Browser extension install requesting proxy+webRequestAuthProvider+<all_urls>
This rule detects the installation of browser extensions that request highly sensitive, over-broad permissions such as proxy configuration management and web authentication provider access, combined with full host access (<all_urls>). This pattern is often indicative of malicious extensions masquerading as legitimate tools (e.g., VPNs) to facilitate credential theft or traffic interception.
Microsoft Sentinel (KQL)

