Software Extensions T1176

Tactic: Persistence

Adversaries may abuse software extensions to establish persistent access to victim systems. Software extensions are modular components that enhance or customize the functionality of software applications, including web browsers, Integrated Development Environments (IDEs), and other platforms. Extensions are typically installed via official marketplaces, app stores, or manually loaded by users, and they often inherit the permissions and access levels of the host application.

Events covered

9 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 15 rules share fields, values, and exclusions.

Fields filtered most (26 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine5contains 4, match 1--load-extension=, --load-extension, --load-extension="*\appdata\local\chrome", -extoff
Image5ends_with 3, is_not_null 1, wildcard 1\chrome.exe, \brave.exe, \msedge.exe, ?:\programdata\*, ?:\users\*\appdata\*
EventType4eq 4exec, modification, overwrite, start
TargetFilename4wildcard 4/users/*/library/application..., /users/*/library/application..., /users/*/library/application support/google/chrome/*/preferences, ?:\users\*\appdata\local\*\*\user data\webstore downloads\*, ?:\users\*\appdata\local\*\user data\default\extensions\*.js
process_name4in 2, eq 1, wildcard 1bash, brave browser, cmd.exe, cscript.exe, google chrome
ParentImage3ends_with 2, is_not_null 1\cmd.exe, \cscript.exe, \mshta.exe, \powershell.exe
TargetObject3wildcard 3hk*\software\*\nativemessaginghosts\*, hk*software\policies\*\extensioninstallwhitelist*, hkey_users\*\control panel\desktop\scrnsave.exe, hkey_users\*\environment\userinitmprlogonscript, hkey_users\*\software\microsoft\command processor\autorun
host.os.type3eq 3
process.code_signature.exists3eq 3false
process.code_signature.trusted3eq 3false
Details2contains 1, length_compare 1.json, 0, >
event.type2eq 2change, creation
file.name2ends_with 1, eq 1.crx, .xpi, preferences, secure preferences
IntVersion1cross_field_compare 1IntVulnVursion
IsActivated1eq 1true

Top indicator values (133 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
Imageends_with
\chrome.exe
313
Imageends_with
\brave.exe
211
Imageends_with
\msedge.exe
214
Imageends_with
\opera.exe
211
Imageends_with
\vivaldi.exe
211
process.code_signature.existseq
false
3119
process.code_signature.trustedeq
false
3115
CommandLinecontains
--load-extension=
22
CommandLinecontains
--load-extension
12
CommandLinecontains
-extoff
1
ParentImageends_with
\powershell.exe
224
ParentImageends_with
\cmd.exe
120
ParentImageends_with
\cscript.exe
117
ParentImageends_with
\mshta.exe
113
CommandLinematch
--load-extension="*\appdata\local\chrome"
1
Detailscontains
.json
1
Detailslength_compare
0
14
Detailslength_compare
>
14
EventTypeeq
exec
1576
EventTypeeq
modification
172
EventTypeeq
overwrite
18
EventTypeeq
start
1391
Imagewildcard
?:\programdata\*
118
Imagewildcard
?:\users\*\appdata\*
112
Imagewildcard
?:\users\public\*
122
Imagewildcard
?:\windows\microsoft.net\*
111
IntVersioncross_field_compare
IntVulnVursion
1
IsActivatedeq
true
1
OriginalFileNameeq
iexplore.exe
1
ParentCommandLinecontains
-executionpolicy bypass -windowstyle hidden -e jab
1

Exclusions (100 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagewildcard
?:\program files\*.exe
3
Imagewildcard
?:\program files (x86)\*
2
process.code_signature.trustedeq
true
2
user.ideq
s-1-5-18
2
user.ideq
s-1-5-19
2
Detailscontains
:\program files (x86)\
1
Detailscontains
:\program files\
1
Detailseq
%windir%\system32\ribbons.scr
1
Detailseq
%windir%\system32\rundll32.exe user32.dll,lockworkstation
1
Detailseq
c:\windows\system32\poqexec.exe /display_progress \systemroot\winsxs\pending.xml
1
Detailseq
c:\windows\system32\poqexec.exe /skip_critical_poq /display_progress...
1
Detailseq
scrnsave.scr
1
Detailswildcard
C:\Program Files (x86)\*.exe
1
Detailswildcard
C:\Program Files\*.exe
1
Detailswildcard
C:\Windows\system32\userinit.exe
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Elastic 8 rules

Splunk 1 rule

Kusto 2 rules

Panther 1 rule