{"id":"T1176.002","name":"IDE Extensions","url":"https://attack.mitre.org/techniques/T1176/002","tactics":["persistence"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0561","stix_id":"x-mitre-detection-strategy--434d1a09-6a53-43ae-8f8c-e0eb853c4a25","name":"Detect malicious IDE extension install/usage and IDE tunneling","url":"https://attack.mitre.org/detectionstrategies/DET0561","analytics":[{"id":"AN1548","stix_id":"x-mitre-analytic--539a4182-ab9e-4abf-a83b-f30cf2dec770","name":"Analytic 1548","description":"Adversary installs or side-loads an IDE extension (VS Code, IntelliJ/JetBrains, Eclipse) or enables IDE tunneling. Chain: (1) IDE binary starts on a non-developer endpoint or server, often with install/force/tunnel flags → (2) extension files/registrations appear under user profile → (3) browser/IDE initiates outbound connections to extension marketplaces, update endpoints, or IDE remote/tunnel services → (4) optional child tools (ssh, node, powershell) execute under the IDE context.","url":"https://attack.mitre.org/detectionstrategies/DET0561#AN1548","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"IDEList","description":"Executable names/paths (e.g., code.exe, idea64.exe, eclipse.exe, jetbrains-gateway.exe) vary by version and packaging."},{"field":"SuspiciousCLI","description":"Flags such as --install-extension, --force, --disable-extensions, --user-data-dir, --uninstall-extension, tunnel/remote flags are tunable."},{"field":"ServerZones","description":"List of hosts where IDEs should never run (prod servers, DCs)."},{"field":"AllowedHosts","description":"Approved extension marketplaces/ide services; use to suppress benign traffic."},{"field":"TimeWindow","description":"Correlation horizon (e.g., 15–30m) between process start, file writes, and outbound IDE/tunnel connections."}],"live":true,"detection_strategies":["DET0561"],"techniques":["T1176.002"]},{"id":"AN1549","stix_id":"x-mitre-analytic--4dff3c9a-4730-46de-af2f-dfa86b249167","name":"Analytic 1549","description":"Adversary installs or abuses IDE extensions via CLI or direct write to profile directories and then communicates with marketplaces or remote tunnel services. Chain: auditd execve (code/idea/eclipse) with install/update flags or writes under ~/.vscode/extensions, ~/.config/JetBrains → outbound flows to *.visualstudio.com, marketplace.visualstudio.com, *.jetbrains.com, githubusercontent.com, or SSH/WebSocket tunnel endpoints → optional ssh/node processes spawned by IDE.","url":"https://attack.mitre.org/detectionstrategies/DET0561#AN1549","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open,creat,rename,write","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Connections from IDE hosts to marketplace/tunnel domains","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"IDEPaths","description":"Per-distro/profile extension directories differ; tune for Chromium/JetBrains snap/flatpak paths."},{"field":"DomainAllowlist","description":"Enterprise-approved repos and proxies to reduce FPs."},{"field":"UserRoleScope","description":"Limit to non-developer users or production servers."},{"field":"TimeWindow","description":"Join horizon across file, process, and network telemetry."}],"live":true,"detection_strategies":["DET0561"],"techniques":["T1176.002"]},{"id":"AN1550","stix_id":"x-mitre-analytic--77d3146f-2066-40a9-872e-ec05d7a4d6d1","name":"Analytic 1550","description":"Adversary adds IDE extensions or plugins (VS Code, JetBrains Toolbox/EAP, Eclipse) via GUI or CLI, possibly via managed profiles. Chain: process start with install/update flags → plist/extension folder changes under ~/Library/Application Support/Code or ~/Library/Application Support/JetBrains → outbound connections to marketplaces/tunnel services → optional helper (ssh/node) spawned.","url":"https://attack.mitre.org/detectionstrategies/DET0561#AN1550","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of Code.app, idea, JetBrainsToolbox, eclipse with install/extension flags","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Writes under ~/Library/Application Support/Code*/extensions or JetBrains plugins","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Outbound connections from IDE processes to marketplace/tunnel domains","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"PlistLocations","description":"Per-app preference domains and plugin directories vary by version."},{"field":"MDMProfiles","description":"If MDM installs extensions, allowlist those events to avoid FPs."},{"field":"TimeWindow","description":"Correlation range between install and first beacon."}],"live":true,"detection_strategies":["DET0561"],"techniques":["T1176.002"]}],"live":true,"version":"1.0","techniques":["T1176.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}