1200KM / detection
T1176 Software Extensions — Detection Rules
Detection workspace for T1176 Software Extensions: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0092 Detection of Malicious or Unauthorized Software Extensions
AN0251 Analytic 0251
Installation or execution of a malicious browser or IDE extension, followed by abnormal registry entries or outbound network connections from the host application
AN0252 Analytic 0252
Installation of configuration profiles or plist entries associated with malicious or unauthorized browser extensions
AN0253 Analytic 0253
Manual or script-based installation of extension-like modules into browser config directories or IDE plugin paths, followed by suspicious network activity
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Command Execution · DC0064
- File Creation · DC0039
- Network Connection Creation · DC0082
- Network Traffic Flow · DC0078
- Process Creation · DC0032
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.