Chromium Secure Preferences super_mac Forgery for Extension Persistence
Detects suspicious modifications to browser 'Secure Preferences' files associated with known bypass techniques for extension integrity checks, coupled with browser process termination and subsequent relaunch using the --restore-last-session flag. This pattern is consistent with adversary activity attempting to inject malicious browser extensions by manipulating browser configuration files.
CQL

