Suspicious Access To Chrome Credential Files

PremiumReviewedSigma · High · v1
Product
windows
Service
security
Author
HuntRule
Published
2026-05-19
Updated
2026-08-28

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects read access to the Google Chrome Local State, Cookies and Login Data files by a process other than Chrome, captured via a SACL file audit and Security event 4663. In the WithSecure Windows Lab 4 tooling such as Chlonium or Mimikatz reads these files to steal the DPAPI master key and decrypt session cookies and stored passwords. Attackers harvest browser credentials and session tokens for account takeover.

Related detections9 linkedT1555.003 — drag to rearrange
Suspicious Access to Chrome Login Data on macOS (via process_creation)
Windows SQLite CLI Querying Chromium Browser Profile Databases
Possible Citrix Bleed Session Token Leak via OpenID Configuration Endpoint (CVE-2023-4966) (via webserver)
Malicious Fake Fortinet Patch Infostealer Execution (via process_creation)
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Malicious Interlock Credential Stealer Output File
Malicious Browser Master Key Decryption Artifacts Written by Katz Stealer (via file_event)
Uncommon Browser Launched with Remote Debugging Port for Cookie Theft (via process_creation)
Suspicious AppleScript Payload Execution via osascript (macOS)
Suspicious Access To Chrome Credential Files
Pivot detection · T1555.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.