Detection rules › Sigma
Access To Browser Credential Files By Uncommon Applications
Detects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage
Known false positives
- Antivirus, Anti-Spyware, Anti-Malware Software
- Backup software
- Legitimate software installed on partitions other than "C:\"
- Searching software such as "everything.exe"
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Credential Access |
Rule body
title: Access To Browser Credential Files By Uncommon Applications
id: 91cb43db-302a-47e3-b3c8-7ede481e27bf
related:
- id: 4b60e527-ec73-4b47-8cb3-f02ad927ca65
type: similar
status: test
description: |
Detects file access requests to browser credential stores by uncommon processes.
Could indicate potential attempt of credential stealing.
Requires heavy baselining before usage
references:
- https://www.zscaler.com/blogs/security-research/ffdroider-stealer-targeting-social-media-platform-users
- https://github.com/lclevy/firepwd
author: frack113, X__Junior (Nextron Systems)
date: 2022-04-09
modified: 2024-07-29
tags:
- attack.t1003
- attack.credential-access
- detection.threat-hunting
logsource:
category: file_access
product: windows
definition: 'Requirements: Microsoft-Windows-Kernel-File ETW provider'
detection:
selection_ie:
FileName|endswith: '\Appdata\Local\Microsoft\Windows\WebCache\WebCacheV01.dat'
selection_firefox:
FileName|endswith:
- '\cookies.sqlite'
- '\places.sqlite'
- 'release\key3.db' # Firefox
- 'release\key4.db' # Firefox
- 'release\logins.json' # Firefox
selection_chromium:
FileName|contains:
- '\User Data\Default\Login Data'
- '\User Data\Local State'
filter_main_system:
Image: System
filter_main_generic:
# This filter is added to avoid large amount of FP with 3rd party software. You should remove this in favour of specific filter per-application
Image|startswith:
- 'C:\Program Files (x86)\'
- 'C:\Program Files\'
- 'C:\Windows\system32\'
- 'C:\Windows\SysWOW64\'
filter_optional_defender:
Image|startswith: 'C:\ProgramData\Microsoft\Windows Defender\'
Image|endswith:
- '\MpCopyAccelerator.exe'
- '\MsMpEng.exe'
filter_optional_thor:
Image|endswith:
- '\thor.exe'
- '\thor64.exe'
condition: 1 of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Antivirus, Anti-Spyware, Anti-Malware Software
- Backup software
- Legitimate software installed on partitions other than "C:\"
- Searching software such as "everything.exe"
level: low
Stages and Predicates
Stage 0: condition
1 of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*Stage 1: selection_ie
selection_ie:
FileName|endswith: '\Appdata\Local\Microsoft\Windows\WebCache\WebCacheV01.dat'
Stage 2: selection_firefox
selection_firefox:
FileName|endswith:
- '\cookies.sqlite'
- '\places.sqlite'
- 'release\key3.db'
- 'release\key4.db'
- 'release\logins.json'
Stage 3: selection_chromium
selection_chromium:
FileName|contains:
- '\User Data\Default\Login Data'
- '\User Data\Local State'
Stage 4: not filter_main_*
filter_main_system:
Image: System
filter_main_generic:
Image|startswith:
- 'C:\Program Files (x86)\'
- 'C:\Program Files\'
- 'C:\Windows\system32\'
- 'C:\Windows\SysWOW64\'
Stage 5: not filter_optional_*
filter_optional_defender:
Image|startswith: 'C:\ProgramData\Microsoft\Windows Defender\'
Image|endswith:
- '\MpCopyAccelerator.exe'
- '\MsMpEng.exe'
filter_optional_thor:
Image|endswith:
- '\thor.exe'
- '\thor64.exe'
Exclusions
The rule actively suppresses these predicates.
| Field | Kind | Excluded values | Search |
|---|---|---|---|
Image | eq | System | excludes:Image field:"Image" value:"System" |
Image | starts_with | C:\Program Files (x86)\ | excludes:Image field:"Image" value:"C:\Program Files (x86)\" |
Image | starts_with | C:\Program Files\ | excludes:Image field:"Image" value:"C:\Program Files\" |
Image | starts_with | C:\Windows\SysWOW64\ | excludes:Image field:"Image" value:"C:\Windows\SysWOW64\" |
Image | starts_with | C:\Windows\system32\ | excludes:Image field:"Image" value:"C:\Windows\system32\" |
Image | ends_with | \MpCopyAccelerator.exe | excludes:Image field:"Image" value:"\MpCopyAccelerator.exe" |
Image | ends_with | \MsMpEng.exe | excludes:Image field:"Image" value:"\MsMpEng.exe" |
Image | starts_with | C:\ProgramData\Microsoft\Windows Defender\ | excludes:Image field:"Image" value:"C:\ProgramData\Microsoft\Windows Defender\" |
Image | ends_with | \thor.exe | excludes:Image field:"Image" value:"\thor.exe" |
Image | ends_with | \thor64.exe | excludes:Image field:"Image" value:"\thor64.exe" |
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
FileName | ends_with |
| field:"file_name" kind:ends_with |
FileName | match |
| field:"file_name" kind:match |