BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: L.A.Y.E.R.S - Layered Analysis Engine for Browser Ex
 tension\n   Risk and Security\n   Tags: DEF CON Demo Labs | Intermediate |
  AppSec | Offense/Red Team |\n   DEF CON Demo Labs\n   When: Saturday\, Au
 g 8\, 13:00 - 13:45 PDT\n   Where: LVCCW Level 1 Hall 3 901 (Demo Labs Tra
 ck 5) - [1]Map\n\n   Description:\n\n   Browser Extensions is one of the o
 verlooked attack surface in the\n   modern era. Most browser extension hav
 e permissions to allow direct\n   access to cookies\, browsing history\, n
 etwork requests and a poorly\n   written extension can help attackers with
  stuff like silently steal\n   credentials\, log keystrokes\, fingerprint 
 users etc.\n\n   L.A.Y.E.R.S. (Logical Analyst for Your Extension Risk Sur
 face) is a\n   fully client-side chrome browser extension security engine 
 that\n   performs multi-layered security analysis on extensions. The tool\
 n   performs analysis on various levels like JS analysis\, permissions\n  
  analysis\, manifest analysis\, secret scanning\, URL extractions etc.\n  
  simultaneously to uncover potential risks. The tool comes with its own\n 
   scoring system guiding the team if the extension is safe to use or\n   n
 ot.\n\n   L.A.Y.E.R.S. is designed for security researchers auditing in-ho
 use\n   extensions\, third-party extensions\, red teams assessing browser 
 attack\n   surfaces\, enterprises enforcing extension policies\, and devel
 opers\n   seeking to harden their own extensions before publication.\n\n  
  What sets L.A.Y.E.R.S. apart begins with its privacy-first\n   architectu
 re - the entire analysis runs in-browser via the File System\n   API and J
 SZip\, with very little setup required. On the detection side\,\n   it inc
 orporates Shannon entropy analysis. To keep results actionable\n   rat\n\n
    Speakers:Abhinav Khanna\,Krishna Chaganti\n\n   SpeakerBio:  Abhinav Kh
 anna\n\n   Abhinav is an Information Security Professional with 7+ years o
 f\n   experience and currently works at S&P Global. His area of expertise\
 n   include Web App Security\, API Security\, Mobile App Security\, Secure
 \n   Architecture. He has spoken at conferences like BlackHat USA\, DefCon
 \n   33\, BlackHat Europe\, BlackHat Asia etc.\n\n   SpeakerBio:  Krishna 
 Chaganti\n\n   Krishna Chaganti works as Associate Director Application Se
 curity at\n   S&P Global\, based in the USA\, with over a decade of experi
 ence in\n   Information Security. As a Certified Information Security Mana
 ger\n   (CISM)\, he leads a team of more than 10 pentesters and specialize
 s in\n   Application Security along with Security Architecture.\n\n   Link
 s:\n       GitHub - [2]https://github.com/infosecak/layers\n   '\n\n   1. 
 #LVCCW_Level1_Hall3\n   2. https://github.com/infosecak/layers\n\n\n
DTEND:20260808T204500Z
DTSTART:20260808T200000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)
SUMMARY:L.A.Y.E.R.S - Layered Analysis Engine for Browser Extension Risk an
 d Security
END:VEVENT
END:VCALENDAR
