Coming SoonHijackShield is launching soon. Sign up for early access
Pricing

Two products, one decision

Block the page — or close the Microsoft 365 loop automatically. Same extension and local agent under both; the buy-up is what happens to a block after it fires.

Pricing announced at general availability — schedule a demo below
Detect · block the page

HijackShield Detect

Stop the attack at render

Full render-time phishing defense in the browser. The complete detection engine — nothing reserved for a higher tier.

Includes

  • AiTM, BitM, BitB, device-code, brand impersonation, ClickFix, fraudulent e-commerce
  • Hybrid ML + 100+ heuristic scoring — on-device, explainable reason tags
  • Weaponized-document & PDF-CVE screening
  • PDF Invoice Fraud detection — invoice / AP fraud caught in the document
  • Infostealer credential-theft detection — ETW-based, watches credential stores for non-browser access
  • Dangerous-download protection
  • 24 optional protections + content controls
  • Managed deployment — GPO / Intune / Chrome Cloud
  • SIEM forwarding to any endpoint — Splunk, Elastic, Sentinel, webhook
  • Resilient delivery — disk queue, 24h retry

For: any org that wants the block — stack-agnostic, any SIEM, any browser fleet, any M365 tier.

The moatDetect + Respond · close the loop

HijackShield Detect + Respond

Block it, then erase the source

Everything in Detect, plus the entire Microsoft 365 response layer — Sentinel content and zero-touch tenant-wide auto-purge as one capability. Block to purge in ~8 minutes, no user or analyst action.

Everything in Detect, plus

  • Zero-touch tenant-wide auto-purge via Microsoft Graph to remediate email threat messages
  • Three-scenario intelligence — External / BEC / Internal ATO
  • Token theft detection with token-replay remediation — automatic session revocation when both signals fire
  • Pre-built Sentinel NRT analytics rules + workbook
  • Identity & email-context enrichment on every detection
  • Importable ARM templates — deploy in minutes
  • Self-documenting incidents + auto-close
  • Any M365 from Business Basic up — no Defender P2 / E5
  • Dry-run default · soft-delete · user-report path for BYOD

For: lean SOC or MSP that needs the loop closed without headcount.

SIEM forwarding is table stakes — bundled, never gated — so it sits in Detect, not behind a paywall. The real buyer's fork is detection vs. automated response. The Sentinel content pack and the zero-touch purge it enables are technically inseparable, so they ship as one capability, not two.

For home & family

Personal plans, too

The same detection engine protects individuals and families — phishing and scam blocking, fake-store and checkout-fraud protection, plus content and parental controls. Individual and family plans launch alongside the business products. Start with a 45-day free trial.

Schedule a demo

See it block a live attack

We'll walk you through HijackShield in your own context — how it blocks MFA-bypass phishing at render, and for Microsoft 365 shops, how the source email is purged tenant-wide in minutes with no analyst action.

Prefer email? Reach us directly at sales@hijackshield.ai for early pricing and deployment questions.

Request a demo

Takes 20 seconds. We'll be in touch within one business day.

I'm interested as a…

Helps us tailor the demo — automated remediation works on any M365 plan, Business Basic and up.

No spam. We'll only contact you to arrange your demo.

Detection capability is identical across both products; the only differences are the Microsoft-native integration and automated-response capabilities. Windows today; macOS on the near-term roadmap. Auto-purge ships dry-run by default and uses soft-delete (Recoverable Items — recoverable).