[{"data":1,"prerenderedAt":3330},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"trust-badges":226,"blog/from-iocs-to-ttps-an-agentic-threat-hunting-case-study":247},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"query":14,"data":15,"variations":20,"lastUpdated":21,"firstPublished":22,"testRatio":23,"createdBy":24,"lastUpdatedBy":25,"folders":26,"meta":27,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",[],{"type":16,"url":17,"text":18,"link":19},"web-banner","https://pushsecurity.com/resources/browser-attacks-report","Get our latest report analyzing browser attack techniques in 2026",{},{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],{"kind":28,"lastPreviewUrl":29,"breakpoints":30,"hasAutosaves":34},"data","",{"xsmall":31,"small":32,"medium":33},320,640,768,true,"3178et4qm7w",{"createdDate":37,"id":38,"name":39,"modelId":40,"published":13,"stageModifiedSincePublish":6,"query":41,"data":42,"variations":97,"lastUpdated":98,"firstPublished":99,"testRatio":23,"createdBy":100,"lastUpdatedBy":101,"folders":102,"meta":103,"rev":107},1774965361051,"fd266d0172cc47429be7ad10f48c99ad","always visible banner","0678d178ec8b41efb8a23c09dba7874d",[],{"ctaText":43,"text":44,"url":29,"blocks":45,"state":93},"ewrererw","testrfesssssssssss",[46,73,81],{"@type":47,"@version":48,"id":49,"component":50,"responsiveStyles":63},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":51,"tag":51,"options":52,"isRSC":62},"TopBannerContent",{"text":53,"ctaText":54,"url":55,"mainText":56,"cta":59},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https://pushsecurity.com/webinar/state-of-browser-security",{"content":57,"fontSize":58},"\u003Cp>Meet Push's browser security experts at BlackHat 2026.\u003C/p>","text-base",{"content":60,"fontSize":58,"url":61},"\u003Cp>Book a meeting →\u003C/p>","https://pushsecurity.com/events/blackhat-2026-meeting",null,{"large":64},{"display":65,"flexDirection":66,"position":67,"flexShrink":68,"boxSizing":69,"marginTop":70,"marginBottom":70,"fontSize":71,"fontWeight":72},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":47,"@version":48,"id":74,"component":75,"responsiveStyles":79},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":76,"options":77,"isRSC":62},"Custom Code",{"code":78,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C/style>\n",{"large":80},{"display":65,"flexDirection":66,"position":67,"flexShrink":68,"boxSizing":69},{"id":82,"@type":47,"tagName":83,"properties":84,"responsiveStyles":88},"builder-pixel-rxorsvni7s","img",{"src":85,"aria-hidden":86,"alt":29,"role":87,"width":68,"height":68},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":89},{"height":68,"width":68,"display":90,"opacity":68,"overflow":91,"pointerEvents":92},"block","hidden","none",{"deviceSize":94,"location":95},"large",{"path":29,"query":96},{},{},1783541846936,1774968080803,"ST0tXQM8slWpFrmioqKHmENB2qe2","kYgMv6WsbvfmlOUYqR2SFwGzw6e2",[],{"kind":104,"lastPreviewUrl":105,"hasLinks":6,"breakpoints":106,"hasErrors":6,"hasAutosaves":6},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default",{"xsmall":31,"small":32,"medium":33},"8j1bzro9gfc",[109,145],{"createdDate":110,"id":111,"name":112,"modelId":113,"published":13,"stageModifiedSincePublish":6,"query":114,"data":115,"variations":138,"lastUpdated":139,"firstPublished":140,"testRatio":23,"createdBy":24,"lastUpdatedBy":24,"folders":141,"meta":142,"rev":144},1776247359804,"9136a8f18b3b4a6ba29b8653a99372b1","testimonial-inductive-automation","20d9eaa352304613b3d1a794b400703d",[],{"link":116,"type":117,"testimonialLink":118,"testimonial":119},{},"testimonial","/customer-stories/inductive-automation",{"@type":120,"id":121,"model":117,"value":122},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79",{"query":123,"folders":124,"createdDate":125,"id":121,"name":126,"modelId":127,"published":13,"data":128,"variations":132,"lastUpdated":133,"firstPublished":134,"testRatio":23,"createdBy":100,"lastUpdatedBy":100,"meta":135,"rev":137},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":129,"jobTitle":130,"quote":126,"image":131},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":28,"lastPreviewUrl":29,"breakpoints":136,"hasAutosaves":34},{"small":32,"medium":33},"spvot0e2m0a",{},1776247404986,1776247404973,[],{"breakpoints":143,"kind":28,"lastPreviewUrl":29,"hasAutosaves":6},{"xsmall":31,"small":32,"medium":33},"13y8l6tympzh",{"createdDate":146,"id":147,"name":148,"modelId":113,"published":13,"meta":149,"stageModifiedSincePublish":6,"query":151,"data":152,"variations":178,"lastUpdated":179,"firstPublished":180,"testRatio":23,"createdBy":24,"lastUpdatedBy":24,"folders":181,"rev":144},1776255761419,"05a9322735fc427db12e2740e4302300","Report: 2026 Browser Attack Techniques",{"breakpoints":150,"kind":28,"lastPreviewUrl":29,"hasAutosaves":6},{"xsmall":31,"small":32,"medium":33},[],{"testimonial":153,"link":172,"type":175,"title":148,"description":176,"image":177},{"@type":120,"id":154,"model":117,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":127,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":23,"createdBy":100,"lastUpdatedBy":24,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":29,"quote":164,"image":165},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":28,"lastPreviewUrl":29,"breakpoints":170,"hasAutosaves":34},{"small":32,"medium":33},"m1ob0wit6bb",{"text":173,"url":174},"Download now","/resources/browser-attacks-report","resource","Learn about the latest techniques being used in the wild.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{},1776255810913,1776255810900,[],[183,205],{"createdDate":184,"id":185,"name":148,"modelId":186,"published":13,"meta":187,"stageModifiedSincePublish":6,"query":189,"data":190,"variations":200,"lastUpdated":201,"firstPublished":202,"testRatio":23,"createdBy":24,"lastUpdatedBy":24,"folders":203,"rev":204},1776256900280,"1f429607996e4e5fae8fe3f9b9610e55","4829faa81e7c4ee8bd2d000e160e8d3c",{"breakpoints":188,"kind":28,"lastPreviewUrl":29,"hasAutosaves":6},{"xsmall":31,"small":32,"medium":33},[],{"testimonial":191,"link":199,"type":175,"title":148,"description":176,"image":177},{"@type":120,"id":154,"model":117,"value":192},{"query":193,"folders":194,"createdDate":158,"id":154,"name":159,"modelId":127,"published":13,"data":195,"variations":196,"lastUpdated":167,"firstPublished":168,"testRatio":23,"createdBy":100,"lastUpdatedBy":24,"meta":197,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":29,"quote":164,"image":165},{},{"kind":28,"lastPreviewUrl":29,"breakpoints":198,"hasAutosaves":34},{"small":32,"medium":33},{"text":173,"url":174},{},1776256937553,1776256937540,[],"l3w2ktbxple",{"createdDate":206,"id":207,"name":208,"modelId":186,"published":13,"stageModifiedSincePublish":6,"query":209,"data":210,"variations":220,"lastUpdated":221,"firstPublished":222,"testRatio":23,"createdBy":24,"lastUpdatedBy":24,"folders":223,"meta":224,"rev":204},1776256949234,"ce043785b71b4ece98eac811ecf4ba10","inductive-automation",[],{"link":211,"type":117,"testimonial":212,"testimonialLink":118},{},{"@type":120,"id":121,"model":117,"value":213},{"query":214,"folders":215,"createdDate":125,"id":121,"name":126,"modelId":127,"published":13,"data":216,"variations":217,"lastUpdated":133,"firstPublished":134,"testRatio":23,"createdBy":100,"lastUpdatedBy":100,"meta":218,"rev":137},[],[],{"author":129,"jobTitle":130,"quote":126,"image":131},{},{"kind":28,"lastPreviewUrl":29,"breakpoints":219,"hasAutosaves":34},{"small":32,"medium":33},{},1776256974140,1776256974130,[],{"breakpoints":225,"kind":28,"lastPreviewUrl":29,"hasAutosaves":6},{"xsmall":31,"small":32,"medium":33},[227,231,235,239,243],{"title":228,"logo":229,"createdDate":230},"SOC2","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":232,"logo":233,"createdDate":234},"GDPR","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":236,"logo":237,"createdDate":238},"Cyber essentials","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":240,"logo":241,"createdDate":242},"ISO IEC 27001","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":244,"logo":245,"createdDate":246},"ISO IEC 27701","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,{"id":248,"title":249,"authorsCollection":250,"content":258,"extension":743,"faqItemsCollection":744,"faqTitle":62,"featured":6,"hashTags":62,"meta":746,"metaTitle":747,"ogImage":62,"publishedDate":748,"relatedBlogPostsCollection":749,"slug":3306,"stem":3307,"subtitle":62,"summary":3308,"synopsis":3319,"sys":3320,"tagsCollection":3323,"__hash__":3329},"blog/blog/from-iocs-to-ttps-an-agentic-threat-hunting-case-study.json","From IOCs to TTPs: An agentic threat hunting case study",{"items":251},[252],{"fullName":253,"firstName":254,"jobTitle":255,"profilePicture":256},"Kelly Davenport","Kelly","Product Team",{"url":257},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"json":259,"links":682},{"nodeType":260,"data":261,"content":262},"document",{},[263,272,279,286,293,300,322,329,336,343,352,356,364,383,389,406,422,439,455,462,469,476,482,489,496,503,510,516,536,551,558,565,572,579,586,593,599,606,613,620,627,634,641,648,655,662],{"nodeType":264,"data":265,"content":266},"paragraph",{},[267],{"nodeType":268,"value":269,"marks":270,"data":271},"text","Every security engineer has a version of this ritual. ",[],{},{"nodeType":264,"data":273,"content":274},{},[275],{"nodeType":268,"value":276,"marks":277,"data":278},"A new campaign hits the news, and you already hear the question coming, “Are we covered?”",[],{},{"nodeType":264,"data":280,"content":281},{},[282],{"nodeType":268,"value":283,"marks":284,"data":285},"So you read the writeup and quickly do the calculus on whether you can extract meaningful data, something to base a behavioral detection around — or not.",[],{},{"nodeType":264,"data":287,"content":288},{},[289],{"nodeType":268,"value":290,"marks":291,"data":292},"Then the choice is: Send the IOCs you can identify to your blocklists and move on for now, or try to dig deeper. The limitations of the first choice are clear; so are the challenges of the second.",[],{},{"nodeType":264,"data":294,"content":295},{},[296],{"nodeType":268,"value":297,"marks":298,"data":299},"That’s the uncomfortable gap between “We’re aware of this threat” and “We have strong detections around it.”",[],{},{"nodeType":264,"data":301,"content":302},{},[303,307,318],{"nodeType":268,"value":304,"marks":305,"data":306},"Because you already know that the IOCs for a novel browser-based attack are likely outdated the moment you block them. And in the case of a ",[],{},{"nodeType":308,"data":309,"content":311},"hyperlink",{"uri":310},"https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/",[312],{"nodeType":268,"value":313,"marks":314,"data":317},"new technique observed by Microsoft",[315],{"type":316},"underline",{},{"nodeType":268,"value":319,"marks":320,"data":321}," earlier this year, you’d be right.",[],{},{"nodeType":264,"data":323,"content":324},{},[325],{"nodeType":268,"value":326,"marks":327,"data":328},"In March, Push’s AI agents took a close look at that Microsoft intel, which details a discovered campaign built around a novel OAuth redirect abuse technique used to deliver users to phishing pages under the cover of trusted services’ OAuth flows. ",[],{},{"nodeType":264,"data":330,"content":331},{},[332],{"nodeType":268,"value":333,"marks":334,"data":335},"What we found was indicative of how these attacks rapidly evolve: No matches for the published IOCs across our install base. But a few months later, we got a true positive. Except it was for new lures, new variants, and different IOCs. What hadn’t changed was the underlying attack delivery technique, and that’s what we used to detect a new campaign on Push customer estates.",[],{},{"nodeType":264,"data":337,"content":338},{},[339],{"nodeType":268,"value":340,"marks":341,"data":342},"In this article, we’ll walk through this example as a case study of how agentic threat hunting helps us go beyond IOCs to extract durable behavioral indicators that close the gap between “We’re aware of this threat” and “We’re covered.”",[],{},{"nodeType":344,"data":345,"content":351},"embedded-entry-block",{"target":346},{"sys":347},{"id":348,"type":349,"linkType":350},"6X7yXNdchH1Qp2tNKRAyVP","Link","Entry",[],{"nodeType":353,"data":354,"content":355},"hr",{},[],{"nodeType":357,"data":358,"content":359},"heading-1",{},[360],{"nodeType":268,"value":361,"marks":362,"data":363},"The intel: Novel abuse of OAuth redirects as a phishing delivery mechanism",[],{},{"nodeType":264,"data":365,"content":366},{},[367,371,379],{"nodeType":268,"value":368,"marks":369,"data":370},"The technique ",[],{},{"nodeType":308,"data":372,"content":373},{"uri":310},[374],{"nodeType":268,"value":375,"marks":376,"data":378},"Microsoft documented",[377],{"type":316},{},{"nodeType":268,"value":380,"marks":381,"data":382}," back in March is an interesting one. It doesn't steal tokens or abuse consent flows. Instead, it weaponizes the OAuth error-handling path itself — turning trusted identity provider domains into a delivery mechanism for phishing and malware.",[],{},{"nodeType":344,"data":384,"content":388},{"target":385},{"sys":386},{"id":387,"type":349,"linkType":350},"486pfUpMxx15vJupxuiePn",[],{"nodeType":264,"data":390,"content":391},{},[392,396,402],{"nodeType":268,"value":393,"marks":394,"data":395},"Here's how it works. The attacker registers a malicious application in an actor-controlled tenant, pointing its redirect URI at attacker infrastructure. They craft an authorization URL using ",[],{},{"nodeType":268,"value":397,"marks":398,"data":401},"prompt=none",[399],{"type":400},"bold",{},{"nodeType":268,"value":403,"marks":404,"data":405}," (forcing silent authentication) and an intentionally invalid scope, which guarantees an OAuth error. ",[],{},{"nodeType":264,"data":407,"content":408},{},[409,413,418],{"nodeType":268,"value":410,"marks":411,"data":412},"The identity provider — Microsoft Entra ID, Google Workspace, or any OAuth-compliant service — handles that error the way the spec says it should: By redirecting the browser to the application's registered redirect URI. The user clicks a link that begins at ",[],{},{"nodeType":268,"value":414,"marks":415,"data":417},"login.microsoftonline.com",[416],{"type":400},{},{"nodeType":268,"value":419,"marks":420,"data":421},", passes through a legitimate authentication endpoint, and lands on an attacker-controlled page.",[],{},{"nodeType":264,"data":423,"content":424},{},[425,429,435],{"nodeType":268,"value":426,"marks":427,"data":428},"Importantly, no token is stolen during the redirect. The OAuth flow is the delivery vehicle, not the compromise mechanism. What happens ",[],{},{"nodeType":268,"value":430,"marks":431,"data":434},"after",[432],{"type":433},"italic",{},{"nodeType":268,"value":436,"marks":437,"data":438}," the redirect — phishing, malware download, credential harvesting — is where the actual attack occurs.",[],{},{"nodeType":264,"data":440,"content":441},{},[442,446,451],{"nodeType":268,"value":443,"marks":444,"data":445},"This technique is also successful because conventional URL filtering sees a legitimate authentication domain, not a phishing destination. The redirect is standards-compliant behavior, and the initial URL carries the domain reputation of a trusted identity provider — which means the usual defenses at the network layer don't fire. (No TI or domain-based detection service in the world would raise a ",[],{},{"nodeType":268,"value":447,"marks":448,"data":450},"microsoft.com",[449],{"type":400},{},{"nodeType":268,"value":452,"marks":453,"data":454}," domain as suspicious!)",[],{},{"nodeType":264,"data":456,"content":457},{},[458],{"nodeType":268,"value":459,"marks":460,"data":461},"With this intel, Push’s agents now had some useful fodder to hunt for.",[],{},{"nodeType":357,"data":463,"content":464},{},[465],{"nodeType":268,"value":466,"marks":467,"data":468},"Hunting from intel: How we developed a behavioral detection",[],{},{"nodeType":264,"data":470,"content":471},{},[472],{"nodeType":268,"value":473,"marks":474,"data":475},"It started with ingestion. When the Microsoft blog was published, Push's TI aggregation agent flagged it as relevant to our detection surface — the technique abuses OAuth redirect behavior observable in the browser, which maps directly to the metadata that Push's browser agent captures.",[],{},{"nodeType":344,"data":477,"content":481},{"target":478},{"sys":479},{"id":480,"type":349,"linkType":350},"26saWWXsyFAZrsrfspGwaF",[],{"nodeType":264,"data":483,"content":484},{},[485],{"nodeType":268,"value":486,"marks":487,"data":488},"The Push intel agent understands not to hunt for IOCs, but rather to think in terms of durable behaviors. It understands the telemetry available to the Push browser extension, and then compares that to the telemetry it would expect to be able to extract for a given technique, before deciding what to hunt for.",[],{},{"nodeType":264,"data":490,"content":491},{},[492],{"nodeType":268,"value":493,"marks":494,"data":495},"In this case, the intel agent extracted two distinct behavioral elements from the research to look for: the OAuth redirect technique and the page users land on after the error.",[],{},{"nodeType":264,"data":497,"content":498},{},[499],{"nodeType":268,"value":500,"marks":501,"data":502},"That extraction step is where surface-level details can become technique-driven hunts. Microsoft's article listed specific client IDs, redirect URLs, and PowerShell command patterns — indicators that are useful for retrospective hunting but will rotate as the campaign evolves. ",[],{},{"nodeType":264,"data":504,"content":505},{},[506],{"nodeType":268,"value":507,"marks":508,"data":509},"The pipeline's job was to identify what wouldn't change: The behavioral mechanics of abusing the OAuth error redirect path as a delivery mechanism, independent of which domains, client IDs, or post-redirect payloads the attacker chose to use. This is the Pyramid of Pain principle in practice: Hunt for the technique, not the indicator, because techniques are genuinely hard for attackers to change.",[],{},{"nodeType":344,"data":511,"content":515},{"target":512},{"sys":513},{"id":514,"type":349,"linkType":350},"7qUVlKVjHMkabu0MJ1S7gC",[],{"nodeType":264,"data":517,"content":518},{},[519,523,532],{"nodeType":268,"value":520,"marks":521,"data":522},"Next, the agents verified what they already knew from Push’s internal TTP knowledge base. In this case, the agents understood the well-known technique of ",[],{},{"nodeType":308,"data":524,"content":526},{"uri":525},"https://owasp.org/www-community/attacks/open_redirect",[527],{"nodeType":268,"value":528,"marks":529,"data":531},"open redirects",[530],{"type":316},{},{"nodeType":268,"value":533,"marks":534,"data":535},", where attackers leverage redirects to deliver users to a malicious page. The example originally published by Microsoft was a novel variation of that — abusing a trusted service and the open redirect technique via a legitimate OAuth error workflow to deliver a multi-stage phishing attack.",[],{},{"nodeType":264,"data":537,"content":538},{},[539,543,547],{"nodeType":268,"value":540,"marks":541,"data":542},"AI models’ deep knowledge of web programming and frameworks is a particular strength here, because they understand which OAuth redirect behavior is normal and common across diverse scenarios, and can pinpoint which elements will be the strongest signal to hunt for malicious behavior. The agents immediately recognized that hunting for ",[],{},{"nodeType":268,"value":397,"marks":544,"data":546},[545],{"type":400},{},{"nodeType":268,"value":548,"marks":549,"data":550}," would be too noisy, as legitimate apps regularly use silent token refresh.",[],{},{"nodeType":264,"data":552,"content":553},{},[554],{"nodeType":268,"value":555,"marks":556,"data":557},"In this case, the approach was simply to find all the instances where a user hit an OAuth error page, and then landed on a login page afterward. Normal behavior for error states would be to return an error response — not send the user on to a page with a password form field or a CAPTCHA. That’s highly suspicious.",[],{},{"nodeType":264,"data":559,"content":560},{},[561],{"nodeType":268,"value":562,"marks":563,"data":564},"The agents then built behavioral queries targeting both behavioral attributes of the attack, and validated them across Push's install base. ",[],{},{"nodeType":264,"data":566,"content":567},{},[568],{"nodeType":268,"value":569,"marks":570,"data":571},"When agents first looked in March, the hunts returned no true positives — the specific campaign Microsoft documented wasn’t active against Push customers at that time.",[],{},{"nodeType":264,"data":573,"content":574},{},[575],{"nodeType":268,"value":576,"marks":577,"data":578},"But the query logic was sound — precise enough to avoid false positives, broad enough to catch technique variants without relying on the specific IOCs that Microsoft documented. So the pipeline promoted it to a live query — a continuing detection that would surface any future instances of the technique across the customer base.",[],{},{"nodeType":357,"data":580,"content":581},{},[582],{"nodeType":268,"value":583,"marks":584,"data":585},"The hunt pays off: A new variant, completely different IOCs",[],{},{"nodeType":264,"data":587,"content":588},{},[589],{"nodeType":268,"value":590,"marks":591,"data":592},"In June, the query fired. A single user at a single customer had been targeted, but with a completely different scenario. ",[],{},{"nodeType":344,"data":594,"content":598},{"target":595},{"sys":596},{"id":597,"type":349,"linkType":350},"7uXgOzxemy1PaJLhUa1txV",[],{"nodeType":264,"data":600,"content":601},{},[602],{"nodeType":268,"value":603,"marks":604,"data":605},"Where the Microsoft-documented example used lures presented as document-sharing links, Teams meeting recordings, or password resets, and the abused trusted service was a Microsoft login link used to trigger the OAuth error, the Push-observed attack chain used different elements. However, the behavioral technique at the core was the same.",[],{},{"nodeType":264,"data":607,"content":608},{},[609],{"nodeType":268,"value":610,"marks":611,"data":612},"In this case, the user clicked a link in a service desk ticket, triggering an OAuth flow that used a redirect URL with parameters designed to make it look like a Grammarly link. After hitting the OAuth error, the user was redirected to a page with a CAPTCHA, and then redirected again to a second page behind a Cloudflare Turnstile that was running a phish kit. While examining the phishing page, Push’s agents found a net-new phish kit that they later added additional detections for. ",[],{},{"nodeType":264,"data":614,"content":615},{},[616],{"nodeType":268,"value":617,"marks":618,"data":619},"Roughly a day after the Push detection fired, Google Safe Browsing flagged both domains as phishing domains. But when the user was first targeted, neither domain had been flagged. In this case, the user exited the redirect flow before entering any credentials.",[],{},{"nodeType":264,"data":621,"content":622},{},[623],{"nodeType":268,"value":624,"marks":625,"data":626},"It’s important to note that this phishing technique also bypasses other controls based on network content pattern analysis or domain-based detections. For example, a network proxy is designed to look for malicious webpages based on known-bad IOCs like domains or page content that contains known-bad script files. This technique uses a dynamic obfuscated Javascript blob that unpacks and loads the webpage on the client side after checking to see if it’s running in a live browser environment, evading proxy-based analysis.",[],{},{"nodeType":264,"data":628,"content":629},{},[630],{"nodeType":268,"value":631,"marks":632,"data":633},"The query now serves as another early-warning flag designed to be broad enough to catch other interesting new variants of this TTP.",[],{},{"nodeType":357,"data":635,"content":636},{},[637],{"nodeType":268,"value":638,"marks":639,"data":640},"Why technique-level detection pays dividends",[],{},{"nodeType":264,"data":642,"content":643},{},[644],{"nodeType":268,"value":645,"marks":646,"data":647},"This example demonstrates the value of behavioral detection. By focusing on technique extraction, we can stay a step ahead of attack evolution, identifying other contexts and campaigns that use the same behavioral technique, without relying on stale IOCs.",[],{},{"nodeType":264,"data":649,"content":650},{},[651],{"nodeType":268,"value":652,"marks":653,"data":654},"For customers, this means no one has to distil the threat intel report into behavioral elements, spend time crafting detections, or work to eliminate false positives. The Push agents do all that automatically, delivering a compounding benefit the more they learn. ",[],{},{"nodeType":264,"data":656,"content":657},{},[658],{"nodeType":268,"value":659,"marks":660,"data":661},"Customers get a fully operationalized threat-hunting and detection engineering capability; and the Push knowledge base itself expands with each new hunt, getting better at identifying emerging threats.",[],{},{"nodeType":264,"data":663,"content":664},{},[665,669,678],{"nodeType":268,"value":666,"marks":667,"data":668},"If you'd like to see how Push's detection pipeline would work in your environment, ",[],{},{"nodeType":308,"data":670,"content":672},{"uri":671},"https://pushsecurity.com/demo",[673],{"nodeType":268,"value":674,"marks":675,"data":677},"book a demo",[676],{"type":316},{},{"nodeType":268,"value":679,"marks":680,"data":681}," with our team.",[],{},{"entries":683},{"hyperlink":684,"inline":685,"block":686},[],[],[687,714,722,729,736],{"sys":688,"__typename":689,"content":690,"name":713,"title":62},{"id":348},"InsightTextBlockComponent",{"json":691},{"data":692,"content":693,"nodeType":260},{},[694],{"data":695,"content":696,"nodeType":264},{},[697,701,709],{"data":698,"marks":699,"value":700,"nodeType":268},{},[],"Note: This is part 2 of a series. ",{"data":702,"content":704,"nodeType":308},{"uri":703},"https://pushsecurity.com/blog/agentic-threat-hunting-benefits-for-customers",[705],{"data":706,"marks":707,"value":708,"nodeType":268},{},[],"Part 1",{"data":710,"marks":711,"value":712,"nodeType":268},{},[]," covers the pipeline’s detection engineering principles and the security outcomes we’re achieving for Push customers.","Agentic case study IB1",{"sys":715,"__typename":716,"title":717,"caption":717,"layoutMode":62,"file":718},{"id":387},"Image","The original attack chain documented in March by Microsoft.",{"url":719,"width":720,"height":721},"https://images.ctfassets.net/y1cdw1ablpvd/1D3TRRoXR4Kyso7bX2ogiC/4e17fd2c068195e9959da9b633ab5f48/microsoft-attack-chain.png",3224,2020,{"sys":723,"__typename":716,"title":724,"caption":724,"layoutMode":62,"file":725},{"id":480},"Push’s intel agent reasoning over some ingested TI on a novel OAuth redirect abuse technique.",{"url":726,"width":727,"height":728},"https://images.ctfassets.net/y1cdw1ablpvd/46ArhTRN2xiFHemmFIo1Y/3976a9c6877f08810f2eea37d306de4e/image4.png",1999,820,{"sys":730,"__typename":716,"title":731,"caption":731,"layoutMode":62,"file":732},{"id":514},"Push agents summarizing the behavioral techniques of the attack and proposing hunt queries.",{"url":733,"width":734,"height":735},"https://images.ctfassets.net/y1cdw1ablpvd/1knJksvSVjMoGKHyAMIN22/5727ee7ce06ddb300355eec119bab885/image3.png",1900,1466,{"sys":737,"__typename":716,"title":738,"caption":738,"layoutMode":62,"file":739},{"id":597},"Push observed the same technique with completely different IOCs a few months after first hunting for it based on Microsoft’s documented campaign example.",{"url":740,"width":741,"height":742},"https://images.ctfassets.net/y1cdw1ablpvd/4zGCbPJbfFXhSJMAPrssTX/10759adf3d14f823209329b0c84fdea7/oauth-redirect-technique-v2.png",3400,1860,"json",{"items":745},[],{},"How Push turns IOC-based intel into browser TTPs for hunting","2026-07-31T00:00:00.000Z",{"items":750},[751,1701,2517],{"__typename":752,"sys":753,"content":755,"title":1683,"synopsis":1684,"hashTags":62,"publishedDate":1685,"slug":1686,"tagsCollection":1687,"authorsCollection":1697},"BlogPosts",{"id":754},"6dJUsirH3rrhy1Stnzkfqk",{"json":756},{"nodeType":260,"data":757,"content":758},{},[759,772,788,842,849,862,882,889,895,898,905,912,941,948,955,1023,1030,1036,1043,1050,1053,1060,1067,1100,1120,1132,1138,1145,1151,1163,1170,1190,1196,1208,1220,1227,1233,1245,1261,1273,1285,1291,1298,1301,1308,1315,1331,1339,1346,1354,1361,1407,1410,1417,1424,1430,1438,1445,1461,1476,1483,1499,1506,1554,1561,1577,1584,1634,1641,1649,1652,1659,1666],{"nodeType":264,"data":760,"content":761},{},[762,766],{"nodeType":268,"value":763,"marks":764,"data":765},"Hey all you security engineers, let’s play ",[],{},{"nodeType":268,"value":767,"marks":768,"data":771},"Would You Rather … ?",[769,770],{"type":433},{"type":400},{},{"nodeType":264,"data":773,"content":774},{},[775,779,784],{"nodeType":268,"value":776,"marks":777,"data":778},"Would you rather spend time trying to write detections for ",[],{},{"nodeType":268,"value":780,"marks":781,"data":783},"modern browser-based attacks",[782],{"type":400},{},{"nodeType":268,"value":785,"marks":786,"data":787}," by …",[],{},{"nodeType":789,"data":790,"content":791},"unordered-list",{},[792,808,827],{"nodeType":793,"data":794,"content":795},"list-item",{},[796],{"nodeType":264,"data":797,"content":798},{},[799,803],{"nodeType":268,"value":800,"marks":801,"data":802},"Combing through MITRE looking for techniques that you can write detections on, only to find you have",[],{},{"nodeType":268,"value":804,"marks":805,"data":807}," little useful telemetry from your typical sources.",[806],{"type":400},{},{"nodeType":793,"data":809,"content":810},{},[811],{"nodeType":264,"data":812,"content":813},{},[814,818,823],{"nodeType":268,"value":815,"marks":816,"data":817},"Curating a list of malicious domain IOCs extracted from endless TI pieces, only to ",[],{},{"nodeType":268,"value":819,"marks":820,"data":822},"never see a single one of them match",[821],{"type":400},{},{"nodeType":268,"value":824,"marks":825,"data":826},".",[],{},{"nodeType":793,"data":828,"content":829},{},[830],{"nodeType":264,"data":831,"content":832},{},[833,838],{"nodeType":268,"value":834,"marks":835,"data":837},"Just giving up and blocking a bunch of domains or IPs",[836],{"type":400},{},{"nodeType":268,"value":839,"marks":840,"data":841}," from every TI feed you come across, while quietly weeping.",[],{},{"nodeType":264,"data":843,"content":844},{},[845],{"nodeType":268,"value":846,"marks":847,"data":848},"Or … ",[],{},{"nodeType":789,"data":850,"content":851},{},[852],{"nodeType":793,"data":853,"content":854},{},[855],{"nodeType":264,"data":856,"content":857},{},[858],{"nodeType":268,"value":859,"marks":860,"data":861},"Inherit constantly evolving detections validated across 3 million-plus browsers, tuned to remove false positives, informed by human threat researchers, and tailored to the known and not-yet-known threats that target account compromise and malware delivery via the browser.",[],{},{"nodeType":264,"data":863,"content":864},{},[865,869,878],{"nodeType":268,"value":866,"marks":867,"data":868},"At Push, we’ve built an ",[],{},{"nodeType":308,"data":870,"content":872},{"uri":871},"https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",[873],{"nodeType":268,"value":874,"marks":875,"data":877},"agentic threat hunting and detection engineering pipeline",[876],{"type":316},{},{"nodeType":268,"value":879,"marks":880,"data":881}," to take that first set of onerous tasks off your plate. The result is a process that looks a lot like the ideal described in detection engineering maturity models, achieved without any extra headcount or subject matter expertise on your team, and scaled to meet the speed and complexity of our current era of AI-enabled adversaries.",[],{},{"nodeType":264,"data":883,"content":884},{},[885],{"nodeType":268,"value":886,"marks":887,"data":888},"Let’s take a look at how the pipeline delivers a collective good by identifying emerging threats or new technique variants in a single customer environment and then delivering detections to everyone.",[],{},{"nodeType":344,"data":890,"content":894},{"target":891},{"sys":892},{"id":893,"type":349,"linkType":350},"sN6q7oEwYyJTkXxyLb81m",[],{"nodeType":353,"data":896,"content":897},{},[],{"nodeType":357,"data":899,"content":900},{},[901],{"nodeType":268,"value":902,"marks":903,"data":904},"Why detection engineering from TI is hard — and why AI-enabled attacks are making it even harder",[],{},{"nodeType":264,"data":906,"content":907},{},[908],{"nodeType":268,"value":909,"marks":910,"data":911},"Detection engineers feel the pain that Beethoven must have felt when he got the critique: “There are just too many notes!”",[],{},{"nodeType":264,"data":913,"content":914},{},[915,919,924,928,937],{"nodeType":268,"value":916,"marks":917,"data":918},"Except where notes = threat intelligence, light on the ",[],{},{"nodeType":268,"value":920,"marks":921,"data":923},"intelligence",[922],{"type":433},{},{"nodeType":268,"value":925,"marks":926,"data":927},". (For a great unpacking of what’s hard about transforming TI into detections, check out this ",[],{},{"nodeType":308,"data":929,"content":931},{"uri":930},"https://medium.com/anton-on-security/detection-engineering-is-painful-and-it-shouldnt-be-part-1-3641d8740458",[932],{"nodeType":268,"value":933,"marks":934,"data":936},"blog series",[935],{"type":316},{},{"nodeType":268,"value":938,"marks":939,"data":940}," from Anton Chuvakin and his Google security colleagues from 2023. The challenge has only gotten harder since then!)",[],{},{"nodeType":264,"data":942,"content":943},{},[944],{"nodeType":268,"value":945,"marks":946,"data":947},"In short, there is too much potential TI, too little actionable detail, and a dearth of useful business-relevant context.",[],{},{"nodeType":264,"data":949,"content":950},{},[951],{"nodeType":268,"value":952,"marks":953,"data":954},"This often manifests as:",[],{},{"nodeType":789,"data":956,"content":957},{},[958,986,1005],{"nodeType":793,"data":959,"content":960},{},[961],{"nodeType":264,"data":962,"content":963},{},[964,969,973,982],{"nodeType":268,"value":965,"marks":966,"data":968},"Feeling constantly behind the threat landscape. ",[967],{"type":400},{},{"nodeType":268,"value":970,"marks":971,"data":972},"SANS Institute’s ",[],{},{"nodeType":308,"data":974,"content":976},{"uri":975},"https://www.sans.org/white-papers/state-detection-engineering-2026",[977],{"nodeType":268,"value":978,"marks":979,"data":981},"State of Detection Engineering 2026",[980],{"type":316},{},{"nodeType":268,"value":983,"marks":984,"data":985}," report found that only 18% of practitioners feel like they’re staying ahead; 56% report barely keeping pace.",[],{},{"nodeType":793,"data":987,"content":988},{},[989],{"nodeType":264,"data":990,"content":991},{},[992,996,1001],{"nodeType":268,"value":993,"marks":994,"data":995},"Access to a huge amount of potential TI, but ",[],{},{"nodeType":268,"value":997,"marks":998,"data":1000},"lacking the time, context, and tools needed to parse the data",[999],{"type":400},{},{"nodeType":268,"value":1002,"marks":1003,"data":1004}," for threats that matter to the business.",[],{},{"nodeType":793,"data":1006,"content":1007},{},[1008],{"nodeType":264,"data":1009,"content":1010},{},[1011,1015,1020],{"nodeType":268,"value":1012,"marks":1013,"data":1014},"More information on IOCs than TTPs, leading to ",[],{},{"nodeType":268,"value":1016,"marks":1017,"data":1019},"ever-growing blocklists and attacks that still slip through",[1018],{"type":400},{},{"nodeType":268,"value":824,"marks":1021,"data":1022},[],{},{"nodeType":264,"data":1024,"content":1025},{},[1026],{"nodeType":268,"value":1027,"marks":1028,"data":1029},"As AI-enabled adversaries continue to make it increasingly trivial to rotate infrastructure or abuse trusted services and workflows to deliver modern attacks, the hill gets steeper. ",[],{},{"nodeType":344,"data":1031,"content":1035},{"target":1032},{"sys":1033},{"id":1034,"type":349,"linkType":350},"4xlCsISP3OT9MAj3wxw67D",[],{"nodeType":264,"data":1037,"content":1038},{},[1039],{"nodeType":268,"value":1040,"marks":1041,"data":1042},"In the case of attacks that target employees via the browser — using advanced phishing methods, commercial toolkits, abuse of OAuth, abuse of trusted services to deliver phishing lures, etc. — most security teams are also working without the right foundational visibility to even begin to mature their detection process against these TTPs.",[],{},{"nodeType":264,"data":1044,"content":1045},{},[1046],{"nodeType":268,"value":1047,"marks":1048,"data":1049},"The missing input is visibility at the layer where these attacks actually execute — the browser session. Without it, detection engineering for browser-based threats is painful guesswork.",[],{},{"nodeType":353,"data":1051,"content":1052},{},[],{"nodeType":357,"data":1054,"content":1055},{},[1056],{"nodeType":268,"value":1057,"marks":1058,"data":1059},"How Push operationalized best practices for hunting from TI using agents",[],{},{"nodeType":264,"data":1061,"content":1062},{},[1063],{"nodeType":268,"value":1064,"marks":1065,"data":1066},"In building our agentic threat hunting and detection engineering pipeline at Push, we set out to solve many of the same problems that any security team faces when maturing its processes:",[],{},{"nodeType":789,"data":1068,"content":1069},{},[1070,1080,1090],{"nodeType":793,"data":1071,"content":1072},{},[1073],{"nodeType":264,"data":1074,"content":1075},{},[1076],{"nodeType":268,"value":1077,"marks":1078,"data":1079},"How to transform TI into technique-level intel we could write durable detections for across a wide customer base at scale?",[],{},{"nodeType":793,"data":1081,"content":1082},{},[1083],{"nodeType":264,"data":1084,"content":1085},{},[1086],{"nodeType":268,"value":1087,"marks":1088,"data":1089},"How to create structured internal knowledge to add context to our detection engineering process that validates the relevance of what we find?",[],{},{"nodeType":793,"data":1091,"content":1092},{},[1093],{"nodeType":264,"data":1094,"content":1095},{},[1096],{"nodeType":268,"value":1097,"marks":1098,"data":1099},"How to verify what’s worthwhile to hunt for, remove false positives, and understand the value of a detection for a specific TTP across an install base of more than 3 million browsers?",[],{},{"nodeType":264,"data":1101,"content":1102},{},[1103,1107,1116],{"nodeType":268,"value":1104,"marks":1105,"data":1106},"The process we created looks a lot like the ",[],{},{"nodeType":308,"data":1108,"content":1110},{"uri":1109},"https://medium.com/anton-on-security/blueprint-for-threat-intel-to-detection-flow-part-7-088024be08dd",[1111],{"nodeType":268,"value":1112,"marks":1113,"data":1115},"best practices",[1114],{"type":316},{},{"nodeType":268,"value":1117,"marks":1118,"data":1119}," on how to turn intelligence into meaningful detections. The difference is that agents let us run this process continuously and at a scale that would be impossible to achieve with human analysts alone.",[],{},{"nodeType":264,"data":1121,"content":1122},{},[1123,1128],{"nodeType":268,"value":1124,"marks":1125,"data":1127},"It starts with ingestion. ",[1126],{"type":400},{},{"nodeType":268,"value":1129,"marks":1130,"data":1131},"An agent tasked with TI aggregation monitors multiple industry sources — vendor reports, researcher disclosures, campaign teardowns — and filters for intelligence relevant to browser-based attack techniques. ",[],{},{"nodeType":344,"data":1133,"content":1137},{"target":1134},{"sys":1135},{"id":1136,"type":349,"linkType":350},"7fsLEGUbOINll70ViNVVkI",[],{"nodeType":264,"data":1139,"content":1140},{},[1141],{"nodeType":268,"value":1142,"marks":1143,"data":1144},"Because this agent already understands the types of attacks and scenarios that matter to Push’s detection surface, it can distinguish signal from noise at the intake stage, flagging useful intel and proposing initial lightweight hunts based on the browser metadata Push can observe. When a potential hunt looks promising, the aggregation agent hands off to a deeper analysis agent to extract what’s actually huntable.",[],{},{"nodeType":344,"data":1146,"content":1150},{"target":1147},{"sys":1148},{"id":1149,"type":349,"linkType":350},"5vyeALIziHamJ0cLiGMdGk",[],{"nodeType":264,"data":1152,"content":1153},{},[1154,1159],{"nodeType":268,"value":1155,"marks":1156,"data":1158},"That extraction step is where a general TI feed becomes something you can build detections from. ",[1157],{"type":400},{},{"nodeType":268,"value":1160,"marks":1161,"data":1162},"Agents built on frontier models have a deep understanding of web programming languages and browser workflows can decompose the intelligence into its meaningful atomic units — the specific behavioral patterns that distinguish a malicious technique from normal browser activity. ",[],{},{"nodeType":264,"data":1164,"content":1165},{},[1166],{"nodeType":268,"value":1167,"marks":1168,"data":1169},"They compare those patterns against everything the Push browser agent can observe: tabs, windows, navigation events, downloads, network requests, DOM content, script execution. Then they discard anything too broad — observable events that are commonplace, even when connected to a malicious TTP — to avoid false positives. ",[],{},{"nodeType":264,"data":1171,"content":1172},{},[1173,1177,1186],{"nodeType":268,"value":1174,"marks":1175,"data":1176},"What survives is one or more huntable technique signatures that can be identified with a high true positive rate. This is the ",[],{},{"nodeType":308,"data":1178,"content":1180},{"uri":1179},"https://pushsecurity.com/blog/the-pyramid-of-pain-in-the-ai-era",[1181],{"nodeType":268,"value":1182,"marks":1183,"data":1185},"Pyramid of Pain principle",[1184],{"type":316},{},{"nodeType":268,"value":1187,"marks":1188,"data":1189}," operationalized at machine speed: Target the technique, not the indicator, because techniques are genuinely hard for attackers to change.",[],{},{"nodeType":344,"data":1191,"content":1195},{"target":1192},{"sys":1193},{"id":1194,"type":349,"linkType":350},"5j0mvdIMkaUwDgCu0nOqSm",[],{"nodeType":264,"data":1197,"content":1198},{},[1199,1204],{"nodeType":268,"value":1200,"marks":1201,"data":1203},"In parallel, the pipeline validates whether the identified technique is genuinely novel or a variant of something Push already detects. ",[1202],{"type":400},{},{"nodeType":268,"value":1205,"marks":1206,"data":1207},"This is where our internal knowledge base comes into play. Built over three years by Push’s in-house research team and augmented continuously by the pipeline itself, it represents what Push knows about browser-based attack behaviors — a structured corpus of TTPs that lets agents classify incoming intelligence as new territory, a known variant that needs a refined detection, or something already covered. That classification determines what happens next: A net-new technique triggers a full hunt; a known variant triggers a refinement cycle; and a duplicate gets deprioritized.",[],{},{"nodeType":264,"data":1209,"content":1210},{},[1211,1216],{"nodeType":268,"value":1212,"marks":1213,"data":1215},"The hunt itself is where hypothesis meets evidence.",[1214],{"type":400},{},{"nodeType":268,"value":1217,"marks":1218,"data":1219}," Agents develop a specific, testable prediction about what the technique looks like in browser telemetry, then validate that prediction across Push’s install base. The aim of the initial hunt is to identify any potential false positives — legitimate browser behavior that matches the pattern. Then the agents refine: adjusting the query, narrowing the behavioral fingerprints, testing again. Each iteration sharpens the detection until the false positive rate drops to a negligible, tolerable level. ",[],{},{"nodeType":264,"data":1221,"content":1222},{},[1223],{"nodeType":268,"value":1224,"marks":1225,"data":1226},"The hunts that produce relevant, high-confidence results become continuous queries — a kind of early warning system for emerging threats we’re actively watching for and learning about. The most useful and reliable of those queries become production detections that protect every Push customer in real time. ",[],{},{"nodeType":344,"data":1228,"content":1232},{"target":1229},{"sys":1230},{"id":1231,"type":349,"linkType":350},"h3MN5kaaGGuL4uvNsP9JZ",[],{"nodeType":264,"data":1234,"content":1235},{},[1236,1241],{"nodeType":268,"value":1237,"marks":1238,"data":1240},"This is what “detect what matters” looks like as an engineering discipline. ",[1239],{"type":400},{},{"nodeType":268,"value":1242,"marks":1243,"data":1244},"By the time the agents have whittled down millions or trillions of browser events into a good hunt query — where good means broad enough to cast a usefully wide net for variations — and then tuned that further into a high-fidelity detection, the result is fewer, sharper detections by design. And because Push detects at the browser session layer before a user can interact with a malicious page, almost all of those detections fire pre-compromise. ",[],{},{"nodeType":264,"data":1246,"content":1247},{},[1248,1252,1257],{"nodeType":268,"value":1249,"marks":1250,"data":1251},"The same 2026 SANS survey mentioned earlier found that ",[],{},{"nodeType":268,"value":1253,"marks":1254,"data":1256},"66% of SOC practitioners cite vendor-provided rules as their primary source of false positives",[1255],{"type":400},{},{"nodeType":268,"value":1258,"marks":1259,"data":1260}," — a structural problem that persists at every organization size. Push’s pipeline produces the opposite outcome: better detections, less noise.",[],{},{"nodeType":264,"data":1262,"content":1263},{},[1264,1269],{"nodeType":268,"value":1265,"marks":1266,"data":1268},"The result is a system with two learning loops.",[1267],{"type":400},{},{"nodeType":268,"value":1270,"marks":1271,"data":1272}," An inner loop handles real-time detection and response for known attacker techniques — the production detections already deployed across the customer base. An outer loop handles continuous discovery — agents hunting for new techniques, refining existing detections, and ingesting external intelligence. ",[],{},{"nodeType":264,"data":1274,"content":1275},{},[1276,1281],{"nodeType":268,"value":1277,"marks":1278,"data":1280},"Each loop feeds the other:",[1279],{"type":400},{},{"nodeType":268,"value":1282,"marks":1283,"data":1284}," The outer loop’s discoveries become the inner loop’s new production detections, and the inner loop’s blocked attacks become raw material for the outer loop to analyze for novel variants. The knowledge base that both loops draw on grows with every cycle, which means the pipeline's detection coverage compounds at roughly the rate the threat landscape grows more complex.",[],{},{"nodeType":344,"data":1286,"content":1290},{"target":1287},{"sys":1288},{"id":1289,"type":349,"linkType":350},"3xVLn9Ldk4cOP4uFYIYyM",[],{"nodeType":264,"data":1292,"content":1293},{},[1294],{"nodeType":268,"value":1295,"marks":1296,"data":1297},"And every validated detection produced by this process, whether it originated from a blocked attack in one customer’s environment, a proactive hunt across the telemetry corpus, or a vendor report about a campaign Push has never observed on customer estates, deploys to the entire customer base.",[],{},{"nodeType":353,"data":1299,"content":1300},{},[],{"nodeType":357,"data":1302,"content":1303},{},[1304],{"nodeType":268,"value":1305,"marks":1306,"data":1307},"Herd immunity, without all the breaches to get there",[],{},{"nodeType":264,"data":1309,"content":1310},{},[1311],{"nodeType":268,"value":1312,"marks":1313,"data":1314},"That last point is where Push’s idea of herd immunity diverges from the traditional definition.",[],{},{"nodeType":264,"data":1316,"content":1317},{},[1318,1322,1327],{"nodeType":268,"value":1319,"marks":1320,"data":1321},"Detection and response platforms and MDR services commonly describe a ",[],{},{"nodeType":268,"value":1323,"marks":1324,"data":1326},"herd immunity benefit",[1325],{"type":400},{},{"nodeType":268,"value":1328,"marks":1329,"data":1330},": What one customer encounters, every customer gets protection against. The mechanism is real, but the learning input is typically a breach or a compromise. Someone has to be the first victim.",[],{},{"nodeType":264,"data":1332,"content":1333},{},[1334],{"nodeType":268,"value":1335,"marks":1336,"data":1338},"Push’s approach is different. ",[1337],{"type":400},{},{"nodeType":264,"data":1340,"content":1341},{},[1342],{"nodeType":268,"value":1343,"marks":1344,"data":1345},"Modern browser-based attacks frequently rely on a series of techniques strung together to achieve a compromise. From its vantage point in the browser, Push catches many novel techniques with existing detections pre-compromise because it recognizes a portion of the attack techniques in the chain. The detection process then identifies what’s new about a previously unseen variation of a known TTP — perhaps an evasion technique the kit hadn’t used before, an unusual lure or infrastructure pattern, etc. ",[],{},{"nodeType":264,"data":1347,"content":1348},{},[1349],{"nodeType":268,"value":1350,"marks":1351,"data":1353},"The detection gets better for customers and no one was compromised to get there.",[1352],{"type":400},{},{"nodeType":264,"data":1355,"content":1356},{},[1357],{"nodeType":268,"value":1358,"marks":1359,"data":1360},"On the external intelligence side, the pipeline ingests published research about a campaign Push has never observed, extracts the durable behavioral characteristics, validates them against browser telemetry, refines the query to tune out false positives, and ships detections before the technique is ever used against a Push customer. The protection arrives ahead of the attack.",[],{},{"nodeType":264,"data":1362,"content":1363},{},[1364,1368,1377,1381,1390,1394,1403],{"nodeType":268,"value":1365,"marks":1366,"data":1367},"These are the processes behind Push’s identification of ",[],{},{"nodeType":308,"data":1369,"content":1371},{"uri":1370},"https://pushsecurity.com/blog/consentfix",[1372],{"nodeType":268,"value":1373,"marks":1374,"data":1376},"ConsentFix",[1375],{"type":316},{},{"nodeType":268,"value":1378,"marks":1379,"data":1380},", ",[],{},{"nodeType":308,"data":1382,"content":1384},{"uri":1383},"https://pushsecurity.com/blog/installfix",[1385],{"nodeType":268,"value":1386,"marks":1387,"data":1389},"InstallFix",[1388],{"type":316},{},{"nodeType":268,"value":1391,"marks":1392,"data":1393},", and ",[],{},{"nodeType":308,"data":1395,"content":1397},{"uri":1396},"https://pushsecurity.com/blog/llmshare-malvertising-campaign",[1398],{"nodeType":268,"value":1399,"marks":1400,"data":1402},"LLMShare",[1401],{"type":316},{},{"nodeType":268,"value":1404,"marks":1405,"data":1406}," — three browser-based attack techniques Push's team discovered or documented for the first time. In several cases, detections were blocking active campaigns against Push customers before the technique had been publicly documented. Those detections rolled out to every customer within hours or days of first observation.",[],{},{"nodeType":353,"data":1408,"content":1409},{},[],{"nodeType":357,"data":1411,"content":1412},{},[1413],{"nodeType":268,"value":1414,"marks":1415,"data":1416},"Outcomes: By the numbers",[],{},{"nodeType":264,"data":1418,"content":1419},{},[1420],{"nodeType":268,"value":1421,"marks":1422,"data":1423},"Looking at the quantifiable outcomes of this agentic threat hunting capability over the last few months, the benefits for customers become clear.",[],{},{"nodeType":344,"data":1425,"content":1429},{"target":1426},{"sys":1427},{"id":1428,"type":349,"linkType":350},"7uNrNGUjjBiG9qEsfen7Xi",[],{"nodeType":1431,"data":1432,"content":1433},"heading-2",{},[1434],{"nodeType":268,"value":1435,"marks":1436,"data":1437},"Velocity",[],{},{"nodeType":264,"data":1439,"content":1440},{},[1441],{"nodeType":268,"value":1442,"marks":1443,"data":1444},"Agents allow us to massively scale our research expertise, delivering detections for emerging threats or new variants much faster than humans alone can.",[],{},{"nodeType":264,"data":1446,"content":1447},{},[1448,1452,1457],{"nodeType":268,"value":1449,"marks":1450,"data":1451},"This year already, we’ve ",[],{},{"nodeType":268,"value":1453,"marks":1454,"data":1456},"tripled",[1455],{"type":400},{},{"nodeType":268,"value":1458,"marks":1459,"data":1460}," the number of new detections shipped to customers.",[],{},{"nodeType":264,"data":1462,"content":1463},{},[1464,1468,1473],{"nodeType":268,"value":1465,"marks":1466,"data":1467},"We’ve also reduced the time it takes to ship production-ready detections for new threats from weeks to ",[],{},{"nodeType":268,"value":1469,"marks":1470,"data":1472},"minutes",[1471],{"type":400},{},{"nodeType":268,"value":824,"marks":1474,"data":1475},[],{},{"nodeType":1431,"data":1477,"content":1478},{},[1479],{"nodeType":268,"value":1480,"marks":1481,"data":1482},"Detection coverage",[],{},{"nodeType":264,"data":1484,"content":1485},{},[1486,1490,1495],{"nodeType":268,"value":1487,"marks":1488,"data":1489},"With that scaled expertise comes broad coverage. We perform an average of ",[],{},{"nodeType":268,"value":1491,"marks":1492,"data":1494},"300+ hunts",[1493],{"type":400},{},{"nodeType":268,"value":1496,"marks":1497,"data":1498}," a month (a mix of live queries for identified TTPs we’re looking for, plus net-new hunts for emerging threats we identify in any given month).",[],{},{"nodeType":264,"data":1500,"content":1501},{},[1502],{"nodeType":268,"value":1503,"marks":1504,"data":1505},"A few other metrics that demonstrate the scale of our detection coverage:",[],{},{"nodeType":789,"data":1507,"content":1508},{},[1509,1524,1539],{"nodeType":793,"data":1510,"content":1511},{},[1512],{"nodeType":264,"data":1513,"content":1514},{},[1515,1520],{"nodeType":268,"value":1516,"marks":1517,"data":1519},"75+",[1518],{"type":400},{},{"nodeType":268,"value":1521,"marks":1522,"data":1523}," attacker tools documented in our KB so far",[],{},{"nodeType":793,"data":1525,"content":1526},{},[1527],{"nodeType":264,"data":1528,"content":1529},{},[1530,1535],{"nodeType":268,"value":1531,"marks":1532,"data":1534},"25+",[1533],{"type":400},{},{"nodeType":268,"value":1536,"marks":1537,"data":1538}," variants of existing attacks we’ve identified and shipped detections for",[],{},{"nodeType":793,"data":1540,"content":1541},{},[1542],{"nodeType":264,"data":1543,"content":1544},{},[1545,1550],{"nodeType":268,"value":1546,"marks":1547,"data":1549},"10,000+",[1548],{"type":400},{},{"nodeType":268,"value":1551,"marks":1552,"data":1553}," monthly sessions analyzed",[],{},{"nodeType":1431,"data":1555,"content":1556},{},[1557],{"nodeType":268,"value":1558,"marks":1559,"data":1560},"Protection from emerging threats",[],{},{"nodeType":264,"data":1562,"content":1563},{},[1564,1568,1573],{"nodeType":268,"value":1565,"marks":1566,"data":1567},"On the emerging threat side, our team was the first to identify or document ",[],{},{"nodeType":268,"value":1569,"marks":1570,"data":1572},"three new browser-based attack techniques",[1571],{"type":400},{},{"nodeType":268,"value":1574,"marks":1575,"data":1576}," — ConsentFix, InstallFix, and LLMShare — shipping detections to all customers quickly after identification.",[],{},{"nodeType":264,"data":1578,"content":1579},{},[1580],{"nodeType":268,"value":1581,"marks":1582,"data":1583},"In that same time frame, we’ve also:",[],{},{"nodeType":789,"data":1585,"content":1586},{},[1587,1615],{"nodeType":793,"data":1588,"content":1589},{},[1590],{"nodeType":264,"data":1591,"content":1592},{},[1593,1597,1602,1606,1611],{"nodeType":268,"value":1594,"marks":1595,"data":1596},"Protected ",[],{},{"nodeType":268,"value":1598,"marks":1599,"data":1601},"60+",[1600],{"type":400},{},{"nodeType":268,"value":1603,"marks":1604,"data":1605}," ",[],{},{"nodeType":268,"value":1607,"marks":1608,"data":1610},"customers in the last 3 months",[1609],{"type":400},{},{"nodeType":268,"value":1612,"marks":1613,"data":1614}," who’ve been targeted with novel phishing techniques — identifying never-before-seen techniques, lures, delivery mechanisms, interactions, tools, or attack chains",[],{},{"nodeType":793,"data":1616,"content":1617},{},[1618],{"nodeType":264,"data":1619,"content":1620},{},[1621,1625,1630],{"nodeType":268,"value":1622,"marks":1623,"data":1624},"Prevented ",[],{},{"nodeType":268,"value":1626,"marks":1627,"data":1629},"225+",[1628],{"type":400},{},{"nodeType":268,"value":1631,"marks":1632,"data":1633}," instances of threats pre-compromise for novel techniques",[],{},{"nodeType":264,"data":1635,"content":1636},{},[1637],{"nodeType":268,"value":1638,"marks":1639,"data":1640},"In all of the above situations, Push customers didn’t have to do anything — no combing through TI to find relevant details, no writing their own detections and tuning out false positives, or spending cycles to unpack a particularly knotty attack chain that used techniques they had never seen before. ",[],{},{"nodeType":264,"data":1642,"content":1643},{},[1644],{"nodeType":268,"value":1645,"marks":1646,"data":1648},"That’s what operationalized intelligence looks like at scale, delivered as a product, not a project.",[1647],{"type":400},{},{"nodeType":353,"data":1650,"content":1651},{},[],{"nodeType":357,"data":1653,"content":1654},{},[1655],{"nodeType":268,"value":1656,"marks":1657,"data":1658},"Learn more about Push",[],{},{"nodeType":264,"data":1660,"content":1661},{},[1662],{"nodeType":268,"value":1663,"marks":1664,"data":1665},"The same foundational capabilities that enable this agentic threat hunting pipeline also deliver other security outcomes for Push customers: gaining visibility and control over AI tool usage; hardening identities by surfacing credential reuse, SSO gaps, and shadow IT; and supporting data loss and insider investigations with browser-layer telemetry that other tools can’t see.",[],{},{"nodeType":264,"data":1667,"content":1668},{},[1669,1673,1680],{"nodeType":268,"value":1670,"marks":1671,"data":1672},"If you’d like to learn more, ",[],{},{"nodeType":308,"data":1674,"content":1675},{"uri":671},[1676],{"nodeType":268,"value":674,"marks":1677,"data":1679},[1678],{"type":316},{},{"nodeType":268,"value":679,"marks":1681,"data":1682},[],{},"How Push’s agentic threat hunting in the browser benefits every customer","Security outcomes you can achieve when AI agents hunt in the browser, identify new threats, and ship detections that benefit everyone.","2026-07-23T00:00:00.000Z","agentic-threat-hunting-benefits-for-customers",{"items":1688},[1689,1693],{"sys":1690,"name":1692},{"id":1691},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"sys":1694,"name":1696},{"id":1695},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":1698},[1699],{"fullName":253,"firstName":254,"jobTitle":255,"profilePicture":1700},{"url":257},{"__typename":752,"sys":1702,"content":1704,"title":2499,"synopsis":2500,"hashTags":62,"publishedDate":2501,"slug":2502,"tagsCollection":2503,"authorsCollection":2509},{"id":1703},"Gcg7PGuICrlRcqq1QFXxH",{"json":1705},{"nodeType":260,"data":1706,"content":1707},{},[1708,1715,1722,1753,1760,1766,1772,1784,1787,1795,1811,1818,1824,1831,1838,1844,1847,1855,1862,1868,1874,1881,1888,1906,1912,1915,1923,1941,1947,1954,1957,1965,1972,1979,1985,1991,2035,2042,2045,2053,2060,2067,2110,2117,2148,2155,2198,2205,2208,2216,2235,2242,2250,2265,2272,2291,2298,2301,2308,2315,2333,2336,2344,2363,2370,2493],{"nodeType":264,"data":1709,"content":1710},{},[1711],{"nodeType":268,"value":1712,"marks":1713,"data":1714},"Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.  ",[],{},{"nodeType":264,"data":1716,"content":1717},{},[1718],{"nodeType":268,"value":1719,"marks":1720,"data":1721},"The content lives on chatgpt.com or claude.ai — domains that users and security tools trust implicitly — so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.",[],{},{"nodeType":264,"data":1723,"content":1724},{},[1725,1729,1737,1741,1749],{"nodeType":268,"value":1726,"marks":1727,"data":1728},"Several variants of this technique have been ",[],{},{"nodeType":308,"data":1730,"content":1732},{"uri":1731},"https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/",[1733],{"nodeType":268,"value":1734,"marks":1735,"data":1736},"reported over the past few months",[],{},{"nodeType":268,"value":1738,"marks":1739,"data":1740},". The earliest examples used shared Claude.ai conversations disguised as installation guides — complete with fake \"Apple Support\" attribution — that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer. ",[],{},{"nodeType":308,"data":1742,"content":1744},{"uri":1743},"https://www.kaspersky.com/blog/share-chatgpt-chat-clickfix-macos-amos-infostealer/54928/",[1745],{"nodeType":268,"value":1746,"marks":1747,"data":1748},"Kaspersky documented a parallel campaign",[],{},{"nodeType":268,"value":1750,"marks":1751,"data":1752}," using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern. ",[],{},{"nodeType":264,"data":1754,"content":1755},{},[1756],{"nodeType":268,"value":1757,"marks":1758,"data":1759},"Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable. ",[],{},{"nodeType":344,"data":1761,"content":1765},{"target":1762},{"sys":1763},{"id":1764,"type":349,"linkType":350},"5lz9zt223pecGvdaqdvSTQ",[],{"nodeType":344,"data":1767,"content":1771},{"target":1768},{"sys":1769},{"id":1770,"type":349,"linkType":350},"51GomAj3VOjnbmgd1DWYu0",[],{"nodeType":264,"data":1773,"content":1774},{},[1775,1780],{"nodeType":268,"value":1776,"marks":1777,"data":1779},"This is a live campaign which is still generating detections across our customer base at the time of writing. ",[1778],{"type":400},{},{"nodeType":268,"value":1781,"marks":1782,"data":1783},"Push customers are already protected and do not need to take further action. The malicious page URLs can be found at the end of this report but are not exhaustive and are liable to change. ",[],{},{"nodeType":353,"data":1785,"content":1786},{},[],{"nodeType":357,"data":1788,"content":1789},{},[1790],{"nodeType":268,"value":1791,"marks":1792,"data":1794},"A fake page, not a fake conversation",[1793],{"type":400},{},{"nodeType":264,"data":1796,"content":1797},{},[1798,1802,1807],{"nodeType":268,"value":1799,"marks":1800,"data":1801},"Previously reported variants relied on shared ",[],{},{"nodeType":268,"value":1803,"marks":1804,"data":1806},"conversations",[1805],{"type":433},{},{"nodeType":268,"value":1808,"marks":1809,"data":1810}," — the attacker created a chat that contained step-by-step instructions for the victim to follow, typically involving pasting a command into their terminal. The social engineering was conversational: the \"AI assistant\" appeared to be helpfully guiding the user through an installation process.",[],{},{"nodeType":264,"data":1812,"content":1813},{},[1814],{"nodeType":268,"value":1815,"marks":1816,"data":1817},"But now, rather than a shared conversation, the attacker has used ChatGPT's code rendering feature to create a fully designed, self-contained web page hosted at a chatgpt.com/s/ URL. It renders as what appears to be a ChatGPT service disruption notice:",[],{},{"nodeType":344,"data":1819,"content":1823},{"target":1820},{"sys":1821},{"id":1822,"type":349,"linkType":350},"1O9gyQab81SnbxhQp2aa5Z",[],{"nodeType":264,"data":1825,"content":1826},{},[1827],{"nodeType":268,"value":1828,"marks":1829,"data":1830},"A professional-looking error message reads: \"We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.\" A prominent download button sits below.",[],{},{"nodeType":264,"data":1832,"content":1833},{},[1834],{"nodeType":268,"value":1835,"marks":1836,"data":1837},"The \"Show code\" toggle at the top of the page reveals what's actually happening — the entire thing is custom HTML and CSS, authored to mimic a ChatGPT system notice, rendered using ChatGPT's code output feature. A web page inside a web page, hosted on a domain that every URL reputation system in the world considers safe.",[],{},{"nodeType":344,"data":1839,"content":1843},{"target":1840},{"sys":1841},{"id":1842,"type":349,"linkType":350},"4kQTfxB3aVH9W9BeYOuljP",[],{"nodeType":353,"data":1845,"content":1846},{},[],{"nodeType":357,"data":1848,"content":1849},{},[1850],{"nodeType":268,"value":1851,"marks":1852,"data":1854},"The download page",[1853],{"type":400},{},{"nodeType":264,"data":1856,"content":1857},{},[1858],{"nodeType":268,"value":1859,"marks":1860,"data":1861},"Clicking the download button redirects the user to openew[.]app, which presents a convincing clone of ChatGPT's official desktop application download page — complete with OpenAI branding, macOS and Windows download buttons, a Chrome extension link, and a mobile download section.",[],{},{"nodeType":344,"data":1863,"content":1867},{"target":1864},{"sys":1865},{"id":1866,"type":349,"linkType":350},"4MdFc4OB37ZihTGx506QJ6",[],{"nodeType":344,"data":1869,"content":1873},{"target":1870},{"sys":1871},{"id":1872,"type":349,"linkType":350},"LaPUy0zpIeY8s4PF2wkat",[],{"nodeType":264,"data":1875,"content":1876},{},[1877],{"nodeType":268,"value":1878,"marks":1879,"data":1880},"The site also displays differently depending on who visits it. When Push researchers examined the URL via URLScan, the scanner was redirected to a different page entirely — a generic AR/VR company website with no obvious connection to ChatGPT. ",[],{},{"nodeType":264,"data":1882,"content":1883},{},[1884],{"nodeType":268,"value":1885,"marks":1886,"data":1887},"Real users in a browser see the fake download page; automated scanners and bots see something benign. This kind of conditional rendering is a well-established evasion technique in the malvertising ecosystem, and it makes the malicious infrastructure harder for security teams and threat intelligence services to identify and analyze.",[],{},{"nodeType":264,"data":1889,"content":1890},{},[1891,1895,1903],{"nodeType":268,"value":1892,"marks":1893,"data":1894},"The downloaded executable poses as \"ChatGPT for Desktop\" and is ",[],{},{"nodeType":308,"data":1896,"content":1898},{"uri":1897},"https://www.virustotal.com/gui/file/de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[1899],{"nodeType":268,"value":1900,"marks":1901,"data":1902},"flagged on VirusTotal",[],{},{"nodeType":268,"value":824,"marks":1904,"data":1905},[],{},{"nodeType":344,"data":1907,"content":1911},{"target":1908},{"sys":1909},{"id":1910,"type":349,"linkType":350},"3FSbwoFJYQrcyo9uMsQIWI",[],{"nodeType":353,"data":1913,"content":1914},{},[],{"nodeType":357,"data":1916,"content":1917},{},[1918],{"nodeType":268,"value":1919,"marks":1920,"data":1922},"The Claude variant: same campaign, different platform",[1921],{"type":400},{},{"nodeType":264,"data":1924,"content":1925},{},[1926,1930,1937],{"nodeType":268,"value":1927,"marks":1928,"data":1929},"Alongside the ChatGPT rendered-page variant, Push has also detected the previously reported style of attack using shared Claude.ai conversations. These follow the pattern documented by ",[],{},{"nodeType":308,"data":1931,"content":1932},{"uri":1731},[1933],{"nodeType":268,"value":1934,"marks":1935,"data":1936},"BleepingComputer",[],{},{"nodeType":268,"value":1938,"marks":1939,"data":1940},": a shared chat disguised as a \"Claude Code on Mac\" installation guide, attributed to \"Apple Support,\" containing a curl command that downloads and executes malware.",[],{},{"nodeType":344,"data":1942,"content":1946},{"target":1943},{"sys":1944},{"id":1945,"type":349,"linkType":350},"5sWayuTsVdiLSLoS4sv2Vc",[],{"nodeType":264,"data":1948,"content":1949},{},[1950],{"nodeType":268,"value":1951,"marks":1952,"data":1953},"The fact that both the ChatGPT and Claude variants are appearing in Push customer environments suggests a campaign — or at least a shared playbook — that is actively experimenting with different platforms and different social engineering approaches to find what converts best.",[],{},{"nodeType":353,"data":1955,"content":1956},{},[],{"nodeType":357,"data":1958,"content":1959},{},[1960],{"nodeType":268,"value":1961,"marks":1962,"data":1964},"Malvertising remains one of the top phishing delivery channels",[1963],{"type":400},{},{"nodeType":264,"data":1966,"content":1967},{},[1968],{"nodeType":268,"value":1969,"marks":1970,"data":1971},"Push has detected this variant across multiple customer environments, with users arriving at these shared chat URLs after searching for terms including \"chatgpt,\" \"chatgpt free,\" \"chat gpt,\" and common typos like \"chatgo,\" \"chatgot,\" and \"cvhatgpt.\" ",[],{},{"nodeType":264,"data":1973,"content":1974},{},[1975],{"nodeType":268,"value":1976,"marks":1977,"data":1978},"You can see an example of this below: it's incredibly convincing, and uses the real ChatGPT domain — so even users that are paying attention are liable to fall for it. ",[],{},{"nodeType":344,"data":1980,"content":1984},{"target":1981},{"sys":1982},{"id":1983,"type":349,"linkType":350},"1GYWOyHpZT1rdTm6IGOKu8",[],{"nodeType":344,"data":1986,"content":1990},{"target":1987},{"sys":1988},{"id":1989,"type":349,"linkType":350},"4HpFJRAZH2lbygaEk2xOnN",[],{"nodeType":264,"data":1992,"content":1993},{},[1994,1998,2006,2010,2018,2022,2031],{"nodeType":268,"value":1995,"marks":1996,"data":1997},"This fits a pattern Push has tracked extensively. ",[],{},{"nodeType":308,"data":1999,"content":2001},{"uri":2000},"https://pushsecurity.com/blog/verizon-dbir-2026-review/",[2002],{"nodeType":268,"value":2003,"marks":2004,"data":2005},"Search-based delivery is now the dominant channel for malware distribution",[],{},{"nodeType":268,"value":2007,"marks":2008,"data":2009}," — our own data shows that ClickFix attacks are reached via search results rather than email in 4 of 5 cases, and Push's own research into ",[],{},{"nodeType":308,"data":2011,"content":2013},{"uri":2012},"https://pushsecurity.com/blog/analysing-a-sophisticated-google-malvertising-attack/",[2014],{"nodeType":268,"value":2015,"marks":2016,"data":2017},"malvertising campaigns impersonating brands like TradingView",[],{},{"nodeType":268,"value":2019,"marks":2020,"data":2021}," and ",[],{},{"nodeType":308,"data":2023,"content":2025},{"uri":2024},"https://pushsecurity.com/blog/google-search-malvertising-campaign-continues-now-impersonating-ahrefs/",[2026],{"nodeType":268,"value":2027,"marks":2028,"data":2030},"Ahrefs",[2029],{"type":316},{},{"nodeType":268,"value":2032,"marks":2033,"data":2034}," has demonstrated how effectively search ads can funnel victims to malicious pages. ",[],{},{"nodeType":264,"data":2036,"content":2037},{},[2038],{"nodeType":268,"value":2039,"marks":2040,"data":2041},"The shared-chat technique adds a new dimension: the destination URL itself is genuine (chatgpt.com, claude.ai), which means even a cautious user who checks the URL before clicking will see nothing suspicious.",[],{},{"nodeType":353,"data":2043,"content":2044},{},[],{"nodeType":357,"data":2046,"content":2047},{},[2048],{"nodeType":268,"value":2049,"marks":2050,"data":2052},"Legitimate platform abuse is everywhere",[2051],{"type":400},{},{"nodeType":264,"data":2054,"content":2055},{},[2056],{"nodeType":268,"value":2057,"marks":2058,"data":2059},"This is one example of a much broader pattern that has become one of the defining characteristics of the 2026 threat landscape: attackers systematically abusing legitimate platforms as attack infrastructure. The scale and variety of this abuse in recent months alone is striking, and it spans every stage of the phishing chain.",[],{},{"nodeType":1431,"data":2061,"content":2062},{},[2063],{"nodeType":268,"value":2064,"marks":2065,"data":2066},"Legit platform abuse for delivery",[],{},{"nodeType":264,"data":2068,"content":2069},{},[2070,2074,2082,2086,2094,2098,2106],{"nodeType":268,"value":2071,"marks":2072,"data":2073},"On the delivery side, attackers have been ",[],{},{"nodeType":308,"data":2075,"content":2077},{"uri":2076},"https://www.bleepingcomputer.com/news/security/amazon-ses-increasingly-abused-in-phishing-to-evade-detection/",[2078],{"nodeType":268,"value":2079,"marks":2080,"data":2081},"weaponizing stolen AWS credentials to send phishing through Amazon SES",[],{},{"nodeType":268,"value":2083,"marks":2084,"data":2085}," that passes SPF, DKIM, and DMARC validation because SES is a legitimate Amazon service. A Vietnamese operation dubbed ",[],{},{"nodeType":308,"data":2087,"content":2089},{"uri":2088},"https://thehackernews.com/2026/05/30000-facebook-accounts-hacked-via.html",[2090],{"nodeType":268,"value":2091,"marks":2092,"data":2093},"AccountDumpling used Google AppSheet's built-in email capability",[],{},{"nodeType":268,"value":2095,"marks":2096,"data":2097}," as a phishing relay to harvest 30,000 Facebook credentials. ",[],{},{"nodeType":308,"data":2099,"content":2101},{"uri":2100},"https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/",[2102],{"nodeType":268,"value":2103,"marks":2104,"data":2105},"Scammers exploited Microsoft's own internal notification pipeline",[],{},{"nodeType":268,"value":2107,"marks":2108,"data":2109}," — sending phishing from the same msonlineservicesteam@microsoftonline.com address that delivers legitimate 2FA codes — with Spamhaus confirming months of ongoing abuse.",[],{},{"nodeType":1431,"data":2111,"content":2112},{},[2113],{"nodeType":268,"value":2114,"marks":2115,"data":2116},"Legit platform abuse for hosting",[],{},{"nodeType":264,"data":2118,"content":2119},{},[2120,2124,2132,2136,2144],{"nodeType":268,"value":2121,"marks":2122,"data":2123},"For hosting, the platforms being abused read like a who's who of modern web infrastructure. ",[],{},{"nodeType":308,"data":2125,"content":2127},{"uri":2126},"https://www.securityweek.com/over-500-organizations-hit-in-years-long-phishing-campaign/",[2128],{"nodeType":268,"value":2129,"marks":2130,"data":2131},"Operation HookedWing ran for four years",[],{},{"nodeType":268,"value":2133,"marks":2134,"data":2135}," on GitHub Pages and Vercel, compromising 500+ organizations across more than 100 GitHub Pages domains before anyone documented it publicly. Cofense has separately ",[],{},{"nodeType":308,"data":2137,"content":2139},{"uri":2138},"https://cofense.com/blog/steal-smarter-not-harder-malicious-use-of-vercel-for-credential-phishing/",[2140],{"nodeType":268,"value":2141,"marks":2142,"data":2143},"documented the growing abuse of Vercel",[],{},{"nodeType":268,"value":2145,"marks":2146,"data":2147}," for credential phishing hosting. Pixm's Q1 2026 phishing report tracked over 100 unique Azure Blob Storage subdomain variants hosting phishing content that carried Microsoft's own domain reputation, alongside abuse of Cloudflare CDN, Cloudflare Workers, Cloudflare R2, Backblaze B2, and Supabase. ",[],{},{"nodeType":1431,"data":2149,"content":2150},{},[2151],{"nodeType":268,"value":2152,"marks":2153,"data":2154},"Abuse of compromised websites that are otherwise legit",[],{},{"nodeType":264,"data":2156,"content":2157},{},[2158,2162,2170,2174,2182,2186,2194],{"nodeType":268,"value":2159,"marks":2160,"data":2161},"Compromised legitimate sites are also being repurposed at scale. A mass exploitation of a ",[],{},{"nodeType":308,"data":2163,"content":2165},{"uri":2164},"https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/",[2166],{"nodeType":268,"value":2167,"marks":2168,"data":2169},"Ghost CMS vulnerability planted ClickFix pages across 700+ websites",[],{},{"nodeType":268,"value":2171,"marks":2172,"data":2173}," including Harvard, Oxford, and DuckDuckGo subdomains. Microsoft recently documented a campaign where ",[],{},{"nodeType":308,"data":2175,"content":2177},{"uri":2176},"https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/",[2178],{"nodeType":268,"value":2179,"marks":2180,"data":2181},"SEO poisoning was combined with AI chatbot recommendation manipulation",[],{},{"nodeType":268,"value":2183,"marks":2184,"data":2185}," to deliver GPU mining malware — extending the poisoning from traditional search results into AI-generated software recommendations. And ",[],{},{"nodeType":308,"data":2187,"content":2189},{"uri":2188},"https://www.helpnetsecurity.com/2026/05/27/deno-rat-malware-fake-chatgpt-claude-installers/",[2190],{"nodeType":268,"value":2191,"marks":2192,"data":2193},"fake ChatGPT and Claude installers on GitHub and SourceForge",[],{},{"nodeType":268,"value":2195,"marks":2196,"data":2197}," have been delivering the DinDoor backdoor and a Deno-based RAT via repositories that mimic legitimate developer tool distributions.",[],{},{"nodeType":264,"data":2199,"content":2200},{},[2201],{"nodeType":268,"value":2202,"marks":2203,"data":2204},"The structural problem is that every one of these platforms is genuinely legitimate, and the security controls that evaluate them — domain reputation, email authentication, URL categorization — confirm them as trusted because they are trusted. This attack extends this pattern into new territory by weaponizing the content-sharing features of AI chatbot platforms specifically, but the underlying principles are the same. ",[],{},{"nodeType":353,"data":2206,"content":2207},{},[],{"nodeType":357,"data":2209,"content":2210},{},[2211],{"nodeType":268,"value":2212,"marks":2213,"data":2215},"Impact analysis",[2214],{"type":400},{},{"nodeType":264,"data":2217,"content":2218},{},[2219,2223,2231],{"nodeType":268,"value":2220,"marks":2221,"data":2222},"Shared-chat malware delivery exploits a structural property of AI platforms that traditional security controls aren't designed to handle. Domain reputation, URL categorization, and safe browsing databases all treat chatgpt.com and claude.ai as trusted — because they are. Using these trusted pages to link off to further convincing-looking pages hosting malware allows the attacker to run campaigns that blend in, as well as rotate the phishing delivery pages later in the chain should they ever be flagged, allowing the campaign to continue without interruption (a well known ",[],{},{"nodeType":308,"data":2224,"content":2226},{"uri":2225},"https://phishing-techniques.pushsecurity.com/",[2227],{"nodeType":268,"value":2228,"marks":2229,"data":2230},"detection evasion technique",[],{},{"nodeType":268,"value":2232,"marks":2233,"data":2234},"). ",[],{},{"nodeType":264,"data":2236,"content":2237},{},[2238],{"nodeType":268,"value":2239,"marks":2240,"data":2241},"What makes the rendered-page variant particularly concerning is that it eliminates the most obvious red flag in the earlier attacks. The Claude.ai conversation variants required the victim to recognize that a shared chat instructing them to paste terminal commands might be suspicious — a tall order for many users, but at least the attack surface was visible. The rendered-page variant shows nothing that looks like an attack. It presents what appears to be a routine service disruption with a reasonable call to action: download the desktop app to continue using ChatGPT. ",[],{},{"nodeType":1431,"data":2243,"content":2244},{},[2245],{"nodeType":268,"value":2246,"marks":2247,"data":2249},"How Push detected the attack",[2248],{"type":400},{},{"nodeType":264,"data":2251,"content":2252},{},[2253,2257,2261],{"nodeType":268,"value":2254,"marks":2255,"data":2256},"We've aligned our detection logic for this technique under the name ",[],{},{"nodeType":268,"value":1399,"marks":2258,"data":2260},[2259],{"type":400},{},{"nodeType":268,"value":2262,"marks":2263,"data":2264}," — a technique-level detection that covers shared content abuse across LLM platforms, not tied to any single campaign or set of IOCs. ",[],{},{"nodeType":264,"data":2266,"content":2267},{},[2268],{"nodeType":268,"value":2269,"marks":2270,"data":2271},"Because Push sees the full context of how a user arrived at a page and what that page does once it renders, we can identify LLMShare attacks regardless of which AI platform is being abused or what social engineering wrapper the attacker has chosen. ",[],{},{"nodeType":264,"data":2273,"content":2274},{},[2275,2279,2287],{"nodeType":268,"value":2276,"marks":2277,"data":2278},"When we identified the initial instances of this campaign, we used our ",[],{},{"nodeType":308,"data":2280,"content":2282},{"uri":2281},"https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline/",[2283],{"nodeType":268,"value":2284,"marks":2285,"data":2286},"agentic threat hunting pipeline",[],{},{"nodeType":268,"value":2288,"marks":2289,"data":2290}," to hunt for additional examples across our customer telemetry, develop the LLMShare detection, and rapidly deploy it to customers. Push blocks users from interacting with the page before any malicious activity can occur. ",[],{},{"nodeType":264,"data":2292,"content":2293},{},[2294],{"nodeType":268,"value":2295,"marks":2296,"data":2297},"Push customers do not need to take any further action.",[],{},{"nodeType":353,"data":2299,"content":2300},{},[],{"nodeType":264,"data":2302,"content":2303},{},[2304],{"nodeType":268,"value":2305,"marks":2306,"data":2307},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":264,"data":2309,"content":2310},{},[2311],{"nodeType":268,"value":2312,"marks":2313,"data":2314},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":264,"data":2316,"content":2317},{},[2318,2321,2330],{"nodeType":268,"value":29,"marks":2319,"data":2320},[],{},{"nodeType":308,"data":2322,"content":2324},{"uri":2323},"https://pushsecurity.com/demo/",[2325],{"nodeType":268,"value":2326,"marks":2327,"data":2329},"Book a live demo to learn more.",[2328],{"type":316},{},{"nodeType":268,"value":29,"marks":2331,"data":2332},[],{},{"nodeType":353,"data":2334,"content":2335},{},[],{"nodeType":357,"data":2337,"content":2338},{},[2339],{"nodeType":268,"value":2340,"marks":2341,"data":2343},"Indicators of compromise",[2342],{"type":400},{},{"nodeType":264,"data":2345,"content":2346},{},[2347,2351,2359],{"nodeType":268,"value":2348,"marks":2349,"data":2350},"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",[],{},{"nodeType":308,"data":2352,"content":2354},{"uri":2353},"https://phishing-techniques.pushsecurity.com/techniques/domain-rotation-redirection/",[2355],{"nodeType":268,"value":2356,"marks":2357,"data":2358},"quickly spin up and rotate the sites used",[],{},{"nodeType":268,"value":2360,"marks":2361,"data":2362}," in the attack chain. IoC-based detections for campaigns like this are of limited value.",[],{},{"nodeType":264,"data":2364,"content":2365},{},[2366],{"nodeType":268,"value":2367,"marks":2368,"data":2369},"At the time of writing, the indicators observed were:",[],{},{"nodeType":2371,"data":2372,"content":2373},"table",{},[2374,2401,2425,2447,2470],{"nodeType":2375,"data":2376,"content":2377},"table-row",{},[2378,2390],{"nodeType":2379,"data":2380,"content":2381},"table-header-cell",{},[2382],{"nodeType":264,"data":2383,"content":2384},{},[2385],{"nodeType":268,"value":2386,"marks":2387,"data":2389},"Indicator",[2388],{"type":400},{},{"nodeType":2379,"data":2391,"content":2392},{},[2393],{"nodeType":264,"data":2394,"content":2395},{},[2396],{"nodeType":268,"value":2397,"marks":2398,"data":2400},"Type",[2399],{"type":400},{},{"nodeType":2375,"data":2402,"content":2403},{},[2404,2415],{"nodeType":2405,"data":2406,"content":2407},"table-cell",{},[2408],{"nodeType":264,"data":2409,"content":2410},{},[2411],{"nodeType":268,"value":2412,"marks":2413,"data":2414},"hxxps://claude[.]ai/share/8e6401b5-4849-46c4-a3cb-29e1c3c49131",[],{},{"nodeType":2405,"data":2416,"content":2417},{},[2418],{"nodeType":264,"data":2419,"content":2420},{},[2421],{"nodeType":268,"value":2422,"marks":2423,"data":2424},"URL",[],{},{"nodeType":2375,"data":2426,"content":2427},{},[2428,2438],{"nodeType":2405,"data":2429,"content":2430},{},[2431],{"nodeType":264,"data":2432,"content":2433},{},[2434],{"nodeType":268,"value":2435,"marks":2436,"data":2437},"hxxps://chatgpt[.]com/s/cb_6a0f1e6bbec88191aa7fede27163f08d",[],{},{"nodeType":2405,"data":2439,"content":2440},{},[2441],{"nodeType":264,"data":2442,"content":2443},{},[2444],{"nodeType":268,"value":2422,"marks":2445,"data":2446},[],{},{"nodeType":2375,"data":2448,"content":2449},{},[2450,2460],{"nodeType":2405,"data":2451,"content":2452},{},[2453],{"nodeType":264,"data":2454,"content":2455},{},[2456],{"nodeType":268,"value":2457,"marks":2458,"data":2459},"openew[.]app",[],{},{"nodeType":2405,"data":2461,"content":2462},{},[2463],{"nodeType":264,"data":2464,"content":2465},{},[2466],{"nodeType":268,"value":2467,"marks":2468,"data":2469},"Domain",[],{},{"nodeType":2375,"data":2471,"content":2472},{},[2473,2483],{"nodeType":2405,"data":2474,"content":2475},{},[2476],{"nodeType":264,"data":2477,"content":2478},{},[2479],{"nodeType":268,"value":2480,"marks":2481,"data":2482},"de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[],{},{"nodeType":2405,"data":2484,"content":2485},{},[2486],{"nodeType":264,"data":2487,"content":2488},{},[2489],{"nodeType":268,"value":2490,"marks":2491,"data":2492},"SHA256",[],{},{"nodeType":264,"data":2494,"content":2495},{},[2496],{"nodeType":268,"value":29,"marks":2497,"data":2498},[],{},"LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":2504},[2505,2507],{"sys":2506,"name":1696},{"id":1695},{"sys":2508,"name":1692},{"id":1691},{"items":2510},[2511],{"fullName":2512,"firstName":2513,"jobTitle":2514,"profilePicture":2515},"Keanu Maharaj","Keanu","Senior Security Researcher",{"url":2516},"https://images.ctfassets.net/y1cdw1ablpvd/VCGOm62jiocjwngWTh32U/e9a30637b1c76bf988d2fec90f5b6c36/1689361049351_1.png",{"__typename":752,"sys":2518,"content":2520,"title":3288,"synopsis":3289,"hashTags":62,"publishedDate":3290,"slug":3291,"tagsCollection":3292,"authorsCollection":3298},{"id":2519},"5RDOpmzJolwT1hk0fNIxzf",{"json":2521},{"nodeType":260,"data":2522,"content":2523},{},[2524,2543,2549,2556,2563,2566,2574,2593,2612,2619,2625,2632,2638,2645,2653,2660,2678,2710,2716,2722,2730,2737,2756,2787,2819,2826,2832,2840,2847,2859,2866,2907,2913,2955,2994,3000,3003,3011,3018,3024,3031,3038,3044,3051,3058,3086,3089,3097,3104,3112,3119,3126,3145,3152,3158,3165,3173,3180,3197,3204,3223,3226,3234,3241,3248,3255,3258,3264,3270],{"nodeType":264,"data":2525,"content":2526},{},[2527,2531,2539],{"nodeType":268,"value":2528,"marks":2529,"data":2530},"Back in 2024, we wrote about ",[],{},{"nodeType":308,"data":2532,"content":2534},{"uri":2533},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[2535],{"nodeType":268,"value":2536,"marks":2537,"data":2538},"how the Pyramid of Pain shapes Push's detection philosophy",[],{},{"nodeType":268,"value":2540,"marks":2541,"data":2542}," — detections targeting indicators that are easy for attackers to change deliver diminishing returns, while detections targeting attacker techniques impose a cost that's hard to absorb. Two years on, every force that made IoC-based detection fragile has intensified.",[],{},{"nodeType":344,"data":2544,"content":2548},{"target":2545},{"sys":2546},{"id":2547,"type":349,"linkType":350},"1iuLYxwI8T1wDUIFSom0G0",[],{"nodeType":264,"data":2550,"content":2551},{},[2552],{"nodeType":268,"value":2553,"marks":2554,"data":2555},"AI hasn't introduced a new problem so much as it's compressed the timelines on an existing one — attackers can generate infrastructure, iterate on tooling, and industrialize newly discovered techniques faster than before. The bottom layers of the Pyramid are collapsing under the weight of machine-speed operations, and the middle layers are starting to buckle too.",[],{},{"nodeType":264,"data":2557,"content":2558},{},[2559],{"nodeType":268,"value":2560,"marks":2561,"data":2562},"These changes mean that technique-level detection is more important than ever. In this article, we’ll dig into how the Pyramid is changing, and what this means for our detection philosophy at Push (TL;DR — it reinforces the path we’re already on: building detections at the top of the Pyramid by harnessing browser visibility). ",[],{},{"nodeType":353,"data":2564,"content":2565},{},[],{"nodeType":357,"data":2567,"content":2568},{},[2569],{"nodeType":268,"value":2570,"marks":2571,"data":2573},"The bottom of the Pyramid was already crumbling",[2572],{"type":400},{},{"nodeType":264,"data":2575,"content":2576},{},[2577,2581,2589],{"nodeType":268,"value":2578,"marks":2579,"data":2580},"The case against indicator-based detection didn't need AI to be compelling. ",[],{},{"nodeType":308,"data":2582,"content":2584},{"uri":2583},"https://www.spamhaus.org/",[2585],{"nodeType":268,"value":2586,"marks":2587,"data":2588},"89% of phishing domains are active for fewer than two days",[],{},{"nodeType":268,"value":2590,"marks":2591,"data":2592},", with just 6.5% surviving past 15 days — by the time a domain makes it onto a blocklist, the campaign has moved on.",[],{},{"nodeType":264,"data":2594,"content":2595},{},[2596,2600,2608],{"nodeType":268,"value":2597,"marks":2598,"data":2599},"We've ",[],{},{"nodeType":308,"data":2601,"content":2603},{"uri":2602},"https://pushsecurity.com/blog/why-most-phishing-attacks-feel-like-a-zero-day/",[2604],{"nodeType":268,"value":2605,"marks":2606,"data":2607},"written before",[],{},{"nodeType":268,"value":2609,"marks":2610,"data":2611}," about how this makes every phishing attack effectively a zero-day for organizations relying on known-bad detection. The phishing kit's behavior — its page structure, script signatures, malicious payload mechanics — is the only detection target that outlasts a single campaign.",[],{},{"nodeType":264,"data":2613,"content":2614},{},[2615],{"nodeType":268,"value":2616,"marks":2617,"data":2618},"When we blogged about the Pyramid of Pain for modern attacks that happen predominantly over the internet, with minimal (or zero) endpoint contact, it first looked like this: ",[],{},{"nodeType":344,"data":2620,"content":2624},{"target":2621},{"sys":2622},{"id":2623,"type":349,"linkType":350},"2N04ycJ6RKGfHdX5X1TwU3",[],{"nodeType":264,"data":2626,"content":2627},{},[2628],{"nodeType":268,"value":2629,"marks":2630,"data":2631},"Now, it looks more like this:",[],{},{"nodeType":344,"data":2633,"content":2637},{"target":2634},{"sys":2635},{"id":2636,"type":349,"linkType":350},"mfhP4WToOQkrHnVkXU0tX",[],{"nodeType":264,"data":2639,"content":2640},{},[2641],{"nodeType":268,"value":2642,"marks":2643,"data":2644},"Let’s explore why. ",[],{},{"nodeType":1431,"data":2646,"content":2647},{},[2648],{"nodeType":268,"value":2649,"marks":2650,"data":2652},"AI is accelerating phishing rotation and delivery",[2651],{"type":400},{},{"nodeType":264,"data":2654,"content":2655},{},[2656],{"nodeType":268,"value":2657,"marks":2658,"data":2659},"Attackers are harnessing AI at every stage, speeding up the process of creating, rotating, and replacing phishing infrastructure at every level, as well as capitalizing on AI adoption itself to enhance their lures. The operational signature is more domains, shorter lifespans, more variation, and fewer of the reuse patterns that blocklists depend on.",[],{},{"nodeType":264,"data":2661,"content":2662},{},[2663,2667,2674],{"nodeType":268,"value":2664,"marks":2665,"data":2666},"Attackers can ",[],{},{"nodeType":308,"data":2668,"content":2669},{"uri":2281},[2670],{"nodeType":268,"value":2671,"marks":2672,"data":2673},"vibe-code entire phishing pages in minutes",[],{},{"nodeType":268,"value":2675,"marks":2676,"data":2677}," — not just cloning legitimate login pages but vibe-cloning them, feeding an AI a screenshot and having it rebuild a convincing frontend with a completely unique backend. ",[],{},{"nodeType":264,"data":2679,"content":2680},{},[2681,2685,2694,2698,2706],{"nodeType":268,"value":2682,"marks":2683,"data":2684},"We've seen attackers clone free SaaS tools like background removers and PDF converters, then inject phishing components or ClickFix payloads into what looks like a functional utility. We’ve even seen attackers distributing malware using AI-generated pages shared using ",[],{},{"nodeType":308,"data":2686,"content":2688},{"uri":2687},"https://pushsecurity.com/blog/llmshare-malvertising-campaign/",[2689],{"nodeType":268,"value":2690,"marks":2691,"data":2693},"LLM tool sharing functionality",[2692],{"type":316},{},{"nodeType":268,"value":2695,"marks":2696,"data":2697},", resulting in phishing delivery pages hosted on real claude.ai and chatgpt.com. And legitimate cloud platforms like ",[],{},{"nodeType":308,"data":2699,"content":2701},{"uri":2700},"https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign",[2702],{"nodeType":268,"value":2703,"marks":2704,"data":2705},"Railway",[],{},{"nodeType":268,"value":2707,"marks":2708,"data":2709},", Cloudflare Workers, and Vercel host and dynamically rotate attack infrastructure, so the domains feeding into blocklists often belong to reputable services that can't simply be blocked. ",[],{},{"nodeType":344,"data":2711,"content":2715},{"target":2712},{"sys":2713},{"id":2714,"type":349,"linkType":350},"5yoLmqysyQazfzLITCUTfc",[],{"nodeType":344,"data":2717,"content":2721},{"target":2718},{"sys":2719},{"id":2720,"type":349,"linkType":350},"5XK5qZMQU19xlA8L2T5y0Z",[],{"nodeType":1431,"data":2723,"content":2724},{},[2725],{"nodeType":268,"value":2726,"marks":2727,"data":2729},"The kit ecosystem is fragmenting faster than anyone can track",[2728],{"type":400},{},{"nodeType":264,"data":2731,"content":2732},{},[2733],{"nodeType":268,"value":2734,"marks":2735,"data":2736},"What we see across our install base is a huge and growing variation in phishing kits — new kits, derivative kits of known platforms, derivatives of those derivatives — appearing on a weekly basis.",[],{},{"nodeType":264,"data":2738,"content":2739},{},[2740,2744,2752],{"nodeType":268,"value":2741,"marks":2742,"data":2743},"As we reported in our ",[],{},{"nodeType":308,"data":2745,"content":2747},{"uri":2746},"https://pushsecurity.com/thank-you/browser-attacks-report",[2748],{"nodeType":268,"value":2749,"marks":2750,"data":2751},"Browser Attacks Report",[],{},{"nodeType":268,"value":2753,"marks":2754,"data":2755},", the most common AiTM kits we detected over the last year were Tycoon 2FA (59% of detections), followed by Sneaky 2FA, FlowerStorm, Evilginx (nominally a red team tool, but widely abused by attackers), NakedPages, Gabagool, and dozens more — but those established names are just the visible layer.",[],{},{"nodeType":264,"data":2757,"content":2758},{},[2759,2763,2771,2775,2783],{"nodeType":268,"value":2760,"marks":2761,"data":2762},"Code is forked, modified, and redeployed across kits in a pattern that ",[],{},{"nodeType":308,"data":2764,"content":2766},{"uri":2765},"https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere",[2767],{"nodeType":268,"value":2768,"marks":2769,"data":2770},"resembles open-source development",[],{},{"nodeType":268,"value":2772,"marks":2773,"data":2774}," more than traditional criminal enterprise, and the rate at which new variants appear is accelerating. The ",[],{},{"nodeType":308,"data":2776,"content":2778},{"uri":2777},"https://pushsecurity.com/blog/device-code-phishing/",[2779],{"nodeType":268,"value":2780,"marks":2781,"data":2782},"Venom kit",[],{},{"nodeType":268,"value":2784,"marks":2785,"data":2786}," reuses Sneaky 2FA's AiTM infrastructure but carries different branding and adds device code phishing — whether it's the same developers, stolen code, or a deliberate fork is unclear.",[],{},{"nodeType":264,"data":2788,"content":2789},{},[2790,2794,2802,2806,2815],{"nodeType":268,"value":2791,"marks":2792,"data":2793},"Tycoon 2FA illustrates the scale of the evolution. The kit evolves continuously, addingnew capabilities, new evasion techniques, and hybridizing with other platforms. Even when Sekoia and Microsoft seized 330+ Tycoon domains in March 2026, the techniques it popularized were already embedded across competitors, and the slack was taken up by rival platforms within days. And in any case, Tycoon was back to ",[],{},{"nodeType":308,"data":2795,"content":2797},{"uri":2796},"https://www.crowdstrike.com/en-us/blog/tycoon2fa-phishing-as-a-service-platform-persists-following-takedown/",[2798],{"nodeType":268,"value":2799,"marks":2800,"data":2801},"normal levels of operation",[],{},{"nodeType":268,"value":2803,"marks":2804,"data":2805}," shortly after. It has also been observed ",[],{},{"nodeType":308,"data":2807,"content":2809},{"uri":2808},"https://www.okta.com/en-nl/blog/threat-intelligence/tycoon_2fa_phishing_actors_scatter/",[2810],{"nodeType":268,"value":2811,"marks":2812,"data":2814},"pivoting to add new device code phishing capabilities",[2813],{"type":316},{},{"nodeType":268,"value":2816,"marks":2817,"data":2818}," (more on that below). ",[],{},{"nodeType":264,"data":2820,"content":2821},{},[2822],{"nodeType":268,"value":2823,"marks":2824,"data":2825},"Tear one down and there are many more to take its place — and meanwhile the original is already evolving into something new.",[],{},{"nodeType":344,"data":2827,"content":2831},{"target":2828},{"sys":2829},{"id":2830,"type":349,"linkType":350},"3UDzUCCizPJhXp3SsoZuSK",[],{"nodeType":1431,"data":2833,"content":2834},{},[2835],{"nodeType":268,"value":2836,"marks":2837,"data":2839},"New techniques are being industrialized faster than ever",[2838],{"type":400},{},{"nodeType":264,"data":2841,"content":2842},{},[2843],{"nodeType":268,"value":2844,"marks":2845,"data":2846},"As well as the fragmentation of existing kits, we’re seeing new techniques added at an accelerating rate. ",[],{},{"nodeType":264,"data":2848,"content":2849},{},[2850,2855],{"nodeType":268,"value":2851,"marks":2852,"data":2854},"Device code phishing",[2853],{"type":400},{},{"nodeType":268,"value":2856,"marks":2857,"data":2858}," is the clearest case study. From early nation state adoption in 2024, it took until 2026 for criminal adoption to really take off, but the take-up this year is unprecedented. The EvilTokens kit packaged device code phishing into a PhaaS offering with GPT-powered spear-phishing and adaptive landing pages, hitting 340+ organizations across five countries in March 2026. ",[],{},{"nodeType":264,"data":2860,"content":2861},{},[2862],{"nodeType":268,"value":2863,"marks":2864,"data":2865},"Now, device code functionality is now a core phish kit component. We’re tracking 18+ kits with device code phishing capabilities and a 37.5x increase in device code phishing detections this year alone, with the technique moving from state-sponsored exclusivity to something any PhaaS customer can rent.",[],{},{"nodeType":264,"data":2867,"content":2868},{},[2869,2873,2881,2885,2890,2894,2903],{"nodeType":268,"value":2870,"marks":2871,"data":2872},"Similarly, when we ",[],{},{"nodeType":308,"data":2874,"content":2876},{"uri":2875},"https://pushsecurity.com/blog/inside-criminal-phishing-panel",[2877],{"nodeType":268,"value":2878,"marks":2879,"data":2880},"infiltrated Doko's Panel",[],{},{"nodeType":268,"value":2882,"marks":2883,"data":2884}," — a ",[],{},{"nodeType":268,"value":2886,"marks":2887,"data":2889},"real-time vishing and AiTM platform",[2888],{"type":400},{},{"nodeType":268,"value":2891,"marks":2892,"data":2893}," used by ShinyHunters and affiliated groups — the codebase was full of LLM-generated artifacts. Multiple groups were using the templated vishing panel and spinning up their own variants, but the AI-generated indicators persisted throughout. This approach to real-time vishing + browser payload has been a ",[],{},{"nodeType":308,"data":2895,"content":2897},{"uri":2896},"https://pushsecurity.com/blog/analyzing-the-instructure-breach/",[2898],{"nodeType":268,"value":2899,"marks":2900,"data":2902},"mainstay of the Com affiliates like ShinyHunters this year",[2901],{"type":316},{},{"nodeType":268,"value":2904,"marks":2905,"data":2906},". ",[],{},{"nodeType":344,"data":2908,"content":2912},{"target":2909},{"sys":2910},{"id":2911,"type":349,"linkType":350},"01mOiserRBXraawXwQyJNm",[],{"nodeType":264,"data":2914,"content":2915},{},[2916,2920,2925,2929,2938,2942,2951],{"nodeType":268,"value":2917,"marks":2918,"data":2919},"The broader ",[],{},{"nodeType":268,"value":2921,"marks":2922,"data":2924},"ClickFix",[2923],{"type":400},{},{"nodeType":268,"value":2926,"marks":2927,"data":2928}," family shows the same acceleration: First reported in early 2024 and adopted by four nation-state groups within a single quarter. Fast forward and ",[],{},{"nodeType":308,"data":2930,"content":2932},{"uri":2931},"https://www.crowdstrike.com/en-us/global-threat-report/",[2933],{"nodeType":268,"value":2934,"marks":2935,"data":2937},"CrowdStrike's data",[2936],{"type":316},{},{"nodeType":268,"value":2939,"marks":2940,"data":2941}," shows a 563% increase in fake CAPTCHA incidents (one of the more common ClickFix lure types), while ",[],{},{"nodeType":308,"data":2943,"content":2945},{"uri":2944},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf",[2946],{"nodeType":268,"value":2947,"marks":2948,"data":2950},"Microsoft reported",[2949],{"type":316},{},{"nodeType":268,"value":2952,"marks":2953,"data":2954}," it as making up 47% of observed attacks according to their Digital Defense Report.",[],{},{"nodeType":264,"data":2956,"content":2957},{},[2958,2962,2966,2970,2978,2982,2990],{"nodeType":268,"value":2959,"marks":2960,"data":2961},"And ",[],{},{"nodeType":268,"value":1373,"marks":2963,"data":2965},[2964],{"type":400},{},{"nodeType":268,"value":2967,"marks":2968,"data":2969}," — a combination of ClickFix and OAuth consent phishing techniques — suggests the next compression is already underway. Push researchers ",[],{},{"nodeType":308,"data":2971,"content":2973},{"uri":2972},"https://pushsecurity.com/blog/consentfix/",[2974],{"nodeType":268,"value":2975,"marks":2976,"data":2977},"discovered the technique",[],{},{"nodeType":268,"value":2979,"marks":2980,"data":2981}," in December 2025 — a browser-native ClickFix variant hijacking OAuth consent grants via Azure CLI's localhost redirect. It was later confirmed to be tied to APT29. By January 2026, a ",[],{},{"nodeType":308,"data":2983,"content":2985},{"uri":2984},"https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit/",[2986],{"nodeType":268,"value":2987,"marks":2988,"data":2989},"criminal ConsentFix v3 toolkit",[],{},{"nodeType":268,"value":2991,"marks":2992,"data":2993}," had appeared on the XSS forum with Cloudflare Workers, ZoomInfo targeting, and automated exfiltration via Pipedream.",[],{},{"nodeType":344,"data":2995,"content":2999},{"target":2996},{"sys":2997},{"id":2998,"type":349,"linkType":350},"41FMif4T0y1maflzonWgL8",[],{"nodeType":353,"data":3001,"content":3002},{},[],{"nodeType":357,"data":3004,"content":3005},{},[3006],{"nodeType":268,"value":3007,"marks":3008,"data":3010},"Why technique-level detection is the only layer that holds",[3009],{"type":400},{},{"nodeType":264,"data":3012,"content":3013},{},[3014],{"nodeType":268,"value":3015,"marks":3016,"data":3017},"The middle of the Pyramid — tool signatures and artifacts — used to offer much more durable detection than infrastructure indicators. Fingerprinting a specific phishing kit by its JavaScript structure or HTML patterns provided a detection target that survived across dozens or hundreds of campaigns, even as the underlying domains rotated. Tool level detections are still better, but not by quite the same margin.",[],{},{"nodeType":344,"data":3019,"content":3023},{"target":3020},{"sys":3021},{"id":3022,"type":349,"linkType":350},"5pxaYdCIFiFKLPhRaPoldX",[],{"nodeType":264,"data":3025,"content":3026},{},[3027],{"nodeType":268,"value":3028,"marks":3029,"data":3030},"When the kit landscape was dominated by a handful of platforms, you could write signatures for Tycoon, Sneaky2FA, EvilProxy, and so on, and cover the lion's share of attacks. With the ecosystem now producing new variants and entirely new kits on a weekly basis, detecting by kit fingerprint starts to look uncomfortably similar to detecting by domain.",[],{},{"nodeType":264,"data":3032,"content":3033},{},[3034],{"nodeType":268,"value":3035,"marks":3036,"data":3037},"But many of these proliferating kits do share behavioral patterns at a deeper level than their code signatures. For example, every device code phishing kit implements fundamentally the same flow: present a lure, generate a device code via the OAuth Device Authorization endpoint, get the user to enter it on the legitimate authorization page, and poll for the resulting tokens. The frontends vary, the infrastructure varies, but the behavioral pattern doesn't.",[],{},{"nodeType":344,"data":3039,"content":3043},{"target":3040},{"sys":3041},{"id":3042,"type":349,"linkType":350},"FyyHayQtsJTwoB1kluMOl",[],{"nodeType":264,"data":3045,"content":3046},{},[3047],{"nodeType":268,"value":3048,"marks":3049,"data":3050},"Genuinely new attack techniques still require human creativity — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted. That kind of innovation hasn't been automated. But the window to discover a technique, build a detection, and then deploy it before it is adopted by criminals at scale is compressing with each generation.",[],{},{"nodeType":264,"data":3052,"content":3053},{},[3054],{"nodeType":268,"value":3055,"marks":3056,"data":3057},"Organizations that detect at the technique level and deploy before commoditization have a structural advantage that increases over time. Waiting for indicators — even tool-level indicators — means chasing a curve that's accelerating away from you. This is the challenge we grapple with every day as we strive for the most resilient detections possible. ",[],{},{"nodeType":3059,"data":3060,"content":3061},"blockquote",{},[3062],{"nodeType":264,"data":3063,"content":3064},{},[3065,3069,3077,3081],{"nodeType":268,"value":3066,"marks":3067,"data":3068},"As our CPO Jacques Louw put it on ",[],{},{"nodeType":308,"data":3070,"content":3072},{"uri":3071},"https://risky.biz/RBNEWSSI128/",[3073],{"nodeType":268,"value":3074,"marks":3075,"data":3076},"Risky Business",[],{},{"nodeType":268,"value":3078,"marks":3079,"data":3080},": ",[],{},{"nodeType":268,"value":3082,"marks":3083,"data":3085},"\"There's no list of bad domains anywhere in the product. It's a crutch — a false cheat code that stops you from doing the detection in the way that actually is resilient, because the next time you see it, it will be on a different domain.\"",[3084],{"type":433},{},{"nodeType":353,"data":3087,"content":3088},{},[],{"nodeType":357,"data":3090,"content":3091},{},[3092],{"nodeType":268,"value":3093,"marks":3094,"data":3096},"What it takes to detect at the top of the Pyramid",[3095],{"type":400},{},{"nodeType":264,"data":3098,"content":3099},{},[3100],{"nodeType":268,"value":3101,"marks":3102,"data":3103},"If technique-level detection is the only layer that holds, two things have to be true about your detection capability: You need the right vantage point, and you need the research velocity to stay ahead.",[],{},{"nodeType":1431,"data":3105,"content":3106},{},[3107],{"nodeType":268,"value":3108,"marks":3109,"data":3111},"You need the right vantage point",[3110],{"type":400},{},{"nodeType":264,"data":3113,"content":3114},{},[3115],{"nodeType":268,"value":3116,"marks":3117,"data":3118},"Technique-level behaviors in browser-based identity attacks — how a phishing page orchestrates credential entry, how a device code flow presents its authorization prompt, how a ClickFix variant manipulates the clipboard — are visible in the browser session and nowhere else.",[],{},{"nodeType":264,"data":3120,"content":3121},{},[3122],{"nodeType":268,"value":3123,"marks":3124,"data":3125},"Network proxies see encrypted traffic and can attempt to reconstruct page behavior from metadata, but DOM manipulation, user interaction sequences, and script execution aren't visible from that vantage point. Email gateways see the delivery mechanism (or nothing at all in the increasing number of social media and search engine based attacks) but not the payload.",[],{},{"nodeType":264,"data":3127,"content":3128},{},[3129,3133,3141],{"nodeType":268,"value":3130,"marks":3131,"data":3132},"As we disclosed in our ",[],{},{"nodeType":308,"data":3134,"content":3135},{"uri":2746},[3136],{"nodeType":268,"value":3137,"marks":3138,"data":3140},"browser attacks report",[3139],{"type":316},{},{"nodeType":268,"value":3142,"marks":3143,"data":3144},", 95% of in-browser attacks we detect use some form of bot protection, often combined with conditional loading techniques like referrer and browser checks, reliably defeating automated analysis techniques. ",[],{},{"nodeType":264,"data":3146,"content":3147},{},[3148],{"nodeType":268,"value":3149,"marks":3150,"data":3151},"Behavioral detection at the technique level requires observing what happens on the page at the moment the user interacts with it — analyzing pages, not links. When you see the entire browsing flow — ad click, redirect chain, page render, credential prompt — an attack stands out immediately. Without that context, any detection system is forced to fill in gaps, and the gaps are where attacks hide.",[],{},{"nodeType":344,"data":3153,"content":3157},{"target":3154},{"sys":3155},{"id":3156,"type":349,"linkType":350},"4804g6u4POUDpL42bzP0EY",[],{"nodeType":264,"data":3159,"content":3160},{},[3161],{"nodeType":268,"value":3162,"marks":3163,"data":3164},"Push sits inside the browser session, observing this in real time. Its detections target the behavioral mechanics of techniques rather than the surface characteristics of individual kits or infrastructure.",[],{},{"nodeType":1431,"data":3166,"content":3167},{},[3168],{"nodeType":268,"value":3169,"marks":3170,"data":3172},"You need the research expertise",[3171],{"type":400},{},{"nodeType":264,"data":3174,"content":3175},{},[3176],{"nodeType":268,"value":3177,"marks":3178,"data":3179},"When the window between technique discovery and industrialized exploitation is measured in weeks rather than years, the detection pipeline needs to operate on that same compressed timescale.",[],{},{"nodeType":264,"data":3181,"content":3182},{},[3183,3187,3193],{"nodeType":268,"value":3184,"marks":3185,"data":3186},"This is where our ",[],{},{"nodeType":308,"data":3188,"content":3189},{"uri":2281},[3190],{"nodeType":268,"value":2284,"marks":3191,"data":3192},[],{},{"nodeType":268,"value":3194,"marks":3195,"data":3196}," fits. It's tripled our monthly detection output — not by generating bigger blocklists, but by scaling the process of discovering behavioral patterns across the telemetry generated by 3+ million browser deployments.",[],{},{"nodeType":264,"data":3198,"content":3199},{},[3200],{"nodeType":268,"value":3201,"marks":3202,"data":3203},"The detections it produces are technique-class by design, targeting how attacks work rather than the infrastructure or specific tool that implements them. The goal is curation, not accumulation — hundreds of high-fidelity behavioral detections rather than the billions of signatures and domain entries that traditional approaches require.",[],{},{"nodeType":264,"data":3205,"content":3206},{},[3207,3211,3219],{"nodeType":268,"value":3208,"marks":3209,"data":3210},"When we detected the first in-the-wild ",[],{},{"nodeType":308,"data":3212,"content":3214},{"uri":3213},"https://pushsecurity.com/blog/installfix/",[3215],{"nodeType":268,"value":3216,"marks":3217,"data":3218},"InstallFix attack",[],{},{"nodeType":268,"value":3220,"marks":3221,"data":3222}," through the pipeline — a user had searched for NotebookLM, clicked a paid Google ad, and was redirected to a fake page with a WebAssembly C2 connector — the detection shipped to all customers within minutes. It didn't depend on knowing the domain, the ad creative, or the specific kit. It depended on recognizing the technique itself.",[],{},{"nodeType":353,"data":3224,"content":3225},{},[],{"nodeType":357,"data":3227,"content":3228},{},[3229],{"nodeType":268,"value":3230,"marks":3231,"data":3233},"Technique-level detection is now the only option",[3232],{"type":400},{},{"nodeType":264,"data":3235,"content":3236},{},[3237],{"nodeType":268,"value":3238,"marks":3239,"data":3240},"As a framework for detection durability, the Pyramid of Pain is more relevant than ever. ",[],{},{"nodeType":264,"data":3242,"content":3243},{},[3244],{"nodeType":268,"value":3245,"marks":3246,"data":3247},"AI has made infrastructure indicators essentially disposable. The tools tier is compressing as criminal vendors vibe-code, fork, and clone tooling at machine speed. Technique-level detection is the layer that holds long-term to be able to proactively detect and block net-new attacks and the kits that power them. ",[],{},{"nodeType":264,"data":3249,"content":3250},{},[3251],{"nodeType":268,"value":3252,"marks":3253,"data":3254},"Novel attack techniques still require human creativity to discover, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation. Defending that layer requires a vantage point inside the browser session and a research pipeline fast enough to stay ahead of the accelerating path from discovery to industrialization.",[],{},{"nodeType":353,"data":3256,"content":3257},{},[],{"nodeType":264,"data":3259,"content":3260},{},[3261],{"nodeType":268,"value":2305,"marks":3262,"data":3263},[],{},{"nodeType":264,"data":3265,"content":3266},{},[3267],{"nodeType":268,"value":2312,"marks":3268,"data":3269},[],{},{"nodeType":264,"data":3271,"content":3272},{},[3273,3276,3284],{"nodeType":268,"value":29,"marks":3274,"data":3275},[],{},{"nodeType":308,"data":3277,"content":3278},{"uri":671},[3279],{"nodeType":268,"value":3280,"marks":3281,"data":3283},"Book a live demo",[3282],{"type":316},{},{"nodeType":268,"value":3285,"marks":3286,"data":3287}," to learn more.",[],{},"The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever","AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.","2026-06-01T00:00:00.000Z","the-pyramid-of-pain-in-the-ai-era",{"items":3293},[3294,3296],{"sys":3295,"name":1692},{"id":1691},{"sys":3297,"name":1696},{"id":1695},{"items":3299},[3300],{"fullName":3301,"firstName":3302,"jobTitle":3303,"profilePicture":3304},"Dan Green","Dan","Threat Research",{"url":3305},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png","from-iocs-to-ttps-an-agentic-threat-hunting-case-study","blog/from-iocs-to-ttps-an-agentic-threat-hunting-case-study",{"json":3309},{"data":3310,"content":3311,"nodeType":260},{},[3312],{"data":3313,"content":3314,"nodeType":264},{},[3315],{"data":3316,"marks":3317,"value":3318,"nodeType":268},{},[],"Here’s how Push’s agentic detection pipeline turns intel into huntable characteristics of attacker behavior, deriving durable detections from a range of sources. In this case study, we’ll look at how we were able to raise an alert the first time a novel OAuth redirect abuse technique was observed in customer environments.","How Push’s agentic detection pipeline turns intel into huntable characteristics of attacker behavior, deriving durable detections from a range of sources.",{"id":3321,"publishedAt":3322},"4fUZAVpkaksHImeoT8jp0f","2026-07-31T09:20:15.969Z",{"items":3324},[3325,3327],{"sys":3326,"name":1696},{"id":1695},{"sys":3328,"name":1692},{"id":1691},"AlO-w1Vb0nlqw2SOkytZHaVW986PI84snBstYGbPrk8",1785495680698]