SquareX Browser Detection and Response: Closing the SWG and EDR Visibility Gap
SquareX’s browser extension turns any browser on any device into an enterprise grade secure browser. SquareX’s industry-first Browser Detection and Response (BDR) solution empowers organizations to proactively defend against browser-native threats including Last Mile Reassembly Attacks, rogue AI agents, malicious extensions and identity attacks. SquareX is the only solution that provides BDR, enterprise browser and browser DLP capabilities in a single extension. Unlike dedicated enterprise browsers, SquareX seamlessly integrates with users’ existing consumer browsers, delivering security without compromising user experience.
In the presentation, Shourya Pratap Singh explains that this solution is necessary because the very definition of an endpoint is evolving. Whereas endpoints were once defined by native applications and local storage, today the browser has become the primary application platform where most organizational work occurs. This shift means that the attack surface has also moved to the browser. Singh argues that traditional security tools, which were designed when browsers were simple rendering tools, are no longer sufficient. The modern browser is a complex ecosystem with advanced protocols and capabilities, making it impossible to infer all threats simply by inspecting network traffic, as was possible in the past. This complexity creates a significant visibility gap for existing security stacks.
Singh details how both Endpoint Detection and Response (EDR) and Secure Web Gateway (SWG) solutions fail to close this gap. EDR tools have limited visibility because the browser operates as a “closed box,” preventing them from seeing threats that live and die entirely within it, such as malicious extensions, identity-based consent attacks, or threats delivered via WebAssembly. Likewise, network-based SWG solutions lack the application context to detect advanced evasions. Singh uses the example of “Last Mile Reassembly Attacks,” where a malicious file is broken into individually benign chunks that pass through network security, only to be reassembled into a threat by JavaScript on the client side. By operating as a browser extension, SquareX’s BDR provides the necessary in-browser visibility to detect and respond to these modern, evasive threats that bypass traditional security controls.
Presented by Shourya Pratap Singh, Principal Software Engineer. Recorded live at Security Field Day 14 in Silicon Valley on September 25, 2025. Watch the entire presentation at https://techfieldday.com/appearance/introducing-squarex-at-security-field-day-14/ or visit https://techfieldday.com/event/xfd14/ or https://sqrx.com for more information.
Transcript
Hello everyone. Uh, this is Shari here, and, uh, so happy to be here and share you all what we have been doing. So, uh, the talk is called, uh, browser Detection and Response, uh, closing the SWG and EDR Gap Visibility Gap.
So a little bit long title, but they will not dip, uh, go into much more detail on what are the gaps currently with existing security setups and how exactly browser security comes into play. So, uh, uh, so just to give you a brief on what all things we're gonna cover. So, uh, we'll first talk about, uh, the, the, the use case of having browser security, how exactly it fill in, what are the different, uh, you know, uh, situations where you would want to have a good browser security control in place.
And, uh, lastly, you know, of course there is no security field unless we talk about the architecture. So we'll go into much more detail on the browser extension architecture in particular, and see how we went ahead and, you know, created a, a, a product from the ground, uh, for, for, uh, for protecting against all these kind of browser native attacks. So, a little bit about me.
So I'm Shari and I'm the principal software engineer at Square. My background is mainly on browser extension and browser security. Um, I was part of the team from the very start, and we have been working together to, uh, to, to create all this, this, this product from the ground up.
Uh, I'm part of the team that architected the browser extension, uh, a a little bit of my security background. So I've presented multiple times mainstay stock at DEFCON this year and last year. And I've also, uh, like, you know, put up my work in, uh, blackhead Europa.
I've also taken workshops on browser extension and malicious browser extension, particularly at Texas Cyber Summit before. So happy to be here. So before we start, I think it's important to understand a bit about the company.
So Squa Ex started as of today, like, uh, two and a half years back. Uh, it's founded by VE Chandrin. Uh, he's basically, uh, a person who has been the secure industry for quite some time, and he has given more than 25 plus stocks at Defcon.
Uh, and, and Blackhead main stage. He's also discovered multiple, uh, zero day vulnerabilities. Uh, he also founded a company previously called Pen Tester Academy, which later got acquired.
Uh, he is also a part of the, uh, he also created this company, which was on wireless monitoring, which was being used by the Department of Defense. He also holds the title of, uh, Microsoft Regional Director, which is given, uh, as an or title only to selective, uh, security folks all over the world. And he's also currently the Black Arsenal Review board member.
So, uh, if we talk about the company, so we have raised so far, uh, 30 million plus, uh, and we had Sequoia, uh, peak, peak xe. Then Syn Ventures join us. So, yeah, um, a little bit about the company and Vic.
Okay, so I think let's start off with understanding, uh, the whole notion of how endpoint as a definition is evolving. So on the left side, if you see here, uh, this is How you know, years back, if you look at endpoint, we would think like, right, so you have your apps, which most of them are native, right? And then you have your storage, which, uh, is like, you know, everything is local.
You're using a lot of USB drives, you, you're saving most of your information on your machine, and most of the threats that are happening are also like, you know, on your device. So the way they are entering there in the device is probably like, you know, from, uh, the older perspective of an endpoint. Similarly, when we talk about identity, uh, uh, a lot about identity is mainly around what kind of users you are using inside the operating system and things like that.
However, uh, nowadays if you look at the current escape, the definition is slightly evolving because most of the work that, uh, people are doing in the organization is shifted, uh, to the browser. In fact, I would say that some departments don't even use anything outside browser for most of the use cases. Uh, we still see people using some applications outside, probably like, you know, outlook or Slack.
But other than that, most of the work that you do is mainly on the browser, and that's how, you know, the definition is also evolving. So most of the attacks are sort of coming via the browser, and the same thing goes for, you know, all the different kind of identities as well. So when we talk about identities, we are talking about identities of the applications you're signing into.
So the definition is evolving, and the attack scape is also evolving. Okay? So now, uh, you know why, uh, the browser is now an application platform, right?
Why it is so important now. So if you look years back, uh, browser was like a very basic, you know, consumer piece, uh, just like a simple software, which is rendering stuff, which is coming from service. And at that point of time, uh, it was very easy to infer all the attacks by just looking at network traffic.
But nowadays the browser itself has become too much complicated. We have Chrome OS now, which is literally, you know, a whole operating system, just, you know, written out of like, uh, chromium code base, right? And because of that, uh, because the whole scape is, you know, evolving so much, we have so many new protocols, like we have web RTC, we have web sockets, we have so many different things, and inspecting all of them is just not possible, uh, entirely at a network layer.
So just looking at network traffic, uh, you know, uh, inferring all application based attacks is simply not possible. And that's the reason why, you know, uh, the way, if you look at, you know, all the different, uh, companies, they have all evolved over time looking at how the scape is changing. So earlier, you know, network base was very easy to infer.
So that's how the company started. And, and at the current time, because of the way there are so many complex things happening and dying within the browser, it's important to also have something within the browser to look at these things. So, you know, these are just couple of, uh, companies who are targeted.
Uh, these are all picked up from, uh, news articles around, and all the different bubbles that you see here are directly or indirectly delivered via the browser. And this is something that, you know, most of the organizations are falling victim to, and many a times they don't even have visibility on how it actually came through. And, uh, square X particularly has been, you know, uh, at a bit forefront.
So we have been, uh, constantly researching on how browser security is coming. These are like couple of research that we have done over the past few years, which was covered by, you know, a lot of different vendors. Okay, so now talking specifically about the three major pillars of browser based protection.
Uh, the first one is browser detection and response, which talks about protecting against any kind of attack that happens via the browser. Now this could include your identity attacks, this could include your malicious extensions. This could include phishing pages, which are obfuscated and delivered in a really complicated way on the browser.
So anything that comes inside the browser, uh, that's where, you know, we call this category as browser detection response. So think of it like, you know, an EDR, but inside the browser, uh, the second category is mainly, you know, uh, use cases, which enterprise browser, uh, uh, vendors are basically pitching, which is mainly around private access. So we'll cover that a little bit towards the end as well.
And third is the browser, DLP. So first, you know, diving in into the browser detection and response. So, uh, let's look at, you know, what EDRs can solve currently.
So if you look at, you know, anything that is happening and dying within the browser, like for example, an identity based attacks, uh, let's say, you know, someone has sent a link which contains like a permission, a consent based attack, where they're asking permission for something very sensitive. So you're sort of relying more on what controls your E Ds can do from that perspective. And that's something they have some limitations on because browser in itself is a very closed box.
Anything that goes outside or anything that comes in is what they have visibility on. Second is like there are many, uh, you know, formats like web assembly, uh, which is also being used very extensively by the websites. Examples are websites like, you know, Figma who use it very extensively to do, uh, you know, very intensive work on the web applications.
And that's where, you know, it becomes very tricky because this is not like a simple JavaScript file you can just look at and say like, you know, Hey, this is something doing, uh, of a scale, because that's like a binary file, and that binary file is living and dying within the browser. The same goes for browser extensions, the same goes for brow, you know, browser ransomware as well. This is all something very interesting, which is coming these days.
So, yeah, so all these categories is something that e ds need to evolve to, and they need to have something to take a look at what's happening inside the browser. Now, can, uh, SS ESSE or SWG solve this? So this is something that, uh, you know, uh, again, like as part of the research we have done, we have covered.
So they don't really have the context about the webpage. So just to give you a very basic example, one of the, uh, attacks that we have seen, uh, what happens is, like, let's say there's a tab, and on that tab there's a simple file that needs to be downloaded. So what attacker can do is they can just break that file into multiple chunks, and all these individual chunks are loaded as different network requests.
On the client side, JavaScript, you just stitch all those chunks together and trigger a download. So what happens is that looking at those individual network requests, a, a a, a proxy based solution cannot figure out that as a whole, it's gonna be a malicious file, but the moment it goes on the client side, you're, you're sort of just relying on your EDR, then like, you know, the file is downloaded and you're just relying on your EDR to figure out like whether it'll stop it. So all your controls just goes back to your last set of controls that you have, which is on the device.
So that's like, you know, one of the few gaps that we have seen, uh, where, uh, you cannot infer everything at a network level. That's just not possible. So as they don't have any kind of web app context as they don't have, uh, you know, uh, uh, knowledge about how the user is interacting to the page, uh, an example of that would be like, you know, let's say you have a phishing page, which is fully protected by a capture check.
Now what happens is, like, unless and until you complete the capture check, the login form will not appear. So any cloud-based scanning that is happening on that page, uh, we'll just have to rely the fact whether to call it suspicious or not, maybe just looking at the domain. Nothing more than that.
So that's where like, you know, all these things which are application level sort of brings that gap in place. Um, you know, this is something that was also admitted by, you know, uh, uh, Palo Alto networks very recently on their September uh, press release where they have mentioned that encrypted evasive attacks that assemble inside the browser can bypass traditional secure web gateways. And that's why like, you know, they're trying to, uh, push the narrative for, you know, having a browser based solution as well in place.
And this is something that we covered, you know, last year at Defcon main stage where we presented the last mile reassembly attacks, which are basically different ways of assembling these files of phishing pages, right on our browser side, bypassing all the traditional secure web gateway controls.