BIOC
Low
✕
Chrome runs with key security features disabled
This chrome process ran with command line arguments that disabled key security features disabled. It can have legitimate uses, but this technique is often used by malware to load malicious or untrusted browser extensions.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Software Extensions: Browser Extensions (T1176.001)
Indicator:
Process action type = execution AND target process cmd = *--disable-extensions-file-access-check* , *--always-authorize-plugins* , *--disable-improved-download-protection* AND target process name = chrome.exe
Preventable: yes