1200KM / detection
T1555.003 Credentials from Web Browsers — Detection Rules
Detection workspace for T1555.003 Credentials from Web Browsers: 7 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious File Access to Browser Credential Storage · experimental · low · {"category":"file_access","product":"windows"}
- Access to Browser Login Data · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - WinPwn Execution - ScriptBlock · test · high · {"category":"ps_script","product":"windows","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - WinPwn Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - WebBrowserPassView Execution · test · medium · {"category":"process_creation","product":"windows"}
- SQLite Chromium Profile Data DB Access · test · high · {"category":"process_creation","product":"windows"}
- Potential Browser Data Stealing · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0037 Detect Suspicious Access to Browser Credential Stores
AN0105 Analytic 0105
Detects unauthorized access to web browser credential stores (e.g., Chrome Login Data, Edge Credential Locker) by processes other than the browser itself. Correlates file reads of credential databases with subsequent API calls to `CryptUnprotectData` or memory inspection attempts.
AN0106 Analytic 0106
Detects attempts to access browser credential stores (e.g., Firefox `logins.json`, Chrome SQLite DB) or processes (e.g., gnome-keyring-daemon). Observes unauthorized file reads and memory inspection of browser processes using ptrace or gdb.
AN0107 Analytic 0107
Detects abnormal access to Safari credential stores (Keychain-backed) or Chrome/Firefox login databases. Observes processes executing `security dump-keychain` or directly reading credential files in `~/Library/Application Support`. Correlates file access with suspicious process ancestry or unsigned binaries.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Molerats · G0021
- APT3 · G0022
- Sandworm Team · G0034
- FIN6 · G0037
- Stealth Falcon · G0038
- Patchwork · G0040
- OilRig · G0049
- APT33 · G0064
- APT37 · G0067
- MuddyWater · G0069
- Leafminer · G0077
- TA505 · G0092
- Kimsuky · G0094
- APT41 · G0096
- Inception · G0100
- ZIRCONIUM · G0128
- Ajax Security Team · G0130
- HEXANE · G1001
- LAPSUS$ · G1004
- Volt Typhoon · G1017
- Malteiro · G1026
- RedCurl · G1039
- APT42 · G1044
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.