Windows File Access to Browser Credential Storage by Non-Browser Processes

Flags non-browser processes reading common browser credential storage files on Windows, indicating potential credential theft.

FreeReviewedSigma · Low · v2
Product
windows
Category
file_access
Author
frack113, X__Junior (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Parth-FourCore (SigmaHQ), DRL 1.1
Published
2025-05-22
Updated
2026-07-31

ATT&CK techniques

Cred Access → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows file access where the accessed path includes browser credential storage locations (such as Login Data, Cookies, EncryptedStorage, and related browser database files) combined with browser profile subpaths. It aims to identify attempts by non-browser processes to read sensitive browser data that attackers can use to obtain usernames, passwords, and session cookies. The detection relies on file_access telemetry including the accessed FileName and the creating process Image/ParentImage to distinguish likely non-browser access.

Related detections9 linkedT1555.003 — drag to rearrange
Suspicious Clipboard Data Access via Get-Clipboard (BeaverTail OtterCookie)
Malicious Edge Credential Parser Execution via PowerShell (via process_creation)
SapphireStealer Working Directory File Drop in Temp
Malicious RemusStealer Credential Exfiltration to pics TLD C2
Suspicious Local Password Validation via dscl authonly
Malicious Fake Fortinet Patch Infostealer Execution (via process_creation)
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Malicious Interlock Credential Stealer Output File
Malicious Browser Master Key Decryption Artifacts Written by Katz Stealer (via file_event)
Windows File Access to Browser Credential Storage by Non-Browser Processes
Pivot detection · T1555.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.