Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Audit and Remediation: Why Does the "Chrome Extensions" Query Return Results for Edge and Other Browsers?

Audit and Remediation: Why Does the "Chrome Extensions" Query Return Results for Edge and Other Browsers?

Environment

  • Carbon Black Cloud Console: All Versions
  • Carbon Black Cloud Sensor: All Supported Versions

Question

Why do Live Query results for the "Chrome Extensions" query include extensions from non-Chrome browsers?

Answer

  • The chrome_extensions table in osquery stores details for all Chromium-based browsers, like Edge, Brave, and Opera.
  • As a result, a query against this table will return extensions installed on any Chromium browsers on the endpoint, unless a WHERE clause is used to filter by browser_type. Example:
    SELECT username,
    DIRECTORY,
           shell,
           TYPE,
           name,
           VERSION,
           locale,
           update_url,
           author,
           persistent,
           PATH
    FROM users
    JOIN chrome_extensions USING (UID) WHERE browser_type = 'chrome';

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎11-16-2023
Views:
115
Contributors