Detecting browser data theft using Windows Event Logs
ID: 6492f9ed-25cc-552e-83a7-7114c31a8fd4
STIX ID: report--6492f9ed-25cc-552e-83a7-7114c31a8fd4
Feed Name: Google Online Security Blog
The report describes a practical detection method to identify theft of Chromium-based browser cookies and credentials on Windows by enabling DPAPI auditing and Crypto-DPAPI debug logging, then correlating event 16385 (SPCryptUnprotect with browser DataDescription) to process creation event 4688 to flag non-browser processes accessing protected data; it includes configuration steps and a demonstration using a Python password stealer to show how to generate alerts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
