Browser Session Token Theft - Non-Browser Process Accessing Cookie Store

This rule detects unauthorized access, creation, or modification of browser-specific sensitive credential files (such as 'Login Data' or 'cookies.sqlite') by processes that are not recognized web browsers or trusted update services. This behavior is a common indicator of information-stealer malware attempting to harvest session cookies and stored credentials.