Chrome/Edge Extensions triggering EDR blocks for command line execution
After an extension update a few days ago, the 1Password chrome and Edge extensions keep triggering my company Fortinet EDR. It is being listed as a malicious "generic.commandline.default" script execution. Every time I change webpages it is triggered. Currently, the only fix so far is to uninstall the 1Password extension from both Edge and Chrome. I have tried removing the extension and reinstalling it.
It is trying to execute the following according to EDR report. (I removed my username) It is also showing as an invalid signature.
cmd.exe /d /s /c ""C:\Users\USERNAME\AppData\Local\1Password\app\8\1Password-BrowserSupport.exe" chrome-extension://dppgmdbiimibapkepcbdbmkaabgiofem/ --parent-window=0" < \\.\pipe\chrome.nativeMessaging.in.251c39119f136db6 > \\.\pipe\chrome.nativeMessaging.out.251c39119f136db6