Hannibal Stealer browser credential harvesting via CefSharp and bcrypt.dll
This rule detects potential credential harvesting activity associated with the Hannibal Stealer. It looks for non-standard processes (processes other than the browsers themselves) that access sensitive browser credential stores (like 'Login Data', 'cookies.sqlite', or 'key4.db') and correlate these file access events with the loading of 'bcrypt.dll' or 'CefSharp.BrowsersSubprocess.dll', which are often used for decryption or browser automation/sub-processes during credential theft.
Microsoft Sentinel (KQL)

