07-01-2016 12:17 PM - edited 02-20-2020 09:01 PM
Is there a way with either a Simple or Advanced Custom detection to stop a browser extension install or to remove/detect an existing one? Can you configure an IOC scan to Quarantine a file?
07-01-2016 01:41 PM
You could just block the URL that the extension downloads from ...
07-01-2016 01:51 PM
What if they are already installed? Also, we've come to find out than when a user logs into their google account on the chrome browser, good synchronizes all their extensions for them (so the download sources are not always unique). We were hoping that we could assert some type of end-point control against these. For example, if we know the extension ID, (which creates a director with the ID name) can we create a signature somehow that quarantines every file in that directory?
07-01-2016 11:05 PM
Hello Team,
You can open a request with TAC so that they can escalate to Fireamp team and request if a signature possible for this in the Endpoint. Fireamp escalation team handles this kind of requests.
Rate if this answer helps you.
Regards
Jetsy
07-02-2016 07:04 AM
I have done that as well.
07-05-2016 10:25 PM
Did they provided any signature ?
07-06-2016 05:21 AM
Essentially, I have to find a way to write a clam AV signature myself, either with HEX signature for the extension ID string or a sha256 of the extension HTML files. No response on why there is not an AMP record of the file IO event when the extension loads from disk.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide