Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0006 ✕

Download CSV Show ATT&CK heatmap
  • Unusual process accessed web browser credentials Informational 2 variations

    An unusual process has accessed a web browser credentials file.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Credentials from Password Stores: Credentials from Web Browsers (T1555.003)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Credentials Grabbing Analytics
    Attacker's goals: Obtain access to credentials (such as cached logins) stored in the web browser.
    Investigative actions: Determine whether it is legitimate for the process to access web browser credential data directly. Analyze the process/application that accessed the credentials. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials cached in the web browser.

    Variations

    Unusual process accessed web browser credentials and executed by a terminal process

    High overridden

    An unusual process has accessed a web browser credentials file. overridden

    Unusual unsigned process accessed web browser credentials

    Low overridden

    An unusual process has accessed a web browser credentials file. overridden