Detects a browser credential or cookie file (Login Data, Cookies, Web Data, Firefox logins.json or key4.db) being created inside a staging location such as Temp, Public, ProgramData or a compressed archive. Stealers copy these files out of the browser profile into a staging folder before exfiltration; browsers themselves never write these filenames to those locations. The rule matched on logsource `file_event`. Verify the event genuinely matches the described behavior, and not a known legitimate case. The rule matches on these fields — examine the exact value in the event:
Investigation queries (read-only):
Relevant defensive analysis techniques (MITRE D3FEND), to apply where the telemetry is available:
Known benign causes for this rule:
⚠️ No automatic action. D3FEND countermeasures for a human to evaluate before any containment/hardening action:
The rule's references — CTI context to qualify the incident: