Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1176 ✕

Download CSV Show ATT&CK heatmap
  • A browser extension was installed or loaded in an uncommon way Informational 3 variations

    A browser extension was installed or loaded in an uncommon way.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Software Extensions: Browser Extensions (T1176.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Chromium Extensions Analytics
    Attacker's goals: Gain persistency on a machine and steal sensitive browsing data.
    Investigative actions: Investigate the extension files and the process that installed them. Check if this extension is currently present at the relevant extensions web store by looking up for its extension ID.

    Variations

    A browser was forced to load an extension using a special command line argument

    Low overridden

    A browser was forced to load an extension using a special command line argument, an uncommon method. overridden

    A browser extension was installed or loaded in an uncommon way by a LOLBIN process

    Low overridden

    A browser extension was installed or loaded in an uncommon way. overridden

    A browser extension was installed or loaded in an uncommon way by an uncommon process

    Low overridden

    A browser extension was installed or loaded in an uncommon way. overridden