Windows process execution of where.exe with browser bookmark database or history artifacts

Alerts on where.exe executions referencing browser history/bookmarks/cookie database artifacts in the command line.

FreeReviewedSigma · Low · v1
Product
windows
Category
process_creation
Author
frack113, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-12-13
Updated
2026-07-30

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows process creation events where.exe is executed and the command line contains strings associated with browser data sources such as Firefox places.sqlite/cookies.sqlite/formhistory.sqlite/logins.json/key3.db/key4.db/sessionstore.jsonlz4 or Chrome History/Bookmarks/Cookies/Login Data. Attackers may use where.exe-like enumeration to locate or validate the presence of user or internal web artifacts that can aid discovery and follow-on access. The detection relies on process creation telemetry and string matches in the executed command line.

Related detections3 linkedT1217 — drag to rearrange
Windows File Access to Browser Credential Storage by Non-Browser Processes
Windows CMD dir /S File and Subfolder Enumeration
PowerShell Script Block Collection of Browser Bookmarks via Get-ChildItem
Windows process execution of where.exe with browser bookmark database or history artifacts
Pivot detection · T1217 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.