Suspicious Browser Remote Debugging Port Cookie Theft via process_creation

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-08
Updated
2026-10-08

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects a Chromium based browser launched with the remote-debugging-port switch which attackers use to attach to the browser and steal cookies and session tokens without triggering DPAPI prompts. The Arcane stealer opened browsers with a remote debugging port to harvest authentication cookies. This technique bypasses cookie encryption so unexpected debugging launches warrant investigation.

Related detections9 linkedT1555.003 — drag to rearrange
Suspicious Chrome Launched With Remote Debugging Port For Cookie Theft
Malicious RemusStealer Credential Exfiltration to pics TLD C2
Suspicious Access to Chrome Login Data on macOS (via process_creation)
Suspicious Access To Chrome Credential Files
Windows SQLite CLI Querying Chromium Browser Profile Databases
Malicious Credential Stealer PowerShell Script Names Targeting Financial Services
Malicious VietCredCare Credential Exfiltration Staging Files
Suspicious CloudScout hxkz_zip Exfiltration Archive Creation via File System
Suspicious Non-Browser Access to Chromium Credential Stores
Suspicious Browser Remote Debugging Port Cookie Theft via process_creation
Pivot detection · T1555.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.