AXS Detection and Protection Engine
The AXS Detection and Protection Engine, built by Palo Alto Networks
Cloud-Delivered Security Services (CDSS) team, is a multi-layered detection system
purpose-built for browser extension threats. It classifies extensions into four
categories: Malicious, High Risk, Medium Risk, and Low Risk.
Inline Analysis: Real-time detection through analyzers such as
Program Taint Analysis, which tracks sensitive data flows and applies JavaScript
deobfuscation to uncover hidden behaviors. At GA, the engine focuses on
high-confidence inline detection.
Threat Intelligence: External intelligence sources enrich detection
— including URL intelligence (AURL) and WildFire threat intelligence — providing
visibility into malicious infrastructure, extension distribution vectors, and
associated malware campaigns.
Key Distinction: Risk (Low / Medium / High) reflects an extension's
potential for harm based on its behavioral profile. Malicious is a definitive
verdict that the extension is actively harmful. An extension can be High Risk
without being Malicious, and a previously Low-Risk extension can be reclassified as
Malicious following a version update.