Browser Shield

Managed browser security: inventory and risk-score extensions, auto-disable the bad ones, block credential-theft pages, and flag any device whose protection is off — priced per device, from one seat to thousands.

What it is

Browser Shield is a managed browser-security product (separate from the Shield WAF). A lightweight extension on each device reports its extension inventory and security posture; the console scores extensions by capability + threat intelligence + deep code analysis, enforces an allow/deny policy, and alerts on credential theft, known-bad sites, ownership changes, and tamper. It spans a single home browser to a 5,000-seat fleet on one engine.

Core capabilities

  • Extension inventory + risk scoring — capability, permissions, sideload provenance, store delisting.
  • Code analysis — static scan of the .crx bundle for eval/remote-code, weak CSP, exfil URLs, obfuscation.
  • Auto-disable — in block mode, denied/malicious extensions are disabled on the device.
  • Credential-theft & bad-site blocking — backed by a synced threat feed.
  • Ownership-change detection — alerts when a Web Store publisher flips (the sold-and-weaponized attack).
  • Tamper detection — a disabled/removed/dark device is flagged UNPROTECTED, not silently lost.
  • SOC integration — webhook/Slack alert fan-out, CSV export, an audit log of every management action.

Getting started

  1. In the console, Browser Shield → Generate enrollment key.
  2. Deploy the extension: force-install via your MDM/GPO (see the deploy guide) or have users self-install and paste the key.
  3. Devices appear within a minute, in monitor mode. Flip to block once the inventory looks right.

Plans

Priced per protected device: Free (1 device, monitoring), Personal and Team(block mode, full detections, console), and Enterprise (MDM deploy, RBAC, audit log, SSO — quoted per device). See pricing.