%GoCortexIO Snippets

Cortex XDR

Local browser credential vault harvesting (Infostealers)

| 10 minutes to implement | ~1 min read
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.

# Snippet - Local browser credential vault harvesting

Catch info-stealers and threat actors red-handed by detecting non-browser processes attempting to read canonical browser login databases and session cookie stores.

## Scenario: 
An info-stealer or hands-on operator reads the local browser credential vaults to harvest saved logins and session cookies. Info stealer ecosystems have continued to grow through 2025-2026 and the file paths are stable.

Logic: focuses on reads of the canonical credential files by a process that is not itself the parent browser. Chrome, Edge, Firefox, and friends touch these paths constantly, hence the exclusion.

- [https://attack.mitre.org/techniques/T1555/003/](https://attack.mitre.org/techniques/T1555/003/)
- [https://www.cyber.gov.au/threats/types-threats/malware/information-stealer-malware](https://www.cyber.gov.au/threats/types-threats/malware/information-stealer-malware)
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
dataset = xdr_data
| filter event_type = ENUM.FILE
| filter lowercase(action_file_path) contains "\\user data\\default\\login data"
    or lowercase(action_file_path) contains "\\user data\\default\\cookies"
    or lowercase(action_file_path) contains "key4.db"
    or lowercase(action_file_path) contains "logins.json"
| filter lowercase(actor_process_image_name) not in (
    "chrome.exe", "msedge.exe", "brave.exe", "firefox.exe", "opera.exe")
| fields _time, agent_hostname, actor_effective_username,
    actor_process_image_name, action_file_path
| limit 500
See all 21 snippets