Analytics BIOC Informational

Unusual process accessed web browser credentials

An unusual process has accessed a web browser credentials file.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores: Credentials from Web Browsers (T1555.003)
Detector tags: Credentials Grabbing Analytics
Attacker's goals:

Obtain access to credentials (such as cached logins) stored in the web browser.

Investigative actions:

Determine whether it is legitimate for the process to access web browser credential data directly. Analyze the process/application that accessed the credentials. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials cached in the web browser.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Unusual process accessed web browser credentials and executed by a terminal process High (parent: Informational)
  • Unusual unsigned process accessed web browser credentials Low (parent: Informational)