By NHI Mgmt Group Editorial TeamBased on Push Security: “The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever” (June 1, 2026)

TL;DR: AI has compressed the lifetime of phishing infrastructure and kit reuse, while 89% of phishing domains now disappear within two days and only 6.5% survive past 15 days, according to Push Security; the practical result is that blocklists and tool signatures are losing durability faster than defenders can refresh them. Technique-level detection, backed by browser visibility and faster research cycles, is now the only layer that remains structurally resilient.


At a glance

What this is: This analysis says AI is shrinking the useful lifespan of phishing indicators, so defenders need detections that track attacker technique rather than disposable domains or kit signatures.

Why it matters: IAM, NHI, and SOC teams need detections that survive rapid infrastructure rotation, because indicator-led control loops are increasingly outpaced by machine-speed attack development.

By the numbers:

  • 89% of phishing domains are active for fewer than two days, with just 6.5% surviving past 15 days.
  • Push Security says it is tracking 18+ kits with device code phishing capabilities.
  • Push Security reports a 37.5x increase in device code phishing detections this year alone.
  • CrowdStrike's data shows a 563% increase in fake CAPTCHA incidents.

Context

Indicator-based threat detection fails when adversaries can replace infrastructure faster than defenders can record it. In browser-based phishing, the domain or hosting layer often changes first, while the attacker technique stays stable long enough to be observed and blocked.

The governance problem is not just phishing volume. It is the shrinking window in which any single indicator remains useful, especially when AI helps attackers generate pages, rotate hosts, and industrialize new abuse patterns more quickly than traditional hunting cycles can respond.


Key questions

Q: Where does indicator-based phishing detection fail in practice?

A: It fails when the attacker can replace the indicator faster than the defender can distribute a block or update a signature. In browser-based phishing, domains, hosting, and kit artefacts are now so short-lived that the useful signal shifts to technique, especially page behaviour and session interaction.

Q: Why do browser-based attacks need browser-level visibility?

A: Because the decisive behaviour happens inside the session, not on the network edge. Browser visibility exposes redirect chains, page logic, prompt orchestration, and token-handling steps that proxies and email tools either miss or only infer. That makes it the most reliable vantage point for behavioural detection.

Q: What are the signs that kit-signature hunting is falling behind?

A: You will see more one-off variants, faster domain turnover, and weaker reuse of the same code or hosting patterns. When detections start missing new derivatives of the same attack family, it usually means the environment has moved beyond signature stability and into technique-level variation.

Q: How should defenders balance indicators and technique-level detection?

A: Use indicators for enrichment, investigation, and clustering, but make technique-level behaviour the primary hunting model. That gives you a control that survives rehosting, rebranding, and kit fragmentation while still allowing indicators to support response and attribution.


Technical breakdown

Why phishing indicators expire faster than control loops

Indicators of compromise are concrete artefacts such as domains, hashes, and URLs. They work only while the attacker keeps reusing them. In this article's model, AI shortens the reuse cycle by accelerating page generation, infrastructure rotation, and kit variation. That means the defensive control loop is always reacting after the campaign has already moved. Technique-level detection avoids that trap by anchoring on the behaviour of the attack, not the disposable surface it uses today. In browser-based phishing, the useful signal is in the interaction sequence, script behaviour, and authorisation flow, not the destination host.

Practical implication: Shift hunting away from static indicators and toward repeatable behavioural patterns that survive domain rotation.

What technique-level detection actually observes in the browser

Technique-level detection looks at how an attack behaves during a live session. For phishing and consent abuse, that includes page rendering, credential prompts, clipboard manipulation, device code enrolment, redirect chains, and token hand-off patterns. Those behaviours are visible in the browser session because they happen at the point of user interaction. Network-only tools usually miss them because they see traffic, not user-contextual page logic. The article's core point is that the browser is the right vantage point for detecting attacks that are increasingly built to evade email gateways and infrastructure-level filtering.

Practical implication: Instrument the browser layer if you want reliable visibility into modern phishing and browser-native abuse.

Why kit signatures are becoming a weaker middle layer

Kit signatures used to sit between weak indicators and high-value technique detections. That middle layer is now degrading because kits are forked, cloned, and rebranded quickly, and many share code patterns only briefly. Once a kit family becomes popular, attackers copy the useful parts into derivatives or entirely new builds. A signature that once covered a large portion of activity can rapidly collapse into a narrow slice of the threat landscape. The article argues that behavioural mechanics are therefore a more durable abstraction than code fingerprints or HTML structure alone.

Practical implication: Treat kit fingerprinting as a support signal, not the primary detection strategy.


NHI Mgmt Group analysis

Technique-level detection is replacing indicator hunting because the unit of attack has changed. AI compression has reduced the practical lifespan of domains, kits, and other disposable artefacts. When infrastructure can be generated and replaced in minutes, the control that survives is the one that keys off attacker behaviour rather than attacker packaging. Practitioners should assume the stable object is now the technique, not the indicator.

Browser visibility has become a governance requirement, not a niche telemetry choice. The article's central distinction is that the browser sees interaction mechanics that email, proxy, and network controls cannot reliably reconstruct. That matters because modern phishing, device code abuse, and consent flows are designed to complete inside the session boundary. Defenders that cannot see the session cannot govern the attack path.

Attack technique commoditisation is collapsing the gap between discovery and mass abuse. The article shows how new abuse patterns move from novel to widely available in compressed timeframes, which means detection engineering has to operate at the same pace. This does not remove the need for indicators, but it demotes them to a short-lived reference layer. The durable control objective is to outlast the kit lifecycle, not chase it.

Browser-native identity attacks now require a detection model that is closer to behavioural policy than to signature matching. The more attacks pivot through the browser, the more identity and access teams need to think in terms of how a session behaves, what it requests, and when it diverges from normal interaction patterns. That is the point at which detection becomes an identity control, not just a threat-hunting exercise. Practitioners should align telemetry, response, and research around the behaviour of the session itself.

What this signals

Technique-first hunting is becoming the default posture for browser-based threats. Teams that still optimise around static indicators will continue to lose coverage as phishing infrastructure becomes cheaper to replace and harder to trust. Browser-native visibility changes the economics because it gives defenders a stable observation point even when the adversary's surface changes.

Session behaviour is now the more durable security boundary. When attacks complete inside a browser session, identity teams have to watch for how the page behaves, not just where it resolves. That pushes threat hunting, access governance, and browser control into the same operational plane.


For practitioners

  • Prioritise technique-based detection engineering Build detections around how an attack behaves in-session, including page flow, prompt behaviour, redirect choreography, and token-handling sequence. De-emphasise reliance on domains and one-off kit artefacts that can be regenerated at machine speed.
  • Expand browser-level telemetry coverage Instrument the browser layer so your team can observe DOM activity, user interaction sequence, and malicious page logic that network tools do not expose. Without that vantage point, session-native phishing and consent abuse stay partially invisible.
  • Shorten research-to-detection cycles Treat new abuse patterns as time-sensitive detection content and push high-confidence behavioural rules quickly, before commoditisation spreads them across variants and reskins.
  • Use indicators as enrichment, not as the primary control Keep domains, hashes, and URLs as supporting context for investigation and triage, but do not build your main hunting programme around their persistence.

Key takeaways

  • Indicator-based detection loses value when infrastructure lifetimes are measured in hours or days rather than weeks.
  • The article's evidence shows that phishing kits and new techniques are proliferating fast enough to make static blocklists a shrinking part of the defence model.
  • Defenders that can observe browser sessions and hunt by technique have a more durable control surface than those relying on domains and signatures.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK, OWASP API Security Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0001;TA0006;TA0010 — Initial Access; Credential Access; ExfiltrationThe article centres on phishing delivery, credential capture, and token theft paths.
Recommendation — Map browser-native phishing behaviours to ATT&CK tactics and tune detections to the observed technique chain.
OWASP API Security Top 10API2 — Broken AuthenticationDevice code and consent abuse subvert authentication flows rather than breaking transport or hosting.
Recommendation — Review authentication flows for abuse paths that let attackers steer users into illegitimate token grants.
NIST CSF 2.0DE.CM-01 — Monitoring for Anomalies and EventsThe article argues for higher-fidelity detection based on behavioural monitoring.
Recommendation — Implement continuous behavioural monitoring for browser sessions and treat indicator feeds as secondary inputs.
CIS Controls v8CIS-8 — Audit Log ManagementDetection depends on collecting and reviewing rich session telemetry rather than only static events.
Recommendation — Centralise browser and identity telemetry so hunting can correlate session behaviour with suspicious access events.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationPhishing and consent abuse exploit insecure authentication interactions around browser-based identity flows.
Recommendation — Harden identity flows against browser-mediated authentication abuse and reduce reliance on user-driven trust decisions.

Key terms

  • Technique-level detection: Technique-level detection identifies the method of attack rather than the artefact an attacker used to deliver it. In browser-based identity abuse, that means watching interaction sequences, redirect behaviour, and protocol misuse that remain stable even when infrastructure, domains, and frontends change.
  • Indicator-based detection: Indicator-based detection relies on known bad domains, hashes, URLs, or other reusable artefacts. It is useful when attackers reuse infrastructure, but it degrades quickly when campaigns rotate assets at speed or generate new delivery layers on demand.
  • Browser-layer visibility: Browser-layer visibility is the ability to observe user activity where it actually happens in the web session, including app use, input, consent, and extensions. For AI governance, it becomes the evidence layer that shows what employees used, what data they exposed, and what access they granted.
  • Phishing Kit: A phishing kit is a packaged set of tools that helps an attacker create and run deceptive email campaigns with minimal technical effort. Modern kits often automate message generation, sender manipulation, and delivery testing, which makes abuse faster to launch and harder to distinguish from legitimate messaging at scale.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org