// MITRE ATT&CK

T1036.012 · Browser Fingerprint

🎯 Stealth LinuxmacOSWindows Sub-technique

Sub-technique of T1036 · Masquerading.

Adversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc. The HTTP User-Agent request header is a string that lets servers and network peers identify the a...

How to detect & mitigate it

Detecting Browser Fingerprint starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.