Citadel browser agent

pinkman

BOSS
Staff member
ADMIN
LEGEND
ULTIMATE
SUPREME
MEMBER
BFD Legacy
Joined
Feb 3, 2025
Messages
2,253
Reaction score
19,016
Deposit
0$
A browser extension that detects malware and shadow IT by analyzing and logging security events in a privacy-preserving manner. Comes pre-integrated with the open-source Wazuh SIEM.

Citadel can perform web filtering, limit the maximum duration of authentication sessions, enforce MFA policies, and assist with password policy enforcement.

Peculiarities

IP, URL or domain is blacklisted (good default blacklists provided, can be bypassable or not by users)
user is using unencrypted protocols for an application (e.g. FTP, HTTP or WS)
user is using URL with username or password in the URL
user has downloaded a file
user has selected a file on the local drive (N.B. it is unknown if the file was uploaded)
user has opened the print dialog for a page (N.B. it is unknown if the dialog was cancelled)
the user is warned that the downloaded file is dangerous
user has accepted downloading of a dangerous file
user has used a password that does not conform to the password policy
user connected using a password but without MFA, when policy requires it for this particular application
security-related browser errors (e.g. certificate issues, detection of phishing or virus, etc. See list)
download:
 
A browser extension that detects malware and shadow IT by analyzing and logging security events in a privacy-preserving manner. Comes pre-integrated with the open-source Wazuh SIEM.

Citadel can perform web filtering, limit the maximum duration of authentication sessions, enforce MFA policies, and assist with password policy enforcement.

Peculiarities

IP, URL or domain is blacklisted (good default blacklists provided, can be bypassable or not by users)
user is using unencrypted protocols for an application (e.g. FTP, HTTP or WS)
user is using URL with username or password in the URL
user has downloaded a file
user has selected a file on the local drive (N.B. it is unknown if the file was uploaded)
user has opened the print dialog for a page (N.B. it is unknown if the dialog was cancelled)
the user is warned that the downloaded file is dangerous
user has accepted downloading of a dangerous file
user has used a password that does not conform to the password policy
user connected using a password but without MFA, when policy requires it for this particular application
security-related browser errors (e.g. certificate issues, detection of phishing or virus, etc. See list)
download:*** Hidden text: cannot be quoted. ***
1
 
Top Bottom