Plan
active
PEEP Toolkit Uses Chrome/Edge Extensions as Post-Compromise Backdoor
- Engineer — Learn: Novel post-compromise persistence technique that abuses Chromium’s Secure Preferences to silently inject malicious extensions — no active exploitation signals, but informs browser hardening strategy: audit enterprise extension allowlists and monitor Secure Preferences file integrity.
- SOC/IR — Plan: New persistence TTP worth adding detection coverage for this quarter: build hunts for unexpected modifications to Chrome/Edge Secure Preferences files and unauthorized extension injection outside the Web Store on managed endpoints, mapping to ATT&CK T1176.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.