# pushsecurity/browser-identity-attacks-matrix

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown

Repository: https://github.com/pushsecurity/browser-identity-attacks-matrix
Canonical: https://ross.abutalabs.com/products/browser-identity-attacks-matrix
Homepage: https://pushsecurity.com/blog/saas-attack-techniques/
License: CC-BY-4.0
License Family: other
Topics: offensive-security, saas, web-security
Last push: 2026-04-21T10:27:36+00:00

## Health v2 (maintenance only)
Score: 64/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 78, release rhythm 35, longevity 81
- inputs: {"age_days": 1142, "days_push": 134, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1436, forks 108 (observed 2026-08-28T04:04:43.668329+00:00)

## What it is
A curated knowledge base of browser and identity attack techniques covering SaaS applications, identity providers, phishing, and browser-based threats, formerly known as the SaaS Attacks Matrix. It is a reference resource for security researchers, red and blue teams, and penetration testers rather than runnable software.

## Use cases
- learn SaaS attack techniques for defense
- build red team scenarios for identity attacks
- understand phishing and AiTM techniques
- map browser-based threats for security training
- research OAuth and session hijacking attacks
- prepare purple team exercises for SaaS threats

## When to choose
- you need a structured reference of SaaS and identity attack techniques
- you are training a security team on browser-based threats
- you are a red teamer planning identity-focused attack simulations

## When to avoid
- you need a tool that detects or blocks attacks in production
- you want runnable software or an API
- you need endpoint or network security tooling

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, penetration-testing, documentation
- domain: security, penetration-testing, web-development
- platform: browser
- tags: attack-matrix, saas-security, identity-attacks, phishing, red-team, blue-team, mitre-attck-style, knowledge-base, web-server

## Member repositories
- pushsecurity/browser-identity-attacks-matrix (main) score 64

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:43.668329+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:36:49.034595+00:00, confidence not recorded.
  - readme: https://github.com/pushsecurity/browser-identity-attacks-matrix (fetched 2026-08-28T04:04:43.668329+00:00, sha f0b1f2f4d512)
  - homepage: https://pushsecurity.com/blog/saas-attack-techniques/ (fetched 2026-08-29T11:48:14.204046+00:00, sha ba6cee49e9c7)
  - site_page: https://pushsecurity.com/about (fetched 2026-08-29T11:48:14.223287+00:00, sha b6e24fe33283)
  - site_page: https://pushsecurity.com/pricing (fetched 2026-08-29T11:48:14.214099+00:00, sha a24092da8739)
  - site_page: https://pushsecurity.com/solution/stop-browser-based-attacks/malicious-oauth-integrations (fetched 2026-08-29T11:48:14.218188+00:00, sha da1c720329b0)
  - site_page: https://pushsecurity.com/customer-stories (fetched 2026-08-29T11:48:14.221011+00:00, sha e852509a4118)
  - site_page: https://pushsecurity.com/faq (fetched 2026-08-29T11:48:14.225675+00:00, sha 8ffb9937e190)
- Data as of 2026-08-30T08:39:29.467469+00:00.
