Cortex XDR
Local browser credential vault harvesting (Infostealers)
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.
# Snippet - Local browser credential vault harvesting
Catch info-stealers and threat actors red-handed by detecting non-browser processes attempting to read canonical browser login databases and session cookie stores.
## Scenario:
An info-stealer or hands-on operator reads the local browser credential vaults to harvest saved logins and session cookies. Info stealer ecosystems have continued to grow through 2025-2026 and the file paths are stable.
Logic: focuses on reads of the canonical credential files by a process that is not itself the parent browser. Chrome, Edge, Firefox, and friends touch these paths constantly, hence the exclusion.
- [https://attack.mitre.org/techniques/T1555/003/](https://attack.mitre.org/techniques/T1555/003/)
- [https://www.cyber.gov.au/threats/types-threats/malware/information-stealer-malware](https://www.cyber.gov.au/threats/types-threats/malware/information-stealer-malware)
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
dataset = xdr_data
| filter event_type = ENUM.FILE
| filter lowercase(action_file_path) contains "\\user data\\default\\login data"
or lowercase(action_file_path) contains "\\user data\\default\\cookies"
or lowercase(action_file_path) contains "key4.db"
or lowercase(action_file_path) contains "logins.json"
| filter lowercase(actor_process_image_name) not in (
"chrome.exe", "msedge.exe", "brave.exe", "firefox.exe", "opera.exe")
| fields _time, agent_hostname, actor_effective_username,
actor_process_image_name, action_file_path
| limit 500