Skip to content

Commit 8ab540c

Browse files
chore: update feeds 2026-05-01
1 parent 00b5399 commit 8ab540c

11 files changed

Lines changed: 18865 additions & 18865 deletions

feeds/elastic_threat_intel.ndjson

Lines changed: 1929 additions & 1929 deletions
Large diffs are not rendered by default.

feeds/extsentry_feed.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"feed_name": "ExtSentry - Browser Extension Threat Intelligence",
33
"feed_version": "1.0",
4-
"generated": "2026-04-30T23:35:16Z",
4+
"generated": "2026-05-01T01:27:05Z",
55
"source": "https://github.com/mthcht/awesome-lists",
66
"license": "TLP:CLEAR",
77
"total_indicators": 1929,

feeds/extsentry_ioc_feed.csv

Lines changed: 1929 additions & 1929 deletions
Large diffs are not rendered by default.

feeds/misp_event.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,8 @@
44
"threat_level_id": "2",
55
"analysis": "2",
66
"distribution": "3",
7-
"date": "2026-04-30",
8-
"timestamp": "1777592116",
7+
"date": "2026-05-01",
8+
"timestamp": "1777598826",
99
"published": false,
1010
"uuid": "41ef2090-fab5-547e-9eb6-2aa8f195c66f",
1111
"Orgc": {

feeds/misp_warninglist.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "ExtSentry - Known Malicious/Suspicious Browser Extension IDs",
3-
"version": 20260430,
3+
"version": 20260501,
44
"description": "List of known malicious, suspicious, and potentially unwanted browser extension IDs. Maintained by mthcht.",
55
"type": "string",
66
"matching_attributes": [

feeds/opencti_import.csv

Lines changed: 1929 additions & 1929 deletions
Large diffs are not rendered by default.

feeds/openioc_browser_extensions.ioc

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
<?xml version="1.0" ?>
2-
<ioc xmlns="http://schemas.mandiant.com/2010/ioc" id="3678fd2f-03b8-5532-a002-c96e7c7abd1e" last-modified="2026-04-30T23:35:16Z">
2+
<ioc xmlns="http://schemas.mandiant.com/2010/ioc" id="3678fd2f-03b8-5532-a002-c96e7c7abd1e" last-modified="2026-05-01T01:27:05Z">
33
<short_description>ExtSentry - Malicious Browser Extension IOCs</short_description>
44
<description>Browser extension IDs flagged as malicious/suspicious. Matches extension IDs in file paths and registry entries. Source: github.com/mthcht/awesome-lists</description>
5-
<authored_date>2026-04-30T23:35:16Z</authored_date>
5+
<authored_date>2026-05-01T01:27:05Z</authored_date>
66
<definition>
77
<Indicator operator="OR" id="5fd27988-48b0-53ea-88c2-7e57099fd433">
88
<IndicatorItem id="5c154364-a541-57d3-b8c4-2d4b60ec0ba5" condition="contains">

feeds/sentinel_analytics_rule.kql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
// ExtSentry - Browser Extension Threat Detection for Microsoft Sentinel
22
// Source: https://github.com/mthcht/awesome-lists
3-
// Generated: 2026-04-30T23:35:16Z
3+
// Generated: 2026-05-01T01:27:05Z
44
// Total extension IDs: 1929 in 10 chunks
55
//
66
// RECOMMENDATION: For production, import the IOC list as a Sentinel Watchlist

feeds/sigma_rules_browser_extensions.yml

Lines changed: 30 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@ description: |
88
references:
99
- https://github.com/mthcht/awesome-lists
1010
author: ExtSentry / mthcht
11-
date: 2026-04-30
12-
modified: 2026-04-30
11+
date: 2026-05-01
12+
modified: 2026-05-01
1313
tags:
1414
- attack.persistence
1515
- attack.t1176
@@ -1964,8 +1964,8 @@ description: |
19641964
references:
19651965
- https://github.com/mthcht/awesome-lists
19661966
author: ExtSentry / mthcht
1967-
date: 2026-04-30
1968-
modified: 2026-04-30
1967+
date: 2026-05-01
1968+
modified: 2026-05-01
19691969
tags:
19701970
- attack.persistence
19711971
- attack.t1176
@@ -3919,8 +3919,8 @@ description: |
39193919
references:
39203920
- https://github.com/mthcht/awesome-lists
39213921
author: ExtSentry / mthcht
3922-
date: 2026-04-30
3923-
modified: 2026-04-30
3922+
date: 2026-05-01
3923+
modified: 2026-05-01
39243924
tags:
39253925
- attack.persistence
39263926
- attack.t1176
@@ -5871,8 +5871,8 @@ description: Detects browser extensions categorized as 'malware' in the ExtSentr
58715871
references:
58725872
- https://github.com/mthcht/awesome-lists
58735873
author: ExtSentry / mthcht
5874-
date: 2026-04-30
5875-
modified: 2026-04-30
5874+
date: 2026-05-01
5875+
modified: 2026-05-01
58765876
tags:
58775877
- attack.persistence
58785878
- attack.t1176
@@ -7612,8 +7612,8 @@ description: Detects browser extensions categorized as 'PUP' in the ExtSentry fe
76127612
references:
76137613
- https://github.com/mthcht/awesome-lists
76147614
author: ExtSentry / mthcht
7615-
date: 2026-04-30
7616-
modified: 2026-04-30
7615+
date: 2026-05-01
7616+
modified: 2026-05-01
76177617
tags:
76187618
- attack.persistence
76197619
- attack.t1176
@@ -7640,8 +7640,8 @@ description: Detects browser extensions categorized as 'compromised' in the ExtS
76407640
references:
76417641
- https://github.com/mthcht/awesome-lists
76427642
author: ExtSentry / mthcht
7643-
date: 2026-04-30
7644-
modified: 2026-04-30
7643+
date: 2026-05-01
7644+
modified: 2026-05-01
76457645
tags:
76467646
- attack.persistence
76477647
- attack.t1176
@@ -7755,8 +7755,8 @@ description: Detects browser extensions categorized as 'cryptocurrency' in the E
77557755
references:
77567756
- https://github.com/mthcht/awesome-lists
77577757
author: ExtSentry / mthcht
7758-
date: 2026-04-30
7759-
modified: 2026-04-30
7758+
date: 2026-05-01
7759+
modified: 2026-05-01
77607760
tags:
77617761
- attack.persistence
77627762
- attack.t1176
@@ -7868,8 +7868,8 @@ description: Detects browser extensions categorized as 'Credential Access' in th
78687868
references:
78697869
- https://github.com/mthcht/awesome-lists
78707870
author: ExtSentry / mthcht
7871-
date: 2026-04-30
7872-
modified: 2026-04-30
7871+
date: 2026-05-01
7872+
modified: 2026-05-01
78737873
tags:
78747874
- attack.persistence
78757875
- attack.t1176
@@ -7893,8 +7893,8 @@ description: Detects browser extensions categorized as 'Defense Evasion' in the
78937893
references:
78947894
- https://github.com/mthcht/awesome-lists
78957895
author: ExtSentry / mthcht
7896-
date: 2026-04-30
7897-
modified: 2026-04-30
7896+
date: 2026-05-01
7897+
modified: 2026-05-01
78987898
tags:
78997899
- attack.persistence
79007900
- attack.t1176
@@ -7917,8 +7917,8 @@ description: Detects browser extensions categorized as 'scam' in the ExtSentry f
79177917
references:
79187918
- https://github.com/mthcht/awesome-lists
79197919
author: ExtSentry / mthcht
7920-
date: 2026-04-30
7921-
modified: 2026-04-30
7920+
date: 2026-05-01
7921+
modified: 2026-05-01
79227922
tags:
79237923
- attack.persistence
79247924
- attack.t1176
@@ -7945,8 +7945,8 @@ description: Detects browser extensions categorized as 'RMM' in the ExtSentry fe
79457945
references:
79467946
- https://github.com/mthcht/awesome-lists
79477947
author: ExtSentry / mthcht
7948-
date: 2026-04-30
7949-
modified: 2026-04-30
7948+
date: 2026-05-01
7949+
modified: 2026-05-01
79507950
tags:
79517951
- attack.persistence
79527952
- attack.t1176
@@ -7969,8 +7969,8 @@ description: Detects browser extensions categorized as 'password manager' in the
79697969
references:
79707970
- https://github.com/mthcht/awesome-lists
79717971
author: ExtSentry / mthcht
7972-
date: 2026-04-30
7973-
modified: 2026-04-30
7972+
date: 2026-05-01
7973+
modified: 2026-05-01
79747974
tags:
79757975
- attack.persistence
79767976
- attack.t1176
@@ -8001,8 +8001,8 @@ description: Detects browser extensions categorized as 'PROXY/VPN' in the ExtSen
80018001
references:
80028002
- https://github.com/mthcht/awesome-lists
80038003
author: ExtSentry / mthcht
8004-
date: 2026-04-30
8005-
modified: 2026-04-30
8004+
date: 2026-05-01
8005+
modified: 2026-05-01
80068006
tags:
80078007
- attack.persistence
80088008
- attack.t1176
@@ -8029,8 +8029,8 @@ description: Detects browser extensions categorized as 'metadata_category' in th
80298029
references:
80308030
- https://github.com/mthcht/awesome-lists
80318031
author: ExtSentry / mthcht
8032-
date: 2026-04-30
8033-
modified: 2026-04-30
8032+
date: 2026-05-01
8033+
modified: 2026-05-01
80348034
tags:
80358035
- attack.persistence
80368036
- attack.t1176
@@ -8055,8 +8055,8 @@ description: |
80558055
references:
80568056
- https://github.com/mthcht/awesome-lists
80578057
author: ExtSentry
8058-
date: 2026-04-30
8059-
modified: 2026-04-30
8058+
date: 2026-05-01
8059+
modified: 2026-05-01
80608060
tags:
80618061
- attack.persistence
80628062
- attack.t1176

0 commit comments

Comments
 (0)