AN0123
Analytic 0123
Windows
Installation of a new browser extension followed by suspicious file writes or outbound network connections to untrusted domains by the browser process.
WinEventLog:Sysmon
EventCode=11
WinEventLog:Security
EventCode=4688
WinEventLog:Sysmon
EventCode=3, 22
WinEventLog:Sysmon
EventCode=13, 14
[UserContext]
Extension installation by privileged or domain users may require higher scrutiny
[BrowserExecutablePath]
Custom or portable browsers may not match default paths
[ExtensionInstallPath]
Installation paths may vary by version or user profile
AN0124
Analytic 0124
macOS
Installation of malicious .mobileconfig profiles or browser extension plist entries followed by abnormal browser child process activity.
macos:unifiedlog
profiles install -type=configuration
macos:unifiedlog
Creation or modification of browser extension .plist files
macos:unifiedlog
Unexpected child process of Safari or Chrome
[PlistPath]
Different versions may store extensions in variant preference folders
[CommandLineFlags]
May vary with OS version; some install flags deprecated in macOS 11+
AN0125
Analytic 0125
Linux
Manual or scripted installation of Chrome extensions using user scripts or config files, followed by unexpected network connections from browser processes.
auditd:SYSCALL
open
NSM:Flow
Browser connections to known C2 or dynamic DNS domains
auditd:SYSCALL
execve
[ExtensionDir]
Location of Chrome/Chromium extensions under user profile may vary
[DomainWatchlist]
Custom list of suspicious destination domains for browser traffic