Skip to content

Commit 9c4af55

Browse files
chore: update feeds 2026-05-21
1 parent db43a80 commit 9c4af55

11 files changed

Lines changed: 19035 additions & 19035 deletions

feeds/elastic_threat_intel.ndjson

Lines changed: 1946 additions & 1946 deletions
Large diffs are not rendered by default.

feeds/extsentry_feed.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"feed_name": "ExtSentry - Browser Extension Threat Intelligence",
33
"feed_version": "1.0",
4-
"generated": "2026-05-20T23:52:45Z",
4+
"generated": "2026-05-21T02:47:23Z",
55
"source": "https://github.com/mthcht/awesome-lists",
66
"license": "TLP:CLEAR",
77
"total_indicators": 1946,

feeds/extsentry_ioc_feed.csv

Lines changed: 1946 additions & 1946 deletions
Large diffs are not rendered by default.

feeds/misp_event.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,8 @@
44
"threat_level_id": "2",
55
"analysis": "2",
66
"distribution": "3",
7-
"date": "2026-05-20",
8-
"timestamp": "1779321165",
7+
"date": "2026-05-21",
8+
"timestamp": "1779331643",
99
"published": false,
1010
"uuid": "41ef2090-fab5-547e-9eb6-2aa8f195c66f",
1111
"Orgc": {

feeds/misp_warninglist.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "ExtSentry - Known Malicious/Suspicious Browser Extension IDs",
3-
"version": 20260520,
3+
"version": 20260521,
44
"description": "List of known malicious, suspicious, and potentially unwanted browser extension IDs. Maintained by mthcht.",
55
"type": "string",
66
"matching_attributes": [

feeds/opencti_import.csv

Lines changed: 1946 additions & 1946 deletions
Large diffs are not rendered by default.

feeds/openioc_browser_extensions.ioc

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
<?xml version="1.0" ?>
2-
<ioc xmlns="http://schemas.mandiant.com/2010/ioc" id="3678fd2f-03b8-5532-a002-c96e7c7abd1e" last-modified="2026-05-20T23:52:45Z">
2+
<ioc xmlns="http://schemas.mandiant.com/2010/ioc" id="3678fd2f-03b8-5532-a002-c96e7c7abd1e" last-modified="2026-05-21T02:47:23Z">
33
<short_description>ExtSentry - Malicious Browser Extension IOCs</short_description>
44
<description>Browser extension IDs flagged as malicious/suspicious. Matches extension IDs in file paths and registry entries. Source: github.com/mthcht/awesome-lists</description>
5-
<authored_date>2026-05-20T23:52:45Z</authored_date>
5+
<authored_date>2026-05-21T02:47:23Z</authored_date>
66
<definition>
77
<Indicator operator="OR" id="5fd27988-48b0-53ea-88c2-7e57099fd433">
88
<IndicatorItem id="9b5ec8dd-9fe4-5c27-a835-533c05dcf7b0" condition="contains">

feeds/sentinel_analytics_rule.kql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
// ExtSentry - Browser Extension Threat Detection for Microsoft Sentinel
22
// Source: https://github.com/mthcht/awesome-lists
3-
// Generated: 2026-05-20T23:52:45Z
3+
// Generated: 2026-05-21T02:47:23Z
44
// Total extension IDs: 1946 in 10 chunks
55
//
66
// RECOMMENDATION: For production, import the IOC list as a Sentinel Watchlist

feeds/sigma_rules_browser_extensions.yml

Lines changed: 30 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@ description: |
88
references:
99
- https://github.com/mthcht/awesome-lists
1010
author: ExtSentry / mthcht
11-
date: 2026-05-20
12-
modified: 2026-05-20
11+
date: 2026-05-21
12+
modified: 2026-05-21
1313
tags:
1414
- attack.persistence
1515
- attack.t1176
@@ -1981,8 +1981,8 @@ description: |
19811981
references:
19821982
- https://github.com/mthcht/awesome-lists
19831983
author: ExtSentry / mthcht
1984-
date: 2026-05-20
1985-
modified: 2026-05-20
1984+
date: 2026-05-21
1985+
modified: 2026-05-21
19861986
tags:
19871987
- attack.persistence
19881988
- attack.t1176
@@ -3953,8 +3953,8 @@ description: |
39533953
references:
39543954
- https://github.com/mthcht/awesome-lists
39553955
author: ExtSentry / mthcht
3956-
date: 2026-05-20
3957-
modified: 2026-05-20
3956+
date: 2026-05-21
3957+
modified: 2026-05-21
39583958
tags:
39593959
- attack.persistence
39603960
- attack.t1176
@@ -5922,8 +5922,8 @@ description: Detects browser extensions categorized as 'malware' in the ExtSentr
59225922
references:
59235923
- https://github.com/mthcht/awesome-lists
59245924
author: ExtSentry / mthcht
5925-
date: 2026-05-20
5926-
modified: 2026-05-20
5925+
date: 2026-05-21
5926+
modified: 2026-05-21
59275927
tags:
59285928
- attack.persistence
59295929
- attack.t1176
@@ -7680,8 +7680,8 @@ description: Detects browser extensions categorized as 'PUP' in the ExtSentry fe
76807680
references:
76817681
- https://github.com/mthcht/awesome-lists
76827682
author: ExtSentry / mthcht
7683-
date: 2026-05-20
7684-
modified: 2026-05-20
7683+
date: 2026-05-21
7684+
modified: 2026-05-21
76857685
tags:
76867686
- attack.persistence
76877687
- attack.t1176
@@ -7708,8 +7708,8 @@ description: Detects browser extensions categorized as 'compromised' in the ExtS
77087708
references:
77097709
- https://github.com/mthcht/awesome-lists
77107710
author: ExtSentry / mthcht
7711-
date: 2026-05-20
7712-
modified: 2026-05-20
7711+
date: 2026-05-21
7712+
modified: 2026-05-21
77137713
tags:
77147714
- attack.persistence
77157715
- attack.t1176
@@ -7823,8 +7823,8 @@ description: Detects browser extensions categorized as 'cryptocurrency' in the E
78237823
references:
78247824
- https://github.com/mthcht/awesome-lists
78257825
author: ExtSentry / mthcht
7826-
date: 2026-05-20
7827-
modified: 2026-05-20
7826+
date: 2026-05-21
7827+
modified: 2026-05-21
78287828
tags:
78297829
- attack.persistence
78307830
- attack.t1176
@@ -7936,8 +7936,8 @@ description: Detects browser extensions categorized as 'Credential Access' in th
79367936
references:
79377937
- https://github.com/mthcht/awesome-lists
79387938
author: ExtSentry / mthcht
7939-
date: 2026-05-20
7940-
modified: 2026-05-20
7939+
date: 2026-05-21
7940+
modified: 2026-05-21
79417941
tags:
79427942
- attack.persistence
79437943
- attack.t1176
@@ -7961,8 +7961,8 @@ description: Detects browser extensions categorized as 'Defense Evasion' in the
79617961
references:
79627962
- https://github.com/mthcht/awesome-lists
79637963
author: ExtSentry / mthcht
7964-
date: 2026-05-20
7965-
modified: 2026-05-20
7964+
date: 2026-05-21
7965+
modified: 2026-05-21
79667966
tags:
79677967
- attack.persistence
79687968
- attack.t1176
@@ -7985,8 +7985,8 @@ description: Detects browser extensions categorized as 'scam' in the ExtSentry f
79857985
references:
79867986
- https://github.com/mthcht/awesome-lists
79877987
author: ExtSentry / mthcht
7988-
date: 2026-05-20
7989-
modified: 2026-05-20
7988+
date: 2026-05-21
7989+
modified: 2026-05-21
79907990
tags:
79917991
- attack.persistence
79927992
- attack.t1176
@@ -8013,8 +8013,8 @@ description: Detects browser extensions categorized as 'RMM' in the ExtSentry fe
80138013
references:
80148014
- https://github.com/mthcht/awesome-lists
80158015
author: ExtSentry / mthcht
8016-
date: 2026-05-20
8017-
modified: 2026-05-20
8016+
date: 2026-05-21
8017+
modified: 2026-05-21
80188018
tags:
80198019
- attack.persistence
80208020
- attack.t1176
@@ -8037,8 +8037,8 @@ description: Detects browser extensions categorized as 'password manager' in the
80378037
references:
80388038
- https://github.com/mthcht/awesome-lists
80398039
author: ExtSentry / mthcht
8040-
date: 2026-05-20
8041-
modified: 2026-05-20
8040+
date: 2026-05-21
8041+
modified: 2026-05-21
80428042
tags:
80438043
- attack.persistence
80448044
- attack.t1176
@@ -8069,8 +8069,8 @@ description: Detects browser extensions categorized as 'PROXY/VPN' in the ExtSen
80698069
references:
80708070
- https://github.com/mthcht/awesome-lists
80718071
author: ExtSentry / mthcht
8072-
date: 2026-05-20
8073-
modified: 2026-05-20
8072+
date: 2026-05-21
8073+
modified: 2026-05-21
80748074
tags:
80758075
- attack.persistence
80768076
- attack.t1176
@@ -8097,8 +8097,8 @@ description: Detects browser extensions categorized as 'metadata_category' in th
80978097
references:
80988098
- https://github.com/mthcht/awesome-lists
80998099
author: ExtSentry / mthcht
8100-
date: 2026-05-20
8101-
modified: 2026-05-20
8100+
date: 2026-05-21
8101+
modified: 2026-05-21
81028102
tags:
81038103
- attack.persistence
81048104
- attack.t1176
@@ -8123,8 +8123,8 @@ description: |
81238123
references:
81248124
- https://github.com/mthcht/awesome-lists
81258125
author: ExtSentry
8126-
date: 2026-05-20
8127-
modified: 2026-05-20
8126+
date: 2026-05-21
8127+
modified: 2026-05-21
81288128
tags:
81298129
- attack.persistence
81308130
- attack.t1176

0 commit comments

Comments
 (0)