Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-08-20
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects browsercore.exe launched by a process other than a known browser or task host, a pattern used to request a PRT cookie for cloud authentication abuse. The cloud lateral-movement research shows attackers invoke browsercore outside its normal browser context to obtain single sign-on artifacts. An unexpected parent for this binary is a heuristic sign of token theft.

Related detections9 linkedT1550.001 — drag to rearrange
Suspicious Kubernetes Service Account Token Generation via kubectl
Suspicious AWS SSO Account Role Enumeration via ListAccountRoles (via cloudtrail)
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious Device Registration Following OAuth Token Theft
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious Entra Agent Service Principal Sign-In With PowerShell User Agent via Sign-In Logs
Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
Possible Check Point SmartConsole Token Redemption Endpoint Access (via proxy)
Suspicious AWS STS Session Token and Role Chaining Abuse via CloudTrail (via aws)
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
Pivot detection · T1550.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.