1200KM / simulation
T1217 Browser Information Discovery — Attack Simulation
Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure. Browser information may also…
Technique description
Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure. Browser information may also…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- List Mozilla Firefox Bookmark Database Files on macOS
Procedure 1ca1f9c7-44bc-46bb-8c85-c50e2e94267b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- List Mozilla Firefox Bookmark Database Files on FreeBSD/Linux
Procedure 3a41f169-a5ab-407f-9269-abafdb5da6c2; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- List Mozilla Firefox bookmarks on Windows with command prompt
Procedure 4312cdbc-79fc-4a9c-becc-53d49c734bc5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- List Safari Bookmarks on MacOS
Procedure 5fc528dd-79de-47f5-8188-25572b7fafe0; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- List Internet Explorer Bookmarks using the command prompt
Procedure 727dbcdb-e495-4ab1-a6c4-80c7f77aef85; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Extract Edge Browsing History
Procedure 74094120-e1f5-47c9-b162-a418a0f624d5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- List Google Chrome / Edge Chromium Bookmarks on Windows with command prompt
Procedure 76f71e2f-480e-4bed-b61e-398fe17499d5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- List Google Chromium Bookmark JSON Files on FreeBSD
Procedure 88ca025b-3040-44eb-9168-bd8af22b82fa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- List Google Chrome Bookmark JSON Files on macOS
Procedure b789d341-154b-4a42-a071-9111588be9bc; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Extract chrome Browsing History
Procedure cfe6315c-4945-40f7-b5a4-48f7af2262af; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- List Google Chrome / Opera Bookmarks on Windows with powershell
Procedure faab755e-4299-48ec-8202-fc7885eb6545; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.