Unusual process accessed a web browser history file
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Sensitive Information Stealing Analytics
ATT&CK Tactic
Discovery (TA0007), Collection (TA0009)
ATT&CK Technique
Browser Information Discovery (T1217), Data from Local System (T1005), Automated Collection (T1119)
Severity
Low
Description
An unusual process has accessed a web browser history file.
Attacker's Goals
Obtain access to the user's browsing history and steal their contents.
Investigative actions
Determine whether it is legitimate for the process to access web browser history.
Analyze the process/application that accessed the file.
Check for any other suspicious actions that were performed by the process.
Look for unusual access of resources using credentials that may be stored in the above file.
Variations
Was this helpful?
