Firefox Encrypted Login Entry

Detects Firefox logins.json encrypted password entries in the JSON format used by Firefox's NSS (Network Security Services) credential store. Mirrors Snaffler rule KeepFFRegexRed.

Type
regex
Engine
boost_regex
Confidence
high
Confidence justification
High confidence: the encryptedPassword JSON key combined with the base64 value constraint is highly specific to Firefox logins.json. The field name is not used in other common credential formats.
Jurisdictions
global
Regulations
Criminal Code Act 1995 (Cth)
Frameworks
CIS Controls, ISO 27001, NIST CSF
Data categories
credentials
Scope
specific
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Compatible, Netskope: Compatible

Pattern

"encryptedPassword"\s*:\s*"[A-Za-z0-9+/=]{16,}"

Corroborative evidence keywords

encryptedUsername, formSubmitURL, guid, timeCreated

Proximity: 300 characters

Should match

Should not match

Known false positives

Collections