Sigma low test sigma
Access To Browser Credential Files By Uncommon Applications
Detects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage
Detection Logic
{
"selection_ie": {
"FileName
| endswith": "\\Appdata\\Local\\Microsoft\\Windows\\WebCache\\WebCacheV01.dat"
},
"selection_firefox": {
"FileName
| endswith": [
"\\cookies.sqlite",
"\\places.sqlite",
"release\\key3.db",
"release\\key4.db",
"release\\logins.json"
]
},
"selection_chromium": {
"FileName
| contains": [
"\\User Data\\Default\\Login Data",
"\\User Data\\Local State"
]
},
"filter_main_system": {
"Image": "System"
},
"filter_main_generic": {
"Image
| startswith": [
"C:\\Program Files (x86)\\",
"C:\\Program Files\\",
"C:\\Windows\\system32\\",
"C:\\Windows\\SysWOW64\\"
]
},
"filter_optional_defender": {
"Image
| startswith": "C:\\ProgramData\\Microsoft\\Windows Defender\\",
"Image
| endswith": [
"\\MpCopyAccelerator.exe",
"\\MsMpEng.exe"
]
},
"filter_optional_thor": {
"Image
| endswith": [
"\\thor.exe",
"\\thor64.exe"
]
},
"condition": "1 of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*"
} False Positives
- ⚠ Antivirus, Anti-Spyware, Anti-Malware Software
- ⚠ Backup software
- ⚠ Legitimate software installed on partitions other than "C:\"
- ⚠ Searching software such as "everything.exe"
Field Validations
Loading…
Comments (0)
Loading comments...