Windows Registry Startup: Chrome VPN Extensions Installed via Extension Registry Keys

Flags Windows Registry updates that register VPN/proxy Chrome extensions via the Chrome Extensions update_url key.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-28
Updated
2026-07-30

ATT&CK techniques

Initial Access → Persistence
  1. Recon

  2. Resource Dev

  3. Execution

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies when Google Chrome extensions that provide VPN/proxy functionality are registered through Windows Registry entries under the Chrome Extensions update_url path. Attackers may use Chrome extensions to establish persistent network routing and conceal traffic by automating extension installation or configuration. The rule relies on Windows Registry set telemetry by matching specific Chrome extension TargetObject identifiers and confirming the Registry location ends with update_url under the Chrome 32-bit extension path.

Related detections9 linkedT1133 — drag to rearrange
SplashTop Network
Suspicious SoftEther VPN Hamcore Config Written to ProgramData (via file_event)
SplashTop Process
AnyDesk Network
OpenCanary RDP New Connection Attempt on Application Logtype 14001
ArcSOC.exe Creates Suspicious Script/Executable Files on Windows
FortiGate: Addition of VPN SSL Web Portal via Event Logs
FortiGate SSL VPN Settings Edited
Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
Windows Registry Startup: Chrome VPN Extensions Installed via Extension Registry Keys
Pivot detection · T1133 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.