Analytics BIOC
Informational
✕
A browser extension was installed or loaded in an uncommon way
A browser extension was installed or loaded in an uncommon way.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Software Extensions: Browser Extensions (T1176.001)
Detector tags: Chromium Extensions Analytics
Attacker's goals:
Gain persistency on a machine and steal sensitive browsing data.
Investigative actions:
Investigate the extension files and the process that installed them. Check if this extension is currently present at the relevant extensions web store by looking up for its extension ID.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- A browser was forced to load an extension using a special command line argument Low (parent: Informational)
- A browser extension was installed or loaded in an uncommon way by a LOLBIN process Low (parent: Informational)
- A browser extension was installed or loaded in an uncommon way by an uncommon process Low (parent: Informational)