
Citadel browser agent Autor: Arno van Wouwe
Citadel is a browser agent that detects malware and shadow IT by analyzing and logging security events in a privacy-respecting way
Na použitie tohto rozšírenia budete potrebovať Firefox
Metadáta rozšírenia
Snímky obrazovky

O tomto rozšírení
Citadel is a browser agent that detects malware and shadow IT by analyzing and logging security events in a privacy-respecting way
Citadel is a browser agent that detects malware and shadow IT by analyzing and logging browser security events to syslog and Windows Event Log a privacy-respecting way. It is meant to be used by CISO and CIO to secure staff laptops, increase situational awareness, verify application of IT policy and allow Digital Forensics and Incident Response (DFIR).
Citadel can download lists of known bad sites and URLs and block access to them.
The following browser security events are detected and reported:
It detects the following events in the browser:
* IP or URL is blacklisted (configurable blacklist)
* the browser has blocked the navigation to the site
* user is using unencrypted protocols for an application (e.g. FTP or HTTP)
* user is using URL with username or password in the URL
* user has downloaded a file
* user has selected a file (n.b. it is unknown if the file was uploaded)
* user has opened the print dialog for a page (n.b. it is unknown if the dialog was cancelled)
* the user is warned that the downloaded file is dangerous
* user has accepted downloading of dangerous file
* user has used a password that does not conform to the password policy
* security-related network errors (see chrome://network-errors)
It also reports on usage statistics of applications, allowing for detection of shadow IT.
Events and reports are written as syslog entries with a relevant level, and can then be consumed by a SIEM or EDR. Citadel comes pre-integrated with the Wazuh, the open source XDR.
Citadel is a browser agent that detects malware and shadow IT by analyzing and logging browser security events to syslog and Windows Event Log a privacy-respecting way. It is meant to be used by CISO and CIO to secure staff laptops, increase situational awareness, verify application of IT policy and allow Digital Forensics and Incident Response (DFIR).
Citadel can download lists of known bad sites and URLs and block access to them.
The following browser security events are detected and reported:
It detects the following events in the browser:
* IP or URL is blacklisted (configurable blacklist)
* the browser has blocked the navigation to the site
* user is using unencrypted protocols for an application (e.g. FTP or HTTP)
* user is using URL with username or password in the URL
* user has downloaded a file
* user has selected a file (n.b. it is unknown if the file was uploaded)
* user has opened the print dialog for a page (n.b. it is unknown if the dialog was cancelled)
* the user is warned that the downloaded file is dangerous
* user has accepted downloading of dangerous file
* user has used a password that does not conform to the password policy
* security-related network errors (see chrome://network-errors)
It also reports on usage statistics of applications, allowing for detection of shadow IT.
Events and reports are written as syslog entries with a relevant level, and can then be consumed by a SIEM or EDR. Citadel comes pre-integrated with the Wazuh, the open source XDR.
Ohodnoťte svoju skúsenosť
PovoleniaĎalšie informácie
Tento doplnok potrebuje:
- Vymieňať si správy s inými programami ako Firefox
- Sťahovať súbory a čítať a upravovať históriu stiahnutých súborov
- Pristupovať k aktivitám prehliadača v priebehu prehliadania
- Pristupovať k údajom pre všetky webové stránky
Tento doplnok vás môže požiadať o:
- Pristupovať k údajom pre všetky webové stránky
Ďalšie informácie
- Odkazy doplnku
- Verzia
- 1.2
- Veľkosť
- 169,91 kB
- Posledná aktualizácia
- pred mesiacom (19. apr 2025)
- Príbuzné kategórie
- Licencia
- Len GNU General Public License v3.0
- História verzií
Pridať do kolekcie
Ďalšie rozšírenia od autora Arno van Wouwe
- Doplnok zatiaľ nie je ohodnotený
- Doplnok zatiaľ nie je ohodnotený
- Doplnok zatiaľ nie je ohodnotený
- Doplnok zatiaľ nie je ohodnotený
- Doplnok zatiaľ nie je ohodnotený
- Doplnok zatiaľ nie je ohodnotený