Windows File Access to Browser Credential Stores by Uncommon Processes

Detects suspicious process access to Firefox/Chromium credential store files on Windows, excluding common system and known benign paths.

FreeReviewedSigma · Low · v5
Product
windows
Category
file_access
Author
frack113, X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-04-09
Updated
2026-07-31
title: Windows File Access to Browser Credential Stores by Uncommon Processes
id: 4544308a-58d3-4224-8a39-98f29bbb1cab
related:
  - id: 4b60e527-ec73-4b47-8cb3-f02ad927ca65
    type: similar
  - id: 91cb43db-302a-47e3-b3c8-7ede481e27bf
    type: derived
status: test
description: This rule flags Windows file access events where a process reads specific browser credential-related files, such as Firefox cookies/places databases and Chromium Login Data/Local State, or the WebCache data file. Credential-stealing attempts often begin by directly accessing these on-disk browser stores, so unusual process access can indicate malicious collection. It relies on Microsoft-Windows-Kernel-File ETW telemetry containing the accessed FileName and the initiating Image, with process allowlisting to reduce noise.
references:
  - https://www.zscaler.com/blogs/security-research/ffdroider-stealer-targeting-social-media-platform-users
  - https://github.com/lclevy/firepwd
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/file/file_access/file_access_win_browsers_credential.yml
author: frack113, X__Junior (Nextron Systems), Huntrule Team
date: 2022-04-09
modified: 2024-07-29
tags:
  - attack.t1003
  - attack.credential-access
  - detection.threat-hunting
logsource:
  category: file_access
  product: windows
  definition: "Requirements: Microsoft-Windows-Kernel-File ETW provider"
detection:
  selection_ie:
    FileName|endswith: \Appdata\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
  selection_firefox:
    FileName|endswith:
      - \cookies.sqlite
      - \places.sqlite
      - release\key3.db
      - release\key4.db
      - release\logins.json
  selection_chromium:
    FileName|contains:
      - \User Data\Default\Login Data
      - \User Data\Local State
  filter_main_system:
    Image: System
  filter_main_generic:
    Image|startswith:
      - C:\Program Files (x86)\
      - C:\Program Files\
      - C:\Windows\system32\
      - C:\Windows\SysWOW64\
  filter_optional_defender:
    Image|startswith: C:\ProgramData\Microsoft\Windows Defender\
    Image|endswith:
      - \MpCopyAccelerator.exe
      - \MsMpEng.exe
  filter_optional_thor:
    Image|endswith:
      - \thor.exe
      - \thor64.exe
  condition: 1 of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Antivirus, Anti-Spyware, Anti-Malware Software
  - Backup software
  - Legitimate software installed on partitions other than "C:\"
  - Searching software such as "everything.exe"
level: low
license: DRL-1.1