[{"data":1,"prerenderedAt":3908},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"trust-badges":226,"blog/agentic-threat-hunting-benefits-for-customers":247},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"query":14,"data":15,"variations":20,"lastUpdated":21,"firstPublished":22,"testRatio":23,"createdBy":24,"lastUpdatedBy":25,"folders":26,"meta":27,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",[],{"type":16,"url":17,"text":18,"link":19},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":28,"lastPreviewUrl":29,"breakpoints":30,"hasAutosaves":34},"data","",{"xsmall":31,"small":32,"medium":33},320,640,768,true,"pddk82g04sg",{"createdDate":37,"id":38,"name":39,"modelId":40,"published":13,"stageModifiedSincePublish":6,"query":41,"data":42,"variations":97,"lastUpdated":98,"firstPublished":99,"testRatio":23,"createdBy":100,"lastUpdatedBy":101,"folders":102,"meta":103,"rev":107},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":43,"text":44,"url":29,"blocks":45,"state":93},"ewrererw","testrfesssssssssss",[46,73,81],{"@type":47,"@version":48,"id":49,"component":50,"responsiveStyles":63},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":51,"tag":51,"options":52,"isRSC":62},"TopBannerContent",{"text":53,"ctaText":54,"url":55,"mainText":56,"cta":59},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https://pushsecurity.com/webinar/state-of-browser-security",{"content":57,"fontSize":58},"\u003Cp>Meet Push's browser security experts at BlackHat 2026.\u003C/p>","text-base",{"content":60,"fontSize":58,"url":61},"\u003Cp>Book a meeting →\u003C/p>","https://pushsecurity.com/events/blackhat-2026-meeting",null,{"large":64},{"display":65,"flexDirection":66,"position":67,"flexShrink":68,"boxSizing":69,"marginTop":70,"marginBottom":70,"fontSize":71,"fontWeight":72},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":47,"@version":48,"id":74,"component":75,"responsiveStyles":79},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":76,"options":77,"isRSC":62},"Custom Code",{"code":78,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C/style>\n",{"large":80},{"display":65,"flexDirection":66,"position":67,"flexShrink":68,"boxSizing":69},{"id":82,"@type":47,"tagName":83,"properties":84,"responsiveStyles":88},"builder-pixel-duwvoo52pz","img",{"src":85,"aria-hidden":86,"alt":29,"role":87,"width":68,"height":68},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":89},{"height":68,"width":68,"display":90,"opacity":68,"overflow":91,"pointerEvents":92},"block","hidden","none",{"deviceSize":94,"location":95},"large",{"path":29,"query":96},{},{},1783541846936,1774968080803,"ST0tXQM8slWpFrmioqKHmENB2qe2","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"kind":104,"lastPreviewUrl":105,"hasLinks":6,"breakpoints":106,"hasErrors":6,"hasAutosaves":6},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default",{"xsmall":31,"small":32,"medium":33},"7h7up6i3j7j",[109,145],{"createdDate":110,"id":111,"name":112,"modelId":113,"published":13,"stageModifiedSincePublish":6,"query":114,"data":115,"variations":138,"lastUpdated":139,"firstPublished":140,"testRatio":23,"createdBy":24,"lastUpdatedBy":24,"folders":141,"meta":142,"rev":144},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":116,"type":117,"testimonialLink":118,"testimonial":119},{},"testimonial","/customer-stories/inductive-automation",{"@type":120,"id":121,"model":117,"value":122},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79",{"query":123,"folders":124,"createdDate":125,"id":121,"name":126,"modelId":127,"published":13,"data":128,"variations":132,"lastUpdated":133,"firstPublished":134,"testRatio":23,"createdBy":100,"lastUpdatedBy":100,"meta":135,"rev":137},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":129,"jobTitle":130,"quote":126,"image":131},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":28,"lastPreviewUrl":29,"breakpoints":136,"hasAutosaves":34},{"small":32,"medium":33},"7phdpptxf4",{},1776247404986,1776247404973,[],{"breakpoints":143,"kind":28,"lastPreviewUrl":29,"hasAutosaves":6},{"xsmall":31,"small":32,"medium":33},"61pdq8p2835",{"createdDate":146,"id":147,"name":148,"modelId":113,"published":13,"meta":149,"stageModifiedSincePublish":6,"query":151,"data":152,"variations":178,"lastUpdated":179,"firstPublished":180,"testRatio":23,"createdBy":24,"lastUpdatedBy":24,"folders":181,"rev":144},1776255761419,"05a9322735fc427db12e2740e4302300","Report: 2026 Browser Attack Techniques",{"breakpoints":150,"kind":28,"lastPreviewUrl":29,"hasAutosaves":6},{"xsmall":31,"small":32,"medium":33},[],{"testimonial":153,"link":172,"type":175,"title":148,"description":176,"image":177},{"@type":120,"id":154,"model":117,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":127,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":23,"createdBy":100,"lastUpdatedBy":24,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":29,"quote":164,"image":165},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":28,"lastPreviewUrl":29,"breakpoints":170,"hasAutosaves":34},{"small":32,"medium":33},"bqwzoip3kn",{"text":173,"url":174},"Download now","/resources/browser-attacks-report","resource","Learn about the latest techniques being used in the wild.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{},1776255810913,1776255810900,[],[183,205],{"createdDate":184,"id":185,"name":148,"modelId":186,"published":13,"meta":187,"stageModifiedSincePublish":6,"query":189,"data":190,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":23,"createdBy":24,"lastUpdatedBy":24,"folders":203,"rev":204},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":188,"kind":28,"lastPreviewUrl":29,"hasAutosaves":6},{"xsmall":31,"small":32,"medium":33},[],{"testimonial":191,"link":199,"type":175,"title":148,"description":176,"image":177},{"@type":120,"id":154,"model":117,"value":192},{"query":193,"folders":194,"createdDate":158,"id":154,"name":159,"modelId":127,"published":13,"data":195,"variations":196,"lastUpdated":167,"firstPublished":168,"testRatio":23,"createdBy":100,"lastUpdatedBy":24,"meta":197,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":29,"quote":164,"image":165},{},{"kind":28,"lastPreviewUrl":29,"breakpoints":198,"hasAutosaves":34},{"small":32,"medium":33},{"text":173,"url":174},{},1776256937553,1776256937540,[],"kcupyf9nl8g",{"createdDate":206,"id":207,"name":208,"modelId":186,"published":13,"stageModifiedSincePublish":6,"query":209,"data":210,"variations":220,"lastUpdated":221,"firstPublished":222,"testRatio":23,"createdBy":24,"lastUpdatedBy":24,"folders":223,"meta":224,"rev":204},1776256949234,"ce043785b71b4ece98eac811ecf4ba10","inductive-automation",[],{"link":211,"type":117,"testimonial":212,"testimonialLink":118},{},{"@type":120,"id":121,"model":117,"value":213},{"query":214,"folders":215,"createdDate":125,"id":121,"name":126,"modelId":127,"published":13,"data":216,"variations":217,"lastUpdated":133,"firstPublished":134,"testRatio":23,"createdBy":100,"lastUpdatedBy":100,"meta":218,"rev":137},[],[],{"author":129,"jobTitle":130,"quote":126,"image":131},{},{"kind":28,"lastPreviewUrl":29,"breakpoints":219,"hasAutosaves":34},{"small":32,"medium":33},{},1776256974140,1776256974130,[],{"breakpoints":225,"kind":28,"lastPreviewUrl":29,"hasAutosaves":6},{"xsmall":31,"small":32,"medium":33},[227,231,235,239,243],{"title":228,"logo":229,"createdDate":230},"SOC2","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":232,"logo":233,"createdDate":234},"GDPR","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":236,"logo":237,"createdDate":238},"Cyber essentials","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":240,"logo":241,"createdDate":242},"ISO IEC 27001","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":244,"logo":245,"createdDate":246},"ISO IEC 27701","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,{"id":248,"title":249,"authorsCollection":250,"content":258,"extension":1307,"faqItemsCollection":1308,"faqTitle":62,"featured":6,"hashTags":62,"meta":1310,"metaTitle":1311,"ogImage":62,"publishedDate":1312,"relatedBlogPostsCollection":1313,"slug":3884,"stem":3885,"subtitle":62,"summary":3886,"synopsis":3897,"sys":3898,"tagsCollection":3901,"__hash__":3907},"blog/blog/agentic-threat-hunting-benefits-for-customers.json","How Push’s agentic threat hunting in the browser benefits every customer",{"items":251},[252],{"fullName":253,"firstName":254,"jobTitle":255,"profilePicture":256},"Kelly Davenport","Kelly","Product Team",{"url":257},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"json":259,"links":1201},{"nodeType":260,"data":261,"content":262},"document",{},[263,280,296,350,357,370,392,399,408,412,420,427,456,463,470,538,545,551,558,565,568,575,582,615,635,647,653,660,666,678,685,705,711,723,735,742,748,760,776,788,800,806,813,816,823,830,846,854,861,869,876,922,925,932,939,945,953,960,976,991,998,1014,1021,1069,1076,1092,1099,1149,1156,1164,1167,1174,1181],{"nodeType":264,"data":265,"content":266},"paragraph",{},[267,272],{"nodeType":268,"value":269,"marks":270,"data":271},"text","Hey all you security engineers, let’s play ",[],{},{"nodeType":268,"value":273,"marks":274,"data":279},"Would You Rather … ?",[275,277],{"type":276},"italic",{"type":278},"bold",{},{"nodeType":264,"data":281,"content":282},{},[283,287,292],{"nodeType":268,"value":284,"marks":285,"data":286},"Would you rather spend time trying to write detections for ",[],{},{"nodeType":268,"value":288,"marks":289,"data":291},"modern browser-based attacks",[290],{"type":278},{},{"nodeType":268,"value":293,"marks":294,"data":295}," by …",[],{},{"nodeType":297,"data":298,"content":299},"unordered-list",{},[300,316,335],{"nodeType":301,"data":302,"content":303},"list-item",{},[304],{"nodeType":264,"data":305,"content":306},{},[307,311],{"nodeType":268,"value":308,"marks":309,"data":310},"Combing through MITRE looking for techniques that you can write detections on, only to find you have",[],{},{"nodeType":268,"value":312,"marks":313,"data":315}," little useful telemetry from your typical sources.",[314],{"type":278},{},{"nodeType":301,"data":317,"content":318},{},[319],{"nodeType":264,"data":320,"content":321},{},[322,326,331],{"nodeType":268,"value":323,"marks":324,"data":325},"Curating a list of malicious domain IOCs extracted from endless TI pieces, only to ",[],{},{"nodeType":268,"value":327,"marks":328,"data":330},"never see a single one of them match",[329],{"type":278},{},{"nodeType":268,"value":332,"marks":333,"data":334},".",[],{},{"nodeType":301,"data":336,"content":337},{},[338],{"nodeType":264,"data":339,"content":340},{},[341,346],{"nodeType":268,"value":342,"marks":343,"data":345},"Just giving up and blocking a bunch of domains or IPs",[344],{"type":278},{},{"nodeType":268,"value":347,"marks":348,"data":349}," from every TI feed you come across, while quietly weeping.",[],{},{"nodeType":264,"data":351,"content":352},{},[353],{"nodeType":268,"value":354,"marks":355,"data":356},"Or … ",[],{},{"nodeType":297,"data":358,"content":359},{},[360],{"nodeType":301,"data":361,"content":362},{},[363],{"nodeType":264,"data":364,"content":365},{},[366],{"nodeType":268,"value":367,"marks":368,"data":369},"Inherit constantly evolving detections validated across 3 million-plus browsers, tuned to remove false positives, informed by human threat researchers, and tailored to the known and not-yet-known threats that target account compromise and malware delivery via the browser.",[],{},{"nodeType":264,"data":371,"content":372},{},[373,377,388],{"nodeType":268,"value":374,"marks":375,"data":376},"At Push, we’ve built an ",[],{},{"nodeType":378,"data":379,"content":381},"hyperlink",{"uri":380},"https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",[382],{"nodeType":268,"value":383,"marks":384,"data":387},"agentic threat hunting and detection engineering pipeline",[385],{"type":386},"underline",{},{"nodeType":268,"value":389,"marks":390,"data":391}," to take that first set of onerous tasks off your plate. The result is a process that looks a lot like the ideal described in detection engineering maturity models, achieved without any extra headcount or subject matter expertise on your team, and scaled to meet the speed and complexity of our current era of AI-enabled adversaries.",[],{},{"nodeType":264,"data":393,"content":394},{},[395],{"nodeType":268,"value":396,"marks":397,"data":398},"Let’s take a look at how the pipeline delivers a collective good by identifying emerging threats or new technique variants in a single customer environment and then delivering detections to everyone.",[],{},{"nodeType":400,"data":401,"content":407},"embedded-entry-block",{"target":402},{"sys":403},{"id":404,"type":405,"linkType":406},"sN6q7oEwYyJTkXxyLb81m","Link","Entry",[],{"nodeType":409,"data":410,"content":411},"hr",{},[],{"nodeType":413,"data":414,"content":415},"heading-1",{},[416],{"nodeType":268,"value":417,"marks":418,"data":419},"Why detection engineering from TI is hard — and why AI-enabled attacks are making it even harder",[],{},{"nodeType":264,"data":421,"content":422},{},[423],{"nodeType":268,"value":424,"marks":425,"data":426},"Detection engineers feel the pain that Beethoven must have felt when he got the critique: “There are just too many notes!”",[],{},{"nodeType":264,"data":428,"content":429},{},[430,434,439,443,452],{"nodeType":268,"value":431,"marks":432,"data":433},"Except where notes = threat intelligence, light on the ",[],{},{"nodeType":268,"value":435,"marks":436,"data":438},"intelligence",[437],{"type":276},{},{"nodeType":268,"value":440,"marks":441,"data":442},". (For a great unpacking of what’s hard about transforming TI into detections, check out this ",[],{},{"nodeType":378,"data":444,"content":446},{"uri":445},"https://medium.com/anton-on-security/detection-engineering-is-painful-and-it-shouldnt-be-part-1-3641d8740458",[447],{"nodeType":268,"value":448,"marks":449,"data":451},"blog series",[450],{"type":386},{},{"nodeType":268,"value":453,"marks":454,"data":455}," from Anton Chuvakin and his Google security colleagues from 2023. The challenge has only gotten harder since then!)",[],{},{"nodeType":264,"data":457,"content":458},{},[459],{"nodeType":268,"value":460,"marks":461,"data":462},"In short, there is too much potential TI, too little actionable detail, and a dearth of useful business-relevant context.",[],{},{"nodeType":264,"data":464,"content":465},{},[466],{"nodeType":268,"value":467,"marks":468,"data":469},"This often manifests as:",[],{},{"nodeType":297,"data":471,"content":472},{},[473,501,520],{"nodeType":301,"data":474,"content":475},{},[476],{"nodeType":264,"data":477,"content":478},{},[479,484,488,497],{"nodeType":268,"value":480,"marks":481,"data":483},"Feeling constantly behind the threat landscape. ",[482],{"type":278},{},{"nodeType":268,"value":485,"marks":486,"data":487},"SANS Institute’s ",[],{},{"nodeType":378,"data":489,"content":491},{"uri":490},"https://www.sans.org/white-papers/state-detection-engineering-2026",[492],{"nodeType":268,"value":493,"marks":494,"data":496},"State of Detection Engineering 2026",[495],{"type":386},{},{"nodeType":268,"value":498,"marks":499,"data":500}," report found that only 18% of practitioners feel like they’re staying ahead; 56% report barely keeping pace.",[],{},{"nodeType":301,"data":502,"content":503},{},[504],{"nodeType":264,"data":505,"content":506},{},[507,511,516],{"nodeType":268,"value":508,"marks":509,"data":510},"Access to a huge amount of potential TI, but ",[],{},{"nodeType":268,"value":512,"marks":513,"data":515},"lacking the time, context, and tools needed to parse the data",[514],{"type":278},{},{"nodeType":268,"value":517,"marks":518,"data":519}," for threats that matter to the business.",[],{},{"nodeType":301,"data":521,"content":522},{},[523],{"nodeType":264,"data":524,"content":525},{},[526,530,535],{"nodeType":268,"value":527,"marks":528,"data":529},"More information on IOCs than TTPs, leading to ",[],{},{"nodeType":268,"value":531,"marks":532,"data":534},"ever-growing blocklists and attacks that still slip through",[533],{"type":278},{},{"nodeType":268,"value":332,"marks":536,"data":537},[],{},{"nodeType":264,"data":539,"content":540},{},[541],{"nodeType":268,"value":542,"marks":543,"data":544},"As AI-enabled adversaries continue to make it increasingly trivial to rotate infrastructure or abuse trusted services and workflows to deliver modern attacks, the hill gets steeper. ",[],{},{"nodeType":400,"data":546,"content":550},{"target":547},{"sys":548},{"id":549,"type":405,"linkType":406},"4xlCsISP3OT9MAj3wxw67D",[],{"nodeType":264,"data":552,"content":553},{},[554],{"nodeType":268,"value":555,"marks":556,"data":557},"In the case of attacks that target employees via the browser — using advanced phishing methods, commercial toolkits, abuse of OAuth, abuse of trusted services to deliver phishing lures, etc. — most security teams are also working without the right foundational visibility to even begin to mature their detection process against these TTPs.",[],{},{"nodeType":264,"data":559,"content":560},{},[561],{"nodeType":268,"value":562,"marks":563,"data":564},"The missing input is visibility at the layer where these attacks actually execute — the browser session. Without it, detection engineering for browser-based threats is painful guesswork.",[],{},{"nodeType":409,"data":566,"content":567},{},[],{"nodeType":413,"data":569,"content":570},{},[571],{"nodeType":268,"value":572,"marks":573,"data":574},"How Push operationalized best practices for hunting from TI using agents",[],{},{"nodeType":264,"data":576,"content":577},{},[578],{"nodeType":268,"value":579,"marks":580,"data":581},"In building our agentic threat hunting and detection engineering pipeline at Push, we set out to solve many of the same problems that any security team faces when maturing its processes:",[],{},{"nodeType":297,"data":583,"content":584},{},[585,595,605],{"nodeType":301,"data":586,"content":587},{},[588],{"nodeType":264,"data":589,"content":590},{},[591],{"nodeType":268,"value":592,"marks":593,"data":594},"How to transform TI into technique-level intel we could write durable detections for across a wide customer base at scale?",[],{},{"nodeType":301,"data":596,"content":597},{},[598],{"nodeType":264,"data":599,"content":600},{},[601],{"nodeType":268,"value":602,"marks":603,"data":604},"How to create structured internal knowledge to add context to our detection engineering process that validates the relevance of what we find?",[],{},{"nodeType":301,"data":606,"content":607},{},[608],{"nodeType":264,"data":609,"content":610},{},[611],{"nodeType":268,"value":612,"marks":613,"data":614},"How to verify what’s worthwhile to hunt for, remove false positives, and understand the value of a detection for a specific TTP across an install base of more than 3 million browsers?",[],{},{"nodeType":264,"data":616,"content":617},{},[618,622,631],{"nodeType":268,"value":619,"marks":620,"data":621},"The process we created looks a lot like the ",[],{},{"nodeType":378,"data":623,"content":625},{"uri":624},"https://medium.com/anton-on-security/blueprint-for-threat-intel-to-detection-flow-part-7-088024be08dd",[626],{"nodeType":268,"value":627,"marks":628,"data":630},"best practices",[629],{"type":386},{},{"nodeType":268,"value":632,"marks":633,"data":634}," on how to turn intelligence into meaningful detections. The difference is that agents let us run this process continuously and at a scale that would be impossible to achieve with human analysts alone.",[],{},{"nodeType":264,"data":636,"content":637},{},[638,643],{"nodeType":268,"value":639,"marks":640,"data":642},"It starts with ingestion. ",[641],{"type":278},{},{"nodeType":268,"value":644,"marks":645,"data":646},"An agent tasked with TI aggregation monitors multiple industry sources — vendor reports, researcher disclosures, campaign teardowns — and filters for intelligence relevant to browser-based attack techniques. ",[],{},{"nodeType":400,"data":648,"content":652},{"target":649},{"sys":650},{"id":651,"type":405,"linkType":406},"7fsLEGUbOINll70ViNVVkI",[],{"nodeType":264,"data":654,"content":655},{},[656],{"nodeType":268,"value":657,"marks":658,"data":659},"Because this agent already understands the types of attacks and scenarios that matter to Push’s detection surface, it can distinguish signal from noise at the intake stage, flagging useful intel and proposing initial lightweight hunts based on the browser metadata Push can observe. When a potential hunt looks promising, the aggregation agent hands off to a deeper analysis agent to extract what’s actually huntable.",[],{},{"nodeType":400,"data":661,"content":665},{"target":662},{"sys":663},{"id":664,"type":405,"linkType":406},"5vyeALIziHamJ0cLiGMdGk",[],{"nodeType":264,"data":667,"content":668},{},[669,674],{"nodeType":268,"value":670,"marks":671,"data":673},"That extraction step is where a general TI feed becomes something you can build detections from. ",[672],{"type":278},{},{"nodeType":268,"value":675,"marks":676,"data":677},"Agents built on frontier models have a deep understanding of web programming languages and browser workflows can decompose the intelligence into its meaningful atomic units — the specific behavioral patterns that distinguish a malicious technique from normal browser activity. ",[],{},{"nodeType":264,"data":679,"content":680},{},[681],{"nodeType":268,"value":682,"marks":683,"data":684},"They compare those patterns against everything the Push browser agent can observe: tabs, windows, navigation events, downloads, network requests, DOM content, script execution. Then they discard anything too broad — observable events that are commonplace, even when connected to a malicious TTP — to avoid false positives. ",[],{},{"nodeType":264,"data":686,"content":687},{},[688,692,701],{"nodeType":268,"value":689,"marks":690,"data":691},"What survives is one or more huntable technique signatures that can be identified with a high true positive rate. This is the ",[],{},{"nodeType":378,"data":693,"content":695},{"uri":694},"https://pushsecurity.com/blog/the-pyramid-of-pain-in-the-ai-era",[696],{"nodeType":268,"value":697,"marks":698,"data":700},"Pyramid of Pain principle",[699],{"type":386},{},{"nodeType":268,"value":702,"marks":703,"data":704}," operationalized at machine speed: Target the technique, not the indicator, because techniques are genuinely hard for attackers to change.",[],{},{"nodeType":400,"data":706,"content":710},{"target":707},{"sys":708},{"id":709,"type":405,"linkType":406},"5j0mvdIMkaUwDgCu0nOqSm",[],{"nodeType":264,"data":712,"content":713},{},[714,719],{"nodeType":268,"value":715,"marks":716,"data":718},"In parallel, the pipeline validates whether the identified technique is genuinely novel or a variant of something Push already detects. ",[717],{"type":278},{},{"nodeType":268,"value":720,"marks":721,"data":722},"This is where our internal knowledge base comes into play. Built over three years by Push’s in-house research team and augmented continuously by the pipeline itself, it represents what Push knows about browser-based attack behaviors — a structured corpus of TTPs that lets agents classify incoming intelligence as new territory, a known variant that needs a refined detection, or something already covered. That classification determines what happens next: A net-new technique triggers a full hunt; a known variant triggers a refinement cycle; and a duplicate gets deprioritized.",[],{},{"nodeType":264,"data":724,"content":725},{},[726,731],{"nodeType":268,"value":727,"marks":728,"data":730},"The hunt itself is where hypothesis meets evidence.",[729],{"type":278},{},{"nodeType":268,"value":732,"marks":733,"data":734}," Agents develop a specific, testable prediction about what the technique looks like in browser telemetry, then validate that prediction across Push’s install base. The aim of the initial hunt is to identify any potential false positives — legitimate browser behavior that matches the pattern. Then the agents refine: adjusting the query, narrowing the behavioral fingerprints, testing again. Each iteration sharpens the detection until the false positive rate drops to a negligible, tolerable level. ",[],{},{"nodeType":264,"data":736,"content":737},{},[738],{"nodeType":268,"value":739,"marks":740,"data":741},"The hunts that produce relevant, high-confidence results become continuous queries — a kind of early warning system for emerging threats we’re actively watching for and learning about. The most useful and reliable of those queries become production detections that protect every Push customer in real time. ",[],{},{"nodeType":400,"data":743,"content":747},{"target":744},{"sys":745},{"id":746,"type":405,"linkType":406},"h3MN5kaaGGuL4uvNsP9JZ",[],{"nodeType":264,"data":749,"content":750},{},[751,756],{"nodeType":268,"value":752,"marks":753,"data":755},"This is what “detect what matters” looks like as an engineering discipline. ",[754],{"type":278},{},{"nodeType":268,"value":757,"marks":758,"data":759},"By the time the agents have whittled down millions or trillions of browser events into a good hunt query — where good means broad enough to cast a usefully wide net for variations — and then tuned that further into a high-fidelity detection, the result is fewer, sharper detections by design. And because Push detects at the browser session layer before a user can interact with a malicious page, almost all of those detections fire pre-compromise. ",[],{},{"nodeType":264,"data":761,"content":762},{},[763,767,772],{"nodeType":268,"value":764,"marks":765,"data":766},"The same 2026 SANS survey mentioned earlier found that ",[],{},{"nodeType":268,"value":768,"marks":769,"data":771},"66% of SOC practitioners cite vendor-provided rules as their primary source of false positives",[770],{"type":278},{},{"nodeType":268,"value":773,"marks":774,"data":775}," — a structural problem that persists at every organization size. Push’s pipeline produces the opposite outcome: better detections, less noise.",[],{},{"nodeType":264,"data":777,"content":778},{},[779,784],{"nodeType":268,"value":780,"marks":781,"data":783},"The result is a system with two learning loops.",[782],{"type":278},{},{"nodeType":268,"value":785,"marks":786,"data":787}," An inner loop handles real-time detection and response for known attacker techniques — the production detections already deployed across the customer base. An outer loop handles continuous discovery — agents hunting for new techniques, refining existing detections, and ingesting external intelligence. ",[],{},{"nodeType":264,"data":789,"content":790},{},[791,796],{"nodeType":268,"value":792,"marks":793,"data":795},"Each loop feeds the other:",[794],{"type":278},{},{"nodeType":268,"value":797,"marks":798,"data":799}," The outer loop’s discoveries become the inner loop’s new production detections, and the inner loop’s blocked attacks become raw material for the outer loop to analyze for novel variants. The knowledge base that both loops draw on grows with every cycle, which means the pipeline's detection coverage compounds at roughly the rate the threat landscape grows more complex.",[],{},{"nodeType":400,"data":801,"content":805},{"target":802},{"sys":803},{"id":804,"type":405,"linkType":406},"3xVLn9Ldk4cOP4uFYIYyM",[],{"nodeType":264,"data":807,"content":808},{},[809],{"nodeType":268,"value":810,"marks":811,"data":812},"And every validated detection produced by this process, whether it originated from a blocked attack in one customer’s environment, a proactive hunt across the telemetry corpus, or a vendor report about a campaign Push has never observed on customer estates, deploys to the entire customer base.",[],{},{"nodeType":409,"data":814,"content":815},{},[],{"nodeType":413,"data":817,"content":818},{},[819],{"nodeType":268,"value":820,"marks":821,"data":822},"Herd immunity, without all the breaches to get there",[],{},{"nodeType":264,"data":824,"content":825},{},[826],{"nodeType":268,"value":827,"marks":828,"data":829},"That last point is where Push’s idea of herd immunity diverges from the traditional definition.",[],{},{"nodeType":264,"data":831,"content":832},{},[833,837,842],{"nodeType":268,"value":834,"marks":835,"data":836},"Detection and response platforms and MDR services commonly describe a ",[],{},{"nodeType":268,"value":838,"marks":839,"data":841},"herd immunity benefit",[840],{"type":278},{},{"nodeType":268,"value":843,"marks":844,"data":845},": What one customer encounters, every customer gets protection against. The mechanism is real, but the learning input is typically a breach or a compromise. Someone has to be the first victim.",[],{},{"nodeType":264,"data":847,"content":848},{},[849],{"nodeType":268,"value":850,"marks":851,"data":853},"Push’s approach is different. ",[852],{"type":278},{},{"nodeType":264,"data":855,"content":856},{},[857],{"nodeType":268,"value":858,"marks":859,"data":860},"Modern browser-based attacks frequently rely on a series of techniques strung together to achieve a compromise. From its vantage point in the browser, Push catches many novel techniques with existing detections pre-compromise because it recognizes a portion of the attack techniques in the chain. The detection process then identifies what’s new about a previously unseen variation of a known TTP — perhaps an evasion technique the kit hadn’t used before, an unusual lure or infrastructure pattern, etc. ",[],{},{"nodeType":264,"data":862,"content":863},{},[864],{"nodeType":268,"value":865,"marks":866,"data":868},"The detection gets better for customers and no one was compromised to get there.",[867],{"type":278},{},{"nodeType":264,"data":870,"content":871},{},[872],{"nodeType":268,"value":873,"marks":874,"data":875},"On the external intelligence side, the pipeline ingests published research about a campaign Push has never observed, extracts the durable behavioral characteristics, validates them against browser telemetry, refines the query to tune out false positives, and ships detections before the technique is ever used against a Push customer. The protection arrives ahead of the attack.",[],{},{"nodeType":264,"data":877,"content":878},{},[879,883,892,896,905,909,918],{"nodeType":268,"value":880,"marks":881,"data":882},"These are the processes behind Push’s identification of ",[],{},{"nodeType":378,"data":884,"content":886},{"uri":885},"https://pushsecurity.com/blog/consentfix",[887],{"nodeType":268,"value":888,"marks":889,"data":891},"ConsentFix",[890],{"type":386},{},{"nodeType":268,"value":893,"marks":894,"data":895},", ",[],{},{"nodeType":378,"data":897,"content":899},{"uri":898},"https://pushsecurity.com/blog/installfix",[900],{"nodeType":268,"value":901,"marks":902,"data":904},"InstallFix",[903],{"type":386},{},{"nodeType":268,"value":906,"marks":907,"data":908},", and ",[],{},{"nodeType":378,"data":910,"content":912},{"uri":911},"https://pushsecurity.com/blog/llmshare-malvertising-campaign",[913],{"nodeType":268,"value":914,"marks":915,"data":917},"LLMShare",[916],{"type":386},{},{"nodeType":268,"value":919,"marks":920,"data":921}," — three browser-based attack techniques Push's team discovered or documented for the first time. In several cases, detections were blocking active campaigns against Push customers before the technique had been publicly documented. Those detections rolled out to every customer within hours or days of first observation.",[],{},{"nodeType":409,"data":923,"content":924},{},[],{"nodeType":413,"data":926,"content":927},{},[928],{"nodeType":268,"value":929,"marks":930,"data":931},"Outcomes: By the numbers",[],{},{"nodeType":264,"data":933,"content":934},{},[935],{"nodeType":268,"value":936,"marks":937,"data":938},"Looking at the quantifiable outcomes of this agentic threat hunting capability over the last few months, the benefits for customers become clear.",[],{},{"nodeType":400,"data":940,"content":944},{"target":941},{"sys":942},{"id":943,"type":405,"linkType":406},"7uNrNGUjjBiG9qEsfen7Xi",[],{"nodeType":946,"data":947,"content":948},"heading-2",{},[949],{"nodeType":268,"value":950,"marks":951,"data":952},"Velocity",[],{},{"nodeType":264,"data":954,"content":955},{},[956],{"nodeType":268,"value":957,"marks":958,"data":959},"Agents allow us to massively scale our research expertise, delivering detections for emerging threats or new variants much faster than humans alone can.",[],{},{"nodeType":264,"data":961,"content":962},{},[963,967,972],{"nodeType":268,"value":964,"marks":965,"data":966},"This year already, we’ve ",[],{},{"nodeType":268,"value":968,"marks":969,"data":971},"tripled",[970],{"type":278},{},{"nodeType":268,"value":973,"marks":974,"data":975}," the number of new detections shipped to customers.",[],{},{"nodeType":264,"data":977,"content":978},{},[979,983,988],{"nodeType":268,"value":980,"marks":981,"data":982},"We’ve also reduced the time it takes to ship production-ready detections for new threats from weeks to ",[],{},{"nodeType":268,"value":984,"marks":985,"data":987},"minutes",[986],{"type":278},{},{"nodeType":268,"value":332,"marks":989,"data":990},[],{},{"nodeType":946,"data":992,"content":993},{},[994],{"nodeType":268,"value":995,"marks":996,"data":997},"Detection coverage",[],{},{"nodeType":264,"data":999,"content":1000},{},[1001,1005,1010],{"nodeType":268,"value":1002,"marks":1003,"data":1004},"With that scaled expertise comes broad coverage. We perform an average of ",[],{},{"nodeType":268,"value":1006,"marks":1007,"data":1009},"300+ hunts",[1008],{"type":278},{},{"nodeType":268,"value":1011,"marks":1012,"data":1013}," a month (a mix of live queries for identified TTPs we’re looking for, plus net-new hunts for emerging threats we identify in any given month).",[],{},{"nodeType":264,"data":1015,"content":1016},{},[1017],{"nodeType":268,"value":1018,"marks":1019,"data":1020},"A few other metrics that demonstrate the scale of our detection coverage:",[],{},{"nodeType":297,"data":1022,"content":1023},{},[1024,1039,1054],{"nodeType":301,"data":1025,"content":1026},{},[1027],{"nodeType":264,"data":1028,"content":1029},{},[1030,1035],{"nodeType":268,"value":1031,"marks":1032,"data":1034},"75+",[1033],{"type":278},{},{"nodeType":268,"value":1036,"marks":1037,"data":1038}," attacker tools documented in our KB so far",[],{},{"nodeType":301,"data":1040,"content":1041},{},[1042],{"nodeType":264,"data":1043,"content":1044},{},[1045,1050],{"nodeType":268,"value":1046,"marks":1047,"data":1049},"25+",[1048],{"type":278},{},{"nodeType":268,"value":1051,"marks":1052,"data":1053}," variants of existing attacks we’ve identified and shipped detections for",[],{},{"nodeType":301,"data":1055,"content":1056},{},[1057],{"nodeType":264,"data":1058,"content":1059},{},[1060,1065],{"nodeType":268,"value":1061,"marks":1062,"data":1064},"10,000+",[1063],{"type":278},{},{"nodeType":268,"value":1066,"marks":1067,"data":1068}," monthly sessions analyzed",[],{},{"nodeType":946,"data":1070,"content":1071},{},[1072],{"nodeType":268,"value":1073,"marks":1074,"data":1075},"Protection from emerging threats",[],{},{"nodeType":264,"data":1077,"content":1078},{},[1079,1083,1088],{"nodeType":268,"value":1080,"marks":1081,"data":1082},"On the emerging threat side, our team was the first to identify or document ",[],{},{"nodeType":268,"value":1084,"marks":1085,"data":1087},"three new browser-based attack techniques",[1086],{"type":278},{},{"nodeType":268,"value":1089,"marks":1090,"data":1091}," — ConsentFix, InstallFix, and LLMShare — shipping detections to all customers quickly after identification.",[],{},{"nodeType":264,"data":1093,"content":1094},{},[1095],{"nodeType":268,"value":1096,"marks":1097,"data":1098},"In that same time frame, we’ve also:",[],{},{"nodeType":297,"data":1100,"content":1101},{},[1102,1130],{"nodeType":301,"data":1103,"content":1104},{},[1105],{"nodeType":264,"data":1106,"content":1107},{},[1108,1112,1117,1121,1126],{"nodeType":268,"value":1109,"marks":1110,"data":1111},"Protected ",[],{},{"nodeType":268,"value":1113,"marks":1114,"data":1116},"60+",[1115],{"type":278},{},{"nodeType":268,"value":1118,"marks":1119,"data":1120}," ",[],{},{"nodeType":268,"value":1122,"marks":1123,"data":1125},"customers in the last 3 months",[1124],{"type":278},{},{"nodeType":268,"value":1127,"marks":1128,"data":1129}," who’ve been targeted with novel phishing techniques — identifying never-before-seen techniques, lures, delivery mechanisms, interactions, tools, or attack chains",[],{},{"nodeType":301,"data":1131,"content":1132},{},[1133],{"nodeType":264,"data":1134,"content":1135},{},[1136,1140,1145],{"nodeType":268,"value":1137,"marks":1138,"data":1139},"Prevented ",[],{},{"nodeType":268,"value":1141,"marks":1142,"data":1144},"225+",[1143],{"type":278},{},{"nodeType":268,"value":1146,"marks":1147,"data":1148}," instances of threats pre-compromise for novel techniques",[],{},{"nodeType":264,"data":1150,"content":1151},{},[1152],{"nodeType":268,"value":1153,"marks":1154,"data":1155},"In all of the above situations, Push customers didn’t have to do anything — no combing through TI to find relevant details, no writing their own detections and tuning out false positives, or spending cycles to unpack a particularly knotty attack chain that used techniques they had never seen before. ",[],{},{"nodeType":264,"data":1157,"content":1158},{},[1159],{"nodeType":268,"value":1160,"marks":1161,"data":1163},"That’s what operationalized intelligence looks like at scale, delivered as a product, not a project.",[1162],{"type":278},{},{"nodeType":409,"data":1165,"content":1166},{},[],{"nodeType":413,"data":1168,"content":1169},{},[1170],{"nodeType":268,"value":1171,"marks":1172,"data":1173},"Learn more about Push",[],{},{"nodeType":264,"data":1175,"content":1176},{},[1177],{"nodeType":268,"value":1178,"marks":1179,"data":1180},"The same foundational capabilities that enable this agentic threat hunting pipeline also deliver other security outcomes for Push customers: gaining visibility and control over AI tool usage; hardening identities by surfacing credential reuse, SSO gaps, and shadow IT; and supporting data loss and insider investigations with browser-layer telemetry that other tools can’t see.",[],{},{"nodeType":264,"data":1182,"content":1183},{},[1184,1188,1197],{"nodeType":268,"value":1185,"marks":1186,"data":1187},"If you’d like to learn more, ",[],{},{"nodeType":378,"data":1189,"content":1191},{"uri":1190},"https://pushsecurity.com/demo",[1192],{"nodeType":268,"value":1193,"marks":1194,"data":1196},"book a demo",[1195],{"type":386},{},{"nodeType":268,"value":1198,"marks":1199,"data":1200}," with our team.",[],{},{"entries":1202},{"hyperlink":1203,"inline":1204,"block":1205},[],[],[1206,1221,1244,1252,1279,1286,1293,1300],{"sys":1207,"__typename":1208,"content":1209,"name":1220,"title":62},{"id":404},"InsightTextBlockComponent",{"json":1210},{"nodeType":260,"data":1211,"content":1212},{},[1213],{"nodeType":264,"data":1214,"content":1215},{},[1216],{"nodeType":268,"value":1217,"marks":1218,"data":1219},"This is Part 1 of a two-part series. In Part 2, we’ll cover a case study of an agentic threat hunt in detail.",[],{},"Herd Immunity IB3",{"sys":1222,"__typename":1208,"content":1223,"name":1243,"title":62},{"id":549},{"json":1224},{"nodeType":260,"data":1225,"content":1226},{},[1227],{"nodeType":264,"data":1228,"content":1229},{},[1230,1234,1239],{"nodeType":268,"value":1231,"marks":1232,"data":1233},"Spamhaus has found that ",[],{},{"nodeType":268,"value":1235,"marks":1236,"data":1238},"89% of phishing domains are active for less than 2 days",[1237],{"type":278},{},{"nodeType":268,"value":1240,"marks":1241,"data":1242},", with just 6.5% surviving for more than 15 days, making it increasingly difficult to rely on blocking known-bad URLs when most phishing attacks are essentially now a zero-day. (And in our experience, any phishing domains still up past a couple of days are just the remnants of a dead campaign that you’ll never see again.)",[],{},"Herd Immunity IB1",{"sys":1245,"__typename":1246,"title":1247,"caption":1247,"layoutMode":62,"file":1248},{"id":651},"Image","Initial analysis of a TI post by Push agents that triggers intel ingestion, checking for potentially huntable elements relevant to Push’s detection capabilities",{"url":1249,"width":1250,"height":1251},"https://images.ctfassets.net/y1cdw1ablpvd/77Bkzr6PPJSB90xp4sEp5o/d3a8a4ce568fd39a6f54d6c031c4affd/image4.png",614,375,{"sys":1253,"__typename":1208,"content":1254,"name":1278,"title":62},{"id":664},{"json":1255},{"nodeType":260,"data":1256,"content":1257},{},[1258],{"nodeType":264,"data":1259,"content":1260},{},[1261,1265,1274],{"nodeType":268,"value":1262,"marks":1263,"data":1264},"While Push uses commercial AI models, that’s not actually where the value is derived for our agentic threat hunting process — rather, it’s all about our browser telemetry. We wrote more about this in ",[],{},{"nodeType":378,"data":1266,"content":1268},{"uri":1267},"https://pushsecurity.com/blog/why-you-cant-vibecode-an-ai-driven-threat-hunting-pipeline",[1269],{"nodeType":268,"value":1270,"marks":1271,"data":1273},"why you can’t vibecode your own AI-driven threat hunting pipeline",[1272],{"type":386},{},{"nodeType":268,"value":1275,"marks":1276,"data":1277},". ",[],{},"Herd Immunity IB2",{"sys":1280,"__typename":1246,"title":1281,"caption":1281,"layoutMode":62,"file":1282},{"id":709},"After reviewing intel, Push agents extract the most likely high-fidelity behavioral indicators of an attack technique and propose some hunt queries",{"url":1283,"width":1284,"height":1285},"https://images.ctfassets.net/y1cdw1ablpvd/3d4gGhPPDix4iiqSuIgXFV/6549a9e414b38a89a5724930339c3c2e/image2.png",1842,804,{"sys":1287,"__typename":1246,"title":1288,"caption":1288,"layoutMode":62,"file":1289},{"id":746},"A glimpse into the reasoning process of the hunt agents, clustering results for efficient analysis before suggesting query refinements",{"url":1290,"width":1291,"height":1292},"https://images.ctfassets.net/y1cdw1ablpvd/4C3ZgBknBiidR5Di147Z5x/ebe51fe33e62f575e8e0870cf86024ab/image5.png",1999,918,{"sys":1294,"__typename":1246,"title":1295,"caption":1295,"layoutMode":62,"file":1296},{"id":804},"Two learning loops for known and unknown threats create a compounding effect for Push’s ability to defend against browser-based attacks",{"url":1297,"width":1298,"height":1299},"https://images.ctfassets.net/y1cdw1ablpvd/3sF0vK2krcVFYwod8Mii44/db0067eb55c2c948e0230452d299ae76/image1.png",1200,900,{"sys":1301,"__typename":1246,"title":1302,"caption":62,"layoutMode":62,"file":1303},{"id":943},"Agentic Detection Infographic ",{"url":1304,"width":1305,"height":1306},"https://images.ctfassets.net/y1cdw1ablpvd/2JYaJir7p8L13Tl6jSqBk6/0db8b9b445c179bc54fe8209435cbd34/Agentic_Detection_Infographic_1__8_.png",3840,2160,"json",{"items":1309},[],{},"Building herd immunity through agentic detections with Push","2026-07-23T00:00:00.000Z",{"items":1314},[1315,2283,3072],{"__typename":1316,"sys":1317,"content":1319,"title":2265,"synopsis":2266,"hashTags":62,"publishedDate":2267,"slug":2268,"tagsCollection":2269,"authorsCollection":2279},"BlogPosts",{"id":1318},"1jfqiWQlL6qkn3i9yjNbFB",{"json":1320},{"data":1321,"content":1322,"nodeType":260},{},[1323,1330,1352,1364,1371,1379,1386,1409,1416,1423,1430,1442,1448,1451,1459,1474,1495,1607,1613,1620,1626,1634,1641,1653,1660,1666,1673,1697,1704,1711,1717,1720,1728,1735,1743,1750,1766,1773,1780,1788,1795,1802,1810,1817,1824,1827,1835,1842,1850,1857,1864,1871,1878,1886,1893,1925,1932,1939,1945,1952,1960,1967,2045,2051,2059,2075,2082,2088,2095,2111,2114,2122,2129,2136,2142,2149,2194,2201,2208,2215,2221,2224,2232,2239,2246],{"data":1324,"content":1325,"nodeType":264},{},[1326],{"data":1327,"marks":1328,"value":1329,"nodeType":268},{},[],"In March, our threat hunting engine flagged something it hadn’t seen before.",{"data":1331,"content":1332,"nodeType":264},{},[1333,1337,1348],{"data":1334,"marks":1335,"value":1336,"nodeType":268},{},[],"Our research team had already been tracking the growing use of ",{"data":1338,"content":1342,"nodeType":1347},{"target":1339},{"sys":1340},{"id":1341,"type":405,"linkType":406},"2U6QpQ9rkY8x5ES48okHZB",[1343],{"data":1344,"marks":1345,"value":1346,"nodeType":268},{},[],"malvertising","entry-hyperlink",{"data":1349,"marks":1350,"value":1351,"nodeType":268},{},[]," tied to phishing campaigns. Malvertising frequently targets users via Google Search results, inserting malicious ads or redirects in place of legitimate ads, and using the familiar context of the search results page to trick users into clicking.",{"data":1353,"content":1354,"nodeType":264},{},[1355,1359],{"data":1356,"marks":1357,"value":1358,"nodeType":268},{},[],"To defend Push customers against this threat, we needed a way to spot malicious activity arising from clicking on Google ads. ",{"data":1360,"marks":1361,"value":1363,"nodeType":268},{},[1362],{"type":276},"But how to separate signal from noise?",{"data":1365,"content":1366,"nodeType":264},{},[1367],{"data":1368,"marks":1369,"value":1370,"nodeType":268},{},[],"Our hunt combined the skills of human researchers and AI agents to find 12 meaningful results from trillions of browser events visible to the Push extension across our install base.",{"data":1372,"content":1373,"nodeType":264},{},[1374],{"data":1375,"marks":1376,"value":1378,"nodeType":268},{},[1377],{"type":278},"Of those, one was novel. ",{"data":1380,"content":1381,"nodeType":264},{},[1382],{"data":1383,"marks":1384,"value":1385,"nodeType":268},{},[],"A user had searched for NotebookLM, clicked a paid Google ad, and gotten redirected to a page impersonating NotebookLM. The page itself was just a facade fronting a Cloudflare Pages-hosted phishing kit with a WebAssembly C2 connector. To the user, it looked like a completely on-brand NotebookLM page, and if they had run the fake install prompt, they would have installed malware. (Note: NotebookLM doesn’t even require a local install, but the page was convincing enough — and AI platforms are changing so quickly — that the lure was extremely believable.)",{"data":1387,"content":1388,"nodeType":264},{},[1389,1394,1405],{"data":1390,"marks":1391,"value":1393,"nodeType":268},{},[1392],{"type":278},"We had found our first in-the-wild ",{"data":1395,"content":1399,"nodeType":1347},{"target":1396},{"sys":1397},{"id":1398,"type":405,"linkType":406},"7bG71Eo43crbIHKzczooVS",[1400],{"data":1401,"marks":1402,"value":1404,"nodeType":268},{},[1403],{"type":278},"InstallFix attack",{"data":1406,"marks":1407,"value":332,"nodeType":268},{},[1408],{"type":278},{"data":1410,"content":1411,"nodeType":264},{},[1412],{"data":1413,"marks":1414,"value":1415,"nodeType":268},{},[],"Within minutes, our analysis agents created detections, and researchers shipped a new detection to every Push customer. ",{"data":1417,"content":1418,"nodeType":264},{},[1419],{"data":1420,"marks":1421,"value":1422,"nodeType":268},{},[],"Eighteen months ago, it would have taken a human analyst days or even weeks to unpack the attack, comb through web requests, de-obfuscate web code, trace JavaScript execution, and extract signals of tactics, techniques, and procedures (TTPs) beyond short-lived single-use IOCs like domain name, then get their work coded up as a detection and deployed to customers. ",{"data":1424,"content":1425,"nodeType":264},{},[1426],{"data":1427,"marks":1428,"value":1429,"nodeType":268},{},[],"That was viable when new tools or techniques showed up once or twice a quarter. It doesn’t stand a chance when attack evolutions occur weekly or even daily. That’s the reality now with AI-generated adversary tools.",{"data":1431,"content":1432,"nodeType":264},{},[1433,1438],{"data":1434,"marks":1435,"value":1437,"nodeType":268},{},[1436],{"type":278},"So, can AI agents replace human threat researchers?",{"data":1439,"marks":1440,"value":1441,"nodeType":268},{},[]," That’s the wrong question. Can AI agents massively scale the expertise of a seasoned human threat hunter without getting bored of repetitive tasks, missing pertinent but easily overlooked details, or creating operational siloes dependent on one person’s knowledge — and do its work continuously across trillions of data points? Yes, absolutely.",{"data":1443,"content":1447,"nodeType":400},{"target":1444},{"sys":1445},{"id":1446,"type":405,"linkType":406},"3OiZ7BrViCTTMmHUAbloEt",[],{"data":1449,"content":1450,"nodeType":409},{},[],{"data":1452,"content":1453,"nodeType":413},{},[1454],{"data":1455,"marks":1456,"value":1458,"nodeType":268},{},[1457],{"type":278},"Why scaling browser threat detection requires more than more analysts",{"data":1460,"content":1461,"nodeType":264},{},[1462,1466,1470],{"data":1463,"marks":1464,"value":1465,"nodeType":268},{},[],"Already this year, we’ve ",{"data":1467,"marks":1468,"value":968,"nodeType":268},{},[1469],{"type":278},{"data":1471,"marks":1472,"value":1473,"nodeType":268},{},[]," the cumulative number of detections shipped to Push customers using this pipeline. That output points to the first problem we set out to solve by employing AI agents: Scaling our research team’s considerable expertise.",{"data":1475,"content":1476,"nodeType":264},{},[1477,1481,1491],{"data":1478,"marks":1479,"value":1480,"nodeType":268},{},[],"Push’s R&D team are experts at understanding and unpacking modern browser-based attacks. This is essential when you consider how quickly attacks themselves are evolving. When we created the ",{"data":1482,"content":1486,"nodeType":1347},{"target":1483},{"sys":1484},{"id":1485,"type":405,"linkType":406},"211Dd0EIrXPOFpvRgs0fEE",[1487],{"data":1488,"marks":1489,"value":1490,"nodeType":268},{},[],"Browser & Identity Attacks Matrix",{"data":1492,"marks":1493,"value":1494,"nodeType":268},{},[]," in 2023 (then called the SaaS Attacks Matrix), many of the ideas in it were theoretical. Not anymore. ",{"data":1496,"content":1497,"nodeType":297},{},[1498,1508,1532],{"data":1499,"content":1500,"nodeType":301},{},[1501],{"data":1502,"content":1503,"nodeType":264},{},[1504],{"data":1505,"marks":1506,"value":1507,"nodeType":268},{},[],"We’ve tracked the rise of AiTM phish kits from their status as MFA-bypassing novelties to the emergence of an entire criminal ecosystem built around increasingly sophisticated Phishing-as-a-Service tools. ",{"data":1509,"content":1510,"nodeType":301},{},[1511],{"data":1512,"content":1513,"nodeType":264},{},[1514,1518,1528],{"data":1515,"marks":1516,"value":1517,"nodeType":268},{},[],"We imagined the simple but effective power of using device code authorization for phishing three years ago; in the last few months, we’ve detected a 37x increase in ",{"data":1519,"content":1523,"nodeType":1347},{"target":1520},{"sys":1521},{"id":1522,"type":405,"linkType":406},"5DmCqTU2Tg4adYScA5vT2x",[1524],{"data":1525,"marks":1526,"value":1527,"nodeType":268},{},[],"device code phishing attacks",{"data":1529,"marks":1530,"value":1531,"nodeType":268},{},[]," across our install base. ",{"data":1533,"content":1534,"nodeType":301},{},[1535],{"data":1536,"content":1537,"nodeType":264},{},[1538,1542,1551,1555,1564,1568,1578,1581,1590,1593,1603],{"data":1539,"marks":1540,"value":1541,"nodeType":268},{},[],"We were also the first to detect a novel post-authorization attack we dubbed ",{"data":1543,"content":1547,"nodeType":1347},{"target":1544},{"sys":1545},{"id":1546,"type":405,"linkType":406},"71EaaK7lfl6bQBbkAU0qjv",[1548],{"data":1549,"marks":1550,"value":888,"nodeType":268},{},[],{"data":1552,"marks":1553,"value":1554,"nodeType":268},{},[]," that combines OAuth consent phishing and ClickFix-style user prompts; reported on the rise of the ridiculously simple yet effective ",{"data":1556,"content":1559,"nodeType":1347},{"target":1557},{"sys":1558},{"id":1398,"type":405,"linkType":406},[1560],{"data":1561,"marks":1562,"value":1563,"nodeType":268},{},[],"InstallFix technique",{"data":1565,"marks":1566,"value":1567,"nodeType":268},{},[]," described earlier; and detected an array of other ",{"data":1569,"content":1573,"nodeType":1347},{"target":1570},{"sys":1571},{"id":1572,"type":405,"linkType":406},"2YmiesBvJHGw4wiKEKzLUq",[1574],{"data":1575,"marks":1576,"value":1577,"nodeType":268},{},[],"creative",{"data":1579,"marks":1580,"value":1118,"nodeType":268},{},[],{"data":1582,"content":1585,"nodeType":1347},{"target":1583},{"sys":1584},{"id":1341,"type":405,"linkType":406},[1586],{"data":1587,"marks":1588,"value":1589,"nodeType":268},{},[],"phishing",{"data":1591,"marks":1592,"value":1118,"nodeType":268},{},[],{"data":1594,"content":1598,"nodeType":1347},{"target":1595},{"sys":1596},{"id":1597,"type":405,"linkType":406},"6Zosy4SU0LpjlaSWX75peb",[1599],{"data":1600,"marks":1601,"value":1602,"nodeType":268},{},[],"campaigns",{"data":1604,"marks":1605,"value":1606,"nodeType":268},{},[]," tied to malvertising scams.",{"data":1608,"content":1612,"nodeType":400},{"target":1609},{"sys":1610},{"id":1611,"type":405,"linkType":406},"53U3LHhhHFYnEpShdLmDqs",[],{"data":1614,"content":1615,"nodeType":264},{},[1616],{"data":1617,"marks":1618,"value":1619,"nodeType":268},{},[],"With an agentic approach, we could scale this expertise and reduce the time it takes to go from technique discovery to production-ready detection. This speed is critical now because adversaries are also using AI tools to do their work, exploding the number of trivial-to-rotate indicators of compromise and overwhelming existing detection workflows that lack an equivalent machine speed.",{"data":1621,"content":1625,"nodeType":400},{"target":1622},{"sys":1623},{"id":1624,"type":405,"linkType":406},"1u00uFbC4xsvP9lqahXbgD",[],{"data":1627,"content":1628,"nodeType":946},{},[1629],{"data":1630,"marks":1631,"value":1633,"nodeType":268},{},[1632],{"type":278},"Scaling behavioral detections, not just making bigger blocklists",{"data":1635,"content":1636,"nodeType":264},{},[1637],{"data":1638,"marks":1639,"value":1640,"nodeType":268},{},[],"But output numbers alone don’t tell the story of successful detections. That’s the other problem we set out to solve at scale: Most secure browser solutions rely on detection logic based on blocking known-bad indicators like domains, IPs, and URLs.",{"data":1642,"content":1643,"nodeType":264},{},[1644,1649],{"data":1645,"marks":1646,"value":1648,"nodeType":268},{},[1647],{"type":278},"If your solution offers 1,000 detections, and they’re all based on known-bad indicators that are easily rotated, then you’ve got 1,000 detections that worked once and will likely never fire again. ",{"data":1650,"marks":1651,"value":1652,"nodeType":268},{},[],"They certainly won’t catch subtle adaptations in adversary techniques that don’t rely on infrastructure changes, which are easy for attackers to swap anyway. ",{"data":1654,"content":1655,"nodeType":264},{},[1656],{"data":1657,"marks":1658,"value":1659,"nodeType":268},{},[],"Push does it differently. Our detection engine is focused on hunting for tactics, techniques, and procedures: the behavioral fingerprints of an attack, not just the infrastructure it runs on. ",{"data":1661,"content":1665,"nodeType":400},{"target":1662},{"sys":1663},{"id":1664,"type":405,"linkType":406},"5jR3YVUiusHGnXDOyrgYpr",[],{"data":1667,"content":1668,"nodeType":264},{},[1669],{"data":1670,"marks":1671,"value":1672,"nodeType":268},{},[],"Instead of blocking based on known-bad domains, URLs, and IPs, our detections are built around user-level and page-level behaviors like what scripts load, how redirects behave, what events fire, what actions a user takes and what happens next, etc. (In fact, Push detections don’t even use any infrastructure-based IOCs, though customers can write their own custom detections if they have a specific IOC they’re keeping an eye on.)",{"data":1674,"content":1675,"nodeType":264},{},[1676,1681,1692],{"data":1677,"marks":1678,"value":1680,"nodeType":268},{},[1679],{"type":278},"All the detections we write would survive infrastructure rotation by adversaries, and many of our existing detections have caught never-before-seen evolutions in TTPs. That’s because we focus on the top of the ",{"data":1682,"content":1686,"nodeType":1347},{"target":1683},{"sys":1684},{"id":1685,"type":405,"linkType":406},"1qegIy4rMdm5XZXnIEoKpE",[1687],{"data":1688,"marks":1689,"value":1691,"nodeType":268},{},[1690],{"type":278},"Pyramid of Pain",{"data":1693,"marks":1694,"value":1696,"nodeType":268},{},[1695],{"type":278},", the indicators that are hardest for attackers to change.",{"data":1698,"content":1699,"nodeType":264},{},[1700],{"data":1701,"marks":1702,"value":1703,"nodeType":268},{},[],"This focus on detecting TTPs has always been our approach. But with the acceleration in both attack types and the ease with which adversaries rotate infrastructure, we needed to build capabilities that scaled our knowledge. ",{"data":1705,"content":1706,"nodeType":264},{},[1707],{"data":1708,"marks":1709,"value":1710,"nodeType":268},{},[],"We did this not by replacing researchers, but by continuously activating their expertise. You can hear what our CEO and Co-founder Adam had to say about this below. ",{"data":1712,"content":1716,"nodeType":400},{"target":1713},{"sys":1714},{"id":1715,"type":405,"linkType":406},"C9gr4nF3f6CW45Aol9xij",[],{"data":1718,"content":1719,"nodeType":409},{},[],{"data":1721,"content":1722,"nodeType":413},{},[1723],{"data":1724,"marks":1725,"value":1727,"nodeType":268},{},[1726],{"type":278},"Core principles for agentic threat hunting",{"data":1729,"content":1730,"nodeType":264},{},[1731],{"data":1732,"marks":1733,"value":1734,"nodeType":268},{},[],"Three principles make Push's agentic threat hunting and detection engineering pipeline work:",{"data":1736,"content":1737,"nodeType":946},{},[1738],{"data":1739,"marks":1740,"value":1742,"nodeType":268},{},[1741],{"type":278},"Context matters more than custom models",{"data":1744,"content":1745,"nodeType":264},{},[1746],{"data":1747,"marks":1748,"value":1749,"nodeType":268},{},[],"We’re not AI researchers; we’re security researchers — we aren't trying to compete in building the most intelligent models. And in our view, AI models are quickly becoming commoditized like cloud infrastructure, anyway. Luckily, the commercial models today already excel at understanding web code. We just need to harness their power with our expertise.",{"data":1751,"content":1752,"nodeType":264},{},[1753,1757,1762],{"data":1754,"marks":1755,"value":1756,"nodeType":268},{},[],"So at Push, we use a variety of commercial AI models and tools in complementary ways. What matters most is the telemetry they analyze, and that’s where Push’s existing product infrastructure shines: We’re already deployed into over ",{"data":1758,"marks":1759,"value":1761,"nodeType":268},{},[1760],{"type":278},"3 million browsers worldwide",{"data":1763,"marks":1764,"value":1765,"nodeType":268},{},[],", and the Push browser extension includes a component that operates as a flight recorder to locally record everything that matters inside a browser session.",{"data":1767,"content":1768,"nodeType":264},{},[1769],{"data":1770,"marks":1771,"value":1772,"nodeType":268},{},[],"This universe of metadata — DOM elements, tab context, script execution, network traffic, user actions, credential entry, etc. — becomes the searchable corpus for hunts. Metadata is stored locally in users’ browsers and only queried during targeted threat hunts. ",{"data":1774,"content":1775,"nodeType":264},{},[1776],{"data":1777,"marks":1778,"value":1779,"nodeType":268},{},[],"This approach avoids dragnet collection of sensitive data. Instead, we focus on collecting metadata and distilling that into patterns and insights that provide context for agents to perform their analysis. This means that Push also does not train or fine-tune models on customer data.",{"data":1781,"content":1782,"nodeType":946},{},[1783],{"data":1784,"marks":1785,"value":1787,"nodeType":268},{},[1786],{"type":278},"Agents are only as good as the context you give them. Good context is researcher-led",{"data":1789,"content":1790,"nodeType":264},{},[1791],{"data":1792,"marks":1793,"value":1794,"nodeType":268},{},[],"AI agents don’t know how to identify the TTPs of browser-based attacks until you give them the right context, and Push researchers have spent years unpacking these techniques and tools. Agents at Push consume our internal knowledge base of identified TTPs, and both humans and agents perform meta-analyses to check their work. The agents have access to large libraries of traces of human interactions with real phishing kits. This is a powerful dataset to build on.",{"data":1796,"content":1797,"nodeType":264},{},[1798],{"data":1799,"marks":1800,"value":1801,"nodeType":268},{},[],"When we don’t get the results we want from AI models, the question is “What context is it missing? What does our human team know that the agents don’t, and how can we give them that context — do they need data, tools, better workflows?” That closes the gap in performance and keeps quality high.",{"data":1803,"content":1804,"nodeType":946},{},[1805],{"data":1806,"marks":1807,"value":1809,"nodeType":268},{},[1808],{"type":278},"Integrated architecture that makes agentic AI the throughput layer, not a bolt-on",{"data":1811,"content":1812,"nodeType":264},{},[1813],{"data":1814,"marks":1815,"value":1816,"nodeType":268},{},[],"The constraint we’re trying to break by using AI isn’t knowledge, it’s throughput. Our researchers deeply understand the techniques and tools. An agentic pipeline can apply that understanding continuously across millions of browsers and trillions of events, ingest new external signals, generate hunt hypotheses, triage results, and return only the findings that warrant escalation.",{"data":1818,"content":1819,"nodeType":264},{},[1820],{"data":1821,"marks":1822,"value":1823,"nodeType":268},{},[],"This approach relies on tight integration of our product and our agentic workflows. We’ll take a closer look at that in the next section.",{"data":1825,"content":1826,"nodeType":409},{},[],{"data":1828,"content":1829,"nodeType":413},{},[1830],{"data":1831,"marks":1832,"value":1834,"nodeType":268},{},[1833],{"type":278},"How the agentic detection pipeline runs",{"data":1836,"content":1837,"nodeType":264},{},[1838],{"data":1839,"marks":1840,"value":1841,"nodeType":268},{},[],"Now let’s look at how agentic threat detection actually works, and some of the emerging best practices we’ve identified. We'll cover two example hunts, one initiated autonomously by the agents themselves, and one by our research team. ",{"data":1843,"content":1844,"nodeType":946},{},[1845],{"data":1846,"marks":1847,"value":1849,"nodeType":268},{},[1848],{"type":278},"Example 1: Autonomous threat hunt",{"data":1851,"content":1852,"nodeType":264},{},[1853],{"data":1854,"marks":1855,"value":1856,"nodeType":268},{},[],"Push’s threat hunting pipeline ingested context from research articles describing a new attack technique, and an agent developed hypotheses on what to hunt for across Push’s install base to identify instances of this attack. ",{"data":1858,"content":1859,"nodeType":264},{},[1860],{"data":1861,"marks":1862,"value":1863,"nodeType":268},{},[],"The agent crafted detection queries and then refined them to reduce false positives. The successful query ran across stored metadata and returned results, validating that there were zero false positives. ",{"data":1865,"content":1866,"nodeType":264},{},[1867],{"data":1868,"marks":1869,"value":1870,"nodeType":268},{},[],"The validated query became a scheduled job that runs on a regular cadence to monitor for potentially malicious signals. A triage agent then received any matches, did an initial analysis, and passed anything that looked suspicious to another agent to perform deeper analysis. This deep analysis agent wields the full investigative toolkit that a human researcher would — using Push’s internal knowledge base, domain age and registration analysis, URLScan and whois lookups, DOM image analysis, and contextual analysis of page-level and user-level behaviors, etc.",{"data":1872,"content":1873,"nodeType":264},{},[1874],{"data":1875,"marks":1876,"value":1877,"nodeType":268},{},[],"Within a few minutes, it can filter a thousand or more signals in a hunt trace down to a handful with meaning and provide an actionable assessment. Then, once the TTP was well-understood, other agents wrote and refined detections that can raise alerts for customers when an event of this type is seen. The Push platform immediately applies the customer’s configured security controls, such as blocking users from interacting with malicious pages.",{"data":1879,"content":1880,"nodeType":946},{},[1881],{"data":1882,"marks":1883,"value":1885,"nodeType":268},{},[1884],{"type":278},"Example 2: Human-initiated threat hunt",{"data":1887,"content":1888,"nodeType":264},{},[1889],{"data":1890,"marks":1891,"value":1892,"nodeType":268},{},[],"Now, going back to the example from the beginning of the article: InstallFix. This hunt started with a thorny problem our research team needed to solve: How to detect bad things downstream of a user interacting with a Google ad? We needed a way to pinpoint the bad links from the good ones.",{"data":1894,"content":1895,"nodeType":264},{},[1896,1900,1905,1908,1913,1916,1921],{"data":1897,"marks":1898,"value":1899,"nodeType":268},{},[],"Our researchers collaborated with agents to formulate the right parameters for hunt queries, taking into account that good ads are normally bought by companies with marketing budgets, so therefore ads will be expected to redirect to pages hosted on custom domains, not shared domains like ",{"data":1901,"marks":1902,"value":1904,"nodeType":268},{},[1903],{"type":278},"*pages.dev",{"data":1906,"marks":1907,"value":893,"nodeType":268},{},[],{"data":1909,"marks":1910,"value":1912,"nodeType":268},{},[1911],{"type":278},"*workers.dev",{"data":1914,"marks":1915,"value":893,"nodeType":268},{},[],{"data":1917,"marks":1918,"value":1920,"nodeType":268},{},[1919],{"type":278},"*squarespace.com",{"data":1922,"marks":1923,"value":1924,"nodeType":268},{},[],", etc.",{"data":1926,"content":1927,"nodeType":264},{},[1928],{"data":1929,"marks":1930,"value":1931,"nodeType":268},{},[],"Our AI agents already understood key TTPs that indicated potential maliciousness on a page: password prompts, file downloads, OAuth integrations, clipboard copies, and similar user prompts that are frequently abused.",{"data":1933,"content":1934,"nodeType":264},{},[1935],{"data":1936,"marks":1937,"value":1938,"nodeType":268},{},[],"The agent ran several queries that returned matching browsing traces — the term we use for sequences of events in a session or tab context — where the user clicked a Google ad, was redirected to a page on a shared hosting domain, and then clicked a button to copy content to their clipboard.",{"data":1940,"content":1944,"nodeType":400},{"target":1941},{"sys":1942},{"id":1943,"type":405,"linkType":406},"4IWOrWuvbwzWRJUkINiwKH",[],{"data":1946,"content":1947,"nodeType":264},{},[1948],{"data":1949,"marks":1950,"value":1951,"nodeType":268},{},[],"We got back high-fidelity findings and then tuned the query into a continuous detection that leveraged existing detection logic around related techniques. This process also effectively back-tests new detections, so we know we’re not going to generate a lot of false positives. Result: A new detection against a new technique, plus several improvements to existing detections.",{"data":1953,"content":1954,"nodeType":946},{},[1955],{"data":1956,"marks":1957,"value":1959,"nodeType":268},{},[1958],{"type":278},"What infrastructure is needed for agentic threat hunting?",{"data":1961,"content":1962,"nodeType":264},{},[1963],{"data":1964,"marks":1965,"value":1966,"nodeType":268},{},[],"Both of these examples illustrate the end-to-end workflows supported by this pipeline. From an infrastructure perspective, you can think about the pipeline as composed of:",{"data":1968,"content":1969,"nodeType":297},{},[1970,1985,2000,2015,2030],{"data":1971,"content":1972,"nodeType":301},{},[1973],{"data":1974,"content":1975,"nodeType":264},{},[1976,1981],{"data":1977,"marks":1978,"value":1980,"nodeType":268},{},[1979],{"type":278},"A flight recorder: ",{"data":1982,"marks":1983,"value":1984,"nodeType":268},{},[],"The Push extension-powered capability that collects and locally stores browser event metadata from users’ browsers.",{"data":1986,"content":1987,"nodeType":301},{},[1988],{"data":1989,"content":1990,"nodeType":264},{},[1991,1996],{"data":1992,"marks":1993,"value":1995,"nodeType":268},{},[1994],{"type":278},"A knowledge base:",{"data":1997,"marks":1998,"value":1999,"nodeType":268},{},[]," Structured knowledge about what Push knows about TTPs and its existing body of detection logic, as well as externally sourced signals of new attack trends.",{"data":2001,"content":2002,"nodeType":301},{},[2003],{"data":2004,"content":2005,"nodeType":264},{},[2006,2011],{"data":2007,"marks":2008,"value":2010,"nodeType":268},{},[2009],{"type":278},"Agents as tools: ",{"data":2012,"marks":2013,"value":2014,"nodeType":268},{},[],"Role-segmented agents that work as a team to triage, investigate, develop hunt queries, return analyses, write detections, and review each others’ work for completeness and accuracy.",{"data":2016,"content":2017,"nodeType":301},{},[2018],{"data":2019,"content":2020,"nodeType":264},{},[2021,2026],{"data":2022,"marks":2023,"value":2025,"nodeType":268},{},[2024],{"type":278},"Humans in the loop: ",{"data":2027,"marks":2028,"value":2029,"nodeType":268},{},[],"Human researchers who collaborate with agents to initiate hunts and tune detections.",{"data":2031,"content":2032,"nodeType":301},{},[2033],{"data":2034,"content":2035,"nodeType":264},{},[2036,2041],{"data":2037,"marks":2038,"value":2040,"nodeType":268},{},[2039],{"type":278},"Platform controls: ",{"data":2042,"marks":2043,"value":2044,"nodeType":268},{},[],"The Push administrator-configured controls that specify how to respond to detected events like AiTM phishing, tuneable by scope, user groups, browser profiles, apps, etc.",{"data":2046,"content":2050,"nodeType":400},{"target":2047},{"sys":2048},{"id":2049,"type":405,"linkType":406},"7FY0vCBUXOt4vnudFuKALC",[],{"data":2052,"content":2053,"nodeType":946},{},[2054],{"data":2055,"marks":2056,"value":2058,"nodeType":268},{},[2057],{"type":278},"What are the best practices for agentic threat detection?",{"data":2060,"content":2061,"nodeType":264},{},[2062,2066,2071],{"data":2063,"marks":2064,"value":2065,"nodeType":268},{},[],"To be effective, agents must specialize and focus. This is the ",{"data":2067,"marks":2068,"value":2070,"nodeType":268},{},[2069],{"type":278},"agents as tools",{"data":2072,"marks":2073,"value":2074,"nodeType":268},{},[]," concept. When we’re asking AI agents to take massive amounts of data and make a high-level decision about a signal in observed browser events, they must work as a team, finding intelligent ways to condense information without losing important context or hallucinating.",{"data":2076,"content":2077,"nodeType":264},{},[2078],{"data":2079,"marks":2080,"value":2081,"nodeType":268},{},[],"Creating a hierarchy of agent jobs — including agents to perform meta-analyses to catch mistakes and verify conclusions — makes the agents effective by giving them a manageable focus that controls the size of context windows.",{"data":2083,"content":2087,"nodeType":400},{"target":2084},{"sys":2085},{"id":2086,"type":405,"linkType":406},"3fzJCknMUmh4Z7YnhBSbsT",[],{"data":2089,"content":2090,"nodeType":264},{},[2091],{"data":2092,"marks":2093,"value":2094,"nodeType":268},{},[],"Creating an agentic workflow requires operationalizing your internal knowledge in a repeatable and trustworthy way. Sharing rich context from human discoveries is the key to getting the best results out of agents. ",{"data":2096,"content":2097,"nodeType":264},{},[2098,2102,2107],{"data":2099,"marks":2100,"value":2101,"nodeType":268},{},[],"It's vital too that the agent uses ",{"data":2103,"marks":2104,"value":2106,"nodeType":268},{},[2105],{"type":278},"privacy-preserving methods and infrastructure.",{"data":2108,"marks":2109,"value":2110,"nodeType":268},{},[]," The Push agent is designed to respect customer and user privacy while enabling high-fidelity detections. We do this by collecting broad browser metadata but storing it locally in users’ browsers and only querying that metadata during active threat hunting investigations.",{"data":2112,"content":2113,"nodeType":409},{},[],{"data":2115,"content":2116,"nodeType":413},{},[2117],{"data":2118,"marks":2119,"value":2121,"nodeType":268},{},[2120],{"type":278},"The compounding effect and how it benefits Push customers",{"data":2123,"content":2124,"nodeType":264},{},[2125],{"data":2126,"marks":2127,"value":2128,"nodeType":268},{},[],"At Push, we think about our detection capability as two learning loops with a compounding effect: An inner loop that serves as our real-time detection and response engine for known attacker techniques, and an outer loop that is the continuous learning our agents do as they hunt for new threats, analyze emerging behaviors, and create new detections. ",{"data":2130,"content":2131,"nodeType":264},{},[2132],{"data":2133,"marks":2134,"value":2135,"nodeType":268},{},[],"The outer loop feeds the inner loop, and vice versa.",{"data":2137,"content":2141,"nodeType":400},{"target":2138},{"sys":2139},{"id":2140,"type":405,"linkType":406},"1Jjqll7IIX2QRxN37gjFMH",[],{"data":2143,"content":2144,"nodeType":264},{},[2145],{"data":2146,"marks":2147,"value":2148,"nodeType":268},{},[],"Customers benefit from this approach because it means they:",{"data":2150,"content":2151,"nodeType":297},{},[2152,2174,2184],{"data":2153,"content":2154,"nodeType":301},{},[2155],{"data":2156,"content":2157,"nodeType":264},{},[2158,2162,2170],{"data":2159,"marks":2160,"value":2161,"nodeType":268},{},[],"Regularly receive ready-made detections against both known and emerging browser-based threats, without having to write their own detections. (Push also provides the ability to write your own ",{"data":2163,"content":2165,"nodeType":378},{"uri":2164},"/help/audience/engineering/resources/custom-detections",[2166],{"data":2167,"marks":2168,"value":2169,"nodeType":268},{},[],"custom detections",{"data":2171,"marks":2172,"value":2173,"nodeType":268},{},[],", too, for environment-specific use cases.)",{"data":2175,"content":2176,"nodeType":301},{},[2177],{"data":2178,"content":2179,"nodeType":264},{},[2180],{"data":2181,"marks":2182,"value":2183,"nodeType":268},{},[],"Can configure Push’s response actions based on their security goals and environment. Agents act as the threat-hunting and detection engineering team; Push customers set the thresholds for how they want to respond. For example, customers can use Push controls to block all AiTM phishing attacks (or even carve out exceptions for their own incident responders to be able to visit malicious pages with just a warning), and agents continually feed new indicators into detection logic for that class of attack.",{"data":2185,"content":2186,"nodeType":301},{},[2187],{"data":2188,"content":2189,"nodeType":264},{},[2190],{"data":2191,"marks":2192,"value":2193,"nodeType":268},{},[],"Get pre-digested and actionable intelligence from every detection, with extremely high fidelity.",{"data":2195,"content":2196,"nodeType":264},{},[2197],{"data":2198,"marks":2199,"value":2200,"nodeType":268},{},[],"This all equates to your own advanced browser threat protection, without requiring the specialized in-house expertise we’ve spent years building.",{"data":2202,"content":2203,"nodeType":264},{},[2204],{"data":2205,"marks":2206,"value":2207,"nodeType":268},{},[],"If you’re a Push customer, you already know that we regularly collaborate with security teams to identify and refine detection use cases, and assist with investigations. In the past few months alone, we’ve worked closely with teams targeted by device code phishing, and InstallFix and ClickFix campaigns, among others. ",{"data":2209,"content":2210,"nodeType":264},{},[2211],{"data":2212,"marks":2213,"value":2214,"nodeType":268},{},[],"If you’re not a customer and are curious about how Push’s agentic threat hunting and detection engineering capabilities can address your use cases, please get in touch.",{"data":2216,"content":2220,"nodeType":400},{"target":2217},{"sys":2218},{"id":2219,"type":405,"linkType":406},"607jrBjlD1vtcbkDfD04DE",[],{"data":2222,"content":2223,"nodeType":409},{},[],{"data":2225,"content":2226,"nodeType":413},{},[2227],{"data":2228,"marks":2229,"value":2231,"nodeType":268},{},[2230],{"type":278},"Learn more",{"data":2233,"content":2234,"nodeType":264},{},[2235],{"data":2236,"marks":2237,"value":2238,"nodeType":268},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":2240,"content":2241,"nodeType":264},{},[2242],{"data":2243,"marks":2244,"value":2245,"nodeType":268},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":2247,"content":2248,"nodeType":264},{},[2249,2253,2261],{"data":2250,"marks":2251,"value":2252,"nodeType":268},{},[],"Book a ",{"data":2254,"content":2256,"nodeType":378},{"uri":2255},"/demo",[2257],{"data":2258,"marks":2259,"value":2260,"nodeType":268},{},[],"live demo",{"data":2262,"marks":2263,"value":2264,"nodeType":268},{},[]," to learn more.","Can AI replace a threat researcher? What we learned building an agentic threat hunting pipeline","How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.","2026-05-12T00:00:00.000Z","can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",{"items":2270},[2271,2275],{"sys":2272,"name":2274},{"id":2273},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":2276,"name":2278},{"id":2277},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":2280},[2281],{"fullName":253,"firstName":254,"jobTitle":255,"profilePicture":2282},{"url":257},{"__typename":1316,"sys":2284,"content":2286,"title":3054,"synopsis":3055,"hashTags":62,"publishedDate":3056,"slug":3057,"tagsCollection":3058,"authorsCollection":3064},{"id":2285},"5RDOpmzJolwT1hk0fNIxzf",{"json":2287},{"nodeType":260,"data":2288,"content":2289},{},[2290,2309,2315,2322,2329,2332,2340,2359,2378,2385,2391,2398,2404,2411,2419,2426,2445,2477,2483,2489,2497,2504,2523,2554,2586,2593,2599,2607,2614,2626,2633,2674,2680,2722,2761,2767,2770,2778,2785,2791,2798,2805,2811,2818,2825,2853,2856,2864,2871,2879,2886,2893,2912,2919,2925,2932,2940,2947,2965,2972,2990,2993,3001,3008,3015,3022,3025,3031,3037],{"nodeType":264,"data":2291,"content":2292},{},[2293,2297,2305],{"nodeType":268,"value":2294,"marks":2295,"data":2296},"Back in 2024, we wrote about ",[],{},{"nodeType":378,"data":2298,"content":2300},{"uri":2299},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[2301],{"nodeType":268,"value":2302,"marks":2303,"data":2304},"how the Pyramid of Pain shapes Push's detection philosophy",[],{},{"nodeType":268,"value":2306,"marks":2307,"data":2308}," — detections targeting indicators that are easy for attackers to change deliver diminishing returns, while detections targeting attacker techniques impose a cost that's hard to absorb. Two years on, every force that made IoC-based detection fragile has intensified.",[],{},{"nodeType":400,"data":2310,"content":2314},{"target":2311},{"sys":2312},{"id":2313,"type":405,"linkType":406},"1iuLYxwI8T1wDUIFSom0G0",[],{"nodeType":264,"data":2316,"content":2317},{},[2318],{"nodeType":268,"value":2319,"marks":2320,"data":2321},"AI hasn't introduced a new problem so much as it's compressed the timelines on an existing one — attackers can generate infrastructure, iterate on tooling, and industrialize newly discovered techniques faster than before. The bottom layers of the Pyramid are collapsing under the weight of machine-speed operations, and the middle layers are starting to buckle too.",[],{},{"nodeType":264,"data":2323,"content":2324},{},[2325],{"nodeType":268,"value":2326,"marks":2327,"data":2328},"These changes mean that technique-level detection is more important than ever. In this article, we’ll dig into how the Pyramid is changing, and what this means for our detection philosophy at Push (TL;DR — it reinforces the path we’re already on: building detections at the top of the Pyramid by harnessing browser visibility). ",[],{},{"nodeType":409,"data":2330,"content":2331},{},[],{"nodeType":413,"data":2333,"content":2334},{},[2335],{"nodeType":268,"value":2336,"marks":2337,"data":2339},"The bottom of the Pyramid was already crumbling",[2338],{"type":278},{},{"nodeType":264,"data":2341,"content":2342},{},[2343,2347,2355],{"nodeType":268,"value":2344,"marks":2345,"data":2346},"The case against indicator-based detection didn't need AI to be compelling. ",[],{},{"nodeType":378,"data":2348,"content":2350},{"uri":2349},"https://www.spamhaus.org/",[2351],{"nodeType":268,"value":2352,"marks":2353,"data":2354},"89% of phishing domains are active for fewer than two days",[],{},{"nodeType":268,"value":2356,"marks":2357,"data":2358},", with just 6.5% surviving past 15 days — by the time a domain makes it onto a blocklist, the campaign has moved on.",[],{},{"nodeType":264,"data":2360,"content":2361},{},[2362,2366,2374],{"nodeType":268,"value":2363,"marks":2364,"data":2365},"We've ",[],{},{"nodeType":378,"data":2367,"content":2369},{"uri":2368},"https://pushsecurity.com/blog/why-most-phishing-attacks-feel-like-a-zero-day/",[2370],{"nodeType":268,"value":2371,"marks":2372,"data":2373},"written before",[],{},{"nodeType":268,"value":2375,"marks":2376,"data":2377}," about how this makes every phishing attack effectively a zero-day for organizations relying on known-bad detection. The phishing kit's behavior — its page structure, script signatures, malicious payload mechanics — is the only detection target that outlasts a single campaign.",[],{},{"nodeType":264,"data":2379,"content":2380},{},[2381],{"nodeType":268,"value":2382,"marks":2383,"data":2384},"When we blogged about the Pyramid of Pain for modern attacks that happen predominantly over the internet, with minimal (or zero) endpoint contact, it first looked like this: ",[],{},{"nodeType":400,"data":2386,"content":2390},{"target":2387},{"sys":2388},{"id":2389,"type":405,"linkType":406},"2N04ycJ6RKGfHdX5X1TwU3",[],{"nodeType":264,"data":2392,"content":2393},{},[2394],{"nodeType":268,"value":2395,"marks":2396,"data":2397},"Now, it looks more like this:",[],{},{"nodeType":400,"data":2399,"content":2403},{"target":2400},{"sys":2401},{"id":2402,"type":405,"linkType":406},"mfhP4WToOQkrHnVkXU0tX",[],{"nodeType":264,"data":2405,"content":2406},{},[2407],{"nodeType":268,"value":2408,"marks":2409,"data":2410},"Let’s explore why. ",[],{},{"nodeType":946,"data":2412,"content":2413},{},[2414],{"nodeType":268,"value":2415,"marks":2416,"data":2418},"AI is accelerating phishing rotation and delivery",[2417],{"type":278},{},{"nodeType":264,"data":2420,"content":2421},{},[2422],{"nodeType":268,"value":2423,"marks":2424,"data":2425},"Attackers are harnessing AI at every stage, speeding up the process of creating, rotating, and replacing phishing infrastructure at every level, as well as capitalizing on AI adoption itself to enhance their lures. The operational signature is more domains, shorter lifespans, more variation, and fewer of the reuse patterns that blocklists depend on.",[],{},{"nodeType":264,"data":2427,"content":2428},{},[2429,2433,2441],{"nodeType":268,"value":2430,"marks":2431,"data":2432},"Attackers can ",[],{},{"nodeType":378,"data":2434,"content":2436},{"uri":2435},"https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline/",[2437],{"nodeType":268,"value":2438,"marks":2439,"data":2440},"vibe-code entire phishing pages in minutes",[],{},{"nodeType":268,"value":2442,"marks":2443,"data":2444}," — not just cloning legitimate login pages but vibe-cloning them, feeding an AI a screenshot and having it rebuild a convincing frontend with a completely unique backend. ",[],{},{"nodeType":264,"data":2446,"content":2447},{},[2448,2452,2461,2465,2473],{"nodeType":268,"value":2449,"marks":2450,"data":2451},"We've seen attackers clone free SaaS tools like background removers and PDF converters, then inject phishing components or ClickFix payloads into what looks like a functional utility. We’ve even seen attackers distributing malware using AI-generated pages shared using ",[],{},{"nodeType":378,"data":2453,"content":2455},{"uri":2454},"https://pushsecurity.com/blog/llmshare-malvertising-campaign/",[2456],{"nodeType":268,"value":2457,"marks":2458,"data":2460},"LLM tool sharing functionality",[2459],{"type":386},{},{"nodeType":268,"value":2462,"marks":2463,"data":2464},", resulting in phishing delivery pages hosted on real claude.ai and chatgpt.com. And legitimate cloud platforms like ",[],{},{"nodeType":378,"data":2466,"content":2468},{"uri":2467},"https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign",[2469],{"nodeType":268,"value":2470,"marks":2471,"data":2472},"Railway",[],{},{"nodeType":268,"value":2474,"marks":2475,"data":2476},", Cloudflare Workers, and Vercel host and dynamically rotate attack infrastructure, so the domains feeding into blocklists often belong to reputable services that can't simply be blocked. ",[],{},{"nodeType":400,"data":2478,"content":2482},{"target":2479},{"sys":2480},{"id":2481,"type":405,"linkType":406},"5yoLmqysyQazfzLITCUTfc",[],{"nodeType":400,"data":2484,"content":2488},{"target":2485},{"sys":2486},{"id":2487,"type":405,"linkType":406},"5XK5qZMQU19xlA8L2T5y0Z",[],{"nodeType":946,"data":2490,"content":2491},{},[2492],{"nodeType":268,"value":2493,"marks":2494,"data":2496},"The kit ecosystem is fragmenting faster than anyone can track",[2495],{"type":278},{},{"nodeType":264,"data":2498,"content":2499},{},[2500],{"nodeType":268,"value":2501,"marks":2502,"data":2503},"What we see across our install base is a huge and growing variation in phishing kits — new kits, derivative kits of known platforms, derivatives of those derivatives — appearing on a weekly basis.",[],{},{"nodeType":264,"data":2505,"content":2506},{},[2507,2511,2519],{"nodeType":268,"value":2508,"marks":2509,"data":2510},"As we reported in our ",[],{},{"nodeType":378,"data":2512,"content":2514},{"uri":2513},"https://pushsecurity.com/thank-you/browser-attacks-report",[2515],{"nodeType":268,"value":2516,"marks":2517,"data":2518},"Browser Attacks Report",[],{},{"nodeType":268,"value":2520,"marks":2521,"data":2522},", the most common AiTM kits we detected over the last year were Tycoon 2FA (59% of detections), followed by Sneaky 2FA, FlowerStorm, Evilginx (nominally a red team tool, but widely abused by attackers), NakedPages, Gabagool, and dozens more — but those established names are just the visible layer.",[],{},{"nodeType":264,"data":2524,"content":2525},{},[2526,2530,2538,2542,2550],{"nodeType":268,"value":2527,"marks":2528,"data":2529},"Code is forked, modified, and redeployed across kits in a pattern that ",[],{},{"nodeType":378,"data":2531,"content":2533},{"uri":2532},"https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere",[2534],{"nodeType":268,"value":2535,"marks":2536,"data":2537},"resembles open-source development",[],{},{"nodeType":268,"value":2539,"marks":2540,"data":2541}," more than traditional criminal enterprise, and the rate at which new variants appear is accelerating. The ",[],{},{"nodeType":378,"data":2543,"content":2545},{"uri":2544},"https://pushsecurity.com/blog/device-code-phishing/",[2546],{"nodeType":268,"value":2547,"marks":2548,"data":2549},"Venom kit",[],{},{"nodeType":268,"value":2551,"marks":2552,"data":2553}," reuses Sneaky 2FA's AiTM infrastructure but carries different branding and adds device code phishing — whether it's the same developers, stolen code, or a deliberate fork is unclear.",[],{},{"nodeType":264,"data":2555,"content":2556},{},[2557,2561,2569,2573,2582],{"nodeType":268,"value":2558,"marks":2559,"data":2560},"Tycoon 2FA illustrates the scale of the evolution. The kit evolves continuously, addingnew capabilities, new evasion techniques, and hybridizing with other platforms. Even when Sekoia and Microsoft seized 330+ Tycoon domains in March 2026, the techniques it popularized were already embedded across competitors, and the slack was taken up by rival platforms within days. And in any case, Tycoon was back to ",[],{},{"nodeType":378,"data":2562,"content":2564},{"uri":2563},"https://www.crowdstrike.com/en-us/blog/tycoon2fa-phishing-as-a-service-platform-persists-following-takedown/",[2565],{"nodeType":268,"value":2566,"marks":2567,"data":2568},"normal levels of operation",[],{},{"nodeType":268,"value":2570,"marks":2571,"data":2572}," shortly after. It has also been observed ",[],{},{"nodeType":378,"data":2574,"content":2576},{"uri":2575},"https://www.okta.com/en-nl/blog/threat-intelligence/tycoon_2fa_phishing_actors_scatter/",[2577],{"nodeType":268,"value":2578,"marks":2579,"data":2581},"pivoting to add new device code phishing capabilities",[2580],{"type":386},{},{"nodeType":268,"value":2583,"marks":2584,"data":2585}," (more on that below). ",[],{},{"nodeType":264,"data":2587,"content":2588},{},[2589],{"nodeType":268,"value":2590,"marks":2591,"data":2592},"Tear one down and there are many more to take its place — and meanwhile the original is already evolving into something new.",[],{},{"nodeType":400,"data":2594,"content":2598},{"target":2595},{"sys":2596},{"id":2597,"type":405,"linkType":406},"3UDzUCCizPJhXp3SsoZuSK",[],{"nodeType":946,"data":2600,"content":2601},{},[2602],{"nodeType":268,"value":2603,"marks":2604,"data":2606},"New techniques are being industrialized faster than ever",[2605],{"type":278},{},{"nodeType":264,"data":2608,"content":2609},{},[2610],{"nodeType":268,"value":2611,"marks":2612,"data":2613},"As well as the fragmentation of existing kits, we’re seeing new techniques added at an accelerating rate. ",[],{},{"nodeType":264,"data":2615,"content":2616},{},[2617,2622],{"nodeType":268,"value":2618,"marks":2619,"data":2621},"Device code phishing",[2620],{"type":278},{},{"nodeType":268,"value":2623,"marks":2624,"data":2625}," is the clearest case study. From early nation state adoption in 2024, it took until 2026 for criminal adoption to really take off, but the take-up this year is unprecedented. The EvilTokens kit packaged device code phishing into a PhaaS offering with GPT-powered spear-phishing and adaptive landing pages, hitting 340+ organizations across five countries in March 2026. ",[],{},{"nodeType":264,"data":2627,"content":2628},{},[2629],{"nodeType":268,"value":2630,"marks":2631,"data":2632},"Now, device code functionality is now a core phish kit component. We’re tracking 18+ kits with device code phishing capabilities and a 37.5x increase in device code phishing detections this year alone, with the technique moving from state-sponsored exclusivity to something any PhaaS customer can rent.",[],{},{"nodeType":264,"data":2634,"content":2635},{},[2636,2640,2648,2652,2657,2661,2670],{"nodeType":268,"value":2637,"marks":2638,"data":2639},"Similarly, when we ",[],{},{"nodeType":378,"data":2641,"content":2643},{"uri":2642},"https://pushsecurity.com/blog/inside-criminal-phishing-panel",[2644],{"nodeType":268,"value":2645,"marks":2646,"data":2647},"infiltrated Doko's Panel",[],{},{"nodeType":268,"value":2649,"marks":2650,"data":2651}," — a ",[],{},{"nodeType":268,"value":2653,"marks":2654,"data":2656},"real-time vishing and AiTM platform",[2655],{"type":278},{},{"nodeType":268,"value":2658,"marks":2659,"data":2660}," used by ShinyHunters and affiliated groups — the codebase was full of LLM-generated artifacts. Multiple groups were using the templated vishing panel and spinning up their own variants, but the AI-generated indicators persisted throughout. This approach to real-time vishing + browser payload has been a ",[],{},{"nodeType":378,"data":2662,"content":2664},{"uri":2663},"https://pushsecurity.com/blog/analyzing-the-instructure-breach/",[2665],{"nodeType":268,"value":2666,"marks":2667,"data":2669},"mainstay of the Com affiliates like ShinyHunters this year",[2668],{"type":386},{},{"nodeType":268,"value":2671,"marks":2672,"data":2673},". ",[],{},{"nodeType":400,"data":2675,"content":2679},{"target":2676},{"sys":2677},{"id":2678,"type":405,"linkType":406},"01mOiserRBXraawXwQyJNm",[],{"nodeType":264,"data":2681,"content":2682},{},[2683,2687,2692,2696,2705,2709,2718],{"nodeType":268,"value":2684,"marks":2685,"data":2686},"The broader ",[],{},{"nodeType":268,"value":2688,"marks":2689,"data":2691},"ClickFix",[2690],{"type":278},{},{"nodeType":268,"value":2693,"marks":2694,"data":2695}," family shows the same acceleration: First reported in early 2024 and adopted by four nation-state groups within a single quarter. Fast forward and ",[],{},{"nodeType":378,"data":2697,"content":2699},{"uri":2698},"https://www.crowdstrike.com/en-us/global-threat-report/",[2700],{"nodeType":268,"value":2701,"marks":2702,"data":2704},"CrowdStrike's data",[2703],{"type":386},{},{"nodeType":268,"value":2706,"marks":2707,"data":2708}," shows a 563% increase in fake CAPTCHA incidents (one of the more common ClickFix lure types), while ",[],{},{"nodeType":378,"data":2710,"content":2712},{"uri":2711},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf",[2713],{"nodeType":268,"value":2714,"marks":2715,"data":2717},"Microsoft reported",[2716],{"type":386},{},{"nodeType":268,"value":2719,"marks":2720,"data":2721}," it as making up 47% of observed attacks according to their Digital Defense Report.",[],{},{"nodeType":264,"data":2723,"content":2724},{},[2725,2729,2733,2737,2745,2749,2757],{"nodeType":268,"value":2726,"marks":2727,"data":2728},"And ",[],{},{"nodeType":268,"value":888,"marks":2730,"data":2732},[2731],{"type":278},{},{"nodeType":268,"value":2734,"marks":2735,"data":2736}," — a combination of ClickFix and OAuth consent phishing techniques — suggests the next compression is already underway. Push researchers ",[],{},{"nodeType":378,"data":2738,"content":2740},{"uri":2739},"https://pushsecurity.com/blog/consentfix/",[2741],{"nodeType":268,"value":2742,"marks":2743,"data":2744},"discovered the technique",[],{},{"nodeType":268,"value":2746,"marks":2747,"data":2748}," in December 2025 — a browser-native ClickFix variant hijacking OAuth consent grants via Azure CLI's localhost redirect. It was later confirmed to be tied to APT29. By January 2026, a ",[],{},{"nodeType":378,"data":2750,"content":2752},{"uri":2751},"https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit/",[2753],{"nodeType":268,"value":2754,"marks":2755,"data":2756},"criminal ConsentFix v3 toolkit",[],{},{"nodeType":268,"value":2758,"marks":2759,"data":2760}," had appeared on the XSS forum with Cloudflare Workers, ZoomInfo targeting, and automated exfiltration via Pipedream.",[],{},{"nodeType":400,"data":2762,"content":2766},{"target":2763},{"sys":2764},{"id":2765,"type":405,"linkType":406},"41FMif4T0y1maflzonWgL8",[],{"nodeType":409,"data":2768,"content":2769},{},[],{"nodeType":413,"data":2771,"content":2772},{},[2773],{"nodeType":268,"value":2774,"marks":2775,"data":2777},"Why technique-level detection is the only layer that holds",[2776],{"type":278},{},{"nodeType":264,"data":2779,"content":2780},{},[2781],{"nodeType":268,"value":2782,"marks":2783,"data":2784},"The middle of the Pyramid — tool signatures and artifacts — used to offer much more durable detection than infrastructure indicators. Fingerprinting a specific phishing kit by its JavaScript structure or HTML patterns provided a detection target that survived across dozens or hundreds of campaigns, even as the underlying domains rotated. Tool level detections are still better, but not by quite the same margin.",[],{},{"nodeType":400,"data":2786,"content":2790},{"target":2787},{"sys":2788},{"id":2789,"type":405,"linkType":406},"5pxaYdCIFiFKLPhRaPoldX",[],{"nodeType":264,"data":2792,"content":2793},{},[2794],{"nodeType":268,"value":2795,"marks":2796,"data":2797},"When the kit landscape was dominated by a handful of platforms, you could write signatures for Tycoon, Sneaky2FA, EvilProxy, and so on, and cover the lion's share of attacks. With the ecosystem now producing new variants and entirely new kits on a weekly basis, detecting by kit fingerprint starts to look uncomfortably similar to detecting by domain.",[],{},{"nodeType":264,"data":2799,"content":2800},{},[2801],{"nodeType":268,"value":2802,"marks":2803,"data":2804},"But many of these proliferating kits do share behavioral patterns at a deeper level than their code signatures. For example, every device code phishing kit implements fundamentally the same flow: present a lure, generate a device code via the OAuth Device Authorization endpoint, get the user to enter it on the legitimate authorization page, and poll for the resulting tokens. The frontends vary, the infrastructure varies, but the behavioral pattern doesn't.",[],{},{"nodeType":400,"data":2806,"content":2810},{"target":2807},{"sys":2808},{"id":2809,"type":405,"linkType":406},"FyyHayQtsJTwoB1kluMOl",[],{"nodeType":264,"data":2812,"content":2813},{},[2814],{"nodeType":268,"value":2815,"marks":2816,"data":2817},"Genuinely new attack techniques still require human creativity — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted. That kind of innovation hasn't been automated. But the window to discover a technique, build a detection, and then deploy it before it is adopted by criminals at scale is compressing with each generation.",[],{},{"nodeType":264,"data":2819,"content":2820},{},[2821],{"nodeType":268,"value":2822,"marks":2823,"data":2824},"Organizations that detect at the technique level and deploy before commoditization have a structural advantage that increases over time. Waiting for indicators — even tool-level indicators — means chasing a curve that's accelerating away from you. This is the challenge we grapple with every day as we strive for the most resilient detections possible. ",[],{},{"nodeType":2826,"data":2827,"content":2828},"blockquote",{},[2829],{"nodeType":264,"data":2830,"content":2831},{},[2832,2836,2844,2848],{"nodeType":268,"value":2833,"marks":2834,"data":2835},"As our CPO Jacques Louw put it on ",[],{},{"nodeType":378,"data":2837,"content":2839},{"uri":2838},"https://risky.biz/RBNEWSSI128/",[2840],{"nodeType":268,"value":2841,"marks":2842,"data":2843},"Risky Business",[],{},{"nodeType":268,"value":2845,"marks":2846,"data":2847},": ",[],{},{"nodeType":268,"value":2849,"marks":2850,"data":2852},"\"There's no list of bad domains anywhere in the product. It's a crutch — a false cheat code that stops you from doing the detection in the way that actually is resilient, because the next time you see it, it will be on a different domain.\"",[2851],{"type":276},{},{"nodeType":409,"data":2854,"content":2855},{},[],{"nodeType":413,"data":2857,"content":2858},{},[2859],{"nodeType":268,"value":2860,"marks":2861,"data":2863},"What it takes to detect at the top of the Pyramid",[2862],{"type":278},{},{"nodeType":264,"data":2865,"content":2866},{},[2867],{"nodeType":268,"value":2868,"marks":2869,"data":2870},"If technique-level detection is the only layer that holds, two things have to be true about your detection capability: You need the right vantage point, and you need the research velocity to stay ahead.",[],{},{"nodeType":946,"data":2872,"content":2873},{},[2874],{"nodeType":268,"value":2875,"marks":2876,"data":2878},"You need the right vantage point",[2877],{"type":278},{},{"nodeType":264,"data":2880,"content":2881},{},[2882],{"nodeType":268,"value":2883,"marks":2884,"data":2885},"Technique-level behaviors in browser-based identity attacks — how a phishing page orchestrates credential entry, how a device code flow presents its authorization prompt, how a ClickFix variant manipulates the clipboard — are visible in the browser session and nowhere else.",[],{},{"nodeType":264,"data":2887,"content":2888},{},[2889],{"nodeType":268,"value":2890,"marks":2891,"data":2892},"Network proxies see encrypted traffic and can attempt to reconstruct page behavior from metadata, but DOM manipulation, user interaction sequences, and script execution aren't visible from that vantage point. Email gateways see the delivery mechanism (or nothing at all in the increasing number of social media and search engine based attacks) but not the payload.",[],{},{"nodeType":264,"data":2894,"content":2895},{},[2896,2900,2908],{"nodeType":268,"value":2897,"marks":2898,"data":2899},"As we disclosed in our ",[],{},{"nodeType":378,"data":2901,"content":2902},{"uri":2513},[2903],{"nodeType":268,"value":2904,"marks":2905,"data":2907},"browser attacks report",[2906],{"type":386},{},{"nodeType":268,"value":2909,"marks":2910,"data":2911},", 95% of in-browser attacks we detect use some form of bot protection, often combined with conditional loading techniques like referrer and browser checks, reliably defeating automated analysis techniques. ",[],{},{"nodeType":264,"data":2913,"content":2914},{},[2915],{"nodeType":268,"value":2916,"marks":2917,"data":2918},"Behavioral detection at the technique level requires observing what happens on the page at the moment the user interacts with it — analyzing pages, not links. When you see the entire browsing flow — ad click, redirect chain, page render, credential prompt — an attack stands out immediately. Without that context, any detection system is forced to fill in gaps, and the gaps are where attacks hide.",[],{},{"nodeType":400,"data":2920,"content":2924},{"target":2921},{"sys":2922},{"id":2923,"type":405,"linkType":406},"4804g6u4POUDpL42bzP0EY",[],{"nodeType":264,"data":2926,"content":2927},{},[2928],{"nodeType":268,"value":2929,"marks":2930,"data":2931},"Push sits inside the browser session, observing this in real time. Its detections target the behavioral mechanics of techniques rather than the surface characteristics of individual kits or infrastructure.",[],{},{"nodeType":946,"data":2933,"content":2934},{},[2935],{"nodeType":268,"value":2936,"marks":2937,"data":2939},"You need the research expertise",[2938],{"type":278},{},{"nodeType":264,"data":2941,"content":2942},{},[2943],{"nodeType":268,"value":2944,"marks":2945,"data":2946},"When the window between technique discovery and industrialized exploitation is measured in weeks rather than years, the detection pipeline needs to operate on that same compressed timescale.",[],{},{"nodeType":264,"data":2948,"content":2949},{},[2950,2954,2961],{"nodeType":268,"value":2951,"marks":2952,"data":2953},"This is where our ",[],{},{"nodeType":378,"data":2955,"content":2956},{"uri":2435},[2957],{"nodeType":268,"value":2958,"marks":2959,"data":2960},"agentic threat hunting pipeline",[],{},{"nodeType":268,"value":2962,"marks":2963,"data":2964}," fits. It's tripled our monthly detection output — not by generating bigger blocklists, but by scaling the process of discovering behavioral patterns across the telemetry generated by 3+ million browser deployments.",[],{},{"nodeType":264,"data":2966,"content":2967},{},[2968],{"nodeType":268,"value":2969,"marks":2970,"data":2971},"The detections it produces are technique-class by design, targeting how attacks work rather than the infrastructure or specific tool that implements them. The goal is curation, not accumulation — hundreds of high-fidelity behavioral detections rather than the billions of signatures and domain entries that traditional approaches require.",[],{},{"nodeType":264,"data":2973,"content":2974},{},[2975,2979,2986],{"nodeType":268,"value":2976,"marks":2977,"data":2978},"When we detected the first in-the-wild ",[],{},{"nodeType":378,"data":2980,"content":2982},{"uri":2981},"https://pushsecurity.com/blog/installfix/",[2983],{"nodeType":268,"value":1404,"marks":2984,"data":2985},[],{},{"nodeType":268,"value":2987,"marks":2988,"data":2989}," through the pipeline — a user had searched for NotebookLM, clicked a paid Google ad, and was redirected to a fake page with a WebAssembly C2 connector — the detection shipped to all customers within minutes. It didn't depend on knowing the domain, the ad creative, or the specific kit. It depended on recognizing the technique itself.",[],{},{"nodeType":409,"data":2991,"content":2992},{},[],{"nodeType":413,"data":2994,"content":2995},{},[2996],{"nodeType":268,"value":2997,"marks":2998,"data":3000},"Technique-level detection is now the only option",[2999],{"type":278},{},{"nodeType":264,"data":3002,"content":3003},{},[3004],{"nodeType":268,"value":3005,"marks":3006,"data":3007},"As a framework for detection durability, the Pyramid of Pain is more relevant than ever. ",[],{},{"nodeType":264,"data":3009,"content":3010},{},[3011],{"nodeType":268,"value":3012,"marks":3013,"data":3014},"AI has made infrastructure indicators essentially disposable. The tools tier is compressing as criminal vendors vibe-code, fork, and clone tooling at machine speed. Technique-level detection is the layer that holds long-term to be able to proactively detect and block net-new attacks and the kits that power them. ",[],{},{"nodeType":264,"data":3016,"content":3017},{},[3018],{"nodeType":268,"value":3019,"marks":3020,"data":3021},"Novel attack techniques still require human creativity to discover, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation. Defending that layer requires a vantage point inside the browser session and a research pipeline fast enough to stay ahead of the accelerating path from discovery to industrialization.",[],{},{"nodeType":409,"data":3023,"content":3024},{},[],{"nodeType":264,"data":3026,"content":3027},{},[3028],{"nodeType":268,"value":2238,"marks":3029,"data":3030},[],{},{"nodeType":264,"data":3032,"content":3033},{},[3034],{"nodeType":268,"value":2245,"marks":3035,"data":3036},[],{},{"nodeType":264,"data":3038,"content":3039},{},[3040,3043,3051],{"nodeType":268,"value":29,"marks":3041,"data":3042},[],{},{"nodeType":378,"data":3044,"content":3045},{"uri":1190},[3046],{"nodeType":268,"value":3047,"marks":3048,"data":3050},"Book a live demo",[3049],{"type":386},{},{"nodeType":268,"value":2264,"marks":3052,"data":3053},[],{},"The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever","AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.","2026-06-01T00:00:00.000Z","the-pyramid-of-pain-in-the-ai-era",{"items":3059},[3060,3062],{"sys":3061,"name":2278},{"id":2277},{"sys":3063,"name":2274},{"id":2273},{"items":3065},[3066],{"fullName":3067,"firstName":3068,"jobTitle":3069,"profilePicture":3070},"Dan Green","Dan","Threat Research",{"url":3071},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1316,"sys":3073,"content":3075,"title":3866,"synopsis":3867,"hashTags":62,"publishedDate":3868,"slug":3869,"tagsCollection":3870,"authorsCollection":3876},{"id":3074},"Gcg7PGuICrlRcqq1QFXxH",{"json":3076},{"nodeType":260,"data":3077,"content":3078},{},[3079,3086,3093,3124,3131,3137,3143,3155,3158,3166,3182,3189,3195,3202,3209,3215,3218,3226,3233,3239,3245,3252,3259,3277,3283,3286,3294,3312,3318,3325,3328,3336,3343,3350,3356,3362,3406,3413,3416,3424,3431,3438,3481,3488,3519,3526,3569,3576,3579,3587,3606,3613,3621,3636,3643,3660,3667,3670,3676,3682,3700,3703,3711,3730,3737,3860],{"nodeType":264,"data":3080,"content":3081},{},[3082],{"nodeType":268,"value":3083,"marks":3084,"data":3085},"Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.  ",[],{},{"nodeType":264,"data":3087,"content":3088},{},[3089],{"nodeType":268,"value":3090,"marks":3091,"data":3092},"The content lives on chatgpt.com or claude.ai — domains that users and security tools trust implicitly — so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.",[],{},{"nodeType":264,"data":3094,"content":3095},{},[3096,3100,3108,3112,3120],{"nodeType":268,"value":3097,"marks":3098,"data":3099},"Several variants of this technique have been ",[],{},{"nodeType":378,"data":3101,"content":3103},{"uri":3102},"https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/",[3104],{"nodeType":268,"value":3105,"marks":3106,"data":3107},"reported over the past few months",[],{},{"nodeType":268,"value":3109,"marks":3110,"data":3111},". The earliest examples used shared Claude.ai conversations disguised as installation guides — complete with fake \"Apple Support\" attribution — that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer. ",[],{},{"nodeType":378,"data":3113,"content":3115},{"uri":3114},"https://www.kaspersky.com/blog/share-chatgpt-chat-clickfix-macos-amos-infostealer/54928/",[3116],{"nodeType":268,"value":3117,"marks":3118,"data":3119},"Kaspersky documented a parallel campaign",[],{},{"nodeType":268,"value":3121,"marks":3122,"data":3123}," using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern. ",[],{},{"nodeType":264,"data":3125,"content":3126},{},[3127],{"nodeType":268,"value":3128,"marks":3129,"data":3130},"Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable. ",[],{},{"nodeType":400,"data":3132,"content":3136},{"target":3133},{"sys":3134},{"id":3135,"type":405,"linkType":406},"5lz9zt223pecGvdaqdvSTQ",[],{"nodeType":400,"data":3138,"content":3142},{"target":3139},{"sys":3140},{"id":3141,"type":405,"linkType":406},"51GomAj3VOjnbmgd1DWYu0",[],{"nodeType":264,"data":3144,"content":3145},{},[3146,3151],{"nodeType":268,"value":3147,"marks":3148,"data":3150},"This is a live campaign which is still generating detections across our customer base at the time of writing. ",[3149],{"type":278},{},{"nodeType":268,"value":3152,"marks":3153,"data":3154},"Push customers are already protected and do not need to take further action. The malicious page URLs can be found at the end of this report but are not exhaustive and are liable to change. ",[],{},{"nodeType":409,"data":3156,"content":3157},{},[],{"nodeType":413,"data":3159,"content":3160},{},[3161],{"nodeType":268,"value":3162,"marks":3163,"data":3165},"A fake page, not a fake conversation",[3164],{"type":278},{},{"nodeType":264,"data":3167,"content":3168},{},[3169,3173,3178],{"nodeType":268,"value":3170,"marks":3171,"data":3172},"Previously reported variants relied on shared ",[],{},{"nodeType":268,"value":3174,"marks":3175,"data":3177},"conversations",[3176],{"type":276},{},{"nodeType":268,"value":3179,"marks":3180,"data":3181}," — the attacker created a chat that contained step-by-step instructions for the victim to follow, typically involving pasting a command into their terminal. The social engineering was conversational: the \"AI assistant\" appeared to be helpfully guiding the user through an installation process.",[],{},{"nodeType":264,"data":3183,"content":3184},{},[3185],{"nodeType":268,"value":3186,"marks":3187,"data":3188},"But now, rather than a shared conversation, the attacker has used ChatGPT's code rendering feature to create a fully designed, self-contained web page hosted at a chatgpt.com/s/ URL. It renders as what appears to be a ChatGPT service disruption notice:",[],{},{"nodeType":400,"data":3190,"content":3194},{"target":3191},{"sys":3192},{"id":3193,"type":405,"linkType":406},"1O9gyQab81SnbxhQp2aa5Z",[],{"nodeType":264,"data":3196,"content":3197},{},[3198],{"nodeType":268,"value":3199,"marks":3200,"data":3201},"A professional-looking error message reads: \"We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.\" A prominent download button sits below.",[],{},{"nodeType":264,"data":3203,"content":3204},{},[3205],{"nodeType":268,"value":3206,"marks":3207,"data":3208},"The \"Show code\" toggle at the top of the page reveals what's actually happening — the entire thing is custom HTML and CSS, authored to mimic a ChatGPT system notice, rendered using ChatGPT's code output feature. A web page inside a web page, hosted on a domain that every URL reputation system in the world considers safe.",[],{},{"nodeType":400,"data":3210,"content":3214},{"target":3211},{"sys":3212},{"id":3213,"type":405,"linkType":406},"4kQTfxB3aVH9W9BeYOuljP",[],{"nodeType":409,"data":3216,"content":3217},{},[],{"nodeType":413,"data":3219,"content":3220},{},[3221],{"nodeType":268,"value":3222,"marks":3223,"data":3225},"The download page",[3224],{"type":278},{},{"nodeType":264,"data":3227,"content":3228},{},[3229],{"nodeType":268,"value":3230,"marks":3231,"data":3232},"Clicking the download button redirects the user to openew[.]app, which presents a convincing clone of ChatGPT's official desktop application download page — complete with OpenAI branding, macOS and Windows download buttons, a Chrome extension link, and a mobile download section.",[],{},{"nodeType":400,"data":3234,"content":3238},{"target":3235},{"sys":3236},{"id":3237,"type":405,"linkType":406},"4MdFc4OB37ZihTGx506QJ6",[],{"nodeType":400,"data":3240,"content":3244},{"target":3241},{"sys":3242},{"id":3243,"type":405,"linkType":406},"LaPUy0zpIeY8s4PF2wkat",[],{"nodeType":264,"data":3246,"content":3247},{},[3248],{"nodeType":268,"value":3249,"marks":3250,"data":3251},"The site also displays differently depending on who visits it. When Push researchers examined the URL via URLScan, the scanner was redirected to a different page entirely — a generic AR/VR company website with no obvious connection to ChatGPT. ",[],{},{"nodeType":264,"data":3253,"content":3254},{},[3255],{"nodeType":268,"value":3256,"marks":3257,"data":3258},"Real users in a browser see the fake download page; automated scanners and bots see something benign. This kind of conditional rendering is a well-established evasion technique in the malvertising ecosystem, and it makes the malicious infrastructure harder for security teams and threat intelligence services to identify and analyze.",[],{},{"nodeType":264,"data":3260,"content":3261},{},[3262,3266,3274],{"nodeType":268,"value":3263,"marks":3264,"data":3265},"The downloaded executable poses as \"ChatGPT for Desktop\" and is ",[],{},{"nodeType":378,"data":3267,"content":3269},{"uri":3268},"https://www.virustotal.com/gui/file/de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[3270],{"nodeType":268,"value":3271,"marks":3272,"data":3273},"flagged on VirusTotal",[],{},{"nodeType":268,"value":332,"marks":3275,"data":3276},[],{},{"nodeType":400,"data":3278,"content":3282},{"target":3279},{"sys":3280},{"id":3281,"type":405,"linkType":406},"3FSbwoFJYQrcyo9uMsQIWI",[],{"nodeType":409,"data":3284,"content":3285},{},[],{"nodeType":413,"data":3287,"content":3288},{},[3289],{"nodeType":268,"value":3290,"marks":3291,"data":3293},"The Claude variant: same campaign, different platform",[3292],{"type":278},{},{"nodeType":264,"data":3295,"content":3296},{},[3297,3301,3308],{"nodeType":268,"value":3298,"marks":3299,"data":3300},"Alongside the ChatGPT rendered-page variant, Push has also detected the previously reported style of attack using shared Claude.ai conversations. These follow the pattern documented by ",[],{},{"nodeType":378,"data":3302,"content":3303},{"uri":3102},[3304],{"nodeType":268,"value":3305,"marks":3306,"data":3307},"BleepingComputer",[],{},{"nodeType":268,"value":3309,"marks":3310,"data":3311},": a shared chat disguised as a \"Claude Code on Mac\" installation guide, attributed to \"Apple Support,\" containing a curl command that downloads and executes malware.",[],{},{"nodeType":400,"data":3313,"content":3317},{"target":3314},{"sys":3315},{"id":3316,"type":405,"linkType":406},"5sWayuTsVdiLSLoS4sv2Vc",[],{"nodeType":264,"data":3319,"content":3320},{},[3321],{"nodeType":268,"value":3322,"marks":3323,"data":3324},"The fact that both the ChatGPT and Claude variants are appearing in Push customer environments suggests a campaign — or at least a shared playbook — that is actively experimenting with different platforms and different social engineering approaches to find what converts best.",[],{},{"nodeType":409,"data":3326,"content":3327},{},[],{"nodeType":413,"data":3329,"content":3330},{},[3331],{"nodeType":268,"value":3332,"marks":3333,"data":3335},"Malvertising remains one of the top phishing delivery channels",[3334],{"type":278},{},{"nodeType":264,"data":3337,"content":3338},{},[3339],{"nodeType":268,"value":3340,"marks":3341,"data":3342},"Push has detected this variant across multiple customer environments, with users arriving at these shared chat URLs after searching for terms including \"chatgpt,\" \"chatgpt free,\" \"chat gpt,\" and common typos like \"chatgo,\" \"chatgot,\" and \"cvhatgpt.\" ",[],{},{"nodeType":264,"data":3344,"content":3345},{},[3346],{"nodeType":268,"value":3347,"marks":3348,"data":3349},"You can see an example of this below: it's incredibly convincing, and uses the real ChatGPT domain — so even users that are paying attention are liable to fall for it. ",[],{},{"nodeType":400,"data":3351,"content":3355},{"target":3352},{"sys":3353},{"id":3354,"type":405,"linkType":406},"1GYWOyHpZT1rdTm6IGOKu8",[],{"nodeType":400,"data":3357,"content":3361},{"target":3358},{"sys":3359},{"id":3360,"type":405,"linkType":406},"4HpFJRAZH2lbygaEk2xOnN",[],{"nodeType":264,"data":3363,"content":3364},{},[3365,3369,3377,3381,3389,3393,3402],{"nodeType":268,"value":3366,"marks":3367,"data":3368},"This fits a pattern Push has tracked extensively. ",[],{},{"nodeType":378,"data":3370,"content":3372},{"uri":3371},"https://pushsecurity.com/blog/verizon-dbir-2026-review/",[3373],{"nodeType":268,"value":3374,"marks":3375,"data":3376},"Search-based delivery is now the dominant channel for malware distribution",[],{},{"nodeType":268,"value":3378,"marks":3379,"data":3380}," — our own data shows that ClickFix attacks are reached via search results rather than email in 4 of 5 cases, and Push's own research into ",[],{},{"nodeType":378,"data":3382,"content":3384},{"uri":3383},"https://pushsecurity.com/blog/analysing-a-sophisticated-google-malvertising-attack/",[3385],{"nodeType":268,"value":3386,"marks":3387,"data":3388},"malvertising campaigns impersonating brands like TradingView",[],{},{"nodeType":268,"value":3390,"marks":3391,"data":3392}," and ",[],{},{"nodeType":378,"data":3394,"content":3396},{"uri":3395},"https://pushsecurity.com/blog/google-search-malvertising-campaign-continues-now-impersonating-ahrefs/",[3397],{"nodeType":268,"value":3398,"marks":3399,"data":3401},"Ahrefs",[3400],{"type":386},{},{"nodeType":268,"value":3403,"marks":3404,"data":3405}," has demonstrated how effectively search ads can funnel victims to malicious pages. ",[],{},{"nodeType":264,"data":3407,"content":3408},{},[3409],{"nodeType":268,"value":3410,"marks":3411,"data":3412},"The shared-chat technique adds a new dimension: the destination URL itself is genuine (chatgpt.com, claude.ai), which means even a cautious user who checks the URL before clicking will see nothing suspicious.",[],{},{"nodeType":409,"data":3414,"content":3415},{},[],{"nodeType":413,"data":3417,"content":3418},{},[3419],{"nodeType":268,"value":3420,"marks":3421,"data":3423},"Legitimate platform abuse is everywhere",[3422],{"type":278},{},{"nodeType":264,"data":3425,"content":3426},{},[3427],{"nodeType":268,"value":3428,"marks":3429,"data":3430},"This is one example of a much broader pattern that has become one of the defining characteristics of the 2026 threat landscape: attackers systematically abusing legitimate platforms as attack infrastructure. The scale and variety of this abuse in recent months alone is striking, and it spans every stage of the phishing chain.",[],{},{"nodeType":946,"data":3432,"content":3433},{},[3434],{"nodeType":268,"value":3435,"marks":3436,"data":3437},"Legit platform abuse for delivery",[],{},{"nodeType":264,"data":3439,"content":3440},{},[3441,3445,3453,3457,3465,3469,3477],{"nodeType":268,"value":3442,"marks":3443,"data":3444},"On the delivery side, attackers have been ",[],{},{"nodeType":378,"data":3446,"content":3448},{"uri":3447},"https://www.bleepingcomputer.com/news/security/amazon-ses-increasingly-abused-in-phishing-to-evade-detection/",[3449],{"nodeType":268,"value":3450,"marks":3451,"data":3452},"weaponizing stolen AWS credentials to send phishing through Amazon SES",[],{},{"nodeType":268,"value":3454,"marks":3455,"data":3456}," that passes SPF, DKIM, and DMARC validation because SES is a legitimate Amazon service. A Vietnamese operation dubbed ",[],{},{"nodeType":378,"data":3458,"content":3460},{"uri":3459},"https://thehackernews.com/2026/05/30000-facebook-accounts-hacked-via.html",[3461],{"nodeType":268,"value":3462,"marks":3463,"data":3464},"AccountDumpling used Google AppSheet's built-in email capability",[],{},{"nodeType":268,"value":3466,"marks":3467,"data":3468}," as a phishing relay to harvest 30,000 Facebook credentials. ",[],{},{"nodeType":378,"data":3470,"content":3472},{"uri":3471},"https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/",[3473],{"nodeType":268,"value":3474,"marks":3475,"data":3476},"Scammers exploited Microsoft's own internal notification pipeline",[],{},{"nodeType":268,"value":3478,"marks":3479,"data":3480}," — sending phishing from the same msonlineservicesteam@microsoftonline.com address that delivers legitimate 2FA codes — with Spamhaus confirming months of ongoing abuse.",[],{},{"nodeType":946,"data":3482,"content":3483},{},[3484],{"nodeType":268,"value":3485,"marks":3486,"data":3487},"Legit platform abuse for hosting",[],{},{"nodeType":264,"data":3489,"content":3490},{},[3491,3495,3503,3507,3515],{"nodeType":268,"value":3492,"marks":3493,"data":3494},"For hosting, the platforms being abused read like a who's who of modern web infrastructure. ",[],{},{"nodeType":378,"data":3496,"content":3498},{"uri":3497},"https://www.securityweek.com/over-500-organizations-hit-in-years-long-phishing-campaign/",[3499],{"nodeType":268,"value":3500,"marks":3501,"data":3502},"Operation HookedWing ran for four years",[],{},{"nodeType":268,"value":3504,"marks":3505,"data":3506}," on GitHub Pages and Vercel, compromising 500+ organizations across more than 100 GitHub Pages domains before anyone documented it publicly. Cofense has separately ",[],{},{"nodeType":378,"data":3508,"content":3510},{"uri":3509},"https://cofense.com/blog/steal-smarter-not-harder-malicious-use-of-vercel-for-credential-phishing/",[3511],{"nodeType":268,"value":3512,"marks":3513,"data":3514},"documented the growing abuse of Vercel",[],{},{"nodeType":268,"value":3516,"marks":3517,"data":3518}," for credential phishing hosting. Pixm's Q1 2026 phishing report tracked over 100 unique Azure Blob Storage subdomain variants hosting phishing content that carried Microsoft's own domain reputation, alongside abuse of Cloudflare CDN, Cloudflare Workers, Cloudflare R2, Backblaze B2, and Supabase. ",[],{},{"nodeType":946,"data":3520,"content":3521},{},[3522],{"nodeType":268,"value":3523,"marks":3524,"data":3525},"Abuse of compromised websites that are otherwise legit",[],{},{"nodeType":264,"data":3527,"content":3528},{},[3529,3533,3541,3545,3553,3557,3565],{"nodeType":268,"value":3530,"marks":3531,"data":3532},"Compromised legitimate sites are also being repurposed at scale. A mass exploitation of a ",[],{},{"nodeType":378,"data":3534,"content":3536},{"uri":3535},"https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/",[3537],{"nodeType":268,"value":3538,"marks":3539,"data":3540},"Ghost CMS vulnerability planted ClickFix pages across 700+ websites",[],{},{"nodeType":268,"value":3542,"marks":3543,"data":3544}," including Harvard, Oxford, and DuckDuckGo subdomains. Microsoft recently documented a campaign where ",[],{},{"nodeType":378,"data":3546,"content":3548},{"uri":3547},"https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/",[3549],{"nodeType":268,"value":3550,"marks":3551,"data":3552},"SEO poisoning was combined with AI chatbot recommendation manipulation",[],{},{"nodeType":268,"value":3554,"marks":3555,"data":3556}," to deliver GPU mining malware — extending the poisoning from traditional search results into AI-generated software recommendations. And ",[],{},{"nodeType":378,"data":3558,"content":3560},{"uri":3559},"https://www.helpnetsecurity.com/2026/05/27/deno-rat-malware-fake-chatgpt-claude-installers/",[3561],{"nodeType":268,"value":3562,"marks":3563,"data":3564},"fake ChatGPT and Claude installers on GitHub and SourceForge",[],{},{"nodeType":268,"value":3566,"marks":3567,"data":3568}," have been delivering the DinDoor backdoor and a Deno-based RAT via repositories that mimic legitimate developer tool distributions.",[],{},{"nodeType":264,"data":3570,"content":3571},{},[3572],{"nodeType":268,"value":3573,"marks":3574,"data":3575},"The structural problem is that every one of these platforms is genuinely legitimate, and the security controls that evaluate them — domain reputation, email authentication, URL categorization — confirm them as trusted because they are trusted. This attack extends this pattern into new territory by weaponizing the content-sharing features of AI chatbot platforms specifically, but the underlying principles are the same. ",[],{},{"nodeType":409,"data":3577,"content":3578},{},[],{"nodeType":413,"data":3580,"content":3581},{},[3582],{"nodeType":268,"value":3583,"marks":3584,"data":3586},"Impact analysis",[3585],{"type":278},{},{"nodeType":264,"data":3588,"content":3589},{},[3590,3594,3602],{"nodeType":268,"value":3591,"marks":3592,"data":3593},"Shared-chat malware delivery exploits a structural property of AI platforms that traditional security controls aren't designed to handle. Domain reputation, URL categorization, and safe browsing databases all treat chatgpt.com and claude.ai as trusted — because they are. Using these trusted pages to link off to further convincing-looking pages hosting malware allows the attacker to run campaigns that blend in, as well as rotate the phishing delivery pages later in the chain should they ever be flagged, allowing the campaign to continue without interruption (a well known ",[],{},{"nodeType":378,"data":3595,"content":3597},{"uri":3596},"https://phishing-techniques.pushsecurity.com/",[3598],{"nodeType":268,"value":3599,"marks":3600,"data":3601},"detection evasion technique",[],{},{"nodeType":268,"value":3603,"marks":3604,"data":3605},"). ",[],{},{"nodeType":264,"data":3607,"content":3608},{},[3609],{"nodeType":268,"value":3610,"marks":3611,"data":3612},"What makes the rendered-page variant particularly concerning is that it eliminates the most obvious red flag in the earlier attacks. The Claude.ai conversation variants required the victim to recognize that a shared chat instructing them to paste terminal commands might be suspicious — a tall order for many users, but at least the attack surface was visible. The rendered-page variant shows nothing that looks like an attack. It presents what appears to be a routine service disruption with a reasonable call to action: download the desktop app to continue using ChatGPT. ",[],{},{"nodeType":946,"data":3614,"content":3615},{},[3616],{"nodeType":268,"value":3617,"marks":3618,"data":3620},"How Push detected the attack",[3619],{"type":278},{},{"nodeType":264,"data":3622,"content":3623},{},[3624,3628,3632],{"nodeType":268,"value":3625,"marks":3626,"data":3627},"We've aligned our detection logic for this technique under the name ",[],{},{"nodeType":268,"value":914,"marks":3629,"data":3631},[3630],{"type":278},{},{"nodeType":268,"value":3633,"marks":3634,"data":3635}," — a technique-level detection that covers shared content abuse across LLM platforms, not tied to any single campaign or set of IOCs. ",[],{},{"nodeType":264,"data":3637,"content":3638},{},[3639],{"nodeType":268,"value":3640,"marks":3641,"data":3642},"Because Push sees the full context of how a user arrived at a page and what that page does once it renders, we can identify LLMShare attacks regardless of which AI platform is being abused or what social engineering wrapper the attacker has chosen. ",[],{},{"nodeType":264,"data":3644,"content":3645},{},[3646,3650,3656],{"nodeType":268,"value":3647,"marks":3648,"data":3649},"When we identified the initial instances of this campaign, we used our ",[],{},{"nodeType":378,"data":3651,"content":3652},{"uri":2435},[3653],{"nodeType":268,"value":2958,"marks":3654,"data":3655},[],{},{"nodeType":268,"value":3657,"marks":3658,"data":3659}," to hunt for additional examples across our customer telemetry, develop the LLMShare detection, and rapidly deploy it to customers. Push blocks users from interacting with the page before any malicious activity can occur. ",[],{},{"nodeType":264,"data":3661,"content":3662},{},[3663],{"nodeType":268,"value":3664,"marks":3665,"data":3666},"Push customers do not need to take any further action.",[],{},{"nodeType":409,"data":3668,"content":3669},{},[],{"nodeType":264,"data":3671,"content":3672},{},[3673],{"nodeType":268,"value":2238,"marks":3674,"data":3675},[],{},{"nodeType":264,"data":3677,"content":3678},{},[3679],{"nodeType":268,"value":2245,"marks":3680,"data":3681},[],{},{"nodeType":264,"data":3683,"content":3684},{},[3685,3688,3697],{"nodeType":268,"value":29,"marks":3686,"data":3687},[],{},{"nodeType":378,"data":3689,"content":3691},{"uri":3690},"https://pushsecurity.com/demo/",[3692],{"nodeType":268,"value":3693,"marks":3694,"data":3696},"Book a live demo to learn more.",[3695],{"type":386},{},{"nodeType":268,"value":29,"marks":3698,"data":3699},[],{},{"nodeType":409,"data":3701,"content":3702},{},[],{"nodeType":413,"data":3704,"content":3705},{},[3706],{"nodeType":268,"value":3707,"marks":3708,"data":3710},"Indicators of compromise",[3709],{"type":278},{},{"nodeType":264,"data":3712,"content":3713},{},[3714,3718,3726],{"nodeType":268,"value":3715,"marks":3716,"data":3717},"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",[],{},{"nodeType":378,"data":3719,"content":3721},{"uri":3720},"https://phishing-techniques.pushsecurity.com/techniques/domain-rotation-redirection/",[3722],{"nodeType":268,"value":3723,"marks":3724,"data":3725},"quickly spin up and rotate the sites used",[],{},{"nodeType":268,"value":3727,"marks":3728,"data":3729}," in the attack chain. IoC-based detections for campaigns like this are of limited value.",[],{},{"nodeType":264,"data":3731,"content":3732},{},[3733],{"nodeType":268,"value":3734,"marks":3735,"data":3736},"At the time of writing, the indicators observed were:",[],{},{"nodeType":3738,"data":3739,"content":3740},"table",{},[3741,3768,3792,3814,3837],{"nodeType":3742,"data":3743,"content":3744},"table-row",{},[3745,3757],{"nodeType":3746,"data":3747,"content":3748},"table-header-cell",{},[3749],{"nodeType":264,"data":3750,"content":3751},{},[3752],{"nodeType":268,"value":3753,"marks":3754,"data":3756},"Indicator",[3755],{"type":278},{},{"nodeType":3746,"data":3758,"content":3759},{},[3760],{"nodeType":264,"data":3761,"content":3762},{},[3763],{"nodeType":268,"value":3764,"marks":3765,"data":3767},"Type",[3766],{"type":278},{},{"nodeType":3742,"data":3769,"content":3770},{},[3771,3782],{"nodeType":3772,"data":3773,"content":3774},"table-cell",{},[3775],{"nodeType":264,"data":3776,"content":3777},{},[3778],{"nodeType":268,"value":3779,"marks":3780,"data":3781},"hxxps://claude[.]ai/share/8e6401b5-4849-46c4-a3cb-29e1c3c49131",[],{},{"nodeType":3772,"data":3783,"content":3784},{},[3785],{"nodeType":264,"data":3786,"content":3787},{},[3788],{"nodeType":268,"value":3789,"marks":3790,"data":3791},"URL",[],{},{"nodeType":3742,"data":3793,"content":3794},{},[3795,3805],{"nodeType":3772,"data":3796,"content":3797},{},[3798],{"nodeType":264,"data":3799,"content":3800},{},[3801],{"nodeType":268,"value":3802,"marks":3803,"data":3804},"hxxps://chatgpt[.]com/s/cb_6a0f1e6bbec88191aa7fede27163f08d",[],{},{"nodeType":3772,"data":3806,"content":3807},{},[3808],{"nodeType":264,"data":3809,"content":3810},{},[3811],{"nodeType":268,"value":3789,"marks":3812,"data":3813},[],{},{"nodeType":3742,"data":3815,"content":3816},{},[3817,3827],{"nodeType":3772,"data":3818,"content":3819},{},[3820],{"nodeType":264,"data":3821,"content":3822},{},[3823],{"nodeType":268,"value":3824,"marks":3825,"data":3826},"openew[.]app",[],{},{"nodeType":3772,"data":3828,"content":3829},{},[3830],{"nodeType":264,"data":3831,"content":3832},{},[3833],{"nodeType":268,"value":3834,"marks":3835,"data":3836},"Domain",[],{},{"nodeType":3742,"data":3838,"content":3839},{},[3840,3850],{"nodeType":3772,"data":3841,"content":3842},{},[3843],{"nodeType":264,"data":3844,"content":3845},{},[3846],{"nodeType":268,"value":3847,"marks":3848,"data":3849},"de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[],{},{"nodeType":3772,"data":3851,"content":3852},{},[3853],{"nodeType":264,"data":3854,"content":3855},{},[3856],{"nodeType":268,"value":3857,"marks":3858,"data":3859},"SHA256",[],{},{"nodeType":264,"data":3861,"content":3862},{},[3863],{"nodeType":268,"value":29,"marks":3864,"data":3865},[],{},"LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":3871},[3872,3874],{"sys":3873,"name":2274},{"id":2273},{"sys":3875,"name":2278},{"id":2277},{"items":3877},[3878],{"fullName":3879,"firstName":3880,"jobTitle":3881,"profilePicture":3882},"Keanu Maharaj","Keanu","Senior Security Researcher",{"url":3883},"https://images.ctfassets.net/y1cdw1ablpvd/VCGOm62jiocjwngWTh32U/e9a30637b1c76bf988d2fec90f5b6c36/1689361049351_1.png","agentic-threat-hunting-benefits-for-customers","blog/agentic-threat-hunting-benefits-for-customers",{"json":3887},{"data":3888,"content":3889,"nodeType":260},{},[3890],{"data":3891,"content":3892,"nodeType":264},{},[3893],{"data":3894,"marks":3895,"value":3896,"nodeType":268},{},[],"Most security tools learn from breaches. Push learns from many attacks that never become breaches. Here are the security outcomes you can achieve when AI agents hunt in the browser, identify new threats, and ship detections that benefit everyone — often stopping new attacks pre-compromise.","Security outcomes you can achieve when AI agents hunt in the browser, identify new threats, and ship detections that benefit everyone.",{"id":3899,"publishedAt":3900},"6dJUsirH3rrhy1Stnzkfqk","2026-07-23T08:17:47.718Z",{"items":3902},[3903,3905],{"sys":3904,"name":2278},{"id":2277},{"sys":3906,"name":2274},{"id":2273},"28dX0XUkhRvRjjZnu0ccIZ5kkTTB9OR7mMh_89WI0v4",1784800268210]