Blog Zscaler

Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta

Products & Solutions

Browser Detection and Response: Why Your Security Stack Needs Eyes Inside the Browser

image

Employees spend the majority of their productive working hours in a browser. They access SaaS applications, collaborate on documents, authenticate into corporate systems, and paste sensitive data into GenAI tools, all through a single application that most security teams barely monitor.

Meanwhile, attackers have noticed. The browser is now a prime target, and the techniques being used against it are evolving faster than the defenses in front of it.

The industry has documented a growing catalog of in-browser attack techniques: adversary-in-the-middle (AiTM) phishing, malicious OAuth grants, hijacked extensions, ClickFix social engineering, and session token theft. At the same time, Microsoft's Work Trend Index found that 78% of AI users at work are bringing their own AI tools without IT approval, introducing data exposure channels that legacy controls were never designed to see.

The common thread across all of these threats is that they live and die inside the browser. They do not trigger file downloads. They do not create suspicious processes on the endpoint. They often bypass URL reputation lists entirely. And that makes them invisible to the tools most organizations rely on.

Why Your EDR and Network Security Stack Can't See What's Happening

Endpoint detection and response (EDR) tools focus on inspecting files and processes at the operating system level. Detection begins when a malicious file lands on disk or a suspicious process spawns. But many of today's browser-based attacks never reach that threshold.

A credential phishing page that renders a fake login portal inside an iframe does not write anything to the endpoint. An AiTM proxy that intercepts session tokens operates entirely within the HTTPS session. A compromised browser extension that scrapes DOM content and exfiltrates it over standard HTTPS generates no anomaly at the network perimeter. The Cloud Security Alliance's AI Safety Initiative put it plainly in April 2026: "Traditional enterprise defenses, DLP, CASB, and EDR, have limited or no native visibility into DOM-level browser extension behavior."

Network security tools face similar constraints. Secure web gateways and firewalls inspect traffic at the network layer, relying on URL categorization, domain reputation, and signature-based detection. These controls work well for known threats. They struggle with attacks that abuse trusted infrastructure: phishing campaigns served from compromised legitimate domains, multi-hop redirects gated behind CAPTCHAs, and scripts that execute conditionally based on whether the visitor is a real user or a security scanner.

The result is a structural blind spot. The browser processes identity decisions, renders sensitive content, executes third-party code via extensions, and mediates clipboard activity. None of that activity is visible to tools operating below or outside the browser process.

The Attack Surface Has Expanded Quietly

Several shifts have widened this gap without most security teams noticing.

Extensions became powerful and exploitable. Modern browser extensions interact with web pages through the Document Object Model (DOM), store data locally, integrate with third-party services, and fetch data across multiple applications using browser APIs. Attackers have learned to weaponize this power. In January 2026, Socket researchers uncovered five coordinated Chrome extensions targeting enterprise HR and ERP systems, exfiltrating session cookies and blocking security administration pages to prevent detection. The Cyberhaven supply chain attack followed a similar playbook: a phished developer credential led to a malicious extension update pushed silently to millions of installed instances. Extension whitelisting, the most common management strategy, offers no protection when a previously trusted extension turns malicious after an acquisition or account compromise.

Personal and work activities share the same browser. Employees access the same browser for corporate SaaS apps and personal email, file storage, and social media. This overlap creates policy challenges that go beyond traditional allow/block decisions. A user might paste sensitive financial data into a personal Google Drive, or log into a shadow SaaS tool with corporate credentials, and neither action generates an alert in most security stacks.

AI tools introduced new data exposure channels. A TELUS Digital Experience survey found that 57% of enterprise employees have entered confidential information into publicly available GenAI tools. Copy-pasting source code into a GenAI chatbot, uploading internal documents to an AI summarization tool, or entering customer PII into an AI-powered form: all of these actions happen inside the browser session, beyond the reach of network-layer controls.

What Browser Detection and Response Actually Means

Addressing this blind spot requires detection and response capabilities that operate where the attacks happen: inside the browser itself.

Zscaler’s industry-first Browser Detection and Response (BDR) technology monitors, detects, mitigates, and enables threat hunting for client-side web attacks in real time. The Zscaler Zero Trust Browser delivers BDR in two deployment models: as a lightweight browser extension that can be pushed via standard group policy (through tools like Microsoft Intune or Jamf) to existing browsers like Chrome, Edge, Safari, and Firefox, and as a full Zscaler Browser for organizations that want a purpose-built enterprise browser with BDR capabilities built in from the ground up. Both options deliver the same core BDR protections, giving security teams the flexibility to meet users where they are or standardize on a managed browser, depending on their security posture and workforce requirements.

Monitor: Visibility That Goes Beyond Network Logs

Because BDR operates inside the browser, it captures signals that network and endpoint tools cannot: DOM mutations, website permission changes, browser API calls, user events, file uploads and downloads, clipboard activity, extension behavior, and WebAssembly execution. This telemetry provides the raw material for detecting attacks that never touch the file system or generate suspicious network signatures.

Detect: Covering the Five Critical Attack Vectors

BDR detection spans five categories that map directly to how attackers exploit the browser today:

  1. Sites. Beyond URL filtering, BDR performs real-time analysis of user-browser interaction, content inspection, and DOM changes. This catches advanced techniques like Browser-in-the-Browser (BiTB) attacks, CAPTCHA-gated phishing, and multi-hop redirect chains. Zscaler's BDR detects over 90 unique web attack types using this approach.
     
  2. Files. A client-side file scanner intercepts and inspects every file before a download reaches the endpoint, detecting malicious payloads without sending the file to an external server. On the upload side, it inspects files for PII and sensitive content to prevent data loss through personal accounts.
     
  3. Extensions. Rather than relying on static whitelists, BDR inspects extension behavior and permission changes in real time. When a previously benign extension starts scraping session cookies or injecting scripts after an update, BDR detects and blocks the activity automatically.
     
  4. Identity. Granular policies govern which SaaS applications and authentication methods each user can access, preventing unauthorized OAuth grants, shadow SaaS usage, and credential reuse across sites. This directly addresses the AiTM and device code phishing techniques that have surged recently.
     
  5. Clipboard. Content inspection on copy and paste operations prevents sensitive data from moving to unauthorized destinations: blocking paste into GenAI prompts, preventing copy from enterprise applications, and enforcing policies on a per-site basis.
     

Mitigate: Responses That Keep Users Working

BDR focuses on detecting and surfacing browser-based threats. When a threat is identified, the Zero Trust Browser provides graduated mitigation options beyond simple allow and block, enabling employees to continue working in a safe environment.

For suspicious or risky web content, administrators can set policies to automatically open flagged sites in an isolated session, where all page rendering, script execution, and active content run in a secure cloud container rather than on the user's device. Content is streamed back to the user as safe images, so employees can continue browsing while code execution, exploits, and malware delivery are contained away from the endpoint. This is particularly useful for individuals who travel frequently, such as sales teams, and need secure, disposable browsing sessions while on the road.

Isolation also provides a safety net for unmanaged and BYOD devices. Because isolated sessions deliver images rather than raw HTML and JavaScript, contractors and employees on personal laptops can access sensitive applications without exposing the endpoint to malware or data exfiltration. Security teams can further tighten these sessions by restricting clipboard operations, disabling downloads, or blocking uploads on a per-policy basis.

The combination of BDR's in-browser detection with isolation capabilities creates a layered defense: threats are identified where they execute (inside the browser), and then contained before they reach the endpoint or the network.

Threat Hunt: Enterprise-Wide Attack Intelligence

BDR provides security teams with capabilities that go well beyond alert triage:

  • Attack graphs map the full sequence of sites visited and actions taken before a policy triggered, revealing the attack path in detail.
  • Attack correlation connects related campaigns across the organization, identifying when the same adversary targets multiple employee groups simultaneously.
  • Attack Vision uses DOM reconstruction to replay exactly what a user saw and did in the 30 seconds before a policy hit, giving security teams a definitive view of whether a breach resulted from negligence or malicious intent.
  • A built-in co-pilot generates plain-language reports for each incident, describing what happened, who was affected, and recommended remediation steps.

Why This Matters Now

The traditional approach to browser security has been reactive: block known malicious domains, maintain a static extension whitelist, and hope the EDR catches anything that slips through. That approach was designed for an era when the browser was one of many applications on the desktop, not the primary place where work, data access, and authentication converge.

The shift to browser-as-workplace happened gradually. The security response needs to catch up. With AI-generated phishing now representing more than 80% of observed social engineering activity according to ENISA's 2025 Threat Landscape report, with extension supply chain attacks growing in scale, and with GenAI tools creating new data loss vectors every week, waiting for threats to reach the endpoint or trigger network signatures means accepting that the most consequential attacks will go undetected.

BDR closes this gap by placing detection and response where the attacks actually execute. As a core capability of the Zscaler Zero Trust Browser, available as both an extension and a full enterprise browser, BDR maintains a continuously updated threat detection library that pushes new policies to all users as new attack techniques emerge.

The browser became the enterprise's most critical application. It is time the security stack caught up.

To learn more about how Zscaler Zero Trust Browser protects your organization with industry-first Browser Detection and Response, visit our page or contact a sales representative.

form submtited
Grazie per aver letto

Questo post è stato utile?

Esclusione di responsabilità: questo articolo del blog è stato creato da Zscaler esclusivamente a scopo informativo ed è fornito "così com'è", senza alcuna garanzia circa l'accuratezza, la completezza o l'affidabilità dei contenuti. Zscaler declina ogni responsabilità per eventuali errori o omissioni, così come per le eventuali azioni intraprese sulla base delle informazioni fornite. Eventuali link a siti web o risorse di terze parti sono offerti unicamente per praticità, e Zscaler non è responsabile del relativo contenuto, né delle pratiche adottate. Tutti i contenuti sono soggetti a modifiche senza preavviso. Accedendo a questo blog, l'utente accetta le presenti condizioni e riconosce di essere l'unico responsabile della verifica e dell'uso delle informazioni secondo quanto appropriato per rispondere alle proprie esigenze.

Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta

Inviando il modulo, si accetta la nostra Informativa sulla privacy.