The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

A Blind Spot in Endpoint Detection and Response (EDR) Allows Sophisticated Attacks to Evade Telemetry

Endpoint detection and response (EDR) solutions are designed to monitor and defend against malware and other threats on endpoints. However, a growing trend reveals that attackers are exploiting a blind spot in EDR: browser-based attacks that evade endpoint telemetry altogether. In this article, we’ll explore the mechanics of these sophisticated attacks and why they pose a significant threat to organizations.

In SaaS-heavy environments, employees often access corporate applications through their web browsers. This creates a new attack surface, as attackers can exploit legitimate user actions to steal sensitive data or disrupt operations. For instance, in 2025, attackers used OAuth tokens associated with Drift integrations to make high-volume API calls against customers’ Salesforce environments, resulting in data theft without any malware process for EDR to inspect.

One such attack is adversary-in-the-middle (AiTM) phishing, where malicious actors intercept authentication flows and capture credentials, session cookies, and OAuth access tokens. This allows them to access sensitive information, create inbox rules, or even take control of corporate systems. In a notable example, Microsoft tracked threat actor Storm-2755 as it targeted Canadian employees through search engine poisoning and malicious ads.

The mechanics of AiTM phishing are straightforward: victims are redirected to a login page controlled by the attacker, which then proxies the authentication flow in real-time. The attacker captures credentials and session cookies, which can be reused from an attacker-controlled infrastructure. This creates a blind spot for EDR solutions, as the authentication flow may appear legitimate from an endpoint perspective.

To prevent these attacks, organizations should consider implementing phishing-resistant FIDO2 WebAuthn authentication, which ties the authentication response to the legitimate origin. Additionally, browser-level controls can block known phishing destinations, restrict access to unapproved web applications, and stop the attack earlier.

NordLayer’s Browser Security Report 2026 found that browser access is a critical component of corporate SaaS applications, identity workflows, files, and admin consoles. In fact, 79% of tools are available only through the browser. This makes it essential for organizations to have visibility into browser activity, which EDR solutions may not provide.

By adding browser-level controls with NordLayer Browser, IT teams can gain centralized control over areas of an attack that EDR may not see clearly: web access, browser extensions, file transfers, and clipboard actions. Web threat protection can block phishing and malicious destinations, while extension policies can allow or block specific Chrome extensions. Furthermore, routing browser traffic through a dedicated IP can help organizations allowlist for SaaS access or use as a network condition in identity policies.

In conclusion, the blind spot in EDR created by browser-based attacks poses a significant threat to organizations. By understanding these sophisticated attacks and implementing robust security measures, such as phishing-resistant authentication and browser-level controls, organizations can better protect themselves against this evolving threat landscape.


Source: Bleeping Computer — 2026-10-02