Traditional endpoint detection and response (EDR) tools focus on artifacts such as processes, files, and system registry changes. But according to security provider NordLayer, browser-based attacks can steal sessions, abuse extensions, or manipulate users without producing the endpoint telemetry EDR is designed to catch.

NordLayer's analysis outlines three evasion paths. Attackers can hijack session tokens or cookies to impersonate authenticated users. They can also exploit malicious or compromised browser extensions, which operate with the user's permissions inside the browser sandbox. In addition, they can manipulate the browser's interface or use social engineering to trick users into performing harmful actions.

Because these techniques may leave no endpoint artifacts, EDR tools can remain blind to the attack. The article suggests that implementing browser-level controls can help close this telemetry gap, advising security teams to extend monitoring and policy enforcement to the browser layer itself.