Windows Browser Launched with Remote Debugging Flags

Alerts on Windows launches of Chromium-based browsers or Firefox with remote debugging command-line flags.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-27
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies when a Chromium-based browser is started with command-line arguments containing --remote-debugging-, or when Firefox is started with -start-debugger-server. Remote debugging enables an external control interface that attackers can abuse for browser manipulation and related injection workflows. It relies on Windows process creation telemetry, matching on the process command line (and Firefox image path suffix for that case).

Related detections2 linkedT1185 — drag to rearrange
Suspicious Browser Launch With Remote Debugging Port via Process Creation
Windows Chromium-Based Browsers Launched with Headless Debugging and User Profile Directory
Windows Browser Launched with Remote Debugging Flags
Pivot detection · T1185 · 2 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.