elastic
high
kql
Potential Entra ID PRT Extraction via BrowserCore
Identifies anomalous execution of BrowserCore.exe, the Windows component used by Chromium-based browsers for native
messaging with the Web Account Manager (WAM). Adversaries abuse BrowserCore to extract Entra ID Primary Refresh Tokens
(PRTs) without interactive browser context, enabling session hijacking. Legitimate BrowserCore launches carry a
chrome-extension:// argument from the browser native-messaging host.