Uncommon Browser Launched with Remote Debugging Port for Cookie Theft (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-08-29
Updated
2026-08-29

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects a Chromium-based browser started with a remote debugging port flag, the technique Electron-based gaming stealers use to attach to the browser and dump cookies directly from a debugged instance. Adversaries launch the browser in debug mode to bypass cookie encryption and harvest session tokens. Debug-mode browser launches are rare outside developer tooling.

Related detections9 linkedT1539 — drag to rearrange
Possible Citrix Bleed Session Token Leak via OpenID Configuration Endpoint (CVE-2023-4966) (via webserver)
Malicious Chrome Extension Sideload via --load-extension from User-Writable Path (via process_creation)
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Possible Citrix NetScaler CVE-2023-4966 Session Token Disclosure
Suspicious Access to Chrome Login Data on macOS (via process_creation)
Suspicious Access To Chrome Credential Files
Suspicious Browser Launch With Remote Debugging for Cookie Theft (via process_creation)
Windows SQLite CLI Querying Chromium Browser Profile Databases
Windows Process Creation: SQLite Access to Firefox Profile Databases
Uncommon Browser Launched with Remote Debugging Port for Cookie Theft (via process_creation)
Pivot detection · T1539 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.