Skip to content
Threat Feed
medium advisory

Detection of Unauthorized Process Access to Browser Credential Stores

Detection of anomalous processes accessing browser user data directories indicates potential credential theft attempts by various information stealers.

This detection analytic identifies non-standard processes attempting to access sensitive browser user data directories on Windows systems. Threat actors frequently leverage this technique to exfiltrate saved credentials, cookies, and personal information as part of a broader credential theft or reconnaissance strategy. This behavior has been observed across numerous malware families, including SnakeKeylogger, StealC, and others documented in various intelligence reports. The detection relies on Windows Security Event ID 4663, which audits object access. By comparing the process requesting access to a curated list of authorized browsers, defenders can isolate malicious or suspicious activity that deviates from established baseline browser behavior.

Impact

Successful exfiltration of browser data provides attackers with immediate access to cached credentials for banking, corporate, and personal services, facilitating unauthorized account takeover, lateral movement, and long-term persistent access to the target environment.

Recommendation

  1. Enable "Audit Object Access" in Group Policy for the targeted directories to generate Event ID 4663 logs.
  2. Maintain a baseline list of authorized browser applications and their paths to minimize false positives in your environment.
  3. Deploy the provided Sigma rule to alert on non-browser processes attempting to read sensitive browser data files.
  4. Investigate any process flagged by the detection, focusing on the parent process lineage and potential network activity immediately following the access request.

Immediate actions

Enable Audit Object Access for browser profile directories

IT Operations 72h

Threat Hunt

Search for processes identified by Event 4663 accessing User Data folders

T1012 medium medium confidence convert to detection

Data: Windows Security Event 4663

Detection coverage 1

Detect Unauthorized Access to Browser Data Profiles

medium

Detects non-browser processes accessing browser user data folders, which is indicative of credential theft activity.

sigma tactics: credential_access techniques: T1012 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →