heroui logo

OSQuery Detected Unwanted Chrome Extensions

Panther Rules

View Source
Summary
This rule, designated as `Osquery.Mac.UnwantedChromeExtensions`, is designed to monitor for potentially unwanted Chrome extensions installed on MacOS devices. Chrome extensions can compromise user credentials or introduce malicious behavior, hence tracking their presence is crucial for maintaining security. The rule leverages Osquery to inspect the installed extensions by gathering data regarding the current extensions' status. If unintended extensions are identified, particularly those linked to known threats, the rule will trigger an alert and recommend actions like uninstalling these extensions to mitigate risks. The severity of this rule is classified as medium, as the presence of unwanted extensions can pose a significant threat to users, especially in corporate environments where sensitive information is handled.
Categories
  • macOS
  • Web
Data Sources
  • Container
  • Application Log
ATT&CK Techniques
  • T1176
Created: 2022-09-02