Two products, one decision
Block the page — or close the Microsoft 365 loop automatically. Same extension and local agent under both; the buy-up is what happens to a block after it fires.
HijackShield Detect
Stop the attack at render
Full render-time phishing defense in the browser. The complete detection engine — nothing reserved for a higher tier.
Includes
- AiTM, BitM, BitB, device-code, brand impersonation, ClickFix, fraudulent e-commerce
- Hybrid ML + 100+ heuristic scoring — on-device, explainable reason tags
- Weaponized-document & PDF-CVE screening
- PDF Invoice Fraud detection — invoice / AP fraud caught in the document
- Infostealer credential-theft detection — ETW-based, watches credential stores for non-browser access
- Dangerous-download protection
- 24 optional protections + content controls
- Managed deployment — GPO / Intune / Chrome Cloud
- SIEM forwarding to any endpoint — Splunk, Elastic, Sentinel, webhook
- Resilient delivery — disk queue, 24h retry
For: any org that wants the block — stack-agnostic, any SIEM, any browser fleet, any M365 tier.
HijackShield Detect + Respond
Block it, then erase the source
Everything in Detect, plus the entire Microsoft 365 response layer — Sentinel content and zero-touch tenant-wide auto-purge as one capability. Block to purge in ~8 minutes, no user or analyst action.
Everything in Detect, plus
- Zero-touch tenant-wide auto-purge via Microsoft Graph to remediate email threat messages
- Three-scenario intelligence — External / BEC / Internal ATO
- Token theft detection with token-replay remediation — automatic session revocation when both signals fire
- Pre-built Sentinel NRT analytics rules + workbook
- Identity & email-context enrichment on every detection
- Importable ARM templates — deploy in minutes
- Self-documenting incidents + auto-close
- Any M365 from Business Basic up — no Defender P2 / E5
- Dry-run default · soft-delete · user-report path for BYOD
For: lean SOC or MSP that needs the loop closed without headcount.
SIEM forwarding is table stakes — bundled, never gated — so it sits in Detect, not behind a paywall. The real buyer's fork is detection vs. automated response. The Sentinel content pack and the zero-touch purge it enables are technically inseparable, so they ship as one capability, not two.
Personal plans, too
The same detection engine protects individuals and families — phishing and scam blocking, fake-store and checkout-fraud protection, plus content and parental controls. Individual and family plans launch alongside the business products. Start with a 45-day free trial.
See it block a live attack
We'll walk you through HijackShield in your own context — how it blocks MFA-bypass phishing at render, and for Microsoft 365 shops, how the source email is purged tenant-wide in minutes with no analyst action.
Prefer email? Reach us directly at sales@hijackshield.ai for early pricing and deployment questions.
Request a demo
Takes 20 seconds. We'll be in touch within one business day.
Detection capability is identical across both products; the only differences are the Microsoft-native integration and automated-response capabilities. Windows today; macOS on the near-term roadmap. Auto-purge ships dry-run by default and uses soft-delete (Recoverable Items — recoverable).