BIOC Low

Chrome runs with key security features disabled

This chrome process ran with command line arguments that disabled key security features disabled. It can have legitimate uses, but this technique is often used by malware to load malicious or untrusted browser extensions.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Persistence
Status:
Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Software Extensions: Browser Extensions (T1176.001)
Indicator:

Process action type = execution AND target process cmd = *--disable-extensions-file-access-check* , *--always-authorize-plugins* , *--disable-improved-download-protection* AND target process name = chrome.exe

Preventable: yes