Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1176

T1176Software Extensions

T1176 — Software Extensions is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 10 detection use cases covering it and 56 threat-intel articles citing it.

Persistence
View on the matrix → Filter Detection Library MITRE official spec ↗
10Use cases
56Articles
2Sub-techniques
1Tactic

Sub-techniques (2)

Use cases covering this technique (10)

Suspicious browser extension installation Internal install · hunting DSΣP [LLM] OkoBot browser-extension loader extl.exe deployed via HDUtil Bespoke install · alerting DSΣPDDCS [LLM] External browser process connects to SiYuan kernel loopback admin port 127.0.0.1:6806 Bespoke exploit · hunting DSΣPDDCS [LLM] Browser extension manifest rewritten adding networking/host permissions (supply-chain) Bespoke install · hunting DSΣPDDCS [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro Bespoke c2 · alerting DSΣPDDCS [LLM] VS Code child process fetching payload from nrwl/nx orphan commit (Nx Console v18.95.0 dropper) Bespoke install · alerting DSΣPDDCS [LLM] Context.ai compromised Chrome extension (ID omddlmnhcofjbnbflmjginpjjblphbgk) present on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] Cyberhaven compromised extension C2 beacon to cyberhavenext[.]pro Bespoke c2 · hunting DSΣPDDCS [LLM] Solidity Language malicious Cursor/VS Code extension folder created on disk (solidityai.solidity-* and related) Bespoke delivery · alerting DSΣPDDCS [LLM] Browser extension folder write at vulnerable React DevTools 4.27.8 / Vue.js devtools 6.5.0 Bespoke exploit · hunting DSΣPDDCS

Articles citing this technique (56)