<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: browsers extensions Alert in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/513245#M2741</link>
    <description>&lt;P&gt;Hey Neelrohit,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for your information!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Mon, 29 Aug 2022 12:56:06 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2022-08-29T12:56:06Z</dc:date>
    <item>
      <title>browsers extensions Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/513183#M2733</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to see more rules which are containing everything about browser extensions. Like in chrome, "browser extension was created".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know to manage chrome via GPO, but there are not always Active Directories and I would like to get an alert, when a new extension is installed and also used (when it was already installed).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not sure, if malware extensions are blocked, because of that it would be nice to get more visibility on this attack vector.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.hackread.com/malicious-chrome-extensions-steal-data-sync-feature/" target="_blank"&gt;https://www.hackread.com/malicious-chrome-extensions-steal-data-sync-feature/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do you say to my idea?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Aug 2022 22:22:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/513183#M2733</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-27T22:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: browsers extensions Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/513192#M2735</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As of now, Cortex XDR does not work on detection and prevention of browser extensions. However, if any process activity or exploitation technique happens on the browser itself leveraging the extension, the browser activity should be blocked in that causality events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Neel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Aug 2022 01:57:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/513192#M2735</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-08-28T01:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: browsers extensions Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/513245#M2741</link>
      <description>&lt;P&gt;Hey Neelrohit,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for your information!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 12:56:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/513245#M2741</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-29T12:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: browsers extensions Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/593129#M6998</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Do you have any ideas or a developed approach to monitoring browsers or monitoring installed extensions?&lt;/P&gt;
&lt;P&gt;Maybe you have some XQL queries you can share or BIOC rules?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 08:49:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/593129#M6998</guid>
      <dc:creator>arekf</dc:creator>
      <dc:date>2024-07-26T08:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: browsers extensions Alert</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/594544#M7053</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_0-1723232223588.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61442i6C48AD4E3D9F5A04/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_0-1723232223588.png" alt="RFeyertag_0-1723232223588.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;NAME !=&lt;/P&gt;
&lt;P&gt;*{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi*|*uBlock0@raymondhill.net.xpi*|*dreamer-balanced-colorway@mozilla.org.xpi*|*innovator-bold-colorway@mozilla.org.xpi*&lt;/P&gt;
&lt;P&gt;PATH =&lt;/P&gt;
&lt;P&gt;*C:\Users\*\AppData\Roaming\Mozilla\Firefox\Profiles\*\extensions\*|*C:\Users\*\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\*|*C:\Users\*\AppData\Local\Google\Chrome\User Data\Default\Extensions\*|*C:\Users\*\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\*&lt;/P&gt;
&lt;P&gt;PATH != *ghbmnnjooekpmoecnnnilnnbdlolhkhi*|*efaidnbmnnnibpcajpcglclefindmkaj*|*extensions\temp*|*extensions\uBlock0@raymondhill.net.xpi*|*nmmhkkegccagdldgiimedpiccmgmieda*|*jid1-ZAdIEUB7XOzOJw@jetpack.xpi*|*dnssec-study@mozilla.org.xpi*|*cjpalhdlnbpafiamejdnhcphjbkeiagm*|*aapbdbdomjkkjkaonfhkkikfgjllcleb*|*felcaaldnbdncclmgdcncolpebgiejap*|*aapocclcgogkmnckokdopfmhonfmgoek*|*hmgmjopcicchpdmfindajdphmgbdnklh*|*ihcjicgdanjaechkgeegckofjjedodee*|*aohghmighlieiainnegkcijnfilokake*|*kjnlgbpnlangffmpnapcfdihmhhfnomg*|*ikhahkidgnljlniknmendeflkdlfhonj*&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here you go&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 19:40:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/browsers-extensions-alert/m-p/594544#M7053</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2024-08-09T19:40:04Z</dc:date>
    </item>
  </channel>
</rss>

