Spread Techniques Playbook

Red-team / threat-intelligence vectors mapped to AetherForge + Emberwake capabilities. For authorized penetration testing, lab environments, and defensive planning only. Landscape as of 2024–2026.

Use Emberwake for campaign builder, spread-kit export, supply-chain wizards, and War Room analytics. This page is the operator playbook — Emberwake stays focused on actions, not tutorials.

What does NOT work anymore

Modern browsers require a user click + run. Silent drive-by RCE, auto-run from Downloads, and CRX sideload via normal download are dead paths for commodity ops.
TechniqueStatusWhy
Silent browser RCE (visit → shell)DeadChromium sandboxes, site isolation, removed plugins
Auto-run from DownloadsDeadSmartScreen, MoTW, user-gesture requirements
Flash/Java plugin drive-byDeadPlugins removed or click-to-play extinct
Unauthenticated curl | bash on cautious adminsHardPipe-to-shell fingerprinting; inspect-before-run mitigations
CRX sideload via downloadDeadDownloadRestrictions; store policy blocks casual sideload

AetherForge stack — has vs needs

CapabilityStatus
GET /get, /install.sh, /install.ps1 with ?pin= + ?c=Working
Spread Kit ZIP export + static lander at /spread/Working
Emberwake campaign builder + War Room funnelWorking
WordPress plugin + npm helper export wizardsWorking
Fusion media ZIP bundlesWorking
USB perpetual propagation (forge flag)Working
LAN autospread / share spreadWorking
SocGholish fake-update branded landerStub
JS fingerprint / TDS gateNeeds
OAuth redirect helperNeeds
Public npm/PyPI typosquat publishOut of scope

Source matrix (markdown): SPREAD_TECHNIQUES.md