Analytics BIOC Informational

A browser extension was installed or loaded in an uncommon way

A browser extension was installed or loaded in an uncommon way.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Software Extensions: Browser Extensions (T1176.001)
Detector tags: Chromium Extensions Analytics
Attacker's goals:

Gain persistency on a machine and steal sensitive browsing data.

Investigative actions:

Investigate the extension files and the process that installed them. Check if this extension is currently present at the relevant extensions web store by looking up for its extension ID.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • A browser was forced to load an extension using a special command line argument Low (parent: Informational)
  • A browser extension was installed or loaded in an uncommon way by a LOLBIN process Low (parent: Informational)
  • A browser extension was installed or loaded in an uncommon way by an uncommon process Low (parent: Informational)