Browser Extension Exfiltration Lab

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Browser Extension Exfiltration Lab

L1 Bithead

Companion lab to the MCP Prompt Injection Kill Chain, focused on malicious browser extensions attempting credential exfiltration.

What the lab covers

Five distinct attack patterns, all inert, walking through how a malicious browser extension attempts credential theft under different technique variations. Each pattern includes XSIAM correlation walkthrough illustrating detection surfaces available in AES.

Detection surfaces demonstrated

  • Browser extension inventory and permission analysis
  • Runtime behavior monitoring for credential access patterns
  • Outbound data flow correlation
  • XSIAM case correlation across the five variations

Cortex AES: Browser Extension Exfiltration - Detection Demonstration LabCortex AES: Browser Extension Exfiltration - Detection Demonstration Lab

How partners use it

Deploy the lab on your own Cortex tenant to explore AES detection capabilities before customer engagements. Useful for partner engineering team training and for surfacing browser extension risk in customer conversations.

Prerequisites

Own Cortex tenant with AES enabled. Setup guide included in the package.

Access

#links See Attachments

InfoSec cleared for partner distribution.

Feedback

Comments and feedback welcome below. 
Note
For the most current version of this resource, contact the author directly via LIVEcommunity direct message.

 

Comments and feedback welcome below.

#Cortex AES #Browser Security Credential Exfiltration Lab #Partner Enablement

 

Best regards,
Vad Vadwlas | Partner Solutions Architect
Cortex Platform | Agentic/AI Security | XSIAM | AI-Driven SOC Enablement
Palo Alto Networks® | 3000 Tannery Way | Santa Clara, CA 95054, USA
Mobile: (301) 697-4925 | www.paloaltonetworks.com

The content of this message is the proprietary and confidential property of Palo Alto Networks, and should be treated as such. If you are not the intended recipient and have received this message in error, please delete this message from your computer system and notify me immediately by e-mail. Any unauthorized use or distribution of the content of this message is prohibited.
0 REPLIES 0
  • 31 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!