MITRE ATT&CK technique
Browser Session Hijacking detection rulesT1185
Browser Session Hijacking (T1185) is a MITRE ATT&CK technique in the Collection tactic. This page lists the 2 community-maintained Sigma detection rules in the library mapped to T1185 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
T1185 on attack.mitre.org2 rules
Top products
Tactic
Potential Data Stealing Via Chromium Headless Debugging
highDetects chromium based browsers starting in headless and debugging mode and pointing to a user profile. This could be a sign of data stealing or remote control
windows · process_creation
Browser Started with Remote Debugging
mediumDetects browsers starting with the remote debugging flags. Which is a technique often used to perform browser injection attacks
windows · process_creation