Renamed BrowserCore.EXE Execution

 Original Source: [Sigma source]
Title: Renamed BrowserCore.EXE Execution
Status: test
Description:Detects process creation with a renamed BrowserCore.exe (used to extract Azure tokens)
References:
  -https://twitter.com/mariuszbit/status/1531631015139102720
Author: Max Altgelt (Nextron Systems)
Date: 2022-06-02
modified:2023-02-03
Tags:
  • -'attack.credential-access'
  • -'attack.stealth'
  • -'attack.t1528'
  • -'attack.t1036.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    OriginalFileName: 'BrowserCore.exe'
  filter_realbrowsercore:
    Image|endswith: '\BrowserCore.exe'
  condition:selection and not 1 of filter_*
Falsepositives:
  -Unknown
Level: high