Browser Started with Remote Debugging

 Original Source: [Sigma source]
Title: Browser Started with Remote Debugging
Status: test
Description:Detects browsers starting with the remote debugging flags. Which is a technique often used to perform browser injection attacks
References:
  -https://yoroi.company/wp-content/uploads/2022/05/EternityGroup_report_compressed.pdf
  -https://www.mdsec.co.uk/2022/10/analysing-lastpass-part-1/
  -https://github.com/defaultnamehere/cookie_crimes/
  -https://github.com/wunderwuzzi23/firefox-cookiemonster
Author: pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-27
modified:2022-12-23
Tags:
  • -'attack.credential-access'
  • -'attack.collection'
  • -'attack.t1185'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_chromium_based:
    CommandLine|contains: ' --remote-debugging-'
  selection_firefox:
    Image|endswith: '\firefox.exe'
    CommandLine|contains: ' -start-debugger-server'
  condition:1 of selection_*
Falsepositives:
  -Unknown
Level: medium