Windows Process Creation: BrowserCore.exe Renamed Execution for Azure Token Theft

Flags renamed BrowserCore.exe executions by matching OriginalFileName while the process image ends with BrowserCore.exe.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Max Altgelt (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-06-02
Updated
2026-07-30

ATT&CK techniques

Defense Evasion → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

Identifies Windows process creation where the executable is launched as a renamed file but retains the OriginalFileName of BrowserCore.exe. This matters because attackers may masquerade as a legitimate browser component to extract authentication material, such as Azure tokens, while evading simplistic filename-based detections. The rule relies on process creation telemetry that includes both OriginalFileName and the Image path for the executed binary.

Related detections9 linkedT1528 — drag to rearrange
Malicious OAuth Application Granted Full Mailbox and EWS Permissions (via m365)
Suspicious GAM OAuth Token Enumeration via Process Creation
Renamed Autohotkey Binary
Suspicious Masqueraded Rundll32 with Mismatched Original Filename (via process_creation)
Suspicious Entra ID Device Code Flow Authentication
Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
Suspicious Renamed git Binary gcmd.exe Execution (via process_creation)
Renamed Execution of a Renamed Windows System Utility (via process_creation)
Suspicious OAuth Application Registration with Localhost Reply URL via Azure AD
Windows Process Creation: BrowserCore.exe Renamed Execution for Azure Token Theft
Pivot detection · T1528 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.