{"id":"T1218.015","name":"Electron Applications","url":"https://attack.mitre.org/techniques/T1218/015","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0025","stix_id":"x-mitre-detection-strategy--d41df11d-b2cd-4afc-89a5-9c77e7f31985","name":"Detecting Electron Application Abuse for Proxy Execution","url":"https://attack.mitre.org/detectionstrategies/DET0025","analytics":[{"id":"AN0071","stix_id":"x-mitre-analytic--dc0bf4ca-1d65-46ee-b4b1-d8f73a6e0cda","name":"Analytic 0071","description":"Abuse of trusted Electron apps (Teams, Slack, Chrome) to spawn child processes or execute payloads via malicious command-line arguments (e.g., --gpu-launcher) and modified app resources (.asar). Behavior chain: suspicious parent process (Electron app) → unusual command-line args → child process creation → optional DLL/network artifacts.","url":"https://attack.mitre.org/detectionstrategies/DET0025#AN0071","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window tying app launch, file tampering, child process, and network events (5–10 minutes typical)."},{"field":"UserContext","description":"Flag admin/service accounts versus standard users executing Electron apps."},{"field":"AllowedElectronApps","description":"Baseline of Electron-based executables expected in the enterprise."},{"field":"AllowedChildProcesses","description":"Whitelist normal child processes (chrome.exe → crashpad_handler.exe) versus anomalies (powershell.exe)."},{"field":"ElectronAppDomainAllowlist","description":"Approved service domains for Teams, Slack, etc. to suppress benign traffic."},{"field":"AsarIntegrityHash","description":"Expected hash/signature of app.asar resources to detect tampering."}],"live":true,"detection_strategies":["DET0025"],"techniques":["T1218.015"]},{"id":"AN0072","stix_id":"x-mitre-analytic--8129e7b8-eaa1-4459-ba70-ebf6d68ca16c","name":"Analytic 0072","description":"Abuse of Linux Electron binaries by modifying app.asar or config JS files and spawning unexpected child processes (bash, curl, python).","url":"https://attack.mitre.org/detectionstrategies/DET0025#AN0072","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Electron-based binary spawning shell or script interpreter","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AsarIntegrityCheck","description":"Baseline of expected asar package signatures per app."},{"field":"SuspiciousChildProcesses","description":"Flag shells/python spawned from Electron parent."}],"live":true,"detection_strategies":["DET0025"],"techniques":["T1218.015"]},{"id":"AN0073","stix_id":"x-mitre-analytic--f2c91a4c-1e79-4350-8a7e-94bc7b7b9a4c","name":"Analytic 0073","description":"Abuse of macOS Electron apps by modifying app.asar bundles and spawning child processes (osascript, curl, sh) from Electron executables.","url":"https://attack.mitre.org/detectionstrategies/DET0025#AN0073","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Electron app spawning unexpected child process","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"CREATE/MODIFY: Modification of app.asar inside .app bundle","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"AllowedAppBundlePaths","description":"Baseline of legitimate Electron app paths under /Applications."},{"field":"SignedToUnsignedTransition","description":"Alert when signed Electron parent spawns unsigned child."}],"live":true,"detection_strategies":["DET0025"],"techniques":["T1218.015"]}],"live":true,"version":"1.0","techniques":["T1218.015"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}