• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Non-browser process accessing Chrome/Edge Login Data or Cookies DB

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•1

    Detects unauthorized processes attempting to access sensitive browser data files, specifically 'Login Data' (passwords) and 'Cookies' for Google Chrome and Microsoft Edge. The rule excludes the browser applications themselves and their update processes to minimize noise.

    Splunk (SPL)

    Tags

    T1555.003 - Credentials from Web BrowsersT1005 - Data from Local SystemTA0009 - CollectionFile AccessCredential AccessWindowsWindows Sysmonspl

    Found in

    • ClickFix Campaign Targets News Outlet with StealCLast updated 21 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 21 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 21 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 21 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?