{"id":"T1036.012","name":"Browser Fingerprint","url":"https://attack.mitre.org/techniques/T1036/012","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0898","stix_id":"x-mitre-detection-strategy--ad21a251-e824-4368-a04c-8a480ee653cc","name":"Detection of Spoofed User-Agent","url":"https://attack.mitre.org/detectionstrategies/DET0898","analytics":[{"id":"AN2029","stix_id":"x-mitre-analytic--b73489af-2e95-4f41-b82e-327a84da2a1d","name":"Analytic 2029","description":"Process execution without GUI context (e.g., powershell.exe, wscript.exe) generates HTTP traffic with a spoofed User-Agent mimicking a legitimate browser. No corresponding UI application (e.g., msedge.exe) is active or in parent lineage. The User-Agent deviates from known enterprise baselines or contains spoofed platform indicators.  User-Agent strings can be gathered with API calls such as `ShellExecuteW` to open the default browser on a socket to receive an HTTP reply, or by hard coding the User-Agent string for a specific browser.","url":"https://attack.mitre.org/detectionstrategies/DET0898#AN2029","platforms":["Windows"],"log_source_references":[{"name":"NSM:Flow","channel":"Inbound HTTP POST with suspicious payload size or user-agent","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-Kernel-Process","channel":"API Calls","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-kernel-process"}],"mutable_elements":[{"field":"HeaderSignatureMatch","description":"Specific HTTP header anomalies or patterns (e.g., spoofed User-Agent)."},{"field":"UserAgentFingerprint","description":"Flag browser-based sessions"},{"field":"NonBrowserProcessList","description":"List of non-browser binaries expected not to initiate web requests (e.g., powershell.exe, cscript.exe)"}],"live":true,"detection_strategies":["DET0898"],"techniques":["T1036.012"]},{"id":"AN2031","stix_id":"x-mitre-analytic--acabb18b-e2d6-4531-92bb-4165f0a16595","name":"Analytic 2031","description":"Detection of HTTP outbound requests with inconsistent or spoofed User-Agent headers from command-line tools (e.g., curl, wget, python requests) following interactive user shells or scheduled jobs outside of normal user session behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0898#AN2031","platforms":["Linux"],"log_source_references":[{"name":"NSM:Flow","channel":"http.log, conn.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"auditd:SYSCALL","channel":"outbound connections","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"HeaderSignatureMatch","description":"Specific HTTP header anomalies or patterns (e.g., spoofed User-Agent)."},{"field":"UserAgentFingerprint","description":"Flag browser-based sessions"}],"live":true,"detection_strategies":["DET0898"],"techniques":["T1036.012"]},{"id":"AN2032","stix_id":"x-mitre-analytic--29ca0e06-e848-44cd-821a-24576276a8af","name":"Analytic 2032","description":"Observation of scripted network requests (e.g., using osascript, curl, or python) that include mismatched or spoofed browser User-Agent strings compared to the typical macOS Safari or Chrome baseline, especially when triggered by non-interactive launch agents, login hooks, or background daemons.","url":"https://attack.mitre.org/detectionstrategies/DET0898#AN2032","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"network connection events","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Inbound HTTP POST with suspicious payload size or user-agent","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"},{"name":"macos:unifiedlog","channel":"exec logs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"UserAgentFingerprint","description":"Flag browser-based sessions"},{"field":"HeaderSignatureMatch","description":"Specific HTTP header anomalies or patterns (e.g., spoofed User-Agent)."}],"live":true,"detection_strategies":["DET0898"],"techniques":["T1036.012"]}],"live":true,"version":"1.0","techniques":["T1036.012"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}