Analytics BIOC Low

Unusual process accessed a web browser history file

An unusual process has accessed a web browser history file.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007) Collection (TA0009)
ATT&CK techniques: Browser Information Discovery (T1217) Data from Local System (T1005) Automated Collection (T1119)
Detector tags: Sensitive Information Stealing Analytics
Attacker's goals:

Obtain access to the user's browsing history and steal their contents.

Investigative actions:

Determine whether it is legitimate for the process to access web browser history. Analyze the process/application that accessed the file. Check for any other suspicious actions that were performed by the process. Look for unusual access of resources using credentials that may be stored in the above file.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Unusual process accessed a web browser history file on Linux Low