BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: L.A.Y.E.R.S - Layered Analysis Engine for Browser Ex
 tension\n   Risk and Security\n   Tags: DEF CON Demo Labs | Intermediate |
  AppSec | Offense/Red Team |\n   DEF CON Demo Labs\n   When: Friday\, Aug 
 7\, 14:00 - 14:45 PDT\n   Where: LVCCW Level 1 Hall 3 901 (Demo Labs Track
  5) - [1]Map\n\n   Description:\n\n   Browser Extensions is one of the ove
 rlooked attack surface in the\n   modern era. Most browser extension have 
 permissions to allow direct\n   access to cookies\, browsing history\, net
 work requests and a poorly\n   written extension can help attackers with s
 tuff like silently steal\n   credentials\, log keystrokes\, fingerprint us
 ers etc.\n\n   L.A.Y.E.R.S. (Logical Analyst for Your Extension Risk Surfa
 ce) is a\n   fully client-side chrome browser extension security engine th
 at\n   performs multi-layered security analysis on extensions. The tool\n 
   performs analysis on various levels like JS analysis\, permissions\n   a
 nalysis\, manifest analysis\, secret scanning\, URL extractions etc.\n   s
 imultaneously to uncover potential risks. The tool comes with its own\n   
 scoring system guiding the team if the extension is safe to use or\n   not
 .\n\n   L.A.Y.E.R.S. is designed for security researchers auditing in-hous
 e\n   extensions\, third-party extensions\, red teams assessing browser at
 tack\n   surfaces\, enterprises enforcing extension policies\, and develop
 ers\n   seeking to harden their own extensions before publication.\n\n   W
 hat sets L.A.Y.E.R.S. apart begins with its privacy-first\n   architecture
  - the entire analysis runs in-browser via the File System\n   API and JSZ
 ip\, with very little setup required. On the detection side\,\n   it incor
 porates Shannon entropy analysis. To keep results actionable\n   rat\n\n  
  Speakers:Abhinav Khanna\,Krishna Chaganti\n\n   SpeakerBio:  Abhinav Khan
 na\n\n   Abhinav is an Information Security Professional with 7+ years of\
 n   experience and currently works at S&P Global. His area of expertise\n 
   include Web App Security\, API Security\, Mobile App Security\, Secure\n
    Architecture. He has spoken at conferences like BlackHat USA\, DefCon\n
    33\, BlackHat Europe\, BlackHat Asia etc.\n\n   SpeakerBio:  Krishna Ch
 aganti\n\n   Krishna Chaganti works as Associate Director Application Secu
 rity at\n   S&P Global\, based in the USA\, with over a decade of experien
 ce in\n   Information Security. As a Certified Information Security Manage
 r\n   (CISM)\, he leads a team of more than 10 pentesters and specializes 
 in\n   Application Security along with Security Architecture.\n\n   Links:
 \n       GitHub - [2]https://github.com/infosecak/layers\n   '\n\n   1. #L
 VCCW_Level1_Hall3\n   2. https://github.com/infosecak/layers\n\n\n
DTEND:20260807T214500Z
DTSTART:20260807T210000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 901 (Demo Labs Track 5)
SUMMARY:L.A.Y.E.R.S - Layered Analysis Engine for Browser Extension Risk an
 d Security
END:VEVENT
END:VCALENDAR
