Skip to main content
Threat playbooks30 playbooks

Browser threatplaybooks.

The browser is where most modern attacks start: phishing links, malicious downloads, session theft, web exploits, and risky AI usage. These pages explain how each threat shows up in the browser and what isolation changes.

Account & Session Attacks.

View category →

Data Theft & Leakage.

View category →

Deception & Impersonation.

View category →

Malware Delivery.

View category →
Malvertising

Malvertising is when malicious ads deliver scams, phishing, or malware—often by redirecting users to a harmful site after a click (or sometimes on ad load).

Malware Delivery
Drive-by downloads

A drive-by download is when a visit to a website triggers an unwanted download or malware installation—often without the user intending to download anything.

Malware Delivery
Malicious downloads

Malicious downloads are files delivered through the browser that look useful (PDFs, installers, “updates”) but contain malware or lead to it.

Malware Delivery
Fake browser updates

Fake browser updates are deceptive popups or pages that claim your browser is outdated and push a malicious “update” download.

Malware Delivery
Malicious browser extensions

Malicious browser extensions abuse browser permissions to steal data, hijack sessions, inject ads, or redirect users to phishing pages.

Malware Delivery
Exploit kits

Exploit kits are automated toolchains that probe a visitor’s browser for vulnerabilities and deliver a payload if they find a match.

Malware Delivery
Browser zero-day exploits

A browser zero-day exploit targets an unknown or unpatched vulnerability in a browser or its components to execute code or escape the sandbox.

Malware Delivery
Watering hole attacks

A watering hole attack compromises a website that a specific group frequently visits, then uses it to deliver malware or credential theft to that group.

Malware Delivery
Ransomware from browser downloads

Ransomware from browser downloads happens when a user downloads and runs a malicious file delivered via a website, ad, or phishing link.

Malware Delivery

Phishing & Social Engineering.

View category →

Web Exploits.

View category →

Start with these pages.

Access anything.
Expose nothing.

Legba is a disposable real browser: it spawns a clean session, does the work, and destroys itself on close.

chromium / real fingerprint · residential ip · burn on close

Real browser. Real IP. Real page. Spawn a session. Do the work. Destroy it. Off your device. Off your stack. Gone on close.