Skip to content

Firefox Cookies

Evidence: Firefox Cookies
Description: Collect Firefox Cookies
Category: Applications
Platform: linux
Short Name: fcookies
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Firefox cookies store session data, authentication tokens, user preferences, and tracking information. Cookies can persist across sessions and contain sensitive data including login credentials, API tokens, and user identifiers. Understanding cookie data is essential for investigating account compromises, tracking malicious domains, and identifying data exfiltration paths.

This collector gathers structured data about firefox cookies.

FieldDescriptionExample
UserNameUser NameExample value
ProfileNameProfile NameExample value
OriginAttributesOrigin AttributesExample value
NameNameExample value
ValueValueExample value
HostHostExample value
PathPathExample value
IsSecureIs Securetrue
IsHTTPOnlyIs HTTP Onlytrue
InBrowserElementIn Browser Element123
SameSiteSame Site123
RawSameSiteRaw Same Site123
SchemeMapScheme Map123
ExpiryExpiry2023-10-15 14:30:25+03:00
LastAccessTimeLast Access Time2023-10-15 14:30:25+03:00
CreationTimeCreation Time2023-10-15 14:30:25+03:00

This collector queries the Firefox cookies.sqlite database to extract cookie information including names, values, domains, paths, expiration times, security flags, and SameSite attributes for all user profiles.

Cookie data reveals visited websites, active sessions, authentication states, and tracking mechanisms. Malicious cookies may indicate session hijacking, credential theft, cross-site scripting attacks, or connections to command-and-control infrastructure. This evidence helps establish user activity timelines, identify compromised accounts, and track attacker access to web services.