Fake privacy-browser geolocation lookup preceding search hijack/extension instal
Detects execution patterns associated with 'NinjaMare' style malware, where a process masquerading as a browser (e.g., tenbrowser.exe, fireflybrowser.exe) performs an external IP geolocation lookup followed by suspicious registry or file modifications indicative of browser hijacking or extension installation within a five-minute window.
Microsoft Sentinel (KQL)

