Suspicious Browser Launch With Remote Debugging for Cookie Theft (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-05-04
Updated
2026-08-28

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects a Chromium-based browser launched with both a remote debugging port and a custom user data directory. Phantom Goblin abuses this to extract cookies and session data directly from the browser.

Related detections9 linkedT1539 — drag to rearrange
Possible Citrix Bleed Session Token Leak via OpenID Configuration Endpoint (CVE-2023-4966) (via webserver)
Uncommon Browser Launched with Remote Debugging Port for Cookie Theft (via process_creation)
Malicious Chrome Extension Sideload via --load-extension from User-Writable Path (via process_creation)
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Possible Citrix NetScaler CVE-2023-4966 Session Token Disclosure
Suspicious Access to Chrome Login Data on macOS (via process_creation)
Suspicious Access To Chrome Credential Files
Windows SQLite CLI Querying Chromium Browser Profile Databases
Windows Process Creation: SQLite Access to Firefox Profile Databases
Suspicious Browser Launch With Remote Debugging for Cookie Theft (via process_creation)
Pivot detection · T1539 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.