Spot the phishing kit behind the page.

Secto spots known phishing kits as the page loads and replaces the fake sign-in with a block page.

See how it happens

Animation: a file shared in Teams leads, past a human check, to a cloned Microsoft sign-in. Secto recognizes the phishing kit and shows its "Deceptive site ahead" page in its place.

How the attack gets through

Phishing kits are built to get past your filters.

  1. 01
    Phishing-as-a-service

    Phishing kits are sold as a service

    One kit, Tycoon 2FA, reached more than 500,000 organizations a month before it was taken down.

  2. 02
    Cloaking

    Scanners get a decoy page

    Many kits show scanners a blank page and save the fake sign-in for real visitors.

  3. 03
    MFA relay

    Relay kits hijack the session

    Relay kits pass the MFA prompt through and take over the account.

  4. 04
    At page load

    Secto recognizes the kit in the page

    However the link arrived, the kit has to load in the browser, where Secto spots it.

Phishing defense

What Secto does.

Detects
Phishing pages built from known kits
The employee sees
A warning page in place of the fake sign-in
Your security team gets
The page, the user and how they got there
Rollout
Monitor first, then warn or block

Talk to the Secto team.

See Secto in action, from the policy console to the employee’s browser.

Visit the Trust Center

Frequently asked questions

Something else?

Talk to a security engineer about your browsers, identity provider and rollout.

Talk to our team
  • Yes. Secto recognizes the major relay kits, including Evilginx and Tycoon 2FA.