You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: Hunting Queries/DeviceProcess/VScodeExtensionofanUser.yaml
+5-3Lines changed: 5 additions & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -1,8 +1,10 @@
1
1
id: 75830932-794e-4a18-b62f-cc2a010080b5
2
2
name: List all the VScode Extensions which are installed on a user system
3
3
description: |
4
-
'Detects potentially malicious Visual Studio Code (VSCode) extensions installed on a users system, which threat actors might use to control devices and exfiltrate personal information.
'Detects observed Visual Studio Code (VS Code) extension installation activity on a user's system within the query time range.
5
+
Note: This query does not return a complete per-user inventory of installed extensions and may miss extensions installed outside the telemetry window or via unsupported installation methods.
0 commit comments