Content cloning detection
Analyzes page structure, DOM elements, and visual design to identify cloned login pages, even perfect copies that bypass URL filters. Powered by its own domain trust database with virtually zero false positives.
Phishing Shield · Browser protection
Browser protection with 14 detection engines. It catches what email filters miss: no configuration and immediate deployment.
Each engine detects what the others miss. Together they form a defense against the most sophisticated phishing attacks, including those that bypass MFA.
Analyzes page structure, DOM elements, and visual design to identify cloned login pages, even perfect copies that bypass URL filters. Powered by its own domain trust database with virtually zero false positives.
Detects g00gle.com, mircosoft.com, and thousands of similar domains in real time.
Detects Unicode tricks, such as a Cyrillic "a" disguised as a Latin "a" to steal credentials.
Identifies Adversary-in-the-Middle kits: Tycoon2FA, EvilProxy, Sneaky2FA, Evilginx, Modlishka, Caffeine, Greatness. Analyzes headers, timing, and resource patterns in real time.
Intercepts clipboard hijacking attacks with Unicode normalization, base64 decoding, and homoglyph detection. Blocks PowerShell, curl, and malicious command injection.
Detects when a form secretly sends your credentials to an attacker's server using cross-origin action URLs.
Detects quishing attacks: QR codes that lead to credential theft pages.
Stops real-time screen sharing attacks where the attacker watches you type. Detects noVNC and WebSocket signatures in the DOM with retry heuristics on MutationObserver.
Continuously monitors token theft even after secure login. Detects cookie and storage mutations with context anomaly scoring.
Alerts when an attacker intercepts your two-factor codes in transit via AiTM token relay.
Crosses an own database of over one million trusted domains, curated phishing URL feeds, and over 18,000 known malicious IPs, continuously updated.
Blocks known phishing sites before your employees see the page. Queries in real time the aggregated feeds of PhishTank and OpenPhish.
With protection that works in the browser, where the page is viewed. Phishing Shield analyzes the structure and appearance of each login page and blocks it if it is a copy, even if the URL is not on any list.
Yes. Several of its engines detect kits placed between the user and the service to steal sessions, relay two-factor codes, and steal tokens after log in.
No. It's an extension for Chrome, Edge, and Chromium browsers that runs on the device itself, without proxies or TLS decryption.
It's distributed via GPO, Microsoft Intune, or any MDM. A full organization can be protected in less than an hour.
Blocked attempts and extension activity reach the Ironchip platform for tracking.
We show you the extension live on a real phishing kit and deploy it to a pilot group.