
Secure Annex
@secureannex
Discover what is hiding in your browser extensions
ID: 1810075589979832320
https://secureannex.com 07-07-2024 22:17:17
22 Tweet
99 Followers
5 Following

VS Code extension analysis! Secure Annex is no longer just browser extensions in Chrome, Edge & Firefox. Analyze and monitor VS Code extensions all in one platform. For as terrifying as browser extension stealing cookies are, IDE extensions basically run in the command line!


tuckner Secure Annex Ok - this needs to go on my todo list now: - if you have a SWG, it should be possible to insert a call to Secure Annex to block low trust installs - if you have osquery , it should be possible to hunt/detecc as part of a pipeline (support for browser extension and vscode

🚨 NEW: Health scores are live in Secure Annex! 0-100 ratings for aspects of extensions that consider current attributes and past events like: Ownership changes Publisher verification status Web store visibility Update frequency +++



Want to know how insecure your browser extensions really are? youtube.com/watch?v=rFlxk8… Recording up from last week where we interview tuckner, founder of Secure Annex, and his workshop he is bringing to ContinuumCon June 20 of "Demystifying Browser Extensions". A lot of











🆕 YARA module this week: Chrome extension bundles! Would be pretty cool to add Mandiant's Permission Hash to the module's output for pivoting fun! Secure Annex exposes Permhash's in their UI/API so this would be a nice CLI format



