Windows Chromium Headless Execution with Mockbin/Mocky URL

Alerts when a Chromium-based browser runs headless on Windows with a mockbin-like URL in the command line.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-09-11
Updated
2026-07-31

What it detects

This rule flags Windows process creations where a Chromium-based browser (brave, chrome, edge, opera, or vivaldi) is launched with the --headless flag and a command-line URL containing mocky/mockbin indicators. Attackers can use headless browsers to automate access to web endpoints for staging or data exfiltration. The detection relies on process creation telemetry, specifically the executable path/name and the full command line.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.