BIOC Informational

Password-related Mozilla files were read by a non-Mozilla process

Adversaries may acquire credentials from web browsers by reading files specific to the target browser.

Module:
Platform Analytics
Agent event type:
File
Category:
Credential Access
Status:
Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores: Credentials from Web Browsers (T1555.003)
Indicator:

File file path = *\mozilla\firefox\* , *\netgate technologies\blackhawk\* , *\8pecxstudios\cyberfox\* , *\comodo\icedragon\* , *\k-meleon\* , *\mozilla\icecat\* AND file name = *.sqlite , *.db , *.json AND action type = read Process initiated by != firefox.exe AND blackhawk.exe AND cyberfox.exe AND icedragon.exe AND k-meleon.exe AND icecat

Preventable: yes