SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsModern web browsers like Chrome, Edge, Safari, and Firefox are ubiquitous, and built-in synchronization capabilities have long since become a standard feature. For even longer, browsers have enabled users to save and edit bookmarks and the names and links stored for each. Where bookmarks were once confined to the device that saved them, this research describes how the ability to synchronize bookmarks across devices introduces a novel vector for data exfiltration and other misuses. As a part of this effort, Brugglemark is a basic PowerShell script that has been created to demonstrate the practical application of the findings presented. Potential countermeasures will also be explored by this paper.