Compliance Node Overview
MITRE ATT&CK T1176 (Browser Extensions) is an Enterprise Persistence technique. Adversaries may abuse Internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality and customize aspects of Internet browsers. They can be installed directly or through a browser's app store and generally have access and permissions to everything that the browser can access. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1033 Limit Software Installation, M1047 Audit, M1051 Update Software, M1017 User Training, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-06, CA-07, CM-02, CM-03, CM-05, CM-06, CM-07, CM-11.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1176/
SHA-256 integrity: 09c1490efe6bef15f0ec624375f2072b186c05d2a7eeb9a51bfef200b88024a7
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1176: Browser Extensions (https://attack.mitre.org/techniques/T1176/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access