Suspicious Where Execution

 Original Source: [Sigma source]
Title: Suspicious Where Execution
Status: test
Description:Adversaries may enumerate browser bookmarks to learn more about compromised hosts. Browser bookmarks may reveal personal information about users (ex: banking sites, interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1217/T1217.md
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
Date: 2021-12-13
modified:2022-06-29
Tags:
  • -'attack.discovery'
  • -'attack.t1217'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  where_exe:
Image|endswith:'\where.exe' OriginalFileName:'where.exe'   where_opt:
    CommandLine|contains:
      -'places.sqlite'
      -'cookies.sqlite'
      -'formhistory.sqlite'
      -'logins.json'
      -'key4.db'
      -'key3.db'
      -'sessionstore.jsonlz4'
      -'History'
      -'Bookmarks'
      -'Cookies'
      -'Login Data'

  condition:all of where_*
Falsepositives:
  -Unknown
Level: low