How Browser Attacks Bypass EDR Detection: 3 Ways to Evade Endpoint Telemetry
Endpoint detection and response (EDR) systems face significant challenges when attackers operate within browser-based workflows that mimic legitimate user activity.
The EDR Blind Spot: 3 Ways Browser Attacks Evade Endpoint Telemetry
Endpoint detection and response (EDR) systems are critical for identifying malicious code execution on devices. However, their effectiveness diminishes when attackers operate within browser-based workflows that mimic legitimate user activity. In environments reliant on software-as-a-service (SaaS) platforms, malicious actions often occur without generating traditional endpoint artifacts such as executable files or suspicious processes. This creates a significant gap in visibility for security teams.
The Salesloft Drift Incident: A Case Study
A notable example occurred in 2025 during the Salesloft Drift incident, where the threat group UNC6395 obtained OAuth tokens linked to Drift integrations. These credentials enabled the actors to make high-volume API requests against Salesforce environments, exfiltrating data without deploying malware. The attack exploited the trust placed in authenticated SaaS sessions, bypassing EDR tools that focus on endpoint-level anomalies.
Browsers as the Primary Interface
Browsers have become the primary interface for accessing corporate SaaS applications, identity systems, and administrative tools. According to NordLayer’s 2026 Browser Security Report, 79% of the 504 reviewed applications are exclusively accessible via web browsers. This reliance means that critical user actions—such as authentication, file uploads, and data transfers—often occur without generating the process or file-based indicators EDR systems are designed to detect.
“79% of the 504 reviewed applications are exclusively accessible via web browsers.” – NordLayer’s 2026 Browser Security Report
Adversary-in-the-Middle (AiTM) Phishing Attacks
Adversary-in-the-middle (AiTM) phishing attacks exemplify this challenge. In 2026, the threat actor Microsoft tracks as Storm-2755 leveraged search engine poisoning and malicious advertisements to redirect Canadian employees to a spoofed Microsoft 365 login page. The attackers intercepted authentication credentials, session cookies, and OAuth tokens by proxying the login flow in real time. Microsoft observed the same session ID transition from the victim’s browser to an Axios user agent, indicating token reuse from an attacker-controlled infrastructure.
Malicious Browser Extensions
Malicious browser extensions present another visibility challenge. These add-ons can execute code within browser processes, accessing sensitive data through standard APIs. In March 2026, Microsoft identified malicious Chromium extensions masquerading as AI assistants. Installed over 900,000 times across 20,000 enterprise environments, these extensions harvested visited URLs and content from ChatGPT and DeepSeek conversations, transmitting the data to attacker-controlled servers.
Browser-Level Attacks Without Endpoint Execution
Browser-based attacks can also occur without triggering endpoint execution. Compromised websites, malicious ads, or injected scripts can manipulate session content, redirect users, or alter clipboard data. For instance, ClickFix attacks use deceptive prompts to trick users into copying and executing malicious commands. In August 2026, Microsoft detected a variant of this technique in the TerminalFix campaign, where fake Cloudflare CAPTCHA prompts prompted users to copy PowerShell commands.
Closing the Security Gap: Three Critical Layers
In SaaS-centric environments, security strategies must extend beyond endpoint telemetry. Three critical layers require focused controls: browser activity, identity management, and SaaS access. Web threat protection can block malicious destinations, while extension policies limit unauthorized add-ons. Organizations should also implement browser-specific monitoring to track data exfiltration, unauthorized uploads, and clipboard activity. EDR remains vital for detecting host-based threats, but browser sessions represent a distinct attack surface. Malicious logins, OAuth approvals, and extension interactions often lack endpoint artifacts, necessitating specialized browser-level defenses.
Conclusion
By addressing vulnerabilities at the browser layer, enterprises can close gaps in their security posture and protect sensitive data from sophisticated SaaS-based threats.
