{"id":"1a3f5d25-9af3-445f-bf4c-70f23a61a8e9","name":"Saas Attacks","slug":"saas-attacks","description":"Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown","website_url":"https://pushsecurity.com/blog/saas-attack-techniques","category":["developer","hr","security"],"score":{"overall":54,"raw":54,"capped":false,"verified":false,"breakdown":{"latency":9,"consistency":6,"doc_quality":4,"error_clarity":3,"auth_simplicity":5,"token_efficiency":6,"first_try_success":7,"response_parseability":4},"source":"prowl","credential_tested":false,"probe_health":{"status":"healthy","up_pct":1.0,"samples":3,"target":"website","p50_latency_ms":71,"last_probed":"2026-10-09T04:52:02.413462+00:00","lookback_hours":24,"no_response":0}},"latency":null,"uptime_30d":null,"protocols":["rest"],"auth_type":null,"mcp_manifest_url":null,"openapi_spec_url":null,"verified":false,"domain_verified":false,"claimed":false,"vendor_id":null,"status":"active","profile":null,"pricing":{"model":"unknown","notes":"No pricing information detected. Likely a free educational/content resource, but unverifiable from checks."},"last_crawled":"2026-10-08T20:31:12.289366+00:00","last_benchmarked":"2026-10-07T20:11:01.744695+00:00","supports_x402":false,"agent_auth_methods":null,"supports_streaming":false,"has_sandbox":false,"sdks":null,"llms_txt_url":null,"similarity_score":null,"telemetry_evidence":null,"agent_signal":null,"mycelio":{"signed":false,"source":"heuristic","outline":[{"id":"lets-talk-about-saas-attack-techniques","depth":1,"heading":"Let’s talk about SaaS attack techniques","preview":"Browser attacksIdentity securitySaaS securityThreat landscapeDetection & responseIdentity attacksOAuth abuseCredential p…","size_bytes":269},{"id":"offensive-security-drives-defensive-security-were-sharing-a-","depth":2,"heading":"Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face.","preview":"Our goal at Push is simple — to stop identity attacks. Today, the vast majority of identity vulnerabilities exist in the…","size_bytes":13223},{"id":"the-saas-attack-matrix","depth":2,"heading":"The SaaS attack matrix","preview":"We’ve taken inspiration from the MITRE ATT&CK framework (certainly intended as the sincerest form of flattery), but want…","size_bytes":1544},{"id":"initial-access-and-poisoned-tenants","depth":3,"heading":"Initial access and poisoned tenants","preview":"Attacks like credential stuffing and email phishing that get you initial access to SaaS apps are fairly well known — bec…","size_bytes":1072},{"id":"living-off-the-saas-land-to-persist-and-avoid-detection","depth":3,"heading":"Living-off-the-(SaaS)-land to persist and avoid detection","preview":"In the endpoint world, a favorite technique is the use of legit OS utilities or LOLBaS (Living-Off-the-Land Binaries and…","size_bytes":1693},{"id":"features-or-vulnerabilities","depth":3,"heading":"Features or vulnerabilities?","preview":"When looking for attack techniques, you’re typically going after features that have weaknesses you can abuse rather than…","size_bytes":1154},{"id":"the-saas-market-is-driving-these-offensive-techniques","depth":2,"heading":"The SaaS market is driving these offensive techniques","preview":"SaaS apps are basically web apps that are run in the cloud and accessed from endpoints, so then WebApp, endpoint, and cl…","size_bytes":368},{"id":"modern-saas-is-easy-to-adopt-easy-to-use-low-friction-low-co","depth":3,"heading":"Modern SaaS is easy to adopt, easy to use, low friction, low cost, low overhead","preview":"Making apps easy to sign up for and low effort to support means you need to make some interesting choices when it comes…","size_bytes":528},{"id":"modern-saas-is-highly-integrated","depth":3,"heading":"Modern SaaS is highly integrated","preview":"Most SaaS apps are trying to build app marketplaces or perform well in other apps' marketplaces (often both), and it’s r…","size_bytes":781},{"id":"problems-with-observing-saas-attacks","depth":2,"heading":"Problems with observing SaaS attacks","preview":"This research begs one question above others: “Are we seeing these attacks in the wild?”","size_bytes":92},{"id":"yes-definitely","depth":3,"heading":"Yes, definitely","preview":"For some of the better-known techniques, like credential stuffing and email phishing, the answer is an easy yes. Stats f…","size_bytes":891},{"id":"for-newer-oauth-attacks-its-a-lot-less-clear","depth":3,"heading":"For newer OAuth attacks, it’s a lot less clear …","preview":"Other techniques like consent phishing have been discussed in some breach disclosures like the 2020 SANS breach. These O…","size_bytes":815},{"id":"but-would-we-know-if-it-was-happening","depth":3,"heading":"But would we know if it was happening?","preview":"On the other hand, there is certainly the possibility that these attacks are increasingly used, but are simply not being…","size_bytes":1706},{"id":"whats-next","depth":2,"heading":"What’s next?","preview":"We’ve barely scratched the surface, but perhaps there is enough here to get the discussion going. From past experience,…","size_bytes":1130},{"id":"related-posts","depth":2,"heading":"Related posts","preview":"The shadow workflow’s evil twin: A nearly invisible attack chainIn this article, we’re going to demonstrate how combinin…","size_bytes":661},{"id":"the-shadow-workflows-evil-twin-a-nearly-invisible-attack-cha","depth":3,"heading":"The shadow workflow’s evil twin: A nearly invisible attack chain","preview":"In this article, we’re going to demonstrate how combining two of our favorite new SaaS attack techniques makes a simple,…","size_bytes":194},{"id":"samljacking-a-poisoned-tenant","depth":3,"heading":"SAMLjacking a poisoned tenant","preview":"In this article, we’re going to demo combining two of our favorite new SaaS attack techniques to make a simple, but effe…","size_bytes":173},{"id":"tracking-identity-based-attacks-in-the-wild","depth":3,"heading":"Tracking identity-based attacks in the wild","preview":"To help organizations keep track of how browser-based identity attacks are evolving, we've put together this index of re…","size_bytes":165},{"id":"subscribe-to-get-updates-from-push","depth":2,"heading":"Subscribe to get updates from Push","preview":"The latest news, articles, and resources, sent to your inbox.  Subscribe","size_bytes":72}],"readiness":80,"fetched_at":1791403861,"affordances":[{"kind":"link","label":"Product","target":"https://pushsecurity.com/product"},{"kind":"link","label":"Pricing","target":"https://pushsecurity.com/pricing"},{"kind":"link","label":"Book a demo","target":"https://pushsecurity.com/demo"},{"kind":"link","label":"Press start >>","target":"https://pushsecurity.com/lp/shadow-ai-busters"},{"kind":"link","label":"https://pushsecurity.com/","target":"https://pushsecurity.com/"},{"kind":"link","label":"vs Remote Browser Isolation","target":"https://pushsecurity.com/solution/tool-replacements/remote-browser-isolation"},{"kind":"link","label":"vs Secure Web Gateways","target":"https://pushsecurity.com/solution/tool-replacements/secure-web-gateways"},{"kind":"link","label":"vs Cloud Access Security Broker","target":"https://pushsecurity.com/solution/tool-replacements/cloud-access-security-broker"},{"kind":"link","label":"vs Security Awareness Training","target":"https://pushsecurity.com/solution/tool-replacements/security-awareness-training"},{"kind":"link","label":"+ Email Security","target":"https://pushsecurity.com/solution/tool-replacements/email-security"},{"kind":"link","label":"Stop account takeoverStop ATO with stolen credential and compromised token detection","target":"https://pushsecurity.com/solution/achieve-security-outcomes/stop-account-takeover"},{"kind":"link","label":"Secure AISee and control AI apps in the browser","target":"https://pushsecurity.com/solution/achieve-security-outcomes/secure-ai"},{"kind":"link","label":"Data loss preventionEnforce DLP at the point of interaction in the browser","target":"https://pushsecurity.com/solution/achieve-security-outcomes/investigate-and-stop-data-loss"},{"kind":"link","label":"Secure shadow ITSee and control shadow SaaS in the browser","target":"https://pushsecurity.com/solution/achieve-security-outcomes/secure-shadow-saas"},{"kind":"link","label":"Harden unmanaged identitiesHarden access paths with visibility, detection, and guardrails","target":"https://pushsecurity.com/solution/achieve-security-outcomes/harden-unmanaged-identities"},{"kind":"link","label":"Secure BYODExtend security to unmanaged devices without MDM","target":"https://pushsecurity.com/solution/achieve-security-outcomes/secure-bring-your-own-device"},{"kind":"link","label":"Investigate browser-related incidentsInvestigate and respond faster with unique browser telemetry","target":"https://pushsecurity.com/solution/achieve-security-outcomes/investigate-browser-related-incidents"},{"kind":"link","label":"Secure ChromebooksProtect Chromebooks against in-browser attacks","target":"https://pushsecurity.com/solution/achieve-security-outcomes/secure-chromebooks"},{"kind":"link","label":"Research blogLatestLatest threat research and insights","target":"https://pushsecurity.com/blog"},{"kind":"link","label":"Resource libraryCheck out our webinars and downloads","target":"https://pushsecurity.com/resources"},{"kind":"link","label":"Customer storiesWhat customers love about Push","target":"https://pushsecurity.com/customer-stories"},{"kind":"link","label":"Help centerGuides for employees and admins","target":"https://pushsecurity.com/help/audience/administrators"},{"kind":"link","label":"Browser attacks in 2026The latest stats & analysis","target":"https://pushsecurity.com/resources/browser-attacks"},{"kind":"link","label":"Browser attacks glossaryUnderstand the threat landscape","target":"https://pushsecurity.com/resources/browser-attacks-glossary"},{"kind":"link","label":"Browser attacks matrixMITRE-inspired resource for red & blue teams","target":"https://pushsecurity.com/resources/browser-identity-attacks-matrix"},{"kind":"link","label":"About usMeet the team and learn what drives us","target":"https://pushsecurity.com/about"},{"kind":"link","label":"PartnersBecome a partner and access resources","target":"https://pushsecurity.com/partner"},{"kind":"link","label":"InvestorsLearn more about our investors and advisors","target":"https://pushsecurity.com/about#investors"},{"kind":"link","label":"EventsSee upcoming webinars and in-person events","target":"https://pushsecurity.com/events"},{"kind":"link","label":"NewsStay up to date on company news","target":"https://pushsecurity.com/news"}],"ttl_seconds":86400,"content_length":15281},"featured":false,"sponsored":false,"source":null}