BIOC
Informational
✕
Password-related Mozilla files were read by a non-Mozilla process
Adversaries may acquire credentials from web browsers by reading files specific to the target browser.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Credential Access
- Status:
- Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores: Credentials from Web Browsers (T1555.003)
Indicator:
File file path = *\mozilla\firefox\* , *\netgate technologies\blackhawk\* , *\8pecxstudios\cyberfox\* , *\comodo\icedragon\* , *\k-meleon\* , *\mozilla\icecat\* AND file name = *.sqlite , *.db , *.json AND action type = read Process initiated by != firefox.exe AND blackhawk.exe AND cyberfox.exe AND icedragon.exe AND k-meleon.exe AND icecat
Preventable: yes