Turning Browser Telemetry Into Evidence-Backed Investigations
.png)
.avif)
.avif)
The browser has become one of the most important security control points in the enterprise.
It is where employees access SaaS applications, upload and download files, interact with GenAI tools, use admin consoles, copy data between systems, and authenticate into critical business applications. Yet for many security teams, browser activity is still not fully connected to the investigation workflow.
That creates a gap.
Endpoint tools may show what happened on a device. Identity systems may show how a user authenticated. Cloud and SaaS tools may show application activity. But the browser often explains the path between those signals: what the user visited, what file was uploaded, what was downloaded, what policy was applied, and what happened immediately before or after an alert.
That is why Daylight built an integration with Island.
Island provides enterprise browser visibility and control. Daylight turns that telemetry into detections, investigations, enrichment, and evidence-backed verdicts as part of its managed detection and response workflow.
The integration was built and proven with a joint customer, and it now allows Daylight to use Island data across the full detection-to-response lifecycle.
How Daylight uses Island
Daylight uses Island in three primary ways.
First, as a detection source. Daylight ingests Island browser audit events and admin audit activity, then runs Daylight-owned detection logic against that telemetry. Daylight can also ingest and act on security events surfaced by Island, such as MITM protection events.
Second, as an investigation source. When an Island-related alert triggers, Daylight queries Island and other integrated systems to collect evidence, understand what happened, and produce a verdict.
Third, as enrichment for alerts from other tools. When an alert originates from endpoint, identity, cloud, SaaS, or another source, Daylight can use Island browser history to understand what the user was doing in the browser at the same time.
This is the core value of the integration: Island is not treated as an isolated log source. It becomes part of the investigation fabric.
Ingesting browser activity into Daylight
Daylight regularly queries Island through its SIEM integration and ingests browser audit events into the Daylight data layer.
The telemetry can include:
- User browsing activity, including URLs, web categories, and policy verdicts
- File uploads and downloads, including threat scan results and metadata
- Application logins
- Clipboard operations
- MITM protection events
- Admin audit actions, including policy changes and system settings modifications
Once this telemetry is ingested, Daylight can run detection logic against it as part of the ingestion pipeline.
That means browser activity becomes a first-class detection surface inside Daylight, alongside endpoint, identity, cloud, SaaS, email, and other security signals.
Detecting risky browser and admin activity
Daylight detectors run against Island telemetry in two modes: event-based detections that evaluate activity as it arrives, and aggregative detections that look for patterns over time.
Examples of Island-based detection coverage include:

This coverage matters because browser risk is not limited to end-user browsing.
A user uploading sensitive data to an AI tool is one type of risk. A suspicious file download is another. But admin activity can be just as important. A compromised or misused admin account that modifies MFA, DLP, OAuth, or browser security policies can create a path to broader compromise.
By ingesting both browser activity and admin audit activity, Daylight can detect risk across the user and control-plane layers of the enterprise browser.
From alert to evidence-backed verdict
An alert is only the start of the work.
When an Island-related alert triggers, Daylight’s investigation engine extracts the relevant indicators and entities, then queries Island and other data sources to collect evidence in real time.
For an Island-originated alert, Daylight can:
- Query Island for the user’s browser activity around the alert
- Enrich indicators such as IP addresses, domains, and file hashes using threat intelligence
- Build user context from identity systems and external sources
- Pull device context from MDM, EDR, and Island device data
- Review related IAM activity around the alert time
- Correlate the evidence into a timeline and verdict
The goal is not simply to confirm that a browser event occurred.
The goal is to answer the questions a security team actually needs answered:
- What did the user do?
- Why did the alert trigger?
- Was the behavior expected or suspicious?
- What evidence supports or contradicts the alert?
- Does this require action, or can it be safely closed?
Daylight applies structured investigation logic to collect the right evidence for each alert type, then analyzes the full picture to produce an evidence-backed verdict. When confidence is low or judgment is required, Daylight’s security experts review the case and make the call.
For certain Island-related detections, such as MITM protection and suspicious file downloads, Daylight can apply dedicated verdict logic to support automated closure when the evidence clearly supports a benign outcome.
That is important. Closing an alert should not mean hiding it. In Daylight, the evidence remains visible and auditable, so customers can see what was checked, why the alert was closed, and what conclusion was reached.
Using Island to enrich every investigation
The integration also works in the other direction.
Island data is valuable even when the original alert does not come from Island.
For example, if an endpoint tool detects a suspicious process, Daylight can query Island to understand whether the file was downloaded through the browser minutes earlier, from which domain, and under what policy verdict.
If an identity system detects unusual authentication, Daylight can use Island browser history to understand what SaaS applications the user accessed around the same time.
If a cloud alert shows unusual activity in an admin console, Daylight can look at whether the user was active in that console through the browser and whether the activity matches an expected workflow.
This is where browser telemetry becomes especially powerful. It gives investigations behavioral context that many security tools do not have on their own.
A cloud alert, endpoint alert, or identity alert can look very different once you understand what the user was doing in the browser at the same moment.
Why this matters
Browser-based activity sits in a difficult security gap.
It is often too high-level for endpoint tools to fully explain. It may not be visible to cloud security tools. It may only be partially covered by network inspection. And it is increasingly where important risk shows up: GenAI data exposure, suspicious downloads, in-browser phishing, credential reuse, admin-console changes, and sensitive SaaS activity.
Island helps close the visibility gap by making the enterprise browser controlled, auditable, and rich with security telemetry.
Daylight helps close the operational gap by turning that telemetry into detections, investigations, timelines, verdicts, and response workflows.
For joint customers, the result is a stronger detection and response model:
- Browser telemetry is ingested into the Daylight data layer
- Daylight detection logic runs against Island activity
- Island alerts are investigated with identity, endpoint, IAM, and threat intelligence context
- Island browser history enriches alerts from other systems
- Evidence-backed verdicts show what happened, what was checked, and why a case was closed or escalated
The browser stops being a blind spot. It becomes part of the same managed investigation model as the rest of the security stack.
The bigger picture
Modern security investigations need more than alerts. They need context.
The browser is one of the richest sources of that context because it shows how users actually interact with applications, files, domains, policies, and business workflows.
By integrating Island telemetry into Daylight’s managed detection and investigation workflow, security teams can move from browser visibility to operational outcomes.
Island provides the browser control point and telemetry.
Daylight turns that telemetry into managed detection, investigation, enrichment, and evidence-backed verdicts.
Together, they help security teams understand what happened, why it happened, and what to do next.






