Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1555.003

T1555.003Credentials from Web Browsers

T1555.003 — Credentials from Web Browsers is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 24 detection use cases covering it and 175 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
24Use cases
175Articles
0Sub-techniques
1Tactic

Use cases covering this technique (24)

Infostealer — non-browser process accessing browser cookie/login DBs Internal actions · alerting DSΣP [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Internal actions · alerting DSP [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Internal install · alerting DSPDDCSCW [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Non Chrome Process Accessing Chrome Default Dir ESCU actions · hunting P Non Firefox Process Access Firefox Profile Dir ESCU actions · hunting P Possible Browser Pass View Parameter ESCU actions · hunting P Windows Credentials from Password Stores Chrome Copied in TEMP Dir ESCU actions · alerting P Windows Credentials from Web Browsers Saved in TEMP Folder ESCU actions · alerting P [LLM] Suspicious ProcessAccess to chrome.exe / msedge.exe with injection-grade rights Bespoke actions · alerting DSΣPDD [LLM] macOS browser 'Safe Storage' master-key theft via security find-generic-password Bespoke actions · alerting DSΣPCS [LLM] Non-Chrome process accessing Google Chrome synced-passkey LevelDB store Bespoke actions · alerting DSΣPDDCS [LLM] Command line referencing Chrome Sync Data LevelDB passkey path (copy/stage for exfil) Bespoke actions · alerting DSΣPDDCS [LLM] Browser credential-store theft via OctLurk browser password decryptor Bespoke actions · hunting DSΣPCS [LLM] CastleStealer/Starland RAT accessing browser credential stores and crypto wallets Bespoke actions · hunting DSΣPDDCS [LLM] Atomic Arch infostealer: build-spawned process harvesting SSH keys, dev tokens and browser/Electron sessions Bespoke actions · hunting DSΣPCS [LLM] Mastra easy-day-js second-stage stealer payload by SHA256 Bespoke install · hunting DSΣPDDCS [LLM] AI agent skill exfiltrates GitHub token / env secrets via dynamic-context shell-out Bespoke actions · alerting DSΣPDDCS [LLM] MuddyWater CE-Notes / LP-Notes / Blub stealer staging-file writes Bespoke actions · alerting DSΣPDDCS [LLM] Non-browser process reading Chrome/Edge/Opera Login Data or Local State Bespoke actions · alerting DSΣPDDCS [LLM] Discord webhook / CDN exfiltration from non-browser process (Empyrean stealer C2) Bespoke actions · hunting DSPDDCS

Articles citing this technique (175)