Access To Browser Credential Files By Uncommon Applications
Description
Detects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage
Query · sigma
selection_ie: FileName|endswith: \Appdata\Local\Microsoft\Windows\WebCache\WebCacheV01.dat selection_firefox: FileName|endswith: - \cookies.sqlite - \places.sqlite - release\key3.db - release\key4.db - release\logins.json selection_chromium: FileName|contains: - \User Data\Default\Login Data - \User Data\Local State filter_main_system: Image: System filter_main_generic: Image|startswith: - C:\Program Files (x86)\ - C:\Program Files\ - C:\Windows\system32\ - C:\Windows\SysWOW64\ filter_optional_defender: Image|startswith: C:\ProgramData\Microsoft\Windows Defender\ Image|endswith: - \MpCopyAccelerator.exe - \MsMpEng.exe filter_optional_thor: Image|endswith: - \thor.exe - \thor64.exe condition: 1 of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
Known false positives
- Antivirus, Anti-Spyware, Anti-Malware Software
- Backup software
- Legitimate software installed on partitions other than "C:\"
- Searching software such as "everything.exe"