Dodatki do przeglądarki Firefox
  • Rozszerzenia
  • Motywy
    • do Firefoksa
    • Słowniki i pakiety językowe
    • Inne strony
    • Dodatki na Androida
Zaloguj się
Podgląd „PhishTriage”

PhishTriage Autor: Culfig OÜ

One-click phishing triage for Gmail, Outlook Web and any page. Reads nothing until you click Analyze.

0 (recenzje: 0)0 (recenzje: 0)
Pobierz Firefoksa i to rozszerzenie
Pobierz plik

Metadane rozszerzenia

Zrzuty ekranu
O tym rozszerzeniu
PhishTriage tells you whether the thing in front of you is a phishing
attempt.
Open the suspicious email, or the login page that feels
wrong, and click Analyze. You get a verdict with a risk score, the indicators behind it, and what to do next.


On an ordinary web page the extension holds no standing access. It reads
the page under activeTab, which exists only in the moment you click.

One exception, and your browser shows it at install: on Gmail and
Outlook Web (mail.google.com, outlook.office.com,
outlook.office365.com, outlook.live.com) a content script is present
from the start, because that is how the Analyze button reaches the mail
toolbar. Nothing else is touched unless you switch on an optional
feature below.

From an email it sends the subject; the sender, recipient and reply-to
addresses; the body, with quoted threads and signatures stripped; the
links; and attachment filenames, not attachment contents. Who a message
claims to be from is the strongest single signal there is. From any
other page: the title, the visible text, the links, and the full address
including path and query.


A verdict argues; an artifact proves. When a web page you analyze comes
back Malicious or Suspicious, a screenshot of the visible tab and that
page's HTML go up with it, so the site can be reported to its host or
registrar. This is the one setting here that starts on: setup shows
it, and the switch is in the popup. Nothing is captured on a benign
verdict, and nothing on Gmail or Outlook Web, where the screenshot would
be of your inbox. Webmail on any other host counts as an ordinary page,
and there the picture is of your inbox — the privacy policy names the
providers this affects. Both are held in memory for the seconds the scan
takes, never written to your disk. Confirmed malicious is kept 12 months,
suspicious 30 days, and a capture a reviewer clears is deleted at once.


Background protection checks each site as it loads and shows a
full-page warning if it is known bad. Your browser asks permission
first; decline, or revoke later. Only the hostname is sent, not the page
you are on. Separate switches send full URLs instead, and cache a site
for an hour; both off.

File protection (Chrome, Edge, Brave) checks your downloads. A
fingerprint goes up with the file's name, its size, and what the
on-device check made of it; the file itself only when you ask for that
one file, or on every download if you switch on
Deep scan every file. Another switch holds files a page builds in your
browser and asks before they save, instead of warning after. For an
ordinary download the extension fetches the file's address a second time
— a browser hands an extension a download's details, not its contents —
and that request carries your cookies as the first did.


No third-party analytics, advertising or telemetry. No identity
permission: it never asks your browser or your mail provider who you
are. Your install is identified by a random id,
replaced at registration by one our server issues; it registers once at
install, sending that id, your browser name, and an enrolment token if
an administrator set one. The feedback buttons under a verdict record
your correction on your own device and send nothing.


Sign in from the popup and the portal opens to finish the link. An
administrator links the device to your organisation there; the extension
never takes a credential. For a fleet, push an enrolment token by
managed policy and devices join at install. Policy also pins the backend
and sets the monitoring, file-protection, deep-scan and evidence
switches for everyone, in either direction, so on a managed device a
switch may already be on, or held off.
Ocenione na 0 przez 0 recenzentów
Zaloguj się, aby ocenić to rozszerzenie
Nie ma jeszcze ocen

Zapisano ocenę w gwiazdkach

5
0
4
0
3
0
2
0
1
0
Nie ma jeszcze recenzji
Uprawnienia i dane

Wymagane uprawnienia:

  • Mieć dostęp do danych użytkownika na stronie „mail.google.com”
  • Mieć dostęp do danych użytkownika na stronie „outlook.office.com”
  • Mieć dostęp do danych użytkownika na stronie „outlook.office365.com”
  • Mieć dostęp do danych użytkownika na stronie „outlook.live.com”

Opcjonalne uprawnienia:

  • Pobierać pliki oraz odczytywać i modyfikować historię pobranych plików przeglądarki
  • Mieć dostęp do aktywności przeglądarki podczas nawigacji

Wymagany zakres zbieranych danych, według autora:

  • Prywatna komunikacja
  • Informacje identyfikujące osobę
  • Treści witryn

Opcjonalny zakres zbieranych danych, według autora:

  • Działania użytkownika w Internecie
  • Działania użytkownika na witrynach
Więcej informacji
Więcej informacji
Odnośniki dodatku
  • Domowa
  • Pomoc
  • Adres e-mail pomocy
  • Skopiuj identyfikator dodatku
Wersja
1.0.0
Rozmiar
144,31 KB
Ostatnia aktualizacja
9 dni temu (14 sie 2026)
Powiązane kategorie
  • Prywatność i bezpieczeństwo
Licencja
Wszelkie prawa zastrzeżone
Prywatność
Zasady ochrony prywatności tego dodatku
Historia wersji
  • Wszystkie wersje
Etykiety
  • security
Dodaj do kolekcji
Zgłoś ten dodatek
Strona domowa Mozilli

Dodatki

  • O serwisie
  • Blog dodatków do Firefoksa
  • Warsztat rozszerzeń
  • Strefa autora
  • Zasady programistów
  • Blog społeczności
  • Forum
  • Zgłoś błąd
  • Wytyczne recenzji

Pobieranie

  • Download Firefox
  • Windows
  • macOS
  • iOS
  • Android
  • Linux
  • All

Najnowsze kompilacje

  • Nightly
  • Beta

Firefox dla firm

  • Enterprise

Społeczność

  • Connect
  • Contribute
  • Developer

Obserwuj nas

  • Instagram
  • YouTube
  • TikTok
  • Bluesky
  • Podcast
  • Prywatność
  • Ciasteczka
  • Kwestie prawne

O ile nie wskazano inaczej, treść tej strony jest dostępna na warunkach licencji Creative Commons Attribution Share-Alike w wersji 3.0 lub nowszej.