Analytics BIOC
Informational
✕
Unusual process accessed web browser cookies
An unusual process has accessed a web browser's session cookie store.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Steal Web Session Cookie (T1539)
Detector tags: Credentials Grabbing Analytics
Attacker's goals:
Obtain access to or hijack sessions to websites stored in the web browser's cookies.
Investigative actions:
Determine whether it is legitimate for the process to access session cookies directly. Analyze the process/application that accessed the cookie store. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials cached in the web browser/cookie store.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Unusual unsigned process accessed web browser cookies Low (parent: Informational)