Spot the phishing kit behind the page.
Secto spots known phishing kits as the page loads and replaces the fake sign-in with a block page.
Animation: a file shared in Teams leads, past a human check, to a cloned Microsoft sign-in. Secto recognizes the phishing kit and shows its "Deceptive site ahead" page in its place.
How the attack gets through
Phishing kits are built to get past your filters.
- 01Phishing-as-a-service
Phishing kits are sold as a service
One kit, Tycoon 2FA, reached more than 500,000 organizations a month before it was taken down.
- 02Cloaking
Scanners get a decoy page
Many kits show scanners a blank page and save the fake sign-in for real visitors.
- 03MFA relay
Relay kits hijack the session
Relay kits pass the MFA prompt through and take over the account.
- 04At page load
Secto recognizes the kit in the page
However the link arrived, the kit has to load in the browser, where Secto spots it.
Phishing defense
What Secto does.
- Detects
- Phishing pages built from known kits
- The employee sees
- A warning page in place of the fake sign-in
- Your security team gets
- The page, the user and how they got there
- Rollout
- Monitor first, then warn or block
Talk to the Secto team.
See Secto in action, from the policy console to the employee’s browser.
Frequently asked questions
Something else?
Talk to a security engineer about your browsers, identity provider and rollout.
Talk to our team- Yes. Secto recognizes the major relay kits, including Evilginx and Tycoon 2FA.
- No. Secto works after the click, whichever channel the link came from. Keep your email filter.
- Yes. Block any site for everyone or for chosen groups.