[{"data":1,"prerenderedAt":4172},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":95,"navbar-about-highlight":155,"navbar-resource-highlight":211,"use-case-page":256,"blog/why-its-time-for-phishing-prevention-to-move-beyond-email":1276},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8,59,76],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":14,"data":15,"variations":50,"lastUpdated":51,"firstPublished":52,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":54,"meta":55,"rev":58},1742213002749,"efff2a27faf4408e9f908eba4b5542fe","inductive-automation","1c6207a5f24948ab82d4a0b17f251193","published",[],{"testimonial":16,"description":43,"type":19,"link":44,"title":47,"testimonialLink":48,"image":49},{"@type":17,"id":18,"model":19,"value":20},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":21,"folders":22,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":26,"variations":30,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":35,"rev":42},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":27,"jobTitle":28,"quote":24,"image":29},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,1,"ST0tXQM8slWpFrmioqKHmENB2qe2",{"kind":36,"lastPreviewUrl":37,"breakpoints":38,"hasAutosaves":41},"data","",{"small":39,"medium":40},640,768,true,"3v32gocrrqz","Join the industry's top security minds as they break down the browser attack landscape.",{"url":45,"text":46},"https://pushsecurity.com/webinar/state-of-browser-security","Save Your Spot","State of Browser Attacks Series","/customer-stories/inductive-automation","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe94fca10aa7b46ac8052b7ea22de54cd",{},1776257019270,1742221533648,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2",[],{"breakpoints":56,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},320,"motto9r9yg",{"createdDate":60,"id":61,"name":62,"modelId":12,"published":13,"query":63,"data":64,"variations":69,"lastUpdated":70,"firstPublished":71,"testRatio":33,"createdBy":53,"lastUpdatedBy":72,"folders":73,"meta":74,"rev":58},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner",[],{"type":65,"url":66,"text":67,"link":68},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,"jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":36,"lastPreviewUrl":37,"breakpoints":75,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},{"createdDate":77,"id":78,"name":79,"modelId":12,"published":13,"stageModifiedSincePublish":6,"query":80,"data":81,"variations":89,"lastUpdated":90,"firstPublished":91,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":92,"meta":93,"rev":58},1742208469288,"6763051b201f44a0838c6400c580ca67","Resource highlight",[],{"image":82,"type":83,"description":84,"link":85,"title":88},"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9","resource","Learn about the latest techniques being used in the wild.",{"url":86,"text":87},"/resources/browser-attacks-report","Download now","Report: 2026 Browser Attack Techniques",{},1776255866789,1742208570400,[],{"kind":36,"lastPreviewUrl":37,"breakpoints":94,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},{"createdDate":96,"id":97,"name":98,"modelId":99,"published":13,"query":100,"data":101,"variations":145,"lastUpdated":146,"firstPublished":147,"testRatio":33,"createdBy":34,"lastUpdatedBy":148,"folders":149,"meta":150,"rev":154},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":102,"text":103,"url":37,"blocks":104,"state":141},"ewrererw","testrfesssssssssss",[105,129],{"@type":106,"@version":107,"id":108,"component":109,"responsiveStyles":119},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":110,"tag":110,"options":111,"isRSC":118},"TopBannerContent",{"text":112,"ctaText":46,"url":45,"mainText":113,"cta":116},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks",{"content":114,"fontSize":115},"\u003Cp>New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks\u003C/p>","text-base",{"content":117,"fontSize":115,"url":45},"\u003Cp>\u003Cstrong style=\"font-weight:700;\">Save Your Spot\u003C/strong>\u003C/p>\n",null,{"large":120},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"marginTop":126,"marginBottom":126,"fontSize":127,"fontWeight":128},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":130,"@type":106,"tagName":131,"properties":132,"responsiveStyles":136},"builder-pixel-08zrjigffq5t","img",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":137},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},"block","hidden","none",{"deviceSize":142,"location":143},"large",{"path":37,"query":144},{},{},1775137295127,1774968080803,"ax7YYfD0OCeqT1Vxxv1G4FUbqVr1",[],{"breakpoints":151,"hasLinks":6,"kind":152,"lastPreviewUrl":153,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","2lvuonnywj",[156,180],{"createdDate":157,"id":158,"name":159,"modelId":160,"published":13,"stageModifiedSincePublish":6,"query":161,"data":162,"variations":173,"lastUpdated":174,"firstPublished":175,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":176,"meta":177,"rev":179},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":163,"type":19,"testimonialLink":48,"testimonial":164},{},{"@type":17,"id":18,"model":19,"value":165},{"query":166,"folders":167,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":168,"variations":169,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":170,"rev":172},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":171,"hasAutosaves":41},{"small":39,"medium":40},"7t755zfvte3",{},1776247404986,1776247404973,[],{"breakpoints":178,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"4moh0qpywtr",{"createdDate":181,"id":182,"name":88,"modelId":160,"published":13,"meta":183,"stageModifiedSincePublish":6,"query":185,"data":186,"variations":207,"lastUpdated":208,"firstPublished":209,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":210,"rev":179},1776255761419,"05a9322735fc427db12e2740e4302300",{"breakpoints":184,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":187,"link":206,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":189},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":190,"folders":191,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":194,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":203,"rev":205},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":36,"lastPreviewUrl":37,"breakpoints":204,"hasAutosaves":41},{"small":39,"medium":40},"6s8ic0w0ao6",{"text":87,"url":86},{},1776255810913,1776255810900,[],[212,235],{"createdDate":213,"id":214,"name":88,"modelId":215,"published":13,"meta":216,"stageModifiedSincePublish":6,"query":218,"data":219,"variations":230,"lastUpdated":231,"firstPublished":232,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":233,"rev":234},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":217,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[],{"testimonial":220,"link":229,"type":83,"title":88,"description":84,"image":82},{"@type":17,"id":188,"model":19,"value":221},{"query":222,"folders":223,"createdDate":192,"id":188,"name":193,"modelId":25,"published":13,"data":224,"variations":225,"lastUpdated":201,"firstPublished":202,"testRatio":33,"createdBy":34,"lastUpdatedBy":53,"meta":226,"rev":228},[],[],{"video":195,"jobTitle":196,"author":197,"qoute":37,"quote":198,"image":199},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":227,"hasAutosaves":41},{"small":39,"medium":40},"r77qqueuo3j",{"text":87,"url":86},{},1776256937553,1776256937540,[],"q0jkez80wkg",{"createdDate":236,"id":237,"name":11,"modelId":215,"published":13,"stageModifiedSincePublish":6,"query":238,"data":239,"variations":250,"lastUpdated":251,"firstPublished":252,"testRatio":33,"createdBy":53,"lastUpdatedBy":53,"folders":253,"meta":254,"rev":234},1776256949234,"ce043785b71b4ece98eac811ecf4ba10",[],{"link":240,"type":19,"testimonial":241,"testimonialLink":48},{},{"@type":17,"id":18,"model":19,"value":242},{"query":243,"folders":244,"createdDate":23,"id":18,"name":24,"modelId":25,"published":13,"data":245,"variations":246,"lastUpdated":31,"firstPublished":32,"testRatio":33,"createdBy":34,"lastUpdatedBy":34,"meta":247,"rev":249},[],[],{"author":27,"jobTitle":28,"quote":24,"image":29},{},{"kind":36,"lastPreviewUrl":37,"breakpoints":248,"hasAutosaves":41},{"small":39,"medium":40},"mnaneamy308",{},1776256974140,1776256974130,[],{"breakpoints":255,"kind":36,"lastPreviewUrl":37,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},[257,441,560,679,797,917,1037,1157],{"createdDate":258,"id":259,"name":260,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":262,"data":268,"variations":429,"lastUpdated":430,"firstPublished":431,"testRatio":33,"screenshot":432,"createdBy":34,"lastUpdatedBy":433,"folders":434,"meta":435,"rev":440},1744829487099,"387451215c314dd5bd654668cdc1a197","Zero-day phishing","cca4143377554c5a9163cc203a8ed2ba",[263],{"@type":264,"property":265,"operator":266,"value":267},"@builder.io/core:Query","urlPath","is","/uc/zero-day-phishing-protection",{"inputs":269,"customFonts":270,"seoTitle":318,"title":318,"tsCode":37,"seoDescription":319,"fontAwesomeIcon":320,"jsCode":37,"blocks":321,"url":267,"state":426},[],[271],{"family":272,"kind":273,"version":274,"lastModified":275,"files":276,"category":295,"menu":296,"subsets":297,"variants":300},"DM Sans","webfonts#webfont","v14","2023-07-13",{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"900italic":286,"700italic":287,"100italic":288,"italic":289,"regular":290,"200italic":291,"500italic":292,"300italic":293,"600italic":294},"https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAop1hTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwA_JxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAIpthTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAC5thTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8gCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9uCm3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDG3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTmf3ZGMZpg.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat8JDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat-7DW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat_XDW3zRmYJpso5.ttf","https://fonts.gstatic.com/s/dmsans/v14/rP2rp2ywxg089UriCZaSExd86J3t9jz86Mvy4qCRAL19DksVat9XCm3zRmYJpso5.ttf","sans-serif","https://fonts.gstatic.com/s/dmsans/v14/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxRT23z.ttf",[298,299],"latin","latin-ext",[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"100","200","300","regular","500","600","800","900","100italic","200italic","300italic","italic","500italic","600italic","700italic","800italic","900italic","Zero-day phishing protection","Detect phishing TTPs directly in the browser and stop credential theft.","faFishingRod",[322,421],{"@type":106,"@version":107,"tagName":323,"id":324,"children":325},"div","builder-76c6b8d1499346c7bc1fd56ae4e93638",[326,343,351,358,370,385,396,407,413],{"@type":106,"@version":107,"layerName":327,"id":328,"component":329,"responsiveStyles":340},"UseCaseHero","builder-5228fe062bef4a40a91e43f1112832fa",{"name":327,"options":330,"isRSC":118},{"title":318,"description":331,"points":332,"video":339},"\u003Cp>Push detects phishing as it happens. Autonomous agents hunt for new phishing techniques, identify kit signatures, and deploy detections within minutes of a new attack being analyzed. From cloned login pages to AiTM credential harvesting, Push sees what traditional filters miss and stops threats before they escalate.\u003C/p>",[333,335,337],{"item":334},"Detect phishing that bypasses traditional filters, including AiTM, SSO password theft, and fake login pages",{"item":336},"Stop never-before-seen attacks with AI-native behavioral and on-page analysis inside the browser",{"item":338},"Investigate faster with unified browser, user, and page context","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F40433ceeb4f94b43a82e039a0f4fd411%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=40433ceeb4f94b43a82e039a0f4fd411&alt=media&optimized=true",{"large":341},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},"transparent",{"@type":106,"@version":107,"id":344,"component":345,"responsiveStyles":348},"builder-96634044407e491299e291ed64669e39",{"name":346,"options":347,"isRSC":118},"TrustedBy",{"AllPartners":41,"backgroundTransparent":6},{"large":349},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},"#000",{"@type":106,"@version":107,"id":352,"component":353,"responsiveStyles":356},"builder-2c3768f930534557bb8978e32b6a6a0f",{"name":354,"options":355,"isRSC":118},"Diagonal",{"darkMode":41},{"large":357},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":360,"component":361,"responsiveStyles":368},"TextImageBlockVertical","builder-7c3c1c2840424db2ad2ccbfaf382dd64",{"name":359,"tag":359,"options":362,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":365,"description":366,"animatedTitle":37,"image":367,"reverse":6,"descriptionPaddingHorizontal":118},1200,800,"\u003Ch2>Why stop at the inbox?\u003C/h2>","\u003Cp>Phishing attacks have evolved. Whether attackers lure users with QR codes, instant messages, or OAuth consent screens, the outcome is the same: it plays out in the browser. Push gives you real-time detection for in-browser threats, stopping phishing and consent-based attacks before they lead to compromise\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7fdcac241f0e4a049166d7076858adeb",{"large":369},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":371,"component":372,"responsiveStyles":380},"builder-41c978b3669749cf947e622b4e79e4d7",{"name":373,"options":374,"isRSC":118},"TextImageBlockHorizontal",{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":377,"description":378,"reverse":41,"image":379},600,100,"\u003Cp>Detect phishing at the edge\u003C/p>","\u003Cp>Push uses industry-first telemetry to detect phishing based on behavior, not static indicators. Autonomous agents analyze how phishing pages behave and how users interact with them, uncovering fake logins, credential theft, and phishing kits the moment they load in the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9df3d180c97b4e61af142af2ccd68721",{"large":381},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},"DM Sans, sans-serif","20px","0px",{"@type":106,"@version":107,"id":386,"component":387,"responsiveStyles":393},"builder-d2a7bc941feb43cdb898bc116b203cf9",{"name":373,"options":388,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":390,"description":391,"reverse":6,"image":392},120,"\u003Ch2>Go beyond blocklists and IOCs\u003C/h2>","\u003Cp>Push goes beyond URLs and easy-to-change indicators. It reads the full phishing playbook like script behavior, session hijacks, DOM changes, user inputs, then connects the dots in real time. This gives your team a complete picture of how the phishing attempt worked, not just an alert.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fabfd58db169b433e96d3f1261797156e",{"large":394},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},"36px",{"@type":106,"@version":107,"layerName":373,"id":397,"component":398,"responsiveStyles":404},"builder-42c32198083f4880acb37c5cb76934da",{"name":373,"options":399,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":401,"description":402,"reverse":41,"image":403},140,"\u003Ch2>Enhance your phishing response\u003C/h2>","\u003Cp>When phishing enters your environment, speed matters. Push gives you instant access to the telemetry that counts like session data, user behavior, and page activity, so you can investigate fast, trigger in-browser prompts, or forward alerts to your SIEM or SOAR for response. All in real time, right from the browser.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbb195aec46904056b85e8688629e558e",{"large":405},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},"47px",{"@type":106,"@version":107,"id":408,"component":409,"responsiveStyles":411},"builder-9a95b9cbc4854421a92ef7b90f6c7adb",{"name":354,"options":410,"isRSC":118},{"darkMode":6},{"large":412},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":414,"component":415,"responsiveStyles":419},"builder-0afa17a9f25c4661a90f314d5578aa18",{"name":416,"tag":416,"options":417,"isRSC":118},"LatestResources",{"sectionHeading":37,"customClass":418},"bg-black",{"large":420},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":422,"@type":106,"tagName":131,"properties":423,"responsiveStyles":424},"builder-pixel-21yj6h3p4wh",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":425},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":427},{"path":37,"query":428},{},{},1776275046831,1745499158657,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fff60c30a8442489c8ed7e0af9599d14f","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"lastPreviewUrl":436,"winningTest":118,"breakpoints":437,"kind":438,"hasLinks":6,"originalContentId":439,"hasAutosaves":6},"https://pushsecurity.com/uc/zero-day-phishing-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=387451215c314dd5bd654668cdc1a197&builder.overrides.387451215c314dd5bd654668cdc1a197=387451215c314dd5bd654668cdc1a197&builder.overrides.use-case-page:/uc/zero-day-phishing-protection=387451215c314dd5bd654668cdc1a197&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},"page","2daa5670b8504fc7ba4700633e8bd921","atvz4dp24b7",{"createdDate":442,"id":443,"name":444,"modelId":261,"published":13,"stageModifiedSincePublish":6,"query":445,"data":448,"variations":552,"lastUpdated":553,"firstPublished":554,"testRatio":33,"screenshot":555,"createdBy":34,"lastUpdatedBy":433,"folders":556,"meta":557,"rev":440},1756833377777,"54f8256648f54d439303734b1e69221b","Browser extension security",[446],{"@type":264,"property":265,"operator":266,"value":447},"/uc/browser-extension-security",{"seoDescription":449,"jsCode":37,"fontAwesomeIcon":450,"tsCode":37,"title":444,"seoTitle":444,"customFonts":451,"inputs":456,"blocks":457,"url":447,"state":549},"Shine a light on risky browser extensions.","faPuzzlePiece",[452],{"kind":273,"family":272,"version":274,"files":453,"category":295,"lastModified":275,"subsets":454,"variants":455,"menu":296},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"100italic":288,"italic":289,"regular":290,"900italic":286,"800italic":285,"700italic":287,"200italic":291,"300italic":293,"500italic":292,"600italic":294},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],[],[458,544],{"@type":106,"@version":107,"tagName":323,"id":459,"meta":460,"children":461},"builder-71d0648c1d2f4ede8d0d0b5b28b7b94c",{"previousId":324},[462,478,485,492,501,511,521,531,538],{"@type":106,"@version":107,"id":463,"meta":464,"component":465,"responsiveStyles":476},"builder-ff325b4b8fad4edea53f38865947e854",{"previousId":328},{"name":327,"options":466,"isRSC":118},{"title":444,"description":467,"points":468,"video":475},"\u003Cp>Browser extensions introduce new code, new permissions, and new potential for risk. Many include AI features, and most go completely unnoticed. Push gives you full visibility into every extension used across your workforce, across major browsers, so you can uncover shadow IT, assess risky permissions, and block unsafe tools before they lead to compromise.\u003C/p>",[469,471,473],{"item":470},"Discover every browser extension in use",{"item":472},"Spot risky or unsanctioned behavior",{"item":474},"Make informed decisions on extension policy","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc538aad95d7f403aa3c3551af72f67c0?alt=media&token=1411fa6d-2eac-4e6c-94bf-ea117da12d67&apiKey=f3a1111ff5be48cdbb123cd9f5795a05",{"large":477},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":479,"meta":480,"component":481,"responsiveStyles":483},"builder-fb89d128c64e47cf9cbb11d90fc24523",{"previousId":344},{"name":346,"options":482,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":484},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":486,"meta":487,"component":488,"responsiveStyles":490},"builder-54388d35126c4d0096eeebaf8c4448cd",{"previousId":352},{"name":354,"options":489,"isRSC":118},{"darkMode":41},{"large":491},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"layerName":359,"id":493,"component":494,"responsiveStyles":499},"builder-3c8fa6785dd6466abf52a2470d66d85a",{"name":359,"tag":359,"options":495,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":496,"description":497,"image":498,"reverse":6},"\u003Ch2>Take control of browser extensions\u003C/h2>","\u003Cp>Attackers are increasingly using malicious browser extensions to gain access to data processed and stored in the browser. And the problem is, most security teams have no visibility into what extensions are being used. Push changes that. With browser-native telemetry, the Push extension continuously inventories browser extensions across your environment, flags the risky ones, and gives you intelligence to act.&nbsp;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0a004f16a6874f4c8fdf14344acc9fec",{"large":500},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":502,"meta":503,"component":504,"responsiveStyles":509},"builder-93738f98109a4009affb349afd7bb182",{"previousId":371},{"name":373,"options":505,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":506,"description":507,"reverse":41,"image":508},"\u003Ch2>Discover every extension in use\u003C/h2>","\u003Cp>Push gives you structured, searchable data about every extension in your environment, so you’re not just seeing what’s there, but also understanding how it got there, what it can do, and who it affects. It’s the kind of granular insight that’s nearly impossible to get from traditional tools, and it lays the groundwork for better policy decisions and faster investigations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0e5727ca99474f14b1b7916bf6bbb782",{"large":510},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":512,"meta":513,"component":514,"responsiveStyles":519},"builder-83393acb12ee4fdd840839185b51edb4",{"previousId":386},{"name":373,"options":515,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":516,"description":517,"reverse":6,"image":518},"\u003Ch2>Spot risky or malicious extensions\u003C/h2>","\u003Cp>Push highlights extensions with dangerous permissions, broad access, or poor reputations. This includes AI extensions that request access far beyond what their stated purpose requires. You can quickly detect sideloaded, manually installed, or development-mode extensions that bypass normal controls. And because Push shows you who’s using them and where, you can respond precisely and effectively.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa104d58c8da34fbb8901f738fb21453b",{"large":520},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":522,"meta":523,"component":524,"responsiveStyles":529},"builder-da98e3de949646d89c53a0d1c2784664",{"previousId":397},{"name":373,"options":525,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":526,"description":527,"reverse":41,"image":528},"\u003Ch2>Accelerate security reviews\u003C/h2>","\u003Cp>Most teams have extension policies, they just don’t have the data to enforce them. Push reveals how each extension entered your environment, whether it was installed manually, sideloaded, or deployed in dev mode. You’ll see which users are running what, and where, so you can surface violations, investigate quickly, and respond with confidence.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F229f355be6f243b180f410d237a75bb3",{"large":530},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":532,"meta":533,"component":534,"responsiveStyles":536},"builder-1a689287d1a1418997d57db578a71105",{"previousId":408},{"name":354,"options":535,"isRSC":118},{"darkMode":6},{"large":537},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":539,"component":540,"responsiveStyles":542},"builder-feb4e75029f84c10b6498ef1f8f79128",{"name":416,"tag":416,"options":541,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":543},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":545,"@type":106,"tagName":131,"properties":546,"responsiveStyles":547},"builder-pixel-0edn39avfcei",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":548},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":550},{"path":37,"query":551},{},{},1776275365038,1757000441666,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8d496cf111644ee5afcc046b72d1ca5a",[],{"kind":438,"winningTest":118,"breakpoints":558,"lastPreviewUrl":559,"hasLinks":6,"originalContentId":259,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/browser-extension-security?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=54f8256648f54d439303734b1e69221b&builder.overrides.54f8256648f54d439303734b1e69221b=54f8256648f54d439303734b1e69221b&builder.overrides.use-case-page:/uc/browser-extension-security=54f8256648f54d439303734b1e69221b&builder.options.locale=Default",{"createdDate":561,"id":562,"name":563,"modelId":261,"published":13,"query":564,"data":567,"variations":670,"lastUpdated":671,"firstPublished":672,"testRatio":33,"screenshot":673,"createdBy":34,"lastUpdatedBy":674,"folders":675,"meta":676,"rev":440},1744923509705,"94bebb7bb99d48629ad157e80cf4d81d","Account takeover detection",[565],{"@type":264,"property":265,"operator":266,"value":566},"/uc/account-takeover-detection",{"title":563,"customFonts":568,"jsCode":37,"seoTitle":563,"seoDescription":573,"fontAwesomeIcon":574,"tsCode":37,"blocks":575,"url":566,"state":667},[569],{"kind":273,"category":295,"variants":570,"menu":296,"files":571,"family":272,"subsets":572,"version":274,"lastModified":275},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"800italic":285,"700italic":287,"italic":289,"900italic":286,"600italic":294,"200italic":291,"regular":290,"100italic":288},[298,299],"Stop ATO with stolen credential and compromised token detection.","faUserSecret",[576,662],{"@type":106,"@version":107,"tagName":323,"id":577,"meta":578,"children":579},"builder-e7913a774cae44c5a23d6081c5c30a52",{"previousId":324},[580,596,603,610,619,629,639,649,656],{"@type":106,"@version":107,"id":581,"meta":582,"component":583,"responsiveStyles":594},"builder-f1f1ab1601bc4c0f8c2a8aafd173675d",{"previousId":328},{"name":327,"options":584,"isRSC":118},{"title":563,"description":585,"points":586,"video":593},"\u003Cp>Attackers don’t need to phish, they just need a password that works. Push monitors for signs of credential-based attacks in real time, directly in the browser, catching account takeover attempts before the damage spreads. From ghost logins to credential stuffing, Push cuts off the paths attackers use to quietly slip in the back door.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[587,589,591],{"item":588},"Identify credential-based ATO as it unfolds",{"item":590},"Surface hijacked sessions and token misuse",{"item":592},"Strengthen authentication where your IdP can’t","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb4dd9db24bc9495b8a686b1b4d492016%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=b4dd9db24bc9495b8a686b1b4d492016&alt=media&optimized=true",{"large":595},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":597,"meta":598,"component":599,"responsiveStyles":601},"builder-0bc0d1c78ece4994993c3a6427a4d533",{"previousId":344},{"name":346,"options":600,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":602},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":604,"meta":605,"component":606,"responsiveStyles":608},"builder-e45de8f3768c4f16938dbf78e4e87524",{"previousId":352},{"name":354,"options":607,"isRSC":118},{"darkMode":41},{"large":609},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":611,"component":612,"responsiveStyles":617},"builder-c98e8bfd341146c1b67c02d5698ff093",{"name":359,"tag":359,"options":613,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":614,"description":615,"image":616,"reverse":6},"\u003Ch2>Assume less. See more.\u003C/h2>","\u003Cp>Most account takeovers don’t start with a breach, they start with a login. Whether it’s a reused password, a local account, or an outdated login flow, Push shows you how accounts are actually accessed day to day, not just how policies say they should be. That means no more blind spots around ghost logins, bypassed SSO, or stale access paths that quietly persist.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F18630ad2746d4eb7b7fcc0428b11a8f0",{"large":618},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":620,"meta":621,"component":622,"responsiveStyles":627},"builder-55c1fc38ddc04fd1a0d6a8e2fb819e00",{"previousId":371},{"name":373,"options":623,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":624,"description":625,"reverse":41,"image":626},"\u003Ch2>Catch stolen credential use in real time\u003C/h2>","\u003Cp>Push monitors login activity directly in the browser to detect signs of credential-based attacks like leaked password use or suspicious login flows. By analyzing attacker TTPs instead of relying on known indicators, Push spots credential stuffing and account takeover attempts the moment they begin, not after they’ve succeeded.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F52b0123cac2c4dfdb1dc0af6adf9d603",{"large":628},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":630,"meta":631,"component":632,"responsiveStyles":637},"builder-dfb31737b30948c6b95323655d571a50",{"previousId":386},{"name":373,"options":633,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":634,"description":635,"reverse":6,"image":636},"\u003Ch2>Detect session hijacks and stealth access\u003C/h2>","\u003Cp>Attackers don’t always need a login screen, they often sidestep it entirely using stolen session tokens. Push detects when valid sessions are reused in unexpected ways, identifying hijacked sessions and stealth access attempts that traditional tools miss. Because we monitor directly in the browser, you see what’s happening inside active sessions in real time.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F94a6859a99e04d309ffe5841f3dbdf5c",{"large":638},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":640,"meta":641,"component":642,"responsiveStyles":647},"builder-f7585b90eb974d03a7dc7eae5b58d227",{"previousId":397},{"name":373,"options":643,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":644,"description":645,"reverse":41,"image":646},"\u003Ch2>Harden accounts before they’re compromised\u003C/h2>","\u003Cp>Push goes beyond alerts. It identifies apps that still allow local logins, even when SSO is configured, so you can remove weak access paths. Push also flags users without MFA, reused work credentials, or weak passwords, and prompts users in-browser to fix risky behaviors before they’re exploited.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01c1b638f1b6497093a4f2b8ceddb5bb",{"large":648},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":650,"meta":651,"component":652,"responsiveStyles":654},"builder-ad81d1e3afec49a791214194eae09bdc",{"previousId":408},{"name":354,"options":653,"isRSC":118},{"darkMode":6},{"large":655},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":657,"component":658,"responsiveStyles":660},"builder-8dac1aa4b9d148628d92252bd8eff822",{"name":416,"tag":416,"options":659,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":661},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":663,"@type":106,"tagName":131,"properties":664,"responsiveStyles":665},"builder-pixel-s5u3wmvz7jq",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":666},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":668},{"path":37,"query":669},{},{},1770892814499,1745499162732,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F58b660fa94aa4b30b0faeb9b663ae41a","SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":677,"hasLinks":6,"originalContentId":259,"breakpoints":678,"winningTest":118,"kind":438,"hasAutosaves":41},"https://pushsecurity.com/uc/account-takeover-detection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.94bebb7bb99d48629ad157e80cf4d81d=94bebb7bb99d48629ad157e80cf4d81d&builder.overrides.use-case-page:/uc/account-takeover-detection=94bebb7bb99d48629ad157e80cf4d81d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":680,"id":681,"name":682,"modelId":261,"published":13,"query":683,"data":686,"variations":789,"lastUpdated":790,"firstPublished":791,"testRatio":33,"screenshot":792,"createdBy":34,"lastUpdatedBy":674,"folders":793,"meta":794,"rev":440},1745009370904,"23eb48fb56d3451cab77cb6ed140ee6d","Attack path hardening",[684],{"@type":264,"property":265,"operator":266,"value":685},"/uc/attack-path-hardening",{"tsCode":37,"seoDescription":687,"jsCode":37,"customFonts":688,"fontAwesomeIcon":693,"seoTitle":682,"title":682,"blocks":694,"url":685,"state":786},"Harden access paths with visibility,  detection, and guardrails.",[689],{"kind":273,"files":690,"version":274,"lastModified":275,"subsets":691,"menu":296,"category":295,"variants":692,"family":272},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"regular":290,"italic":289,"800italic":285,"500italic":292,"600italic":294,"200italic":291,"900italic":286,"700italic":287,"100italic":288,"300italic":293},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"faRadar",[695,781],{"@type":106,"@version":107,"tagName":323,"id":696,"meta":697,"children":698},"builder-1d8553eddcaa44d7bba9e2f4ca13af2a",{"previousId":577},[699,715,722,729,738,748,758,768,775],{"@type":106,"@version":107,"id":700,"meta":701,"component":702,"responsiveStyles":713},"builder-84fe3d7c85a743cf8cef649aa974f1ef",{"previousId":581},{"name":327,"options":703,"isRSC":118},{"title":682,"description":704,"points":705,"video":712},"\u003Cp>Push continuously monitors your environment for exposed login paths, weak credentials, and missing protections like MFA. It detects the gaps attackers exploit and helps you close them before they’re used.\u003C/p>",[706,708,710],{"item":707},"Find weak spots like reused passwords, local logins, and missing MFA",{"item":709},"Monitor how users actually log in across apps, flows, and tools",{"item":711},"Enforce secure access with in-browser guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fdbdcf52892034f1bbddded77f753a343%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=dbdcf52892034f1bbddded77f753a343&alt=media&optimized=true",{"large":714},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":716,"meta":717,"component":718,"responsiveStyles":720},"builder-b3f66f5b08054cc78a06fecfc3ae2337",{"previousId":597},{"name":346,"options":719,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":721},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":723,"meta":724,"component":725,"responsiveStyles":727},"builder-4c73418b84be49ed85e6e13d2625c5a0",{"previousId":604},{"name":354,"options":726,"isRSC":118},{"darkMode":41},{"large":728},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":730,"component":731,"responsiveStyles":736},"builder-dec0246085e1485c803f7152b1922a81",{"name":359,"tag":359,"options":732,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":733,"description":734,"image":735,"reverse":6},"\u003Ch2>Find the gaps that lead to compromise\u003C/h2>","\u003Cp>Misconfigurations don’t show up in your config files, they show up in how users actually access apps. Push monitors real login behavior in the browser, surfacing risky patterns like local login access, duplicate accounts, or missing protections that leave doors wide open.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F309a59bba8d247a19476bb369397460e",{"large":737},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":739,"meta":740,"component":741,"responsiveStyles":746},"builder-ebf049a645604a249550996a88f8f3b6",{"previousId":620},{"name":373,"options":742,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":743,"description":744,"reverse":41,"image":745},"\u003Ch2>See real login behavior\u003C/h2>","\u003Cp>Push watches authentication flows as they happen, giving you a live view of how users log in, which methods they choose, and where protections like MFA are missing. Plus, uncover every app and account in use, even shadow IT you didn’t know existed, without relying on stale config files or IdP assumptions. \u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb51f6b0357cc451b87a7a5016d984e5e",{"large":747},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":749,"meta":750,"component":751,"responsiveStyles":756},"builder-431d175c59004669b0b2776b07d71737",{"previousId":630},{"name":373,"options":752,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":753,"description":754,"reverse":6,"image":755},"\u003Ch2>Find and fix posture drift\u003C/h2>","\u003Cp>Security posture isn’t static. Push continuously monitors for issues like missing MFA or legacy login methods. When something falls out of policy, you know immediately with custom notifications so you can act before it turns into risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F324e39127dfc41e592b1183dfb39892d",{"large":757},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":759,"meta":760,"component":761,"responsiveStyles":766},"builder-3dffdcbe0a484e2ca4c03f019b6d40ee",{"previousId":640},{"name":373,"options":762,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":763,"description":764,"reverse":41,"image":765},"\u003Ch2>Guide users with in-browser guardrails\u003C/h2>","\u003Cp>Push doesn’t just surface problems, it helps you fix them. When users sign in without MFA, reuse a password, or use insecure credentials, Push prompts them directly in the browser to secure their access. It’s faster, more effective, and actually gets results.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fee8b75d13e45488aba55434a8b49ebb0",{"large":767},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":769,"meta":770,"component":771,"responsiveStyles":773},"builder-976bc222cd7647ff905f1e01cfedc453",{"previousId":650},{"name":354,"options":772,"isRSC":118},{"darkMode":6},{"large":774},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":776,"component":777,"responsiveStyles":779},"builder-8c47ec2fd0f74382bb3e6c870555632c",{"name":416,"tag":416,"options":778,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":780},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":782,"@type":106,"tagName":131,"properties":783,"responsiveStyles":784},"builder-pixel-7akm7dayau8",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":785},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":787},{"path":37,"query":788},{},{},1770892844854,1745499166112,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6ca12bf728a045f1a31d40c0beb3bfe5",[],{"kind":438,"lastPreviewUrl":795,"breakpoints":796,"hasLinks":6,"originalContentId":562,"winningTest":118,"hasAutosaves":6},"https://pushsecurity.com/uc/attack-path-hardening?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.23eb48fb56d3451cab77cb6ed140ee6d=23eb48fb56d3451cab77cb6ed140ee6d&builder.overrides.use-case-page:/uc/attack-path-hardening=23eb48fb56d3451cab77cb6ed140ee6d&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":798,"id":799,"name":800,"modelId":261,"published":13,"query":801,"data":804,"variations":909,"lastUpdated":910,"firstPublished":911,"testRatio":33,"screenshot":912,"createdBy":34,"lastUpdatedBy":674,"folders":913,"meta":914,"rev":440},1761675020232,"ea4f309d2ffe46c5aa97ebf0fda4e2e3","ClickFix Protection",[802],{"@type":264,"property":265,"operator":266,"value":803},"/uc/clickfix-protection",{"seoDescription":805,"fontAwesomeIcon":806,"customFonts":807,"seoTitle":812,"jsCode":37,"tsCode":37,"title":812,"blocks":813,"url":803,"state":906},"Block attacks that trick users into running malicious code.","faLaptopCode",[808],{"files":809,"subsets":810,"menu":296,"version":274,"kind":273,"family":272,"lastModified":275,"variants":811,"category":295},{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"200italic":291,"800italic":285,"700italic":287,"600italic":294,"100italic":288,"italic":289,"regular":290,"300italic":293,"500italic":292,"900italic":286},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],"ClickFix protection",[814,901],{"@type":106,"@version":107,"tagName":323,"id":815,"meta":816,"children":817},"builder-d7eefdde0f2a4b2b9de3dcb2978fd6cb",{"previousId":696},[818,834,841,848,858,868,878,888,895],{"@type":106,"@version":107,"id":819,"meta":820,"component":821,"responsiveStyles":832},"builder-56e2c54bcce040a4af8b92ae03706c12",{"previousId":700},{"name":327,"options":822,"isRSC":118},{"title":812,"description":823,"points":824,"image":831},"\u003Cp>ClickFix attacks are one of the fastest-growing threats, tricking users into copying malicious code from a webpage and running it locally. This technique bypasses traditional EDR, email gateways, and network filters, leading directly to ransomware and data theft. Push stops this attack at the source, in the browser, by detecting and blocking the malicious behavior before the user can ever paste the code.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[825,827,829],{"item":826},"Detect ClickFix, FileFix, and fake CAPTCHA in the browser",{"item":828},"Block malicious copy-and-paste actions before code is executed",{"item":830},"See full telemetry into which users were targeted and what they saw","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b74af62889847ebb3927364485b0546",{"large":833},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":835,"meta":836,"component":837,"responsiveStyles":839},"builder-05f9614d4e3e4dc88b3ee8658f54e10e",{"previousId":716},{"name":346,"options":838,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":840},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":842,"meta":843,"component":844,"responsiveStyles":846},"builder-c4fb5179366243c1b6c32d368675cf47",{"previousId":723},{"name":354,"options":845,"isRSC":118},{"darkMode":41},{"large":847},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":849,"meta":850,"component":851,"responsiveStyles":856},"builder-261af50705fd445d8cca4a6ba20d5391",{"previousId":730},{"name":359,"tag":359,"options":852,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":853,"description":854,"reverse":6,"image":855},"\u003Ch2>Stop ClickFix-style attacks before they become a breach\u003C/h2>","\u003Cp>Traditional security tools are blind to malicious copy and paste attacks because the attack exploits a gap between the browser and the endpoint. EDR only sees the payload after it runs, and network tools see only part of the picture.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F98b2f7e08dec4eafaf8e24937605b8cf",{"large":857},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":859,"meta":860,"component":861,"responsiveStyles":866},"builder-7d21b8aab8064c40b1e5dd23c4749309",{"previousId":739},{"name":373,"options":862,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":863,"description":864,"reverse":41,"image":865},"\u003Ch2>Discover lures at the source\u003C/h2>","\u003Cp>Push inspects page behavior to identify ClickFix attacks as they happen. By inspecting the page, its structure, and how the user interacts with it, Push can detect and block these in-browser threats in real time. This deep, TTP-based inspection spots the trap even on novel pages that are built to bypass traditional web filters and blocklists.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F665bf47e01544c75bf9ddafd3917927b",{"large":867},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":383,"marginTop":384},{"@type":106,"@version":107,"id":869,"meta":870,"component":871,"responsiveStyles":876},"builder-fb91943adf6149259ed9e1e6566c9afe",{"previousId":749},{"name":373,"options":872,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":873,"description":874,"reverse":6,"image":875},"\u003Ch2>Block the malicious action\u003C/h2>","\u003Cp>When Push detects a malicious script, it intercepts the user's action and blocks the code from being copied to the clipboard. The user is protected, the attack is stopped, and no malicious code ever reaches the endpoint. Unlike broad DLP tools, this action is surgical, targeting only malicious behavior without disrupting normal work.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5ee68f81f1ac416685cbfe91298cf827",{"large":877},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":879,"meta":880,"component":881,"responsiveStyles":886},"builder-bfac95fada864e5a8259b955b5b5f98b",{"previousId":759},{"name":373,"options":882,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":883,"description":884,"reverse":41,"image":885},"\u003Ch2>Accelerate ClickFix investigations\u003C/h2>","\u003Cp>When an attack happens, knowing what the user saw or did is critical. Push provides rich browser session data for rapid investigation and containment. Security teams get detailed telemetry on which users were targeted, what lure they were served, and when the block occurred. This enables defenders to reconstruct what happened and respond quickly, even when other tools miss the activity entirely.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6cdf2a8aeddc4e9a9023cbf974e40239",{"large":887},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":889,"meta":890,"component":891,"responsiveStyles":893},"builder-136892e831684a6987f87d3be67c33d1",{"previousId":769},{"name":354,"options":892,"isRSC":118},{"darkMode":6},{"large":894},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":896,"component":897,"responsiveStyles":899},"builder-dec26b739f2f42beb5a73cfc6c675b60",{"name":416,"tag":416,"options":898,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":900},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":902,"@type":106,"tagName":131,"properties":903,"responsiveStyles":904},"builder-pixel-zzjpxxgrc2l",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":905},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":907},{"path":37,"query":908},{},{},1770892881888,1761847585203,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F375467b8bef34ed1a8a1cc5b8b67d75f",[],{"lastPreviewUrl":915,"originalContentId":681,"winningTest":118,"hasLinks":6,"kind":438,"breakpoints":916,"hasAutosaves":6},"https://pushsecurity.com/uc/clickfix-protection?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.ea4f309d2ffe46c5aa97ebf0fda4e2e3=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.overrides.use-case-page:/uc/clickfix-protection=ea4f309d2ffe46c5aa97ebf0fda4e2e3&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":918,"id":919,"name":920,"modelId":261,"published":13,"query":921,"data":924,"variations":1029,"lastUpdated":1030,"firstPublished":1031,"testRatio":33,"screenshot":1032,"createdBy":34,"lastUpdatedBy":674,"folders":1033,"meta":1034,"rev":440},1745009743870,"a9d5556e77f84a37b5bd52310a7110c1","Incident response",[922],{"@type":264,"property":265,"operator":266,"value":923},"/uc/incident-response",{"seoDescription":925,"customFonts":926,"title":920,"jsCode":37,"fontAwesomeIcon":931,"seoTitle":932,"tsCode":37,"blocks":933,"url":923,"state":1026},"Investigate and respond faster with unique browser telemetry.",[927],{"kind":273,"subsets":928,"menu":296,"variants":929,"category":295,"family":272,"version":274,"lastModified":275,"files":930},[298,299],[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"900italic":286,"600italic":294,"200italic":291,"300italic":293,"100italic":288,"700italic":287,"800italic":285,"regular":290,"italic":289,"500italic":292},"faSatelliteDish","Browser based incident response",[934,1021],{"@type":106,"@version":107,"tagName":323,"id":935,"meta":936,"children":937},"builder-653c4aed737b4def88dc4cd2d695660a",{"previousId":696},[938,955,962,969,978,988,998,1008,1015],{"@type":106,"@version":107,"id":939,"meta":940,"component":941,"responsiveStyles":953},"builder-18190bd36518467d9154d27d7e945b9b",{"previousId":700},{"name":327,"options":942,"isRSC":118},{"title":943,"description":944,"points":945,"video":952},"Browser-based incident response","\u003Cp>Push gives you real-time visibility into what actually happened during a breach, right in the browser where the attack played out. From credential theft to session hijacking, Push captures high-fidelity telemetry so you can investigate quickly, contain confidently, and shut it down before it spreads.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>",[946,948,950],{"item":947},"Reconstruct what happened with real browser session context",{"item":949},"Investigate faster with real-world session context",{"item":951},"Trigger response actions automatically through your SIEM or SOAR","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd00e39d3b6e346c296261d875cf55652%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=d00e39d3b6e346c296261d875cf55652&alt=media&optimized=true",{"large":954},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":956,"meta":957,"component":958,"responsiveStyles":960},"builder-8a0a8ea63f5d48dd8a6726f2d49cf0ca",{"previousId":716},{"name":346,"options":959,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":961},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":963,"meta":964,"component":965,"responsiveStyles":967},"builder-2df65c3f54334df2b26e7cb744886cdc",{"previousId":723},{"name":354,"options":966,"isRSC":118},{"darkMode":41},{"large":968},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":970,"component":971,"responsiveStyles":976},"builder-2c32c869efc2423ab69ef06b150e9f97",{"name":359,"tag":359,"options":972,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":973,"description":974,"image":975,"reverse":6},"\u003Ch2>See attacks unfold, not just their aftermath\u003C/h2>","\u003Cp>Attacks happen in the browser, not in logs. Push captures what traditional tools miss: what users clicked, what loaded, what was entered, and how attackers moved. That gives you real-world evidence, not just assumptions, when every second matters.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F36fc719bd1de4a38b916f4d25c81a26d",{"large":977},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":979,"meta":980,"component":981,"responsiveStyles":986},"builder-370e53c6016e432db01e9193a2ce90f6",{"previousId":739},{"name":373,"options":982,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":983,"description":984,"reverse":41,"image":985},"\u003Ch2>Investigate faster with high-fidelity data\u003C/h2>","\u003Cp>Reconstructing an incident shouldn’t feel like guesswork. Push records detailed telemetry from inside the browser: page loads, credential inputs, DOM changes, session activity, user behavior. It’s structured, exportable, and ready to plug into your investigation workflows, so you can move fast without digging through proxy logs or relying on user reports.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa6adda040e684e67a8d68a55c5ce5f6d",{"large":987},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":989,"meta":990,"component":991,"responsiveStyles":996},"builder-a7f3767a8d184bd08fb24520bf210e95",{"previousId":749},{"name":373,"options":992,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":993,"description":994,"reverse":6,"image":995},"\u003Ch2>Contain and respond in real time\u003C/h2>","\u003Cp>When something looks off, Push doesn’t just alert you, it gives you options. Guide users with in-browser prompts. Terminate sessions. Trigger SOAR workflows. Enrich SIEM alerts. Push gives you the context and control to stop spread before it starts.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb3dedeed5aba4847a2c2d22e10d0ec12",{"large":997},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":999,"meta":1000,"component":1001,"responsiveStyles":1006},"builder-b92036ee0ece4b32acdbdcc7c377366b",{"previousId":759},{"name":373,"options":1002,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1003,"description":1004,"reverse":41,"image":1005},"\u003Ch2>Prevent the next one\u003C/h2>","\u003Cp>Push helps you respond fast, but it also helps you fix what went wrong. It surfaces misconfigurations and risky behaviors that made the attack possible in the first place, then guides users in-browser to remediate. One tool. Full loop. No loose ends.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc1ecc2d5d3814b62b072fac01827ff96",{"large":1007},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1009,"meta":1010,"component":1011,"responsiveStyles":1013},"builder-5e8ae39655274de89da32ab573a2525a",{"previousId":769},{"name":354,"options":1012,"isRSC":118},{"darkMode":6},{"large":1014},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1016,"component":1017,"responsiveStyles":1019},"builder-dfd6850cfb4741d2b8a0c16c2780f00a",{"name":416,"tag":416,"options":1018,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1020},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1022,"@type":106,"tagName":131,"properties":1023,"responsiveStyles":1024},"builder-pixel-z197gdgcmu",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1025},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1027},{"path":37,"query":1028},{},{},1770892908052,1745427419274,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb07017bfd318431690a5bb35bda35b99",[],{"kind":438,"breakpoints":1035,"originalContentId":681,"winningTest":118,"lastPreviewUrl":1036,"hasLinks":6,"hasAutosaves":6},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/incident-response?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.a9d5556e77f84a37b5bd52310a7110c1=a9d5556e77f84a37b5bd52310a7110c1&builder.overrides.use-case-page:/uc/incident-response=a9d5556e77f84a37b5bd52310a7110c1&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"createdDate":1038,"id":1039,"name":1040,"modelId":261,"published":13,"query":1041,"data":1044,"variations":1149,"lastUpdated":1150,"firstPublished":1151,"testRatio":33,"screenshot":1152,"createdBy":34,"lastUpdatedBy":674,"folders":1153,"meta":1154,"rev":440},1746122471259,"5f118e24433d46ceb79f5099987156d7","Shadow SaaS",[1042],{"@type":264,"property":265,"operator":266,"value":1043},"/uc/shadow-saas",{"seoTitle":1045,"seoDescription":1046,"customFonts":1047,"fontAwesomeIcon":1052,"title":1053,"jsCode":37,"tsCode":37,"blocks":1054,"url":1043,"state":1146},"Find and secure shadow SaaS","See and control shadow SaaS in the browser.",[1048],{"kind":273,"variants":1049,"files":1050,"family":272,"version":274,"subsets":1051,"lastModified":275,"category":295,"menu":296},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"300italic":293,"500italic":292,"regular":290,"900italic":286,"italic":289,"100italic":288,"200italic":291,"600italic":294,"700italic":287,"800italic":285},[298,299],"faShieldCheck","Secure shadow SaaS",[1055,1141],{"@type":106,"@version":107,"tagName":323,"id":1056,"meta":1057,"children":1058},"builder-04da805c4cd34652a2db452fcda52e1d",{"previousId":935},[1059,1075,1082,1089,1098,1108,1118,1128,1135],{"@type":106,"@version":107,"id":1060,"meta":1061,"component":1062,"responsiveStyles":1073},"builder-830d414faeaf41439142f9157e8288c8",{"previousId":939},{"name":327,"options":1063,"isRSC":118},{"title":1045,"description":1064,"points":1065,"video":1072},"\u003Cp>SaaS sprawl is one of today’s fastest-growing security blind spots because most tools monitor around the edges. Push sees it at the source, in the browser, revealing every app users access, flagging risky tools, and helping you shut down exposure before it leads to a breach. No guesswork. No nasty surprises. Just real-time visibility and control.\u003C/p>",[1066,1068,1070],{"item":1067},"Discover every SaaS app users access, managed or not",{"item":1069},"Spot accounts with weak security postures like missing MFA, unmanaged access, and no SSO",{"item":1071},"Control usage with in-browser prompts, blocks, and security guardrails","https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3e4eece318d04d6586e691d59d0741cf%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=3e4eece318d04d6586e691d59d0741cf&alt=media&optimized=true",{"large":1074},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1076,"meta":1077,"component":1078,"responsiveStyles":1080},"builder-cd7833f966cb4c7e8adf0d6c979414a6",{"previousId":956},{"name":346,"options":1079,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1081},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1083,"meta":1084,"component":1085,"responsiveStyles":1087},"builder-49d720b45430454e8b08c526f267c19f",{"previousId":963},{"name":354,"options":1086,"isRSC":118},{"darkMode":41},{"large":1088},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1090,"component":1091,"responsiveStyles":1096},"builder-3dde0bf6c8544e5e9ab41b18a9d68034",{"name":359,"tag":359,"options":1092,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1093,"description":1094,"image":1095,"reverse":6},"\u003Ch2>Use your browser to curb Saas Sprawl\u003C/h2>","\u003Cp>Shadow SaaS isn’t hiding in your network, it’s in your browser. From AI tools to unsanctioned file-sharing sites, security risks live in the apps your users sign into every day. Push maps your organization's true SaaS footprint in real time, exposing apps and accounts with unmanaged access, poor authentication, or no security oversight.\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6811a214c7949b6bbe0b9a3bca62efd",{"large":1097},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1099,"meta":1100,"component":1101,"responsiveStyles":1106},"builder-e2420451ccdc4f088d0a4904cff45935",{"previousId":979},{"name":373,"options":1102,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1103,"description":1104,"reverse":41,"image":1105},"\u003Ch2>Discover hidden SaaS usage\u003C/h2>","\u003Cp>Push captures live browser telemetry across every tab and session. Whether a user signs into a sanctioned app with a personal account or tries a new AI plugin, you’ll see it in real time, with no integrations or manual tagging.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe16e301f9af94665b95d98232a863d8a",{"large":1107},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1109,"meta":1110,"component":1111,"responsiveStyles":1116},"builder-b36de7fce7994beea9e58d94662e7166",{"previousId":989},{"name":373,"options":1112,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1113,"description":1114,"reverse":6,"image":1115},"\u003Ch2>Spot risky access and unsafe usage\u003C/h2>","\u003Cp>Discovery is just the beginning. Push flags apps with risky traits, no MFA, no SSO, known vulnerabilities, or broad access scopes. You’ll know which tools introduce real risk, and which users are exposed so you can act with precision.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F6585f3c242da4d70ae3cb7d02f481bef",{"large":1117},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1119,"meta":1120,"component":1121,"responsiveStyles":1126},"builder-dc366b5134684fe7a508edf8913103ea",{"previousId":999},{"name":373,"options":1122,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1123,"description":1124,"reverse":41,"image":1125},"\u003Ch2>Close gaps before they grow\u003C/h2>","\u003Cp>Push turns insight into action. When risky SaaS use is detected, guide users to enable MFA, block high-risk apps, or apply in-browser guardrails automatically. All without deploying new infrastructure or managing dozens of integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe6d60b6d91414819bc6258a318f00557",{"large":1127},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1129,"meta":1130,"component":1131,"responsiveStyles":1133},"builder-8708f6f0d8da4b3f9e17bf16cda70219",{"previousId":1009},{"name":354,"options":1132,"isRSC":118},{"darkMode":6},{"large":1134},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1136,"component":1137,"responsiveStyles":1139},"builder-8ff4b38d60534cf28cb523ab0f754875",{"name":416,"tag":416,"options":1138,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1140},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1142,"@type":106,"tagName":131,"properties":1143,"responsiveStyles":1144},"builder-pixel-d1ul2kmxbed",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1145},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1147},{"path":37,"query":1148},{},{},1770892936802,1746714967208,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F01bfb2304521412fbd2e1a1180904d40",[],{"originalContentId":919,"winningTest":118,"lastPreviewUrl":1155,"breakpoints":1156,"kind":438,"hasLinks":6,"hasAutosaves":6},"https://pushsecurity.com/uc/shadow-saas?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=5f118e24433d46ceb79f5099987156d7&builder.overrides.5f118e24433d46ceb79f5099987156d7=5f118e24433d46ceb79f5099987156d7&builder.overrides.use-case-page:/uc/shadow-saas=5f118e24433d46ceb79f5099987156d7&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"xsmall":57,"small":39,"medium":40},{"createdDate":1158,"id":1159,"name":1160,"modelId":261,"published":13,"query":1161,"data":1164,"variations":1268,"lastUpdated":1269,"firstPublished":1270,"testRatio":33,"screenshot":1271,"createdBy":34,"lastUpdatedBy":674,"folders":1272,"meta":1273,"rev":440},1764707470172,"b62629ce2f3741158d961cd10fe74b31","Shadow AI",[1162],{"@type":264,"property":265,"operator":266,"value":1163},"/uc/shadow-ai",{"fontAwesomeIcon":1165,"seoTitle":1166,"jsCode":37,"customFonts":1167,"title":1172,"tsCode":37,"seoDescription":1173,"blocks":1174,"url":1163,"state":1265},"faBrainCircuit","Secure AI native and AI enhanced apps. ",[1168],{"variants":1169,"category":295,"files":1170,"subsets":1171,"family":272,"kind":273,"menu":296,"lastModified":275,"version":274},[301,302,303,304,305,306,128,307,308,309,310,311,312,313,314,315,316,317],{"100":277,"200":278,"300":279,"500":280,"600":281,"700":282,"800":283,"900":284,"800italic":285,"regular":290,"700italic":287,"200italic":291,"italic":289,"500italic":292,"600italic":294,"300italic":293,"100italic":288,"900italic":286},[298,299],"Secure shadow AI","See and control shadow AI apps in the browser.",[1175,1260],{"@type":106,"@version":107,"tagName":323,"id":1176,"meta":1177,"children":1178},"builder-a6e5717a2c914d5695058e4ee201a05d",{"previousId":1056},[1179,1195,1202,1209,1219,1228,1237,1247,1254],{"@type":106,"@version":107,"id":1180,"meta":1181,"component":1182,"responsiveStyles":1193},"builder-3e0ed678683f4a0eb7aa00253cf263b2",{"previousId":1060},{"name":327,"options":1183,"isRSC":118},{"title":1172,"description":1184,"points":1185,"image":1192},"\u003Cp>Your employees are adopting AI faster than you can track it. From native features in corporate apps to unapproved shadow tools, it’s all happening in the browser. Push detects every AI interaction in real time, letting you categorize apps and enforce acceptable use policies in the browser.\u003C/p>",[1186,1188,1190],{"item":1187},"Map every AI tool used across your workforce",{"item":1189},"Review and classify apps by sensitivity, purpose, and policy status",{"item":1191},"Enforce AI usage rules directly in the browser","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F33cf153d920f4e389f3650253577cff7",{"large":1194},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":342},{"@type":106,"@version":107,"id":1196,"meta":1197,"component":1198,"responsiveStyles":1200},"builder-76968f8471d14893b8189d75b08fb426",{"previousId":1076},{"name":346,"options":1199,"isRSC":118},{"AllPartners":41,"backgroundTransparent":6},{"large":1201},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"backgroundColor":350},{"@type":106,"@version":107,"id":1203,"meta":1204,"component":1205,"responsiveStyles":1207},"builder-b55b9d4bc5a649d8839ce7f6c2043d95",{"previousId":1083},{"name":354,"options":1206,"isRSC":118},{"darkMode":41},{"large":1208},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1210,"meta":1211,"component":1212,"responsiveStyles":1217},"builder-c3f38ef4d75d4989a29b5903175ed8a1",{"previousId":1090},{"name":359,"tag":359,"options":1213,"isRSC":118},{"darkMode":6,"maxWidth":363,"maxTextWidth":364,"title":1214,"description":1215,"image":1216,"reverse":6},"\u003Ch2>Use your browser to govern AI \u003C/h2>","\u003Cp>The AI footprint inside your company is bigger than you think. From text generators to meeting assistants and design copilots, employees test, adopt, and connect new tools constantly. Push shows you those tools and which users are accessing them, without relying on network scans or API integrations.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F30b43bda6f1644c19478fb1efa20050c",{"large":1218},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1220,"meta":1221,"component":1222,"responsiveStyles":1226},"builder-90ee9cb9afc44e7f885523715bf51a53",{"previousId":1099},{"name":373,"options":1223,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":376,"title":1224,"description":1225,"reverse":41,"image":1115},"\u003Ch2>Discover every AI tool users touch\u003C/h2>","\u003Cp>Push captures live telemetry from the browser, identifying every AI-native and AI-enhanced application users access. You’ll know which corporate identities are connected, how data flows, and what new AI apps appear across your environment. \u003C/p>",{"large":1227},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"fontFamily":382,"paddingTop":384,"marginTop":384},{"@type":106,"@version":107,"id":1229,"meta":1230,"component":1231,"responsiveStyles":1235},"builder-9e44539fa53c4d8e87406036c921fc46",{"previousId":1109},{"name":373,"options":1232,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":389,"title":1233,"description":1234,"reverse":6,"image":1125},"\u003Ch2>Classify and manage AI risk\u003C/h2>","\u003Cp>For apps you choose to allow, Push lets you apply custom in-browser banners. You can bulk-select categories of AI tools and require users to read and acknowledge your acceptable use policy before they proceed. This creates an auditable trail and moves policy from an easy to forget document to an active, in-workflow control.\u003C/p>",{"large":1236},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":395},{"@type":106,"@version":107,"layerName":373,"id":1238,"meta":1239,"component":1240,"responsiveStyles":1245},"builder-44c1a891926f4bdeaaa37e90721fe6ac",{"previousId":1119},{"name":373,"options":1241,"isRSC":118},{"darkMode":6,"maxWidth":363,"imageMaxWidth":375,"textPaddingTop":400,"title":1242,"description":1243,"reverse":41,"image":1244},"\u003Ch2>Enforce your AI policy in the browser\u003C/h2>","\u003Cp>When an AI tool is deemed non-compliant or too risky, Push blocks it at the source. The block happens directly in the browser, preventing the user from accessing the site or submitting data. This gives you an immediate, powerful lever to stop data exfiltration and enforce a hard line on unacceptable risk.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fa359ac1805af4e15a8a7f84632b9bb55",{"large":1246},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125,"paddingTop":406},{"@type":106,"@version":107,"id":1248,"meta":1249,"component":1250,"responsiveStyles":1252},"builder-dcc906f9cbe54dc68b3c672668e7a38f",{"previousId":1129},{"name":354,"options":1251,"isRSC":118},{"darkMode":6},{"large":1253},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"@type":106,"@version":107,"id":1255,"component":1256,"responsiveStyles":1258},"builder-d2d64780c31b4349bc75805b23a07e38",{"name":416,"tag":416,"options":1257,"isRSC":118},{"sectionHeading":37,"customClass":418},{"large":1259},{"display":121,"flexDirection":122,"position":123,"flexShrink":124,"boxSizing":125},{"id":1261,"@type":106,"tagName":131,"properties":1262,"responsiveStyles":1263},"builder-pixel-wxx9tk70r9p",{"src":133,"aria-hidden":134,"alt":37,"role":135,"width":124,"height":124},{"large":1264},{"height":124,"width":124,"display":138,"opacity":124,"overflow":139,"pointerEvents":140},{"deviceSize":142,"location":1266},{"path":37,"query":1267},{},{},1770892957225,1764950077593,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe558b8b069884037a8e6904f7ecc029c",[],{"winningTest":118,"breakpoints":1274,"originalContentId":1039,"kind":438,"lastPreviewUrl":1275,"hasLinks":6,"hasAutosaves":41},{"xsmall":57,"small":39,"medium":40},"https://pushsecurity.com/uc/shadow-ai?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=use-case-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.use-case-page=b62629ce2f3741158d961cd10fe74b31&builder.overrides.b62629ce2f3741158d961cd10fe74b31=b62629ce2f3741158d961cd10fe74b31&builder.overrides.use-case-page:/uc/shadow-ai=b62629ce2f3741158d961cd10fe74b31&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default",{"_path":1277,"_dir":1278,"_draft":6,"_partial":6,"_locale":37,"sys":1279,"summary":1282,"title":1296,"subtitle":118,"metaTitle":1297,"synopsis":1292,"hashTags":118,"publishedDate":1298,"slug":1299,"tagsCollection":1300,"relatedBlogPostsCollection":1310,"ogImage":3464,"authorsCollection":3466,"content":3474,"_id":4167,"_type":4168,"_source":4169,"_file":4170,"_stem":4171,"_extension":4168},"/blog/why-its-time-for-phishing-prevention-to-move-beyond-email","blog",{"id":1280,"publishedAt":1281},"4UgGUvlZNqkJtx9nNprKg0","2026-01-30T09:14:17.851Z",{"json":1283},{"data":1284,"content":1285,"nodeType":1295},{},[1286],{"data":1287,"content":1288,"nodeType":1294},{},[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":1293},{},[],"Modern MFA-bypass phishing attacks are routinely defeating primarily email-based security controls. Why are controls failing and what can we do about it? ","text","paragraph","document","Why it's time for phishing prevention to move beyond email","Moving beyond email-based phishing prevention","2025-03-20T00:00:00.000Z","why-its-time-for-phishing-prevention-to-move-beyond-email",{"items":1301},[1302,1306],{"sys":1303,"name":1305},{"id":1304},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":1307,"name":1309},{"id":1308},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1311},[1312,1912,3127],{"__typename":1313,"sys":1314,"content":1316,"title":1894,"synopsis":1895,"hashTags":118,"publishedDate":1896,"slug":1897,"tagsCollection":1898,"authorsCollection":1904},"BlogPosts",{"id":1315},"11C3shj5SlkS8sAd3AlYDp",{"json":1317},{"data":1318,"content":1319,"nodeType":1295},{},[1320,1342,1362,1369,1378,1385,1393,1400,1407,1416,1436,1443,1450,1457,1463,1470,1503,1510,1517,1524,1531,1537,1544,1551,1558,1590,1596,1603,1610,1641,1647,1654,1661,1668,1675,1681,1687,1694,1701,1708,1714,1721,1728,1735,1742,1761,1778,1785,1792,1799,1805,1812,1831,1837,1844,1872,1879,1886],{"data":1321,"content":1322,"nodeType":1294},{},[1323,1327,1338],{"data":1324,"marks":1325,"value":1326,"nodeType":1293},{},[],"It’s been well reported that ",{"data":1328,"content":1330,"nodeType":1337},{"uri":1329},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/",[1331],{"data":1332,"marks":1333,"value":1336,"nodeType":1293},{},[1334],{"type":1335},"underline","identity attacks are on the rise","hyperlink",{"data":1339,"marks":1340,"value":1341,"nodeType":1293},{},[],", and constantly evolving phishing tools and techniques are a big part of this. In particular, the increasing prevalence of MFA has led to AitM phishing attacks becoming much more common. The threat intelligence industry naturally wants to locate and shutdown all the phishing servers – but the phishers are fighting back.",{"data":1343,"content":1344,"nodeType":1294},{},[1345,1349,1358],{"data":1346,"marks":1347,"value":1348,"nodeType":1293},{},[],"Before we dive into how AitM phishing kits evade detection, you should check out our earlier blog post on ‘",{"data":1350,"content":1352,"nodeType":1337},{"uri":1351},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[1353],{"data":1354,"marks":1355,"value":1357,"nodeType":1293},{},[1356],{"type":1335},"Phishing 2.0 – how phishing toolkits are evolving with AitM",{"data":1359,"marks":1360,"value":1361,"nodeType":1293},{},[],"’ if you want to get up to speed with what these toolkits are, and why attackers are using them more regularly. ",{"data":1363,"content":1364,"nodeType":1294},{},[1365],{"data":1366,"marks":1367,"value":1368,"nodeType":1293},{},[],"In this blog post, we’re going to look at a recent instance of the NakedPages AitM phishing toolkit and some of the steps it takes to frustrate detection and analysis. In particular, we’ll look at how malicious activity is obfuscated through the use of legitimate SaaS services. NakedPages uses a range of different techniques and so serves as a good case study as to how AitM toolkits are being designed to evade detection.",{"data":1370,"content":1376,"nodeType":1377},{"target":1371},{"sys":1372},{"id":1373,"type":1374,"linkType":1375},"2Qcn2nNRXVkdqqxGO8lDZf","Link","Entry",[],"embedded-entry-block",{"data":1379,"content":1380,"nodeType":1294},{},[1381],{"data":1382,"marks":1383,"value":1384,"nodeType":1293},{},[],"Before we dive in, it’s useful to keep in mind that while there is a lot of complication here, most of this happens in seconds and is transparent to the intended victim accessing from a real browser.",{"data":1386,"content":1387,"nodeType":1392},{},[1388],{"data":1389,"marks":1390,"value":1391,"nodeType":1293},{},[],"Step 1: Cloudflare Workers for the initial gateway","heading-1",{"data":1394,"content":1395,"nodeType":1294},{},[1396],{"data":1397,"marks":1398,"value":1399,"nodeType":1293},{},[],"A key feature of the NakedPages kit is that it has several stages and redirections and, in order for it to operate as intended, the target has to arrive at the beginning. The first step involves visiting a URL that is simply a Cloudflare Worker. Cloudflare Workers are a serverless execution environment, a bit like AWS lambdas.",{"data":1401,"content":1402,"nodeType":1294},{},[1403],{"data":1404,"marks":1405,"value":1406,"nodeType":1293},{},[],"The benefit to the attacker is that this gives them a highly reputable primary domain as it is one owned and operated by Cloudflare. Flagging recently registered or uncategorized/rare domains for further analysis won’t work for this. For example, the URL used in this instance was the following:",{"data":1408,"content":1409,"nodeType":1294},{},[1410],{"data":1411,"marks":1412,"value":1415,"nodeType":1293},{},[1413],{"type":1414},"code","hxxps://226028cc.502f135e3e036e726fba22d4.workers.dev",{"data":1417,"content":1418,"nodeType":1294},{},[1419,1423,1432],{"data":1420,"marks":1421,"value":1422,"nodeType":1293},{},[],"For other examples of Cloudflare Workers being abused for phishing, ",{"data":1424,"content":1426,"nodeType":1337},{"uri":1425},"https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/its-raining-phish-and-scams-how-cloudflare-pages-dev-and-workers-dev-domains-get-abused/",[1427],{"data":1428,"marks":1429,"value":1431,"nodeType":1293},{},[1430],{"type":1335},"check out this blog post from Trustwave",{"data":1433,"marks":1434,"value":1435,"nodeType":1293},{},[],".",{"data":1437,"content":1438,"nodeType":1392},{},[1439],{"data":1440,"marks":1441,"value":1442,"nodeType":1293},{},[],"Step 2: Cloudflare Turnstile for bot detection",{"data":1444,"content":1445,"nodeType":1294},{},[1446],{"data":1447,"marks":1448,"value":1449,"nodeType":1293},{},[],"The only purpose of the Cloudflare Worker is to act as a bot gateway to prevent automated analysis getting further than this point. For this it uses Cloudflare Turnstile. Turnstile is a highly effective tool for detecting the difference between bots and human users as a replacement for CAPTCHAs used by websites across the world. ",{"data":1451,"content":1452,"nodeType":1294},{},[1453],{"data":1454,"marks":1455,"value":1456,"nodeType":1293},{},[],"If it doesn’t work transparently then you’ll probably see something like this:",{"data":1458,"content":1462,"nodeType":1377},{"target":1459},{"sys":1460},{"id":1461,"type":1374,"linkType":1375},"4XNxLbiZf3xUK1WeFDjjxl",[],{"data":1464,"content":1465,"nodeType":1294},{},[1466],{"data":1467,"marks":1468,"value":1469,"nodeType":1293},{},[],"However, who else wants to keep out the bots? Well, phishers of course! There are many sandbox environments and other automated platforms out there, visiting every URL they come across in the search for malicious behavior. This stops many of them in their tracks as they never get past the Turnstile check. ",{"data":1471,"content":1472,"nodeType":1294},{},[1473,1477,1486,1490,1499],{"data":1474,"marks":1475,"value":1476,"nodeType":1293},{},[],"Malicious use of Turnstile use has become much more common now. Examples include other criminal kits ",{"data":1478,"content":1480,"nodeType":1337},{"uri":1479},"https://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/",[1481],{"data":1482,"marks":1483,"value":1485,"nodeType":1293},{},[1484],{"type":1335},"such as Tycoon",{"data":1487,"marks":1488,"value":1489,"nodeType":1293},{},[],", as well as ",{"data":1491,"content":1493,"nodeType":1337},{"uri":1492},"https://fin3ss3g0d.net/index.php/2024/04/08/evilgophishs-approach-to-advanced-bot-detection-with-cloudflare-turnstile/",[1494],{"data":1495,"marks":1496,"value":1498,"nodeType":1293},{},[1497],{"type":1335},"open-source phishing tools focused on red teaming",{"data":1500,"marks":1501,"value":1502,"nodeType":1293},{},[],". ",{"data":1504,"content":1505,"nodeType":1392},{},[1506],{"data":1507,"marks":1508,"value":1509,"nodeType":1293},{},[],"Step 3: Required URL parameters and custom auth headers",{"data":1511,"content":1512,"nodeType":1294},{},[1513],{"data":1514,"marks":1515,"value":1516,"nodeType":1293},{},[],"If you get past Turnstile, then you’ll finally be redirected to a more conventionally suspicious domain. However, you’ll need to supply the correct URL parameters and headers, or that request might behave differently. ",{"data":1518,"content":1519,"nodeType":1294},{},[1520],{"data":1521,"marks":1522,"value":1523,"nodeType":1293},{},[],"Suspicious domains can be found and interrogated through other means, such as observing new domain registrations or certificate transparency logs. In this case, the phishers add other steps involving required URL parameters and custom headers. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":1525,"content":1526,"nodeType":1294},{},[1527],{"data":1528,"marks":1529,"value":1530,"nodeType":1293},{},[],"The following code snippet shows how this operates. Bonus points for spotting how they actually forgot to implement their own RSA encryption function and instead send their “encrypted” user agents in clear text:",{"data":1532,"content":1536,"nodeType":1377},{"target":1533},{"sys":1534},{"id":1535,"type":1374,"linkType":1375},"45aif31bot9phquQPkz20p",[],{"data":1538,"content":1539,"nodeType":1392},{},[1540],{"data":1541,"marks":1542,"value":1543,"nodeType":1293},{},[],"Step 4: Requiring JavaScript execution",{"data":1545,"content":1546,"nodeType":1294},{},[1547],{"data":1548,"marks":1549,"value":1550,"nodeType":1293},{},[],"Another aspect of the previous step is that it requires JavaScript to execute. That means defensive techniques that simply make HTTP(S) requests and scrape content will not automatically be able to follow the link without allowing JavaScript execution. This forces the use of dynamic sandbox techniques that actually load a DOM, as it’s almost impossible for static analysis to generically solve this problem.",{"data":1552,"content":1553,"nodeType":1392},{},[1554],{"data":1555,"marks":1556,"value":1557,"nodeType":1293},{},[],"Step 5: Redirecting to legitimate domains",{"data":1559,"content":1560,"nodeType":1294},{},[1561,1565,1573,1577,1586],{"data":1562,"marks":1563,"value":1564,"nodeType":1293},{},[],"Attackers will also redirect to legitimate domains to mask their activity. Let’s say a defender has visited the attacker’s malicious domain without executing JavaScript or supplying the correct URL parameters. The attacker doesn’t want to activate their malicious phishing behavior at this point, so they need to do something benign instead. In this case, they simply redirect to ",{"data":1566,"content":1568,"nodeType":1337},{"uri":1567},"https://example.com",[1569],{"data":1570,"marks":1571,"value":1567,"nodeType":1293},{},[1572],{"type":1335},{"data":1574,"marks":1575,"value":1576,"nodeType":1293},{},[],". Interestingly, ",{"data":1578,"content":1580,"nodeType":1337},{"uri":1579},"https://www.youtube.com/watch?v=-W-LxcbUxI4&t=643s",[1581],{"data":1582,"marks":1583,"value":1585,"nodeType":1293},{},[1584],{"type":1335},"EvilProxy has also been seen redirecting to example.com too",{"data":1587,"marks":1588,"value":1589,"nodeType":1293},{},[],":",{"data":1591,"content":1595,"nodeType":1377},{"target":1592},{"sys":1593},{"id":1594,"type":1374,"linkType":1375},"450Y7W1uXVkKSps5y0xhBe",[],{"data":1597,"content":1598,"nodeType":1392},{},[1599],{"data":1600,"marks":1601,"value":1602,"nodeType":1293},{},[],"Step 6: HTTP referer header masking",{"data":1604,"content":1605,"nodeType":1294},{},[1606],{"data":1607,"marks":1608,"value":1609,"nodeType":1293},{},[],"Maintainers of legitimate websites often look at the HTTP referer header to see where they are being linked from. This is often a critical task for businesses, particularly for things like marketing. However, what if employees spot strange redirects coming in from suspicious looking domains like the ones used by this phishing kit? Perhaps they might investigate those domains and/or tip off relevant security vendors and organizations. ",{"data":1611,"content":1612,"nodeType":1294},{},[1613,1617,1625,1629,1637],{"data":1614,"marks":1615,"value":1616,"nodeType":1293},{},[],"Unless, of course, you were to use a service to mask the HTTP referrer – which is exactly what the phishing kit does in this case. NakedPages makes use of ",{"data":1618,"content":1620,"nodeType":1337},{"uri":1619},"https://href.li/",[1621],{"data":1622,"marks":1623,"value":1619,"nodeType":1293},{},[1624],{"type":1335},{"data":1626,"marks":1627,"value":1628,"nodeType":1293},{},[]," as a service to strip the referral to ensure the redirection is performed anonymously. Rather conveniently, it seems the default example that ",{"data":1630,"content":1632,"nodeType":1337},{"uri":1631},"https://href.li",[1633],{"data":1634,"marks":1635,"value":1631,"nodeType":1293},{},[1636],{"type":1335},{"data":1638,"marks":1639,"value":1640,"nodeType":1293},{},[]," uses is… example.com:",{"data":1642,"content":1646,"nodeType":1377},{"target":1643},{"sys":1644},{"id":1645,"type":1374,"linkType":1375},"78xFQwTG1r0YWGJ24iEdYP",[],{"data":1648,"content":1649,"nodeType":1392},{},[1650],{"data":1651,"marks":1652,"value":1653,"nodeType":1293},{},[],"Step 7: Loading balanced domains",{"data":1655,"content":1656,"nodeType":1294},{},[1657],{"data":1658,"marks":1659,"value":1660,"nodeType":1293},{},[],"You’re probably thinking: Step 7? Surely, if a victim’s browser has finally made it this far then the attackers would just serve up the malicious phishing content at this point, right? Well, we aren’t quite done yet. These initial gateway servers are one of the most important components to keep undetected, as existing phishing campaigns and (as yet unread) emails will be leading to them.",{"data":1662,"content":1663,"nodeType":1294},{},[1664],{"data":1665,"marks":1666,"value":1667,"nodeType":1293},{},[],"Once we get to the more obviously malicious phishing activity, there is a higher chance of detection and user reports. In this case the phishing kit actually retrieves a new URL to redirect to, along with a suitable JWT authentication parameter. The benefit of this is that when URLs/hostnames get flagged as malicious, blocked or otherwise taken down, the phishing kit can just redirect to other hostnames, and the attacker’s can keep updating with new URLs over time. ",{"data":1669,"content":1670,"nodeType":1294},{},[1671],{"data":1672,"marks":1673,"value":1674,"nodeType":1293},{},[],"Below we can see an example of the response containing a URL, with a JWT auth parameter:",{"data":1676,"content":1680,"nodeType":1377},{"target":1677},{"sys":1678},{"id":1679,"type":1374,"linkType":1375},"4NpH7V5oEdTASNNJsqCJ47",[],{"data":1682,"content":1686,"nodeType":1377},{"target":1683},{"sys":1684},{"id":1685,"type":1374,"linkType":1375},"7oqkrhNXtyOlJMEz0BZyLo",[],{"data":1688,"content":1689,"nodeType":1294},{},[1690],{"data":1691,"marks":1692,"value":1693,"nodeType":1293},{},[],"Automating this request in this example brings back around 20 different primary domains used for the final phishing attack. These domains are rotated over time as some are blocked and new ones are created.",{"data":1695,"content":1696,"nodeType":1392},{},[1697],{"data":1698,"marks":1699,"value":1700,"nodeType":1293},{},[],"Step 8: Breaking login page signatures",{"data":1702,"content":1703,"nodeType":1294},{},[1704],{"data":1705,"marks":1706,"value":1707,"nodeType":1293},{},[],"If all the previous checks have passed then a victim user is finally presented with a phishing page. The attacker has most closely emulated the sign-on page for live.com for Outlook in this case, though it also has some aspects from a business Microsoft login too, as we can see in the examples below:",{"data":1709,"content":1713,"nodeType":1377},{"target":1710},{"sys":1711},{"id":1712,"type":1374,"linkType":1375},"2Ez0fgAlmkrisdQGWfL6CV",[],{"data":1715,"content":1716,"nodeType":1294},{},[1717],{"data":1718,"marks":1719,"value":1720,"nodeType":1293},{},[],"However, one obvious change can be seen in the HTML title in the tab header. This normally says something like “Sign in to Outlook” or “Sign in to your account”. In this case, the phishing kit has randomized the HTML title. \n\nOne super easy way to detect websites pretending to be common login pages that have 1:1 cloned the website or are performing full reverse proxy AiTM techniques would be to search for obvious HTML content like this. Not many legitimate websites should have an HTML title of “Sign in to Outlook” other than Microsoft’s own legitimate domains for it, right?",{"data":1722,"content":1723,"nodeType":1294},{},[1724],{"data":1725,"marks":1726,"value":1727,"nodeType":1293},{},[],"Taking a closer look, we’ll see that the HTML, DOM and JavaScript etc. differ quite significantly from the true login pages, even if the visual appearance is very similar. One reason for this is to make it harder for defenders to simply signature on specific aspects of commonly spoofed login pages.",{"data":1729,"content":1730,"nodeType":1392},{},[1731],{"data":1732,"marks":1733,"value":1734,"nodeType":1293},{},[],"Step 9: B2B targeting",{"data":1736,"content":1737,"nodeType":1294},{},[1738],{"data":1739,"marks":1740,"value":1741,"nodeType":1293},{},[],"The final interesting aspect of this particular example is that it modifies its behavior during the login process depending on whether a personal Microsoft account or an organization account is used.",{"data":1743,"content":1744,"nodeType":1294},{},[1745,1749,1757],{"data":1746,"marks":1747,"value":1748,"nodeType":1293},{},[],"When entering an email address associated with a personal Microsoft account, or picking ‘personal account’ when prompted after entering an email address that is used for both purposes, the server will return a 302 redirect and send the user to ",{"data":1750,"content":1752,"nodeType":1337},{"uri":1751},"https://login.live.com/",[1753],{"data":1754,"marks":1755,"value":1751,"nodeType":1293},{},[1756],{"type":1335},{"data":1758,"marks":1759,"value":1760,"nodeType":1293},{},[]," where they can then re-enter their credentials and login to Microsoft legitimately if they continue. This reduces the potential for detection further as no AitM phishing login will actually occur.",{"data":1762,"content":1763,"nodeType":1294},{},[1764,1768,1774],{"data":1765,"marks":1766,"value":1767,"nodeType":1293},{},[],"On the other hand, when using an organization account the phishing process continues as expected. ",{"data":1769,"marks":1770,"value":1773,"nodeType":1293},{},[1771],{"type":1772},"bold","This phishing campaign is exclusively targeting corp accounts",{"data":1775,"marks":1776,"value":1777,"nodeType":1293},{},[]," and you could almost say it has a B2B (or is that A2B?) rather than B2C business model.  ",{"data":1779,"content":1780,"nodeType":1392},{},[1781],{"data":1782,"marks":1783,"value":1784,"nodeType":1293},{},[],"Conclusion",{"data":1786,"content":1787,"nodeType":1294},{},[1788],{"data":1789,"marks":1790,"value":1791,"nodeType":1293},{},[],"As you may have guessed from the extremely suspicious domains in use and examples of sloppy coding (like forgetting to implement an encryption function) the NakedPages kit is far from sophisticated. Despite this, the tricks that attackers are using to make detection and analysis more difficult seem to be quite effective when used in a layered model. ",{"data":1793,"content":1794,"nodeType":1294},{},[1795],{"data":1796,"marks":1797,"value":1798,"nodeType":1293},{},[],"For example, at the time of writing this particular Worker had been up for at least two days and was currently only triggering 1 detection on VirusTotal. ",{"data":1800,"content":1804,"nodeType":1377},{"target":1801},{"sys":1802},{"id":1803,"type":1374,"linkType":1375},"1mIOpDtmgcMasK6dEhRHsm",[],{"data":1806,"content":1807,"nodeType":1294},{},[1808],{"data":1809,"marks":1810,"value":1811,"nodeType":1293},{},[],"One key takeaway is that it’s near impossible to stay on top of all the phishing servers on the internet. Even the untargeted mass campaigns will initially be missed by TI feeds, let alone the targeted ones. ",{"data":1813,"content":1814,"nodeType":1294},{},[1815,1819,1827],{"data":1816,"marks":1817,"value":1818,"nodeType":1293},{},[],"The best foot forward for resilience against these attacks is through the use of domain-bound MFA methods like WebAuthn. Common MFA methods like OTPs, SMS, push notifications etc. are routinely bypassed using ",{"data":1820,"content":1821,"nodeType":1337},{"uri":1351},[1822],{"data":1823,"marks":1824,"value":1826,"nodeType":1293},{},[1825],{"type":1335},"AitM techniques that proxy the MFA authentication as well",{"data":1828,"marks":1829,"value":1830,"nodeType":1293},{},[],". Even if you are one of the few who use phishing-resistant MFA methods like WebAuthn or other passkeys, the devil is in the detail and we’ve seen MFA downgrade attacks being used to bypass them by choosing a phishable method that’s also active.",{"data":1832,"content":1836,"nodeType":1377},{"target":1833},{"sys":1834},{"id":1835,"type":1374,"linkType":1375},"17lSgRFD6fDzRUn9eOHJg6",[],{"data":1838,"content":1839,"nodeType":1392},{},[1840],{"data":1841,"marks":1842,"value":1843,"nodeType":1293},{},[],"P.S. How did we detect this?",{"data":1845,"content":1846,"nodeType":1294},{},[1847,1851,1856,1860,1869],{"data":1848,"marks":1849,"value":1850,"nodeType":1293},{},[],"After all that, you might be wondering how we managed to automate a process to generically pass through all these detection evasion techniques – ",{"data":1852,"marks":1853,"value":1855,"nodeType":1293},{},[1854],{"type":1772},"well the short answer is: We didn’t.",{"data":1857,"marks":1858,"value":1859,"nodeType":1293},{},[]," Instead, we detected the act of an employee ",{"data":1861,"content":1863,"nodeType":1337},{"uri":1862},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[1864],{"data":1865,"marks":1866,"value":1868,"nodeType":1293},{},[1867],{"type":1335},"attempting to put their Microsoft password into a website that wasn’t Microsoft",{"data":1870,"marks":1871,"value":1435,"nodeType":1293},{},[],{"data":1873,"content":1874,"nodeType":1294},{},[1875],{"data":1876,"marks":1877,"value":1878,"nodeType":1293},{},[],"The TTP for phishing is effectively “trick someone into putting their valid credentials into the wrong site” – so detecting that behavior directly (the action of entering a legit password into the wrong site) can be a lot simpler and more effective than playing the cat-and-mouse detection → detection-evasion game.",{"data":1880,"content":1881,"nodeType":1294},{},[1882],{"data":1883,"marks":1884,"value":1885,"nodeType":1293},{},[],"Having said that, if you’re interested, here are the domain IOCs for this campaign:",{"data":1887,"content":1888,"nodeType":1294},{},[1889],{"data":1890,"marks":1891,"value":1893,"nodeType":1293},{},[1892],{"type":1414},"226028cc[.]502f135e3e036e726fba22d4[.]workers[.]dev\nacevoorgukmembership[.]buzz\nalerteditorroyalsocietyorgnz[.]buzz\nandymarshallsgeniuslocidigestghostiomghostio[.]buzz\nblogresponseinsperitycom[.]buzz\ncampaigneventbritecomnoreply[.]buzz\ncharityexcellencer1technologytrustnewsorg[.]buzz\nclerkenwelldesignweekcomnoreply[.]buzz\nconfirminfothetrainlinecomauto[.]buzz\nhealthestatejournalcomnoreply[.]buzz\nmentalhealthdesignandbuildcomnoreply[.]buzz\nnoreplynotificationswhoopcom[.]buzz\nstepexhibitionscomeventsupport[.]buzz\ntheathletice1theathleticcom[.]buzz\nthekakahoonssubstackcom[.]buzz","How AitM phishing kits evade detection","Taking a closer look at the steps that AitM phishing kits take to hide from the prying eyes of security teams and threat intelligence vendors.","2024-07-23T00:00:00.000Z","how-aitm-phishing-kits-evade-detection",{"items":1899},[1900,1902],{"sys":1901,"name":1309},{"id":1308},{"sys":1903,"name":1305},{"id":1304},{"items":1905},[1906],{"fullName":1907,"firstName":1908,"jobTitle":1909,"profilePicture":1910},"Luke Jennings","Luke","Vice President, R&D",{"url":1911},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"__typename":1313,"sys":1913,"content":1915,"title":3107,"synopsis":3108,"hashTags":118,"publishedDate":3109,"slug":3110,"tagsCollection":3111,"authorsCollection":3119},{"id":1914},"5KqYY7p174lSpuinfTfEZU",{"json":1916},{"data":1917,"content":1918,"nodeType":1295},{},[1919,1926,1983,1990,1994,2001,2008,2041,2053,2056,2063,2076,2083,2103,2109,2129,2136,2147,2167,2187,2194,2214,2220,2240,2243,2250,2257,2264,2283,2303,2310,2330,2337,2344,2370,2377,2397,2418,2424,2431,2451,2454,2461,2480,2500,2507,2560,2567,2570,2577,2584,2603,2623,2630,2637,2644,2665,2672,2679,2685,2691,2694,2701,2708,2715,2735,2746,2765,2772,2779,2789,2796,2803,2824,2830,2833,2840,2847,2854,2927,2934,2941,2948,2956,2977,2984,2990,3001,3022,3029,3037,3058,3065,3072,3078,3081,3088],{"data":1920,"content":1921,"nodeType":1294},{},[1922],{"data":1923,"marks":1924,"value":1925,"nodeType":1293},{},[],"From massive breaches like the Snowflake incident to novel phishing techniques documented by Push researchers, 2024 was the year that identity attacks left their mark. Looking back over what we saw in the wild and what we found through Push’s own research, three key themes stand out:",{"data":1927,"content":1928,"nodeType":1982},{},[1929,1949,1959],{"data":1930,"content":1931,"nodeType":1948},{},[1932],{"data":1933,"content":1934,"nodeType":1294},{},[1935,1939,1944],{"data":1936,"marks":1937,"value":1938,"nodeType":1293},{},[],"Account takeover techniques on cloud apps are fundamentally different from traditional network-based attacks. To have the best chance of preventing account takeover, defenders need to  disrupt attacks ",{"data":1940,"marks":1941,"value":1943,"nodeType":1293},{},[1942],{"type":312},"before",{"data":1945,"marks":1946,"value":1947,"nodeType":1293},{},[]," they’re successful.","list-item",{"data":1950,"content":1951,"nodeType":1948},{},[1952],{"data":1953,"content":1954,"nodeType":1294},{},[1955],{"data":1956,"marks":1957,"value":1958,"nodeType":1293},{},[],"It’s not easy or practical to maintain 100 percent compliance on identity posture standards in a world where employees are using and signing up to apps outside of IT oversight — but it is possible to make this work a lot easier by using tools that help you scale your remediation activities.",{"data":1960,"content":1961,"nodeType":1948},{},[1962],{"data":1963,"content":1964,"nodeType":1294},{},[1965,1969,1978],{"data":1966,"marks":1967,"value":1968,"nodeType":1293},{},[],"Despite another year where cybersecurity spend increased (now up to almost $1,100 per user, according to ",{"data":1970,"content":1972,"nodeType":1337},{"uri":1971},"https://www.forrester.com/report/2024-cybersecurity-benchmarks-global/RES181118",[1973],{"data":1974,"marks":1975,"value":1977,"nodeType":1293},{},[1976],{"type":1335},"Forrester",{"data":1979,"marks":1980,"value":1981,"nodeType":1293},{},[],"), existing approaches are not successfully preventing account takeovers. Security teams need to be able to detect and respond to these attacks where they happen: The browser.","unordered-list",{"data":1984,"content":1985,"nodeType":1294},{},[1986],{"data":1987,"marks":1988,"value":1989,"nodeType":1293},{},[],"In this article, we’ll take a look back at how these themes influenced key features we delivered for Push customers in 2024.",{"data":1991,"content":1992,"nodeType":1993},{},[],"hr",{"data":1995,"content":1996,"nodeType":1392},{},[1997],{"data":1998,"marks":1999,"value":2000,"nodeType":1293},{},[],"Defending against modern phishing attacks",{"data":2002,"content":2003,"nodeType":1294},{},[2004],{"data":2005,"marks":2006,"value":2007,"nodeType":1293},{},[],"Phishing techniques that bypass MFA are now the norm, and few organizations have successfully achieved full coverage of phishing-resistant MFA methods. ",{"data":2009,"content":2010,"nodeType":1294},{},[2011,2015,2024,2028,2037],{"data":2012,"marks":2013,"value":2014,"nodeType":1293},{},[],"Equally, while phishing attacks via email remain the most commonly reported vector, phishing attacks increasingly target users outside of email. For example, phishing links are often encountered through normal internet use — such as ",{"data":2016,"content":2018,"nodeType":1337},{"uri":2017},"https://www.bleepingcomputer.com/news/security/hackers-use-google-search-ads-to-steal-google-ads-accounts/",[2019],{"data":2020,"marks":2021,"value":2023,"nodeType":1293},{},[2022],{"type":1335},"in malicious Google ads",{"data":2025,"marks":2026,"value":2027,"nodeType":1293},{},[]," — and attackers frequently conduct their campaigns over IM platforms like Slack and Teams. Late last year there was ",{"data":2029,"content":2031,"nodeType":1337},{"uri":2030},"https://www.linkedin.com/posts/kevin-beaumont-security_ive-been-assisting-a-few-orgs-hit-with-successful-activity-7268055739116445701-xxjZ?utm_source=share&utm_medium=member_desktop",[2032],{"data":2033,"marks":2034,"value":2036,"nodeType":1293},{},[2035],{"type":1335},"a rise in attackers inundating users with spam via Teams",{"data":2038,"marks":2039,"value":2040,"nodeType":1293},{},[],", combined with phone scams posing as IT admins. Since anti-phishing controls are usually email-based, they fail to protect users from attacks taking place elsewhere. ",{"data":2042,"content":2043,"nodeType":1294},{},[2044,2048],{"data":2045,"marks":2046,"value":2047,"nodeType":1293},{},[],"At Push, we’ve built a suite of anti-phishing features over the last year that act as a defense-in-depth approach to the types of modern phishing techniques we’ve been observing in the wild. ",{"data":2049,"marks":2050,"value":2052,"nodeType":1293},{},[2051],{"type":1772},"Here’s what we built and why.",{"data":2054,"content":2055,"nodeType":1993},{},[],{"data":2057,"content":2058,"nodeType":1392},{},[2059],{"data":2060,"marks":2061,"value":2062,"nodeType":1293},{},[],"Protecting passwords used for SSO",{"data":2064,"content":2065,"nodeType":2075},{},[2066,2071],{"data":2067,"marks":2068,"value":2070,"nodeType":1293},{},[2069],{"type":1772},"What happened?",{"data":2072,"marks":2073,"value":2074,"nodeType":1293},{},[]," ","heading-2",{"data":2077,"content":2078,"nodeType":1294},{},[2079],{"data":2080,"marks":2081,"value":2082,"nodeType":1293},{},[],"Attackers explicitly targeted Okta, Entra, and Google Workspace accounts in 2023 and 2024, so we knew a top priority would be protecting identity provider accounts. These IdP accounts are a key target because they allow attackers to move laterally to other valuable apps and data via SSO following the initial account takeover.",{"data":2084,"content":2085,"nodeType":1294},{},[2086,2090,2099],{"data":2087,"marks":2088,"value":2089,"nodeType":1293},{},[],"It’s not just the typical IdPs you need to watch out for, either: Apps like GitHub, Slack, Salesforce, Facebook, X, and others all provide SSO functionality, increasing the blast radius of a compromise. And as we reported in ",{"data":2091,"content":2093,"nodeType":1337},{"uri":2092},"https://pushsecurity.com/blog/cross-idp-impersonation/",[2094],{"data":2095,"marks":2096,"value":2098,"nodeType":1293},{},[2097],{"type":1335},"our research on cross-IdP impersonation",{"data":2100,"marks":2101,"value":2102,"nodeType":1293},{},[],", apps can be accessed using multiple SSO methods simultaneously — and 3 in 5 apps that we tested recently did not require re-verification by default when adding a new login method.",{"data":2104,"content":2108,"nodeType":1377},{"target":2105},{"sys":2106},{"id":2107,"type":1374,"linkType":1375},"3EOOr4dVQoiPjl2ucUs1mA",[],{"data":2110,"content":2111,"nodeType":1294},{},[2112,2116,2125],{"data":2113,"marks":2114,"value":2115,"nodeType":1293},{},[],"Phishing is a problem that would be significantly reduced in a world without passwords. But while the ideal case is that organizations can put in place phishing-resistant authentication methods like passkeys or other WebAuthn-based methods, the reality is that ",{"data":2117,"content":2119,"nodeType":1337},{"uri":2118},"https://www.ncsc.gov.uk/blog-post/passkeys-not-perfect-getting-better",[2120],{"data":2121,"marks":2122,"value":2124,"nodeType":1293},{},[2123],{"type":1335},"it’s not a perfect solution right now",{"data":2126,"marks":2127,"value":2128,"nodeType":1293},{},[]," — widespread passkey implementation is hard to achieve.",{"data":2130,"content":2131,"nodeType":1294},{},[2132],{"data":2133,"marks":2134,"value":2135,"nodeType":1293},{},[],"One of the key advantages of passkeys is that they are domain-bound: Meaning they can’t be used on a site with the wrong domain. So, we started thinking: What if it were possible to essentially domain-bind a password? ",{"data":2137,"content":2138,"nodeType":2075},{},[2139,2144],{"data":2140,"marks":2141,"value":2143,"nodeType":1293},{},[2142],{"type":1772},"What we built",{"data":2145,"marks":2146,"value":2074,"nodeType":1293},{},[],{"data":2148,"content":2149,"nodeType":1294},{},[2150,2154,2163],{"data":2151,"marks":2152,"value":2153,"nodeType":1293},{},[],"In the first half of 2024, we delivered our ",{"data":2155,"content":2156,"nodeType":1337},{"uri":1862},[2157],{"data":2158,"marks":2159,"value":2162,"nodeType":1293},{},[2160,2161],{"type":1335},{"type":1772},"SSO password protection",{"data":2164,"marks":2165,"value":2166,"nodeType":1293},{},[]," feature, which allows Push administrators to block employees from entering their IdP password into any site that’s not the identity provider — in effect domain-binding SSO credentials. ",{"data":2168,"content":2169,"nodeType":1294},{},[2170,2174,2183],{"data":2171,"marks":2172,"value":2173,"nodeType":1293},{},[],"Push accomplishes this via the Push browser agent, which ",{"data":2175,"content":2177,"nodeType":1337},{"uri":2176},"https://pushsecurity.com/help/10109/#how-does-sso-password-protection-work",[2178],{"data":2179,"marks":2180,"value":2182,"nodeType":1293},{},[2181],{"type":1335},"observes and fingerprints",{"data":2184,"marks":2185,"value":2186,"nodeType":1293},{},[]," the user’s SSO password and legitimate SSO login pages, and then enforces in-browser controls to prevent an SSO password from being submitted on any URL that doesn’t match the legitimate provider, an extremely strong anti-phishing protection. Separately, Push also verifies that passwords it observes are not easily guessable.",{"data":2188,"content":2189,"nodeType":1294},{},[2190],{"data":2191,"marks":2192,"value":2193,"nodeType":1293},{},[],"The idea behind this approach is to gain some similar benefits to passkeys — by ensuring that passwords used for SSO access to your apps cannot be phished and are unique and strong — but in a way that “just works” with existing password-based authentication. ",{"data":2195,"content":2196,"nodeType":1294},{},[2197,2201,2210],{"data":2198,"marks":2199,"value":2200,"nodeType":1293},{},[],"Organizations that monitor for SSO password reuse will find that the practice turns out to be incredibly widespread, so being able to detect and prevent password reuse — even outside of actual phishing attempts — is an asset to security teams. (Our ",{"data":2202,"content":2204,"nodeType":1337},{"uri":2203},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[2205],{"data":2206,"marks":2207,"value":2209,"nodeType":1293},{},[2208],{"type":1335},"research shows",{"data":2211,"marks":2212,"value":2213,"nodeType":1293},{},[]," that 10% of IdP accounts are using a password that is shared with another app — where it is much more likely to be compromised.) ",{"data":2215,"content":2219,"nodeType":1377},{"target":2216},{"sys":2217},{"id":2218,"type":1374,"linkType":1375},"4Ce999wf4mqCZwu1jLofsx",[],{"data":2221,"content":2222,"nodeType":1294},{},[2223,2227,2236],{"data":2224,"marks":2225,"value":2226,"nodeType":1293},{},[],"By streaming events to your SIEM and setting up a simple automation, you can also use Push-supplied intelligence on SSO password reuse to ",{"data":2228,"content":2230,"nodeType":1337},{"uri":2229},"https://pushsecurity.com/blog/automating-sso-password-resets-using-push/",[2231],{"data":2232,"marks":2233,"value":2235,"nodeType":1293},{},[2234],{"type":1335},"automatically reset",{"data":2237,"marks":2238,"value":2239,"nodeType":1293},{},[]," potentially compromised passwords — this provides instant response to successful phishing and gets rid of password re-use of your most sensitive credentials in one move - the kind of combo we love!",{"data":2241,"content":2242,"nodeType":1993},{},[],{"data":2244,"content":2245,"nodeType":1392},{},[2246],{"data":2247,"marks":2248,"value":2249,"nodeType":1293},{},[],"Blocking AitM phishing and cloned login pages",{"data":2251,"content":2252,"nodeType":2075},{},[2253],{"data":2254,"marks":2255,"value":2070,"nodeType":1293},{},[2256],{"type":1772},{"data":2258,"content":2259,"nodeType":1294},{},[2260],{"data":2261,"marks":2262,"value":2263,"nodeType":1293},{},[],"When you’re able to detect SSO passwords being used in all the wrong places, it’s not surprising that one of the main offenders is phishing attacks. ",{"data":2265,"content":2266,"nodeType":1294},{},[2267,2271,2279],{"data":2268,"marks":2269,"value":2270,"nodeType":1293},{},[],"In 2024, we wrote extensively about the rise in ",{"data":2272,"content":2273,"nodeType":1337},{"uri":1351},[2274],{"data":2275,"marks":2276,"value":2278,"nodeType":1293},{},[2277],{"type":1335},"modern phishing attacks",{"data":2280,"marks":2281,"value":2282,"nodeType":1293},{},[]," that use adversary-in-the middle toolkits (AiTM), including EvilNoVNC, Evilginx, and others.",{"data":2284,"content":2285,"nodeType":1294},{},[2286,2290,2299],{"data":2287,"marks":2288,"value":2289,"nodeType":1293},{},[],"AiTM phishing is a newer variant of phishing that allows attackers to bypass MFA protection by using tools that act as a proxy between the end-user and a legitimate login portal. AitM attacks increased 146% in 2023 (",{"data":2291,"content":2293,"nodeType":1337},{"uri":2292},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf",[2294],{"data":2295,"marks":2296,"value":2298,"nodeType":1293},{},[2297],{"type":1335},"Microsoft",{"data":2300,"marks":2301,"value":2302,"nodeType":1293},{},[],").",{"data":2304,"content":2305,"nodeType":1294},{},[2306],{"data":2307,"marks":2308,"value":2309,"nodeType":1293},{},[],"This trend in tradecraft was reflected in our own customer base last year, but what’s interesting is that we observed a lot of phish kits and tactics that were new — meaning traditional detections failed to find them before Push did. ",{"data":2311,"content":2312,"nodeType":1294},{},[2313,2317,2326],{"data":2314,"marks":2315,"value":2316,"nodeType":1293},{},[],"In particular, we saw newer ",{"data":2318,"content":2320,"nodeType":1337},{"uri":2319},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection/",[2321],{"data":2322,"marks":2323,"value":2325,"nodeType":1293},{},[2324],{"type":1335},"web-based obfuscation techniques",{"data":2327,"marks":2328,"value":2329,"nodeType":1293},{},[]," that allowed attackers to get past the features of email security tools like web gateways and email scanning appliances, such as bypassing web sandbox analysis, and deter other forms of automated investigation by using Cloudflare Turnstile and other tactics — similar to the approaches legit websites use to protect against automated bots (this is essentially the same problem for both).",{"data":2331,"content":2332,"nodeType":1294},{},[2333],{"data":2334,"marks":2335,"value":2336,"nodeType":1293},{},[],"The gap in existing controls was obvious: When all phishing routes eventually lead to the browser, security teams need to be able to detect and respond in the browser. To do this well they need to observe what the employee sees, not what loads in a sandbox.",{"data":2338,"content":2339,"nodeType":2075},{},[2340],{"data":2341,"marks":2342,"value":2143,"nodeType":1293},{},[2343],{"type":1772},{"data":2345,"content":2346,"nodeType":1294},{},[2347,2351,2361,2366],{"data":2348,"marks":2349,"value":2350,"nodeType":1293},{},[],"To address this gap, we released new capabilities for the Push browser agent to be able to ",{"data":2352,"content":2354,"nodeType":1337},{"uri":2353},"https://pushsecurity.com/blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser/",[2355],{"data":2356,"marks":2357,"value":2360,"nodeType":1293},{},[2358,2359],{"type":1335},{"type":1772},"detect and block",{"data":2362,"marks":2363,"value":2365,"nodeType":1293},{},[2364],{"type":1772}," when a site is running AiTM phishing toolkits",{"data":2367,"marks":2368,"value":2369,"nodeType":1293},{},[],". ",{"data":2371,"content":2372,"nodeType":1294},{},[2373],{"data":2374,"marks":2375,"value":2376,"nodeType":1293},{},[],"Push does this via a set of readymade detections for common AiTM tools. By dynamically analyzing the behavior of malware in the browser, the Push browser agent can find indicators of compromise beyond just domains, file names, IP addresses, etc., focusing instead on behavioral attributes, such as Javascript calls being made or data structures saved to local storage.",{"data":2378,"content":2379,"nodeType":1294},{},[2380,2384,2393],{"data":2381,"marks":2382,"value":2383,"nodeType":1293},{},[],"This approach of focusing on the top of the ",{"data":2385,"content":2387,"nodeType":1337},{"uri":2386},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/#id-building-effective-identity-threat-detection-controls_id-scenario-detecting-a-web-based-phishing-attack",[2388],{"data":2389,"marks":2390,"value":2392,"nodeType":1293},{},[2391],{"type":1335},"Pyramid of Pain",{"data":2394,"marks":2395,"value":2396,"nodeType":1293},{},[]," — e.g. building detections for attributes of an attack that are the hardest for attackers to change, and therefore the most reliably accurate — is core to Push’s design philosophy. ",{"data":2398,"content":2399,"nodeType":1294},{},[2400,2404,2414],{"data":2401,"marks":2402,"value":2403,"nodeType":1293},{},[],"Finally, toward the second half of the year, we released ",{"data":2405,"content":2407,"nodeType":1337},{"uri":2406},"https://pushsecurity.com/blog/introducing-cloned-login-page-detection/",[2408],{"data":2409,"marks":2410,"value":2413,"nodeType":1293},{},[2411,2412],{"type":1335},{"type":1772},"cloned login page detection",{"data":2415,"marks":2416,"value":2417,"nodeType":1293},{},[],", a natural extension of our layered approach to preventing phishing attacks in the browser. With this security control, you can identify malicious webpages that are masquerading as legitimate IdP login portals. ",{"data":2419,"content":2423,"nodeType":1377},{"target":2420},{"sys":2421},{"id":2422,"type":1374,"linkType":1375},"4y25OxesssUk9lzEx12HFa",[],{"data":2425,"content":2426,"nodeType":1294},{},[2427],{"data":2428,"marks":2429,"value":2430,"nodeType":1293},{},[],"When a cloned login page is detected, you can add the URL to your blocklist in Push and prevent any other employees from being targeted. ",{"data":2432,"content":2433,"nodeType":1294},{},[2434,2438,2447],{"data":2435,"marks":2436,"value":2437,"nodeType":1293},{},[],"By layering multiple anti-phishing controls that all prevent account takeover, defenders have the best chance at thwarting the ",{"data":2439,"content":2441,"nodeType":1337},{"uri":2440},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[2442],{"data":2443,"marks":2444,"value":2446,"nodeType":1293},{},[2445],{"type":1335},"short, fast attack chains",{"data":2448,"marks":2449,"value":2450,"nodeType":1293},{},[]," that are emblematic of today’s identity attacks.",{"data":2452,"content":2453,"nodeType":1993},{},[],{"data":2455,"content":2456,"nodeType":1392},{},[2457],{"data":2458,"marks":2459,"value":2460,"nodeType":1293},{},[],"Defending against stolen sessions and stolen credentials",{"data":2462,"content":2463,"nodeType":1294},{},[2464,2468,2477],{"data":2465,"marks":2466,"value":2467,"nodeType":1293},{},[],"With as little as $10 to buy a stolen password and a little skill, attackers capitalized on the use of stolen credentials last year. Stolen creds were the No. 1 attacker action in 2023 and 2024, according to ",{"data":2469,"content":2471,"nodeType":1337},{"uri":2470},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[2472],{"data":2473,"marks":2474,"value":2476,"nodeType":1293},{},[2475],{"type":1335},"Verizon",{"data":2478,"marks":2479,"value":1435,"nodeType":1293},{},[],{"data":2481,"content":2482,"nodeType":1294},{},[2483,2487,2496],{"data":2484,"marks":2485,"value":2486,"nodeType":1293},{},[],"Nowhere was this more plain than in the ",{"data":2488,"content":2490,"nodeType":1337},{"uri":2489},"https://pushsecurity.com/blog/snowflake-retro/",[2491],{"data":2492,"marks":2493,"value":2495,"nodeType":1293},{},[2494],{"type":1335},"attacks on Snowflake customers",{"data":2497,"marks":2498,"value":2499,"nodeType":1293},{},[],", one of the biggest breaches of last year. In this incident, cyber criminals targeted around 165 customers of the cloud-based data warehouse tool Snowflake by taking over accounts using credentials harvested from infostealer infections dating as far back as 2020.",{"data":2501,"content":2502,"nodeType":1294},{},[2503],{"data":2504,"marks":2505,"value":2506,"nodeType":1293},{},[],"The Snowflake incident underscored the challenges of control and visibility that security teams face when attempting to secure identities on a patchwork of managed and unmanaged apps:",{"data":2508,"content":2509,"nodeType":1982},{},[2510,2520,2530,2540,2550],{"data":2511,"content":2512,"nodeType":1948},{},[2513],{"data":2514,"content":2515,"nodeType":1294},{},[2516],{"data":2517,"marks":2518,"value":2519,"nodeType":1293},{},[],"Do I know all the workforce accounts my employees use?",{"data":2521,"content":2522,"nodeType":1948},{},[2523],{"data":2524,"content":2525,"nodeType":1294},{},[2526],{"data":2527,"marks":2528,"value":2529,"nodeType":1293},{},[],"Do those accounts have a strong security posture?",{"data":2531,"content":2532,"nodeType":1948},{},[2533],{"data":2534,"content":2535,"nodeType":1294},{},[2536],{"data":2537,"marks":2538,"value":2539,"nodeType":1293},{},[],"Do those accounts use MFA? The most phishing-resistant methods?",{"data":2541,"content":2542,"nodeType":1948},{},[2543],{"data":2544,"content":2545,"nodeType":1294},{},[2546],{"data":2547,"marks":2548,"value":2549,"nodeType":1293},{},[],"Do I have tools to detect, respond, and remediate after an account takeover or breach of a critical software vendor?",{"data":2551,"content":2552,"nodeType":1948},{},[2553],{"data":2554,"content":2555,"nodeType":1294},{},[2556],{"data":2557,"marks":2558,"value":2559,"nodeType":1293},{},[],"Do I know when a session has been stolen, pointing to a device compromised by infostealer malware?",{"data":2561,"content":2562,"nodeType":1294},{},[2563],{"data":2564,"marks":2565,"value":2566,"nodeType":1293},{},[],"Here’s what we delivered last year to make it easier for security teams to protect their organizations from the threat of stolen sessions and stolen creds.",{"data":2568,"content":2569,"nodeType":1993},{},[],{"data":2571,"content":2572,"nodeType":1392},{},[2573],{"data":2574,"marks":2575,"value":2576,"nodeType":1293},{},[],"Detecting stolen sessions",{"data":2578,"content":2579,"nodeType":2075},{},[2580],{"data":2581,"marks":2582,"value":2070,"nodeType":1293},{},[2583],{"type":1772},{"data":2585,"content":2586,"nodeType":1294},{},[2587,2590,2599],{"data":2588,"marks":2589,"value":37,"nodeType":1293},{},[],{"data":2591,"content":2593,"nodeType":1337},{"uri":2592},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/",[2594],{"data":2595,"marks":2596,"value":2598,"nodeType":1293},{},[2597],{"type":1335},"Infostealer malware",{"data":2600,"marks":2601,"value":2602,"nodeType":1293},{},[]," — a type of malware designed to collect user credentials, including session cookies, from end-user devices — had a very successful 2024, accounting for nearly 10 percent of activity that Red Canary was able to associate with named threats, and the majority of all detected malware that Sophos threat researchers documented last year.",{"data":2604,"content":2605,"nodeType":1294},{},[2606,2610,2619],{"data":2607,"marks":2608,"value":2609,"nodeType":1293},{},[],"While the use of stolen credentials is rampant, often facilitated by successful infostealer campaigns, a related attack type also ",{"data":2611,"content":2613,"nodeType":1337},{"uri":2612},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/#id-the-state-of-infostealers-today",[2614],{"data":2615,"marks":2616,"value":2618,"nodeType":1293},{},[2617],{"type":1335},"jumped in prevalence",{"data":2620,"marks":2621,"value":2622,"nodeType":1293},{},[]," last year: session token theft attacks.",{"data":2624,"content":2625,"nodeType":1294},{},[2626],{"data":2627,"marks":2628,"value":2629,"nodeType":1293},{},[],"Using stolen tokens, adversaries don’t need to bypass MFA directly. They can simply import the tokens into their browser and assume an already authorized session. ",{"data":2631,"content":2632,"nodeType":2075},{},[2633],{"data":2634,"marks":2635,"value":2143,"nodeType":1293},{},[2636],{"type":1772},{"data":2638,"content":2639,"nodeType":1294},{},[2640],{"data":2641,"marks":2642,"value":2643,"nodeType":1293},{},[],"In order to detect a stolen session in use, you need telemetry that allows you to tie activity to a trusted endpoint. This didn’t previously exist, and you have to be in the browser to do it. So that’s what we built. ",{"data":2645,"content":2646,"nodeType":1294},{},[2647,2651,2661],{"data":2648,"marks":2649,"value":2650,"nodeType":1293},{},[],"Push’s ",{"data":2652,"content":2654,"nodeType":1337},{"uri":2653},"https://pushsecurity.com/blog/introducing-session-token-theft-detection-why-browser-is-best/",[2655],{"data":2656,"marks":2657,"value":2660,"nodeType":1293},{},[2658,2659],{"type":1335},{"type":1772},"session theft detection",{"data":2662,"marks":2663,"value":2664,"nodeType":1293},{},[]," capability uses the power of the Push browser extension to inject a unique marker into the user-agent string of sessions that occur in browsers enrolled in Push. ",{"data":2666,"content":2667,"nodeType":1294},{},[2668],{"data":2669,"marks":2670,"value":2671,"nodeType":1293},{},[],"By analyzing logs from your IdP in your SIEM, you can then identify activity from the same session that both has and that lacks the Push marker, indicating that a session has been extracted from the browser and maliciously imported into a different browser that is not enrolled in Push.",{"data":2673,"content":2674,"nodeType":1294},{},[2675],{"data":2676,"marks":2677,"value":2678,"nodeType":1293},{},[],"This is a reliable signal that a stolen session token is being used and an endpoint has been compromised.",{"data":2680,"content":2684,"nodeType":1377},{"target":2681},{"sys":2682},{"id":2683,"type":1374,"linkType":1375},"1XNNkaoW64t3PPvC54KGXF",[],{"data":2686,"content":2690,"nodeType":1377},{"target":2687},{"sys":2688},{"id":2689,"type":1374,"linkType":1375},"6dOEnPzZXd9DqeSdalqlzO",[],{"data":2692,"content":2693,"nodeType":1993},{},[],{"data":2695,"content":2696,"nodeType":1392},{},[2697],{"data":2698,"marks":2699,"value":2700,"nodeType":1293},{},[],"Detecting compromised credentials",{"data":2702,"content":2703,"nodeType":2075},{},[2704],{"data":2705,"marks":2706,"value":2070,"nodeType":1293},{},[2707],{"type":1772},{"data":2709,"content":2710,"nodeType":1294},{},[2711],{"data":2712,"marks":2713,"value":2714,"nodeType":1293},{},[],"Alongside stolen session cookies, stolen credentials made a lot of headlines last year. The 2024 Verizon DBIR found that 79% of web application compromises were the result of breached creds, and researchers at IBM found a 71% year-over-year increase in cyberattacks using stolen or compromised credentials.",{"data":2716,"content":2717,"nodeType":1294},{},[2718,2722,2731],{"data":2719,"marks":2720,"value":2721,"nodeType":1293},{},[],"In Push’s own research, we counted ",{"data":2723,"content":2725,"nodeType":1337},{"uri":2724},"https://pushsecurity.com/blog/2024-identity-breaches/",[2726],{"data":2727,"marks":2728,"value":2730,"nodeType":1293},{},[2729],{"type":1335},"30 public identity-related breaches",{"data":2732,"marks":2733,"value":2734,"nodeType":1293},{},[]," in 2024 where the breach and the breach vector were disclosed. Of those, nearly three-quarters were the result of compromised credentials, including notable breaches such as Microsoft, Change Healthcare, and the attacks on Snowflake customers.",{"data":2736,"content":2737,"nodeType":2745},{},[2738],{"data":2739,"content":2740,"nodeType":1294},{},[2741],{"data":2742,"marks":2743,"value":2744,"nodeType":1293},{},[],"73% of public identity-related breaches in 2024 were the result of compromised credentials (the rest were phishing attacks). ","blockquote",{"data":2747,"content":2748,"nodeType":1294},{},[2749,2753,2761],{"data":2750,"marks":2751,"value":2752,"nodeType":1293},{},[],"The influx of compromised credentials has been amplified by the ",{"data":2754,"content":2755,"nodeType":1337},{"uri":2592},[2756],{"data":2757,"marks":2758,"value":2760,"nodeType":1293},{},[2759],{"type":1335},"rise of infostealers",{"data":2762,"marks":2763,"value":2764,"nodeType":1293},{},[],", which contribute the vast majority of valid stolen credentials, alongside mass credential phishing campaigns and third-party data breach dumps. ",{"data":2766,"content":2767,"nodeType":1294},{},[2768],{"data":2769,"marks":2770,"value":2771,"nodeType":1293},{},[],"And while there’s no shortage of threat intelligence about stolen credentials for sale on the web, security teams struggle to separate the needle from the haystack because a large portion of TI on stolen creds is out of date.",{"data":2773,"content":2774,"nodeType":1294},{},[2775],{"data":2776,"marks":2777,"value":2778,"nodeType":1293},{},[],"In evaluating TI data here at Push, we reviewed 5,763 username and password combos that matched domains in use by Push customers. We found that less than 1% of the creds in a multi-vendor dataset were true positives. In other words, 99.5% of the stolen creds we checked were false positives at the time of review — illustrating the challenge security teams face when trying to extract actionable intelligence from this kind of data. ",{"data":2780,"content":2781,"nodeType":2745},{},[2782],{"data":2783,"content":2784,"nodeType":1294},{},[2785],{"data":2786,"marks":2787,"value":2788,"nodeType":1293},{},[],"99.5% of the findings in compromised credential feeds were found to be false positives.",{"data":2790,"content":2791,"nodeType":2075},{},[2792],{"data":2793,"marks":2794,"value":2143,"nodeType":1293},{},[2795],{"type":1772},{"data":2797,"content":2798,"nodeType":1294},{},[2799],{"data":2800,"marks":2801,"value":2802,"nodeType":1293},{},[],"Using its browser agent, Push assesses the strength of end-user passwords by creating and analyzing a truncated, salted SHA256 hash of the password for a given account. (These k-anonymized fingerprints are never seen by Push’s back-end and exist only in local browser extension storage.) ",{"data":2804,"content":2805,"nodeType":1294},{},[2806,2810,2820],{"data":2807,"marks":2808,"value":2809,"nodeType":1293},{},[],"These fingerprints give Push a directly observable source of truth for corporate creds, which allowed us to build a ",{"data":2811,"content":2813,"nodeType":1337},{"uri":2812},"https://pushsecurity.com/blog/verified-stolen-credential-detection/",[2814],{"data":2815,"marks":2816,"value":2819,"nodeType":1293},{},[2817,2818],{"type":1335},{"type":1772},"verified stolen credential detection",{"data":2821,"marks":2822,"value":2823,"nodeType":1293},{},[]," capability last year that removes all false positives from TI sources to pinpoint only those stolen creds still actively in use by employees.",{"data":2825,"content":2829,"nodeType":1377},{"target":2826},{"sys":2827},{"id":2828,"type":1374,"linkType":1375},"3BITHZvDadjHpOAqIn0g4w",[],{"data":2831,"content":2832,"nodeType":1993},{},[],{"data":2834,"content":2835,"nodeType":1392},{},[2836],{"data":2837,"marks":2838,"value":2839,"nodeType":1293},{},[],"Reducing and securing shadow IT and account sprawl",{"data":2841,"content":2842,"nodeType":1294},{},[2843],{"data":2844,"marks":2845,"value":2846,"nodeType":1293},{},[],"You can think of this last part of the story as the ground from which the attack trends we’ve been talking about emerged: The shift to doing business almost entirely in the browser, and the resulting sprawl in accounts and unmanaged apps, leading to an explosion of internet-facing identities for threat actors to target.",{"data":2848,"content":2849,"nodeType":1294},{},[2850],{"data":2851,"marks":2852,"value":2853,"nodeType":1293},{},[],"Even in organizations with mature security practices, the challenge of getting 100% compliance with identity posture best practices is evident. Last year, Push researchers analyzed a data set of 300,000 accounts from our customer base and found that:",{"data":2855,"content":2856,"nodeType":1982},{},[2857,2876,2895],{"data":2858,"content":2859,"nodeType":1948},{},[2860],{"data":2861,"content":2862,"nodeType":1294},{},[2863,2867,2872],{"data":2864,"marks":2865,"value":2866,"nodeType":1293},{},[],"Organizations have ",{"data":2868,"marks":2869,"value":2871,"nodeType":1293},{},[2870],{"type":1772},"more apps and identities than they thought",{"data":2873,"marks":2874,"value":2875,"nodeType":1293},{},[]," — an average of ~15 identities per employee and ~220 apps per organization.",{"data":2877,"content":2878,"nodeType":1948},{},[2879],{"data":2880,"content":2881,"nodeType":1294},{},[2882,2886,2891],{"data":2883,"marks":2884,"value":2885,"nodeType":1293},{},[],"Many accounts ",{"data":2887,"marks":2888,"value":2890,"nodeType":1293},{},[2889],{"type":1772},"lack basic security protections",{"data":2892,"marks":2893,"value":2894,"nodeType":1293},{},[],", with 37% of accounts lacking any form of MFA and ~9% of accounts using a password that is leaked, weak, or reused, making them especially susceptible to account takeover. On accounts where password is the only login method in use (e.g. not using SSO or any other federated login like OIDC), there was no MFA in use in 4 out of 5 cases.",{"data":2896,"content":2897,"nodeType":1948},{},[2898],{"data":2899,"content":2900,"nodeType":1294},{},[2901,2905,2910,2914,2923],{"data":2902,"marks":2903,"value":2904,"nodeType":1293},{},[],"Security ",{"data":2906,"marks":2907,"value":2909,"nodeType":1293},{},[2908],{"type":1772},"gaps persist even with SSO",{"data":2911,"marks":2912,"value":2913,"nodeType":1293},{},[]," accounts — with 10% of SSO-using accounts also having a local password, a risk for ",{"data":2915,"content":2917,"nodeType":1337},{"uri":2916},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/",[2918],{"data":2919,"marks":2920,"value":2922,"nodeType":1293},{},[2921],{"type":1335},"ghost logins",{"data":2924,"marks":2925,"value":2926,"nodeType":1293},{},[],"; and 1 in 5 IdP accounts themselves missing MFA.",{"data":2928,"content":2929,"nodeType":1294},{},[2930],{"data":2931,"marks":2932,"value":2933,"nodeType":1293},{},[],"From our perspective, organizations need scalable controls, and they need easy-to-deploy tools that get them visibility of all their workforce identities, apps, and accounts alongside telemetry that makes the information actionable.",{"data":2935,"content":2936,"nodeType":1294},{},[2937],{"data":2938,"marks":2939,"value":2940,"nodeType":1293},{},[],"Push already provides a real-time inventory of all your accounts and apps, including internal corporate apps, and analyzes the security posture, login methods, and MFA status of those accounts to offer a comprehensive picture of your identity attack surface. ",{"data":2942,"content":2943,"nodeType":1294},{},[2944],{"data":2945,"marks":2946,"value":2947,"nodeType":1293},{},[],"To help customers enforce their security policies even more seamlessly, here’s what we built last year:",{"data":2949,"content":2950,"nodeType":2075},{},[2951],{"data":2952,"marks":2953,"value":2955,"nodeType":1293},{},[2954],{"type":1772},"1. App banners",{"data":2957,"content":2958,"nodeType":1294},{},[2959,2963,2973],{"data":2960,"marks":2961,"value":2962,"nodeType":1293},{},[],"With a range of modes from informing to blocking, ",{"data":2964,"content":2966,"nodeType":1337},{"uri":2965},"https://pushsecurity.com/help/10106#start",[2967],{"data":2968,"marks":2969,"value":2972,"nodeType":1293},{},[2970,2971],{"type":1335},{"type":1772},"app banners",{"data":2974,"marks":2975,"value":2976,"nodeType":1293},{},[]," allow security teams to communicate best practices and policies with end-users directly in their browser. It works by displaying a banner with your custom message on the login and signup pages for workplace apps. ",{"data":2978,"content":2979,"nodeType":1294},{},[2980],{"data":2981,"marks":2982,"value":2983,"nodeType":1293},{},[],"Using configuration rules, you can set conditions for how banner controls get applied. Common use cases include: Restricting use of GenAI software; carving out an exception for admins on a specific app; reminding users to log in with SSO instead of a password, and others. ",{"data":2985,"content":2989,"nodeType":1377},{"target":2986},{"sys":2987},{"id":2988,"type":1374,"linkType":1375},"4RPHmeMLyZmb5V8rXYLtey",[],{"data":2991,"content":2992,"nodeType":2075},{},[2993,2998],{"data":2994,"marks":2995,"value":2997,"nodeType":1293},{},[2996],{"type":1772},"2. Password manager identification",{"data":2999,"marks":3000,"value":2074,"nodeType":1293},{},[],{"data":3002,"content":3003,"nodeType":1294},{},[3004,3008,3018],{"data":3005,"marks":3006,"value":3007,"nodeType":1293},{},[],"We also expanded Push’s capability to observe employees’ account security posture by adding an identification of ",{"data":3009,"content":3011,"nodeType":1337},{"uri":3010},"https://pushsecurity.com/blog/stop-users-saving-corp-creds-into-personal-password-managers/",[3012],{"data":3013,"marks":3014,"value":3017,"nodeType":1293},{},[3015,3016],{"type":1335},{"type":1772},"which password manager",{"data":3019,"marks":3020,"value":3021,"nodeType":1293},{},[]," (if any) they’re using. ",{"data":3023,"content":3024,"nodeType":1294},{},[3025],{"data":3026,"marks":3027,"value":3028,"nodeType":1293},{},[],"We’ve heard from many security teams that they’re concerned about corporate credentials being stored in unapproved password managers — not to mention the ROI from ensuring employees are all using the corporate password manager you already pay for. This feature helps them achieve both objectives.",{"data":3030,"content":3031,"nodeType":2075},{},[3032],{"data":3033,"marks":3034,"value":3036,"nodeType":1293},{},[3035],{"type":1772},"3. MFA enforcement",{"data":3038,"content":3039,"nodeType":1294},{},[3040,3044,3054],{"data":3041,"marks":3042,"value":3043,"nodeType":1293},{},[],"Finally, we rounded out 2024 with a new security control called ",{"data":3045,"content":3047,"nodeType":1337},{"uri":3046},"https://pushsecurity.com/blog/enforce-mfa-on-third-party-apps/",[3048],{"data":3049,"marks":3050,"value":3053,"nodeType":1293},{},[3051,3052],{"type":1335},{"type":1772},"MFA enforcement",{"data":3055,"marks":3056,"value":3057,"nodeType":1293},{},[]," that builds on the popular app banners concept by detecting when users lack MFA and then prompting them to register for MFA. ",{"data":3059,"content":3060,"nodeType":1294},{},[3061],{"data":3062,"marks":3063,"value":3064,"nodeType":1293},{},[],"Admins choose which apps they wish to enforce MFA on, and the Push extension does the rest. ",{"data":3066,"content":3067,"nodeType":1294},{},[3068],{"data":3069,"marks":3070,"value":3071,"nodeType":1293},{},[],"Security teams we work with are especially eager to use this feature to close MFA coverage gaps on non-SSO and otherwise unmanaged applications.",{"data":3073,"content":3077,"nodeType":1377},{"target":3074},{"sys":3075},{"id":3076,"type":1374,"linkType":1375},"4imhff7SWJi2Gan5iFEs2P",[],{"data":3079,"content":3080,"nodeType":1993},{},[],{"data":3082,"content":3083,"nodeType":1392},{},[3084],{"data":3085,"marks":3086,"value":3087,"nodeType":1293},{},[],"Want to see more?",{"data":3089,"content":3090,"nodeType":1294},{},[3091,3095,3103],{"data":3092,"marks":3093,"value":3094,"nodeType":1293},{},[],"There’s a lot we didn’t touch on here that Push can help you achieve. If you’d like to learn more, ",{"data":3096,"content":3098,"nodeType":1337},{"uri":3097},"https://pushsecurity.com/demo/",[3099],{"data":3100,"marks":3101,"value":3102,"nodeType":1293},{},[],"set up a demo with our team",{"data":3104,"marks":3105,"value":3106,"nodeType":1293},{},[]," or sign up yourself to have a look at the platform.","How real-world attacks and research drove Push’s most popular features of 2024","How in-the-wild attacks and our own R&D inspired what we built in 2024 to stop account takeover and reduce security risks across your workforce identities. ","2025-01-16T00:00:00.000Z","push-features-2024",{"items":3112},[3113,3115],{"sys":3114,"name":1309},{"id":1308},{"sys":3116,"name":3118},{"id":3117},"3pjES4THCIfSAwhGdNwBcy","Identity security",{"items":3120},[3121],{"fullName":3122,"firstName":3123,"jobTitle":3124,"profilePicture":3125},"Kelly Davenport","Kelly","Product Team",{"url":3126},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1313,"sys":3128,"content":3130,"title":3447,"synopsis":3448,"hashTags":118,"publishedDate":3449,"slug":3450,"tagsCollection":3451,"authorsCollection":3457},{"id":3129},"4bYO5rVy9n2OO3vtMVQeda",{"json":3131},{"nodeType":1295,"data":3132,"content":3133},{},[3134,3141,3160,3176,3183,3190,3193,3200,3207,3260,3267,3273,3276,3283,3290,3297,3304,3311,3328,3334,3341,3348,3365,3371,3378,3385,3392,3399,3406,3409,3416,3435,3441],{"nodeType":1392,"data":3135,"content":3136},{},[3137],{"nodeType":1293,"value":3138,"marks":3139,"data":3140},"All phishing eventually leads to the browser",[],{},{"nodeType":1294,"data":3142,"content":3143},{},[3144,3148,3157],{"nodeType":1293,"value":3145,"marks":3146,"data":3147},"The best attack detection methods are those that focus on ",[],{},{"nodeType":1337,"data":3149,"content":3151},{"uri":3150},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[3152],{"nodeType":1293,"value":3153,"marks":3154,"data":3156},"detecting indicators that are difficult for attackers to change or obfuscate",[3155],{"type":1335},{},{"nodeType":1293,"value":2369,"marks":3158,"data":3159},[],{},{"nodeType":1294,"data":3161,"content":3162},{},[3163,3167,3172],{"nodeType":1293,"value":3164,"marks":3165,"data":3166},"For a credential phishing attack to succeed, the victim ",[],{},{"nodeType":1293,"value":3168,"marks":3169,"data":3171},"has",[3170],{"type":1335},{},{"nodeType":1293,"value":3173,"marks":3174,"data":3175}," to enter their password into a webpage. There’s no two-ways about it, attackers cannot change this. ",[],{},{"nodeType":1294,"data":3177,"content":3178},{},[3179],{"nodeType":1293,"value":3180,"marks":3181,"data":3182},"So it stands to reason that, if you can detect this user behavior, and block them from entering their password, then you can stop phishing. ",[],{},{"nodeType":1294,"data":3184,"content":3185},{},[3186],{"nodeType":1293,"value":3187,"marks":3188,"data":3189},"This is exactly what Push does.",[],{},{"nodeType":1993,"data":3191,"content":3192},{},[],{"nodeType":2075,"data":3194,"content":3195},{},[3196],{"nodeType":1293,"value":3197,"marks":3198,"data":3199},"Most anti-phishing tools are easily bypassed",[],{},{"nodeType":1294,"data":3201,"content":3202},{},[3203],{"nodeType":1293,"value":3204,"marks":3205,"data":3206},"Other anti-phishing tools rely on detecting elements of the attack that attackers can change and hide, such as domains or the webpage contents. Attackers use tricks to evade these detection, like:",[],{},{"nodeType":1982,"data":3208,"content":3209},{},[3210,3220,3230,3240,3250],{"nodeType":1948,"data":3211,"content":3212},{},[3213],{"nodeType":1294,"data":3214,"content":3215},{},[3216],{"nodeType":1293,"value":3217,"marks":3218,"data":3219},"Using Cloudflare Workers to block automatic analysis of their phishing site",[],{},{"nodeType":1948,"data":3221,"content":3222},{},[3223],{"nodeType":1294,"data":3224,"content":3225},{},[3226],{"nodeType":1293,"value":3227,"marks":3228,"data":3229},"Hacking a Wordpress blog to get a reputable domain that passes domain checks ",[],{},{"nodeType":1948,"data":3231,"content":3232},{},[3233],{"nodeType":1294,"data":3234,"content":3235},{},[3236],{"nodeType":1293,"value":3237,"marks":3238,"data":3239},"Using redirects and rotating the URLs delivered to the victim to bypass link analysis",[],{},{"nodeType":1948,"data":3241,"content":3242},{},[3243],{"nodeType":1294,"data":3244,"content":3245},{},[3246],{"nodeType":1293,"value":3247,"marks":3248,"data":3249},"Randomizing the HTML title for the web page to bypass blocklists ",[],{},{"nodeType":1948,"data":3251,"content":3252},{},[3253],{"nodeType":1294,"data":3254,"content":3255},{},[3256],{"nodeType":1293,"value":3257,"marks":3258,"data":3259},"One-time phishing links that only work the first time they are clicked",[],{},{"nodeType":1294,"data":3261,"content":3262},{},[3263],{"nodeType":1293,"value":3264,"marks":3265,"data":3266},"Push is putting an end to this game of cat and mouse, by keeping it really simple; you can’t phish someone who can’t put their password into a phishing page. ",[],{},{"nodeType":1377,"data":3268,"content":3272},{"target":3269},{"sys":3270},{"id":3271,"type":1374,"linkType":1375},"6AwOZSpqaChmeksnj4SyWE",[],{"nodeType":1993,"data":3274,"content":3275},{},[],{"nodeType":2075,"data":3277,"content":3278},{},[3279],{"nodeType":1293,"value":3280,"marks":3281,"data":3282},"Domain-binding passwords",[],{},{"nodeType":1294,"data":3284,"content":3285},{},[3286],{"nodeType":1293,"value":3287,"marks":3288,"data":3289},"If you’re familiar with how passkeys are domain-bound, then think of what Push does as domain-binding passwords. We pin the password to its legitimate domain(s) and then don’t allow it to be entered into any webpage on any other domain. ",[],{},{"nodeType":1294,"data":3291,"content":3292},{},[3293],{"nodeType":1293,"value":3294,"marks":3295,"data":3296},"But just because you’ve stopped your users from being phished doesn’t mean you don’t want to know when attackers are attempting to phish your users and how. ",[],{},{"nodeType":1294,"data":3298,"content":3299},{},[3300],{"nodeType":1293,"value":3301,"marks":3302,"data":3303},"Push still inspects webpages to see if attackers are rendering cloned app login pages in the browser or if known AitM and BitM toolkits are being used. This way you don’t lose visibility of the unsuccessful attacks that are targeting your users. Think of it as a handy second and third layer of defense.",[],{},{"nodeType":1294,"data":3305,"content":3306},{},[3307],{"nodeType":1293,"value":3308,"marks":3309,"data":3310},"Lets run through a quick before and after example:",[],{},{"nodeType":2075,"data":3312,"content":3313},{},[3314,3318,3324],{"nodeType":1293,"value":3315,"marks":3316,"data":3317},"Scenario 1: An attacker attempts to phish an employee that ",[],{},{"nodeType":1293,"value":3319,"marks":3320,"data":3323},"doesn’t",[3321,3322],{"type":1335},{"type":1772},{},{"nodeType":1293,"value":3325,"marks":3326,"data":3327}," have Push deployed to their browser.",[],{},{"nodeType":1377,"data":3329,"content":3333},{"target":3330},{"sys":3331},{"id":3332,"type":1374,"linkType":1375},"2CbGMUSJsP1mNeHkmpLl6N",[],{"nodeType":1294,"data":3335,"content":3336},{},[3337],{"nodeType":1293,"value":3338,"marks":3339,"data":3340},"Here, an attacker hacks a Wordpress blog to get a reputable domain and then runs a phishing toolkit on the webpage. They email one of your employees a link to it. Your SWG / email scanning solution inspects it in a sandbox but the phish kit detects this and redirects to a benign site so that it passes the inspection. ",[],{},{"nodeType":1294,"data":3342,"content":3343},{},[3344],{"nodeType":1293,"value":3345,"marks":3346,"data":3347},"Your user gets the email with the link and is now free to interact with the phishing page. They enter their credentials plus MFA code into the page and voila! The attacker steals them and is able to compromise the user’s account.  ",[],{},{"nodeType":2075,"data":3349,"content":3350},{},[3351,3355,3361],{"nodeType":1293,"value":3352,"marks":3353,"data":3354},"Scenario 2: An attacker attempts to phish an employee that ",[],{},{"nodeType":1293,"value":3356,"marks":3357,"data":3360},"does",[3358,3359],{"type":1335},{"type":1772},{},{"nodeType":1293,"value":3362,"marks":3363,"data":3364}," have Push deployed to their browser. ",[],{},{"nodeType":1377,"data":3366,"content":3370},{"target":3367},{"sys":3368},{"id":3369,"type":1374,"linkType":1375},"77smnID1woCfFJrJPyTvKY",[],{"nodeType":1294,"data":3372,"content":3373},{},[3374],{"nodeType":1293,"value":3375,"marks":3376,"data":3377},"This time, the attacker uses the same phishing toolkit and domain from the first example. But in reality, they don’t have to send it to your employee using email, instead, they could use LinkedIn messenger, Slack, Teams, or any application that allows employees to communicate with each other. ",[],{},{"nodeType":1294,"data":3379,"content":3380},{},[3381],{"nodeType":1293,"value":3382,"marks":3383,"data":3384},"Like before, the user receives the link, opens it and starts to enter their credentials into the webpage. This time though, the Push browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page.",[],{},{"nodeType":1294,"data":3386,"content":3387},{},[3388],{"nodeType":1293,"value":3389,"marks":3390,"data":3391},"The first detection Push makes is checking that the password the user is entering matches the domain that password is pinned to. Since it doesn't match, based on this detection alone the user is automatically redirected to a blocking page. An important point to make here is that the password never leaves the user’s browser and the check is made using a shortened salted hash of the password.   ",[],{},{"nodeType":1294,"data":3393,"content":3394},{},[3395],{"nodeType":1293,"value":3396,"marks":3397,"data":3398},"The second detection Push makes is that the rendered web app is using a cloned app login page. The third detection is that a phishing toolkit is running in the web app code. ",[],{},{"nodeType":1294,"data":3400,"content":3401},{},[3402],{"nodeType":1293,"value":3403,"marks":3404,"data":3405},"In this particular scenario these second and third detections serve as useful context for understanding the nature of the phishing attack. But both will still redirect to a blocking page if they are triggered in isolation of the other phishing detections. ",[],{},{"nodeType":1993,"data":3407,"content":3408},{},[],{"nodeType":1392,"data":3410,"content":3411},{},[3412],{"nodeType":1293,"value":3413,"marks":3414,"data":3415},"We don’t just stop phishing attacks",[],{},{"nodeType":1294,"data":3417,"content":3418},{},[3419,3423,3431],{"nodeType":1293,"value":3420,"marks":3421,"data":3422},"We also detect other identity-related attack techniques used to compromise user accounts. That includes credential stuffing, password spraying and session hijacking using stolen session tokens. If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",[],{},{"nodeType":1337,"data":3424,"content":3425},{"uri":3097},[3426],{"nodeType":1293,"value":3427,"marks":3428,"data":3430},"book some time with one of our team",[3429],{"type":1335},{},{"nodeType":1293,"value":3432,"marks":3433,"data":3434},".  ",[],{},{"nodeType":1377,"data":3436,"content":3440},{"target":3437},{"sys":3438},{"id":3439,"type":1374,"linkType":1375},"2JSmYDaiAciOx7Z1MRuJlA",[],{"nodeType":1294,"data":3442,"content":3443},{},[3444],{"nodeType":1293,"value":37,"marks":3445,"data":3446},[],{},"Detecting and blocking phishing attacks in the browser","How Push detects and blocks phishing attempts in the browser – explained in less than two minutes. ","2024-10-23T00:00:00.000Z","detecting-and-blocking-phishing-attacks-in-the-browser",{"items":3452},[3453,3455],{"sys":3454,"name":1305},{"id":1304},{"sys":3456,"name":1309},{"id":1308},{"items":3458},[3459],{"fullName":3460,"firstName":3461,"jobTitle":3124,"profilePicture":3462},"Alex Henshall","Alex",{"url":3463},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg",{"url":3465},"https://images.ctfassets.net/y1cdw1ablpvd/5D3plIXabnqgyWWtxOXjHp/985db5f050236a3cfb7051dc873a39e2/1_-_Thumbnail.png",{"items":3467},[3468],{"fullName":3469,"firstName":3470,"jobTitle":3471,"profilePicture":3472},"Dan Green","Dan","Threat Research",{"url":3473},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"json":3475,"links":4094},{"nodeType":1295,"data":3476,"content":3477},{},[3478,3485,3515,3521,3528,3531,3539,3546,3553,3586,3593,3600,3607,3610,3618,3637,3644,3651,3657,3664,3671,3674,3682,3689,3696,3702,3709,3729,3762,3769,3772,3780,3787,3794,3799,3806,3813,3820,3826,3833,3839,3846,3849,3857,3864,3871,3874,3882,3889,3896,3903,3906,3914,3921,3928,3935,3942,3949,3954,3961,3968,3973,3980,4013,4020,4032,4052,4058,4061,4068,4075],{"nodeType":1294,"data":3479,"content":3480},{},[3481],{"nodeType":1293,"value":3482,"marks":3483,"data":3484},"Most organizations today have invested in an email security solution of some description. But even the most premium tools have significant limitations when it comes to modern phishing attacks. ",[],{},{"nodeType":1294,"data":3486,"content":3487},{},[3488,3492,3499,3503,3512],{"nodeType":1293,"value":3489,"marks":3490,"data":3491},"The data speaks for itself — phishing remains as big a problem as it ever was (if not bigger!) despite enormous investment in security products and training. In 2024, identity-based attack vectors involving a human element (phishing and stolen credentials) accounted for 80% of the initial access observed by ",[],{},{"nodeType":1337,"data":3493,"content":3494},{"uri":2470},[3495],{"nodeType":1293,"value":2476,"marks":3496,"data":3498},[3497],{"type":1335},{},{"nodeType":1293,"value":3500,"marks":3501,"data":3502},", while 69% of organizations experienced a phishing incident in 2024 according to ",[],{},{"nodeType":1337,"data":3504,"content":3506},{"uri":3505},"https://www.idsalliance.org/white-paper/2024-trends-in-securing-digital-identities/",[3507],{"nodeType":1293,"value":3508,"marks":3509,"data":3511},"IDSA",[3510],{"type":1335},{},{"nodeType":1293,"value":2369,"marks":3513,"data":3514},[],{},{"nodeType":1377,"data":3516,"content":3520},{"target":3517},{"sys":3518},{"id":3519,"type":1374,"linkType":1375},"4urh9lIuo0ePgVIJZNtP2B",[],{"nodeType":1294,"data":3522,"content":3523},{},[3524],{"nodeType":1293,"value":3525,"marks":3526,"data":3527},"So, why are phishing attacks still so effective for attackers? ",[],{},{"nodeType":1993,"data":3529,"content":3530},{},[],{"nodeType":1392,"data":3532,"content":3533},{},[3534],{"nodeType":1293,"value":3535,"marks":3536,"data":3538},"Modern phishing attacks are evading established controls",[3537],{"type":1772},{},{"nodeType":1294,"data":3540,"content":3541},{},[3542],{"nodeType":1293,"value":3543,"marks":3544,"data":3545},"Let’s start with the lay of the land: What controls and capabilities do organizations typically rely on when it comes to blocking credential phishing?  ",[],{},{"nodeType":1294,"data":3547,"content":3548},{},[3549],{"nodeType":1293,"value":3550,"marks":3551,"data":3552},"If you’re using an email security solution, you’re relying on the following core capabilities when it comes to detecting malicious phishing pages:",[],{},{"nodeType":1982,"data":3554,"content":3555},{},[3556,3571],{"nodeType":1948,"data":3557,"content":3558},{},[3559],{"nodeType":1294,"data":3560,"content":3561},{},[3562,3567],{"nodeType":1293,"value":3563,"marks":3564,"data":3566},"Known-bad blocklists:",[3565],{"type":1772},{},{"nodeType":1293,"value":3568,"marks":3569,"data":3570}," Block users from accessing known-bad or unapproved domains/URLs, and block traffic from known-bad malicious IPs, using Threat Intelligence (TI) feeds.",[],{},{"nodeType":1948,"data":3572,"content":3573},{},[3574],{"nodeType":1294,"data":3575,"content":3576},{},[3577,3582],{"nodeType":1293,"value":3578,"marks":3579,"data":3581},"Malicious webpage detection:",[3580],{"type":1772},{},{"nodeType":1293,"value":3583,"marks":3584,"data":3585}," Inspect webpages by loading them in a sandbox to detect malicious elements.",[],{},{"nodeType":1294,"data":3587,"content":3588},{},[3589],{"nodeType":1293,"value":3590,"marks":3591,"data":3592},"This also applies to other solutions that rely on these capabilities, such as web-based content filtering (e.g. Google Safe Browsing), CASB, SASE, SWG, etc. ",[],{},{"nodeType":1294,"data":3594,"content":3595},{},[3596],{"nodeType":1293,"value":3597,"marks":3598,"data":3599},"But, attackers are now using specific tactics, techniques, procedures (TTPs) and tooling designed to defeat these solutions. ",[],{},{"nodeType":1294,"data":3601,"content":3602},{},[3603],{"nodeType":1293,"value":3604,"marks":3605,"data":3606},"Let’s look at where these controls are falling short. ",[],{},{"nodeType":1993,"data":3608,"content":3609},{},[],{"nodeType":1392,"data":3611,"content":3612},{},[3613],{"nodeType":1293,"value":3614,"marks":3615,"data":3617},"Attackers are innovating with new tooling and techniques",[3616],{"type":1772},{},{"nodeType":1294,"data":3619,"content":3620},{},[3621,3625,3634],{"nodeType":1293,"value":3622,"marks":3623,"data":3624},"The vast majority of phishing attacks today are executed using ",[],{},{"nodeType":1337,"data":3626,"content":3628},{"uri":3627},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/?utm_campaign=9983377-FY25Q1_Bleeping-Computer-Organic-Article&utm_source=bleepingcomputer&utm_medium=sponsored-content&utm_content=organic%20article",[3629],{"nodeType":1293,"value":3630,"marks":3631,"data":3633},"AitM phishing kits — otherwise known as “MFA bypass” kits",[3632],{"type":1335},{},{"nodeType":1293,"value":1435,"marks":3635,"data":3636},[],{},{"nodeType":1294,"data":3638,"content":3639},{},[3640],{"nodeType":1293,"value":3641,"marks":3642,"data":3643},"These kits use dedicated tooling to act as a proxy between the target and a legitimate login portal for an application. This allows the target to log in successfully with a legitimate service they use and even continue to interact with it. ",[],{},{"nodeType":1294,"data":3645,"content":3646},{},[3647],{"nodeType":1293,"value":3648,"marks":3649,"data":3650},"As it’s a proxy to the real application, the page will appear exactly as the user expects, because they are logging into the legitimate site – just taking a detour via the attacker’s device. However, because the attacker is sitting in the middle of this connection, they are able to observe all interactions, intercept authentication material like credentials, MFA codes, and session tokens to take control of the authenticated session and gain control of the user account. ",[],{},{"nodeType":1377,"data":3652,"content":3656},{"target":3653},{"sys":3654},{"id":3655,"type":1374,"linkType":1375},"3ZAawfzPVfhb8cmvWNZEVK",[],{"nodeType":1294,"data":3658,"content":3659},{},[3660],{"nodeType":1293,"value":3661,"marks":3662,"data":3663},"MFA was once widely regarded as the silver bullet for phishing (we all remember the Microsoft stat “MFA prevents over 99% of identity-based attacks”) but this is no longer the case. ",[],{},{"nodeType":1294,"data":3665,"content":3666},{},[3667],{"nodeType":1293,"value":3668,"marks":3669,"data":3670},"Not only are these kits incredibly effective at bypassing other anti-phishing controls like MFA, attackers are building them specifically to evade common detection tooling and techniques. ",[],{},{"nodeType":1993,"data":3672,"content":3673},{},[],{"nodeType":2075,"data":3675,"content":3676},{},[3677],{"nodeType":1293,"value":3678,"marks":3679,"data":3681},"Known-bad blocklists can’t keep up",[3680],{"type":1772},{},{"nodeType":1294,"data":3683,"content":3684},{},[3685],{"nodeType":1293,"value":3686,"marks":3687,"data":3688},"The fundamental limitation with known-bad blocklists is that they focus on indicators that are easy for attackers to change, in turn making detections based on them easy to bypass. ",[],{},{"nodeType":1294,"data":3690,"content":3691},{},[3692],{"nodeType":1293,"value":3693,"marks":3694,"data":3695},"Attackers have gotten pretty good at disguising and rotating these elements. In modern phishing attacks, every target can receive a unique email and link. Even just using a URL shortener can bypass this. It’s equivalent to a malware hash – trivial to change, and therefore not a great thing to pin your detections on. The kind of detection that sits right at the bottom of the Pyramid of Pain. ",[],{},{"nodeType":1377,"data":3697,"content":3701},{"target":3698},{"sys":3699},{"id":3700,"type":1374,"linkType":1375},"6cG2fx3AikwptyEyXKrYCK",[],{"nodeType":1294,"data":3703,"content":3704},{},[3705],{"nodeType":1293,"value":3706,"marks":3707,"data":3708},"You could look at which IP address the user connects to, but these days it’s very simple for attackers to add a new IP to their cloud-hosted server. If a domain is flagged as known-bad, the attacker only has to register a new domain, or compromise a WordPress server on an already trusted domain. Both of these things are happening on a massive scale as attackers pre-plan for the fact that their domains will be burned at some point. Attackers are more than happy to spend $10-$20 per new domain in the grand scheme of the potential proceeds of crime. ",[],{},{"nodeType":1294,"data":3710,"content":3711},{},[3712,3716,3725],{"nodeType":1293,"value":3713,"marks":3714,"data":3715},"For example, ",[],{},{"nodeType":1337,"data":3717,"content":3719},{"uri":3718},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection/?utm_campaign=9983377-FY25Q1_Bleeping-Computer-Organic-Article&utm_source=bleepingcomputer&utm_medium=sponsored-content&utm_content=organic%20article",[3720],{"nodeType":1293,"value":3721,"marks":3722,"data":3724},"recent examples of Adversary-in-the-Middle phishing kits",[3723],{"type":1335},{},{"nodeType":1293,"value":3726,"marks":3727,"data":3728}," including Tycoon, Nakedpages, Evilginx were seen to rotate the URLs they resolve to (from a continually refreshed pool of URLs), mask the HTTP Referer header to disguise suspicious redirects, and redirect to benign (legitimate) domains if anyone but the intended victims attempted to visit the page. ",[],{},{"nodeType":1294,"data":3730,"content":3731},{},[3732,3736,3745,3749,3758],{"nodeType":1293,"value":3733,"marks":3734,"data":3735},"And in many cases, attackers are ",[],{},{"nodeType":1337,"data":3737,"content":3739},{"uri":3738},"https://www.bleepingcomputer.com/news/security/campaign-abusing-hubspot-targets-20-000-microsoft-azure-accounts/",[3740],{"nodeType":1293,"value":3741,"marks":3742,"data":3744},"leveraging legitimate SaaS services",[3743],{"type":1335},{},{"nodeType":1293,"value":3746,"marks":3747,"data":3748}," to conduct their campaigns (",[],{},{"nodeType":1337,"data":3750,"content":3752},{"uri":3751},"https://www.bleepingcomputer.com/news/security/proofpoint-settings-exploited-to-send-millions-of-phishing-emails-daily/",[3753],{"nodeType":1293,"value":3754,"marks":3755,"data":3757},"sometimes even using email protection services themselves!",[3756],{"type":1335},{},{"nodeType":1293,"value":3759,"marks":3760,"data":3761},") making it even harder to filter genuine from harmful links. ",[],{},{"nodeType":1294,"data":3763,"content":3764},{},[3765],{"nodeType":1293,"value":3766,"marks":3767,"data":3768},"But there’s a bigger issue here – for defenders to know that a URL, IP, or domain name is bad, it needs to be reported first. When are things reported? Typically after being used in an attack — so unfortunately, someone always gets hurt. ",[],{},{"nodeType":1993,"data":3770,"content":3771},{},[],{"nodeType":2075,"data":3773,"content":3774},{},[3775],{"nodeType":1293,"value":3776,"marks":3777,"data":3779},"Malicious webpage detections are failing",[3778],{"type":1772},{},{"nodeType":1294,"data":3781,"content":3782},{},[3783],{"nodeType":1293,"value":3784,"marks":3785,"data":3786},"Attackers are using various tricks to prevent security tools and bots from reaching their phishing pages to analyse them. ",[],{},{"nodeType":1294,"data":3788,"content":3789},{},[3790],{"nodeType":1293,"value":3791,"marks":3792,"data":3793},"Using legitimate services to host their domains is increasingly common, with services like Cloudflare Workers used for the initial gateway, and Cloudflare Turnstile to prevent security bots from advancing to the page. ",[],{},{"nodeType":1377,"data":3795,"content":3798},{"target":3796},{"sys":3797},{"id":1461,"type":1374,"linkType":1375},[],{"nodeType":1294,"data":3800,"content":3801},{},[3802],{"nodeType":1293,"value":3803,"marks":3804,"data":3805},"Even if you can get past Turnstile, then you’ll need to supply the correct URL parameters and headers, and execute JavaScript, to be served the malicious page. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",[],{},{"nodeType":1294,"data":3807,"content":3808},{},[3809],{"nodeType":1293,"value":3810,"marks":3811,"data":3812},"And if all this wasn’t enough, they’re also obfuscating both visual and DOM elements to prevent signature-based detections from picking them up — so even if you can land on the page, there’s a high chance that your detections won’t trigger. ",[],{},{"nodeType":1294,"data":3814,"content":3815},{},[3816],{"nodeType":1293,"value":3817,"marks":3818,"data":3819},"By changing the DOM structure, attackers are loading functionally equivalent pages that look very different under the hood.",[],{},{"nodeType":1377,"data":3821,"content":3825},{"target":3822},{"sys":3823},{"id":3824,"type":1374,"linkType":1375},"2dN8np5odBecf7r1vBr69K",[],{"nodeType":1294,"data":3827,"content":3828},{},[3829],{"nodeType":1293,"value":3830,"marks":3831,"data":3832},"They’re also randomizing page titles, dynamically decoding text, changing the size and name of image elements, using different favicons, blurring backgrounds, substituting logos, and more… all to defeat common detections. ",[],{},{"nodeType":1377,"data":3834,"content":3838},{"target":3835},{"sys":3836},{"id":3837,"type":1374,"linkType":1375},"3hlzM3qIqaZHy3qxtnRS5x",[],{"nodeType":1294,"data":3840,"content":3841},{},[3842],{"nodeType":1293,"value":3843,"marks":3844,"data":3845},"With all this, it’s no surprise that defenders can’t keep up. ",[],{},{"nodeType":1993,"data":3847,"content":3848},{},[],{"nodeType":1392,"data":3850,"content":3851},{},[3852],{"nodeType":1293,"value":3853,"marks":3854,"data":3856},"The verdict",[3855],{"type":1772},{},{"nodeType":1294,"data":3858,"content":3859},{},[3860],{"nodeType":1293,"value":3861,"marks":3862,"data":3863},"Historically, the industry has seen email security solutions and anti-phishing as the same thing. But it’s clear that email-based phishing protection isn’t really cutting it when it comes to modern credential phishing attacks (the most common and impactful phishing variant today). ",[],{},{"nodeType":1294,"data":3865,"content":3866},{},[3867],{"nodeType":1293,"value":3868,"marks":3869,"data":3870},"This isn’t to say that email-based solutions have no value — far from it. But relying on email scanners to detect phishing pages as a single line of defense isn’t enough anymore. ",[],{},{"nodeType":1993,"data":3872,"content":3873},{},[],{"nodeType":1392,"data":3875,"content":3876},{},[3877],{"nodeType":1293,"value":3878,"marks":3879,"data":3881},"Building better phishing controls",[3880],{"type":1772},{},{"nodeType":1294,"data":3883,"content":3884},{},[3885],{"nodeType":1293,"value":3886,"marks":3887,"data":3888},"The key to solving this problem is, put simply, building better controls. But to do this, we need to move away from email as being the primary (or often the only) place where phishing attacks can be stopped. ",[],{},{"nodeType":1294,"data":3890,"content":3891},{},[3892],{"nodeType":1293,"value":3893,"marks":3894,"data":3895},"While email is the main delivery vector for phishing attacks (at least, according to the data we have, which comes primarily from email security solutions) it’s not the only one. Phishing links are increasingly delivered to victims over IM platforms, social media — and generally over the internet. ",[],{},{"nodeType":1294,"data":3897,"content":3898},{},[3899],{"nodeType":1293,"value":3900,"marks":3901,"data":3902},"A better solution to the problem would therefore be able to follow the user across the sites they use, and see the actual phishing pages as the user sees them, as opposed to a sandbox (which, as we’ve discussed, attackers are well prepared for). ",[],{},{"nodeType":1993,"data":3904,"content":3905},{},[],{"nodeType":2075,"data":3907,"content":3908},{},[3909],{"nodeType":1293,"value":3910,"marks":3911,"data":3913},"Is browser-based phishing protection the solution?",[3912],{"type":1772},{},{"nodeType":1294,"data":3915,"content":3916},{},[3917],{"nodeType":1293,"value":3918,"marks":3919,"data":3920},"While we’ve been conditioned to think about phishing as something that happens over email, it’s actually the browser where most of the action happens, regardless of the initial delivery channel.",[],{},{"nodeType":1294,"data":3922,"content":3923},{},[3924],{"nodeType":1293,"value":3925,"marks":3926,"data":3927},"And while it’s tempting to view the delivery of a phishing link as the attack itself, the phish can’t succeed unless the victim enters their genuine credentials on the malicious page. ",[],{},{"nodeType":1294,"data":3929,"content":3930},{},[3931],{"nodeType":1293,"value":3932,"marks":3933,"data":3934},"Push provides a browser-based identity security solution that stops phishing attacks where they happen — in employee browsers. ",[],{},{"nodeType":1294,"data":3936,"content":3937},{},[3938],{"nodeType":1293,"value":3939,"marks":3940,"data":3941},"Being in the browser delivers a lot of advantages when it comes to detecting and intercepting phishing attacks. You see the live webpage that the user sees, meaning you have much better visibility of malicious elements running on the page. It also means that you can implement real-time controls that kick in when a malicious element is detected. ",[],{},{"nodeType":1294,"data":3943,"content":3944},{},[3945],{"nodeType":1293,"value":3946,"marks":3947,"data":3948},"There’s a clear difference when you compare a phishing attack with and without Push. ",[],{},{"nodeType":1377,"data":3950,"content":3953},{"target":3951},{"sys":3952},{"id":3332,"type":1374,"linkType":1375},[],{"nodeType":1294,"data":3955,"content":3956},{},[3957],{"nodeType":1293,"value":3958,"marks":3959,"data":3960},"Here, an attacker hacks a WordPress blog to get a reputable domain and then runs a phishing toolkit on the webpage. They email one of your employees a link to it. Your SWG or email scanning solution inspects it in a sandbox but the phish kit detects this and redirects to a benign site so that it passes the inspection. ",[],{},{"nodeType":1294,"data":3962,"content":3963},{},[3964],{"nodeType":1293,"value":3965,"marks":3966,"data":3967},"Your user gets the email with the link and is now free to interact with the phishing page. They enter their credentials plus MFA code into the page and voila! The attacker steals the authenticated session and takes over the user’s account.  ",[],{},{"nodeType":1377,"data":3969,"content":3972},{"target":3970},{"sys":3971},{"id":3369,"type":1374,"linkType":1375},[],{"nodeType":1294,"data":3974,"content":3975},{},[3976],{"nodeType":1293,"value":3977,"marks":3978,"data":3979},"But with Push, our browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page, detecting that:",[],{},{"nodeType":1982,"data":3981,"content":3982},{},[3983,3993,4003],{"nodeType":1948,"data":3984,"content":3985},{},[3986],{"nodeType":1294,"data":3987,"content":3988},{},[3989],{"nodeType":1293,"value":3990,"marks":3991,"data":3992},"The password the user is entering matches the domain that password is pinned to. Since it doesn't match, based on this detection alone the user is automatically redirected to a blocking page. ",[],{},{"nodeType":1948,"data":3994,"content":3995},{},[3996],{"nodeType":1294,"data":3997,"content":3998},{},[3999],{"nodeType":1293,"value":4000,"marks":4001,"data":4002},"The rendered web app is using a cloned app login page.",[],{},{"nodeType":1948,"data":4004,"content":4005},{},[4006],{"nodeType":1294,"data":4007,"content":4008},{},[4009],{"nodeType":1293,"value":4010,"marks":4011,"data":4012},"A phishing toolkit is running on the web page. ",[],{},{"nodeType":1294,"data":4014,"content":4015},{},[4016],{"nodeType":1293,"value":4017,"marks":4018,"data":4019},"As a result, the user is blocked from interacting with the phishing site and prevented from continuing. ",[],{},{"nodeType":1294,"data":4021,"content":4022},{},[4023,4027],{"nodeType":1293,"value":4024,"marks":4025,"data":4026},"These are good examples of detections that are difficult (or impossible) for an attacker to evade — ",[],{},{"nodeType":1293,"value":4028,"marks":4029,"data":4031},"you can’t phish a victim if they can’t enter their credentials into your phishing site! ",[4030],{"type":1772},{},{"nodeType":1294,"data":4033,"content":4034},{},[4035,4039,4048],{"nodeType":1293,"value":4036,"marks":4037,"data":4038},"If we look at the Pyramid of Pain again, we can see that these are much harder detections for attackers to get around, ",[],{},{"nodeType":1337,"data":4040,"content":4042},{"uri":4041},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/?utm_campaign=9983377-FY25Q1_Bleeping-Computer-Organic-Article&utm_source=bleepingcomputer&utm_medium=sponsored-content&utm_content=organic%20article",[4043],{"nodeType":1293,"value":4044,"marks":4045,"data":4047},"enabling earlier detection and interception of account takeover ",[4046],{"type":1335},{},{"nodeType":1293,"value":4049,"marks":4050,"data":4051},"when compared to static, TI-driven blocklists — stopping attacks before anyone gets hurt.",[],{},{"nodeType":1377,"data":4053,"content":4057},{"target":4054},{"sys":4055},{"id":4056,"type":1374,"linkType":1375},"6q8H7vA8k7mLrSsr5R0TZ1",[],{"nodeType":1993,"data":4059,"content":4060},{},[],{"nodeType":1392,"data":4062,"content":4063},{},[4064],{"nodeType":1293,"value":3413,"marks":4065,"data":4067},[4066],{"type":1772},{},{"nodeType":1294,"data":4069,"content":4070},{},[4071],{"nodeType":1293,"value":4072,"marks":4073,"data":4074},"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",[],{},{"nodeType":1294,"data":4076,"content":4077},{},[4078,4082,4090],{"nodeType":1293,"value":4079,"marks":4080,"data":4081},"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",[],{},{"nodeType":1337,"data":4083,"content":4085},{"uri":4084},"https://pushsecurity.com/demo?utm_campaign=9983377-FY25Q1_Bleeping-Computer-Organic-Article&utm_source=bleepingcomputer&utm_medium=sponsored-content&utm_content=organic%20article",[4086],{"nodeType":1293,"value":3427,"marks":4087,"data":4089},[4088],{"type":1335},{},{"nodeType":1293,"value":4091,"marks":4092,"data":4093}," for a live demo. ",[],{},{"entries":4095},{"hyperlink":4096,"inline":4097,"block":4098},[],[],[4099,4108,4116,4124,4132,4139,4146,4154,4160],{"sys":4100,"__typename":4101,"title":4102,"caption":4103,"layoutMode":118,"file":4104},{"id":3519},"Image","Source: 2024 Trends in Identity Security - Identity Defined Security Alliance (IDSA)","Source: 2024 Trends in Identity Security – Identity Defined Security Alliance (IDSA)",{"url":4105,"width":4106,"height":4107},"https://images.ctfassets.net/y1cdw1ablpvd/4wcIXJu4Yhq7lHZuGbX1w0/b097fff859f61a0e853f8a10e2d838aa/image7.png",1730,782,{"sys":4109,"__typename":4101,"title":4110,"caption":4111,"layoutMode":118,"file":4112},{"id":3655},"Evilginx screenshot - email controls blog","Evilginx being used to take over an M365 account",{"url":4113,"width":4114,"height":4115},"https://images.ctfassets.net/y1cdw1ablpvd/4fhOQ0Vohnrd8X0WaJkXDZ/82832b1f912717ca3782d9163daa8781/3.png",1999,1127,{"sys":4117,"__typename":4101,"title":4118,"caption":4119,"layoutMode":118,"file":4120},{"id":3700},"Pyramid of Pain: Original","Original Pyramid of Pain model, created by David Bianco.",{"url":4121,"width":4122,"height":4123},"https://images.ctfassets.net/y1cdw1ablpvd/7dPJT7PYKX71FCCi0GeDzg/16fb3b07959612a45c1b7636da33e541/image3.png",720,405,{"sys":4125,"__typename":4101,"title":4126,"caption":4127,"layoutMode":118,"file":4128},{"id":1461},"Turnstile requiring human interaction","Cloudflare Turnstile requiring human interaction",{"url":4129,"width":4130,"height":4131},"https://images.ctfassets.net/y1cdw1ablpvd/DbEYzQt7m3jY56ALCYWEy/59846e7bd4a3ed204722a9d561e97231/image2.png",938,361,{"sys":4133,"__typename":4101,"title":4134,"caption":4134,"layoutMode":118,"file":4135},{"id":3824},"Comparing a legitimate page’s DOM structure with an attacker’s cloned page",{"url":4136,"width":4137,"height":4138},"https://images.ctfassets.net/y1cdw1ablpvd/4HmklQ1H0YIMlNdTkZR8B0/e2e727d9d96867b9d46e35bf097f7a0f/6.png",1875,562,{"sys":4140,"__typename":4101,"title":4141,"caption":4142,"layoutMode":118,"file":4143},{"id":3837},"Comparing a fake and real M365 login page","The left image is a fake login page — looks pretty believable though, right?",{"url":4144,"width":4114,"height":4145},"https://images.ctfassets.net/y1cdw1ablpvd/4piMCOgm2TgWBiKjyjL0Tw/d0a7ab35f9173f639b8454215536938e/7.png",871,{"sys":4147,"__typename":4101,"title":4148,"caption":4149,"layoutMode":118,"file":4150},{"id":3332},"Phishing detection without Push","Phishing detection: Without Push (it's not looking good...)",{"url":4151,"width":4152,"height":4153},"https://images.ctfassets.net/y1cdw1ablpvd/1oBYz6u0WH0gMnd89bkZjU/61bf589f62b898b91e4f8045caf1d4e1/Phishing_detection_without_Push__3_.png",1535,764,{"sys":4155,"__typename":4101,"title":4156,"caption":4157,"layoutMode":118,"file":4158},{"id":3369},"Phishing detection: With Push","Phishing detection: With Push (Pow! Take that attacker)",{"url":4159,"width":4152,"height":4153},"https://images.ctfassets.net/y1cdw1ablpvd/7lxmav3wYkltbFp3N9KeIQ/06080c5b629590fe3551cf5944f011ec/Phishing_detection_with_Push__2_.png",{"sys":4161,"__typename":4101,"title":4162,"caption":4163,"layoutMode":118,"file":4164},{"id":4056},"Updated Pyramid of Pain (IoCs and TTPs)","Applying the Pyramid of Pain to identity-based attacks",{"url":4165,"width":4114,"height":4166},"https://images.ctfassets.net/y1cdw1ablpvd/7kfzRw2EuOtDbaDTIQI7r0/8304e44e0feb903e8db3bbdf12243d76/10.png",1477,"content:blog:why-its-time-for-phishing-prevention-to-move-beyond-email.json","json","content","blog/why-its-time-for-phishing-prevention-to-move-beyond-email.json","blog/why-its-time-for-phishing-prevention-to-move-beyond-email",1776359985488]