<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How I detect vpn  extension in browser ( Chrome, Firefox, Brave )? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-i-detect-vpn-extension-in-browser-chrome-firefox-brave/m-p/571561#M5833</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cyber-Elite lia-component-message-view-widget-author-username"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A id="link_17" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130" target="_self" aria-label="View Profile of aleksandar.astardzhiev"&gt;&lt;SPAN class="login-bold"&gt;Aleksandar.Astardzhiev&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the reply. currently I find something and trying to follow this process, it usually detects some &lt;STRONG&gt;.crx&lt;/STRONG&gt; name extension which is exist on some endpoint. Maybe it will help to u also. Please share you opinion.&amp;nbsp;&lt;BR /&gt;link :&amp;nbsp;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-poc-monitoring-malicious-chrome-extensions/td-p/519888" target="_blank"&gt;LIVEcommunity - Cortex XDR PoC: Monitoring Malicious Chrome Extensions - LIVEcommunity - 519888 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jan 2024 10:23:44 GMT</pubDate>
    <dc:creator>Prashanta</dc:creator>
    <dc:date>2024-01-03T10:23:44Z</dc:date>
    <item>
      <title>How I detect vpn  extension in browser ( Chrome, Firefox, Brave )?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-i-detect-vpn-extension-in-browser-chrome-firefox-brave/m-p/571514#M5831</link>
      <description>&lt;P&gt;How I detect &lt;STRONG&gt;VPN extensions&lt;/STRONG&gt; in browser ( like, EDGE, Chrome, Firefox, Brave)? with XQL query.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 04:55:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-i-detect-vpn-extension-in-browser-chrome-firefox-brave/m-p/571514#M5831</guid>
      <dc:creator>Prashanta</dc:creator>
      <dc:date>2024-01-03T04:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: How I detect vpn  extension in browser ( Chrome, Firefox, Brave )?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-i-detect-vpn-extension-in-browser-chrome-firefox-brave/m-p/571558#M5832</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/593283889"&gt;@Prashanta&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my humble opinion there is no way to detect browser extensions using the XQL.&lt;/P&gt;
&lt;P&gt;Generally speaking XQL gives you a way to search/query the event logs. XDR is doing really great job by collecting information which process is generating the network traffic. But this means that those logs will only show that "FireFox is trying to access surfshark.com" (for example), it will not tell if the user is trying to open the page or there is browser extension that is trying to make the connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Long time ago I tried to achieve something similar - List/Detect browser extensions on endpoint from CortexXDR&lt;/P&gt;
&lt;P&gt;What I did is I tried to create custom python script that I imported in XDR. &lt;BR /&gt;The script was basically searching for the directory where the three most common browsers keep their extensions and read the manifest file and print out the name and the extension ID. My idea was as next step to check the ID agains a list of known malicius IDs like &lt;A href="https://github.com/mallorybowes/chrome-mal-ids" target="_blank"&gt;https://github.com/mallorybowes/chrome-mal-ids&lt;/A&gt;, but I never complete this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not sure if my approach was the best, but in my understanding it is the only one since the Operating System does not make difference if FireFox is trying to connect to VPN because there is extension installed or just user accessing a web page.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 09:59:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-i-detect-vpn-extension-in-browser-chrome-firefox-brave/m-p/571558#M5832</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2024-01-03T09:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: How I detect vpn  extension in browser ( Chrome, Firefox, Brave )?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-i-detect-vpn-extension-in-browser-chrome-firefox-brave/m-p/571561#M5833</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cyber-Elite lia-component-message-view-widget-author-username"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A id="link_17" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130" target="_self" aria-label="View Profile of aleksandar.astardzhiev"&gt;&lt;SPAN class="login-bold"&gt;Aleksandar.Astardzhiev&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the reply. currently I find something and trying to follow this process, it usually detects some &lt;STRONG&gt;.crx&lt;/STRONG&gt; name extension which is exist on some endpoint. Maybe it will help to u also. Please share you opinion.&amp;nbsp;&lt;BR /&gt;link :&amp;nbsp;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-poc-monitoring-malicious-chrome-extensions/td-p/519888" target="_blank"&gt;LIVEcommunity - Cortex XDR PoC: Monitoring Malicious Chrome Extensions - LIVEcommunity - 519888 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 10:23:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-i-detect-vpn-extension-in-browser-chrome-firefox-brave/m-p/571561#M5833</guid>
      <dc:creator>Prashanta</dc:creator>
      <dc:date>2024-01-03T10:23:44Z</dc:date>
    </item>
  </channel>
</rss>

