Vidar Stealer Chromium KeyRing Memory Scan via NtReadVirtualMemory
Detects Vidar Stealer scanning the memory of a forked browser process for the Chromium KeyRing 32-byte pattern using NtReadVirtualMemory and NtQueryVirtualMemory to locate the v20_master_key across MEM_COMMIT and MEM_PRIVATE regions.
Microsoft Sentinel (KQL)

