T1217 — Browser Information Discovery
T1217: Browser Information Discovery
MITRE ATT&CK® Enterprise technique
| Tactics | Discovery |
| Platforms | Linux, macOS, Windows |
| Permissions required | — |
| Version | 2.0 |
Description
Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.(Citation: Kaspersky Autofill)
Browser information may also highlight additional targets after an adversary has access to valid credentials, especially Credentials In Files associated with logins cached by a browser.
Specific storage locations vary based on platform and/or application, but browser information is typically stored in local files and databases (e.g., %APPDATA%/Google/Chrome).(Citation: Chrome Roaming Profiles)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1217
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/