tag: Proxy · 2 items
- Engineer — Plan: Extensions impersonating legitimate tools and silently proxying browser traffic is a real enterprise risk if employees install free VPNs on managed Chrome instances. Audit installed extensions across corporate devices and enforce an allowlist policy to block unapproved extensions.
- SOC/IR — Learn: Browser extension-based traffic interception is a useful TTP to understand, but the summary provides no IOCs, C2 infrastructure details, or SIEM/EDR-actionable signals — primarily consumer-targeted with no immediate detection engineering opportunity.
- Leader — Skip
- Engineer — Plan: Audit any corporate-managed Chrome extensions against a blocklist of the 737 identified fakes; establish a policy requiring allowlisted extensions only for managed devices.
- SOC/IR — Plan: Build detection for unusual SOCKS5 proxy egress from endpoints, and consider hunting for browser extension IDs associated with this campaign in endpoint telemetry.
- Leader — Learn: Illustrates scale of Chrome Web Store supply-chain risk for enterprise endpoints; useful context for policy decisions around browser extension governance, but no immediate board-level action required.