@kevinmirsky I don't have any specific resources other than some of my own writing, but imagine the following:
A malicious browser extension is catching your browser logins. And you have Active Directory-joined Okta. Now that browser extension has your AD creds—maybe even your privileged, tiered AD creds—without so much as a nod toward LSASS.
