Detection of Unauthorized Process Access to Browser Credential Stores
Detection of anomalous processes accessing browser user data directories indicates potential credential theft attempts by various information stealers.
This detection analytic identifies non-standard processes attempting to access sensitive browser user data directories on Windows systems. Threat actors frequently leverage this technique to exfiltrate saved credentials, cookies, and personal information as part of a broader credential theft or reconnaissance strategy. This behavior has been observed across numerous malware families, including SnakeKeylogger, StealC, and others documented in various intelligence reports. The detection relies on Windows Security Event ID 4663, which audits object access. By comparing the process requesting access to a curated list of authorized browsers, defenders can isolate malicious or suspicious activity that deviates from established baseline browser behavior.
Impact
Successful exfiltration of browser data provides attackers with immediate access to cached credentials for banking, corporate, and personal services, facilitating unauthorized account takeover, lateral movement, and long-term persistent access to the target environment.
Recommendation
- Enable "Audit Object Access" in Group Policy for the targeted directories to generate Event ID 4663 logs.
- Maintain a baseline list of authorized browser applications and their paths to minimize false positives in your environment.
- Deploy the provided Sigma rule to alert on non-browser processes attempting to read sensitive browser data files.
- Investigate any process flagged by the detection, focusing on the parent process lineage and potential network activity immediately following the access request.
Immediate actions
Enable Audit Object Access for browser profile directories
Threat Hunt
Search for processes identified by Event 4663 accessing User Data folders
Data: Windows Security Event 4663
Detection coverage 1
Detect Unauthorized Access to Browser Data Profiles
mediumDetects non-browser processes accessing browser user data folders, which is indicative of credential theft activity.
Detection queries are available on the platform. Get full rules →