MITRE ATT&CK technique
Steal Web Session Cookie detection rulesT1539
Steal Web Session Cookie (T1539) is a MITRE ATT&CK technique in the Credential Access tactic. This page lists the 2 community-maintained Sigma detection rules in the library mapped to T1539 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
T1539 on attack.mitre.org2 rules
Top products
Tactic
SQLite Chromium Profile Data DB Access
highDetect usage of the "sqlite" binary to query databases in Chromium-based browsers for potential data stealing.
windows · process_creation
SQLite Firefox Profile Data DB Access
highDetect usage of the "sqlite" binary to query databases in Firefox and other Gecko-based browsers for potential data stealing.
windows · process_creation