Potential Browser Debugging via Localhost


Description

Identifies localhost network connection between a Chromium-based browser and another process, which may indicate an attempt to debug the browser process via Chromium browser APIs to steal authentication information such as getAllCookies.

Query · eql

sequence with maxspan=5s
 [network where process.pid != 4 and event.action == "connection_accepted" and network.direction == "ingress" and
  process.name in~ ("chrome.exe", "msedge.exe") and source.address like "127.*" and destination.address like "127.*" and
  process.executable :
            ("?:\\Program Files\\Google\\Chrome\\Application\\chrome.exe",
             "?:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe",
             "?:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
             "?:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe")] as event0
 [api where process.Ext.api.name == "connect" and process.Ext.api.summary like "connect( ipv4, tcp, 127.*, * )" and
  endswith~(process.Ext.api.summary, concat(event0.destination.port, " )")) and event0.process.pid != process.pid and
  process.thread.Ext.call_stack_final_user_module.hash.sha256 != null and
  _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry, $entry.trusted == false or $entry.exists == false) and
  not _arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info: "*chromedriver.exe!GetHandleVerifier*") and
  not process.thread.Ext.call_stack_final_user_module.path : ("c:\\windows\\assembly\\nativeimages_v*\\system.ni.dll", "c:\\windows\\system32\\samsrv.dll") and
  not process.thread.Ext.call_stack_final_user_module.name in ("Unknown", "Undetermined") and
  not process.thread.Ext.call_stack_final_user_module.hash.sha256 in
                                      ("df16aa50573f8f212bf37cad492903cddab482b803d78635984313e76fbadc01",
                                       "70d1254a5036902b3f5a75d376b3760adaf780e5642ef53726e1aaf36a66af97",
                                       "609667eee9c70de0e530e89cfb2880646ce3141439e4a9482fb4f09ac987233e",
                                       "6c2416a1a092392c5d1aaa71ed2196244fb3318679eb34693eba078a8a4cafaf",
                                       "ba21fb58c0be6963b7dba8efdfa8b772b014b2fa3c455f6328101f2ae883859a",
                                       "5284115e5f0c5b5637b06d997f3a207266b284030bb6aa871053bbb252846d18", 
                                       "124a0ccd28e94ecaf776bbc3162536c98bb776cd35c97dcb10888e030dc888cd", 
                                       "451fee99ad986f8e6424128a9b4b2c8448116467eb0b81d620129ee1bd2dd1b9",
                                       "8a4836504d8012fda22ba8dd04e4e3e157e5a6bb94bdd94327fcc29c3693979f",
                                       "f5efbbdb213f4c4d3ea5c38ce1307aa72d04dc6d53347cd90fa0f53e9e4099cf",
                                       "b2d32d44a52ce88a71c53ef9386fe00476f7a4dbca8a4c48699f17b38214599b",
                                       "7bc1900eb03326975191e09edd999c4c08e5d16775e7c47808c5fd5a9ecda033",
                                       "1d43aeffed77ab28ed529472758d079837be5fc7cc611c43d791ee37d3b71d89",
                                       "c78b0d66fba7e4bd500f34223acd433d282f5dc7321e2887141be23049c31141",
                                       "d560bf8624329838c4e518ef86e9ffa50468a8ccd13067ff9d22ac6715b32299")]
Raw source Potential Browser Debugging via Localhost · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
Identifies localhost network connection between a Chromium-based browser and another process, which may indicate an
attempt to debug the browser process via Chromium browser APIs to steal authentication information such as
getAllCookies.
"""
id = "c86090ab-b507-40b6-abdf-2d7104454d49"
license = "Elastic License v2"
name = "Potential Browser Debugging via Localhost"
os_list = ["windows"]
reference = [
    "https://github.com/defaultnamehere/cookie_crimes",
    "https://embracethered.com/blog/posts/2020/cookie-crimes-on-mirosoft-edge/",
    "https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/post/multi/gather/chrome_cookies.md",
    "https://posts.specterops.io/hands-in-the-cookie-jar-dumping-cookies-with-chromiums-remote-debugger-port-34c4f468844e",
    "https://github.com/BishopFox/sliver/wiki/Cursed",
]
version = "1.0.7"

query = '''
sequence with maxspan=5s
 [network where process.pid != 4 and event.action == "connection_accepted" and network.direction == "ingress" and
  process.name in~ ("chrome.exe", "msedge.exe") and source.address like "127.*" and destination.address like "127.*" and
  process.executable :
            ("?:\\Program Files\\Google\\Chrome\\Application\\chrome.exe",
             "?:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe",
             "?:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe",
             "?:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe")] as event0
 [api where process.Ext.api.name == "connect" and process.Ext.api.summary like "connect( ipv4, tcp, 127.*, * )" and
  endswith~(process.Ext.api.summary, concat(event0.destination.port, " )")) and event0.process.pid != process.pid and
  process.thread.Ext.call_stack_final_user_module.hash.sha256 != null and
  _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry, $entry.trusted == false or $entry.exists == false) and
  not _arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info: "*chromedriver.exe!GetHandleVerifier*") and
  not process.thread.Ext.call_stack_final_user_module.path : ("c:\\windows\\assembly\\nativeimages_v*\\system.ni.dll", "c:\\windows\\system32\\samsrv.dll") and
  not process.thread.Ext.call_stack_final_user_module.name in ("Unknown", "Undetermined") and
  not process.thread.Ext.call_stack_final_user_module.hash.sha256 in
                                      ("df16aa50573f8f212bf37cad492903cddab482b803d78635984313e76fbadc01",
                                       "70d1254a5036902b3f5a75d376b3760adaf780e5642ef53726e1aaf36a66af97",
                                       "609667eee9c70de0e530e89cfb2880646ce3141439e4a9482fb4f09ac987233e",
                                       "6c2416a1a092392c5d1aaa71ed2196244fb3318679eb34693eba078a8a4cafaf",
                                       "ba21fb58c0be6963b7dba8efdfa8b772b014b2fa3c455f6328101f2ae883859a",
                                       "5284115e5f0c5b5637b06d997f3a207266b284030bb6aa871053bbb252846d18", 
                                       "124a0ccd28e94ecaf776bbc3162536c98bb776cd35c97dcb10888e030dc888cd", 
                                       "451fee99ad986f8e6424128a9b4b2c8448116467eb0b81d620129ee1bd2dd1b9",
                                       "8a4836504d8012fda22ba8dd04e4e3e157e5a6bb94bdd94327fcc29c3693979f",
                                       "f5efbbdb213f4c4d3ea5c38ce1307aa72d04dc6d53347cd90fa0f53e9e4099cf",
                                       "b2d32d44a52ce88a71c53ef9386fe00476f7a4dbca8a4c48699f17b38214599b",
                                       "7bc1900eb03326975191e09edd999c4c08e5d16775e7c47808c5fd5a9ecda033",
                                       "1d43aeffed77ab28ed529472758d079837be5fc7cc611c43d791ee37d3b71d89",
                                       "c78b0d66fba7e4bd500f34223acd433d282f5dc7321e2887141be23049c31141",
                                       "d560bf8624329838c4e518ef86e9ffa50468a8ccd13067ff9d22ac6715b32299")]
'''

min_endpoint_version = "8.10.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 1

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1539"
name = "Steal Web Session Cookie"
reference = "https://attack.mitre.org/techniques/T1539/"


[threat.tactic]
id = "TA0006"
name = "Credential Access"
reference = "https://attack.mitre.org/tactics/TA0006/"

[internal]
min_endpoint_version = "8.10.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.