Potential Data Stealing Via Chromium Headless Debugging

 Original Source: [Sigma source]
Title: Potential Data Stealing Via Chromium Headless Debugging
Status: test
Description:Detects chromium based browsers starting in headless and debugging mode and pointing to a user profile. This could be a sign of data stealing or remote control
References:
  -https://github.com/defaultnamehere/cookie_crimes/
  -https://mango.pdf.zone/stealing-chrome-cookies-without-a-password
  -https://embracethered.com/blog/posts/2020/cookie-crimes-on-mirosoft-edge/
  -https://embracethered.com/blog/posts/2020/chrome-spy-remote-control/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-23
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.collection'
  • -'attack.stealth'
  • -'attack.t1185'
  • -'attack.t1564.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'--remote-debugging-'
      -'--user-data-dir'
      -'--headless'

  condition:selection
Falsepositives:
  -Unknown
Level: high