A growing number of cyberattacks are evading traditional endpoint detection and response (EDR) tools by exploiting the very nature of modern computing environments. In today’s cloud-first world, many employees access corporate applications through web browsers, relying on services like Google Workspace, Microsoft 365, or Salesforce to get their work done. But this shift in how we work has created a blind spot for EDR systems, which are designed to detect and respond to malicious activity on endpoint devices.
EDR remains an essential tool for detecting and responding to attacks that involve executing code on the host, but it’s not foolproof. As demonstrated by recent high-profile incidents like the 2025 Salesloft Drift breach, attackers can use legitimate browser-based SaaS activities to steal sensitive data without leaving behind malicious processes or artifacts for EDR to detect.
This is because many corporate applications now rely on OAuth tokens and cloud-based workflows to authenticate users and authorize access. In these scenarios, an attacker’s actions may appear entirely normal from the perspective of endpoint telemetry. For example, an employee may authenticate to a cloud application, approve an OAuth request, open sensitive files, or upload data through a browser session – all without creating new malicious processes that EDR would flag.
One particularly insidious tactic is adversary-in-the-middle (AiTM) phishing. This type of attack involves redirecting victims to a fake login page controlled by the attacker, which then captures credentials and session cookies. The attackers can then replay these stolen sessions to access sensitive information or take control of user accounts. As we’ve seen with recent attacks like those attributed to Storm-2755, AiTM phishing can be devastating for organizations.
In some cases, attackers may also use malicious browser extensions or clipboard-based execution lures to carry out their attacks. These types of tactics can be particularly difficult to detect using traditional EDR tools, as they often don’t create the endpoint artifacts that these systems rely on.
So what’s a security-conscious organization to do? The answer lies in acknowledging the limitations of EDR and implementing additional controls at the browser level. This includes using phishing-resistant authentication protocols like FIDO2 WebAuthn, which tie the authentication response to the legitimate origin and make it much harder for attackers to intercept sessions.
Browser-level controls can also play a crucial role in preventing AiTM attacks. By blocking known phishing destinations, restricting access to unapproved web applications, and enforcing policies around browser extensions, organizations can significantly reduce their attack surface.
To take this approach further, consider implementing a browser that offers centralized control over web access, extension management, file transfers, and clipboard actions – such as the NordLayer Browser. This type of solution provides IT teams with visibility into areas of an attack that EDR may not see clearly, allowing them to respond more effectively to emerging threats.
In conclusion, while EDR remains a vital tool in the cybersecurity arsenal, it’s essential to recognize its limitations and adapt our defenses accordingly. By acknowledging the role of browser-based attacks and implementing additional controls at the browser level, organizations can reduce their exposure to these types of threats and stay ahead of the evolving threat landscape.
Source: Bleeping Computer — 2026-10-02