Browser Information Discovery T1217
Tactic: Discovery
Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.
Events covered
3 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
Authoring guide
These 6 rules share fields, values, and exclusions.
Fields filtered most (17 distinct)
These fields appear most often in rule filters.
Top indicator values (205 distinct)
These values appear most often in rule predicates.
Exclusions (130 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Windows
Domain: Endpoint
Sigma 4 rules
- Automated Collection Bookmarks Using Get-ChildItem PowerShell
- File And SubFolder Enumeration Via Dir Command
- Suspicious File Access to Browser Credential Storage
- Suspicious Where Execution