T1217Techniquediscoveryagent-callable

T1217Browser Information Discovery

Platforms: Linux · Windows · macOS

ATT&CK version: 14.1

What it is

Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.(Citation: Kaspersky Autofill) Browser information may also highlight additional targets after an adversary has access to valid credentials, especially [Credentials In Files](https://attack.mitre.org/techniques/T1552/001) associated with logins cached by a browser. Specific storage locations vary based on platform and/or application, but browser information is typically stored in local files and databases (e.g., `%APPDATA%/Google/Chrome`).(Citation: Chrome Roaming Profiles)

ATT&CK tactics· 1

Discovery

References

  1. https://attack.mitre.org/techniques/T1217
  2. https://support.google.com/chrome/a/answer/7349337
  3. https://www.kaspersky.com/blog/browser-data-theft/27871/
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.