Malicious Browser Extension Installation
This detection/hunting query identifies Chromium-based browser extensions matching known malicious extension IDs from the ExtSentry IOC feed. Adversaries and commodity malware families sideload extensions to steal session cookies, intercept credentials, and maintain persistence inside the browser, where the activity survives endpoint remediation that does not touch the browser profile. The rule covers three installation paths: files written to the extension directories, registry registration and policy-based force-install, and command-line sideloading via --load-extension. Wallet and password manager extensions are excluded upstream as sensitive rather than malicious.
Microsoft Sentinel (KQL)

