{"id":"T1185","name":"Browser Session Hijacking","url":"https://attack.mitre.org/techniques/T1185","tactics":["collection"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0507","stix_id":"x-mitre-detection-strategy--759a29fb-8697-46f7-baa3-a891b28c064e","name":"Detect browser session hijacking via privilege, handle access, and remote thread into browsers","url":"https://attack.mitre.org/detectionstrategies/DET0507","analytics":[{"id":"AN1398","stix_id":"x-mitre-analytic--c3629243-7cd6-4e56-9275-73f5752f0f08","name":"Analytic 1398","description":"Adversary gains high integrity or special privileges (e.g., SeDebugPrivilege), locates a running browser process, opens it with write/inject rights, and modifies it (e.g., CreateRemoteThread / DLL load) to inherit cookies/tokens or establish a browser pivot. Optional step: create a new logon session or use explicit credentials, then drive the victim browser to intranet resources.","url":"https://attack.mitre.org/detectionstrategies/DET0507#AN1398","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4672","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4673","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=8","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"BrowserList","description":"Set of monitored browsers (chrome.exe, msedge.exe, firefox.exe, iexplore.exe). Adjust per fleet."},{"field":"AccessMaskSet","description":"Access rights implying injection (e.g., 0x1FFFFF, 0x1F3FF, VM_WRITE, VM_OPERATION, CREATE_THREAD). Tune by EDR mapping."},{"field":"SignerAllowList","description":"Allowed module signers within browser processes (e.g., Microsoft, Google). Helps flag unsigned/unknown ImageLoad into browsers."},{"field":"InternalCIDR","description":"Enterprise internal ranges or DNS suffixes to identify intranet pivoting via the browser."},{"field":"TimeWindow","description":"Correlation interval (e.g., 10–20 minutes) linking privilege gain → access → modification → network usage."},{"field":"ParentAllowList","description":"Legitimate tools that may automate browsers (e.g., Selenium drivers). Reduce FPs by allowlisting."},{"field":"UserContext","description":"Scope analytics to high-value users, admin workstations, or servers where browsers shouldn’t be automated."}],"live":true,"detection_strategies":["DET0507"],"techniques":["T1185"]}],"live":true,"version":"1.0","techniques":["T1185"]}],"sigma_rules":[{"id":"3e8207c5-fcd2-4ea6-9418-15d45b4890e4","title":"Potential Data Stealing Via Chromium Headless Debugging","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-12-23","modified":null,"description":"Detects chromium based browsers starting in headless and debugging mode and pointing to a user profile. This could be a sign of data stealing or remote control","references":["https://github.com/defaultnamehere/cookie_crimes/","https://mango.pdf.zone/stealing-chrome-cookies-without-a-password","https://embracethered.com/blog/posts/2020/cookie-crimes-on-mirosoft-edge/","https://embracethered.com/blog/posts/2020/chrome-spy-remote-control/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.collection","attack.stealth","attack.t1185","attack.t1564.003"],"path":"rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_debugging.yml","techniques":["T1185","T1564.003"],"cves":[]},{"id":"b3d34dc5-2efd-4ae3-845f-8ec14921f449","title":"Browser Started with Remote Debugging","author":"pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-07-27","modified":"2022-12-23","description":"Detects browsers starting with the remote debugging flags. Which is a technique often used to perform browser injection attacks","references":["https://yoroi.company/wp-content/uploads/2022/05/EternityGroup_report_compressed.pdf","https://www.mdsec.co.uk/2022/10/analysing-lastpass-part-1/","https://github.com/defaultnamehere/cookie_crimes/","https://github.com/wunderwuzzi23/firefox-cookiemonster"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.collection","attack.t1185"],"path":"rules/windows/process_creation/proc_creation_win_browsers_remote_debugging.yml","techniques":["T1185"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-34192","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2012-0767","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-24682","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}