Sigma low test sigma

Access To Browser Credential Files By Uncommon Applications

Detects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage

View Source

Detection Logic

{
  "selection_ie": {
    "FileName
| endswith": "\\Appdata\\Local\\Microsoft\\Windows\\WebCache\\WebCacheV01.dat"
  },
  "selection_firefox": {
    "FileName
| endswith": [
      "\\cookies.sqlite",
      "\\places.sqlite",
      "release\\key3.db",
      "release\\key4.db",
      "release\\logins.json"
    ]
  },
  "selection_chromium": {
    "FileName
| contains": [
      "\\User Data\\Default\\Login Data",
      "\\User Data\\Local State"
    ]
  },
  "filter_main_system": {
    "Image": "System"
  },
  "filter_main_generic": {
    "Image
| startswith": [
      "C:\\Program Files (x86)\\",
      "C:\\Program Files\\",
      "C:\\Windows\\system32\\",
      "C:\\Windows\\SysWOW64\\"
    ]
  },
  "filter_optional_defender": {
    "Image
| startswith": "C:\\ProgramData\\Microsoft\\Windows Defender\\",
    "Image
| endswith": [
      "\\MpCopyAccelerator.exe",
      "\\MsMpEng.exe"
    ]
  },
  "filter_optional_thor": {
    "Image
| endswith": [
      "\\thor.exe",
      "\\thor64.exe"
    ]
  },
  "condition": "1 of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*"
}

False Positives

  • Antivirus, Anti-Spyware, Anti-Malware Software
  • Backup software
  • Legitimate software installed on partitions other than "C:\"
  • Searching software such as "everything.exe"

Field Validations

Loading…

Comments (0)

Loading comments...