Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Detect browser launched with a sideloaded extension flag

Matches process creation where the command line carries a Chromium extension-sideloading switch — the unpacked-extension load path an adversary uses to install a browser extension from a local directory without going through the web store. The match is on CommandLine alone rather than on the browser image: MITRE's BrowserExecutablePath knob warns that custom and portable browsers do not sit at default paths, and these switches are browser-specific enough to stand on their own. The rest of the analytic — the file writes and outbound connections that follow the install — is a correlation Sigma cannot express, so this rule covers the install event only. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0044, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Detect browser launched with a sideloaded extension flagid: 93c9e97b-4861-4042-9b15-38c1d0ee87fastatus: experimentaldescription: |  Matches process creation where the command line carries a Chromium  extension-sideloading switch — the unpacked-extension load path an adversary  uses to install a browser extension from a local directory without going  through the web store. The match is on CommandLine alone rather than on the  browser image: MITRE's BrowserExecutablePath knob warns that custom and  portable browsers do not sit at default paths, and these switches are  browser-specific enough to stand on their own. The rest of the analytic —  the file writes and outbound connections that follow the install — is a  correlation Sigma cannot express, so this rule covers the install event only.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0044, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1176/001  - https://attack.mitre.org/detectionstrategies/DET0044author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.persistence  - attack.t1176.001logsource:  category: process_creation  product: windowsdetection:  selection:    CommandLine|contains:      - '--load-extension='      - '--disable-extensions-except='      - '--pack-extension='      - '--install-chrome-app='  condition: selectionfalsepositives:  - "Extension developers. Loading an unpacked extension from a working directory is the normal development loop, so on engineering endpoints this fires constantly. MITRE's UserContext knob is the tuning point — reserve the alert for accounts that have no business developing extensions, or exclude command lines whose extension path sits under a known source tree."  - "Automated browser testing. Selenium, Puppeteer and Playwright launch Chromium with '--load-extension=' and '--disable-extensions-except=' pointing at a temporary profile directory; the ExtensionInstallPath knob is where that temp-directory prefix gets excluded."  - "Packaging steps in a build pipeline that call '--pack-extension=' to produce a signed .crx as a release artefact."level: medium

Sentinel · KQL

Run this as a search.

DeviceProcessEvents| where (ProcessCommandLine contains "--load-extension=" or ProcessCommandLine contains "--disable-extensions-except=" or ProcessCommandLine contains "--pack-extension=" or ProcessCommandLine contains "--install-chrome-app=")

Splunk · SPL

Run this as a search.

index=* (CommandLine="*--load-extension=*" OR CommandLine="*--disable-extensions-except=*" OR CommandLine="*--pack-extension=*" OR CommandLine="*--install-chrome-app=*")

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE (TO_LOWER(process.command_line) LIKE "*--load-extension=*" OR TO_LOWER(process.command_line) LIKE "*--disable-extensions-except=*" OR TO_LOWER(process.command_line) LIKE "*--pack-extension=*" OR TO_LOWER(process.command_line) LIKE "*--install-chrome-app=*")

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,process_creation,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <rule id="100000" level="7">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="CommandLine" type="pcre2">(?i)(--load-extension=|--disable-extensions-except=|--pack-extension=|--install-chrome-app=)</field>    <description>Detect browser launched with a sideloaded extension flag</description>    <mitre>      <id>T1176.001</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.