APT36 SHEETCREEP: vaultsvc.exe Dropped to AppData\Local\Microsoft\Vault

Detects file creation or modification events within the Windows Credential Vault folder (AppData\Local\Microsoft\Vault), excluding legitimate activity by the 'vaultsvc.exe' process. This could indicate an attempt to access, modify, or exfiltrate stored credentials.