<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Browser Extension Exfiltration Lab in Integration Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/integration-discussions/browser-extension-exfiltration-lab/m-p/1263992#M210</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Companion lab to the MCP Prompt Injection Kill Chain, focused on malicious browser extensions attempting credential exfiltration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What the lab covers&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Five distinct attack patterns, all inert, walking through how a malicious browser extension attempts credential theft under different technique variations. Each pattern includes XSIAM correlation walkthrough illustrating detection surfaces available in AES.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Detection surfaces demonstrated&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Browser extension inventory and permission analysis&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Runtime behavior monitoring for credential access patterns&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Outbound data flow correlation&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;XSIAM case correlation across the five variations&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cortex AES: Browser Extension Exfiltration - Detection Demonstration Lab" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72506i40646C4D0ED73DA3/image-size/large?v=v2&amp;amp;px=999" role="button" title="browser_extension_detection_layers.png" alt="Cortex AES: Browser Extension Exfiltration - Detection Demonstration Lab" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Cortex AES: Browser Extension Exfiltration - Detection Demonstration Lab&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How partners use it&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Deploy the lab on your own Cortex tenant to explore AES detection capabilities before customer engagements. Useful for partner engineering team training and for surfacing browser extension risk in customer conversations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Prerequisites&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Own Cortex tenant with AES enabled. Setup guide included in the package.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Access&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;#links &lt;STRONG&gt;See Attachments&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;InfoSec cleared for partner distribution.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Feedback&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Comments and feedback welcome below.&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;For the most current version of this resource, contact the author directly via LIVEcommunity direct message.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Comments and feedback welcome below.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;#Cortex AES&lt;/SPAN&gt;&amp;nbsp;#&lt;SPAN&gt;Browser Security&lt;/SPAN&gt; &lt;SPAN&gt;Credential Exfiltration&lt;/SPAN&gt; &lt;SPAN&gt;Lab&lt;/SPAN&gt;&amp;nbsp;#&lt;SPAN&gt;Partner Enablement&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Sep 2026 16:33:23 GMT</pubDate>
    <dc:creator>vvadwlas</dc:creator>
    <dc:date>2026-09-09T16:33:23Z</dc:date>
    <item>
      <title>Browser Extension Exfiltration Lab</title>
      <link>https://live.paloaltonetworks.com/t5/integration-discussions/browser-extension-exfiltration-lab/m-p/1263992#M210</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Companion lab to the MCP Prompt Injection Kill Chain, focused on malicious browser extensions attempting credential exfiltration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What the lab covers&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Five distinct attack patterns, all inert, walking through how a malicious browser extension attempts credential theft under different technique variations. Each pattern includes XSIAM correlation walkthrough illustrating detection surfaces available in AES.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Detection surfaces demonstrated&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Browser extension inventory and permission analysis&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Runtime behavior monitoring for credential access patterns&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Outbound data flow correlation&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;XSIAM case correlation across the five variations&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cortex AES: Browser Extension Exfiltration - Detection Demonstration Lab" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72506i40646C4D0ED73DA3/image-size/large?v=v2&amp;amp;px=999" role="button" title="browser_extension_detection_layers.png" alt="Cortex AES: Browser Extension Exfiltration - Detection Demonstration Lab" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Cortex AES: Browser Extension Exfiltration - Detection Demonstration Lab&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How partners use it&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Deploy the lab on your own Cortex tenant to explore AES detection capabilities before customer engagements. Useful for partner engineering team training and for surfacing browser extension risk in customer conversations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Prerequisites&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Own Cortex tenant with AES enabled. Setup guide included in the package.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Access&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;#links &lt;STRONG&gt;See Attachments&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;InfoSec cleared for partner distribution.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Feedback&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Comments and feedback welcome below.&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;For the most current version of this resource, contact the author directly via LIVEcommunity direct message.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Comments and feedback welcome below.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;#Cortex AES&lt;/SPAN&gt;&amp;nbsp;#&lt;SPAN&gt;Browser Security&lt;/SPAN&gt; &lt;SPAN&gt;Credential Exfiltration&lt;/SPAN&gt; &lt;SPAN&gt;Lab&lt;/SPAN&gt;&amp;nbsp;#&lt;SPAN&gt;Partner Enablement&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 16:33:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/integration-discussions/browser-extension-exfiltration-lab/m-p/1263992#M210</guid>
      <dc:creator>vvadwlas</dc:creator>
      <dc:date>2026-09-09T16:33:23Z</dc:date>
    </item>
  </channel>
</rss>

