{"id":"T1176","name":"Software Extensions","url":"https://attack.mitre.org/techniques/T1176","tactics":["persistence"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0092","stix_id":"x-mitre-detection-strategy--eaa0f0da-bee7-4ce3-97e5-46d5ac2a9257","name":"Detection of Malicious or Unauthorized Software Extensions","url":"https://attack.mitre.org/detectionstrategies/DET0092","analytics":[{"id":"AN0251","stix_id":"x-mitre-analytic--ce76c289-b810-44cf-b71e-afc76a70f7bf","name":"Analytic 0251","description":"Installation or execution of a malicious browser or IDE extension, followed by abnormal registry entries or outbound network connections from the host application","url":"https://attack.mitre.org/detectionstrategies/DET0092#AN0251","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"Image","description":"Path of browser or IDE launching subprocesses—may vary depending on installed applications"},{"field":"ParentImage","description":"Legitimate parent-child process relationships for known safe extensions"},{"field":"RegistryPath","description":"Expected registry keys under HKCU/HKLM for installed extensions"},{"field":"TimeWindow","description":"Tunable interval to correlate extension install with follow-on C2 traffic"}],"live":true,"detection_strategies":["DET0092"],"techniques":["T1176"]},{"id":"AN0252","stix_id":"x-mitre-analytic--d8f9ab20-4c82-42fc-9316-91781fa9e5e1","name":"Analytic 0252","description":"Installation of configuration profiles or plist entries associated with malicious or unauthorized browser extensions","url":"https://attack.mitre.org/detectionstrategies/DET0092#AN0252","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of 'profiles install -type=configuration'","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Creation of .plist under /Library/Managed Preferences/","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Suspicious outbound traffic from browser binary to non-standard domains","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"PlistPath","description":"Directory path for user-specific extension configuration files"},{"field":"CommandLine","description":"Usage of profiles CLI tool—can be modified by legitimate tools or MDMs"},{"field":"TimeWindow","description":"Correlation window between configuration install and observable extension behavior"}],"live":true,"detection_strategies":["DET0092"],"techniques":["T1176"]},{"id":"AN0253","stix_id":"x-mitre-analytic--560f859b-2174-4655-b927-b274ad0bda3f","name":"Analytic 0253","description":"Manual or script-based installation of extension-like modules into browser config directories or IDE plugin paths, followed by suspicious network activity","url":"https://attack.mitre.org/detectionstrategies/DET0092#AN0253","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"fs:fileevents","channel":"creat","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"fs-fileevents"},{"name":"NSM:Flow","channel":"Abnormal browser traffic volume or destination","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"DirectoryPath","description":"Common plugin or extension directories may vary by distro or browser (e.g., ~/.config/google-chrome/Default/Extensions)"},{"field":"ExecPath","description":"Path to scripting tools used in installation (e.g., bash, curl, unzip)"},{"field":"TimeWindow","description":"Tunable interval between install and first network beacon"}],"live":true,"detection_strategies":["DET0092"],"techniques":["T1176"]}],"live":true,"version":"1.0","techniques":["T1176"]}],"sigma_rules":[{"id":"0a74c5a9-1b71-4475-9af2-7829d320d5c2","title":"ChromeLoader Malware Execution","author":"@kostastsale","status":"test","level":"high","date":"2022-01-10","modified":null,"description":"Detects execution of ChromeLoader malware via a registered scheduled task","references":["https://github.com/xephora/Threat-Remediation-Scripts/tree/main/Threat-Track/CS_INSTALLER","https://twitter.com/th3_protoCOL/status/1480621526764322817","https://twitter.com/Kostastsale/status/1480716528421011458","https://www.virustotal.com/gui/file/ded20df574b843aaa3c8e977c2040e1498ae17c12924a19868df5b12dee6dfdd"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.t1053.005","attack.t1059.001","attack.t1176","detection.emerging-threats"],"path":"rules-emerging-threats/2022/Malware/ChromeLoader/proc_creation_win_malware_chrome_loader_execution.yml","techniques":["T1053.005","T1059.001","T1176"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}