Analytics BIOC Informational

Chrome Extension Installed By User

A Chrome extension was installed or updated by a Google Workspace user.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003)
ATT&CK techniques: Supply Chain Compromise: Compromise Software Dependencies and Development Tools (T1195.001) Software Extensions: Browser Extensions (T1176.001)
Detector tags: Google Workspace
Attacker's goals:

Adversaries may leverage browser extensions installation to gain Initial Access and Persistence, enabling them to intercept credentials and hijack active web sessions.

Investigative actions:

Review the extension installed, it's OAuth scopes, reputation and permissions. Analyze subsequent network traffic from the user's device or browser for connections to newly registered domains. Investigate the source IP and identity for previous malicious activity or anomalies.

Test period:
N/A (single event)
Deduplication:
1 Day