Find sigma rule
Attack: Browser Bookmark Discovery
Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.(Citation: Kaspersky Autofill)
Browser information may also highlight additional targets after an adversary has access to valid credentials, especially Credentials In Files associated with logins cached by a browser.
Specific storage locations vary based on platform and/or application, but browser information is typically stored in local files and databases (e.g., %APPDATA%/Google/Chrome
).(Citation: Chrome Roaming Profiles)
MITRE
Tactic
- discovery
technique
- T1217
Test : List Google Chrome / Opera Bookmarks on Windows with powershell
OS
- windows
Description:
Searches for Google Chrome’s and Opera’s Bookmarks file (on Windows distributions) that contains bookmarks. Upon execution, paths that contain bookmark files will be displayed.
Executor
powershell
Sigma Rule
- posh_ps_get_childitem_bookmarks.yml (id: e0565f5d-d420-4e02-8a68-ac00d864f9cf)