Analytics BIOC
Informational
✕
Unusual process accessed web browser credentials
An unusual process has accessed a web browser credentials file.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores: Credentials from Web Browsers (T1555.003)
Detector tags: Credentials Grabbing Analytics
Attacker's goals:
Obtain access to credentials (such as cached logins) stored in the web browser.
Investigative actions:
Determine whether it is legitimate for the process to access web browser credential data directly. Analyze the process/application that accessed the credentials. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials cached in the web browser.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Unusual process accessed web browser credentials and executed by a terminal process High (parent: Informational)
- Unusual unsigned process accessed web browser credentials Low (parent: Informational)