Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0507 — Detect browser session hijacking via privilege, handle access, and remote thread into browsers
DET0507

Detect browser session hijacking via privilege, handle access, and remote thread into browsers

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1398 Analytic 1398
Windows

Adversary gains high integrity or special privileges (e.g., SeDebugPrivilege), locates a running browser process, opens it with write/inject rights, and modifies it (e.g., CreateRemoteThread / DLL load) to inherit cookies/tokens or establish a browser pivot. Optional step: create a new logon session or use explicit credentials, then drive the victim browser to intranet resources.

WinEventLog:Security EventCode=4672 WinEventLog:Security EventCode=4673 WinEventLog:Security EventCode=4624, 4648 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=8 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=3, 22
[BrowserList] Set of monitored browsers (chrome.exe, msedge.exe, firefox.exe, iexplore.exe). Adjust per fleet.
[AccessMaskSet] Access rights implying injection (e.g., 0x1FFFFF, 0x1F3FF, VM_WRITE, VM_OPERATION, CREATE_THREAD). Tune by EDR mapping.
[SignerAllowList] Allowed module signers within browser processes (e.g., Microsoft, Google). Helps flag unsigned/unknown ImageLoad into browsers.
[InternalCIDR] Enterprise internal ranges or DNS suffixes to identify intranet pivoting via the browser.
[TimeWindow] Correlation interval (e.g., 10–20 minutes) linking privilege gain → access → modification → network usage.
[ParentAllowList] Legitimate tools that may automate browsers (e.g., Selenium drivers). Reduce FPs by allowlisting.
[UserContext] Scope analytics to high-value users, admin workstations, or servers where browsers shouldn’t be automated.

Detected Techniques

1

Details

MITRE ID
DET0507
STIX ID
x-mitre-detection-strategy--759a29fb-8697-46f7-baa3-a891b28c064e
Analytics
1
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.