TL;DR: The number of detections shipped each month has tripled by combining human researchers with AI agents to sift trillions of browser events, surface novel attacks like InstallFix, and turn behavioral findings into production detections, according to Push Security. The key lesson is that speed and fidelity come from operationalised context, not bigger blocklists.
At a glance
What this is: Push Security describes an agentic threat-hunting pipeline that pairs human researchers with AI agents to find browser-based attacks and turn them into detections faster.
Why it matters: IAM and security teams should pay attention because browser attacks now target identity flows, and detection quality depends more on context and behaviour than on static indicators.
Context
Browser-based attacks have moved beyond simple malicious links and obvious infrastructure abuse. Modern phishing, malvertising, AiTM kits, device code phishing, OAuth consent abuse, and fake install flows now exploit the browser as both the delivery channel and the control point for identity compromise.
Push Security’s article argues that legacy detection models fail when adversaries rotate domains, gate payloads, or hide behind believable user journeys. The problem is not the absence of alerts alone, but the lack of analyst context that turns browser telemetry into durable detection logic for identity-adjacent attacks.
The article frames agentic threat hunting as an operational response to that gap: human expertise supplies the threat semantics, while AI agents scale the repetitive analysis needed to convert browser events into production detections.
Key questions
Q: How should security teams detect browser attacks when domains and URLs rotate constantly?
A: They should move away from infrastructure-only blocklists and detect the technique instead. Behavioural evidence such as redirects, script execution, credential entry, and page interactions survives domain rotation and gives hunters a more stable basis for browser threat detection.
Q: Why do human researchers still matter in agentic threat hunting?
A: Human researchers supply the context that makes agent output useful. They know which browser behaviours represent a phishing kit, a fake install flow, or a consent abuse pattern, and that knowledge is what keeps agents from producing noisy or shallow results.
Q: What breaks when browser detections rely only on known-bad indicators?
A: The detections age out as soon as attackers rotate infrastructure or serve payloads only to active targets. You may have many detections on paper, but if they depend on reusable infrastructure markers, they will miss technique changes and create a false sense of coverage.
Q: How do teams know if AI threat hunting is actually improving detection?
A: Measure how quickly intelligence becomes an active hunt, how many hunts run continuously, and how often findings map to real adversary techniques rather than noise. If those metrics improve, the programme is becoming more operational. If they do not, the AI layer is only adding complexity.
Technical breakdown
How browser threat hunting shifts from infrastructure to behaviour
Browser attacks are difficult to catch with known-bad lists because domains, URLs, and IPs are easy to rotate. The more durable signal is behavioural: script loading patterns, redirect chains, credential entry, page structure, and what the user does next. That is why techniques such as malvertising, AiTM, ClickFix, and fake install prompts matter more than single-use indicators. A hunt that starts from behaviour can survive infrastructure churn and still detect a campaign even when the attacker swaps hosting, DNS, or landing pages.
Practical implication: build detections around page and user behaviour, not around infrastructure indicators that attackers can replace overnight.
Why context is the control plane for AI-assisted hunting
AI agents are only as good as the context they are given. In this model, telemetry is not just raw logs but a curated corpus of DOM elements, tab state, network traffic, user actions, and researcher-built knowledge about known TTPs. The agents do not replace analysts; they operationalise what analysts already know and then use that context to triage, cluster, and refine findings at scale. Without domain context, agents will miss subtle attack patterns or generate low-value noise.
Practical implication: centralise hunter knowledge and attack context before trying to automate analysis, or the agents will simply accelerate bad judgments.
How an agentic detection pipeline turns findings into production controls
The pipeline described in the article uses multiple agent roles: one to generate hypotheses, another to validate and reduce false positives, and others to triage and deepen the analysis. Once a query is validated, it can become a scheduled detection that continuously monitors for the same technique. This matters because the goal is not just discovery. It is a repeatable path from new technique to deployed detection, with human researchers reviewing quality while agents handle throughput. That architecture makes the detector adaptive without making the control itself fragile.
Practical implication: separate hypothesis generation, validation, and production deployment so that detection engineering can scale without losing review discipline.
Threat narrative
Attacker objective: The attacker wants to convert a trusted browser interaction into credential compromise, malware delivery, or token theft without relying on static infrastructure that is easy to block.
- Entry begins with malvertising and browser-based phishing, where a user searches for a legitimate AI product, clicks a paid ad, and is redirected to a convincing fake page.
- Credential or session abuse follows through a spoofed install flow and a web-based lure designed to capture trust and potentially deliver malware through the browser interaction.
- Impact is achieved when the user is steered into a malicious browser session that can support phishing, token theft, or malware installation while appearing legitimate to the victim.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- Mailchimp breach 2022: Attackers socially engineered Mailchimp staff, used a support tool to export 102 customer lists and exposed customer API keys for phishing.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Behavioural hunting is replacing indicator chasing as the meaningful control boundary for browser attacks. Known-bad domains and URLs are too easy to rotate, which means they no longer describe the real security problem. The durable unit of analysis is the technique, not the infrastructure. Practitioners should treat browser telemetry as a behavioural evidence stream, not a blocklist input.
Agentic hunting only works when human context becomes machine-readable. The strongest part of this model is not the model itself but the conversion of analyst judgment into reusable context, queries, and review loops. That is a governance pattern as much as a detection pattern. Teams that cannot operationalise their own expertise will not scale it through agents.
Browser identity attacks are now shaping the browser security control stack. Malvertising, device code phishing, ConsentFix, and fake install pages show that identity compromise increasingly begins in the browser rather than at the login screen. That forces security and IAM teams to think about browser-layer signals as part of identity defence, not just endpoint defence.
Context is the named control concept here: detection fidelity depends on context density, not model sophistication. The article shows that commercial models can reason over web code, but only after researchers supply the TTP library, browser metadata, and validation workflow. The implication is that context curation is now an operational control, not just an analyst convenience.
AI-assisted detection engineering is becoming a throughput layer for the security function. The article’s two-loop model, where outer-loop learning feeds inner-loop response, is a useful operating pattern for modern teams. It reduces time from discovery to detection and creates a feedback cycle that keeps pace with daily technique drift. Practitioners should design for compounding learning, not one-off automation.
From our research library:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
- Read next: Top 10 Agentic AI Identity Issues
What this signals
Context density is now a defensive control. Browser threat hunting improves when researchers encode real attack semantics into the workflow, because agents cannot infer technique meaning from raw telemetry alone. Teams that want similar results should think about knowledge capture as part of detection engineering, not as an afterthought.
Technique-first detection is becoming the right pattern for browser and identity attacks. When payloads are gated, infrastructure rotates, and lures look legitimate, the only durable signal is the behaviour chain that precedes compromise. That has implications for browser security, IAM monitoring, and incident response alike.
69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey. This article shows why that sentiment extends beyond agent governance into browser-layer identity defense, where user trust and machine speed now intersect.
For practitioners
- Prioritise behavioural browser signals Base detections on redirect chains, script behaviour, page structure, credential entry, and post-click actions instead of relying on domains, URLs, or IPs.
- Operationalise analyst context Turn your best hunters’ knowledge into a reusable TTP library, investigation notes, and validation prompts that agents can use repeatedly.
- Separate hypothesis, triage, and validation Use different agent roles for idea generation, false-positive reduction, and deeper investigation so one step does not contaminate the next.
- Keep browser metadata privacy-preserving Store broad browser metadata locally where possible and query it only during active hunts so detection scale does not become dragnet collection.
Key takeaways
- Browser threat hunting is moving toward behavioural detection because infrastructure indicators are too easy to rotate and too weak to explain modern phishing tradecraft.
- The article’s main evidence is that human context plus AI agents can turn trillions of browser events into usable detections without losing analyst judgment.
- For practitioners, the lesson is to encode TTP knowledge into repeatable workflows so browser-layer identity attacks can be detected before the lure turns into compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP API Security Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI02 — Tool Misuse | Agents here are used to analyse and triage browser threats, so misuse and validation are central. |
| ASI03 — Identity & Privilege Abuse | The article focuses on browser identity attacks and the trust abuse that follows from malicious pages and prompts. | |
| Recommendation — Constrain agent tool use to validated hunt steps and review outputs before promotion to production detections. Map browser attack paths to identity and privilege abuse patterns before they become recurring detections. | ||
| OWASP API Security Top 10 | API10 — Unsafe Consumption of APIs | The detections rely on safe use of external lookups and analysis services inside investigative workflows. |
| Recommendation — Review external service usage in investigative pipelines so analysis tooling cannot be abused or poisoned. | ||
| MITRE ATT&CK | TA0001;TA0006;TA0009 — Initial Access; Credential Access; Collection | The article describes browser-based phishing, credential capture, and user interaction leading to compromise. |
| Recommendation — Map browser phishing hunts to initial access, credential access, and collection tactics to improve coverage. | ||
| NIST CSF 2.0 | DE.AE — Anomalies and Events | Behavioural browser hunting depends on identifying anomalous page and user activity in telemetry. |
| Recommendation — Tune anomaly detection around browser events that indicate phishing kits, redirects, or fake install flows. | ||
Key terms
- Behavioral Detection: A monitoring approach that looks for unusual activity rather than relying only on static inventories. For SaaS integrations, it detects drift in token use, data movement, timing, and endpoint behavior so teams can spot compromise, misuse, or automation that no longer matches its expected pattern.
- Threat Hunting: Threat hunting is the proactive search for signs of compromise that bypassed normal detection controls. It combines logs, telemetry, and investigator judgement to find hidden attacker behaviour before it becomes a larger incident or disrupts recovery.
- Tactic, Technique, Procedure: Tactic, Technique, Procedure, or TTP, is a way of describing attack behavior at three levels of detail. Tactics are the adversary’s goals, techniques are the methods used to reach those goals, and procedures are the specific implementations seen in a campaign or test.
- Agentic workflow: An agentic workflow is a sequence of tasks executed by an AI agent with some level of tool access and decision authority. In security terms, the workflow matters because it can span multiple systems, identities, and permissions, which makes attribution and revocation harder than with ordinary automation.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org