logo

When on Workstation, Do as the Local Browsers Do!

ID: ab3523db-09d8-5b9c-b5d1-525c6c41286e

STIX ID: report--ab3523db-09d8-5b9c-b5d1-525c6c41286e

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This post describes how attackers can abuse browser extensions and steal stored credentials/cookies from Chromium-based and other browsers, demonstrates audit and SACL configuration for Windows, and supplies Splunk SPL detection templates and tagging strategies (covering Event IDs 4657, 4663, 4688, 4695) plus examples using SharpChrome/SharpChromium and extension IOCs to help defenders detect such activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.