Skip to content
Threat Feed

Tag

Stealer

5 briefs RSS
high advisory

Windows Credential Access from Browser Password Store Detection

This brief describes a detection for suspicious activity on Windows systems where an uncommon or unauthorized process attempts to access browser user data profiles, a common behavior observed in Trojan Stealers like SnakeKeylogger to harvest sensitive browser information and credentials for exfiltration.

credential-access stealer windows endpoint-detection
1r 3t
high threat

Suspicious Process Accessing Browser Password Store

Detection of non-browser processes accessing browser user data folders, a tactic used by malware such as Snake Keylogger to steal credentials and sensitive information.

Splunk Enterprise +2 Snake Keylogger credential-access stealer windows
2r 1t
high threat

Non-Chrome Process Accessing Chrome Login Data

This analytic identifies non-Chrome processes accessing the Chrome user data file 'login data', an SQLite database containing sensitive information like saved passwords, potentially indicating credential theft attempts.

Chrome RedLine Stealer +1 credential-access stealer
2r 1t
high advisory

Non-Firefox Process Accessing Firefox Profile Directory

Detection of non-Firefox processes accessing the Firefox profile directory, potentially indicating malware attempting to steal user credentials and data.

Firefox credential-access stealer
2r 1t
high advisory

Non-Discord Application Accessing Discord LevelDB Database

This analytic detects non-Discord applications accessing the Discord LevelDB database by monitoring Windows Security Event logs (event code 4663), which may indicate attempts to steal Discord credentials or access sensitive user data, potentially compromising user profiles, messages, and other critical information.

Discord credential-access stealer windows
2r 1t