A recent analysis from NordLayer, covered by BleepingComputer, puts words to something those of us in IR have been watching unfold across engagements for the past two years: the browser has become the primary attack surface in the enterprise, and it operates in a space where traditional EDR telemetry is structurally weak. Attackers have figured out that if they can complete their objectives inside a browser session — stealing tokens, abusing extensions, or manipulating the user into doing the work — they never have to drop a payload, spawn a suspicious process, or write a persistence key. No artifacts, no alerts, no forensic trail on the endpoint.
This matters right now because the defensive industry spent a decade hardening the endpoint. EDR coverage in mature organizations is genuinely good at catching commodity malware, LOLBin abuse, and unsigned process execution. Attackers adapted. The result is a class of intrusions — session hijacking, adversary-in-the-middle (AiTM) phishing, malicious browser extensions, and in-browser social engineering like ClickFix — where the first endpoint artifact appears only after the attacker has already authenticated as your user. By then, you're doing incident response, not prevention.
This post breaks down the three evasion techniques NordLayer highlights, explains why each defeats endpoint telemetry, and gives SOC teams concrete detection logic, hunt queries, and hardening steps to close the gap.
Technical Analysis: Three Ways Browser Attacks Evade EDR
1. Session and Token Theft — Authentication Without Artifacts
Modern web authentication is bearer-token based. Once a user authenticates and MFA succeeds, the session cookie or OAuth token is the identity. Attackers exploit this in two ways that both live primarily in the browser:
- AiTM phishing via reverse proxy frameworks (Evilginx-style tooling): the victim interacts with a pixel-perfect proxy of the real login page. Credentials and the MFA-approved session token are captured in transit. The victim's endpoint sees a browser making an HTTPS connection to a lookalike domain — indistinguishable from normal browsing at the process level.
- Cookie and token theft from browser stores: infostealers and hands-on operators target the encrypted cookie databases (
Cookies,Login Data,Local Stateunder Chrome/Edge/Brave profile directories) and DPAPI-decrypt session material. The theft itself is a file read followed by a DPAPI call — milliseconds of activity that blends into baseline noise unless you're explicitly watching for it.
The critical point for defenders: once the token leaves the endpoint, the attacker's subsequent activity happens from their infrastructure, authenticated as your user. Your EDR sees nothing. Your identity provider sees a valid session — from a new ASN, an impossible-travel geography, or a residential proxy — and unless you're correlating identity telemetry, nothing fires.
2. Malicious Browser Extensions — Persistence That Looks Like a Feature
Extensions are the most under-governed execution environment in the enterprise. A malicious or compromised extension can read every page the user visits, inject JavaScript, scrape DOM content (including credentials and session data), modify requests, and exfiltrate over legitimate-looking HTTPS — all within the browser's own process. To EDR, it's just chrome.exe doing chrome.exe things.
The attack vectors we see operationally:
- Sideloaded extensions dropped into the user profile's extension directories or loaded via developer mode.
- ExtensionInstallForcelist abuse: registry/policy keys that force-install an extension by ID — a persistence mechanism that survives browser restarts and looks like admin configuration.
- Compromised legitimate extensions: a popular extension with hundreds of thousands of users gets acquired or its update pipeline is compromised, and the malicious version auto-updates to the entire install base. This is a supply-chain problem that no endpoint agent inspects.
- Consent phishing via extension OAuth grants, where the extension requests broad permissions the user rubber-stamps.
Extension telemetry is simply not in scope for most EDR products. Chrome and Edge extension manifests, permissions, and update behavior live in the browser's own management plane — which is why browser-level controls are the answer, not more endpoint agents.
3. In-Browser User Manipulation — The User Executes the Payload
The third technique is the one generating the most IR volume in 2025-2026: manipulating the user into executing the attacker's commands. ClickFix and its variants present a fake CAPTCHA or "browser update" or "fix this error" dialog inside the web page, instructing the victim to press Win+R, paste a clipboard-injected command, and hit Enter. The JavaScript that poisons the clipboard runs in the browser; the resulting powershell.exe or mshta.exe execution is launched by explorer.exe via the Run dialog — a chain that looks like deliberate user action, not exploitation.
Because the initial delivery is pure in-page social engineering, there is no malicious download, no macro, no exploit. The first endpoint artifact is a user-initiated process execution with a heavily obfuscated command line. If your detections are tuned for parent-child anomalies like Office spawning PowerShell, you'll miss it — the parent is explorer.exe.
Exploitation Status
These are not theoretical techniques. AiTM session theft, infostealer cookie harvesting, and ClickFix-style delivery are all confirmed, high-volume, in-the-wild tradecraft observed across ransomware intrusions, BEC operations, and initial access broker activity throughout 2025 and into 2026. No single CVE applies — this is an architectural blind spot, not a patchable bug. That makes detection engineering and browser-layer controls the remediation.
Detection & Response
The detection philosophy here: you cannot detect what happens purely inside the browser's rendering engine with endpoint process telemetry alone. But every one of these techniques produces secondary artifacts — file access to credential stores, extension writes to the profile, policy registry changes, and user-spawned script interpreters. That is where a SOC can win.
Sigma Rules
---
title: Browser Credential Store Access by Non-Browser Process
id: 3f8a1c92-7e41-4b2d-9c6a-5d1e2f8a9b01
status: experimental
description: Detects non-browser processes reading Chrome/Edge/Brave cookie and credential databases, consistent with session token and cookie theft (infostealer or hands-on operator tradecraft).
references:
- https://attack.mitre.org/techniques/T1539/
- https://attack.mitre.org/techniques/T1555/003/
- https://www.bleepingcomputer.com/news/security/the-edr-blind-spot-3-ways-browser-attacks-evade-endpoint-telemetry/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.credential_access
- attack.t1539
- attack.t1555.003
logsource:
category: file_event
product: windows
detection:
selection_paths:
TargetFilename|contains:
- '\Google\Chrome\User Data\'
- '\Microsoft\Edge\User Data\'
- '\BraveSoftware\Brave-Browser\User Data\'
selection_files:
TargetFilename|endswith:
- '\Cookies'
- '\Login Data'
- '\Local State'
- '\Web Data'
exclusion_browsers:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\brave.exe'
- '\MsMpEng.exe'
condition: selection_paths and selection_files and not exclusion_browsers
falsepositives:
- Legitimate password managers and backup software (whitelist by signer and path)
- Forensic/IR tooling during sanctioned investigations
level: high
---
title: Browser Extension Sideloading or Force-Install via Policy
id: 9c2d4e71-1a63-4f8b-b5d2-8e7f3a6c9d42
status: experimental
description: Detects force-installation of browser extensions via policy registry keys or writes of new extension manifests into user profile directories, consistent with malicious extension persistence.
references:
- https://attack.mitre.org/techniques/T1176/
- https://www.bleepingcomputer.com/news/security/the-edr-blind-spot-3-ways-browser-attacks-evade-endpoint-telemetry/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.persistence
- attack.t1176
logsource:
category: registry_set
product: windows
detection:
selection_forcelist:
TargetObject|contains:
- '\Policies\Google\Chrome\ExtensionInstallForcelist'
- '\Policies\Microsoft\Edge\ExtensionInstallForcelist'
- '\Policies\BraveSoftware\Brave\ExtensionInstallForcelist'
exclusion_admins:
Image|endswith:
- '\sccm\'
- '\IntuneManagementExtension\'
- '\gpupdate.exe'
condition: selection_forcelist and not exclusion_admins
falsepositives:
- Legitimate enterprise extension deployment via GPO/Intune — baseline and whitelist known management processes
level: high
---
title: Run Dialog Spawned Script Interpreter — ClickFix Style Execution
id: 6b1e8a34-2f95-4c7d-a3e1-9d4c7b2e5f83
status: experimental
description: Detects script interpreters or LOLBins spawned directly by explorer.exe with obfuscated or encoded command lines, consistent with ClickFix/fake CAPTCHA clipboard-paste execution where the user is manipulated in-browser into running the payload.
references:
- https://attack.mitre.org/techniques/T1204/002/
- https://attack.mitre.org/techniques/T1059/001/
- https://www.bleepingcomputer.com/news/security/the-edr-blind-spot-3-ways-browser-attacks-evade-endpoint-telemetry/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.execution
- attack.t1204.002
- attack.t1059.001
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\explorer.exe'
selection_image:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\mshta.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\curl.exe'
selection_flags:
CommandLine|contains:
- ' -enc'
- ' -ec '
- 'FromBase64String'
- 'IEX'
- 'Invoke-Expression'
- 'DownloadString'
- 'hidden'
- ' -w h'
- 'mshta http'
- 'javascript:'
condition: selection_parent and selection_image and selection_flags
falsepositives:
- Rare; legitimate admin tooling seldom runs encoded/obfuscated commands from the Run dialog. Tune for IT automation accounts if present.
level: high
A note on tuning: rule one will light up in environments with enterprise password managers that legitimately read browser stores — whitelist by binary signer, not by path alone. Rule two assumes your management plane (SCCM/Intune/GPO) is the only entity that should touch extension force-list policies; any other writer is high-fidelity. Rule three is deliberately scoped to the Run-dialog parent chain specifically to catch the ClickFix user-manipulation pattern without inheriting the noise of generic PowerShell detections.
KQL — Microsoft Sentinel / Defender
This hunt pairs the ClickFix execution pattern with subsequent network egress to flag likely staged payload downloads — the browser is invisible here, but the command line and the follow-on connection are not:
// Hunt: ClickFix-style user-manipulated execution + outbound payload staging
let RunDialogExec =
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName =~ "explorer.exe"
| where FileName in~ ("powershell.exe","pwsh.exe","mshta.exe","wscript.exe","cscript.exe","curl.exe")
| where ProcessCommandLine has_any ("-enc","-ec ","FromBase64String","IEX","Invoke-Expression","DownloadString","mshta http","javascript:","hidden")
| project ExecTime=TimeGenerated, DeviceName, DeviceId, AccountName, FileName, ProcessCommandLine, ProcessId;
RunDialogExec
| join kind=leftouter (
DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemotePort in (80,443,8080)
| where RemoteUrl !has_any ("microsoft.com","windowsupdate.com","office.com","google.com","bing.com")
| project NetTime=TimeGenerated, DeviceId, InitiatingProcessId=ProcessId, RemoteUrl, RemoteIP
) on $left.ProcessId == $right.InitiatingProcessId
| project ExecTime, DeviceName, AccountName, FileName, ProcessCommandLine, RemoteUrl, RemoteIP
| order by ExecTime desc;
For session-theft follow-through, correlate at the identity layer — this is where AiTM actually becomes visible. Hunt for session reuse from anomalous infrastructure in Entra sign-in logs ingested to Sentinel (SigninLogs): look for a single session token (SessionId) authenticated from two or more distinct ASNs or geographies within a short window, especially where one source is a residential proxy or hosting provider range. That correlation — valid token, anomalous source — is the highest-fidelity AiTM indicator available to a SOC, and it lives entirely outside the endpoint.
Velociraptor VQL — Extension Inventory Hunt
Since EDR doesn't inventory extensions, do it yourself. This artifact enumerates every Chrome/Edge extension manifest across user profiles and extracts permissions so analysts can triage for high-risk permission sets (webRequest, cookies, <all_urls>, tabs) or extensions absent from your approved baseline:
-- Hunt: Enumerate browser extensions and permissions across all user profiles
LET manifests = SELECT FullPath, read_file(filename=FullPath) AS ManifestRaw
FROM glob(globs=[
'C:/Users/*/AppData/Local/Google/Chrome/User Data/*/Extensions/*/*/manifest.json',
'C:/Users/*/AppData/Local/Microsoft/Edge/User Data/*/Extensions/*/*/manifest.json'
])
SELECT FullPath,
parse_json(data=ManifestRaw).name AS ExtensionName,
parse_json(data=ManifestRaw).version AS Version,
parse_json(data=ManifestRaw).permissions AS Permissions,
parse_json(data=ManifestRaw).host_permissions AS HostPermissions,
parse_json(data=ManifestRaw).update_url AS UpdateURL
FROM manifests
WHERE Permissions =~ 'webRequest|cookies|<all_urls>|tabs|nativeMessaging'
OR UpdateURL !~ 'clients2.google.com|edge.microsoft.com'
Run this fleet-wide, export the results, and diff against your approved extension list. Any extension with nativeMessaging or a non-store update_url deserves immediate analyst review — that is the sideloading signature.
Hardening & Verification Script
The following PowerShell audits local extension policy state and enforces a default-deny extension posture for Chrome and Edge. Extension allowlisting is the single highest-impact control against technique #2 — run it in audit mode first, inventory what users actually need, then flip to enforcement via GPO/Intune:
# === Browser Extension Hardening: Audit + Enforce Default-Deny ===
# Run as SYSTEM/elevated. Test in a pilot OU before broad enforcement.
$browsers = @{
'Chrome' = 'HKLM:\SOFTWARE\Policies\Google\Chrome'
'Edge' = 'HKLM:\SOFTWARE\Policies\Microsoft\Edge'
}
# --- AUDIT: report current extension policy state ---
foreach ($b in $browsers.GetEnumerator()) {
$path = $b.Value
Write-Host "===== $($b.Key) ====="
foreach ($key in 'ExtensionInstallBlocklist','ExtensionInstallAllowlist','ExtensionInstallForcelist') {
$k = Join-Path $path $key
if (Test-Path $k) { (Get-Item $k).Property | ForEach-Object { Write-Host "$key :: $_ = $((Get-ItemProperty $k).$_)" } }
else { Write-Host "$key :: NOT CONFIGURED" }
}
}
# --- ENFORCE: default-deny all extensions, allowlist explicitly approved IDs ---
$approved = @(
'cjpalhdlnbpafiamejdnhcphjbkeiagm' # example: uBlock Origin — replace with YOUR approved IDs
)
foreach ($b in $browsers.GetEnumerator()) {
$base = $b.Value
if (-not (Test-Path $base)) { New-Item $base -Force | Out-Null }
$block = Join-Path $base 'ExtensionInstallBlocklist'
$allow = Join-Path $base 'ExtensionInstallAllowlist'
New-Item $block -Force | Out-Null; New-Item $allow -Force | Out-Null
Set-ItemProperty $block -Name '1' -Value '*' # block everything by default
for ($i=0; $i -lt $approved.Count; $i++) {
Set-ItemProperty $allow -Name ($i+1) -Value $approved[$i]
}
Write-Host "Enforced default-deny extension policy for $($b.Key)"
}
# --- VERIFY: confirm policies landed ---
foreach ($b in $browsers.GetEnumerator()) {
Get-ItemProperty "$($b.Value)\ExtensionInstallBlocklist" -ErrorAction SilentlyContinue
Get-ItemProperty "$($b.Value)\ExtensionInstallAllowlist" -ErrorAction SilentlyContinue
}
Remediation: Closing the Browser Blind Spot
There is no patch for this — it's an architectural telemetry gap. Remediation is layered:
- Bind sessions to devices and shorten token lifetimes. Deploy phishing-resistant MFA (FIDO2/passkeys) — AiTM reverse proxies can relay OTP and push-based MFA but cannot relay a hardware-bound WebAuthn assertion. Enforce Conditional Access token protection / continuous access evaluation so stolen session cookies fail replay from foreign infrastructure. Reduce session lifetime for high-risk apps and require re-auth on ASN or device change.
- Enforce default-deny browser extension policy. Use Chrome Enterprise / Edge management (or a dedicated browser security platform) to allowlist extensions by ID, block developer mode, and disable sideloading. Audit existing installs with the VQL hunt above before enforcement.
- Deploy browser-layer telemetry. EDR cannot see DOM injection, malicious extension behavior, or clipboard poisoning. Browser-native security controls (enterprise browser management APIs, secure enterprise browsers, or browser detection-and-response tooling) fill exactly this gap — as NordLayer's analysis correctly argues, browser-level controls are the compensating control for an endpoint-level blind spot.
- Harden against ClickFix-style user manipulation. Disable the Run dialog for standard users where operationally feasible, block
mshta.exeand script interpreters for non-admin roles via WDAC/AppLocker, and train users on the specific "paste this command to fix" lure — it is now common enough to warrant its own awareness module. - Correlate identity telemetry in your SIEM. Ingest Entra/Okta sign-in logs and build session-reuse analytics (one session, two geographies/ASNs). This is your highest-fidelity AiTM detection and it requires zero endpoint instrumentation.
- Monitor cookie-store access. Deploy the Sigma rule above (or equivalent EDR custom detections) for non-browser access to browser credential databases, and enable Chrome's App-Bound Encryption where supported to raise the cost of cookie theft.
The strategic takeaway for CISOs: endpoint coverage is necessary but no longer sufficient. Attackers have moved up the stack into the browser session layer. Your detection architecture, your identity controls, and your browser governance need to move with them — or the next IR engagement starts after the attacker is already authenticated.
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.