected to a more conventionally suspicious domain. However, you’ll need to supply the correct URL parameters and headers, or that request might behave differently. ",{"data":1518,"content":1519,"nodeType":1294},{},[1520],{"data":1521,"marks":1522,"value":1523,"nodeType":1293},{},[],"Suspicious domains can be found and interrogated through other means, such as observing new domain registrations or certificate transparency logs. In this case, the phishers add other steps involving required URL parameters and custom headers. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":1525,"content":1526,"nodeType":1294},{},[1527],{"data":1528,"marks":1529,"value":1530,"nodeType":1293},{},[],"The following code snippet shows how this operates. Bonus points for spotting how they actually forgot to implement their own RSA encryption function and instead send their “encrypted” user agents in clear text:",{"data":1532,"content":1536,"nodeType":1377},{"target":1533},{"sys":1534},{"id":1535,"type":1374,"linkType":1375},"45aif31bot9phquQPkz20p",[],{"data":1538,"content":1539,"nodeType":1392},{},[1540],{"data":1541,"marks":1542,"value":1543,"nodeType":1293},{},[],"Step 4: Requiring JavaScript execution",{"data":1545,"content":1546,"nodeType":1294},{},[1547],{"data":1548,"marks":1549,"value":1550,"nodeType":1293},{},[],"Another aspect of the previous step is that it requires JavaScript to execute. That means defensive techniques that simply make HTTP(S) requests and scrape content will not automatically be able to follow the link without allowing JavaScript execution. This forces the use of dynamic sandbox techniques that actually load a DOM, as it’s almost impossible for static analysis to generically solve this problem.",{"data":1552,"content":1553,"nodeType":1392},{},[1554],{"data":1555,"marks":1556,"value":1557,"nodeType":1293},{},[],"Step 5: Redirecting to legitimate domains",{"data":1559,"content":1560,"nodeType":1294},{},[1561,1565,1573,1577,1586],{"data":1562,"marks":1563,"value":1564,"nodeType":1293},{},[],"Attackers will also redirect to legitimate domains to mask their activity. Let’s say a defender has visited the attacker’s malicious domain without executing JavaScript or supplying the correct URL parameters. The attacker doesn’t want to activate their malicious phishing behavior at this point, so they need to do something benign instead. In this case, they simply redirect to ",{"data":1566,"content":1568,"nodeType":1337},{"uri":1567},"https://example.com",[1569],{"data":1570,"marks":1571,"value":1567,"nodeType":1293},{},[1572],{"type":1335},{"data":1574,"marks":1575,"value":1576,"nodeType":1293},{},[],". Interestingly, ",{"data":1578,"content":1580,"nodeType":1337},{"uri":1579},"https://www.youtube.com/watch?v=-W-LxcbUxI4&t=643s",[1581],{"data":1582,"marks":1583,"value":1585,"nodeType":1293},{},[1584],{"type":1335},"EvilProxy has also been seen redirecting to example.com too",{"data":1587,"marks":1588,"value":1589,"nodeType":1293},{},[],":",{"data":1591,"content":1595,"nodeType":1377},{"target":1592},{"sys":1593},{"id":1594,"type":1374,"linkType":1375},"450Y7W1uXVkKSps5y0xhBe",[],{"data":1597,"content":1598,"nodeType":1392},{},[1599],{"data":1600,"marks":1601,"value":1602,"nodeType":1293},{},[],"Step 6: HTTP referer header masking",{"data":1604,"content":1605,"nodeType":1294},{},[1606],{"data":1607,"marks":1608,"value":1609,"nodeType":1293},{},[],"Maintainers of legitimate websites often look at the HTTP referer header to see where they are being linked from. This is often a critical task for businesses, particularly for things like marketing. However, what if employees spot strange redirects coming in from suspicious looking domains like the ones used by this phishing kit? Perhaps they might investigate those domains and/or tip off relevant security vendors and organizations. ",{"data":1611,"content":1612,"nodeType":1294},{},[1613,1617,1625,1629,1637],{"data":1614,"marks":1615,"value":1616,"nodeType":1293},{},[],"Unless, of course, you were to use a service to mask the HTTP referrer – which is exactly what the phishing kit does in this case. NakedPages makes use of ",{"data":1618,"content":1620,"nodeType":1337},{"uri":1619},"https://href.li/",[1621],{"data":1622,"marks":1623,"value":1619,"nodeType":1293},{},[1624],{"type":1335},{"data":1626,"marks":1627,"value":1628,"nodeType":1293},{},[]," as a service to strip the referral to ensure the redirection is performed anonymously. Rather conveniently, it seems the default example that ",{"data":1630,"content":1632,"nodeType":1337},{"uri":1631},"https://href.li",[1633],{"data":1634,"marks":1635,"value":1631,"nodeType":1293},{},[1636],{"type":1335},{"data":1638,"marks":1639,"value":1640,"nodeType":1293},{},[]," uses is… example.com:",{"data":1642,"content":1646,"nodeType":1377},{"target":1643},{"sys":1644},{"id":1645,"type":1374,"linkType":1375},"78xFQwTG1r0YWGJ24iEdYP",[],{"data":1648,"content":1649,"nodeType":1392},{},[1650],{"data":1651,"marks":1652,"value":1653,"nodeType":1293},{},[],"Step 7: Loading balanced domains",{"data":1655,"content":1656,"nodeType":1294},{},[1657],{"data":1658,"marks":1659,"value":1660,"nodeType":1293},{},[],"You’re probably thinking: Step 7? Surely, if a victim’s browser has finally made it this far then the attackers would just serve up the malicious phishing content at this point, right? Well, we aren’t quite done yet. These initial gateway servers are one of the most important components to keep undetected, as existing phishing campaigns and (as yet unread) emails will be leading to them.",{"data":1662,"content":1663,"nodeType":1294},{},[1664],{"data":1665,"marks":1666,"value":1667,"nodeType":1293},{},[],"Once we get to the more obviously malicious phishing activity, there is a higher chance of detection and user reports. In this case the phishing kit actually retrieves a new URL to redirect to, along with a suitable JWT authentication parameter. The benefit of this is that when URLs/hostnames get flagged as malicious, blocked or otherwise taken down, the phishing kit can just redirect to other hostnames, and the attacker’s can keep updating with new URLs over time. ",{"data":1669,"content":1670,"nodeType":1294},{},[1671],{"data":1672,"marks":1673,"value":1674,"nodeType":1293},{},[],"Below we can see an example of the response containing a URL, with a JWT auth parameter:",{"data":1676,"content":1680,"nodeType":1377},{"target":1677},{"sys":1678},{"id":1679,"type":1374,"linkType":1375},"4NpH7V5oEdTASNNJsqCJ47",[],{"data":1682,"content":1686,"nodeType":1377},{"target":1683},{"sys":1684},{"id":1685,"type":1374,"linkType":1375},"7oqkrhNXtyOlJMEz0BZyLo",[],{"data":1688,"content":1689,"nodeType":1294},{},[1690],{"data":1691,"marks":1692,"value":1693,"nodeType":1293},{},[],"Automating this request in this example brings back around 20 different primary domains used for the final phishing attack. These domains are rotated over time as some are blocked and new ones are created.",{"data":1695,"content":1696,"nodeType":1392},{},[1697],{"data":1698,"marks":1699,"value":1700,"nodeType":1293},{},[],"Step 8: Breaking login page signatures",{"data":1702,"content":1703,"nodeType":1294},{},[1704],{"data":1705,"marks":1706,"value":1707,"nodeType":1293},{},[],"If all the previous checks have passed then a victim user is finally presented with a phishing page. The attacker has most closely emulated the sign-on page for live.com for Outlook in this case, though it also has some aspects from a business Microsoft login too, as we can see in the examples below:",{"data":1709,"content":1713,"nodeType":1377},{"target":1710},{"sys":1711},{"id":1712,"type":1374,"linkType":1375},"2Ez0fgAlmkrisdQGWfL6CV",[],{"data":1715,"content":1716,"nodeType":1294},{},[1717],{"data":1718,"marks":1719,"value":1720,"nodeType":1293},{},[],"However, one obvious change can be seen in the HTML title in the tab header. This normally says something like “Sign in to Outlook” or “Sign in to your account”. In this case, the phishing kit has randomized the HTML title. \n\nOne super easy way to detect websites pretending to be common login pages that have 1:1 cloned the website or are performing full reverse proxy AiTM techniques would be to search for obvious HTML content like this. Not many legitimate websites should have an HTML title of “Sign in to Outlook” other than Microsoft’s own legitimate domains for it, right?",{"data":1722,"content":1723,"nodeType":1294},{},[1724],{"data":1725,"marks":1726,"value":1727,"nodeType":1293},{},[],"Taking a closer look, we’ll see that the HTML, DOM and JavaScript etc. differ quite significantly from the true login pages, even if the visual appearance is very similar. One reason for this is to make it harder for defenders to simply signature on specific aspects of commonly spoofed login pages.",{"data":1729,"content":1730,"nodeType":1392},{},[1731],{"data":1732,"marks":1733,"value":1734,"nodeType":1293},{},[],"Step 9: B2B targeting",{"data":1736,"content":1737,"nodeType":1294},{},[1738],{"data":1739,"marks":1740,"value":1741,"nodeType":1293},{},[],"The final interesting aspect of this particular example is that it modifies its behavior during the login process depending on whether a personal Microsoft account or an organization account is used.",{"data":1743,"content":1744,"nodeType":1294},{},[1745,1749,1757],{"data":1746,"marks":1747,"value":1748,"nodeType":1293},{},[],"When entering an email address associated with a personal Microsoft account, or picking ‘personal account’ when prompted after entering an email address that is used for both purposes, the server will return a 302 redirect and send the user to ",{"data":1750,"content":1752,"nodeType":1337},{"uri":1751},"https://login.live.com/",[1753],{"data":1754,"marks":1755,"value":1751,"nodeType":1293},{},[1756],{"type":1335},{"data":1758,"marks":1759,"value":1760,"nodeType":1293},{},[]," where they can then re-enter their credentials and login to Microsoft legitimately if they continue. This reduces the potential for detection further as no AitM phishing login will actually occur.",{"data":1762,"content":1763,"nodeType":1294},{},[1764,1768,1774],{"data":1765,"marks":1766,"value":1767,"nodeType":1293},{},[],"On the other hand, when using an organization account the phishing process continues as expected. ",{"data":1769,"marks":1770,"value":1773,"nodeType":1293},{},[1771],{"type":1772},"bold","This phishing campaign is exclusively targeting corp accounts",{"data":1775,"marks":1776,"value":1777,"nodeType":1293},{},[]," and you could almost say it has a B2B (or is that A2B?) rather than B2C business model.  ",{"data":1779,"content":1780,"nodeType":1392},{},[1781],{"data":1782,"marks":1783,"value":1784,"nodeType":1293},{},[],"Conclusion",{"data":1786,"content":1787,"nodeType":1294},{},[1788],{"data":1789,"marks":1790,"value":1791,"nodeType":1293},{},[],"As you may have guessed from the extremely suspicious domains in use and examples of sloppy coding (like forgetting to implement an encryption function) the NakedPages kit is far from sophisticated. Despite this, the tricks that attackers are using to make detection and analysis more difficult seem to be quite effective when used in a layered model. ",{"data":1793,"content":1794,"nodeType":1294},{},[1795],{"data":1796,"marks":1797,"value":1798,"nodeType":1293},{},[],"For example, at the time of writing this particular Worker had been up for at least two days and was currently only triggering 1 detection on VirusTotal. ",{"data":1800,"content":1804,"nodeType":1377},{"target":1801},{"sys":1802},{"id":1803,"type":1374,"linkType":1375},"1mIOpDtmgcMasK6dEhRHsm",[],{"data":1806,"content":1807,"nodeType":1294},{},[1808],{"data":1809,"marks":1810,"value":1811,"nodeType":1293},{},[],"One key takeaway is that it’s near impossible to stay on top of all the phishing servers on the internet. Even the untargeted mass campaigns will initially be missed by TI feeds, let alone the targeted ones. ",{"data":1813,"content":1814,"nodeType":1294},{},[1815,1819,1827],{"data":1816,"marks":1817,"value":1818,"nodeType":1293},{},[],"The best foot forward for resilience against these attacks is through the use of domain-bound MFA methods like WebAuthn. Common MFA methods like OTPs, SMS, push notifications etc. are routinely bypassed using ",{"data":1820,"content":1821,"nodeType":1337},{"uri":1351},[1822],{"data":1823,"marks":1824,"value":1826,"nodeType":1293},{},[1825],{"type":1335},"AitM techniques that proxy the MFA authentication as well",{"data":1828,"marks":1829,"value":1830,"nodeType":1293},{},[],". Even if you are one of the few who use phishing-resistant MFA methods like WebAuthn or other passkeys, the devil is in the detail and we’ve seen MFA downgrade attacks being used to bypass them by choosing a phishable method that’s also active.",{"data":1832,"content":1836,"nodeType":1377},{"target":1833},{"sys":1834},{"id":1835,"type":1374,"linkType":1375},"17lSgRFD6fDzRUn9eOHJg6",[],{"data":1838,"content":1839,"nodeType":1392},{},[1840],{"data":1841,"marks":1842,"value":1843,"nodeType":1293},{},[],"P.S. How did we detect this?",{"data":1845,"content":1846,"nodeType":1294},{},[1847,1851,1856,1860,1869],{"data":1848,"marks":1849,"value":1850,"nodeType":1293},{},[],"After all that, you might be wondering how we managed to automate a process to generically pass through all these detection evasion techniques – ",{"data":1852,"marks":1853,"value":1855,"nodeType":1293},{},[1854],{"type":1772},"well the short answer is: We didn’t.",{"data":1857,"marks":1858,"value":1859,"nodeType":1293},{},[]," Instead, we detected the act of an employee ",{"data":1861,"content":1863,"nodeType":1337},{"uri":1862},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[1864],{"data":1865,"marks":1866,"value":1868,"nodeType":1293},{},[1867],{"type":1335},"attempting to put their Microsoft password into a website that wasn’t Microsoft",{"data":1870,"marks":1871,"value":1435,"nodeType":1293},{},[],{"data":1873,"content":1874,"nodeType":1294},{},[1875],{"data":1876,"marks":1877,"value":1878,"nodeType":1293},{},[],"The TTP for phishing is effectively “trick someone into putting their valid credentials into the wrong site” – so detecting that behavior directly (the action of entering a legit password into the wrong site) can be a lot simpler and more effective than playing the cat-and-mouse detection → detection-evasion game.",{"data":1880,"content":1881,"nodeType":1294},{},[1882],{"data":1883,"marks":1884,"value":1885,"nodeType":1293},{},[],"Having said that, if you’re interested, here are the domain IOCs for this campaign:",{"data":1887,"content":1888,"nodeType":1294},{},[1889],{"data":1890,"marks":1891,"value":1893,"nodeType":1293},{},[1892],{"type":1414},"226028cc[.]502f135e3e036e726fba22d4[.]workers[.]dev\nacevoorgukmembership[.]buzz\nalerteditorroyalsocietyorgnz[.]buzz\nandymarshallsgeniuslocidigestghostiomghostio[.]buzz\nblogresponseinsperitycom[.]buzz\ncampaigneventbritecomnoreply[.]buzz\ncharityexcellencer1technologytrustnewsorg[.]buzz\nclerkenwelldesignweekcomnoreply[.]buzz\nconfirminfothetrainlinecomauto[.]buzz\nhealthestatejournalcomnoreply[.]buzz\nmentalhealthdesignandbuildcomnoreply[.]buzz\nnoreplynotificationswhoopcom[.]buzz\nstepexhibitionscomeventsupport[.]buzz\ntheathletice1theathleticcom[.]buzz\nthekakahoonssubstackcom[.]buzz","How AitM phishing kits evade detection","Taking a closer look at the steps that AitM phishing kits take to hide from the prying eyes of security teams and threat intelligence vendors.","2024-07-23T00:00:00.000Z","how-aitm-phishing-kits-evade-detection",{"items":1899},[1900,1902],{"sys":1901,"name":1309},{"id":1308},{"sys":1903,"name":1305},{"id":1304},{"items":1905},[1906],{"fullName":1907,"firstName":1908,"jobTitle":1909,"profilePicture":1910},"Luke Jennings","Luke","Vice President, R&D",{"url":1911},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"__typename":1313,"sys":1913,"content":1915,"title":2427,"synopsis":2428,"hashTags":118,"publishedDate":2429,"slug":2430,"tagsCollection":2431,"authorsCollection":2439},{"id":1914},"6Uvqu6LcWzOVfA9mxtu841",{"json":1916},{"nodeType":1295,"data":1917,"content":1918},{},[1919,1925,1932,1967,1974,1994,2001,2047,2054,2061,2068,2074,2081,2171,2178,2185,2208,2215,2222,2229,2236,2243,2250,2301,2308,2314,2332,2338,2345,2365,2372,2379,2386,2393,2400,2407],{"nodeType":1377,"data":1920,"content":1924},{"target":1921},{"sys":1922},{"id":1923,"type":1374,"linkType":1375},"2HffP4X7owzpfj41jnzXmV",[],{"nodeType":1294,"data":1926,"content":1927},{},[1928],{"nodeType":1293,"value":1929,"marks":1930,"data":1931},"To detect session token theft, you need three things:",[],{},{"nodeType":1933,"data":1934,"content":1935},"unordered-list",{},[1936,1947,1957],{"nodeType":1937,"data":1938,"content":1939},"list-item",{},[1940],{"nodeType":1294,"data":1941,"content":1942},{},[1943],{"nodeType":1293,"value":1944,"marks":1945,"data":1946},"Robust logs that provide an identifier to help tie activity to a specific session",[],{},{"nodeType":1937,"data":1948,"content":1949},{},[1950],{"nodeType":1294,"data":1951,"content":1952},{},[1953],{"nodeType":1293,"value":1954,"marks":1955,"data":1956},"A well-oiled SOC to correlate observed activity in those logs",[],{},{"nodeType":1937,"data":1958,"content":1959},{},[1960],{"nodeType":1294,"data":1961,"content":1962},{},[1963],{"nodeType":1293,"value":1964,"marks":1965,"data":1966},"And telemetry to tie those logs to a trusted endpoint",[],{},{"nodeType":1294,"data":1968,"content":1969},{},[1970],{"nodeType":1293,"value":1971,"marks":1972,"data":1973},"The only problem? That third thing didn’t really exist. So we created it.",[],{},{"nodeType":1294,"data":1975,"content":1976},{},[1977,1981,1990],{"nodeType":1293,"value":1978,"marks":1979,"data":1980},"In this article, we’ll cover how Push’s recently released ",[],{},{"nodeType":1337,"data":1982,"content":1984},{"uri":1983},"https://pushsecurity.com/help/10114#start",[1985],{"nodeType":1293,"value":1986,"marks":1987,"data":1989},"session theft detection",[1988],{"type":1335},{},{"nodeType":1293,"value":1991,"marks":1992,"data":1993}," feature works, why we built it, and why the unique control point provided by a browser agent unlocks new capabilities for blue teams fighting the effects of infostealer malware and other stolen credential-based attacks.",[],{},{"nodeType":1392,"data":1995,"content":1996},{},[1997],{"nodeType":1293,"value":1998,"marks":1999,"data":2000},"(You probably already know) Why this matters",[],{},{"nodeType":1294,"data":2002,"content":2003},{},[2004,2008,2017,2021,2030,2034,2043],{"nodeType":1293,"value":2005,"marks":2006,"data":2007},"Session token theft is a ",[],{},{"nodeType":1337,"data":2009,"content":2011},{"uri":2010},"https://owasp.org/www-community/attacks/Session_hijacking_attack",[2012],{"nodeType":1293,"value":2013,"marks":2014,"data":2016},"session hijacking",[2015],{"type":1335},{},{"nodeType":1293,"value":2018,"marks":2019,"data":2020}," technique where endpoint malware is used to extract sessions from an endpoint, and until recently it was ",[],{},{"nodeType":1337,"data":2022,"content":2024},{"uri":2023},"https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/",[2025],{"nodeType":1293,"value":2026,"marks":2027,"data":2029},"relatively rare",[2028],{"type":1335},{},{"nodeType":1293,"value":2031,"marks":2032,"data":2033},". It’s easier to ",[],{},{"nodeType":1337,"data":2035,"content":2037},{"uri":2036},"https://pushsecurity.com/blog/what-is-credential-stuffing/",[2038],{"nodeType":1293,"value":2039,"marks":2040,"data":2042},"gain access via a password",[2041],{"type":1335},{},{"nodeType":1293,"value":2044,"marks":2045,"data":2046}," than it is to steal a session cookie. ",[],{},{"nodeType":1294,"data":2048,"content":2049},{},[2050],{"nodeType":1293,"value":2051,"marks":2052,"data":2053},"But there’s an inverse relationship between session-based attacks and MFA adoption. As MFA becomes widespread, adversaries turn to new effective methods of initial entry.",[],{},{"nodeType":1294,"data":2055,"content":2056},{},[2057],{"nodeType":1293,"value":2058,"marks":2059,"data":2060},"An increasingly common approach involves the use of infostealer malware, which can extract saved credentials, browser cookies, cryptowallets, and other valuable data from the infected endpoint.",[],{},{"nodeType":1294,"data":2062,"content":2063},{},[2064],{"nodeType":1293,"value":2065,"marks":2066,"data":2067},"Using stolen tokens, adversaries don’t need to bypass MFA directly. They can simply import the tokens into their browser and assume an already authorized session.",[],{},{"nodeType":1377,"data":2069,"content":2073},{"target":2070},{"sys":2071},{"id":2072,"type":1374,"linkType":1375},"66B5MBFIhbmky7VuLGbuM3",[],{"nodeType":1294,"data":2075,"content":2076},{},[2077],{"nodeType":1293,"value":2078,"marks":2079,"data":2080},"A few recent stats show the scope of the problem:",[],{},{"nodeType":1933,"data":2082,"content":2083},{},[2084,2106,2128,2150],{"nodeType":1937,"data":2085,"content":2086},{},[2087],{"nodeType":1294,"data":2088,"content":2089},{},[2090,2094,2103],{"nodeType":1293,"value":2091,"marks":2092,"data":2093},"Nearly half of the malware detected last year by Sophos targeted victims’ data specifically, and the majority of that malware was classified as infostealers. Source: ",[],{},{"nodeType":1337,"data":2095,"content":2097},{"uri":2096},"https://news.sophos.com/en-us/2024/03/12/2024-sophos-threat-report/",[2098],{"nodeType":1293,"value":2099,"marks":2100,"data":2102},"2024 Sophos Threat Report",[2101],{"type":1335},{},{"nodeType":1293,"value":37,"marks":2104,"data":2105},[],{},{"nodeType":1937,"data":2107,"content":2108},{},[2109],{"nodeType":1294,"data":2110,"content":2111},{},[2112,2116,2125],{"nodeType":1293,"value":2113,"marks":2114,"data":2115},"Information-stealing malware accounted for nearly 10 percent of activity that Red Canary was able to associate with named threats last year. They also found a rise in stealer malware targeting macOS compared to previous years. Source: ",[],{},{"nodeType":1337,"data":2117,"content":2119},{"uri":2118},"https://redcanary.com/threat-detection-report/trends/info-stealers/",[2120],{"nodeType":1293,"value":2121,"marks":2122,"data":2124},"2024 Red Canary Threat Detection Report",[2123],{"type":1335},{},{"nodeType":1293,"value":37,"marks":2126,"data":2127},[],{},{"nodeType":1937,"data":2129,"content":2130},{},[2131],{"nodeType":1294,"data":2132,"content":2133},{},[2134,2138,2147],{"nodeType":1293,"value":2135,"marks":2136,"data":2137},"Stolen credentials continued to rank as the top initial access method for breaches analyzed by Verizon. Source: ",[],{},{"nodeType":1337,"data":2139,"content":2141},{"uri":2140},"https://www.verizon.com/business/resources/reports/dbir/",[2142],{"nodeType":1293,"value":2143,"marks":2144,"data":2146},"2024 Data Breach Investigations Report",[2145],{"type":1335},{},{"nodeType":1293,"value":37,"marks":2148,"data":2149},[],{},{"nodeType":1937,"data":2151,"content":2152},{},[2153],{"nodeType":1294,"data":2154,"content":2155},{},[2156,2160,2168],{"nodeType":1293,"value":2157,"marks":2158,"data":2159},"The number of token replay attacks is increasing, with Microsoft detecting 147,000 attacks in 2023, a 111% increase year-over-year. Source: ",[],{},{"nodeType":1337,"data":2161,"content":2163},{"uri":2162},"https://techcommunity.microsoft.com/t5/microsoft-entra-blog/how-to-break-the-token-theft-cyber-attack-chain/ba-p/4062700",[2164],{"nodeType":1293,"value":2165,"marks":2166,"data":2167},"Microsoft Blog",[],{},{"nodeType":1293,"value":37,"marks":2169,"data":2170},[],{},{"nodeType":1392,"data":2172,"content":2173},{},[2174],{"nodeType":1293,"value":2175,"marks":2176,"data":2177},"What's missing from current defenses",[],{},{"nodeType":1294,"data":2179,"content":2180},{},[2181],{"nodeType":1293,"value":2182,"marks":2183,"data":2184},"When defending against infostealer malware or other forms of session and credential theft, there are a few common challenges that organizations may face:",[],{},{"nodeType":1933,"data":2186,"content":2187},{},[2188,2198],{"nodeType":1937,"data":2189,"content":2190},{},[2191],{"nodeType":1294,"data":2192,"content":2193},{},[2194],{"nodeType":1293,"value":2195,"marks":2196,"data":2197},"Their endpoint security tooling doesn’t provide complete coverage across their device fleet, though they thought it did.",[],{},{"nodeType":1937,"data":2199,"content":2200},{},[2201],{"nodeType":1294,"data":2202,"content":2203},{},[2204],{"nodeType":1293,"value":2205,"marks":2206,"data":2207},"The malware is good enough to evade EDR detection, or it was able to execute and exfiltrate sessions or other data before it was stopped.",[],{},{"nodeType":1294,"data":2209,"content":2210},{},[2211],{"nodeType":1293,"value":2212,"marks":2213,"data":2214},"Existing approaches to detecting stolen sessions also pose a noisy problem. Relying on IP-based or geolocation-based signals can result in frequent false positives. (And not all identity provider logs include a session identifier that you can use to perform correlations in the first place.)",[],{},{"nodeType":1294,"data":2216,"content":2217},{},[2218],{"nodeType":1293,"value":2219,"marks":2220,"data":2221},"The missing piece is a trusted signal for legitimate sessions that you can use to correlate with other data in order to identify unexpected activity that indicates a compromised identity and device.",[],{},{"nodeType":1392,"data":2223,"content":2224},{},[2225],{"nodeType":1293,"value":2226,"marks":2227,"data":2228},"Generating unique telemetry via the browser",[],{},{"nodeType":1294,"data":2230,"content":2231},{},[2232],{"nodeType":1293,"value":2233,"marks":2234,"data":2235},"Push’s solution to detecting stolen sessions falls into the category of “so simple, why didn’t this already exist?”",[],{},{"nodeType":1294,"data":2237,"content":2238},{},[2239],{"nodeType":1293,"value":2240,"marks":2241,"data":2242},"The answer: Because you need to be in the browser to do it. The Push browser agent sits in a unique position that we can leverage to provide telemetry that otherwise would be extremely difficult to create.",[],{},{"nodeType":1294,"data":2244,"content":2245},{},[2246],{"nodeType":1293,"value":2247,"marks":2248,"data":2249},"Here’s how it works:",[],{},{"nodeType":1933,"data":2251,"content":2252},{},[2253,2263,2273],{"nodeType":1937,"data":2254,"content":2255},{},[2256],{"nodeType":1294,"data":2257,"content":2258},{},[2259],{"nodeType":1293,"value":2260,"marks":2261,"data":2262},"Via the Push browser agent, Push injects a unique marker into the user agent string of sessions that occur in browsers enrolled in Push.",[],{},{"nodeType":1937,"data":2264,"content":2265},{},[2266],{"nodeType":1294,"data":2267,"content":2268},{},[2269],{"nodeType":1293,"value":2270,"marks":2271,"data":2272},"Administrators then add the list of domains where they wish to inject the marker into sessions, such as an identity provider like Okta or Microsoft.",[],{},{"nodeType":1937,"data":2274,"content":2275},{},[2276],{"nodeType":1294,"data":2277,"content":2278},{},[2279,2283,2288,2292,2297],{"nodeType":1293,"value":2280,"marks":2281,"data":2282},"By analyzing logs from the IdP, you can identify activity from the same session that both ",[],{},{"nodeType":1293,"value":2284,"marks":2285,"data":2287},"has",[2286],{"type":312},{},{"nodeType":1293,"value":2289,"marks":2290,"data":2291}," the Push marker and that ",[],{},{"nodeType":1293,"value":2293,"marks":2294,"data":2296},"lacks",[2295],{"type":312},{},{"nodeType":1293,"value":2298,"marks":2299,"data":2300}," the marker. This can only ever happen when a session is extracted from a browser and maliciously imported into a different browser.",[],{},{"nodeType":1294,"data":2302,"content":2303},{},[2304],{"nodeType":1293,"value":2305,"marks":2306,"data":2307},"This is a high-fidelity signal that a stolen session token is in use.",[],{},{"nodeType":1377,"data":2309,"content":2313},{"target":2310},{"sys":2311},{"id":2312,"type":1374,"linkType":1375},"3zQamWSaZFIbMUhQZtM2II",[],{"nodeType":1294,"data":2315,"content":2316},{},[2317,2321,2329],{"nodeType":1293,"value":2318,"marks":2319,"data":2320},"Learn more about configuring this feature in our ",[],{},{"nodeType":1337,"data":2322,"content":2323},{"uri":1983},[2324],{"nodeType":1293,"value":2325,"marks":2326,"data":2328},"Help Center",[2327],{"type":1335},{},{"nodeType":1293,"value":1435,"marks":2330,"data":2331},[],{},{"nodeType":1377,"data":2333,"content":2337},{"target":2334},{"sys":2335},{"id":2336,"type":1374,"linkType":1375},"35dpGqNY6cTM0fSQRflLiO",[],{"nodeType":1392,"data":2339,"content":2340},{},[2341],{"nodeType":1293,"value":2342,"marks":2343,"data":2344},"Unlocking new capabilities for blue teams",[],{},{"nodeType":1294,"data":2346,"content":2347},{},[2348,2352,2361],{"nodeType":1293,"value":2349,"marks":2350,"data":2351},"As we’ve said before, we see browser telemetry and browser-based controls as the ",[],{},{"nodeType":1337,"data":2353,"content":2355},{"uri":2354},"https://pushsecurity.com/blog/what-is-itdr-identity-threat-detection-response/",[2356],{"nodeType":1293,"value":2357,"marks":2358,"data":2360},"missing piece",[2359],{"type":1335},{},{"nodeType":1293,"value":2362,"marks":2363,"data":2364}," in security strategies to stop identity attacks — particularly for modern organizations with complex identity ecosystems that span IdPs, SaaS apps, OAuth-connected apps, and more.",[],{},{"nodeType":1294,"data":2366,"content":2367},{},[2368],{"nodeType":1293,"value":2369,"marks":2370,"data":2371},"Where the browser agent approach particularly shines is that it’s application-agnostic. ",[],{},{"nodeType":1294,"data":2373,"content":2374},{},[2375],{"nodeType":1293,"value":2376,"marks":2377,"data":2378},"As long as the app you want to monitor provides robust logs, you can inject the Push-supplied marker into any session on any app. ",[],{},{"nodeType":1294,"data":2380,"content":2381},{},[2382],{"nodeType":1293,"value":2383,"marks":2384,"data":2385},"This allows you to detect suspicious activity even on internal corporate assets, such as an intranet. ",[],{},{"nodeType":1294,"data":2387,"content":2388},{},[2389],{"nodeType":1293,"value":2390,"marks":2391,"data":2392},"A tidy side effect is that you can also use this feature to identify unmanaged devices accessing sensitive corporate internal resources because they will lack the Push browser agent-supplied marker.",[],{},{"nodeType":1294,"data":2394,"content":2395},{},[2396],{"nodeType":1293,"value":2397,"marks":2398,"data":2399},"There are probably a few other creative use cases for this feature, so we look forward to seeing what you come up with!",[],{},{"nodeType":1392,"data":2401,"content":2402},{},[2403],{"nodeType":1293,"value":2404,"marks":2405,"data":2406},"Find out more",[],{},{"nodeType":1294,"data":2408,"content":2409},{},[2410,2414,2423],{"nodeType":1293,"value":2411,"marks":2412,"data":2413},"To see Push in action, ",[],{},{"nodeType":1337,"data":2415,"content":2417},{"uri":2416},"https://pushsecurity.com/demo/",[2418],{"nodeType":1293,"value":2419,"marks":2420,"data":2422},"book a demo",[2421],{"type":1335},{},{"nodeType":1293,"value":2424,"marks":2425,"data":2426},". We’ll be happy to show you this feature, along with how we discover all the apps your employees are using, even the ones not behind SSO, and how we detect vulnerable identities and stop identity attacks with browser-based controls.",[],{},"Introducing session token theft detection: Why browser is best","Push's browser agent identifies session token theft by adding telemetry to the user agent string to create a new high-fidelity signal for your security team.","2024-06-25T00:00:00.000Z","introducing-session-token-theft-detection-why-browser-is-best",{"items":2432},[2433,2435],{"sys":2434,"name":1309},{"id":1308},{"sys":2436,"name":2438},{"id":2437},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"items":2440},[2441],{"fullName":2442,"firstName":2443,"jobTitle":2444,"profilePicture":2445},"Kelly Davenport","Kelly","Product Team",{"url":2446},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1313,"sys":2448,"content":2450,"title":3288,"synopsis":3289,"hashTags":118,"publishedDate":3290,"slug":3291,"tagsCollection":3292,"authorsCollection":3298},{"id":2449},"174u87EYeKMKHzYYxBLlHO",{"json":2451},{"nodeType":1295,"data":2452,"content":2453},{},[2454,2461,2468,2475,2507,2514,2521,2539,2547,2554,2572,2579,2586,2593,2599,2606,2649,2656,2663,2670,2693,2700,2707,2714,2762,2769,2776,2783,2790,2802,2809,2817,2824,2857,2864,2871,2878,2885,2955,2963,2970,2977,3011,3018,3026,3033,3040,3052,3068,3101,3120,3127,3146,3153,3160,3178,3185,3192,3199,3232,3239,3258,3276,3282],{"nodeType":1294,"data":2455,"content":2456},{},[2457],{"nodeType":1293,"value":2458,"marks":2459,"data":2460},"Identity attacks like phishing, credential stuffing, and session hijacking are now the leading cause of cyber security breaches, as attackers shift their attention to the sprawl of third-party applications and services that has become the backbone of business IT. ",[],{},{"nodeType":1294,"data":2462,"content":2463},{},[2464],{"nodeType":1293,"value":2465,"marks":2466,"data":2467},"The attacker’s goal in these attacks is account takeover: logging into a user account to access your company app tenant. From there, the attacker can usually achieve all of their objectives from inside the compromised app, usually involving dumping sensitive data with which to hold the company to ransom, or selling the data on underground criminal marketplaces. ",[],{},{"nodeType":1294,"data":2469,"content":2470},{},[2471],{"nodeType":1293,"value":2472,"marks":2473,"data":2474},"These attack techniques have been commonplace for over a decade — but the shift in attack context away from attacking endpoints (user devices and servers) to cloud services is seeing something of an identity attack renaissance. ",[],{},{"nodeType":1294,"data":2476,"content":2477},{},[2478,2481,2490,2494,2503],{"nodeType":1293,"value":37,"marks":2479,"data":2480},[],{},{"nodeType":1337,"data":2482,"content":2484},{"uri":2483},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[2485],{"nodeType":1293,"value":2486,"marks":2487,"data":2489},"Ghost logins",[2488],{"type":1335},{},{"nodeType":1293,"value":2491,"marks":2492,"data":2493}," are one of the leading factors in successful ",[],{},{"nodeType":1337,"data":2495,"content":2497},{"uri":2496},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/credential_stuffing/description.md",[2498],{"nodeType":1293,"value":2499,"marks":2500,"data":2502},"credential stuffing",[2501],{"type":1335},{},{"nodeType":1293,"value":2504,"marks":2505,"data":2506}," attacks driving account takeover.",[],{},{"nodeType":1392,"data":2508,"content":2509},{},[2510],{"nodeType":1293,"value":2511,"marks":2512,"data":2513},"Ghost logins 101",[],{},{"nodeType":1294,"data":2515,"content":2516},{},[2517],{"nodeType":1293,"value":2518,"marks":2519,"data":2520},"Simply put, ghost logins are often-forgotten alternative login methods that are tricky for security teams to manage and secure — because they don’t know about them. Because of this, they’re likely to possess weak configurations that make them susceptible to account takeover attacks. ",[],{},{"nodeType":1294,"data":2522,"content":2523},{},[2524,2528,2536],{"nodeType":1293,"value":2525,"marks":2526,"data":2527},"We found that ",[],{},{"nodeType":1337,"data":2529,"content":2531},{"uri":2530},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[2532],{"nodeType":1293,"value":2533,"marks":2534,"data":2535},"ghost logins are present in ~10% of the accounts per organization",[],{},{"nodeType":1293,"value":1502,"marks":2537,"data":2538},[],{},{"nodeType":2540,"data":2541,"content":2542},"heading-2",{},[2543],{"nodeType":1293,"value":2544,"marks":2545,"data":2546},"Why do ghost logins exist?",[],{},{"nodeType":1294,"data":2548,"content":2549},{},[2550],{"nodeType":1293,"value":2551,"marks":2552,"data":2553},"Identity management used to be something that was centrally contained and managed using an enterprise identity service like Active Directory. Most users probably only had one or two identities that you really cared about: the one they used to log into their company laptop and domain, and maybe also to log into a VPN. ",[],{},{"nodeType":1294,"data":2555,"content":2556},{},[2557,2561,2568],{"nodeType":1293,"value":2558,"marks":2559,"data":2560},"Now, there are ",[],{},{"nodeType":1337,"data":2562,"content":2563},{"uri":2530},[2564],{"nodeType":1293,"value":2565,"marks":2566,"data":2567},"200+ business apps in use per company, creating 1000s of sprawled identities",[],{},{"nodeType":1293,"value":2569,"marks":2570,"data":2571}," across an ecosystem of business apps and services accessed over the internet.",[],{},{"nodeType":1294,"data":2573,"content":2574},{},[2575],{"nodeType":1293,"value":2576,"marks":2577,"data":2578},"Most businesses have tried to solve this problem with single sign on (SSO). The logic being that if you can use a single set of credentials (and therefore, a single identity) to access all of your business apps, and then secure those credentials with MFA, then this problem goes away. However…",[],{},{"nodeType":2540,"data":2580,"content":2581},{},[2582],{"nodeType":1293,"value":2583,"marks":2584,"data":2585},"SSO expectations versus reality",[],{},{"nodeType":1294,"data":2587,"content":2588},{},[2589],{"nodeType":1293,"value":2590,"marks":2591,"data":2592},"Unfortunately, the reality of SSO implementation is flawed. Most apps accept multiple login methods that can be configured — and used — simultaneously (yes, most apps don’t have proper session controls).  ",[],{},{"nodeType":1377,"data":2594,"content":2598},{"target":2595},{"sys":2596},{"id":2597,"type":1374,"linkType":1375},"3sOz3HkiyJpY9nFtGCWEOV",[],{"nodeType":1294,"data":2600,"content":2601},{},[2602],{"nodeType":1293,"value":2603,"marks":2604,"data":2605},"This is made worse by the fact that:",[],{},{"nodeType":1933,"data":2607,"content":2608},{},[2609,2619,2629,2639],{"nodeType":1937,"data":2610,"content":2611},{},[2612],{"nodeType":1294,"data":2613,"content":2614},{},[2615],{"nodeType":1293,"value":2616,"marks":2617,"data":2618},"Most apps can't be locked down to restrict which login methods are accepted.",[],{},{"nodeType":1937,"data":2620,"content":2621},{},[2622],{"nodeType":1294,"data":2623,"content":2624},{},[2625],{"nodeType":1293,"value":2626,"marks":2627,"data":2628},"Users often self-adopt apps, and default to a username and password (and typically miss out MFA). ",[],{},{"nodeType":1937,"data":2630,"content":2631},{},[2632],{"nodeType":1294,"data":2633,"content":2634},{},[2635],{"nodeType":1293,"value":2636,"marks":2637,"data":2638},"SSO isn’t always possible if you aren’t using a supported IdP — and only one in three apps support SAML, the preferred enterprise-grade protocol.",[],{},{"nodeType":1937,"data":2640,"content":2641},{},[2642],{"nodeType":1294,"data":2643,"content":2644},{},[2645],{"nodeType":1293,"value":2646,"marks":2647,"data":2648},"Even where SSO is possible, configuring an app for SSO doesn't automatically delete any legacy local logins.",[],{},{"nodeType":1294,"data":2650,"content":2651},{},[2652],{"nodeType":1293,"value":2653,"marks":2654,"data":2655},"Inevitably, this means that there are many situations in which users will create local accounts — typically with a username and password, and without MFA. This is how ghost logins are born.",[],{},{"nodeType":2540,"data":2657,"content":2658},{},[2659],{"nodeType":1293,"value":2660,"marks":2661,"data":2662},"How are ghost logins created? ",[],{},{"nodeType":1294,"data":2664,"content":2665},{},[2666],{"nodeType":1293,"value":2667,"marks":2668,"data":2669},"Ghost logins can be created in the following ways:",[],{},{"nodeType":1933,"data":2671,"content":2672},{},[2673,2683],{"nodeType":1937,"data":2674,"content":2675},{},[2676],{"nodeType":1294,"data":2677,"content":2678},{},[2679],{"nodeType":1293,"value":2680,"marks":2681,"data":2682},"A user self-adopts an app, setting up an account with a local username and password. The app is later adopted companywide and brought under SSO. This creates an additional SSO login method, likely as the default, but the local login will continue to exist unless explicitly disabled or deleted. ",[],{},{"nodeType":1937,"data":2684,"content":2685},{},[2686],{"nodeType":1294,"data":2687,"content":2688},{},[2689],{"nodeType":1293,"value":2690,"marks":2691,"data":2692},"Secondary/backup login methods can often be added later in the app settings after logging in. This includes things like setting up a secondary email to send a login link to, or setting up API access to remove the need to authenticate altogether. ",[],{},{"nodeType":1294,"data":2694,"content":2695},{},[2696],{"nodeType":1293,"value":2697,"marks":2698,"data":2699},"So, ghost logins are very easily introduced through the normal course of app adoption and use by employees. ",[],{},{"nodeType":2540,"data":2701,"content":2702},{},[2703],{"nodeType":1293,"value":2704,"marks":2705,"data":2706},"Why do ghost logins pose a risk? ",[],{},{"nodeType":1294,"data":2708,"content":2709},{},[2710],{"nodeType":1293,"value":2711,"marks":2712,"data":2713},"Ghost logins pose a risk for a number of reasons, as they: ",[],{},{"nodeType":1933,"data":2715,"content":2716},{},[2717,2732,2747],{"nodeType":1937,"data":2718,"content":2719},{},[2720],{"nodeType":1294,"data":2721,"content":2722},{},[2723,2728],{"nodeType":1293,"value":2724,"marks":2725,"data":2727},"Typically have less secure configurations ",[2726],{"type":1772},{},{"nodeType":1293,"value":2729,"marks":2730,"data":2731},"than your preferred login method – and may be missing key controls like MFA.  ",[],{},{"nodeType":1937,"data":2733,"content":2734},{},[2735],{"nodeType":1294,"data":2736,"content":2737},{},[2738,2743],{"nodeType":1293,"value":2739,"marks":2740,"data":2742},"Are effectively shadow logins",[2741],{"type":1772},{},{"nodeType":1293,"value":2744,"marks":2745,"data":2746}," – IT/security don’t know about them, and if using an IdP as your primary identity security interface, they won’t necessarily be visible without taking a deeper look at individual apps. ",[],{},{"nodeType":1937,"data":2748,"content":2749},{},[2750],{"nodeType":1294,"data":2751,"content":2752},{},[2753,2758],{"nodeType":1293,"value":2754,"marks":2755,"data":2757},"Can be used simultaneously with SSO",[2756],{"type":1772},{},{"nodeType":1293,"value":2759,"marks":2760,"data":2761}," – so you can have an unrestricted number of concurrent sessions with SSO and non SSO logins active at the same time, without the user being kicked out of the previous session.",[],{},{"nodeType":1294,"data":2763,"content":2764},{},[2765],{"nodeType":1293,"value":2766,"marks":2767,"data":2768},"Ghost logins provide opportunities for attackers to bypass security controls for initial access and persistence in an application (which we’ll come onto in more detail later). They also provide an opportunity for malicious insiders, e.g. a disgruntled employee, to access systems even after SSO access is revoked. If the security team relies on IdP logs to audit app logins, these accounts can go undetected.",[],{},{"nodeType":1294,"data":2770,"content":2771},{},[2772],{"nodeType":1293,"value":2773,"marks":2774,"data":2775},"To be able to identify them, you’d need to log into the app admin dashboard. But depending on how the app was adopted, you (as a security admin) may not even be an app-level admin — it’s not unusual for individual teams to administer their own apps. And even if you do have access, it’s not always easy (or possible) to gather this level of information about user account configuration. ",[],{},{"nodeType":1294,"data":2777,"content":2778},{},[2779],{"nodeType":1293,"value":2780,"marks":2781,"data":2782},"It’s very easy to see how these vulnerable login methods can be overlooked by security teams – let’s look at how they can be identified and exploited by attackers. ",[],{},{"nodeType":1392,"data":2784,"content":2785},{},[2786],{"nodeType":1293,"value":2787,"marks":2788,"data":2789},"How can ghost logins be exploited by attackers?",[],{},{"nodeType":1294,"data":2791,"content":2792},{},[2793,2798],{"nodeType":1293,"value":2794,"marks":2795,"data":2797},"Let’s take an example scenario:",[2796],{"type":1772},{},{"nodeType":1293,"value":2799,"marks":2800,"data":2801}," You’re using an IdP solution like Okta or Microsoft/Entra with SAML SSO as the default login method for your core business apps. Via your IdP you require MFA when authenticating to your IdP apps page, and also potentially when signing into an individual connected app. ",[],{},{"nodeType":1294,"data":2803,"content":2804},{},[2805],{"nodeType":1293,"value":2806,"marks":2807,"data":2808},"However, you only recently introduced your IdP solution, and your users previously accessed this app with a local username and password. Although you asked your users to configure MFA in the app itself, not all of them did. And when you deployed your IdP solution, you didn’t manually unset all the local password-based logins for the apps you connected to it. ",[],{},{"nodeType":1294,"data":2810,"content":2811},{},[2812],{"nodeType":1293,"value":2813,"marks":2814,"data":2816},"Unknown to you, there are now hundreds of local accounts for core business apps which lack MFA. ",[2815],{"type":1772},{},{"nodeType":1294,"data":2818,"content":2819},{},[2820],{"nodeType":1293,"value":2821,"marks":2822,"data":2823},"There are two main scenarios in which ghost logins can be utilized by an attacker:",[],{},{"nodeType":1933,"data":2825,"content":2826},{},[2827,2842],{"nodeType":1937,"data":2828,"content":2829},{},[2830],{"nodeType":1294,"data":2831,"content":2832},{},[2833,2838],{"nodeType":1293,"value":2834,"marks":2835,"data":2837},"To bypass robustly configured login methods",[2836],{"type":1772},{},{"nodeType":1293,"value":2839,"marks":2840,"data":2841}," such as SSO to compromise an app identity during the initial access phase of an attack. ",[],{},{"nodeType":1937,"data":2843,"content":2844},{},[2845],{"nodeType":1294,"data":2846,"content":2847},{},[2848,2853],{"nodeType":1293,"value":2849,"marks":2850,"data":2852},"To create additional login methods for an already compromised account to ensure persistent access",[2851],{"type":1772},{},{"nodeType":1293,"value":2854,"marks":2855,"data":2856}," – even if the original compromised login method is revoked or disabled. This could be either the result of compromising an identity belonging to a specific app, or having previously compromised an IdP account (e.g. Okta).",[],{},{"nodeType":1294,"data":2858,"content":2859},{},[2860],{"nodeType":1293,"value":2861,"marks":2862,"data":2863},"Let's look at these use cases in more detail. ",[],{},{"nodeType":2540,"data":2865,"content":2866},{},[2867],{"nodeType":1293,"value":2868,"marks":2869,"data":2870},"Ghost logins for initial access",[],{},{"nodeType":1294,"data":2872,"content":2873},{},[2874],{"nodeType":1293,"value":2875,"marks":2876,"data":2877},"Arguably the most dangerous use case for ghost logins is to conduct credential attacks against accounts using a username and password. Logins with a weak or guessable password, or a reused password that has appeared in a public data breach dump, are primed for account takeover. ",[],{},{"nodeType":1294,"data":2879,"content":2880},{},[2881],{"nodeType":1293,"value":2882,"marks":2883,"data":2884},"The cyber crime ecosystem is leaning toward the theft, sale, and use of stolen credentials (not just emails and passwords, but session tokens too). ",[],{},{"nodeType":1933,"data":2886,"content":2887},{},[2888,2911,2933],{"nodeType":1937,"data":2889,"content":2890},{},[2891],{"nodeType":1294,"data":2892,"content":2893},{},[2894,2898,2907],{"nodeType":1293,"value":2895,"marks":2896,"data":2897},"There are 600 million identity attacks per day, with 99% involving passwords (",[],{},{"nodeType":1337,"data":2899,"content":2901},{"uri":2900},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf",[2902],{"nodeType":1293,"value":2903,"marks":2904,"data":2906},"Microsoft",[2905],{"type":1335},{},{"nodeType":1293,"value":2908,"marks":2909,"data":2910},").",[],{},{"nodeType":1937,"data":2912,"content":2913},{},[2914],{"nodeType":1294,"data":2915,"content":2916},{},[2917,2921,2930],{"nodeType":1293,"value":2918,"marks":2919,"data":2920},"Over 1000 credentials are posted online per day, per marketplace with an average sale price of $10, and 65% posted less than one day after being collected (",[],{},{"nodeType":1337,"data":2922,"content":2924},{"uri":2923},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[2925],{"nodeType":1293,"value":2926,"marks":2927,"data":2929},"Verizon",[2928],{"type":1335},{},{"nodeType":1293,"value":2908,"marks":2931,"data":2932},[],{},{"nodeType":1937,"data":2934,"content":2935},{},[2936],{"nodeType":1294,"data":2937,"content":2938},{},[2939,2943,2952],{"nodeType":1293,"value":2940,"marks":2941,"data":2942},"One million new stealer logs are distributed every month, with an estimated 3-5% containing credentials and session cookies to corporate IT environments (",[],{},{"nodeType":1337,"data":2944,"content":2946},{"uri":2945},"https://www.bleepingcomputer.com/news/security/single-sign-on-and-the-cybercrime-ecosystem/",[2947],{"nodeType":1293,"value":2948,"marks":2949,"data":2951},"Flare",[2950],{"type":1335},{},{"nodeType":1293,"value":2908,"marks":2953,"data":2954},[],{},{"nodeType":1294,"data":2956,"content":2957},{},[2958],{"nodeType":1293,"value":2959,"marks":2960,"data":2962},"So, it’s easier than ever for attackers to gather breached credentials and weaponize them at scale. ",[2961],{"type":1772},{},{"nodeType":1294,"data":2964,"content":2965},{},[2966],{"nodeType":1293,"value":2967,"marks":2968,"data":2969},"Realistically, any username and password combination for addresses belonging to a specific organization/domain can be attempted on any app. Breached credential data will often provide a strong indicator of other apps also in use for that organization. And for apps with a custom tenant URL (that cannot be easily guessed) data dumps often helpfully include the URLs for those login pages, too.  ",[],{},{"nodeType":1294,"data":2971,"content":2972},{},[2973],{"nodeType":1293,"value":2974,"marks":2975,"data":2976},"The risk posed by the massive amounts of leaked credentials available is heightened because: ",[],{},{"nodeType":1933,"data":2978,"content":2979},{},[2980,3001],{"nodeType":1937,"data":2981,"content":2982},{},[2983],{"nodeType":1294,"data":2984,"content":2985},{},[2986,2990,2997],{"nodeType":1293,"value":2987,"marks":2988,"data":2989},"Many employees reuse passwords, with ",[],{},{"nodeType":1337,"data":2991,"content":2992},{"uri":2530},[2993],{"nodeType":1293,"value":2994,"marks":2995,"data":2996},"~9% of all accounts using a breached, weak, or reused password",[],{},{"nodeType":1293,"value":2998,"marks":2999,"data":3000},". This isn’t just for low-risk apps either, and includes the reuse of highly sensitive IdP creds. ",[],{},{"nodeType":1937,"data":3002,"content":3003},{},[3004],{"nodeType":1294,"data":3005,"content":3006},{},[3007],{"nodeType":1293,"value":3008,"marks":3009,"data":3010},"Organizations don’t typically rotate or enforce changes to SaaS app passwords in the same way they might for company account/device login connected to Active Directory.  ",[],{},{"nodeType":1294,"data":3012,"content":3013},{},[3014],{"nodeType":1293,"value":3015,"marks":3016,"data":3017},"Ghost logins aren’t limited to just username and password either. For example, a breached social account such as Facebook or Google can result in a broader compromise if those accounts have been connected to any corporate apps.   ",[],{},{"nodeType":1294,"data":3019,"content":3020},{},[3021],{"nodeType":1293,"value":3022,"marks":3023,"data":3025},"So, exploiting ghost logins can be a highly effective method for attackers to gain initial access to a user account from which to launch further attacks.  ",[3024],{"type":1772},{},{"nodeType":2540,"data":3027,"content":3028},{},[3029],{"nodeType":1293,"value":3030,"marks":3031,"data":3032},"Ghost logins for persistence and defense evasion",[],{},{"nodeType":1294,"data":3034,"content":3035},{},[3036],{"nodeType":1293,"value":3037,"marks":3038,"data":3039},"Now, we’ll take a look at how attackers can leverage ghost logins as part of the later stages of an attack, having already established an initial foothold via account compromise. ",[],{},{"nodeType":1294,"data":3041,"content":3042},{},[3043,3047],{"nodeType":1293,"value":3044,"marks":3045,"data":3046},"If an organization has a reasonable level of security monitoring in-place (depending on log availability from the particular app vendor), or a victim receives a notification about an unusual login (e.g. from a new device or unusual IP) then access to an account can be short-lived. ",[],{},{"nodeType":1293,"value":3048,"marks":3049,"data":3051},"However, ghost logins can provide attackers with the tools to maintain persistent access to a compromised account, even if the initial compromised login method is disabled or revoked. ",[3050],{"type":1772},{},{"nodeType":1294,"data":3053,"content":3054},{},[3055,3059,3064],{"nodeType":1293,"value":3056,"marks":3057,"data":3058},"For example, if a social login is used to access an account, an adversary may be able to configure a separate username/password login, or even (though much less commonly) connect a second social account that the adversary controls. This allows the adversary to maintain persistent access to the user account ",[],{},{"nodeType":1293,"value":3060,"marks":3061,"data":3063},"even in the event of password changes or MFA changes",[3062],{"type":1772},{},{"nodeType":1293,"value":3065,"marks":3066,"data":3067},". The attack will go unnoticed if the victim organization relies on SSO logs for auditing access to SaaS applications because the attack bypasses SSO, as the login remains local to the SaaS app or, in the case of an OIDC SSO login, the adversary’s own social account.",[],{},{"nodeType":1294,"data":3069,"content":3070},{},[3071,3075,3084,3088,3097],{"nodeType":1293,"value":3072,"marks":3073,"data":3074},"Another quirk is that it’s common for ordinary users to become app-level admins when an app is self-adopted by an individual or team. If an attacker is able to gain control of such an account, it can then be used to target other users without needing to deliver phishing links by hijacking SAML-based authentication. In this scenario, users attempting to sign in using SAML SSO are directed it to an attacker-controlled tenant in a watering hole attack (also known as ",[],{},{"nodeType":1337,"data":3076,"content":3078},{"uri":3077},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/samljacking/description.md",[3079],{"nodeType":1293,"value":3080,"marks":3081,"data":3083},"SAMLjacking",[3082],{"type":1335},{},{"nodeType":1293,"value":3085,"marks":3086,"data":3087},", which you can ",[],{},{"nodeType":1337,"data":3089,"content":3091},{"uri":3090},"https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/",[3092],{"nodeType":1293,"value":3093,"marks":3094,"data":3096},"read more about in another blog post",[3095],{"type":1335},{},{"nodeType":1293,"value":3098,"marks":3099,"data":3100},"). ",[],{},{"nodeType":1294,"data":3102,"content":3103},{},[3104,3108,3116],{"nodeType":1293,"value":3105,"marks":3106,"data":3107},"If you're curious as to how an attacker might be able to compromise an IdP account such as Okta, ",[],{},{"nodeType":1337,"data":3109,"content":3110},{"uri":1351},[3111],{"nodeType":1293,"value":3112,"marks":3113,"data":3115},"you should check out our blog post on AitM and BitM phishing techniques",[3114],{"type":1335},{},{"nodeType":1293,"value":3117,"marks":3118,"data":3119},".  ",[],{},{"nodeType":1392,"data":3121,"content":3122},{},[3123],{"nodeType":1293,"value":3124,"marks":3125,"data":3126},"Case study: Snowflake",[],{},{"nodeType":1294,"data":3128,"content":3129},{},[3130,3134,3142],{"nodeType":1293,"value":3131,"marks":3132,"data":3133},"The ",[],{},{"nodeType":1337,"data":3135,"content":3137},{"uri":3136},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[3138],{"nodeType":1293,"value":3139,"marks":3140,"data":3141},"recent attacks on 165 Snowflake customers",[],{},{"nodeType":1293,"value":3143,"marks":3144,"data":3145},", resulting in hundreds of millions of breached customer records, were the product of a credential stuffing campaign using stolen credentials from infostealer infections dating back to 2020. ",[],{},{"nodeType":1294,"data":3147,"content":3148},{},[3149],{"nodeType":1293,"value":3150,"marks":3151,"data":3152},"The industry response to Snowflake was typical: check whether Snowflake has been set up for SSO, and if so, job done — we’re protected by MFA.",[],{},{"nodeType":1294,"data":3154,"content":3155},{},[3156],{"nodeType":1293,"value":3157,"marks":3158,"data":3159},"The reality was that MFA was not — and could not — be centrally enforced for username and password accounts. Even if MFA was applied at the IdP level for SSO logins, it was not enforced for local username and password logins. It needed to be opted-into by the user. ",[],{},{"nodeType":1294,"data":3161,"content":3162},{},[3163,3167,3175],{"nodeType":1293,"value":3164,"marks":3165,"data":3166},"This meant the most logical thing to do was to disable local accounts. But because Snowflake is essentially a cloud-hosted SQL database, there was no easy-to-use GUI to access local account config data. Once you’d managed to get an admin account with the right permissions, you needed to run various commands to find and unset the accounts. ",[],{},{"nodeType":1337,"data":3168,"content":3170},{"uri":3169},"https://pushsecurity.com/resources/video/demonstrating-ghost-logins-in-snowflake-and-how-to-remediate-them/",[3171],{"nodeType":1293,"value":3172,"marks":3173,"data":3174},"But if you didn’t have the exact type of admin account, misleading results would be returned — and even after you had fixed the vulnerability it took hours to update the database. ",[],{},{"nodeType":1293,"value":37,"marks":3176,"data":3177},[],{},{"nodeType":1294,"data":3179,"content":3180},{},[3181],{"nodeType":1293,"value":3182,"marks":3183,"data":3184},"This meant that organizations were exposed to these attacks for a prolonged period, and were left uncertain as to whether they had addressed the vulnerabilities or not. ",[],{},{"nodeType":1392,"data":3186,"content":3187},{},[3188],{"nodeType":1293,"value":3189,"marks":3190,"data":3191},"Using Push to find and fix ghost logins across your app inventory",[],{},{"nodeType":1294,"data":3193,"content":3194},{},[3195],{"nodeType":1293,"value":3196,"marks":3197,"data":3198},"Finding and fixing ghost logins is a challenge for most organizations. Since you can’t rely on the view provided by your IdP, you need to:",[],{},{"nodeType":1933,"data":3200,"content":3201},{},[3202,3212,3222],{"nodeType":1937,"data":3203,"content":3204},{},[3205],{"nodeType":1294,"data":3206,"content":3207},{},[3208],{"nodeType":1293,"value":3209,"marks":3210,"data":3211},"Discover the apps in use across your organization",[],{},{"nodeType":1937,"data":3213,"content":3214},{},[3215],{"nodeType":1294,"data":3216,"content":3217},{},[3218],{"nodeType":1293,"value":3219,"marks":3220,"data":3221},"Get admin rights, audit each app, and unset any local credentials (enforcing MFA at the app-level too if you can, for good measure)",[],{},{"nodeType":1937,"data":3223,"content":3224},{},[3225],{"nodeType":1294,"data":3226,"content":3227},{},[3228],{"nodeType":1293,"value":3229,"marks":3230,"data":3231},"Configure the app to prevent local accounts being created (again, if possible)",[],{},{"nodeType":1294,"data":3233,"content":3234},{},[3235],{"nodeType":1293,"value":3236,"marks":3237,"data":3238},"Not only is this a sisyphean task with continually moving goalposts, but depending on which apps you use, and how they’ve been designed, it may not be possible to remediate every instance of ghost logins. For that reason, it’s important to also invest in your identity threat detection and response capabilities — for when, not if, an account takeover attempt occurs. ",[],{},{"nodeType":1294,"data":3240,"content":3241},{},[3242,3246,3255],{"nodeType":1293,"value":3243,"marks":3244,"data":3245},"Push helps organizations to defend against ghost logins and other identity threats with a defense-in-depth approach: Using a browser-based agent to generate visibility of all logins (not just via IdP logs) while also detecting, intercepting, and shutting down account takeover attempts via phishing, credential stuffing, and session hijacking. ",[],{},{"nodeType":1337,"data":3247,"content":3249},{"uri":3248},"https://pushsecurity.com/",[3250],{"nodeType":1293,"value":3251,"marks":3252,"data":3254},"Learn more here.",[3253],{"type":1335},{},{"nodeType":1293,"value":37,"marks":3256,"data":3257},[],{},{"nodeType":1294,"data":3259,"content":3260},{},[3261,3265,3273],{"nodeType":1293,"value":3262,"marks":3263,"data":3264},"And if you'd like to learn more about ghost logins and other identity attack techniques, ",[],{},{"nodeType":1337,"data":3266,"content":3268},{"uri":3267},"https://github.com/pushsecurity/saas-attacks?tab=readme-ov-file",[3269],{"nodeType":1293,"value":3270,"marks":3271,"data":3272},"check out the SaaS attack matrix on GitHub",[],{},{"nodeType":1293,"value":1502,"marks":3274,"data":3275},[],{},{"nodeType":1377,"data":3277,"content":3281},{"target":3278},{"sys":3279},{"id":3280,"type":1374,"linkType":1375},"1VMpMgZvx9hgps2OoxCTmF",[],{"nodeType":1294,"data":3283,"content":3284},{},[3285],{"nodeType":1293,"value":37,"marks":3286,"data":3287},[],{},"Ghost logins: When forgotten identities come back to haunt you","How ghost logins can be used by cyber attackers for account takeover and persistence.","2024-07-10T00:00:00.000Z","ghost-logins-when-forgotten-identities-come-back-to-haunt-you",{"items":3293},[3294,3296],{"sys":3295,"name":1305},{"id":1304},{"sys":3297,"name":1309},{"id":1308},{"items":3299},[3300],{"fullName":3301,"firstName":3302,"jobTitle":3303,"profilePicture":3304},"Dan Green","Dan","Threat Research",{"url":3305},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"items":3307},[3308],{"fullName":3301,"firstName":3302,"jobTitle":3303,"profilePicture":3309},{"url":3305},{"json":3311,"links":4462},{"nodeType":1295,"data":3312,"content":3313},{},[3314,3346,3358,3374,3381,3388,3392,3399,3406,3531,3538,3545,3641,3648,3655,3708,3715,3738,3795,3798,3805,3824,3844,3851,3870,3877,3889,3892,3899,3906,3954,3961,3968,3988,3991,3998,4005,4012,4031,4038,4045,4052,4072,4079,4086,4093,4100,4120,4127,4134,4141,4148,4179,4185,4188,4195,4202,4208,4215,4222,4245,4252,4259,4302,4318,4338,4344,4351,4358,4365,4397,4443,4450,4456],{"nodeType":1294,"data":3315,"content":3316},{},[3317,3321,3330,3334,3342],{"nodeType":1293,"value":3318,"marks":3319,"data":3320},"Infostealer malware seems to be grabbing the headlines right now. It’s easy to see why, too, after laying claim to one of the ",[],{},{"nodeType":1337,"data":3322,"content":3324},{"uri":3323},"https://www.wired.com/story/snowflake-breach-advanced-auto-parts-lendingtree/",[3325],{"nodeType":1293,"value":3326,"marks":3327,"data":3329},"biggest breaches in history",[3328],{"type":1335},{},{"nodeType":1293,"value":3331,"marks":3332,"data":3333},". The ",[],{},{"nodeType":1337,"data":3335,"content":3336},{"uri":3136},[3337],{"nodeType":1293,"value":3338,"marks":3339,"data":3341},"recent attacks on Snowflake customers",[3340],{"type":1335},{},{"nodeType":1293,"value":3343,"marks":3344,"data":3345}," saw ~165 businesses compromised using stolen credentials, resulting in millions of breached customer records, with the full impact still emerging. ",[],{},{"nodeType":1294,"data":3347,"content":3348},{},[3349,3353],{"nodeType":1293,"value":3350,"marks":3351,"data":3352},"Notably, ",[],{},{"nodeType":1293,"value":3354,"marks":3355,"data":3357},"80% of the credentials used to access Snowflake customer accounts had found their way online after being stolen in infostealer infections – dating back as early as 2020. ",[3356],{"type":1772},{},{"nodeType":1294,"data":3359,"content":3360},{},[3361,3365,3370],{"nodeType":1293,"value":3362,"marks":3363,"data":3364},"The Snowflake situation is a reminder of how lucrative stolen credentials can be for attackers – and how the cybercrime ecosystem has tilted as a result. As the saying goes nowadays, ",[],{},{"nodeType":1293,"value":3366,"marks":3367,"data":3369},"hackers don’t hack in, they log in",[3368],{"type":1772},{},{"nodeType":1293,"value":3371,"marks":3372,"data":3373},". Stolen credentials are the lowest hanging fruit available to attackers, and their appetite (and the ecosystem needed to feed it) is insatiable. As an attacker, the prospect of picking up access to a major enterprise for just $10 or less (or even for free) is hard to resist – why wouldn’t you buy a ticket and take the gamble?  ",[],{},{"nodeType":1294,"data":3375,"content":3376},{},[3377],{"nodeType":1293,"value":3378,"marks":3379,"data":3380},"Infostealers are a huge part of the shift toward identity attacks. Along with phishing, infostealers are the primary mechanism for attackers to harvest credentials. Unlike phishing, infostealers can collect a large number of credentials (and other helpful data saved in the browser) in one fell swoop. But, they do have limitations. For example, you would expect any credible EDR to detect and block these attacks. And yet, the success of the attacks on Snowflake customers show us that gaps are being found and exploited.  ",[],{},{"nodeType":1294,"data":3382,"content":3383},{},[3384],{"nodeType":1293,"value":3385,"marks":3386,"data":3387},"In this article, we’ll look at the history of infostealers, how they work, and what the trends show us about how the cybercrime ecosystem is leaning into the opportunity they present.    ",[],{},{"nodeType":3389,"data":3390,"content":3391},"hr",{},[],{"nodeType":1392,"data":3393,"content":3394},{},[3395],{"nodeType":1293,"value":3396,"marks":3397,"data":3398},"The state of infostealers today",[],{},{"nodeType":1294,"data":3400,"content":3401},{},[3402],{"nodeType":1293,"value":3403,"marks":3404,"data":3405},"Infostealers, and the mass credential harvesting they enable, are a big part of the rise in identity attacks. The stats support this, as:",[],{},{"nodeType":1933,"data":3407,"content":3408},{},[3409,3428,3450,3470,3489,3509],{"nodeType":1937,"data":3410,"content":3411},{},[3412],{"nodeType":1294,"data":3413,"content":3414},{},[3415,3418,3425],{"nodeType":1293,"value":2940,"marks":3416,"data":3417},[],{},{"nodeType":1337,"data":3419,"content":3420},{"uri":2945},[3421],{"nodeType":1293,"value":2948,"marks":3422,"data":3424},[3423],{"type":1335},{},{"nodeType":1293,"value":2908,"marks":3426,"data":3427},[],{},{"nodeType":1937,"data":3429,"content":3430},{},[3431],{"nodeType":1294,"data":3432,"content":3433},{},[3434,3438,3447],{"nodeType":1293,"value":3435,"marks":3436,"data":3437},"Infostealer activity increased by 266% in 2023, while the number of attacks featuring valid credentials saw a 71% increase year-over-year (",[],{},{"nodeType":1337,"data":3439,"content":3441},{"uri":3440},"https://www.ibm.com/downloads/cas/L0GKXDWJ",[3442],{"nodeType":1293,"value":3443,"marks":3444,"data":3446},"IBM",[3445],{"type":1335},{},{"nodeType":1293,"value":2908,"marks":3448,"data":3449},[],{},{"nodeType":1937,"data":3451,"content":3452},{},[3453],{"nodeType":1294,"data":3454,"content":3455},{},[3456,3460,3467],{"nodeType":1293,"value":3457,"marks":3458,"data":3459},"147,000 token replay attacks were detected by Microsoft in 2023, an 111% increase year-over-year (",[],{},{"nodeType":1337,"data":3461,"content":3462},{"uri":2162},[3463],{"nodeType":1293,"value":2903,"marks":3464,"data":3466},[3465],{"type":1335},{},{"nodeType":1293,"value":3098,"marks":3468,"data":3469},[],{},{"nodeType":1937,"data":3471,"content":3472},{},[3473],{"nodeType":1294,"data":3474,"content":3475},{},[3476,3479,3486],{"nodeType":1293,"value":2918,"marks":3477,"data":3478},[],{},{"nodeType":1337,"data":3480,"content":3481},{"uri":2923},[3482],{"nodeType":1293,"value":2926,"marks":3483,"data":3485},[3484],{"type":1335},{},{"nodeType":1293,"value":2908,"marks":3487,"data":3488},[],{},{"nodeType":1937,"data":3490,"content":3491},{},[3492],{"nodeType":1294,"data":3493,"content":3494},{},[3495,3499,3506],{"nodeType":1293,"value":3496,"marks":3497,"data":3498},"Nearly half of the malware detected last year by Sophos targeted victims’ data specifically, and the majority of that malware was classified as infostealers (",[],{},{"nodeType":1337,"data":3500,"content":3501},{"uri":2096},[3502],{"nodeType":1293,"value":3503,"marks":3504,"data":3505},"Sophos",[],{},{"nodeType":1293,"value":2908,"marks":3507,"data":3508},[],{},{"nodeType":1937,"data":3510,"content":3511},{},[3512],{"nodeType":1294,"data":3513,"content":3514},{},[3515,3519,3528],{"nodeType":1293,"value":3516,"marks":3517,"data":3518},"Attacks on session cookies happen at the same order of magnitude as password-based attacks (",[],{},{"nodeType":1337,"data":3520,"content":3522},{"uri":3521},"https://github.com/WICG/dbsc/issues/13#issuecomment-1977657864",[3523],{"nodeType":1293,"value":3524,"marks":3525,"data":3527},"Google",[3526],{"type":1335},{},{"nodeType":1293,"value":2908,"marks":3529,"data":3530},[],{},{"nodeType":2540,"data":3532,"content":3533},{},[3534],{"nodeType":1293,"value":3535,"marks":3536,"data":3537},"How did we get here?",[],{},{"nodeType":1294,"data":3539,"content":3540},{},[3541],{"nodeType":1293,"value":3542,"marks":3543,"data":3544},"Let’s go back to the beginning. When they first emerged, infostealers were designed to steal online banking and credit card information. The most notable early example comes from as far back as 2006 with the ZeuS trojan. After the ZeuS source code was leaked in March 2011, the creation of multiple variants boosted the popularity of this type of malware and inspired the development of infostealers with increasingly sophisticated capabilities.",[],{},{"nodeType":1294,"data":3546,"content":3547},{},[3548,3552,3561,3565,3574,3578,3587,3591,3600,3603,3612,3615,3624,3628,3637],{"nodeType":1293,"value":3549,"marks":3550,"data":3551},"Modern infostealers rose to prominence in around 2018 with the emergence of ",[],{},{"nodeType":1337,"data":3553,"content":3555},{"uri":3554},"https://malpedia.caad.fkie.fraunhofer.de/details/win.arkei_stealer",[3556],{"nodeType":1293,"value":3557,"marks":3558,"data":3560},"Arkei",[3559],{"type":1335},{},{"nodeType":1293,"value":3562,"marks":3563,"data":3564},", which quickly spawned the more popular ",[],{},{"nodeType":1337,"data":3566,"content":3568},{"uri":3567},"https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar",[3569],{"nodeType":1293,"value":3570,"marks":3571,"data":3573},"Vidar",[3572],{"type":1335},{},{"nodeType":1293,"value":3575,"marks":3576,"data":3577}," stealer. Today, some of the most popular families are ",[],{},{"nodeType":1337,"data":3579,"content":3581},{"uri":3580},"https://malpedia.caad.fkie.fraunhofer.de/details/win.risepro",[3582],{"nodeType":1293,"value":3583,"marks":3584,"data":3586},"RisePro",[3585],{"type":1335},{},{"nodeType":1293,"value":3588,"marks":3589,"data":3590},", ",[],{},{"nodeType":1337,"data":3592,"content":3594},{"uri":3593},"https://malpedia.caad.fkie.fraunhofer.de/details/win.redline_stealer",[3595],{"nodeType":1293,"value":3596,"marks":3597,"data":3599},"RedLine",[3598],{"type":1335},{},{"nodeType":1293,"value":3588,"marks":3601,"data":3602},[],{},{"nodeType":1337,"data":3604,"content":3606},{"uri":3605},"https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc",[3607],{"nodeType":1293,"value":3608,"marks":3609,"data":3611},"StealC",[3610],{"type":1335},{},{"nodeType":1293,"value":3588,"marks":3613,"data":3614},[],{},{"nodeType":1337,"data":3616,"content":3618},{"uri":3617},"https://malpedia.caad.fkie.fraunhofer.de/details/win.raccoon",[3619],{"nodeType":1293,"value":3620,"marks":3621,"data":3623},"Raccoon",[3622],{"type":1335},{},{"nodeType":1293,"value":3625,"marks":3626,"data":3627},", and ",[],{},{"nodeType":1337,"data":3629,"content":3631},{"uri":3630},"https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma",[3632],{"nodeType":1293,"value":3633,"marks":3634,"data":3636},"Lumma",[3635],{"type":1335},{},{"nodeType":1293,"value":3638,"marks":3639,"data":3640},", with new variants and families appearing all the time. ",[],{},{"nodeType":1294,"data":3642,"content":3643},{},[3644],{"nodeType":1293,"value":3645,"marks":3646,"data":3647},"Infostealers are used by all manner of threat actors of varying levels of sophistication. For larger groups with sufficient resources, the creation of new, custom stealers and malware packages is a common tactic to attempt to evade detection. ",[],{},{"nodeType":1294,"data":3649,"content":3650},{},[3651],{"nodeType":1293,"value":3652,"marks":3653,"data":3654},"But despite all the variants, infostealers do have common capabilities and characteristics, such as:",[],{},{"nodeType":1933,"data":3656,"content":3657},{},[3658,3668,3678,3688,3698],{"nodeType":1937,"data":3659,"content":3660},{},[3661],{"nodeType":1294,"data":3662,"content":3663},{},[3664],{"nodeType":1293,"value":3665,"marks":3666,"data":3667},"Extracting information from the browsers of a compromised device, such as passwords, cookies, autofill information, downloaded file information.",[],{},{"nodeType":1937,"data":3669,"content":3670},{},[3671],{"nodeType":1294,"data":3672,"content":3673},{},[3674],{"nodeType":1293,"value":3675,"marks":3676,"data":3677},"Snapshotting the desktop and system inventory, with details such as the username, location data, hardware configuration, and information regarding installed security software.",[],{},{"nodeType":1937,"data":3679,"content":3680},{},[3681],{"nodeType":1294,"data":3682,"content":3683},{},[3684],{"nodeType":1293,"value":3685,"marks":3686,"data":3687},"Sending stolen data back to a C2 server.",[],{},{"nodeType":1937,"data":3689,"content":3690},{},[3691],{"nodeType":1294,"data":3692,"content":3693},{},[3694],{"nodeType":1293,"value":3695,"marks":3696,"data":3697},"Facilitating the deployment of additional tools and malware as part of a package. ",[],{},{"nodeType":1937,"data":3699,"content":3700},{},[3701],{"nodeType":1294,"data":3702,"content":3703},{},[3704],{"nodeType":1293,"value":3705,"marks":3706,"data":3707},"Often (but not always) self-terminating once complete, leaving little trace on the victim machine and no ongoing behavior that might be detected. ",[],{},{"nodeType":1294,"data":3709,"content":3710},{},[3711],{"nodeType":1293,"value":3712,"marks":3713,"data":3714},"Infostealers are distributed in similar ways to other types of malware, such as:",[],{},{"nodeType":1933,"data":3716,"content":3717},{},[3718,3728],{"nodeType":1937,"data":3719,"content":3720},{},[3721],{"nodeType":1294,"data":3722,"content":3723},{},[3724],{"nodeType":1293,"value":3725,"marks":3726,"data":3727},"Delivery of malicious executable files via phishing emails or by having a victim download content from a malicious website. ",[],{},{"nodeType":1937,"data":3729,"content":3730},{},[3731],{"nodeType":1294,"data":3732,"content":3733},{},[3734],{"nodeType":1293,"value":3735,"marks":3736,"data":3737},"‘Drive-by’ style attacks where the victim has only to visit an infected website.",[],{},{"nodeType":1294,"data":3739,"content":3740},{},[3741,3745,3754,3757,3766,3769,3778,3782,3791],{"nodeType":1293,"value":3742,"marks":3743,"data":3744},"They’re typically spread via malvertising, P2P downloads, and deceptive software download sites. ",[],{},{"nodeType":1337,"data":3746,"content":3748},{"uri":3747},"https://www.bleepingcomputer.com/news/security/fake-cheat-lures-gamers-into-spreading-infostealer-malware/",[3749],{"nodeType":1293,"value":3750,"marks":3751,"data":3753},"Gaming forums",[3752],{"type":1335},{},{"nodeType":1293,"value":3588,"marks":3755,"data":3756},[],{},{"nodeType":1337,"data":3758,"content":3760},{"uri":3759},"https://cybersecuritynews.com/facebook-account-hijack-malware/",[3761],{"nodeType":1293,"value":3762,"marks":3763,"data":3765},"Facebook ads",[3764],{"type":1335},{},{"nodeType":1293,"value":3625,"marks":3767,"data":3768},[],{},{"nodeType":1337,"data":3770,"content":3772},{"uri":3771},"https://www.fortinet.com/blog/threat-research/lumma-variant-on-youtube",[3773],{"nodeType":1293,"value":3774,"marks":3775,"data":3777},"YouTube video descriptions",[3776],{"type":1335},{},{"nodeType":1293,"value":3779,"marks":3780,"data":3781}," are popular locations for malicious links, but recent examples also include ",[],{},{"nodeType":1337,"data":3783,"content":3785},{"uri":3784},"https://www.bleepingcomputer.com/news/security/over-3-000-github-accounts-used-by-malware-distribution-service/",[3786],{"nodeType":1293,"value":3787,"marks":3788,"data":3790},"complex malware distribution networks on GitHub",[3789],{"type":1335},{},{"nodeType":1293,"value":3792,"marks":3793,"data":3794}," – such as the recent campaign from ‘Stargazer Goblin’ with more than 3,000 fake accounts creating and promoting hundreds of fake repositories to increase their apparent legitimacy and make them more likely to appear on GitHub's trending section.",[],{},{"nodeType":3389,"data":3796,"content":3797},{},[],{"nodeType":1392,"data":3799,"content":3800},{},[3801],{"nodeType":1293,"value":3802,"marks":3803,"data":3804},"Infostealers are key to the cybercrime ecosystem",[],{},{"nodeType":1294,"data":3806,"content":3807},{},[3808,3812,3820],{"nodeType":1293,"value":3809,"marks":3810,"data":3811},"After being stolen, ",[],{},{"nodeType":1337,"data":3813,"content":3814},{"uri":2945},[3815],{"nodeType":1293,"value":3816,"marks":3817,"data":3819},"infostealer data inevitably finds its way onto hacker forums and marketplaces",[3818],{"type":1335},{},{"nodeType":1293,"value":3821,"marks":3822,"data":3823},", both on the clearweb and darkweb. Popular infostealers have their own dedicated Telegram channels to advertise and sell stolen data. Private channels also exist, with the channel owner distributing tens of thousands of logs per week to a limited number of threat actors who pay $200-$400 for access to the channel. This allows them to get ‘first pick’ of stolen logs, which are later shared through public Telegram channels. ",[],{},{"nodeType":1294,"data":3825,"content":3826},{},[3827,3831,3840],{"nodeType":1293,"value":3828,"marks":3829,"data":3830},"Public data eventually makes its way onto services such as Have I Been Pwned (HIBP), which gives individuals and security teams some visibility of which credentials have been compromised. For example, ",[],{},{"nodeType":1337,"data":3832,"content":3834},{"uri":3833},"https://www.troyhunt.com/telegram-combolists-and-361m-email-addresses/",[3835],{"nodeType":1293,"value":3836,"marks":3837,"data":3839},"in June, Troy Hunt (creator of HIBP) wrote",[3838],{"type":1335},{},{"nodeType":1293,"value":3841,"marks":3842,"data":3843}," about the impact of channels like Telegram and the sale of combolists (username, password, login portal URL), after being sent 122GB of data scraped out of thousands of Telegram channels, containing 361M unique email addresses (of which 151M had never been seen in HIBP before). ",[],{},{"nodeType":1294,"data":3845,"content":3846},{},[3847],{"nodeType":1293,"value":3848,"marks":3849,"data":3850},"The cybercrime ecosystem is complex, with a developed supply chain and organizations fulfilling different roles as a result: from malware-as-a-service developers, to initial access brokers, to the operators that actually conduct the attacks (be they ransomware, data theft, etc.) – and many, many other roles in between. Sometimes, a single group and/or its affiliates will conduct the full chain, but this is far less common today. ",[],{},{"nodeType":1294,"data":3852,"content":3853},{},[3854,3857,3866],{"nodeType":1293,"value":37,"marks":3855,"data":3856},[],{},{"nodeType":1337,"data":3858,"content":3860},{"uri":3859},"https://www.secureworks.com/research/the-growing-threat-from-infostealers",[3861],{"nodeType":1293,"value":3862,"marks":3863,"data":3865},"Infostealers are often sold by malware developers to other attackers as a monthly subscription service.",[3864],{"type":1335},{},{"nodeType":1293,"value":3867,"marks":3868,"data":3869}," The price can range from $50 to over $1,000 USD per month for access to a stealer command and control (C2) server operated by the developer. The service often features a range of support functions, including multiple ways to view, download, and share stolen data. Self-hosted stealer C2 servers are also available and are usually sold for a flat fee. ",[],{},{"nodeType":1294,"data":3871,"content":3872},{},[3873],{"nodeType":1293,"value":3874,"marks":3875,"data":3876},"There’s also evidence that there is an element of target coordination – with one marketplace, Russian Market, allowing users to ‘preorder’ credentials for a $1,000 USD deposit from 2022. ",[],{},{"nodeType":1294,"data":3878,"content":3879},{},[3880,3885],{"nodeType":1293,"value":3881,"marks":3882,"data":3884},"So what? Well, there's evidently an abundance of breached data already online, and attackers have the tools readily available to have this pile grow exponentially bigger and more useful.",[3883],{"type":1772},{},{"nodeType":1293,"value":3886,"marks":3887,"data":3888}," It’s also probably more coordinated than we like to admit – a particularly intimidating prospect in the wake of Snowflake, which will no doubt have many criminals smelling blood in the water. ",[],{},{"nodeType":3389,"data":3890,"content":3891},{},[],{"nodeType":1392,"data":3893,"content":3894},{},[3895],{"nodeType":1293,"value":3896,"marks":3897,"data":3898},"How can stolen data be abused by attackers? ",[],{},{"nodeType":1294,"data":3900,"content":3901},{},[3902],{"nodeType":1293,"value":3903,"marks":3904,"data":3905},"It’s pretty obvious that attackers getting access to all of your passwords and session cookies is bad, but there is a clear value hierarchy from a corporate security perspective. So, from highest to lowest risk:",[],{},{"nodeType":1933,"data":3907,"content":3908},{},[3909,3924,3939],{"nodeType":1937,"data":3910,"content":3911},{},[3912],{"nodeType":1294,"data":3913,"content":3914},{},[3915,3920],{"nodeType":1293,"value":3916,"marks":3917,"data":3919},"Stolen session cookies",[3918],{"type":1772},{},{"nodeType":1293,"value":3921,"marks":3922,"data":3923}," simply need to be imported into an attacker’s browser to resume an active session on an app. That means access can be gained without needing to enter a username and password, or pass any MFA checks. ",[],{},{"nodeType":1937,"data":3925,"content":3926},{},[3927],{"nodeType":1294,"data":3928,"content":3929},{},[3930,3935],{"nodeType":1293,"value":3931,"marks":3932,"data":3934},"Stolen usernames, passwords",[3933],{"type":1772},{},{"nodeType":1293,"value":3936,"marks":3937,"data":3938},", and login page URLs can be used to access any accounts that lack MFA. ",[],{},{"nodeType":1937,"data":3940,"content":3941},{},[3942],{"nodeType":1294,"data":3943,"content":3944},{},[3945,3950],{"nodeType":1293,"value":3946,"marks":3947,"data":3949},"Stolen autofill data",[3948],{"type":1772},{},{"nodeType":1293,"value":3951,"marks":3952,"data":3953}," can be used to gather other valuable information that could be useful for impersonating the victim when speaking to social engineering IT support staff, for example to reset or remove MFA.",[],{},{"nodeType":1294,"data":3955,"content":3956},{},[3957],{"nodeType":1293,"value":3958,"marks":3959,"data":3960},"Naturally, stolen session cookies are the most valuable prize, but they are often valid for only a limited time before the user must re-authenticate, and active sessions can often be terminated by security admins. Unfortunately, it’s not that uncommon for sessions to last for up to a month, or even sometimes indefinitely.",[],{},{"nodeType":1294,"data":3962,"content":3963},{},[3964],{"nodeType":1293,"value":3965,"marks":3966,"data":3967},"Stolen usernames and passwords are a different story. As the Snowflake breaches demonstrate, passwords can remain valid for years after a breach, particularly in the world of SaaS apps where mandatory password rotation is not as common as for a user’s primary domain account.",[],{},{"nodeType":1294,"data":3969,"content":3970},{},[3971,3975,3984],{"nodeType":1293,"value":3972,"marks":3973,"data":3974},"There’s also the problem of ",[],{},{"nodeType":1337,"data":3976,"content":3978},{"uri":3977},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/",[3979],{"nodeType":1293,"value":3980,"marks":3981,"data":3983},"ghost logins",[3982],{"type":1335},{},{"nodeType":1293,"value":3985,"marks":3986,"data":3987}," – where a local login with a username and password (and probably lacking MFA) can exist alongside other, more secure login methods such as SSO. Given the fact that many apps are self-adopted by users, these accounts continue to exist even when an app is subsequently added to SSO via the chosen IdP, meaning they can fly under the radar of security teams. ",[],{},{"nodeType":3389,"data":3989,"content":3990},{},[],{"nodeType":1392,"data":3992,"content":3993},{},[3994],{"nodeType":1293,"value":3995,"marks":3996,"data":3997},"Should you be concerned about infostealers?",[],{},{"nodeType":1294,"data":3999,"content":4000},{},[4001],{"nodeType":1293,"value":4002,"marks":4003,"data":4004},"It’s commonly thought that infostealers are primarily a concern for unmanaged devices that lack security controls common to corporate IT, such as EDR. But there’s a couple of reasons why corporate users are also at risk:",[],{},{"nodeType":2540,"data":4006,"content":4007},{},[4008],{"nodeType":1293,"value":4009,"marks":4010,"data":4011},"EDR can be bypassed",[],{},{"nodeType":1294,"data":4013,"content":4014},{},[4015,4019,4028],{"nodeType":1293,"value":4016,"marks":4017,"data":4018},"EDR is seen as the go-to solution for defending against infostealer malware. However, attackers are always looking for ways to get around security controls by obfuscating malicious behavior and evading signature-based checks. For example, ",[],{},{"nodeType":1337,"data":4020,"content":4022},{"uri":4021},"https://thehackernews.com/2024/07/microsoft-defender-flaw-exploited-to.html",[4023],{"nodeType":1293,"value":4024,"marks":4025,"data":4027},"a flaw in Microsoft Defender SmartScreen was recently exploited to deliver infostealer malware",[4026],{"type":1335},{},{"nodeType":1293,"value":1435,"marks":4029,"data":4030},[],{},{"nodeType":1294,"data":4032,"content":4033},{},[4034],{"nodeType":1293,"value":4035,"marks":4036,"data":4037},"Getting total coverage across your endpoint estate is notoriously difficult, if not totally unrealistic. Unless the malware is stopped on execution, then data will inevitably be stolen, and will continue to be taken until stopped (or it self-terminates). And once an attacker has stolen employee credentials or sessions, the credential stuffing and session hijacking attacks that come next won’t touch the endpoint. For those reasons, you can’t rely on EDR as a single line of defense against infostealers.",[],{},{"nodeType":2540,"data":4039,"content":4040},{},[4041],{"nodeType":1293,"value":4042,"marks":4043,"data":4044},"Unmanaged devices such as BYOD or third-parties are vulnerable",[],{},{"nodeType":1294,"data":4046,"content":4047},{},[4048],{"nodeType":1293,"value":4049,"marks":4050,"data":4051},"Companies that support BYOD often have less secure configurations than those with fully managed devices. The same applies to third-party contractors, who often use their own devices to access company systems on a temporary basis. ",[],{},{"nodeType":1294,"data":4053,"content":4054},{},[4055,4059,4068],{"nodeType":1293,"value":4056,"marks":4057,"data":4058},"This issue was acutely felt in the Snowflake attacks: There is some suggestion that targeting key third-party suppliers – ",[],{},{"nodeType":1337,"data":4060,"content":4062},{"uri":4061},"https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/",[4063],{"nodeType":1293,"value":4064,"marks":4065,"data":4067},"such as EPAM Systems, a software engineering firm and Snowflake ‘Elite Tier Partner’",[4066],{"type":1335},{},{"nodeType":1293,"value":4069,"marks":4070,"data":4071}," – yielded some of the access needed. It’s unclear what came first, but it’s possible (likely, even) that EPAM was identified as a target specifically because of its lucrative customer base – third-parties are a known weak point for red teamers, so it would be foolish to assume that attackers don’t also think this way. It’s possible too that EPAM were specifically targeted because of their Snowflake chops – adding another indicator that Snowflake was potentially a premeditated attack inspired by the availability of Snowflake credentials online. ",[],{},{"nodeType":2540,"data":4073,"content":4074},{},[4075],{"nodeType":1293,"value":4076,"marks":4077,"data":4078},"Browser profiles can be synced across devices, increasing the blast radius",[],{},{"nodeType":1294,"data":4080,"content":4081},{},[4082],{"nodeType":1293,"value":4083,"marks":4084,"data":4085},"It’s not uncommon for employees to access their personal email accounts from company devices. When accessing any browser, you are typically prompted to sign in with your account credentials (e.g. your Google account). If a user signs into a browser on a company device with a personal account, you’re usually prompted to sync your account across devices. This usually means that any saved passwords, search history, and settings are shared across devices. ",[],{},{"nodeType":1294,"data":4087,"content":4088},{},[4089],{"nodeType":1293,"value":4090,"marks":4091,"data":4092},"Naturally, this means that if a personal device is compromised where you’re also logged into the browser profile, then an infostealer will be able to harvest information saved into that profile across devices.",[],{},{"nodeType":1294,"data":4094,"content":4095},{},[4096],{"nodeType":1293,"value":4097,"marks":4098,"data":4099},"Even when using separate browser profiles for work and personal, it’s easy for the two to converge, or to slip into using the wrong profile. Accessing personal accounts (or at least synchronizing data across accounts) is usually a workplace policy violation, but it’s unfortunately all too common. ",[],{},{"nodeType":1294,"data":4101,"content":4102},{},[4103,4107,4116],{"nodeType":1293,"value":4104,"marks":4105,"data":4106},"Previous vulnerabilities have exacerbated this problem, such as ",[],{},{"nodeType":1337,"data":4108,"content":4110},{"uri":4109},"https://thehackernews.com/2024/01/malware-using-google-multilogin-exploit.html",[4111],{"nodeType":1293,"value":4112,"marks":4113,"data":4115},"an exploit affecting Google MultiLogin to maintain access to synced accounts even after a password reset",[4114],{"type":1335},{},{"nodeType":1293,"value":4117,"marks":4118,"data":4119},". ",[],{},{"nodeType":2540,"data":4121,"content":4122},{},[4123],{"nodeType":1293,"value":4124,"marks":4125,"data":4126},"Are infostealers a bigger problem than credential phishing? ",[],{},{"nodeType":1294,"data":4128,"content":4129},{},[4130],{"nodeType":1293,"value":4131,"marks":4132,"data":4133},"The short answer is: No. The longer answer is: They are both part of the bigger problem of identity attacks, and attackers can wield both approaches simultaneously. ",[],{},{"nodeType":1294,"data":4135,"content":4136},{},[4137],{"nodeType":1293,"value":4138,"marks":4139,"data":4140},"While they are delivered to victims in similar ways to phishing links, most organizations are arguably better protected against infostealers than modern phishing attacks because endpoint security controls provide another layer of protection, in theory – whereas modern phishing attacks don’t necessarily involve the delivery of malware that executes on the device. ",[],{},{"nodeType":1294,"data":4142,"content":4143},{},[4144],{"nodeType":1293,"value":4145,"marks":4146,"data":4147},"Infostealers arguably provide more bang for the attacker’s buck, grabbing a stack of credentials and useful data in one go. In contrast, phishing is usually much more targeted, and involves the compromise of a narrower set of credentials – typically focusing on a particular site or app. ",[],{},{"nodeType":1294,"data":4149,"content":4150},{},[4151,4155,4164,4168,4175],{"nodeType":1293,"value":4152,"marks":4153,"data":4154},"It’s worth focusing on the TTP, not the particular tool being used: The attacker technique here is ",[],{},{"nodeType":1337,"data":4156,"content":4158},{"uri":4157},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/session_cookie_theft/description.md",[4159],{"nodeType":1293,"value":4160,"marks":4161,"data":4163},"session cookie theft",[4162],{"type":1335},{},{"nodeType":1293,"value":4165,"marks":4166,"data":4167},", and subsequently session hijacking by importing the cookie into the attacker’s browser. Both infostealers and ",[],{},{"nodeType":1337,"data":4169,"content":4170},{"uri":1351},[4171],{"nodeType":1293,"value":4172,"marks":4173,"data":4174},"modern phishing attacks",[],{},{"nodeType":1293,"value":4176,"marks":4177,"data":4178}," involve the theft of session tokens, and so are valid means to achieve this end. In fact, there’s nothing to stop threat groups from employing both simultaneously.",[],{},{"nodeType":1377,"data":4180,"content":4184},{"target":4181},{"sys":4182},{"id":4183,"type":1374,"linkType":1375},"7fil6aaQDFfJGYUnQ14k10",[],{"nodeType":3389,"data":4186,"content":4187},{},[],{"nodeType":1392,"data":4189,"content":4190},{},[4191],{"nodeType":1293,"value":4192,"marks":4193,"data":4194},"Infostealers in action",[],{},{"nodeType":1294,"data":4196,"content":4197},{},[4198],{"nodeType":1293,"value":4199,"marks":4200,"data":4201},"Check out the video demo below to see the attack chain in action from the point of an infostealer compromise, showing session cookie theft, reimporting the cookies into the attacker's browser, and evading policy-based controls in M365. It also shows the targeting of downstream apps that are usually accessed via SSO in the context of both a Microsoft Entra and Okta compromise.",[],{},{"nodeType":1377,"data":4203,"content":4207},{"target":4204},{"sys":4205},{"id":4206,"type":1374,"linkType":1375},"4J7LqqjQX2W52AbmcVmjUt",[],{"nodeType":1392,"data":4209,"content":4210},{},[4211],{"nodeType":1293,"value":4212,"marks":4213,"data":4214},"What can organizations do about the infostealer threat? ",[],{},{"nodeType":1294,"data":4216,"content":4217},{},[4218],{"nodeType":1293,"value":4219,"marks":4220,"data":4221},"Security teams should have two main concerns:",[],{},{"nodeType":1933,"data":4223,"content":4224},{},[4225,4235],{"nodeType":1937,"data":4226,"content":4227},{},[4228],{"nodeType":1294,"data":4229,"content":4230},{},[4231],{"nodeType":1293,"value":4232,"marks":4233,"data":4234},"Data that is already out there from historical data dumps, but is still valid. ",[],{},{"nodeType":1937,"data":4236,"content":4237},{},[4238],{"nodeType":1294,"data":4239,"content":4240},{},[4241],{"nodeType":1293,"value":4242,"marks":4243,"data":4244},"Data in private channels that attackers could use in the future, that you are blind to. ",[],{},{"nodeType":1294,"data":4246,"content":4247},{},[4248],{"nodeType":1293,"value":4249,"marks":4250,"data":4251},"As always, the root-cause of the problem is a lack of meaningful visibility of what apps your employees are using (including those outside your IdP) and whether the associated identities are configured securely. ",[],{},{"nodeType":1294,"data":4253,"content":4254},{},[4255],{"nodeType":1293,"value":4256,"marks":4257,"data":4258},"A layered, defense-in-depth approach is required to resolve the issue, by:",[],{},{"nodeType":1933,"data":4260,"content":4261},{},[4262,4272,4282,4292],{"nodeType":1937,"data":4263,"content":4264},{},[4265],{"nodeType":1294,"data":4266,"content":4267},{},[4268],{"nodeType":1293,"value":4269,"marks":4270,"data":4271},"Deploying MFA across all your identities and apps, including any local logins that can’t be put behind SSO. ",[],{},{"nodeType":1937,"data":4273,"content":4274},{},[4275],{"nodeType":1294,"data":4276,"content":4277},{},[4278],{"nodeType":1293,"value":4279,"marks":4280,"data":4281},"Configuring time-limited session lifetimes for all apps to ensure that any stolen session tokens can only be used temporarily. ",[],{},{"nodeType":1937,"data":4283,"content":4284},{},[4285],{"nodeType":1294,"data":4286,"content":4287},{},[4288],{"nodeType":1293,"value":4289,"marks":4290,"data":4291},"Ensuring that employees don’t access or synchronize personal accounts on their work devices, as well as limiting non-work activities on their work device as much as possible.",[],{},{"nodeType":1937,"data":4293,"content":4294},{},[4295],{"nodeType":1294,"data":4296,"content":4297},{},[4298],{"nodeType":1293,"value":4299,"marks":4300,"data":4301},"Implementing a robust EDR/MDR solution to detect and respond to malware compromises on user devices. ",[],{},{"nodeType":1294,"data":4303,"content":4304},{},[4305,4309,4314],{"nodeType":1293,"value":4306,"marks":4307,"data":4308},"Organizations also have the option of investing in a commercial TI feed to detect and report data breaches affecting employees. But in our experience, these feeds contain ",[],{},{"nodeType":1293,"value":4310,"marks":4311,"data":4313},"a lot ",[4312],{"type":1772},{},{"nodeType":1293,"value":4315,"marks":4316,"data":4317},"of false positives – so unless you have password visibility for employee accounts across apps, it’s going to waste a chunk of valuable time for you and your employees.",[],{},{"nodeType":1294,"data":4319,"content":4320},{},[4321,4325,4334],{"nodeType":1293,"value":4322,"marks":4323,"data":4324},"It would be remiss of us not to mention our recently released ",[],{},{"nodeType":1337,"data":4326,"content":4328},{"uri":4327},"https://pushsecurity.com/blog/introducing-session-token-theft-detection-why-browser-is-best/",[4329],{"nodeType":1293,"value":4330,"marks":4331,"data":4333},"session token theft detection feature",[4332],{"type":1335},{},{"nodeType":1293,"value":4335,"marks":4336,"data":4337}," that identifies session token theft by adding telemetry to the user agent string – using the power of our browser agent to create a new high-fidelity signal for security teams. It can also be applied more generally to detect any session taking place in an unmanaged browser – so you can use it to spot unauthorized access to company apps in general, too.  ",[],{},{"nodeType":1377,"data":4339,"content":4343},{"target":4340},{"sys":4341},{"id":4342,"type":1374,"linkType":1375},"3XgpqEGzZSD2J0uvnCg5D8",[],{"nodeType":2540,"data":4345,"content":4346},{},[4347],{"nodeType":1293,"value":4348,"marks":4349,"data":4350},"What’s next for infostealers?",[],{},{"nodeType":1294,"data":4352,"content":4353},{},[4354],{"nodeType":1293,"value":4355,"marks":4356,"data":4357},"All the signs point to the fact that infostealers will continue being a useful tool in the attacker’s arsenal. The Snowflake attacks in particular are both a warning for defenders and encouragement for attackers. It's also a good reminder that while infostealers were once used to harvest things like VPN creds to pivot to the internal network, they're now largely used to target third-party services over the internet. ",[],{},{"nodeType":1294,"data":4359,"content":4360},{},[4361],{"nodeType":1293,"value":4362,"marks":4363,"data":4364},"To evade EDR, it’s likely that we’ll see a growing number of families and variants used by individual groups, or better ‘enterprise’ capabilities from malware-as-a-service vendors. ",[],{},{"nodeType":1294,"data":4366,"content":4367},{},[4368,4372,4381,4385,4393],{"nodeType":1293,"value":4369,"marks":4370,"data":4371},"One notable quirk is that, to date, infostealers have not really branched out from targeting browsers. Take the example of password manager apps – you would think this would be an obvious target, right? But, they’re not usually targeted (",[],{},{"nodeType":1337,"data":4373,"content":4375},{"uri":4374},"https://securitysenses.com/posts/malware-targeting-password-managers",[4376],{"nodeType":1293,"value":4377,"marks":4378,"data":4380},"with some exceptions",[4379],{"type":1335},{},{"nodeType":1293,"value":4382,"marks":4383,"data":4384},"). And when they do, ",[],{},{"nodeType":1337,"data":4386,"content":4387},{"uri":4374},[4388],{"nodeType":1293,"value":4389,"marks":4390,"data":4392},"they work by eavesdropping on the password manager’s browser extension in action",[4391],{"type":1335},{},{"nodeType":1293,"value":4394,"marks":4395,"data":4396}," – meaning they are intercepted one-at-a-time as the user uses them, rather than targeting the password manager directly and exporting the saved passwords all at once. It will be interesting to see whether these capabilities are added in the future. ",[],{},{"nodeType":1294,"data":4398,"content":4399},{},[4400,4404,4413,4417,4426,4430,4439],{"nodeType":1293,"value":4401,"marks":4402,"data":4403},"On the other hand, there are defensive security developments that could reduce the ability of attackers to leverage things like stolen session tokens, such as ",[],{},{"nodeType":1337,"data":4405,"content":4407},{"uri":4406},"https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-token-protection",[4408],{"nodeType":1293,"value":4409,"marks":4410,"data":4412},"Microsoft’s token binding feature in Entra",[4411],{"type":1335},{},{"nodeType":1293,"value":4414,"marks":4415,"data":4416},", or ",[],{},{"nodeType":1337,"data":4418,"content":4420},{"uri":4419},"https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html",[4421],{"nodeType":1293,"value":4422,"marks":4423,"data":4425},"Google’s device bound session cookies",[4424],{"type":1335},{},{"nodeType":1293,"value":4427,"marks":4428,"data":4429},". Google also released an ",[],{},{"nodeType":1337,"data":4431,"content":4433},{"uri":4432},"https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html?m=1",[4434],{"nodeType":1293,"value":4435,"marks":4436,"data":4438},"app-bound encryption feature",[4437],{"type":1335},{},{"nodeType":1293,"value":4440,"marks":4441,"data":4442},", which adds additional protection against infostealers attempting to steal browser data in Chrome if the underlying Windows device is compromised. ",[],{},{"nodeType":1294,"data":4444,"content":4445},{},[4446],{"nodeType":1293,"value":4447,"marks":4448,"data":4449},"That said, mature versions of these controls are still years away, and while session cookie theft is a key risk of infostealers, it’s not the only risk – so alternative controls and mitigations remain valuable to security teams in the present. ",[],{},{"nodeType":1377,"data":4451,"content":4455},{"target":4452},{"sys":4453},{"id":4454,"type":1374,"linkType":1375},"5loTnpvwGD3kaKMXBp23hZ",[],{"nodeType":1294,"data":4457,"content":4458},{},[4459],{"nodeType":1293,"value":37,"marks":4460,"data":4461},[],{},{"entries":4463},{"hyperlink":4464,"inline":4465,"block":4466},[],[],[4467,4474,4483,4487],{"sys":4468,"__typename":4469,"type":4470,"ctaText":4471,"buttonLabel":4472,"buttonColour":4473,"buttonUrl":1351},{"id":4183},"CtaWidget","Custom","Learn more about modern AitM and BitM phishing toolkits","Read the Blog","sea blue",{"sys":4475,"__typename":4476,"title":4477,"youTubeUrl":4478,"imagePlaceholder":4479},{"id":4206},"ExternalVideo","Session hijacking using stolen session cookies","https://www.youtube.com/watch?v=RlSweA5UfYw",{"url":4480,"width":4481,"height":4482},"https://images.ctfassets.net/y1cdw1ablpvd/4ONwBrDgXX7NdfkMoIVu8v/775f0c1646e90220b2df9fe17ec30690/Slide_16_9_-_44__2_.png",1920,1080,{"sys":4484,"__typename":4469,"type":4470,"ctaText":4485,"buttonLabel":4472,"buttonColour":4486,"buttonUrl":4327},{"id":4342},"Learn more about how we use browser telemetry to detect and stop session token theft","sunny orange",{"sys":4488,"__typename":4469,"type":4470,"ctaText":4489,"buttonLabel":4490,"buttonColour":4486,"buttonUrl":4491},{"id":4454},"Check out our on-demand webinar for everything you need to know about infostealers and session hijacking","Watch on-demand","https://pushsecurity.com/resources/video/infostealers-webinar-ondemand/","content:blog:what-the-rise-of-infostealers-says-about-identity-attacks.json","json","content","blog/what-the-rise-of-infostealers-says-about-identity-attacks.json","blog/what-the-rise-of-infostealers-says-about-identity-attacks",1776359987926]