BotCity vs Push Security

Side-by-side comparison of features, pricing, and ratings

Analysis reviewed Live tool data as of 2026-10-08
Cross-checked through our multi-step verification ·
Saved

At a glance

DimensionBotCityPush Security
Target ProblemShadow Python scripts & AI-generated code running on endpointsBrowser-based attacks (AiTM, ClickFix, session hijacking) and AI tool data leakage
Key Detection MethodEndpoint script execution monitoring with risk classificationBrowser telemetry + AI-powered threat hunting
DeploymentEndpoint agent + cloud dashboardBrowser extension (multi-browser) + cloud platform
Pricing ModelContact sales (no transparent pricing)Freemium (free tier available); paid plans likely per-seat
Compliance ReadinessAudit trail for script execution; executive dashboard with risk trendsAudit trail for AI tool usage; supports AI regulations (US, EU, UK)
Recent News ImpactNo recent newsExperienced poisoned tenant attack (2026); advocates browser security over training

Choose Push Security if your primary risk is browser-based attacks (AiTM, session hijacking) and unmanaged AI tool use; its free tier and multi-browser support lower the barrier. Choose BotCity if your biggest blind spot is Python scripts and AI-generated code running on endpoints, and you need governance without blocking productivity — but be prepared for a sales conversation on pricing.

BotCity
BotCity

BotCity is a Python governance platform that discovers, monitors, and controls the Python scripts and AI agents running on enterprise endpoints.

Visit Website
Push Security
Push Security

Push Security delivers browser security for the AI era — stopping AiTM, ClickFix and consent phishing while governing shadow AI

Visit Website
Pricing
Contact Sales
Paid
Plans
—
$5/user/month
Custom
Popularity
7 views
7.5k views
Skill Level
Intermediate
Advanced
API Available
Platforms
Desktop
Web
Categories
🛡️ AI Governance & Guardrails🔒 Security & Privacy
🚨 Threat Detection & SOC🔒 Security & Privacy
Features
Real-time monitoring of Python script execution across endpoints by user, machine, and area
Detects scripts launched from native interpreters, IDEs, and Jupyter notebooks
Traces who wrote each script, what data it touched, and when it ran
Alerts when Python accesses databases, internal APIs, files, and credentials
Each alert includes a description, recommended actions, and the exact code snippet involved
Policy enforcement by runtime with custom policies for use cases and data processing
Library authorization that permits only approved, vulnerability-free dependencies
Vulnerability scanning across script code and imported libraries
Retains a copy of every script for audit, IP protection, and use-case analysis
Executive dashboard analyzing alert recurrence and trends by risk type
Flags suspicious network traffic and atypical Python behavior during execution
Centralized inventory of Python scripts and AI agents by area, user, and machine
Orchestrator: CI/CD pipeline with code versioning and security checks
Isolated runtime environments with dependencies pinned for reproducible production runs
Scheduling with dependency and trigger handling, load balancing, and batch processing with retries and logs
Behavioral phishing detection and blocking inside the browser extension
Real-time Adversary-in-the-Middle (AiTM) reverse-proxy phishing detection
Cloned login page, Browser-in-the-Browser (BitB) and Browser-in-the-Middle (BitM) detection
ClickFix clipboard injection blocking at the point of interaction
Device code phishing detection and blocking of kits that bypass passkeys
Consent phishing detection with OAuth consent monitoring, blocking and app removal
Malicious browser extension inventory, risk scoring, allowlisting and blocking
Supply chain change monitoring for extensions (ownership transfers, permission escalations, delisting)
Infostealer delivery detection and compromise response
Ghost login detection for password fallback paths that bypass SSO
QR code and SMS mobile phishing detection
Credential stuffing detection across SaaS logins
Session hijacking detection via browser session markers
Shadow AI app discovery and agentic browser detection (Comet, Atlas, Dia)
AI prompt, AI clipboard and AI file upload monitoring with blocking
Integrations
Okta
Google Workspace
Microsoft 365
Microsoft Teams
Microsoft Sentinel
Datadog
Splunk
SentinelOne
Slack
REST API

What real users say: BotCity vs Push Security

Not marketing copy and not our opinion — a structured sweep of public discussion (reviews, forums, communities and video comments), showing what people praise and what they complain about for each tool.

BotCity

No verifiable community signal. We scanned public discussion on Sep 9, 2026 and found posts matching the name “BotCity”, but could not establish that they are about this product rather than something else sharing its name. Rather than publish a score built on the wrong subject, we publish none.

Push Security

30 mentions across 3 sources · 34% positive — critical (weighted across 3 sources)

Hacker News, YouTube, Lemmy

What users praise

  • • Interaction-level detection catches ClickFix, OAuth consent phishing and pastes that URL-reputation tools miss
  • • Explicit AiTM, BitB and BitM reverse-proxy coverage addresses the phishing class that beats MFA
  • • Shadow-AI discovery and policy enforcement is a genuinely differentiated control for 2025-era risk
  • • No endpoint agent, no network appliance — deployment is extension-based and fast

What frustrates them

  • • Nearly no independent community reviews — Reddit, Product Hunt and GitHub data is essentially absent
  • • Browser-extension-only coverage leaves non-browser auth paths and mobile-first flows unmonitored
  • • Blocking at the paste/upload/consent level risks interrupting legitimate workflows and generating tickets
  • • Autonomous threat-hunting agents risk adding noise to already-overloaded SOC alert queues

Researched Oct 7, 2026

Who should pick which

  • Security team facing AiTM phishing attacks
    Pick: Push Security

    Push specializes in detecting and blocking AiTM, ClickFix, and session hijacking in real time via browser telemetry.

  • Compliance officer needing AI tool governance
    Pick: Push Security

    Push provides AI tool inventory, DLP controls (clipboard, file uploads), and audit trails aligned with AI regulations.

  • IT governance manager overseeing shadow Python scripts
    Pick: BotCity

    BotCity monitors Python script execution on endpoints, classifying risk and providing code-level alerts — ideal for governing AI-generated scripts.

  • Solo founder with limited budget
    Pick: Push Security

    Push offers a free tier, making it accessible for small teams to start securing browser-based threats immediately.

  • Enterprise with strict endpoint controls (no browser extensions)
    Pick: BotCity

    BotCity deploys as an endpoint agent, bypassing extension restrictions; however, pricing requires sales contact.

Frequently Asked Questions

BotCity vs Push Security: which should you choose?

Choose Push Security if your primary risk is browser-based attacks (AiTM, session hijacking) and unmanaged AI tool use; its free tier and multi-browser support lower the barrier. Choose BotCity if your biggest blind spot is Python scripts and AI-generated code running on endpoints, and you need governance without blocking productivity — but be prepared for a sales conversation on pricing.

Can Push Security block all browser-based attacks?

Push detects and blocks AiTM phishing, ClickFix, ConsentFix, session hijacking, and malicious OAuth grants, but no tool stops every attack.

Does BotCity detect AI-generated code?

Yes, BotCity focuses on Python scripts, including those generated by AI, monitoring their execution and data access.

Which tool is easier to deploy?

Push deploys as a browser extension across multiple browsers; BotCity requires an endpoint agent. Push is generally simpler for browser coverage.

Do either tools support on-premises deployment?

Push is cloud-only; BotCity's deployment model is not specified but appears cloud-based.

Which is better for compliance with AI regulations?

Push explicitly addresses US, EU, and UK AI regulations with browser visibility; BotCity provides audit trails for script execution.

Can I try either tool for free?

Push offers a freemium tier; BotCity requires contacting sales, no free tier mentioned.

Do these tools replace EDR?

No, they complement EDR. Push addresses browser-specific attacks EDRs miss; BotCity covers Python scripts EDRs may not monitor deeply.

Which tool has more recent updates?

Push has multiple news items from 2026; BotCity has no recent news as of this comparison.

More BotCity or Push Security comparisons

Explore each tool further

Browse these categories

Still deciding? Get the weekly AI tools brief

One email a week — new tools, honest comparisons, no spam.

Last reviewed: July 3, 2026