Unattended browser extension install triggered while session idle
This rule detects the installation of browser extensions that occur during an idle user session (greater than 7 minutes). This behavior is consistent with automated, remote-driven synthetic input injection, often utilized by malware (e.g., NinjaMare) to install malicious extensions without user consent while the system is unattended.
Microsoft Sentinel (KQL)

