Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0006 ✕ technique: T1555 ✕
Download CSV Show ATT&CK heatmapUnusual process accessed web browser credentials Informational 2 variations
An unusual process has accessed a web browser credentials file.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Credentials from Password Stores: Credentials from Web Browsers (T1555.003)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Credentials Grabbing AnalyticsAttacker's goals: Obtain access to credentials (such as cached logins) stored in the web browser.Investigative actions: Determine whether it is legitimate for the process to access web browser credential data directly. Analyze the process/application that accessed the credentials. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials cached in the web browser.Variations
Unusual process accessed web browser credentials and executed by a terminal process
High overridden
An unusual process has accessed a web browser credentials file. overridden
Unusual unsigned process accessed web browser credentials
Low overridden
An unusual process has accessed a web browser credentials file. overridden