
Summary
This detection rule identifies modifications to Windows registry values that disable automatic updates for Google Chrome. It specifically monitors changes to certain registry keys associated with Chrome updates, such as \"DisableAutoUpdateChecksCheckboxValue\", \"Update{8A69D345-D564-463C-AFF1-A69D9E530F96}\", \"UpdateDefault\" and \"AutoUpdateCheckPeriodMinutes\". By setting their values to \"1\" or \"0\", these changes can effectively prevent Chrome from receiving crucial security updates. The implications of these changes are significant, as they can indicate potential policy violations, attempts to maintain unauthorized extensions, or facilitate malware persistence. Therefore, this rule is essential for monitoring browser security and ensuring compliance with update policies in a corporate environment.
Categories
- Windows
- Endpoint
Data Sources
- Windows Registry
ATT&CK Techniques
- T1185
Created: 2026-01-12