Malicious Chrome/Edge Extension File Presence Detection
This rule monitors DeviceFileEvents for the presence of specific browser extension files on disk known to be associated with malicious campaigns. It utilizes a predefined mapping of extension IDs to names to identify and flag files matching the known malicious browser extensions.
Microsoft Sentinel (KQL)

