For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual process accessed web browser credentials

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detector Tags

Credentials Grabbing Analytics

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Credentials from Password Stores: Credentials from Web Browsers (T1555.003)

Severity

Informational

Description

An unusual process has accessed a web browser credentials file.

Attacker's Goals

Obtain access to credentials (such as cached logins) stored in the web browser.

Investigative actions

  • Determine whether it is legitimate for the process to access web browser credential data directly.

  • Analyze the process/application that accessed the credentials.

  • Check for any other suspicious actions that were performed by the process.

  • Look for unusual access to resources using credentials cached in the web browser.

Variations

Unusual process accessed web browser credentials and executed by a terminal process

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Credentials from Password Stores: Credentials from Web Browsers (T1555.003)

Severity

High

Description

An unusual process has accessed a web browser credentials file.

Attacker's Goals

Obtain access to credentials (such as cached logins) stored in the web browser.

Investigative actions

  • Determine whether it is legitimate for the process to access web browser credential data directly.

  • Analyze the process/application that accessed the credentials.

  • Check for any other suspicious actions that were performed by the process.

  • Look for unusual access to resources using credentials cached in the web browser.

Unusual unsigned process accessed web browser credentials

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Credentials from Password Stores: Credentials from Web Browsers (T1555.003)

Severity

Low

Description

An unusual process has accessed a web browser credentials file.

Attacker's Goals

Obtain access to credentials (such as cached logins) stored in the web browser.

Investigative actions

  • Determine whether it is legitimate for the process to access web browser credential data directly.

  • Analyze the process/application that accessed the credentials.

  • Check for any other suspicious actions that were performed by the process.

  • Look for unusual access to resources using credentials cached in the web browser.

Was this helpful?