Phishing Shield · Browser protection

Stop phishing before it strikes.

Browser protection with 14 detection engines. It catches what email filters miss: no configuration and immediate deployment.

99.8%detection rate
<0.05%false positives
14detection engines

Fourteen engines. Zero blind spots.

Each engine detects what the others miss. Together they form a defense against the most sophisticated phishing attacks, including those that bypass MFA.

Content cloning detection

Analyzes page structure, DOM elements, and visual design to identify cloned login pages, even perfect copies that bypass URL filters. Powered by its own domain trust database with virtually zero false positives.

Typosquatting

Detects g00gle.com, mircosoft.com, and thousands of similar domains in real time.

Homoglyph detection

Detects Unicode tricks, such as a Cyrillic "a" disguised as a Latin "a" to steal credentials.

AiTM / reverse proxy

Identifies Adversary-in-the-Middle kits: Tycoon2FA, EvilProxy, Sneaky2FA, Evilginx, Modlishka, Caffeine, Greatness. Analyzes headers, timing, and resource patterns in real time.

ClickFix protection

Intercepts clipboard hijacking attacks with Unicode normalization, base64 decoding, and homoglyph detection. Blocks PowerShell, curl, and malicious command injection.

Form hijacking

Detects when a form secretly sends your credentials to an attacker's server using cross-origin action URLs.

QR phishing

Detects quishing attacks: QR codes that lead to credential theft pages.

VNC attack detection

Stops real-time screen sharing attacks where the attacker watches you type. Detects noVNC and WebSocket signatures in the DOM with retry heuristics on MutationObserver.

Session hijacking protection

Continuously monitors token theft even after secure login. Detects cookie and storage mutations with context anomaly scoring.

MFA bypass detection

Alerts when an attacker intercepts your two-factor codes in transit via AiTM token relay.

Threat intelligence

Crosses an own database of over one million trusted domains, curated phishing URL feeds, and over 18,000 known malicious IPs, continuously updated.

Phishing database

Blocks known phishing sites before your employees see the page. Queries in real time the aggregated feeds of PhishTank and OpenPhish.

From download to entire workforce protected in less than an hour.

No network changesNo proxies or TLS decryption: traffic stays on the device.
Automated distributionVia GPO, Microsoft Intune, or any MDM, in minutes.
Chrome, Edge, and ChromiumA lightweight extension on the browser you already use.
Zero frictionWorks in the background without interrupting browsing.

Frequently asked questions about Phishing Shield

How do I protect staff from cloned login pages?

With protection that works in the browser, where the page is viewed. Phishing Shield analyzes the structure and appearance of each login page and blocks it if it is a copy, even if the URL is not on any list.

Does it work against phishing that bypasses MFA?

Yes. Several of its engines detect kits placed between the user and the service to steal sessions, relay two-factor codes, and steal tokens after log in.

Do I need to change the network or install a proxy?

No. It's an extension for Chrome, Edge, and Chromium browsers that runs on the device itself, without proxies or TLS decryption.

How is it deployed across the company?

It's distributed via GPO, Microsoft Intune, or any MDM. A full organization can be protected in less than an hour.

What does the security team see?

Blocked attempts and extension activity reach the Ironchip platform for tracking.

Protect your workforce before the next click.

We show you the extension live on a real phishing kit and deploy it to a pilot group.

What we need for the pilot

  • Browsers managed by GPO, Intune, or your MDM
  • Chrome or Edge in template versions
  • A pilot group of exposed users
  • A channel to alert about what's blocked