For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual process accessed web browser cookies

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

Credentials Grabbing Analytics

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal Web Session Cookie (T1539)

Severity

Informational

Description

An unusual process has accessed a web browser's session cookie store.

Attacker's Goals

Obtain access to or hijack sessions to websites stored in the web browser's cookies.

Investigative actions

  • Determine whether it is legitimate for the process to access session cookies directly.

  • Analyze the process/application that accessed the cookie store.

  • Check for any other suspicious actions that were performed by the process.

  • Look for unusual access to resources using credentials cached in the web browser/cookie store.

Variations

Unusual unsigned process accessed web browser cookies

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal Web Session Cookie (T1539)

Severity

Low

Description

An unusual process has accessed a web browser's session cookie store.

Attacker's Goals

Obtain access to or hijack sessions to websites stored in the web browser's cookies.

Investigative actions

  • Determine whether it is legitimate for the process to access session cookies directly.

  • Analyze the process/application that accessed the cookie store.

  • Check for any other suspicious actions that were performed by the process.

  • Look for unusual access to resources using credentials cached in the web browser/cookie store.

Was this helpful?