BIOC Informational

Unsigned process accessed a Thunderbird Mail profiles folder

An attacker may access the Thunderbird Mail profiles folder to extract users' credentials.

Module:
Platform Analytics
Agent event type:
File
Category:
Credential Access
Status:
Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores (T1555)
Indicator:

File action type = all AND file path = *\appdata\*thunderbird\profile* Process initiator signature = Unsigned , cgo signature = Unsigned , os parent signature = Unsigned AND initiator path != *Program Files* AND cgo path != *Program Files* AND os parent path != *Program Files* Host host os != linux AND host os = windows

Preventable: yes