1200KM / simulation
T1176 Software Extensions — Attack Simulation
Adversaries may abuse software extensions to establish persistent access to victim systems. Software extensions are modular components that enhance or customize the functionality of software applications, including web browsers, Integrated Development Environments (IDEs), and other platforms. Extensions are typically installed via official marketplaces, app stores, or manually loaded by users, and they often inherit the permissions and access…
Technique description
Adversaries may abuse software extensions to establish persistent access to victim systems. Software extensions are modular components that enhance or customize the functionality of software applications, including web browsers, Integrated Development Environments (IDEs), and other platforms. Extensions are typically installed via official marketplaces, app stores, or manually loaded by users, and they often inherit the permissions and access…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Edge Chromium Addon - VPN
Procedure 3d456e2b-a7db-4af8-b5b3-720e7c4d9da5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Chrome/Chromium (Developer Mode)
Procedure 3ecd790d-2617-4abf-9a8c-4e8d47da9ee1; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Google Chrome Load Unpacked Extension With Command Line
Procedure 7a714703-9f6b-461c-b06d-e6aeac650f27; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Firefox
Procedure cb790029-17e6-4c43-b96f-002ce5f10938; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.