Browser Shield
Managed browser security: inventory and risk-score extensions, auto-disable the bad ones, block credential-theft pages, and flag any device whose protection is off — priced per device, from one seat to thousands.
What it is
Browser Shield is a managed browser-security product (separate from the Shield WAF). A lightweight extension on each device reports its extension inventory and security posture; the console scores extensions by capability + threat intelligence + deep code analysis, enforces an allow/deny policy, and alerts on credential theft, known-bad sites, ownership changes, and tamper. It spans a single home browser to a 5,000-seat fleet on one engine.
Core capabilities
- Extension inventory + risk scoring — capability, permissions, sideload provenance, store delisting.
- Code analysis — static scan of the
.crxbundle for eval/remote-code, weak CSP, exfil URLs, obfuscation. - Auto-disable — in block mode, denied/malicious extensions are disabled on the device.
- Credential-theft & bad-site blocking — backed by a synced threat feed.
- Malvertising / fake-download detection — flags a risky installer download corroborated as a malvertising chain: either the filename impersonates well-known software (Chrome, AnyDesk, Zoom, TeamViewer, …) while served from a host that isn't the vendor's, or the page that initiated it showed a fake-download / scam interstitial in the last few minutes. Extends the risky-download signal with referrer + install-shape correlation; monitor-only. Only the file type, brand, and serving host are reported — never the path or contents.
- AiTM phishing / session defense — flags an adversary-in-the-middle reverse-proxy (Evilginx / Tycoon 2FA / EvilProxy) rendering a real Microsoft or Google login on a domain that isn't the provider's — the MFA-bypass, session-cookie-theft attack — before the password is entered. (Providers whose login is embeddable on customer domains, e.g. Okta/Auth0/Duo, need the org's sanctioned-SSO-domain list — a follow-up.) Also flags token exfiltration — an auth token (JWT or session cookie) read from cookies/storage and sent verbatim to a different site (the XSS / malicious-third-party-script cookie-theft pattern).
- Privacy & anti-tracking — detects covert WebRTC IP-address leaks (real public IP past a VPN, and internal network IPs) and audio fingerprinting; optional prevention hardens the browser's WebRTC handling and injects inaudible audio noise, with a per-host allowlist.
- DoubleClickjacking / UI-redress — flags a sensitive approval (OAuth consent, wallet/transaction approval, account link) activated immediately after the window regained focus — the focus-steal double-click that hijacks the second click onto a real approval button, bypassing X-Frame-Options / frame-busting. Monitor-only (a timing heuristic).
- Active formjacking / Magecart detection — flags a Luhn-valid payment-card number (on a page with payment fields) or a password's verbatim value leaving the page cross-site to a destination that isn't a known payment processor or identity provider — the skimmer actually firing, upgrading the passive "login page loads N third-party scripts" surface signal to detection of the theft itself. Field values never leave the device; only the classification and destination host are reported. Monitor-only while the processor/IdP exclusion lists soak.
- Push-notification abuse protection — flags a scam-pattern page (fake human-verification, scare text, full-screen overlay) that holds the origin's notification permission — the "click Allow to prove you're human" lure that keeps pushing fake system/antivirus alerts after the tab closes. In block mode with revocation enabled, the device removes the grant via the browser's content settings and verifies it took effect (a failed revoke is reported, never silently assumed).
- OAuth illicit-consent-grant detection — flags an app requesting high-risk scopes (persistent access, mailbox read/write, send-as-you, full file access) on the real Microsoft/Google consent screen — the consent-phishing breach that involves no fake page and survives password resets and MFA. Legitimate apps request these scopes too, so it's a dashboard triage signal (monitor-only), with the scope categories and unverified-publisher flag recorded per event.
- Ownership-change detection — alerts when a Web Store publisher flips (the sold-and-weaponized attack).
- Permission-escalation detection — alerts when a silent update adds a high-risk permission (cookies, all-site access,
webRequest, native messaging) an extension didn't have before — the delta that follows a compromised update pipeline. - Tamper detection — a disabled/removed/dark device is flagged UNPROTECTED, not silently lost.
- SOC integration — webhook/Slack alert fan-out, CSV export, an audit log of every management action.
Privacy & anti-tracking protection
A web page can quietly read more about a device than it should: WebRTC can discover the real public IP (bypassing a VPN/proxy) and enumerate internal network addresses with no permission prompt, and the WebAudioAPI can build a stable, cookieless device fingerprint. Browser Shield sees both from inside the page and reports them to the console.
- Detection is on by default and never modifies a page — it just surfaces what happened, so it's safe to run everywhere.
- Prevention is opt-in per vector (off by default): WebRTC IP handling is hardened at the browser level, and audio read-outs get inaudible noise so a fingerprint can't be correlated across sites. A per-host allowlist exempts trusted video-call and audio apps so they're never degraded.
- Configure it in Manage policy → Privacy & anti-tracking (an admin can also lock a toggle, or force it fleet-wide via MDM). Users can opt in on their own device from the extension's options page unless a toggle is locked.
- The console shows a fleet WebRTC prevention health card — and if prevention was requested but didn't take effect on a device (e.g. another extension controls the browser's WebRTC setting), that device is flagged rather than silently assumed protected.
Getting started
- In the console, Browser Shield → Generate enrollment key.
- Deploy the extension: force-install via your MDM/GPO (see the deploy guide) or have users self-install and paste the key.
- Devices appear within a minute, in monitor mode. Flip to block once the inventory looks right.
Plans
Priced per protected device: Free (1 device, monitoring), Personal and Team(block mode, full detections, console), and Enterprise (MDM deploy, RBAC, audit log, SSO — quoted per device). See pricing.