Security
X-Signature
A blocked URL detection occurred.
The unique identifier for the event. This can be used as an idempotency key.
Example:"c478966c-f927-411c-b919-179832d3d50c"
The unique identifier of the tenant the event belongs to.
Example:"4f9d2e7a-1b3c-4d5e-8f6a-7c8b9d0e1f2a"
When the event occurred, formatted as a UNIX timestamp (in seconds).
Example:1698604061
The description of the event. Note: this is subject to change and should not be used to match on this object.
Example:"user@example.com triggered a new blocked URL detection"
The friendly name of this object. Note: this is subject to change and should not be used to match on this object.
Example:"Blocked URL"
- https://api.pushsecurity.comhttps://api.pushsecurity.com/blocked-url-detection
{ "version": "1", "id": "c478966c-f927-411c-b919-179832d3d50c", "tenantId": "4f9d2e7a-1b3c-4d5e-8f6a-7c8b9d0e1f2a", "timestamp": 1698604061, "category": "DETECTION", "description": "user@example.com triggered a new blocked URL detection", "type": "CREATE", "object": "BLOCKED_URL", "friendlyName": "Blocked URL", "new": { "id": "c478966c-f927-411c-b919-179832d3d50c", "employeeId": "37cda962-7e78-49bc-8721-1becd16276a3", "employee": { "id": "2a2197de-ad2c-47e4-8dcb-fb0f04cf83e0", "email": "john.hill@example.com", "firstName": "John", "lastName": "Hill", "department": "Security Engineering", "location": "New York", "licensed": true, "chatopsEnabled": true, "creationTimestamp": 1698669223 }, "browserId": "2a2197de-ad2c-47e4-8dcb-fb0f04cf83e0", "browser": "CHROME", "severity": "LOW", "detectionType": "PHISHING", "detectionLink": "https://console.pushsecurity.com/app/detections?id=c478966c-f927-411c-b919-179832d3d50c", "response": "BLOCKED", "creationTimestamp": 1698604061, "lastActivityTimestamp": 1698604061, "archived": true, "classification": "FALSE_POSITIVE", "events": [ { "id": "c478966c-f927-411c-b919-179832d3d50c", "creationTimestamp": 1698604061, "detectionEventType": "PHISHING_TOOL_DETECTED", "detectionEventName": "string", "accountId": "37cda962-7e78-49bc-8721-1becd16276a3", "appType": "PUSH_SECURITY", "phishingToolIndicator": "AITM_TOOL_EVILGINX_01", "controlMode": "INFORM", "description": "Phishing attempt detected", "clonedLoginPageIndicator": "MICROSOFT_01", "extensionId": "dljjddkmmcminffjbcmeccgfbjlhmhlm", "extensionName": "Example Extension", "profileEmail": "john.hill@example.com", "maliciousBrowserExtensionIndicator": "EXTENSION_ID", "customIndicator": "TORRENT_MAGNET_LINK", "response": "BLOCKED", "email": "john.hill@example.com", "url": "https://example.com/phishing", "matchedUrl": "https://example.com/phishing", "referrerUrl": "https://mail.google.com", "clonedLoginPageUrls": [ "https://example.com/phishing" ], "sourceIpAddress": "8.158.25.38", "metadata": "{\"source_type\": \"Telegram\", \"breach_type\": \"Stealer Malware Logs\", \"breach_publication_date\": \"2025-04-01\"}", "experimental": false, "domainCategories": [ { … } ] } ] }, "old": { "id": "c478966c-f927-411c-b919-179832d3d50c", "employeeId": "37cda962-7e78-49bc-8721-1becd16276a3", "employee": { "id": "2a2197de-ad2c-47e4-8dcb-fb0f04cf83e0", "email": "john.hill@example.com", "firstName": "John", "lastName": "Hill", "department": "Security Engineering", "location": "New York", "licensed": true, "chatopsEnabled": true, "creationTimestamp": 1698669223 }, "browserId": "2a2197de-ad2c-47e4-8dcb-fb0f04cf83e0", "browser": "CHROME", "severity": "LOW", "detectionType": "PHISHING", "detectionLink": "https://console.pushsecurity.com/app/detections?id=c478966c-f927-411c-b919-179832d3d50c", "response": "BLOCKED", "creationTimestamp": 1698604061, "lastActivityTimestamp": 1698604061, "archived": true, "classification": "FALSE_POSITIVE", "events": [ { "id": "c478966c-f927-411c-b919-179832d3d50c", "creationTimestamp": 1698604061, "detectionEventType": "PHISHING_TOOL_DETECTED", "detectionEventName": "string", "accountId": "37cda962-7e78-49bc-8721-1becd16276a3", "appType": "PUSH_SECURITY", "phishingToolIndicator": "AITM_TOOL_EVILGINX_01", "controlMode": "INFORM", "description": "Phishing attempt detected", "clonedLoginPageIndicator": "MICROSOFT_01", "extensionId": "dljjddkmmcminffjbcmeccgfbjlhmhlm", "extensionName": "Example Extension", "profileEmail": "john.hill@example.com", "maliciousBrowserExtensionIndicator": "EXTENSION_ID", "customIndicator": "TORRENT_MAGNET_LINK", "response": "BLOCKED", "email": "john.hill@example.com", "url": "https://example.com/phishing", "matchedUrl": "https://example.com/phishing", "referrerUrl": "https://mail.google.com", "clonedLoginPageUrls": [ "https://example.com/phishing" ], "sourceIpAddress": "8.158.25.38", "metadata": "{\"source_type\": \"Telegram\", \"breach_type\": \"Stealer Malware Logs\", \"breach_publication_date\": \"2025-04-01\"}", "experimental": false, "domainCategories": [ { … } ] } ] } }