T1036.012 — Browser Fingerprint
T1036.012: Browser Fingerprint
MITRE ATT&CK® Enterprise technique
| Tactics | Stealth |
| Platforms | Linux, macOS, Windows |
| Permissions required | — |
| Version | 2.0 |
| Parent technique | T1036 |
Description
Adversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc. The HTTP User-Agent request header is a string that lets servers and network peers identify the application, operating system, vendor, and/or version of the requesting user agent.(Citation: Mozilla User Agent)
Adversaries may gather this information through System Information Discovery or by users navigating to adversary-controlled websites, and then use that information to craft their web traffic to evade defenses.(Citation: Gummy Browsers Targeted Browser Spoofing against State-of-the-Art Fingerprinting Techniques)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1036/012
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/