MITRE ATT&CK technique
Software Extensions detection rulesT1176
Software Extensions (T1176) is a MITRE ATT&CK technique in the Persistence tactic. This page lists the 3 community-maintained Sigma detection rules in the library mapped to T1176 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
Top products
Tactic
ChromeLoader Malware Execution
highDetects execution of ChromeLoader malware via a registered scheduled task
windows · process_creation
Suspicious Chromium Browser Instance Executed With Custom Extension
highDetects a suspicious process spawning a Chromium based browser process with the 'load-extension' flag to start an instance with a custom extension
windows · process_creation
Chromium Browser Instance Executed With Custom Extension
mediumDetects a Chromium based browser process with the 'load-extension' flag to start a instance with a custom extension
windows · process_creation